TL;DR: Identity remained the most targeted attack surface in Expel’s 2026 Annual Threat Report, which says 68.6% of incidents it saw in 2025 involved identity as the primary entry point; the report also argues security teams need to translate control success into business risk and dollars, not just block counts, according to Expel. That framing matters because stronger identity controls change the meaning of an incident, not the need for governance.
At a glance
What this is: Expel’s annual threat report says identity was the main attack surface in 68.6% of incidents it observed in 2025, and argues that cybersecurity success should be measured in business risk reduction rather than raw attack counts.
Why it matters: For IAM and NHI practitioners, this reinforces that identity controls now sit at the center of both attack prevention and executive risk reporting, so governance has to prove impact in operational and financial terms.
By the numbers:
- 68.6% of all the incidents Expel saw in 2025 involved identity as the main attack surface.
👉 Read Expel's 2026 Annual Threat Report on identity-led incidents and risk translation
Context
Identity is no longer just one control plane among many. When most incidents begin with identity exposure, weak authentication, or account abuse, the practical question shifts from whether security tools detected activity to whether identity governance reduced the attacker’s usable access. That is relevant across human IAM, NHI estates, and emerging agentic AI systems that inherit the same access and privilege patterns.
Expel’s report frames the problem as a measurement gap as much as a technical one. Security teams often count prevented attempts, while business leaders care about reduced loss, preserved operations, and lower exposure. The article’s starting position is typical for organisations that have improved first-line identity controls but still struggle to express their value in business terms.
Key questions
Q: How should teams measure whether identity governance is actually reducing risk?
A: Track exposure, not just activity. The most useful indicators are privileged access coverage, orphaned identities, time to revoke access, and ownership completeness. If reporting only shows provisioning volume, audit completion, or incident counts, it may describe operational motion without revealing whether access is becoming safer.
Q: Why does identity now matter so much in detection and response programmes?
A: Identity is the control plane for most access decisions, so abuse often shows up first as unusual authentication, permission change, or delegation behaviour. If those signals are invisible or fragmented, attackers can move laterally or persist without triggering strong alerts. Identity governance and detection now depend on each other.
Q: What do security teams get wrong about blocked identity attacks?
A: They often count them as successful security outcomes without explaining the business loss that was prevented. A blocked attack is valuable, but its importance depends on how much access was stopped and how quickly. Mature reporting distinguishes between denial, containment, and full compromise.
Q: How should organisations communicate identity risk to business leaders?
A: Use dollars, downtime, and operational exposure rather than technical jargon. Business leaders respond to expected loss, recovery cost, and resilience impact. Security teams are more persuasive when they show how identity controls reduce the likelihood and cost of an incident instead of simply listing attacks blocked.
Technical breakdown
Why identity becomes the highest-volume attack surface
Identity becomes the preferred attack surface because it is the control point that connects credentials, authentication, privilege, and session access. Once attackers obtain a password, token, or approved session, they often bypass perimeter controls entirely and operate inside trusted workflows. Stronger controls such as SSO, MFA, and passkeys reduce simple password replay, but they do not remove the underlying governance problem: every identity still needs lifecycle ownership, access scoping, and revocation discipline across systems and service accounts.
Practical implication: map identity incident volume to the controls that actually change attacker reach, not just to login-block metrics.
How identity controls change the meaning of an incident
A blocked credential use can still be a security incident, but its business meaning is different from a successful account takeover. The key distinction is whether the attacker was stopped at authentication or allowed to progress into privilege use, lateral movement, or data access. That is why identity controls should be assessed as loss-limiting mechanisms. In NHI environments, the same logic applies to API keys, service accounts, and tokens, where one compromised secret can represent repeated access until it is rotated or revoked.
Practical implication: separate attempted compromise, denied access, and successful misuse in incident reporting and board metrics.
Translating identity risk into business language
Identity governance is easier to defend when it is expressed in likelihood, blast radius, and expected loss rather than in raw alert counts. Business leaders do not need every technical detail, but they do need to understand how identity controls affect the probability and cost of compromise. This is where quantitative threat reporting matters: incident mix, attack surface frequency, and control effectiveness give security teams a foundation for risk calculations that align with budget, prioritisation, and resilience decisions.
Practical implication: build reporting that links identity exposure to financial and operational impact, not just technical detection rates.
