TL;DR: 2025’s most consequential breaches showed that AI-assisted tooling, automated reconnaissance, and commoditised exploitation have made advanced attack chains accessible to mid-tier actors, according to FireCompass’s panel brief. The implication is clear: periodic testing and point-in-time assurance no longer match how attackers operate, so blast-radius control and continuous validation now matter more than prevention alone.
NHIMG editorial — based on content published by FireCompass: Panel Brief | Top Breaches in Cyber Security in 2025
Questions worth separating out
Q: What breaks when periodic pentesting is used to govern continuously changing identities?
A: Periodic testing breaks because it assumes the attack surface stays stable long enough to be assessed.
Q: Why do service accounts with standing privilege increase lateral movement risk?
A: Standing privilege expands the blast radius of one compromised identity.
Q: How should organisations measure whether identity governance is actually working?
A: Organisations should measure whether governance reduces incident cost, manual workload, and time to detect or contain risky access.
Practitioner guidance
- Continuously inventory identity planes Track users, service accounts, API tokens, OAuth grants, and cloud IAM roles as one live inventory so new exposures are visible before they are abused.
- Test exploit chains, not single findings Validate whether an exposed identity can move from initial access to token replay, lateral cloud access, and privileged control-plane actions in your environment.
- Reduce standing privilege in SaaS and cloud controls Remove broad, persistent access from integrations and service identities so a harvested credential has limited reach if it is replayed.
What's in the full article
FireCompass's full blog covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of the continuous automated red teaming workflow and how it maps to live attack paths.
- Specific examples of attack surface discovery across cloud assets, SaaS integrations, and shadow IT.
- Operational detail on how the platform validates exploitability and generates remediation playbooks.
- The panel discussion context behind the 2025 breach categories and defender lag argument.
👉 Read FireCompass's panel brief on the top breaches in cyber security in 2025 →
2025 breach trends: is your testing model still point-in-time?
Explore further
Continuous validation is now the only credible assurance model for identity-rich environments. The article’s core claim is that attackers operate continuously while defenders still audit periodically, and that mismatch is now the real control gap. For IAM and NHI programmes, this means identity governance cannot be treated as a scheduled event. It must be proven continuously against the live attack surface, not assumed from a last-quarter report.
A question worth separating out:
Q: Should organisations prioritise continuous testing or access reviews first?
A: Organisations should prioritise continuous testing when identities, APIs, and integrations change frequently, because access reviews alone cannot keep pace with runtime exposure. Reviews still matter, but they should validate ownership and lifecycle, while continuous testing proves whether live credentials can actually be abused. The right sequence is visibility first, then review, then containment.
👉 Read our full editorial: 2025 breach trends show why continuous testing now beats point-in-time assurance