Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity attacks dominate incidents in 2025, so what should teams do?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Identity remained the most targeted attack surface in Expel’s 2026 Annual Threat Report, which says 68.6% of incidents it saw in 2025 involved identity as the primary entry point; the report also argues security teams need to translate control success into business risk and dollars, not just block counts, according to Expel. That framing matters because stronger identity controls change the meaning of an incident, not the need for governance.

NHIMG editorial — based on content published by Expel: 2026 Annual Threat Report and its identity-risk findings

By the numbers:

Questions worth separating out

Q: How should teams measure whether identity governance is actually reducing risk?

A: Track exposure, not just activity.

Q: Why does identity now matter so much in detection and response programmes?

A: Identity is the control plane for most access decisions, so abuse often shows up first as unusual authentication, permission change, or delegation behaviour.

Q: What do security teams get wrong about blocked identity attacks?

A: They often count them as successful security outcomes without explaining the business loss that was prevented.

Practitioner guidance

  • Measure identity incidents in business terms Track prevented compromise, successful misuse, expected loss, and recovery cost in the same reporting pack so leadership sees control value, not just alert volume.
  • Separate denied access from confirmed compromise Classify identity events by stage reached, including blocked login, token abuse, privilege use, and downstream impact, so the SOC can report meaningful control effectiveness.
  • Extend identity governance to NHIs and AI-linked credentials Apply the same ownership, revocation, and scoping discipline to service accounts, tokens, and agent credentials that you already expect for human accounts.

What's in the full report

Expel's full report covers the incident mix, control context, and risk framing this post intentionally leaves at a higher level:

  • How Expel broke down incident volume by attack surface and why identity led the list
  • The report's quantitative framing for translating control wins into business risk
  • Operational context around SSO, MFA, and passkeys in reducing identity abuse
  • The report's broader incident categories that can support likelihood calculations

👉 Read Expel's 2026 Annual Threat Report on identity-led incidents and risk translation →

Identity attacks dominate incidents in 2025, so what should teams do?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Identity governance is now a business risk function, not just an authentication function. When identity sits at the centre of incident volume, the security programme is really managing who or what can act with trust in the environment. That includes human users, service accounts, workload identities, and AI-linked credentials. The practical conclusion is that IAM and NHI governance must be assessed by their effect on exposure and loss, not by login metrics alone.

A question worth separating out:

Q: How should organisations communicate identity risk to business leaders?

A: Use dollars, downtime, and operational exposure rather than technical jargon. Business leaders respond to expected loss, recovery cost, and resilience impact. Security teams are more persuasive when they show how identity controls reduce the likelihood and cost of an incident instead of simply listing attacks blocked.

👉 Read our full editorial: Identity attacks remain the top incident surface in Expel's 2026 report



   
ReplyQuote
Share: