Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Continuous validation and password risk: what changed for IAM teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A global investment firm cut same-scope pentest impacts from 251 to zero and cracked Active Directory passwords from 40 to zero after shifting from point-in-time testing to continuous validation, according to Horizons.ai. The lesson for security leaders is that finding volume matters far less than proving whether weaknesses can still chain into business impact.

NHIMG editorial — based on content published by Horizons.ai: Patch Tuesday to Pentest Wednesday: How a Global Investment Firm Reduced Security Surprises

By the numbers:

Questions worth separating out

Q: What breaks when password policy exists but cracked credentials are never revalidated?

A: Password policy can look effective while cracked or reused credentials remain exploitable in the environment.

Q: Why do identity weaknesses matter more when they can be chained with other flaws?

A: Because attackers do not need a single catastrophic issue if they can combine smaller ones into a usable path.

Q: How should security teams measure whether identity security maturity is actually reducing risk?

A: Measure whether identity controls reduce standing privilege, excess entitlement, and time-to-revoke, not just whether reviews and approvals happened.

Practitioner guidance

  • Validate whether weaknesses still chain into identity compromise Use repeatable attack-path testing to confirm whether misconfigurations, credentials, and access paths can still be combined into meaningful impact.
  • Automate cracked-password remediation workflows Route cracked Active Directory password findings into notification, manager escalation, and forced reset workflows, then retest until the account is verified clean.
  • Track credential exposure as a measurable risk window Define how long cracked or exposed credentials remain valid before reset, and use that metric to drive executive reporting.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The phased rollout approach used to introduce continuous validation across 18 locations without disrupting operations
  • The team’s internal workflow for turning password audit results into manager escalation and remediation tracking
  • The way Claude was used with read-only access to NodeZero data to query findings in natural language
  • The same-scope pentest evidence showing how 46 minor weaknesses remained while exploit paths dropped to zero

👉 Read Horizons.ai's analysis of continuous validation and reduced security surprises →

Continuous validation and password risk: what changed for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Continuous validation exposes the gap between finding management and risk management. Many programmes can catalogue weaknesses, but far fewer can prove which weaknesses still chain into business impact after remediation. The important shift is not simply more testing, but testing that answers whether a control set actually prevents compromise. For identity teams, that means access, password hygiene, and remediation workflows must be judged by outcome, not activity.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when exposed credentials persist after remediation tickets close?

A: The accountable team is usually the one that owns identity governance and remediation closure, because the risk sits at the intersection of access management, password hygiene, and operational follow-through. Frameworks such as NIST CSF and NIST SP 800-53 expect controls to be verified, not assumed.

👉 Read our full editorial: Continuous validation reduced identity surprises for a global investment firm



   
ReplyQuote
Share: