By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ExpelPublished March 13, 2026

TL;DR: Identity-based incidents accounted for 68.6% of cases and 47.7% of those led to successful account access, according to Expel’s 2026 Annual Threat Report, while its CISO-CFO disconnect report shows budget and language gaps that leave basic controls underfunded. The real problem is governance: organisations still fail on controls they already understand.


At a glance

What this is: This is an analysis of how finance-security communication gaps contribute to preventable identity-based attacks, using Expel’s threat and survey data as evidence.

Why it matters: It matters because IAM, PAM, and NHI programmes often fail at the funding and execution stage, where weak business translation leaves MFA, configuration control, and identity governance partially deployed.

By the numbers:

👉 Read Expel’s analysis of identity-based attacks and the CISO-CFO disconnect


Context

Identity-based attacks keep succeeding when organisations treat authentication, access control, and monitoring as partially implemented programmes instead of enforced controls. In this case, the failure is not a lack of awareness, but a gap between known risk and funded execution, which is where IAM and NHI governance often break down.

Expel’s research shows that the security problem is also a communication problem. When finance teams do not trust the way security explains business impact, funding decisions slow down, and foundational controls such as MFA, configuration management, and credential governance remain unevenly deployed.

That pattern is not typical of mature identity programmes, but it is common enough to explain why known attack paths keep working at scale.


Key questions

Q: What breaks when identity controls are only documented and not executed consistently?

A: When identity controls exist only on paper, the organisation loses the ability to prevent or promptly detect bad access, missed approvals, and offboarding gaps. That creates a control deficiency first, then a broader governance problem if the failures repeat. The practical test is whether the control produces reliable evidence in real operations, not whether it is written into policy.

Q: Why do identity programmes often lose funding over time?

A: Identity programmes lose funding when leaders classify ongoing governance work as one-time implementation rather than recurring assurance. Once the initial rollout is complete, renewal, review, and maintenance costs are easier to defer, but the control surface then degrades. The result is a programme that looks funded while its actual protection weakens.

Q: How do you know if MFA and identity controls are actually working?

A: You measure whether attacks fail consistently at the point of authentication and whether exceptions are rare, visible, and approved. If successful account access keeps occurring through legitimate-looking credentials, the control exists on paper but not in practice.

Q: Who is accountable when identity risk is discovered but not fixed?

A: Accountability belongs to the team that can actually enforce the change, not the team that merely reports the issue. If security owns the risk but cannot revoke access, the operating model is misaligned. Frameworks such as the NIST Cybersecurity Framework 2.0 expect governance to connect detection with response and recovery.


Technical breakdown

Why identity-based attacks succeed when controls are only partially deployed

Identity attacks often do not require technical sophistication. Stolen credentials and hijacked tokens work because the attacker is already presenting valid-looking identity material, and many environments still accept it unless MFA, device checks, or conditional access is consistently enforced. The important point is not that controls fail in theory, but that they fail unevenly when deployment is incomplete. That creates a gap between policy and practice, which attackers exploit repeatedly.

Practical implication: validate that MFA, conditional access, and token protections are enforced everywhere they matter, not just in selected systems.

How budget gaps become identity risk gaps

Security investment decisions shape whether identity controls are fully operational or only nominally present. If finance evaluates requests using ROI language while security reports using maturity scores or detection counts, critical identity work can appear optional even when it is foundational. That matters for NHI governance too, because service accounts, tokens, and machine credentials often slip through when programmes fund visible tooling before lifecycle controls. The result is predictable: the organisation believes it has coverage, but the control is not actually complete.

Practical implication: tie identity and NHI investments to business exposure, not programme activity, so funding decisions match the actual attack surface.

Why cloud and identity failures compound each other

Cloud incidents are often small in volume but large in consequence because misconfiguration, exposed secrets, and unpatched services can quickly widen access. Those paths frequently intersect with identity because compromised credentials or over-privileged accounts turn a local issue into a broader compromise. In practice, cloud security, IAM, and secrets governance need to be analysed together, not as separate programmes. When they are separated, attackers move through the handoff points.

Practical implication: review cloud exposure, privilege scope, and secret handling as one control set rather than three disconnected teams.


Threat narrative

Attacker objective: The attacker wants legitimate-looking access that bypasses weakly enforced identity controls and opens the path to account compromise or wider cloud impact.

  1. Entry begins with stolen credentials or hijacked authentication tokens that let attackers appear legitimate at the point of access.
  2. Escalation succeeds where MFA, configuration management, or monitoring is not fully deployed or properly enforced, allowing valid access to become account compromise.
  3. Impact follows when identity-based access reaches business systems and cloud infrastructure, turning partial control failures into operational disruption.

NHI Mgmt Group analysis

Identity control failure is often a funding failure before it is a technical failure. The article’s strongest point is that the needed controls already exist, but they are not always deployed rigorously enough to stop basic attacks. That is a governance problem, not a technology discovery problem. For IAM and PAM leaders, the lesson is that partial implementation is a control failure, not an acceptable intermediate state.

Finance-language translation is now part of identity governance. Security teams cannot rely on maturity metrics alone when the business uses exposure, continuity, and cost avoidance to judge investment. This affects NHI and human identity programmes alike, because both depend on sustained funding for lifecycle control, access review, and enforcement. Practitioners should treat financial framing as a core part of governance, not a side skill.

