TL;DR: Cybercrime and cyber insecurity entered the WEF Global Risks Report 2023 top 10, underscoring that digital disruption is now treated as a persistent business risk rather than a passing threat, according to INTIGRITI's analysis of the report. For practitioners, the signal is that resilience, identity control, and operational recovery must be governed as core risk-management capabilities, not separate security workstreams.
At a glance
What this is: The article argues that the WEF Global Risks Report 2023 elevates cybercrime and cyber insecurity into a top-tier global business risk.
Why it matters: This matters because identity, access, and resilience controls now sit on the path between digital dependence and operational disruption for both human and machine-driven systems.
By the numbers:
- The breakdown of critical information infrastructure was ranked 16th among long-term threats.
- The report says cyber threats are a new entrant in the top 10 rankings of greatest global risks.
👉 Read INTIGRITI's analysis of the WEF Global Risks Report 2023 and cybersecurity
Context
The governance gap here is not whether cyber risk exists, but whether organisations have treated it as a permanent operating condition rather than an exceptional event. The WEF framing matters because it links cybercrime, critical infrastructure disruption, and technology dependence into one risk picture, which is exactly where identity controls, privileged access, and recovery planning become business-critical.
For identity and security programmes, the article's central point is that digital infrastructure now underpins essential services and daily operations, so compromise can cascade quickly across people, systems, and services. The identity angle is genuine: as more processes depend on connected platforms, access governance for human users, non-human identities, and AI-enabled workflows becomes part of resilience, not just administration.
The article is typical of broad cyber-risk commentary in that it focuses on macro risk trends rather than control design, but its implications are still operational for practitioners.
Key questions
Q: What breaks when cyber risk is not treated as an identity governance issue?
A: Access sprawl becomes a resilience problem when organisations separate security controls from identity governance. If human users, service accounts, and automation identities are not managed together, attackers can move from one trusted access path into critical services. That makes containment slower, recovery harder, and business impact wider.
Q: Why do non-human identities matter in critical infrastructure risk planning?
A: Non-human identities often control the systems that keep infrastructure running, including APIs, service accounts, and automation tools. If those identities are over-privileged or poorly monitored, compromise can affect availability and not just data confidentiality. They therefore belong in resilience planning, not only in technical access reviews.
Q: How can security teams know whether identity controls are actually reducing breach impact?
A: Look for evidence that suspicious accounts are contained fast, active sessions are terminated, and privileged access is limited to the smallest possible set of systems. If a compromised account can still reach sensitive resources after detection, the controls are not working well enough to limit impact.
Q: Who is accountable when emergency access causes a service outage?
A: Accountability should sit with both the system owner and the access owner, because emergency access is a governance decision as much as an operational one. If access was granted without a clear approval path, session traceability, and review process, the organisation owns the failure, not just the individual who executed the change.
Technical breakdown
Why cyber risk now behaves like a permanent control problem
Cyber risk stops being an episodic threat when digital services become the delivery layer for finance, transport, energy, healthcare, and public services. In that setting, compromise is not only about data theft. It can interrupt availability, corrupt trust, and force recovery across connected systems. The practical issue is governance, because the same access paths that enable agility also expand the blast radius when identities, credentials, or service controls are weak. For identity teams, this means access boundaries, privileged roles, and recovery dependencies have to be designed for continuous pressure, not occasional incidents.
Practical implication: treat cyber risk as an always-on control design problem and map identity dependencies into resilience planning.
How digital infrastructure turns identity into a resilience control
When critical services depend on cloud platforms, APIs, IoT devices, and automated workflows, identity becomes the mechanism that determines who or what can change, read, or disrupt those services. Human users still matter, but so do service accounts, tokens, certificates, and AI-driven agents that make decisions at runtime. That creates a governance challenge: if these identities are over-privileged or poorly monitored, a compromise can move from one system to many. This is where identity governance and non-human identity management intersect directly with cyber resilience.
Practical implication: inventory human and non-human identities together and validate that each privilege path is necessary, monitored, and recoverable.
Why critical infrastructure depends on access controls, not just detection
Detection matters, but the WEF theme shows that prevention and containment are what separate manageable incidents from systemic disruption. Critical infrastructure environments often contain older integration patterns, distributed trust, and vendor-managed access, which makes identity sprawl particularly dangerous. If access cannot be revoked cleanly, segmented effectively, or validated continuously, recovery takes longer and operational impact grows. The control question is whether organisations can limit action before disruption cascades, not simply observe it after the fact.
Practical implication: pair detection with strict access revocation, segmentation, and privileged session control across critical services.
Threat narrative
Attacker objective: The attacker aims to interrupt essential services or widen operational disruption by abusing trusted digital access paths.
- Entry occurs through the digital dependency layer, where attackers target exposed services, weak authentication, or trusted integrations that connect critical operations to external systems.
- Escalation follows when over-privileged accounts, shared credentials, or weakly governed service identities let the attacker expand from one access point into multiple systems or workflows.
- Impact emerges as service disruption, data compromise, or operational shutdown across infrastructure that relies on those connected identity and access paths.
