By NHI Mgmt Group Editorial TeamBased on RSA Security: “UK Reports Worse Data Breaches and Greater Concern for IT Help Desk Risk: RSA ID IQ Report Unveils Top Identity Threats” (December 10, 2025)

TL;DR: 69% of global organisations experienced an identity-related breach in the last three years, while 65% are seriously concerned about service desk bypass attacks and 90% report challenges moving toward passwordless authentication, according to RSA Security’s 2026 ID IQ Report. The data shows identity programmes are still failing at the points where trust, recovery, and human workflow intersect.


At a glance

What this is: RSA Security’s 2026 ID IQ Report shows identity breaches, help desk bypass concern, and passwordless friction are all rising together.

Why it matters: IAM, PAM, and workforce identity teams need to treat recovery workflows and social engineering resistance as core control surfaces, not support functions.

By the numbers:

  • 69% of global organisations experienced an identity-related breach in the last three years.
  • 65% of organisations are seriously concerned about a similar attack.
  • 90% of organisations globally reported challenges in moving toward passwordless authentication.
  • 24% of organisations said identity-related breach costs exceeded $10M.

Context

Identity breaches are no longer just an authentication problem. They now expose a governance gap where recovery paths, help desk processes, and user authentication choices can be turned into the easiest route past formal IAM controls.

RSA Security’s 2026 ID IQ Report argues that this gap is widening at the same time as organisations try to modernise authentication. The article also shows a strong UK-specific concern profile, which suggests the control weakness is operational, not merely theoretical.

For identity programmes, the real issue is that the control plane and the human support plane are still too loosely connected. When service desk workflows can be socially engineered, the organisation may have strong policy on paper and weak enforcement at the moment trust is re-established.


Key questions

Q: What breaks when help desk recovery can override identity assurance?

A: When support staff can reset access without strong verification, the help desk becomes an attack path rather than a safeguard. Attackers use social engineering to turn recovery workflows into account takeover. That failure usually appears first in the exception process, then in privileged access, and finally in downstream data exposure.

Q: Why do service desk bypass attacks create such high breach risk?

A: Because the support channel often sits close to the authority needed to restore trust. If an attacker can impersonate a legitimate user, they may obtain a reset, MFA rebind, or other recovery action that bypasses the front-door controls entirely. That makes the support process a higher-value target than many login screens.

Q: How do organisations know whether passwordless access is actually improving security?

A: Look for reduced password dependence, fewer lockouts, lower help desk reset volume, and stronger control over high-risk workflows such as shared workstation access and privileged clinical systems. If user friction drops while identity assurance rises, the programme is moving in the right direction.

Q: Which identity workflows need the strongest governance after a help desk breach?

A: The highest priority workflows are account recovery, privileged reset, MFA re-enrolment, and any process that can restore trust after a lost device or suspected compromise. Those are the moments when identity assurance is re-established, so they need the strictest verification, approvals, and logging. Weakness there turns a support event into an enterprise incident.


Technical breakdown

Service desk bypass as an identity control failure

Service desk bypass attacks succeed when an attacker does not need to defeat the primary authentication flow and can instead persuade a support process to reset, rebind, or recover access. That makes the help desk part of the identity attack surface, not just a service channel. In practice, the weakness is often weak verification, inconsistent scripts, and excessive discretion in recovery workflows. Once a recovery path can override stronger controls, the attacker is targeting the exception path rather than the normal login path.

Practical implication: treat account recovery and support verification as enforceable identity controls, not customer service procedures.

Why passwordless stalls in mixed-authentication estates

Passwordless adoption often slows because organisations run mixed estates where some users, devices, and applications still depend on passwords, legacy federation, or manual fallback. That creates a transition problem: the authentication model is only as strong as the weakest remaining path into the account. If users routinely fall back to passwords, passwordless becomes an optional convenience layer rather than the primary trust mechanism. The article’s data suggests the transition burden is organisational, not just technical.

Practical implication: map every fallback path before declaring passwordless adoption complete.

Identity breach economics and the cost of weak recovery

Identity-related breaches become more expensive when attackers can move from account access to support escalation and then to wider environment control. In those cases, the breach is no longer confined to a single credential event. It becomes a process failure that expands into downtime, incident response effort, and potentially broader compromise across connected systems. The article’s cost figures show that identity failures now carry board-level financial consequences, not just security metrics.

Practical implication: measure recovery-path risk alongside login risk when prioritising IAM investment.


Threat narrative

Attacker objective: The attacker wants to convert help desk trust into usable account control, then use that access for theft, disruption, or wider environment compromise.

  1. Entry begins with social engineering or bypass of the IT help desk rather than a direct password attack, giving the adversary a trusted route into account recovery.
  2. Credential access follows when the support process resets or rebinds an account, or otherwise grants access that the attacker could not obtain through the primary login flow.
  3. Escalation occurs when that recovered identity has enough reach to access administrative or high-value systems, turning one manipulated interaction into broader compromise.
  4. Impact is achieved through data theft, service disruption, or ransomware-style damage once the attacker has used the recovered access to operate as a legitimate user or admin.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.
  • Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Help desk trust is now an identity control plane, not a back-office function: The article shows that recovery and support workflows can override stronger authentication when they are socially engineered. That means the security boundary is not the login form alone, but the process that can reissue trust after failure. Practitioners should stop treating service desk security as separate from IAM governance.

Passwordless adoption is constrained by fallback governance, not user preference alone: The report’s passwordless findings point to a structural problem in mixed-authentication estates. If passwords remain available in routine recovery or device-change scenarios, the programme still depends on them as a safety valve. Identity teams should read passwordless progress as a whole-path design issue, not a front-end feature gap.

Identity breach cost is a control-quality signal, not just an incident metric: When 24% of organisations report costs above $10M, the issue is no longer limited to compromised accounts. It reflects how fast support, authentication, and response processes allow a breach to spread. That makes process integrity part of the economic control surface, which is where board attention belongs.

Human workflow remains the most exploitable trust layer in IAM: Technical controls can still be bypassed when a person is induced to approve, reset, or escalate access. The article reinforces a recurring pattern: the hardest identity problems are often not cryptographic, they are procedural. Security leaders should evaluate where human discretion can still substitute for policy enforcement.

Identity breach frequency is now high enough to force programme redesign: The jump to 69% of organisations reporting identity-related breaches suggests this is no longer an edge case. The category has moved from isolated compromise to a repeatable attack path that targets trust re-establishment. Practitioners should respond by redesigning governance around recovery, not just authentication.

From our research library:

What this signals

Help desk trust is becoming a primary attack surface: The article shows why support workflows have to be governed like privileged processes. If a support agent can reset trust with insufficient assurance, the organisation has built an alternate path around IAM, not a backstop for it. That is why account recovery belongs in the same risk conversation as privileged access and authentication policy.

Passwordless programmes fail when fallback paths remain easy to invoke: Mixed estates create hidden dependencies that keep passwords alive even after formal adoption. The practical question is not whether users can sign in without passwords in the best case, but whether the organisation has removed the recovery and exception paths that keep passwords operational in the worst case.

Identity breach economics expose control maturity: The report’s 24% figure for breaches exceeding $10M shows that identity failures now have direct financial consequences. That should push practitioners to prioritise recovery-path controls and support verification as part of loss reduction, not just user experience or IT operations.


For practitioners

  • Harden account recovery verification Require step-up verification, callback controls, and restricted support scripts for any reset or rebind action that changes account trust.
  • Remove password fallback from priority journeys Eliminate routine password fallback where passwordless is already deployed, and inventory every remaining path that can silently re-enable passwords.
  • Separate support discretion from access administration Limit who can approve identity changes, and ensure service desk staff cannot independently override policy for privileged accounts.
  • Review privileged recovery paths for every high-value role Map which admin, finance, and executive accounts can still be recovered through help desk workflows, then tighten those paths first.

Key takeaways

  • Identity breaches are rising because attackers are finding the trust gaps between primary authentication and recovery workflows.
  • The scale of the problem is material, with 69% breach exposure reported and 24% of organisations seeing breach costs above $10M.
  • The control point that matters most is the support and recovery path, where stronger identity controls are still being bypassed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationHelp desk bypass and passwordless friction both point to weak assurance in identity verification flows.
Recommendation — Strengthen authentication assurance in recovery and fallback flows before trust is restored.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPasswordless adoption and recovery workflows are authenticator lifecycle problems, not just UX issues.
Recommendation — Govern issuance, reset, and retirement of authenticators across every access journey.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about restoring and controlling access through support processes.
Recommendation — Tie access restoration to explicit authorisation checks and review restored entitlements quickly.
CIS Controls v8CIS-5 — Account ManagementThe report centres on account recovery, privileged resets, and support-driven account changes.
Recommendation — Centralise account lifecycle controls and review every support-initiated change to user access.
MITRE ATT&CKTA0001;TA0006;TA0040 — Initial Access; Credential Access; ImpactThe report describes social engineering into help desks leading to account takeover and damage.
Recommendation — Map support-bypass incidents to TA0001, TA0006, and TA0040 to improve detection and response playbooks.

Key terms

  • Service Desk Bypass: A social engineering path that convinces support staff or recovery workflows to reissue access without the legitimate user proving control under the same conditions as normal login. It is dangerous because the recovery channel often inherits authority from the identity system it is meant to repair.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Account Recovery: Account recovery is the process used to restore access when a user cannot authenticate normally. In mature IAM programmes, recovery is treated as part of the trust chain because a weak reset path can bypass stronger login controls and become the easiest route to account takeover.
  • Identity-Related Breach: An identity-related breach is an incident where stolen, abused, or over-permissioned identities are the main path to compromise. These events often bypass traditional perimeter defenses because the attacker is not breaking in technically, but logging in with a credential that the system still trusts.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org