TL;DR: Palo Alto Networks’ $25 billion acquisition of CyberArk confirms that identity controls now sit at the center of breach prevention, according to Bravura Security, with Verizon’s 2025 DBIR showing stolen credentials in 22% of breaches and 88% of web application breaches. Identity governance is no longer a supporting layer; it is the perimeter control plane.
Editorial analysis by NHI Mgmt Group, based on content published by Bravura Security: “Why the Palo Alto CyberArk Deal is a Game-Changer in IAM Cybersecurity”.
By the numbers:
- Stolen credentials remained the single most common initial attack vector in 22% of breaches, according to Verizon's 2025 DBIR cited by Bravura Security.
- 88% of web application breaches involved the use of stolen credentials, according to Verizon's 2025 DBIR cited by Bravura Security.
- 60% of breaches involved a human element, including stolen passwords, phishing clicks, or misuse of access, according to Verizon's 2025 DBIR cited by Bravura Security.
Key questions
A: Perimeter tools lose most of their value once an attacker has valid authentication, because the session looks legitimate.
Q: Why do privileged accounts create outsized breach risk?
A: Privileged accounts can change configurations, access sensitive data, and disable controls, so a single compromise often has disproportionate impact.
Q: How can security teams tell whether an identity platform is actually reducing governance risk?
A: Look for fewer manual exceptions, faster propagation of role changes, and auditable evidence that matches the real change event.
Practitioner guidance
- Inventory privileged identities across the estate Create a single view of human admins, service accounts, API keys, and other non-human identities that can exercise elevated access.
- Reassess standing privilege and entitlement sprawl Review which accounts retain persistent elevation after the task, project, or role that justified them has ended.
- Tie identity events to response workflows Ensure authenticated access anomalies, privilege changes, and unusual session behaviour feed directly into incident triage.
Bottom line: The article frames identity, not perimeter tooling alone, as the main control plane for modern breach prevention.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity has become the control boundary that determines whether perimeter security matters at all. When attackers can authenticate as a legitimate user, many network defenses are bypassed before they start. That shifts the real security question from blocking entry to governing trust, privilege, and session scope across every identity type. Practitioners should treat identity as the first policy boundary, not a downstream control.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- 42% of machine identities have privileged access and 61% of organisations lack identity security controls for cloud workloads, according to CyberArk's 2025 Identity Security Landscape.
A question worth separating out:
Q: Should organisations treat human and non-human SaaS access the same way?
A: They should apply the same governance standard, even if the operational details differ. Human users, service accounts, and application identities can all accumulate excess permissions, so approval, review, and revocation discipline should cover each of them. The key difference is frequency and automation, not whether least privilege applies at all.
👉 Read our full editorial: Palo Alto CyberArk deal reframes identity as the new perimeter