By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: SafeBreachPublished January 14, 2026

TL;DR: Identity abuse, lateral movement, and AI-driven infostealing are the stealthy behaviours most likely to evade enterprise controls, according to SafeBreach. The key shift is that validation data, not tool counts or patch metrics, now better reveals where resilience is failing, based on SafeBreach’s inaugural 2026 State of the Breach Report and more than 1.8 million high-fidelity simulations.


At a glance

What this is: SafeBreach’s inaugural breach report argues that empirical simulation data reveals where enterprise controls fail in real attack paths, with identity abuse, lateral movement, and AI-driven infostealing emerging as the most telling patterns.

Why it matters: For IAM, PAM, and broader security teams, the report reinforces that resilience depends on whether controls stop attack paths in practice, not whether policies or tools exist on paper.

👉 Read SafeBreach’s 2026 State of the Breach Report on enterprise resilience


Context

Breach report data is only useful when it shows whether controls stop real attack paths, not whether they exist in a policy library. This report is about cyber resilience, but it has a clear identity security dimension because the tactics that quietly succeed most often are identity abuse, lateral movement, and exposed access pathways.

In enterprise environments, attackers rarely need a dramatic zero-day to create material impact. They often rely on control gaps that let credentials, privileges, or delegated access persist long enough to be abused, which is why validation data is more useful than abstract assurance claims. SafeBreach frames the problem through simulation evidence rather than survey sentiment, and that makes the starting point unusually operational rather than promotional.


Key questions

Q: How do organisations know whether resilience controls are actually working?

A: They know by testing under failure conditions, not by checking configuration alone. A resilience control is working if the team can still reach critical credentials, restore service, and complete remediation when the main environment is down. If the process only works when production is healthy, it is availability theatre rather than resilience.

Q: Why do identity abuse and lateral movement remain such persistent risks?

A: They remain persistent because they rely on legitimate access relationships that many enterprises still trust by default. Service accounts, tokens, delegated permissions, and over-provisioned privileges often create quiet paths across environments. When those paths are not continuously tested, attackers can move laterally without needing a noisy exploit chain or obvious malware.

Q: What do security teams get wrong about exposure management?

A: They often confuse visibility with control effectiveness. Knowing where assets, alerts, or tools exist does not prove that an attacker path is blocked. Exposure management has to answer a harder question: if a real adversary uses current tradecraft, does the environment stop them before identity abuse or lateral movement becomes impact?

Q: How should organisations respond when simulation reveals a surviving attack path?

A: Treat the result as governance evidence, not just an engineering defect. Confirm which access control failed, whether the issue is standing privilege, weak segmentation, or detection latency, and then re-test the same path after remediation. The goal is to prove the path is closed, not to assume it is closed because a fix was deployed.


Technical breakdown

Why breach simulation exposes control gaps better than coverage metrics

Breach and attack simulation tests whether a control interrupts a known attack path, not whether a tool is deployed or a rule exists. That distinction matters because coverage metrics can look healthy while important kill-chain steps still succeed in production conditions. When the report says simulation data reveals where organisations are effective and where attackers are silently succeeding, it is pointing to control effectiveness, not product inventory. For identity-heavy environments, this is especially important because access abuse often occurs within authorised channels, not through obvious malware behaviour.

Practical implication: measure whether controls break attack paths at the point of abuse, not just whether they are configured.

Why identity abuse and lateral movement remain high-value attacker paths

Identity abuse means attackers use valid credentials, tokens, or delegated permissions rather than noisy exploit chains. Lateral movement follows when one foothold provides access to adjacent systems, accounts, or workloads. These are persistent security problems because they exploit trust relationships that infrastructure often assumes are legitimate. In mature enterprises, that trust is frequently encoded in service accounts, privileged automation, and over-permissioned access grants, so the offensive path can stay quiet until impact is already underway.

Practical implication: review standing access, delegated permissions, and service account scope as attack-path controls, not administrative housekeeping.

How AI-driven infostealing changes exposure validation

AI-driven infostealing raises the speed and scale of credential collection, phishing adaptation, and payload variation. That does not replace established tradecraft, but it can compress the time between initial lure and usable access. For defenders, the important change is that validation must now consider whether detection and containment still work when adversaries automate reconnaissance and targeting. The issue is not merely whether AI is involved, but whether it shortens the window in which identity, endpoint, and monitoring controls can intervene.

Practical implication: test whether your detection and containment stack still works when attacker tradecraft is faster, more adaptive, and partially automated.


Threat narrative

Attacker objective: The attacker objective is to turn valid access and trust relationships into quiet progress across the environment without triggering effective containment.

  1. Entry begins with high-fidelity attacker behaviours being simulated against enterprise environments, including CISA alerts, nation-state tradecraft, ransomware, and infostealer activity.
  2. Escalation occurs when identity abuse or lateral movement remains viable despite layered controls, showing that authorised access paths can still be exploited.
  3. Impact is realised when organisations rely on tool coverage and patch metrics instead of proof that controls stop actual attack paths, leaving hidden exposure unresolved.

NHI Mgmt Group analysis

Control validation is becoming the real resilience metric. Enterprise security programmes increasingly fail not because they lack tools, but because they cannot prove that those tools interrupt attacker behaviour in real environments. Simulation data is more valuable than dashboard output because it measures whether an attack path breaks when pressure is applied. The practical conclusion is that validation needs to sit beside policy and telemetry as a core governance input.

