TL;DR: Palo Alto Networks’ $25 billion acquisition of CyberArk confirms that identity controls now sit at the center of breach prevention, according to Bravura Security, with Verizon’s 2025 DBIR showing stolen credentials in 22% of breaches and 88% of web application breaches. Identity governance is no longer a supporting layer; it is the perimeter control plane.
At a glance
What this is: Bravura Security argues that the Palo Alto CyberArk acquisition is a market signal that identity, not network perimeter alone, is now the main battleground for breach prevention.
Why it matters: IAM, PAM, and NHI teams need to treat privilege and credential governance as core security architecture because stolen identity still drives a large share of real-world compromise.
By the numbers:
- Stolen credentials remained the single most common initial attack vector in 22% of breaches, according to Verizon's 2025 DBIR cited by Bravura Security.
- 88% of web application breaches involved the use of stolen credentials, according to Verizon's 2025 DBIR cited by Bravura Security.
- 60% of breaches involved a human element, including stolen passwords, phishing clicks, or misuse of access, according to Verizon's 2025 DBIR cited by Bravura Security.
- Insider privilege misuse accounted for 6% of breaches, according to Verizon's 2025 DBIR cited by Bravura Security.
Context
Identity is the control layer that determines whether a user, service, or machine can enter, act, and persist inside a modern environment. In this article, the primary IAM cybersecurity question is not whether perimeter tools still matter, but how much breach resistance depends on identity and privilege governance once credentials are exposed.
The Palo Alto CyberArk deal is being used as market evidence that vendors now see identity as central to security architecture, not a side capability. For practitioners, the more important issue is that platform consolidation does not remove the need to define ownership, lifecycle, and least privilege across human, machine, and privileged access.
The article also points to a broader operating reality: security teams are coping with siloed tooling while attackers keep exploiting the path of least resistance through authenticated access. That is a typical condition in mature enterprise environments, not an edge case.
Key questions
A: Perimeter tools lose most of their value once an attacker has valid authentication, because the session looks legitimate. The control failure is not just login compromise. It is the absence of tighter privilege, session, and anomaly constraints that would make stolen access far less useful.
Q: Why do privileged accounts create outsized breach risk?
A: Privileged accounts can change configurations, access sensitive data, and disable controls, so a single compromise often has disproportionate impact. If those accounts are broad, poorly monitored, or left active after use, attackers can move from initial access to system-wide disruption far faster than with ordinary user accounts.
Q: How can security teams tell whether an identity platform is actually reducing governance risk?
A: Look for fewer manual exceptions, faster propagation of role changes, and auditable evidence that matches the real change event. If reviewers still need side spreadsheets, if connector drift is common, or if certification campaigns are broad and shallow, the platform is automating activity rather than reducing risk.
Q: Should organisations treat human and non-human SaaS access the same way?
A: They should apply the same governance standard, even if the operational details differ. Human users, service accounts, and application identities can all accumulate excess permissions, so approval, review, and revocation discipline should cover each of them. The key difference is frequency and automation, not whether least privilege applies at all.
Technical breakdown
Why stolen credentials still bypass perimeter controls
A stolen credential turns authentication into the attacker’s entry point, which means perimeter tools often never see a hostile exploit chain at all. The issue is not just password theft. It is the fact that once a valid identity is compromised, the adversary inherits the trust already attached to that account, token, or session. In practice, this collapses the distinction between legitimate and malicious use unless additional controls constrain privilege, session scope, and anomaly response. That is why identity abuse is such a persistent attack pattern across web apps, cloud services, and admin consoles.
Practical implication: Treat valid-authentication abuse as a primary detection and control problem, not only a phishing or password hygiene problem.
Why privileged access changes the blast radius
Privileged access is different from ordinary access because it expands what a compromised account can change, read, or disable. A standard user credential may expose data, but a privileged identity can reconfigure controls, create persistence, or erase evidence. That is why PAM and identity governance matter together. PAM limits how privilege is issued and used, while governance determines who should have it, for how long, and under what review cycle. In a platform-converged world, the challenge is not simply centralising privilege. It is proving that the control boundary still exists after integration.
Practical implication: Map every privileged pathway to its business-critical impact and verify that standing privilege is not being normalised inside the platform stack.
How identity and security platforms converge without solving governance by themselves
Platform consolidation can improve correlation across network, endpoint, cloud, and identity signals, but correlation is not governance. A unified console may reduce operator friction, yet it does not automatically solve offboarding, entitlement cleanup, third-party access, or machine identity inventory. Those are lifecycle and ownership problems. The article’s core point is that identity has become the perimeter, but the hard work remains in making identity controls precise enough to survive scale, mergers, and mixed human-machine environments.
Practical implication: Use platform convergence to improve visibility, but keep lifecycle and entitlement controls as explicit governance workstreams.
Threat narrative
Attacker objective: The attacker objective is to turn legitimate authentication into unauthorized access that bypasses perimeter defenses and exposes high-value systems or data.
- Attackers gain entry by using stolen credentials or harvested passwords rather than exploiting the network perimeter directly.
- Once authenticated, they abuse the trust attached to the identity to reach web applications, admin functions, or privileged resources.
- Privilege misuse or excessive entitlements expand the blast radius, enabling data theft, persistence, or control changes.
- Impact follows when the compromised identity is treated as legitimate long enough to move, act, or persist inside the environment.
