Join our Newsletter — 33% off our NHI Course

Identity threat detection and response: is your access model ready?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Passwords still anchor most breach paths, with Verizon reporting that 80% of breaches stem from compromised credentials, while IBM says 90% of successful cyberattacks start at endpoints. Imprivata’s acquisition of Verosint signals that access control now needs continuous identity risk detection, not just stronger login gates.

Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “As Credential-Based Attacks Soar, Identity Threat Detection and Response Becomes Critical to Secure Access”.

By the numbers:

  • 90% of successful cyberattacks originate at endpoint devices, according to IBM’s Cost of a Data Breach Report cited by Imprivata.
  • 70% of data breaches originate at endpoint devices, according to IBM’s Cost of a Data Breach Report cited by Imprivata.

Key questions

Q: How should security teams respond when access decisions are no longer safe to make only at login?

A: They should move to session-aware governance, where identity, device, and behavioural signals can change access decisions after authentication.

Q: Why do compromised credentials remain so effective in modern environments?

A: Compromised credentials remain effective because they produce legitimate-looking access.

Q: What are the signs that identity threat detection is failing in an enterprise environment?

A: Warning signs include breaches being identified by customers or external parties, long investigation windows with little internal evidence, and attackers remaining active for weeks without being detected.

Practitioner guidance

  • Map your access controls to the full identity lifecycle Identify where your environment still assumes authentication is the end of the control path.
  • Add session-level risk signals to IAM decisions Feed device health, access pattern anomalies, and contextual identity signals into the access stack so policy can respond while a session is active, not only at sign-in.
  • Reduce friction that encourages credential sharing Review where login friction is pushing users toward workarounds that weaken identity assurance.

Bottom line: Compromised credentials and endpoint-originated attacks remain central breach paths, which is why identity controls now have to work beyond the login event.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Identity threat detection and response marks the point where access security becomes a lifecycle discipline. If access is only checked at login, the programme is blind to the period when identity abuse actually unfolds. ITDR changes the governance question from who authenticated to whether that identity remains trustworthy as conditions change, which is why it belongs in IAM, PAM, and NHI governance conversations alike.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: When should organisations prioritise continuous identity over stricter login policies?

A: Organisations should prioritise continuous identity when active sessions, privileged automation, or long-lived machine access create more risk than a stronger initial login can address. If the threat is what happens after authentication, then login-only controls are misaligned. Continuous identity matters most where access can remain dangerous long after it was granted.

👉 Read our full editorial: Identity threat detection and response is becoming central to secure access


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.