Identity abuse remains the most underappreciated resilience gap. When attackers use legitimate credentials, tokens, or delegated access, traditional perimeter thinking offers little help. That is why identity control effectiveness, especially around privilege scope and standing access, belongs in every resilience review. The lesson for practitioners is to treat identity governance as attack-path governance, not just lifecycle administration.

AI-driven infostealing creates a faster adversary model, not a new one. The report’s focus on AI-generated threats matters because automation can compress the time available for detection and response. That makes continuous validation more important, not less, because slow or assumption-driven controls will miss the pace shift. Practitioners should assume that adversaries will increasingly test identity and endpoint defences at machine speed.

Validation gaps reveal where programmes are undertesting the most dangerous paths. The report argues that some environments are not just underperforming, they are underexamined. That distinction matters because a blind spot in simulation is a blind spot in governance. The field implication is clear: security leaders need evidence about what has never been tested, not just what passed a tabletop exercise.

Measurable control effectiveness is replacing anecdotal confidence. The most credible resilience programme is the one that can show how often it stops real attack behaviour, where it fails, and which exposure paths remain open. That approach aligns security investment with actual risk reduction. Practitioners should make validation evidence a standing input to prioritisation and board reporting.

What this signals

Control validation will increasingly shape security prioritisation. If your programme still relies mainly on coverage metrics, this report is a warning that you may be managing visibility rather than resilience. The next step is to connect exposure validation with identity governance, because the same attack paths that survive simulation often begin with over-extended credentials or unclear privilege boundaries. For teams working through that shift, the NHI Lifecycle Management Guide is the right place to align provisioning, rotation, and offboarding with measurable control outcomes.

Validation gaps are becoming governance gaps. When the environment is undertested, leaders cannot tell whether a low-risk dashboard simply reflects unexamined attack paths. That changes how IAM, PAM, and security architecture teams should frame assurance. The practical move is to pair detection engineering with lifecycle controls and to benchmark the result against the MITRE ATT&CK Enterprise Matrix so attack techniques map back to specific control failures.

A more useful operating model is emerging: test, observe, remediates, and re-test until identity abuse and lateral movement no longer survive validation. That approach fits the wider move toward measurable assurance in security programmes, where evidence outranks assumption. For identity teams, it also reinforces why the Ultimate Guide to NHIs , Key Challenges and Risks remains relevant when you need to explain why sprawl and over-privilege keep defeating mature environments.


For practitioners

  • Use attack-path validation as a board-level metric Report whether your environment stops real attacker behaviours, not just how many alerts were generated or tools deployed. Tie validation results to risk acceptance decisions so leadership can see which attack paths still survive control testing.
  • Prioritise identity abuse scenarios in simulation plans Include credential misuse, delegated access abuse, and lateral movement in your recurring tests. These scenarios are where mature environments often discover that standing access and over-permissioning still create material exposure.

Key takeaways

  • The report’s core message is that resilience cannot be inferred from tools, dashboards, or patch counts.
  • Identity abuse and lateral movement remain the most important quiet failure modes because they exploit trusted access rather than obvious exploits.
  • Practitioners should treat validation evidence as a control input, then re-test until surviving attack paths are actually closed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe report centers on credential abuse and lateral movement as stealthy attacker behaviours.
NIST CSF 2.0DE.CM-8Validation data helps determine whether monitoring and control effectiveness are real.
NIST SP 800-53 Rev 5SI-4The report’s focus on attack-path interruption aligns with system monitoring and response.
CIS Controls v8CIS-5 , Account ManagementIdentity abuse and standing access are central to the report’s resilience findings.
NIST AI RMFMANAGEThe report’s empirical validation approach supports ongoing risk treatment and monitoring.

Use MANAGE to operationalise recurring validation, remediation, and re-testing for real attack behaviours.


Key terms

  • Breach and Attack Simulation: Breach and attack simulation is a method for testing whether security controls stop realistic attacker behaviours in a live or production-like environment. It measures control effectiveness against known techniques, helping teams distinguish between theoretical coverage and actual resilience.
  • Control Effectiveness: The degree to which a control actually works in real operating conditions, not just on paper. Auditors assess whether the control is designed well, executed consistently, and supported by evidence that shows it reduced the intended risk.
  • Identity Abuse: Identity abuse is the misuse of valid credentials, tokens, delegated permissions, or trusted access relationships to move through an environment. It is dangerous because it often appears legitimate to systems and operators until the attacker has already advanced.

What's in the full report

SafeBreach’s full report covers the operational detail this post intentionally leaves for the source:

  • Simulation data that breaks down which attack behaviours were most often stopped versus which continued through layered controls
  • Sector-by-sector resilience patterns that show where different industries performed better or worse under the same attack behaviours
  • Benchmarking detail that helps CISOs compare architecture types and exposure validation results across similar enterprises
  • Examples of the emerging AI-generated threat categories used in the report’s simulation set

👉 The full SafeBreach report covers simulation data, sector benchmarks, and validation gaps in greater detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle practices that support measurable control effectiveness. It gives security and identity practitioners a structured way to connect governance decisions to operational risk.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org