NHI Mgmt Group analysis
Identity governance is now a business risk function, not just an authentication function. When identity sits at the centre of incident volume, the security programme is really managing who or what can act with trust in the environment. That includes human users, service accounts, workload identities, and AI-linked credentials. The practical conclusion is that IAM and NHI governance must be assessed by their effect on exposure and loss, not by login metrics alone.
Blocked access should be measured as controlled loss reduction, not counted as a false sense of victory. The report’s core tension is that many teams still celebrate denial at the perimeter or identity layer without tying it to avoided business harm. That is understandable, but incomplete. A mature programme distinguishes between detection value and risk value, then uses both in executive reporting.
Identity exposure economics: the same credential event can be a minor control win or a major business incident depending on how quickly access is denied and whether privilege was already expanded. This matters for NHI estates where secrets often have broad reuse, and for human IAM where access paths are already federated. Practitioners should treat identity hardening as a way to compress attacker dwell time and lower expected loss.
AI and automation will widen the identity surface unless governance keeps pace. As more systems delegate actions to software agents and machine identities, the same access and control assumptions that apply to human users will be stress-tested at machine speed. That means identity governance, PAM, and lifecycle controls need to extend cleanly into non-human and agentic contexts. The practitioner conclusion is to plan for identity scale, not just identity count.
What this signals
Identity reporting is moving toward loss-based measurement, and that will force better alignment between SOC metrics, IAM governance, and board-level risk language. Teams that cannot show how identity controls reduce exposure will struggle to justify investment even when detection volumes fall.
Identity loss compression: the most valuable identity control outcome is not zero alerts, but a shorter window between compromise and containment. That is especially true for NHIs and federated access paths, where one secret or token can be reused across many systems before a human notices.
As identity expands into service accounts and AI-linked credentials, organisations should expect more pressure to prove ownership, revocation speed, and business impact. The strongest programmes will pair technical enforcement with risk translation, using resources like the Ultimate Guide to NHIs and the 52 NHI Breaches Analysis to anchor governance decisions.
For practitioners
- Measure identity incidents in business terms Track prevented compromise, successful misuse, expected loss, and recovery cost in the same reporting pack so leadership sees control value, not just alert volume.
- Separate denied access from confirmed compromise Classify identity events by stage reached, including blocked login, token abuse, privilege use, and downstream impact, so the SOC can report meaningful control effectiveness.
- Extend identity governance to NHIs and AI-linked credentials Apply the same ownership, revocation, and scoping discipline to service accounts, tokens, and agent credentials that you already expect for human accounts.
- Translate identity control wins into risk reduction Use incident frequency and access-loss assumptions to estimate avoided damage, then present those estimates in financial terms for board and budget discussions.
Key takeaways
- Identity is still the attack surface that most often turns an attempt into a meaningful incident, which makes governance and lifecycle control central to risk reduction.
- Blocked access only becomes a security success story when teams can show how much loss, exposure, or downtime was avoided.
- NHI and AI-linked credentials will make identity measurement harder, so programmes need reporting that connects control effectiveness to business impact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity-led incident volume maps to NHI exposure and lifecycle governance gaps. |
| NIST CSF 2.0 | PR.AC-1 | Identity compromise is fundamentally an access control and verification problem. |
| NIST SP 800-53 Rev 5 | IA-5 | Secret and authenticator management are central to identity abuse prevention. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0004 , Privilege Escalation | Identity incidents often start with credential access and move into privilege abuse. |
Strengthen identity assurance and access enforcement where incident volume is highest.
Key terms
- Identity Attack Surface: Identity attack surface is the total set of accounts, tokens, login endpoints, trust paths, and supporting systems that can be probed for access. For password spraying, the risk grows with every externally reachable authentication path and every dormant or weakly protected identity.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Risk Translation Layer: A risk translation layer is the process or system that converts technical cyber signals into business-relevant impact statements. In GRC programmes, it links posture data to loss, interruption or regulatory categories so that leadership can make decisions in the same language as the risk register.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
What's in the full report
Expel's full report covers the incident mix, control context, and risk framing this post intentionally leaves at a higher level:
- How Expel broke down incident volume by attack surface and why identity led the list
- The report's quantitative framing for translating control wins into business risk
- Operational context around SSO, MFA, and passkeys in reducing identity abuse
- The report's broader incident categories that can support likelihood calculations
👉 The full Expel report adds the incident metrics and business framing behind the identity findings.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and workload identity. It helps identity and security practitioners build controls that align access management with operational risk.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org