Join our Newsletter — 33% off our NHI Course

Identity breach costs and help desk hijacks: what teams missed

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Identity-related breaches rose to 69% of organisations over the last three years, while 45% said breach costs exceeded typical breach costs and 24% reported losses above $10 million, according to RSA Security’s 2026 RSA ID IQ Report. The data shows identity governance is failing at both prevention and containment, especially where help desk abuse and weak passwordless adoption intersect.

Editorial analysis by NHI Mgmt Group, based on content published by RSA Security: “92% of Australian Organisations Are Failed by Identity Security: RSA ID IQ Report Unveils Top Identity Threats”.

By the numbers:

  • Identity-related breaches rose to 69% of organisations over the last three years, according to RSA Security.
  • 45% of organisations said identity-related breach costs exceeded the typical cost of a breach, according to RSA Security.
  • 24% of organisations said identity-related breach costs exceeded $10 million, according to RSA Security.

Key questions

Q: What breaks when help desk resets are treated as low-risk support tasks?

A: The reset path becomes a privileged access channel that attackers can target through social engineering.

Q: Why do help desk hijacks create such high breach costs?

A: They create high breach costs because they often deliver trusted access, which lets attackers move beyond the initial account into admin functions, data access, and broader operational disruption.

Q: What should organisations prioritise after adopting passwordless login?

A: Organisations should next review recovery workflows, privilege boundaries, and secrets management.

Practitioner guidance

  • Tighten account recovery governance Require step-up proofing, dual approval for overrides, and full audit trails for any reset, unlock, or identity change that support staff perform.
  • Map support workflows to privileged access Classify help desk systems and personnel actions as privileged access paths, then review who can reset, override, or re-enrol identities.
  • Reduce password fallback exposure Accelerate passwordless rollout where feasible, but also remove weak fallback routes that still allow passwords, recovery codes, or manual bypasses to reintroduce risk.

Bottom line: Identity-related breaches are rising fast enough that IAM teams need to treat support workflows as part of the identity attack surface, not a back-office exception.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 20 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Help desk security is now an identity governance control, not a support function. The article shows that attackers are bypassing authentication by manipulating the people and workflows that recover identities. That shifts the control problem from front-door login security to the lifecycle of account recovery, reset approval, and support-side proofing. IAM programmes that keep help desk controls outside formal governance are leaving the highest-trust path under the weakest oversight.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should security leaders review after a service desk bypass attack?

A: Security leaders should review who can verify, reset, re-enrol, and override identities, how those actions are approved, and whether logs prove the request was legitimate. They should also test whether support staff can be manipulated into acting outside policy. The goal is to prove that recovery controls are resistant to social engineering, not just documented.

👉 Read our full editorial: Identity breaches surge as help desk hijacks raise IAM risk


This post was modified 20 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.