TL;DR: Identity compromise drives a large share of breaches, with stolen credentials cited in 86% of incidents and compromised identities as the first step in 80%, according to Zluri’s article. That makes identity security a governance problem, not just an authentication problem, because access scope, rotation, and monitoring determine how far an attacker can move.
At a glance
What this is: This is a Zluri explainer arguing that identity security is a governance problem, with least privilege failing when access scope, rotation, and monitoring are weak.
Why it matters: It matters because IAM teams now have to govern humans, third parties, and NHIs as one access surface, or attackers will keep using identity compromise as the easiest path to breach expansion.
By the numbers:
- Stolen credentials cause 86% of breaches, according to Zluri.
Context
Identity security is the discipline of controlling who or what can access systems and data, then proving that access stays within policy over time. In Zluri's framing, least privilege fails when identity scope is broad, authentication is weak, and access is not continuously reviewed.
The article treats identity compromise as a governance failure, not only an authentication issue. That is the right lens for IAM teams because the same access model now spans employees, vendors, service accounts, and machine identities, all of which can become breach entry points when lifecycle and monitoring controls are inconsistent.
Key questions
Q: Why does least privilege still fail in real IAM programmes?
A: Least privilege fails when access is granted more broadly than the work requires, then left in place after the need changes. The problem is usually not the principle but the lifecycle around it, including poor scoping, weak review, and no effective removal of stale permissions.
Q: Why do compromised credentials remain so effective in modern environments?
A: Compromised credentials remain effective because they produce legitimate-looking access. Many environments still trust the identity after the password, token, or session is accepted, even if the login originated from a risky device or abnormal context. That makes identity confidence a live security issue, especially when access is broad or long-lived.
Q: What breaks when service accounts are not centrally governed?
A: When service accounts are created and maintained outside a central identity process, ownership, purpose, and retirement become unclear. That creates hidden credentials, weak accountability, and access that outlives the workload it was meant to support. The result is not just inventory drift, but a persistent governance gap that IAM and PAM teams cannot close with human identity controls alone.
Q: How should security teams prioritise identity work when NHIs outnumber humans at scale?
A: Start with identities that can reach sensitive systems, inherit privilege, or create lateral movement potential. Inventory is only the first step. Prioritisation should focus on blast radius, revocation difficulty, and how much trust a given identity can accumulate across cloud, SaaS, and AI workflows.
Technical breakdown
Why least privilege breaks down when identities are over-scoped
Least privilege only works when the requested access closely matches the role, task, and duration of use. In practice, access models often drift because entitlements are assigned for convenience, inherited through broad roles, or left in place after the original need has passed. That creates a wider blast radius even when authentication is strong. The problem is not the idea of least privilege itself, but the gap between intended scope and actual entitlements across users, third parties, service accounts, and machine identities.
Practical implication: review entitlement scope and remove standing access that no longer maps to a current business need.
How weak authentication becomes an access-control failure
Authentication answers who or what is presenting the credential, but it does not by itself prove that the resulting access is safe. Password-only access, stale credentials, and weak verification all increase the chance that a valid identity is being used by the wrong actor. Once that happens, authorization controls may still look correct on paper while the credential itself has already been compromised. Identity security therefore has to join authentication strength with credential lifecycle control and access review, not treat them as separate workstreams.
Practical implication: strengthen authentication and credential hygiene together so a valid login cannot automatically translate into trusted access.
Why service accounts and machine identities need the same governance discipline
Service accounts and machine identities are non-human identities that often hold elevated privileges so systems can run, sync, or automate tasks. That makes them attractive to attackers because they can be persistent, less visible than user accounts, and harder to review manually. Zluri's article reflects a broader reality: identity security is no longer just about human login events. If NHIs are not inventoried, bounded, rotated, and monitored, they create silent access paths that bypass the intent of least privilege.
Threat narrative
Attacker objective: The attacker aims to turn one compromised identity into broader access to sensitive data and higher-value systems.
- Entry occurs when an attacker obtains valid credentials or otherwise compromises an identity, turning trusted access into the initial foothold.
- Escalation follows when that identity has broader permissions than the task requires, allowing the attacker to move from one account or system to additional resources.