Standing access and weak deployment discipline create the same blast-radius problem across human and non-human identities. Identity-based attacks succeed when access is valid enough to pass initial checks but not constrained enough to stop misuse. In NHI environments, that maps directly to unmanaged tokens, service accounts, and over-privileged credentials. The practitioner conclusion is straightforward: if identity controls are not enforced consistently, attack scale rises faster than detection can compensate.

Control visibility must be matched to executive accountability. The article shows that director-level coordination can produce operational outcomes, but C-suite alignment is what changes budget outcomes. That matters because identity governance programmes need both technical ownership and financial sponsorship to close the gap between policy and practice. Organisations that do not elevate the conversation will keep rediscovering the same failures.

NHI lifecycle discipline is the named concept this report exposes: funding drift. When lifecycle controls such as provisioning, rotation, revocation, and offboarding are not tied to business risk language, they become easy to postpone. The result is a governance gap where machine credentials remain active longer than intended and accountability is diffuse. Practitioners should treat lifecycle funding as part of the control itself, not as an administrative afterthought.

What this signals

Funding discipline is becoming an identity control in its own right. When organisations cannot translate identity risk into financial exposure, critical controls remain partial, and partial controls are the condition attackers need. The programme-level response is to treat funding decisions as part of governance, not separate from it.

The reporting model matters as much as the technical stack. Security leaders who can show business impact, continuity risk, and cost avoidance are more likely to secure durable support for MFA, secrets governance, and NHI lifecycle controls. For background on the broader identity risk landscape, see the Ultimate Guide to NHIs.

Finance-visible metrics should become part of identity operations. If a control cannot be defended in terms of reduced exposure or avoided disruption, it will struggle against competing priorities. That is especially true for NHI programmes, where hidden credentials and standing access create risk that is easy to underestimate until it is exploited.


For practitioners

  • Map identity risk to financial exposure Translate MFA gaps, token abuse, and cloud credential exposure into downtime cost, recovery spend, and regulatory impact so finance can evaluate the request in its own language.
  • Audit where identity controls are only partially deployed Verify that MFA, conditional access, and authentication protections are enforced across all production systems, not just the highest-profile ones.
  • Join NHI lifecycle control to budget ownership Tie service account provisioning, secret rotation, and revocation to named business owners so machine identities do not persist outside accountable funding lines.
  • Use executive-level metrics for identity investment cases Lead budget reviews with exposure reduction, cost avoidance, and continuity protection instead of maturity scores that finance does not use to make capital decisions.

Key takeaways

  • Identity attacks keep succeeding because partially deployed controls leave legitimate-looking access paths open.
  • The report’s core governance lesson is that security funding and business translation directly shape whether identity controls are actually enforced.
  • IAM, PAM, and NHI teams need to frame control coverage in financial terms if they want sustained executive support.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03The article centres on incomplete NHI and identity control deployment.
NIST CSF 2.0PR.AC-1Identity-based access control and authentication are central to the failure mode described.
NIST SP 800-53 Rev 5IA-2Authentication weaknesses and MFA gaps are directly implicated in the article.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe attack pattern described uses stolen credentials and legitimate access for progression.
NIST AI RMFGOVERNThe article’s central issue is accountability for how risk is explained and funded.

Apply GOVERN to assign clear responsibility for security-risk communication and investment decisions.


Key terms

  • Identity-centric attack: An identity-centric attack is a compromise path that uses valid credentials, tokens, or sessions instead of breaking technical controls at the network edge. The attacker behaves like a legitimate identity long enough to move laterally, escalate privilege, or exfiltrate data while appearing authorised.
  • Control deployment gap: The gap between a control existing in policy or tooling and that control being fully operational across the environment. In identity security, this often shows up as partial MFA coverage, inconsistent conditional access, or weak enforcement of lifecycle controls for accounts and credentials.
  • Non-Human Identity Governance: Non-human identity governance is the practice of managing, controlling, and auditing every machine identity across its full lifecycle. It covers service accounts, API keys, tokens, certificates, and AI agent credentials — ensuring each has a defined owner, scoped privilege, rotation schedule, and revocation path. Without governance, NHIs accumulate silently and become the primary attack surface in cloud and automated environments.
  • Security-finance translation: The process of expressing cyber risk in business terms that finance leaders can use in funding decisions. It links technical control gaps to cost avoidance, continuity, and exposure reduction so identity programmes can compete effectively for investment.

What's in the full article

Expel’s full blog covers the source data and executive discussion this post intentionally leaves at the strategic level:

  • The underlying 2026 Annual Threat Report findings behind the 68.6% identity-based incident rate and the control failures behind successful access.
  • The CISO-CFO disconnect survey results from 300 executives, including confidence scores and collaboration patterns.
  • The security-finance framework for translating identity risk into budget language, including the metrics finance actually uses.
  • The full webinar discussion with Expel and SMBC leaders on how to communicate risk across functions.

👉 Expel’s full post includes the threat report findings, survey data, and executive guidance on closing the funding gap.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity control design to the operational and financial realities that shape programme decisions.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org