By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Arxan TechnologiesPublished December 17, 2025

TL;DR: Enterprise technology spending reached nearly $4 trillion in 2025, and Arxan Technologies’ analysis says the bigger story was execution strain: cloud, AI, modernization, and software investments multiplied faster than organisations could absorb them. The result is a governance problem for capacity, dependency management, and adaptive planning, not simply a budget problem.


At a glance

What this is: Digital.ai argues that 2025’s record IT spending exposed a widening gap between investment ambition and an organisation’s ability to absorb change.

Why it matters: For IAM, NHI, and broader security programmes, the lesson is that control design must keep pace with accelerating platform change, interdependencies, and AI-driven operational drift.

By the numbers:

👉 Read Arxan Technologies' analysis of 2025 IT spend and execution strain


Context

Enterprise technology spending can rise sharply while delivery capacity stays flat or even declines. That mismatch becomes a security and governance problem when cloud expansion, AI adoption, and modernization all advance together, because every new platform, integration, and workflow adds control dependencies that existing operating models were not built to manage.

For identity practitioners, the relevant question is not how much organisations spend on transformation, but whether identity governance, privilege control, and workload access oversight can keep pace with that transformation. As AI systems, cloud services, and modernised applications multiply, the blast radius of weak access decisions grows faster than review cycles, making execution discipline as important as architectural ambition.


Key questions

Q: How should security teams govern access when transformation programmes change continuously?

A: They should treat access governance as a live control process, not a periodic review. That means tying entitlement decisions to delivery milestones, updating privileged access when architecture changes, and closing temporary permissions as soon as the change is complete. If review cycles stay fixed while systems keep changing, access state will drift out of sync with reality.

Q: Why do AI infrastructure programmes create new identity governance risk?

A: They create risk because machine-speed workflows can combine APIs, secrets, and delegated authority faster than conventional review cycles can observe. That breaks assumptions built around human-paced approval, auditing, and recertification. The result is not just more access, but less clarity about which component exercised that access and whether it was still appropriate.

Q: What are the signs that identity controls are falling behind transformation work?

A: Common signs include frequent manual access exceptions, delayed entitlement cleanup, inconsistent ownership of service accounts, and review findings that repeat across multiple projects. If security teams cannot explain which change introduced a permission or why it still exists, control freshness is already slipping.

Q: What should organisations prioritise first when security and delivery capacity are stretched?

A: They should prioritise control freshness for the highest-change areas, especially cloud, AI, and privileged access. The first goal is not perfect coverage, but reducing the time between environment change and access correction. That sequence limits drift while broader governance improvements catch up.


Technical breakdown

Why compound transformation strains identity and security controls

Compound transformation happens when cloud migration, AI adoption, modernization, and software expansion all progress at once. Each initiative changes access paths, control boundaries, and operational ownership. The technical problem is not only volume, but dependency coupling: one application change can affect authentication flows, telemetry, entitlements, and downstream approvals in another system. That makes static governance models fragile, especially when teams rely on periodic reviews rather than continuous context. In identity terms, the more systems change simultaneously, the harder it becomes to maintain accurate entitlement scope, privileged access boundaries, and service-account accountability.

Practical implication: treat transformation programmes as access-change events and reassess identity controls whenever architecture shifts.

How AI and cloud expansion complicate entitlement governance

AI infrastructure and cloud growth increase the number of machine identities, service accounts, tokens, certificates, and delegated access paths that must be governed. When infrastructure teams move quickly, credentials and entitlements often outlive the workflow they were created for. The operational result is governance lag, where access provisioning, review, and removal happen after the environment has already changed. That lag is especially risky in cloud-native environments because automation can multiply mis-scoped permissions at scale. For identity teams, this means entitlement quality becomes a runtime issue, not just a policy issue.

Practical implication: move entitlement review closer to deployment and automate lifecycle controls for machine identities.

What adaptive planning means for security and identity operations

Adaptive planning is the practice of treating the operating plan as a living control layer rather than a fixed annual document. In complex environments, capacity, risk, and dependencies change too quickly for quarterly governance alone to stay accurate. For security and IAM teams, adaptive planning means synchronising access governance with project delivery, infrastructure change, and workload lifecycle events. It also means planning for exceptions, because modernisation and AI work inevitably create temporary access paths and partial migrations. The architectural benefit is better alignment between who can act, where they can act, and what changed since the last review.

Practical implication: align IAM checkpoints with delivery milestones, not calendar cycles.


NHI Mgmt Group analysis

Execution capacity is becoming an identity control issue. When organisations scale AI, cloud, and modernization simultaneously, the practical failure is not just operational overload. It is that identity governance, especially for service accounts and privileged access, cannot absorb the pace of change. Programmes that treat access review as a periodic ceremony will miss the fact that entitlements are now moving inside live transformation streams. Practitioners should therefore treat change velocity as a control variable, not a business metric.

