Join our Newsletter — 33% off our NHI Course

Identity threat detection and response: what the new funding means

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Its €2.5 million pre-seed extension, backed by financial-sector investors including Criteria Venture Tech and Bankinter, reflects the growing view that identity is now the primary attacker entry point and that regulated environments need faster detection, response, and compliance alignment, according to 8Layers. Identity governance is shifting from periodic checks to continuous visibility across sessions, service accounts, and cloud identities.

Editorial analysis by NHI Mgmt Group, based on content published by 8Layers: “We raised €1M more. Here's how we'll use it to keep solving the problem from the core”.

Key questions

Q: How should security teams detect identity attacks when attackers are already inside valid sessions?

A: Security teams should look for deviations in behavior rather than relying only on authentication success.

Q: Why do service accounts and administrator accounts need different governance than human logins?

A: Because they are designed for different runtime patterns.

Q: What are the signs that an identity programme is too audit-focused?

A: A programme is too audit-focused when it can explain access after the fact but cannot see abuse forming in real time.

Practitioner guidance

  • Map identity telemetry to real attack paths Correlate credentials, sessions, service accounts, and cloud resources as one chain so that abuse can be seen in context rather than as isolated alerts.
  • Separate posture controls from detection controls Use posture to reduce standing exposure and use runtime detection to catch identity abuse that still gets through, especially in regulated environments.
  • Build compliance evidence from live identity state Align technical identity baselines with audit requirements so the same control data can support security operations and framework alignment.

Bottom line: 8Layers frames identity as the primary attack surface, with credentials, sessions, and service accounts driving the shift toward runtime detection.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Identity threat detection has become a governance problem, not just a monitoring problem: The article is really describing a shift from static access oversight to runtime identity control. When credentials, sessions, and service accounts are the primary attack surface, periodic review alone cannot keep pace with abuse that unfolds between review cycles. Practitioners should read this as a signal that identity visibility now has to operate continuously, not only during audit windows.

A question worth separating out:

Q: What should organisations do when AI agents start using machine identities to act independently?

A: They should treat the agent as a governed non-human identity with runtime guardrails, not just an automation feature. That means constraining issued credentials, monitoring behaviour, and revoking access quickly when the agent acts outside its intended scope or accesses unfamiliar systems.

👉 Read our full editorial: 8Layers funding signals demand for identity threat detection and response



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.