Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity attacks keep landing: what finance-security gaps mean for IAM


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Identity-based incidents accounted for 68.6% of cases and 47.7% of those led to successful account access, according to Expel’s 2026 Annual Threat Report, while its CISO-CFO disconnect report shows budget and language gaps that leave basic controls underfunded. The real problem is governance: organisations still fail on controls they already understand.

NHIMG editorial — based on content published by Expel: the third blog in the webinar series on speaking CFO and the research behind it

By the numbers:

Questions worth separating out

Q: What breaks when identity controls are only documented and not executed consistently?

A: When identity controls exist only on paper, the organisation loses the ability to prevent or promptly detect bad access, missed approvals, and offboarding gaps.

Q: Why do identity programmes often lose funding over time?

A: Identity programmes lose funding when leaders classify ongoing governance work as one-time implementation rather than recurring assurance.

Q: How do you know if MFA and identity controls are actually working?

A: You measure whether attacks fail consistently at the point of authentication and whether exceptions are rare, visible, and approved.

Practitioner guidance

  • Map identity risk to financial exposure Translate MFA gaps, token abuse, and cloud credential exposure into downtime cost, recovery spend, and regulatory impact so finance can evaluate the request in its own language.
  • Audit where identity controls are only partially deployed Verify that MFA, conditional access, and authentication protections are enforced across all production systems, not just the highest-profile ones.
  • Join NHI lifecycle control to budget ownership Tie service account provisioning, secret rotation, and revocation to named business owners so machine identities do not persist outside accountable funding lines.

What's in the full article

Expel’s full blog covers the source data and executive discussion this post intentionally leaves at the strategic level:

  • The underlying 2026 Annual Threat Report findings behind the 68.6% identity-based incident rate and the control failures behind successful access.
  • The CISO-CFO disconnect survey results from 300 executives, including confidence scores and collaboration patterns.
  • The security-finance framework for translating identity risk into budget language, including the metrics finance actually uses.
  • The full webinar discussion with Expel and SMBC leaders on how to communicate risk across functions.

👉 Read Expel’s analysis of identity-based attacks and the CISO-CFO disconnect →

Identity attacks keep landing: what finance-security gaps mean for IAM?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Identity control failure is often a funding failure before it is a technical failure. The article’s strongest point is that the needed controls already exist, but they are not always deployed rigorously enough to stop basic attacks. That is a governance problem, not a technology discovery problem. For IAM and PAM leaders, the lesson is that partial implementation is a control failure, not an acceptable intermediate state.

A question worth separating out:

Q: Who is accountable when identity risk is discovered but not fixed?

A: Accountability belongs to the team that can actually enforce the change, not the team that merely reports the issue. If security owns the risk but cannot revoke access, the operating model is misaligned. Frameworks such as the NIST Cybersecurity Framework 2.0 expect governance to connect detection with response and recovery.

👉 Read our full editorial: Finance-security misalignment is letting identity attacks keep succeeding



   
ReplyQuote
Share: