TL;DR: Identity now sits at the center of enterprise attack paths, with Arcon arguing that fragmented stacks, standing privilege, machine identity sprawl, and cloud entitlement complexity will make old perimeter assumptions increasingly brittle. The practical shift is toward continuous, policy-driven governance where access, telemetry, and privilege control operate as one system.
At a glance
What this is: This is Arcon’s 2026 identity security outlook, and its core claim is that identity has become the primary security perimeter as cloud entitlements, machine identities, and privilege misuse expand.
Why it matters: It matters because IAM, PAM, NHI, and security operations teams now have to govern access as a live control plane, not a periodic review exercise.
By the numbers:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
👉 Read Arcon's 2026 identity security outlook
Context
Identity security is no longer confined to login, password, and MFA controls. In modern enterprises, the real perimeter is the set of human and non-human identities that can reach systems, move privileges, and persist across cloud, SaaS, and third-party environments. Arcon’s 2026 outlook argues that identity has become the control layer through which most serious compromise paths now run.
That matters for IAM because the governance problem is no longer limited to who signs in. It now includes service accounts, bots, pipelines, workloads, tokens, and privileged sessions that can outlive the business context that created them. When temporary access becomes permanent exposure, the identity programme has shifted from administration to risk containment.
Ultimate Guide to NHIs remains the clearest baseline for that governance model, especially where secrets, rotation, and lifecycle enforcement intersect with Zero Trust expectations.
Key questions
Q: What breaks when identity governance relies only on access reviews?
A: Access reviews assume the reviewable state is a stable entitlement that reflects real risk. In fast-moving cloud and agentic environments, the risky state may have already changed by the time the review runs. Teams then certify a snapshot instead of governing the behaviour that creates exposure.
Q: Why do non-human identities complicate zero trust architecture?
A: Because zero trust assumes access can be verified continuously, yet many machine identities are created for automation, reused widely, and left in place long after their original purpose ends. The result is standing trust hidden inside infrastructure. Teams need continuous verification plus lifecycle enforcement to make zero trust real for machines.
Q: How do security teams know whether JIT access is actually reducing risk?
A: Look for shorter credential lifetime, fewer always-on permissions, and lower exposure of credentials in code, pipelines, and runtime environments. If the same identities remain broadly reachable or access still persists between tasks, JIT is only changing the workflow, not the risk model.
Q: Who is accountable when privileged access controls fail in cloud environments?
A: Accountability usually sits with the identity, platform, and cloud operations teams together, because the failure spans authentication, role design, and secret handling. Governance frameworks such as the NIST Cybersecurity Framework 2.0 expect control ownership to be explicit. If no team owns the full path from grant to revocation, the gap persists.
Technical breakdown
Why identity fabrics are replacing fragmented IAM stacks
A fragmented identity stack separates authentication, PAM, governance, analytics, and cloud entitlement management into disconnected tools. That creates gaps between control points, even when each product works as designed. An identity fabric is the attempt to unify identity telemetry, authorization logic, privilege controls, and risk decisions so that access can be evaluated continuously rather than in isolated systems. The architectural shift is less about consolidation for its own sake and more about removing blind spots between identity layers.
Practical implication: map where identity decisions are split across tools, then prioritise the control seams that create ungoverned access paths.
Just-in-time access and the collapse of standing privilege
Standing privilege persists because organisations treat access as a role attribute rather than a time-bound condition. JIT access changes the model by issuing elevated rights only for the task window, then revoking them automatically. The technical value is not just shorter duration, but reduced attack surface, better session accountability, and less residual access after the work is complete. In cloud and third-party contexts, the problem is often not obtaining access but ensuring it disappears when the business need ends.
Practical implication: identify privileged accounts and third-party permissions that remain active outside task windows, then convert the highest-risk ones to task-scoped elevation.
Identity threat detection and response needs telemetry, not assumptions
ITDR works by correlating identity events such as privilege escalation, entitlement change, token abuse, lateral movement, and session hijacking. Unlike policy engines, it looks for deviations from expected identity behaviour after access has already been granted. That makes identity telemetry a detection layer for abuse that endpoint tools may miss, especially when attackers use valid credentials. The technical requirement is reliable logging across authentication, authorization, and session activity so that suspicious identity behaviour can trigger containment.
Practical implication: ensure identity logs are centralised with session data so abnormal privilege behaviour can be detected and contained quickly.
Threat narrative
Attacker objective: The objective is to turn legitimate identity access into durable control over critical systems without triggering traditional perimeter defenses.
- Entry begins when attackers gain access through credential abuse, token theft, or third-party access that appears legitimate to the receiving system.
- Escalation follows when those identities hold excessive permissions or standing privilege, allowing privilege escalation, lateral movement, and persistent access inside cloud and SaaS environments.
- Impact arrives when the attacker uses that identity foothold to reach critical systems, manipulate data, or maintain stealthy persistence that bypasses perimeter controls.
Breaches seen in the wild
- JetBrains Marketplace AI Plugin Campaign — 15 malicious JetBrains Marketplace plugins steal AI API keys from 70,000+ developers via supply chain attack.
- Code Formatting Tools Credential Leaks — Widely used code formatting tools cause massive credential and secrets leaks in enterprise environments.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity has become the security perimeter because the old perimeter no longer contains the attack path. The article is right to treat identity as the control plane that now mediates access to cloud, SaaS, and critical systems. Once attackers can move through legitimate credentials, the distinction between network boundary and identity boundary collapses. Practitioners should treat identity governance as the primary enforcement layer, not a supporting control.
Standing privilege is the structural weakness that makes identity compromise durable. Persistent administrative access, long-lived credentials, and temporary third-party permissions that never expire all create an unnecessary exposure window. This is not just over-permissioning; it is access that outlives its business purpose. The practitioner conclusion is simple: any privilege that remains active after the task has finished is an avoidable governance failure.
Machine identity governance is now the decisive NHI challenge, not an edge case. Service accounts, workloads, tokens, and pipeline identities now scale faster than human governance processes can absorb. Ultimate Guide to NHIs shows why lifecycle, rotation, and visibility controls must be applied to these identities with the same seriousness as privileged human access. The implication is that NHI governance can no longer be treated as a niche control domain.
Continuous entitlement intelligence is becoming the real measure of IAM maturity. Quarterly reviews and periodic snapshots are too slow for environments where entitlements shift across cloud and SaaS in real time. The key concept here is entitlement drift: access that becomes riskier as context changes, even if the role definition remains the same. Practitioners should judge maturity by how fast they can detect and correct drift, not by how many reviews they complete.
Session visibility is now a board-level requirement for privileged work. The article captures an important shift from policy claims to evidence of control. Full-session recording, command-level logging, and tamper-resistant audit trails turn privileged activity into something accountable after the fact. For IAM and PAM teams, that means operational control and audit assurance are converging into the same control requirement.
From our research:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- That gap makes lifecycle governance the forward path, especially when paired with the 52 NHI Breaches Analysis and the OWASP Non-Human Identity Top 10.
What this signals
Identity perimeter thinking will now shape procurement and governance together. Security teams will increasingly evaluate IAM, PAM, and NHI controls as one operational stack rather than separate programmes. That shift matters because the same entitlement drift that weakens cloud governance also weakens privileged access oversight, which means programme owners need a shared control model and shared telemetry.
Entitlement drift is the named risk to watch. Once access is treated as a live condition, not a static role, teams can start measuring how quickly permissions exceed business need. With 96% of organisations storing secrets outside secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs, the operational problem is already beyond simple credential hygiene.
Cloud and SaaS governance will keep moving toward continuous assurance, and that will force identity teams to align with the NIST SP 800-207 Zero Trust Architecture model more directly. The next practical step is to connect entitlement analytics, session visibility, and lifecycle controls so reviewers can see risk as it develops, not after the quarter ends.
For practitioners
- Inventory identity sprawl across all actor types Build a single inventory of human users, service accounts, workload identities, API keys, tokens, and privileged third-party access. Separate active, dormant, and orphaned identities so you can see where governance is already failing.
- Convert standing privilege into task-scoped elevation Prioritise administrative accounts and third-party access paths that remain active outside a defined business task. Use just-in-time elevation with automatic revocation and session visibility for the highest-risk access paths.
- Centralise identity telemetry for detection and response Correlate authentication, entitlement changes, token use, and session behaviour in the same monitoring workflow. Identity misuse is easier to contain when anomalous privilege movement is visible as a sequence, not as isolated alerts.
- Apply lifecycle controls to non-human access first Focus offboarding, rotation, and recertification on service accounts, API keys, and pipeline credentials that can persist after teams forget they exist. Treat expired business need as a revocation trigger, not a documentation issue.
- Measure cloud entitlement drift continuously Track how often permissions exceed actual workload need across multi-cloud and SaaS estates. Use the drift signal to drive recertification, privilege reduction, and risk scoring instead of relying on quarterly access reviews.
Key takeaways
- Identity is now the enterprise perimeter, which makes governance, telemetry, and privilege control inseparable.
- Standing privilege and machine identity sprawl are the two structural problems that keep turning identity into an attack path.
- The control model is moving from periodic review to continuous entitlement intelligence, and teams that do not adapt will keep documenting risk instead of reducing it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Standing secrets and lifecycle gaps are central to the article's NHI risk model. |
| NIST Zero Trust (SP 800-207) | 3.2 | The post frames identity as the perimeter, which is core Zero Trust territory. |
| NIST CSF 2.0 | PR.AC-4 | The article focuses on continuous access governance and least privilege. |
| NIST SP 800-53 Rev 5 | IA-5 | Credential lifecycle and authenticator management are central to the article's NHI concerns. |
| CIS Controls v8 | CIS-5 , Account Management | Account and privileged access management are the article's main operational themes. |
Use CIS-5 to inventory, review, and retire dormant accounts and non-human credentials on a fixed cadence.
Key terms
- Identity Fabric: An identity fabric is a connected control model that shares context across governance, privileged access, and access management. It is not a product category. The aim is to make identity decisions coherent across the full lifecycle so ownership, privilege, and enforcement reinforce each other.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
- Identity Threat Detection and Response: Identity threat detection and response is the practice of finding misuse of credentials, unusual access patterns, and compromised identities across human and machine actors. For NHIs, it relies on telemetry from code, vaults, cloud services, and pipelines to detect abuse early enough to contain it.
What's in the full article
Arcon's full outlook covers the operational detail this post intentionally leaves for the source:
- The full 2026 prediction set behind each identity trend, including converged platforms, JIT, ITDR, machine identities, and continuous entitlement intelligence.
- The source article's own breakdown of how identity telemetry, privilege elevation, and session oversight fit together in day-to-day operations.
- Additional context on the practical shift from periodic compliance to continuous control.
- The article's closing summary of how identity becomes a structural security foundation rather than a supporting function.
Deepen your knowledge
NHI governance, machine identity security, secrets management, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM, PAM, or NHI programme, it is worth exploring.
Published by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org