- Impact comes when the attacker uses that trust to reach sensitive data, control higher-value access, or expand the breach beyond the original account.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Least privilege is an entitlement design problem, not a slogan: The article correctly shows that access becomes risky when identities receive more scope than their job actually requires. That is true for employees, vendors, service accounts, and machine identities alike. The practitioner takeaway is that privilege has to be governed as a living entitlement state, not a one-time provisioning decision.
Identity compromise is now a governance failure that spans human and non-human access: Zluri's framing reflects the modern access surface, where a single credential issue can compromise a user, a third party, or a workload. That is why identity security cannot be separated from lifecycle control, review cadence, and privileged access oversight. Teams need one governance model that covers all three identity classes.
Standing access is the real weakness behind most least-privilege failures: The article points to continuous monitoring and access drift, which are the symptoms of access that outlives its purpose. That is the governing assumption that breaks most often: that access granted at the start of work remains appropriate until the next review. Practitioners should treat unused and over-broad access as a programme defect, not an isolated exception.
Non-human identities expose the limits of user-centric IAM thinking: Service accounts and machine identities are not side cases; they are part of the core identity estate. If those identities are not governed with the same discipline as human accounts, least privilege becomes incomplete by design. The field now has to treat NHI lifecycle management as a first-class security control, not an operational afterthought.
What this signals
Identity security only works when privilege is treated as a lifecycle condition: Teams need to see access as something that changes, expires, and must be revalidated across joiner, mover, and leaver events. That applies to employees and contractors, but it matters just as much for service accounts and machine identities that can otherwise keep access long after their business purpose has ended.
Least privilege fails fastest where identity governance stops at the human user: The article's core lesson is that broad access is not only a permissions problem, it is a programme design problem. If NHIs are outside the same review, ownership, and monitoring model as human identities, the control framework is incomplete before an attacker ever arrives.
For practitioners
- Map the full identity estate Inventory human users, third-party accounts, service accounts, and machine identities in one view so entitlement gaps are visible across the whole access surface.
- Tighten role scope before adding more controls Review roles and access packages for over-broad permissions, inherited access, and stale entitlements that exceed current job or workload requirements.
- Bring non-human identities into recertification Include service accounts, automation credentials, and machine identities in access reviews so privileged access does not escape governance simply because it is non-human.
- Harden credential lifecycle management Rotate or revoke exposed credentials, shorten standing access windows, and tie authenticator renewal to ownership and task need rather than convenience.
- Monitor access drift continuously Track permission growth, dormant accounts, and unusual use patterns so identity security moves from periodic audit to ongoing control.
Key takeaways
- Identity compromise remains a primary breach path because valid credentials can bypass normal controls and expose broader entitlements.
- The article points to a familiar governance pattern: over-scoped access, weak authentication, and poor monitoring turn least privilege into theory rather than practice.
- The control that changes outcomes is not a single tool, but disciplined identity governance across lifecycle, scope, and review for humans and NHIs alike.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article repeatedly links breach risk to access that exceeds role need, including service and machine identities. |
| NHI-07 — Long-Lived Secrets | It discusses credential compromise, rotation, and persistent access paths that outlive the original purpose. | |
| Recommendation — Audit non-human entitlements for excess privilege and remove access that exceeds the current task. Shorten secret lifetime and tie renewal to ownership, task need, and revocation events. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential rotation and management are central to the article's access-control argument. |
| Recommendation — Apply authenticator lifecycle controls to rotate, revoke, and replace exposed credentials promptly. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about entitlement scope and whether access matches legitimate need. |
| Recommendation — Continuously verify that access permissions and entitlements match business need and role scope. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes credential compromise leading to broader access and movement through systems. |
| Recommendation — Map credential compromise to TA0006 and hunt for subsequent lateral movement from the same identity. | ||
Key terms
- Least Privilege: A security principle requiring that every identity, human or non-human, is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.
- Identity Security: Identity security is the discipline of governing who and what can access systems, data, and tools, then proving those decisions are enforced. In practice it spans human users, service accounts, tokens, certificates, and AI agents across the full access lifecycle.
- Service Account: A special-purpose account used by applications, automated tools, or services rather than a human user to interact with systems, APIs, and infrastructure. Service accounts are a primary category of NHI and one of the most frequently exploited attack vectors.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org