TL;DR: Identity-based attacks are now the dominant enterprise entry path, and the article argues that legacy IAM, IdPs, and quarterly access reviews were built for a pre-cloud world that no longer exists, according to Newcore. The architecture problem is no longer hypothetical: identity platforms must govern humans, workloads, and agents together, or they become the weakest part of the stack.
NHIMG editorial — based on content published by Newcore: Identity platforms now sit at the center of enterprise risk
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What breaks when governance relies only on quarterly access reviews?
A: Quarterly reviews miss the day-to-day drift that accumulates between certification cycles.
Q: Why do shared secrets and replayable tokens increase enterprise risk?
A: They create portable trust that can be copied, replayed, or abused far beyond the original authentication event.
Q: What do security teams get wrong about agentic identity?
A: The common mistake is assuming an AI client can be governed like a normal service account with one stable use case.
Practitioner guidance
- Audit identity assumptions that still depend on human-paced review Identify where quarterly access reviews, manual certification, or ticket-based approval still define trust for workloads and agents.
- Separate actor types in the identity graph Keep humans, service accounts, and agents in the same policy plane, but give each one distinct lifecycle rules, attribution, and privilege boundaries.
- Reduce reusable trust material across the stack Find shared secrets, replayable tokens, and signing keys that function like enterprise-wide skeleton keys.
What's in the full article
Newcore's full article covers the operational detail this post intentionally leaves for the source:
- The vendor’s full framing of how a converged identity platform should handle humans, workloads, and agents in one control plane.
- The specific architectural claims behind hardware-bound, phishing-resistant, split-trust identity design.
- The migration argument for moving from legacy IAM to a rebuilt identity platform without rip-and-replace downtime.
👉 Read Newcore's perspective on rebuilding identity architecture for humans, workloads, and agents →
Identity platforms and agentic AI: what does the rebuild require?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity is no longer a feeder system for security tooling. It is the control plane the CISO has to defend directly. When attackers now enter through credential abuse, token theft, MFA bypass, or session hijack, the centre of gravity has moved from perimeter thinking to identity architecture. The implication is that identity governance cannot remain an administrative layer sitting underneath the real security stack.
A few things that frame the scale:
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to 2024 ESG Report: Managing Non-Human Identities.
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, which shows how far governance gaps can spread before they are measured.
A question worth separating out:
Q: Who is accountable when identity infrastructure is the entry point?
A: Accountability usually spans platform owners, IAM operations, and security governance because the failure often sits in the trust layer rather than in a single endpoint. Frameworks such as NIST CSF and OWASP Non-Human Identity Top 10 help assign ownership for privileged access, federation integrity, and non-human credentials. The practical goal is clear responsibility for the systems that issue trust.
👉 Read our full editorial: Identity platforms now sit at the center of enterprise risk