Join our Newsletter — 33% off our NHI Course

Identity breach costs and help desk hijacks: what should teams do?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: 69% of organisations experienced an identity-related breach in the last three years, 45% said those breaches cost more than the typical incident, and 24% said costs exceeded $10M, according to RSA Security's 2026 RSA ID IQ Report. Identity failure is now a recurring business-resilience problem, not an edge case for IAM teams.

Editorial analysis by NHI Mgmt Group, based on content published by RSA Security: “Brazil Leads the World in Global Identity Security Survey: RSA ID IQ Report Unveils Top Identity Threats”.

By the numbers:

  • 69% of organisations experienced an identity-related breach in the last three years.
  • 45% of organisations said that the cost of an identity-related breach exceeded the typical cost of a breach.
  • 24% of organisations said identity-related breach costs exceeded $10M.

Key questions

Q: What breaks when help desk recovery processes are easier to abuse than primary authentication?

A: When recovery is easier to manipulate than login, attackers bypass the strongest control and go after the weakest trust decision.

Q: Why do identity-related breaches become so expensive so quickly?

A: Identity compromise often gives attackers legitimate access rather than a narrow technical foothold.

Q: What are the signs that help desk security controls are failing?

A: Warning signs include undocumented support actions, excessive help desk entitlements, exceptions handled outside normal change management, and requests approved without out-of-band verification.

Practitioner guidance

  • Harden service desk identity proofing Require stronger verification for resets, rebinds, and account recovery, especially where privileged or federated identities are involved.
  • Map and govern fallback authentication paths Document every alternate route into an account, including recovery codes, device resets, and support-assisted re-enrolment.
  • Measure breach containment by identity path Track how quickly a suspected identity compromise can be isolated across SSO, help desk, and downstream applications.

Bottom line: Identity breaches are rising fast enough that they now represent a recurring governance and resilience problem for security teams.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 11 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Identity governance is now a breach-cost control, not just an access-control discipline. The report links identity failure to both higher breach frequency and higher breach cost, which means governance gaps now translate directly into financial exposure. The practical issue is no longer whether identity is central to security, but whether the programme can reduce blast radius when identity fails. Leaders should treat identity outcomes as resilience metrics, not only compliance artefacts.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations prioritise recovery design or new authentication factors first?

A: Recovery design usually comes first because a weak recovery path can undermine a strong factor. If users can re-enter the environment through interceptable OTP flows or inconsistent manual resets, the new method does not change the underlying exposure surface.

👉 Read our full editorial: Identity breaches and help desk hijacks are escalating globally


This post was modified 11 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.