By NHI Mgmt Group Editorial TeamBased on Axiad: “A Wave of Identity Security Reports Defines a Big Problem” (September 16, 2025)

TL;DR: Identity security reports show 97% of organisations are challenged by identity verification, only 45% use MFA, and 93% reported two or more identity-related breaches in the last year, according to Axiad. The pattern is clear: identity risk is now a core security problem, not an operational side issue.


At a glance

What this is: This is a commentary on multiple identity risk reports that converge on the same finding: identity verification, MFA adoption, NHI privilege, and breach frequency are all showing persistent weakness.

Why it matters: It matters because identity governance now spans human users and NHIs, and weak verification plus overprivileged access creates a breach path that IAM, IGA, and PAM teams have to treat as a core security issue.

By the numbers:

  • 97% of organizations are challenged by identity verification, according to Axiad.
  • Only 45% are using multifactor authentication to verify the identity of users, according to Axiad.
  • 93% of organizations had two or more identity-related breaches in the last year, according to Axiad.

Context

Identity risk is the widening gap between who or what is allowed to access systems and how confidently that identity can be verified at runtime. In this article, Axiad pulls together several recent reports to show that the gap is no longer theoretical: both human identity controls and non-human identity governance are failing at the same time.

The article's core message is that identity can no longer be treated as an operational convenience layer. For IAM, IGA, and PAM teams, the question is not whether identity touches security, but whether identity controls are being governed as a primary attack surface across users, workloads, and third parties.


Key questions

Q: What breaks when identity verification is weak in non-face-to-face business relations?

A: Weak verification allows higher fraud risk, poor customer risk classification, and inconsistent due diligence. In practice, that can lead to accounts being opened for the wrong person, inadequate screening, and greater exposure during audits or investigations. The control failure is not just operational. It also creates regulatory and reputational risk when firms cannot demonstrate proper customer identification.

Q: Why do overprivileged NHIs create more breach risk than limited ones?

A: Overprivileged NHIs enlarge the attack path because every additional permission becomes an option for escalation or data access. In cloud and CI/CD environments, that means one stolen token can reach far beyond the original job. Narrow scope and short duration reduce both the attacker’s choices and the time available to exploit them.

Q: What are the signs that identity governance is not working in practice?

A: Common warning signs are repeated access workarounds, ignored approval workflows, super admins holding too much power, and teams bypassing the process because it is too slow or hard to use. If access reviews are always behind, permissions stay stale, and IT has to chase owners for answers, governance is operating more as paperwork than control.

Q: Who should own identity discovery when IAM, PAM, and NHI teams overlap?

A: Ownership should sit with the team that can unify identity data and drive remediation across domains, usually under identity security or IGA leadership. IAM, PAM, and NHI specialists all contribute, but discovery fails when each team only governs its own tooling instead of one common identity plane.


Technical breakdown

Why identity verification breaks down in practice

Identity verification fails when organisations rely on weak, inconsistent, or overly convenient authentication methods that do not prove the claimant is the right actor. The article points to MFA adoption gaps and notes that some MFA is not phishing resistant, which means the mechanism may still be bypassed through credential capture or social engineering. For human identity programmes, this is not just about adding a second factor. It is about whether the proofing and authentication path meaningfully resists identity-based attack techniques.

Practical implication: verify whether your authentication stack is phishing resistant, not merely whether MFA is enabled.

How overprivileged NHIs expand the attack surface

Non-human identities often accumulate permissions that outlive the task they were created for, which creates standing access that attackers can abuse once credentials or tokens are exposed. The article cites a report showing 97% of NHIs have excessive privileges and 92% are exposed to third parties, which is a classic governance failure in lifecycle control, third-party access, and entitlement scoping. In NHI terms, the issue is not only the secret itself, but the amount of access the secret unlocks.

Practical implication: review NHI entitlement scope and third-party exposure together, not as separate controls.

Why identity breach volume keeps climbing

When identity becomes the easiest path into environments, breach volume rises because attackers can move through valid access rather than noisy exploitation. The article cites a report showing 93% of organizations had two or more identity-related breaches in the last year, while identity counts are expected to rise 3x in the next year. That combination suggests the control plane is scaling more slowly than the identity estate, which makes governance, detection, and recertification increasingly hard to keep aligned.

Practical implication: design identity controls for scale growth, or breach frequency will outpace manual governance cycles.


  • Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity verification has become a security control failure, not an authentication preference. The article's synthesis shows that 97% of organisations are challenged by identity verification, while only 45% use MFA. That gap tells us many programmes are still optimised for access convenience rather than assurance, and phishing-resistant authentication remains the dividing line between symbolic control and meaningful control. Practitioners should treat identity verification as a frontline defence requirement, not a user experience trade-off.

Overprivileged NHIs create identity attack surface that most governance models still undercount. The report cited by Axiad says 97% of NHIs have excessive privileges and 92% are exposed to third parties. That combination means machine identity risk is not confined to secret storage, because the blast radius is defined by what the identity can reach once it is used. The practitioner takeaway is to govern NHI privilege as an exposure problem, not just a credential problem.

Identity-related breaches are now evidence of governance debt accumulating faster than programme maturity. When 93% of organizations report two or more identity-related breaches and identity counts are expected to grow 3x, the issue is no longer isolated misconfiguration. It shows that identity programmes are being asked to scale across more subjects, more third-party paths, and more verification points than their current operating model can absorb. Security leaders should treat identity governance as a core resilience function.

Identity risk is now a cross-domain issue spanning human IAM, NHI governance, and third-party trust. The article usefully brings together employee credential reuse, MFA weakness, overprivileged machines, and breach frequency into one picture. That is the right lens because attackers do not respect internal programme boundaries. Practitioners should align IAM, PAM, and NHI governance around one shared risk model instead of separate control silos.

Identity security needs a named concept: verification debt. This is the accumulated gap between the identities an organisation has created and the confidence it can still have in proving they are legitimate at runtime. The more complex the environment becomes, the more that debt compounds across humans, machines, and third parties. Teams should measure and reduce verification debt before it turns into repeated breach exposure.

What this signals

Verification debt is the right lens for this moment. Organisations are not dealing with a single control gap so much as an accumulating mismatch between identity growth and identity assurance. As the identity estate expands, the decisive question becomes whether the programme can still prove who or what is accessing the environment at the point of use, not just at onboarding.

A strong IAM posture now depends on treating humans, NHIs, and third parties as one identity continuum. That means authentication strength, entitlement scope, and offboarding discipline have to be measured together, because attackers will always choose the weakest governance boundary rather than the neatest organisational one.


For practitioners

  • Strengthen phishing-resistant verification Replace weak or easily bypassed MFA paths for high-risk user access, especially where phishing and credential replay are realistic threats. Prioritise privileged and remote access first, because those identities are the most valuable entry points.
  • Review NHI privilege scope Inventory service accounts, tokens, and other NHIs, then remove permissions that are not required for the current task or relationship. Separate third-party exposures from internally owned workloads so that shared access paths do not hide excess privilege.
  • Treat identity as a breach surface Bring identity-related incidents into the same governance review cadence as endpoint and cloud incidents, with explicit ownership for remediation tracking. Use breach trends to challenge whether current identity controls are actually reducing attack paths.
  • Align IAM, PAM, and NHI governance Create a single risk view for user identities, privileged access, and machine identities so that access reviews, offboarding, and exception handling are judged against the same risk model. This avoids fragmented control decisions across separate teams.

Key takeaways

  • Identity security remains a governance problem because verification, privilege scope, and breach frequency are all deteriorating at once.
  • The report data points to a broad control gap across human and non-human identities, not a single product or team failure.
  • Programmes that do not treat identity as a primary attack surface will keep absorbing breach risk faster than they can reduce it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article explicitly cites excessive NHI privilege as a core identity risk.
NHI-03 — Vulnerable Third-Party NHIThe article highlights third-party exposure as a major driver of machine identity risk.
Recommendation — Review NHI entitlements against current task scope and remove standing access that exceeds need. Map third-party NHI access paths and revoke any relationship-linked credentials that outlive the vendor need.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article discusses MFA adoption and identity verification weaknesses that fall under authenticator governance.
Recommendation — Use authenticator management to enforce stronger verification and retire weak or non-phishing-resistant factors.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on verification and entitlement failures across users and NHIs.
Recommendation — Align access permissions and entitlements with current identity risk rather than inherited access history.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article's risks map to credential abuse and expanded access after identity compromise.
Recommendation — Map identity control gaps to credential access and lateral movement paths during detection planning.

Key terms

  • Identity verification: Identity verification is the process of confirming that a user, workload, or agent is the entity it claims to be before access is granted. In AI-heavy environments, that verification must include the requester, the system acting on its behalf, and the sensitivity of the action.
  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Overprivileged Nhi: An overprivileged NHI is a service account, token, key, or other machine identity that has been granted more access than it needs to do its job. The risk is not theoretical. Excess scope increases blast radius, makes compromise more valuable to attackers, and slows containment when the identity is abused.
  • Verification debt: The accumulated gap between the identities an organisation manages and the confidence it can still have in validating them at the moment of access. It grows when verification, entitlement review, and offboarding do not keep pace with identity sprawl.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org