Breaches seen in the wild
- BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity has become the control boundary that determines whether perimeter security matters at all. When attackers can authenticate as a legitimate user, many network defenses are bypassed before they start. That shifts the real security question from blocking entry to governing trust, privilege, and session scope across every identity type. Practitioners should treat identity as the first policy boundary, not a downstream control.
Platform convergence does not eliminate governance debt. A larger security stack may improve telemetry and response, but it does not automatically fix entitlement sprawl, dormant access, third-party offboarding, or privileged account ownership. The market may be moving toward unified platforms, yet the underlying identity problem remains lifecycle control. Practitioners should separate console integration from governance effectiveness.
Privileged access is the point where identity risk becomes operational risk. The article’s emphasis on PAM is well placed because compromised privilege changes the blast radius, not just the entry vector. That is why identity security can no longer be split into workforce IAM on one side and elevated access on the other. Practitioners should evaluate whether privilege is being governed as a special case or as part of the core identity model.
Identity-aware security only works when the identity inventory is complete. The article correctly extends the issue beyond humans to machine and non-human identities, which is where many programmes still undercount exposure. If service accounts, tokens, and API keys are missing from the governance model, the perimeter has been rebuilt in theory but not in practice. Practitioners should assume that incomplete identity inventory equals incomplete defence.
Identity blast radius is now the most useful way to think about breach exposure. The article points to a market truth that security leaders can no longer avoid: the control that matters most is the one that limits what a compromised identity can do next. That makes lifecycle review, privilege scoping, and session governance the measures that determine whether a valid login becomes a major incident. Practitioners should optimise for blast-radius reduction, not just authentication success.
From our research library:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- 42% of machine identities have privileged access and 61% of organisations lack identity security controls for cloud workloads, according to CyberArk's 2025 Identity Security Landscape.
- Read next: Privileged Access Management Guide
What this signals
Identity blast radius: The useful metric is no longer how many identities exist, but how much damage a single authenticated identity can do before containment. That pushes programmes toward tighter entitlement boundaries, shorter privilege duration, and clearer ownership of machine and privileged accounts.
The Palo Alto CyberArk deal reinforces a governance pattern that many teams have already felt operationally. Identity and privilege can no longer be managed as separate domains, because the attacker only needs one valid path to turn access into impact. Practitioners should prepare for closer integration between IAM, PAM, and non-human identity inventory, while keeping review and offboarding controls explicit rather than assumed.
For practitioners
- Inventory privileged identities across the estate Create a single view of human admins, service accounts, API keys, and other non-human identities that can exercise elevated access. Separate inherited privilege from explicitly approved access so you can see which identities are carrying hidden blast radius.
- Reassess standing privilege and entitlement sprawl Review which accounts retain persistent elevation after the task, project, or role that justified them has ended. Prioritise identities that can change configuration, read sensitive data, or administer security tools.
- Tie identity events to response workflows Ensure authenticated access anomalies, privilege changes, and unusual session behaviour feed directly into incident triage. If an account is compromised, response should focus on limiting the next action that identity can take rather than only resetting the password.
- Separate platform integration from governance ownership Document who owns provisioning, review, offboarding, and exception handling for each identity class before consolidating tools or vendor stacks. Integration without ownership clarity usually creates blind spots instead of closing them.
Key takeaways
- The article frames identity, not perimeter tooling alone, as the main control plane for modern breach prevention.
- The evidence it cites is directional and concrete, with stolen credentials, privilege misuse, and the human element all appearing repeatedly in breach data.
- Practitioners should respond by tightening privilege scope, making identity inventory complete, and separating platform integration from governance ownership.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on privilege as the main breach multiplier across human and non-human identities. |
| NHI-07 — Long-Lived Secrets | Stolen credentials and persistent access are the article's core breach drivers. | |
| Recommendation — Reduce standing elevation and scope every non-human identity to the minimum access it needs. Shorten secret lifetime and revoke credentials that outlive their task or owner. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article's credential-abuse theme maps directly to authenticator lifecycle control. |
| Recommendation — Enforce authenticator issuance, rotation, and revocation under IA-5. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post argues that entitlements and authorization boundaries determine real exposure. |
| Recommendation — Continuously review entitlements and remove access that no longer matches business need. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes stolen credentials as the entry path that leads to broader compromise. |
| Recommendation — Map credential abuse and lateral movement patterns in detections and response playbooks. | ||
Key terms
- Identity Perimeter: The identity perimeter is the access boundary defined by who or what is requesting entry, not by where the request comes from. In zero trust, it is the point where authentication, authorization, and risk context decide whether a caller can proceed.
- Privilege Blast Radius: The amount of damage an attacker can do after compromising a privileged identity. It is a more useful operational measure than simple account counts because it reflects how far access can spread across cloud, SaaS, and machine identities once a control path is abused.
- Platform convergence: Platform convergence is the process of collapsing duplicate identity workflows, policy engines, and audit paths into a more coherent operating model. The goal is not fewer tools for its own sake, but faster and more trustworthy identity decisions with less manual reconciliation.
- Credential Abuse: Credential abuse is the use of valid secrets or accounts by an unauthorised party or for unauthorised purposes. In practice, it often looks like normal authentication unless teams correlate context, privilege, and behaviour. It is one of the most persistent ways identity failures become breaches.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org