NHI Mgmt Group analysis
Cyber risk has become an identity governance problem, not just a security category. The WEF framing is useful because it links operational dependence, digital trust, and systemic disruption. Once business processes and critical services rely on connected identities, access control quality directly shapes resilience. That is why IAM, PAM, and non-human identity governance belong in enterprise risk discussions, not only security operations. Practitioners should treat identity control as part of the organisation's continuity model.
Non-human identities are now part of the resilience surface. The article focuses on infrastructure and digital systems, but the real control boundary increasingly includes service accounts, API keys, certificates, and AI agents. These identities can make changes faster than human operators can intervene, which means over-privilege becomes an outage multiplier as well as a breach risk. The named concept here is identity-to-infrastructure coupling: when access decisions directly influence whether critical services stay available. Practitioners should map where machine identities can affect production outcomes.
The risk signal is not just more attacks, but more consequence from the same attack types. When cybercrime is recognised as a top global risk, the governance implication is that impact is no longer local to a single environment. A compromised identity, a mis-scoped integration, or a failed offboarding process can propagate into service interruption. That raises the bar for lifecycle control, privileged access review, and recovery testing. Practitioners should measure whether their identity controls can contain blast radius under real disruption conditions.
Resilience planning must include access failure scenarios. Many programmes still assume availability failures are separate from identity failures, but the article points to the opposite. If access is the mechanism through which services are operated, then lost control of access is itself a resilience event. This strengthens the case for tighter privileged governance, segmented administration, and faster credential revocation. Practitioners should build incident scenarios around identity compromise as a direct path to operational degradation.
What this signals
Identity-to-infrastructure coupling is the governance pattern most security teams still under-measure. As more services depend on connected identities, the question is no longer whether access exists, but whether it can be constrained quickly enough to preserve continuity. That makes identity inventory, privilege review, and recovery testing a resilience requirement rather than a hygiene exercise.
The WEF framing should push programmes to join up IAM, PAM, and non-human identity governance with continuity planning. Teams that still treat user access, machine access, and incident recovery as separate workstreams will struggle to contain disruption when an identity compromise lands in production. The most mature posture is one where access failure is rehearsed as a business interruption scenario.
For broader risk governance, the signal is that cyber exposure now has board-level operating consequences across human and machine access paths. The right next step is to align identity controls to continuity objectives and test whether critical services can fail safe when credentials, roles, or automation identities are abused.
For practitioners
- Map identity dependencies into critical service recovery plans Document which human and non-human identities can alter, pause, or restore essential services, then test recovery paths against loss of those identities. This reveals where continuity depends on a single credential, account, or admin workflow.
- Review privileged access across infrastructure-facing accounts Identify accounts and tokens that can touch production, network, cloud, or operational systems. Reduce standing privilege, separate duties, and require explicit approval for high-impact actions.
- Track non-human identities alongside human identity estates Include service accounts, APIs, certificates, and automation identities in the same inventory and review process as user identities. The goal is to stop invisible access paths from becoming the easiest route to disruption.
- Test containment against access compromise scenarios Run exercises that assume a trusted identity is abused, then measure how quickly access can be revoked, segmented, and re-established without spreading disruption across dependent services.
Key takeaways
- Cybercrime is now framed as a persistent global risk, which means identity governance has to be built for continuous pressure rather than periodic review cycles.
- The article's real operational lesson is that digital infrastructure, privileged access, and service continuity are now tightly coupled.
- Security teams should test whether identity controls can contain disruption fast enough to protect essential services when access is compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.RA-1 | The article is about recognising cyber risk as an enterprise governance issue. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central where access paths can affect infrastructure resilience. |
| OWASP Non-Human Identity Top 10 | NHI-03 | The article's identity angle includes machine identity sprawl and access governance. |
| NIST Zero Trust (SP 800-207) | Continuous verification supports the article's resilience-through-access-control theme. | |
| CIS Controls v8 | CIS-5 , Account Management | Account management directly addresses the identity sprawl that weakens resilience. |
Use NHI-03 to review lifecycle control for service accounts, tokens, and other non-human identities.
Key terms
- Identity-to-Infrastructure Coupling: The degree to which identity controls directly affect whether infrastructure can operate, recover, or be disrupted. In modern environments, this includes user accounts, service identities, tokens, and automation agents that can change production systems, making identity governance a resilience concern as well as an access-control one.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Operational Resilience: Operational resilience is the ability to keep critical services running or recover them quickly after disruption. In identity-led environments, that depends on authentication services, privilege management, and recovery procedures that can be tested under realistic failure conditions.
What's in the full article
INTIGRITI's full article covers the report excerpts and contextual analysis this post intentionally leaves at a governance level:
- The article's broader discussion of WEF's short-term and long-term risk framing for cybercrime, infrastructure, and technology dependence.
- The specific examples it uses to connect cyber risk to smart cities, IoT networks, and critical services.
- The surrounding commentary on how businesses should interpret cyber threats as a permanent condition rather than a short-lived spike.
- The original article's links to related cybersecurity commentary and further reading.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity control to broader security and resilience programmes.
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org