Cloud and AI expansion are creating governance debt in machine identities. The article’s core pattern is that every new platform or automated workflow introduces more non-human identities, more delegation chains, and more lifecycle exceptions. That is classic NHI governance debt: access that was legitimate at deployment remains in place after the workload, team, or architecture has changed. The lesson for IAM and PAM teams is that lifecycle cleanup must be embedded in delivery, not deferred to post-project remediation.

Adaptive planning is a governance model, not a project management slogan. The article correctly recognises that transformation is continuous, but security teams should read that as a control-design warning. If plan updates do not feed entitlement decisions, telemetry review, and privileged access rules, then the organisation is managing motion without governance. Frameworks such as NIST Cybersecurity Framework 2.0 and NIST SP 800-53 reinforce the need to tie operational change to control maintenance. Practitioners should make control freshness part of the planning model.

Named concept: control freshness lag. This article illustrates the gap between how quickly environments change and how slowly governance catches up. The result is stale access, outdated assumptions, and fragmented accountability across engineering, security, and operations. For identity-led programmes, the right response is to measure how long control state remains valid after architecture changes, then shorten that window before it becomes a breach condition.

The market signal is clear: governance now has to scale at the same rate as infrastructure investment. The organisations that struggle are not necessarily underfunded. They are misaligned, with delivery velocity outrunning identity, access, and operational control processes. For practitioners, that means security architecture should be evaluated alongside transformation roadmaps, not after them.

What this signals

Control freshness lag: as transformation accelerates, the interval between a real-world change and a governance update becomes a measurable risk surface. That is where entitlement drift, privileged access sprawl, and incomplete offboarding start to accumulate, especially in cloud and AI-heavy programmes.

Security leaders should expect more environments where infrastructure change and identity change are effectively the same event. The practical response is to connect planning, access lifecycle, and exception handling so governance updates travel with delivery rather than behind it.

The broader signal is that AI adoption will keep stretching traditional access models, which makes lifecycle discipline and workload identity governance more important than another layer of reporting.


For practitioners

  • Map identity controls to transformation milestones Tie entitlement reviews, privileged access approvals, and service-account recertification to migration waves, AI rollouts, and platform cutovers instead of quarterly calendars.
  • Track machine identity growth as a programme risk Measure new service accounts, tokens, certificates, and delegated access paths created by each initiative, then assign ownership before the workflow goes live.
  • Embed access cleanup into delivery pipelines Require offboarding, rotation, and entitlement pruning as part of project closure so temporary access does not survive after modernisation work ends.
  • Use external frameworks to reset control freshness Anchor governance checks to NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls when environment changes outpace review cycles.

Key takeaways

  • Enterprise spend can surge while control capacity stays flat, creating governance debt that shows up first in identity and access management.
  • AI, cloud, and modernization programmes multiply machine identities and dependency chains, so stale permissions become more likely unless lifecycle controls move into delivery.
  • Practitioners should measure how quickly identity controls age after architectural change, because control freshness is now a security metric.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01The article centres on governance oversight as transformation accelerates.
NIST SP 800-53 Rev 5CM-3Change control is central when architecture shifts affect access and dependencies.
CIS Controls v8CIS-4 , Secure Configuration of Enterprise Assets and SoftwareFast-changing environments need configuration discipline to avoid control drift.
ISO/IEC 27001:2022A.8.32Change management is directly relevant to transformation-driven governance lag.

Use change management controls to keep identity and access decisions aligned with current system state.


Key terms

  • Identity Freshness: Identity freshness is the degree to which the governance system reflects the live state of accounts, groups, entitlements, and credentials. It is not just a performance metric. In practice, freshness determines whether access reviews, approvals, and offboarding actions are based on reality or on a delayed snapshot.
  • Governance Debt: The accumulation of unresolved identity control weaknesses created when teams prioritise speed over lifecycle design. In NHI environments, it shows up as accounts with unclear ownership, undocumented purpose, stale credentials, and no reliable retirement path, all of which make later security work harder.
  • Compound Transformation: A condition where several major change programmes run at the same time, such as cloud migration, AI adoption, and application modernisation. The result is more dependency coupling and more control touchpoints than normal operating models can absorb. Security teams must treat it as an operating-state change, not just a project portfolio.
  • Machine identity lifecycle: Machine identity lifecycle is the full governance process for a non-human identity from creation to retirement. It includes provisioning, access scoping, rotation, renewal, offboarding, and auditability, and it fails when any one of those steps is handled manually or inconsistently.

What's in the full article

Arxan Technologies' full blog covers the operational detail this post intentionally leaves for the source:

  • The article breaks down the five investment domains and the practical pressures behind each one, including AI infrastructure, cloud, enterprise software, modernization, and outsourcing.
  • It expands the vision-versus-reality comparison with examples of where budget growth did not translate into usable capacity or stable operations.
  • It outlines the adaptive planning model the vendor recommends for teams managing concurrent transformation programmes.
  • It includes the source set and market-signal references the post only summarises at a higher level.

👉 Arxan Technologies' full post expands the investment breakdown, reality checks, and adaptive planning model.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners turn identity control principles into operational practice across fast-changing environments.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org