TL;DR: Attackers usually choose the cheapest path, according to Expel’s webinar-based analysis of 300 CISOs and CFOs, while identity incidents still dominated 68.6% of events and 52.3% were blocked by basic controls such as MFA and conditional access. The security case for finance is now about measurable risk reduction, business enablement, and the cost of leaving fundamentals unfinished.
NHIMG editorial — based on content published by Expel: the second part of its CISO-CFO webinar series on security ROI and basic controls
By the numbers:
- Identity attacks made up 68.6% of incidents in Expel’s 2026 Annual Threat Report.
- Over half of identity attacks, 52.3%, were blocked by MFA and conditional access policies.
- Only 23% of companies say their cybersecurity metrics are well understood by top executives.
Questions worth separating out
Q: What breaks when identity controls are only documented and not executed consistently?
A: When identity controls exist only on paper, the organisation loses the ability to prevent or promptly detect bad access, missed approvals, and offboarding gaps.
Q: Why do basic identity controls often outperform advanced threat tooling?
A: Basic identity controls outperform advanced tooling because they interrupt the most common attack paths before compromise spreads.
Q: How can security teams know if cloud identity governance is actually working?
A: The clearest signals are fewer unresolved access findings, shorter evidence-collection cycles, lower counts of stale keys, and reduced reliance on manual review.
Practitioner guidance
- Baseline identity control coverage first Inventory MFA, conditional access, managed-device enforcement, onboarding, and offboarding coverage across all business units.
- Translate control performance into avoided-loss metrics Report identity security as blocked compromise attempts, reduced exception counts, and faster offboarding rather than abstract maturity scores.
- Audit configuration drift across access policies Compare approved identity policy baselines with actual enforcement in production, including tenant-specific overrides and legacy exceptions.
What's in the full article
Expel's full article covers the operational detail this post intentionally leaves for the source:
- How the webinar participants framed security ROI for CFO audiences, including the language that made budget discussions land.
- The full breakdown of identity, endpoint, cloud, and third-party control examples that illustrate where fundamentals most often fail.
- The survey context from 300 CISOs and CFOs, including how the research was used to support the business-case argument.
- The broader CISO-CFO communication model that Expel and SMBC used to connect security controls to business enablement.
👉 Read Expel's analysis of how boring security controls drive cybersecurity ROI →
Boring security controls: what finance leaders actually fund?
Explore further
Boring controls are still the dominant risk-reduction lever in identity security. The market often rewards sophisticated narratives, but most real-world compromise still starts with weak authentication, stale access, or policy gaps. For IAM and PAM leaders, that means the highest-value work is usually the least glamorous work, because it reduces the attack paths that adversaries actually use.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: Who is accountable when identity risk causes measurable business impact?
A: Accountability sits with the teams that own identity governance, privileged access, and security risk decisions, not with the alerting tool alone. Organisations should define who can translate identity findings into financial exposure, who approves remediation, and who is responsible for containment when a privileged identity is compromised.
👉 Read our full editorial: Boring security controls deliver the clearest cybersecurity ROI