TL;DR: Identity failures still dominate breach paths, with 22% of incidents involving stolen credentials overall and 88% of basic web app attacks using them, while organisations needed 241 days on average to detect and contain breaches, according to StrongDM’s 2025 breach statistics. The control gap is not perimeter strength but the combination of credential governance, detection speed, and third-party access control.
Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “35+ Alarming Data Breach Statistics for 2026”.
By the numbers:
- In 2025, the mean time to identify was 181 days and the mean time to contain was 60 days, for 241 days end-to-end.
- In 2025, 22% of breaches involved stolen credentials overall.
- In basic web app attacks, 88% used stolen credentials.
Key questions
Q: What breaks when compromised credentials are still accepted by identity systems?
A: When compromised credentials are still accepted, detection becomes a post-exploitation signal rather than a control.
Q: Why do breaches with valid credentials stay active for so long?
A: Because detection and containment are separate problems, and both can fail.
Q: What are the signs that third-party access controls are failing in practice?
A: Common warning signs include broad or stale tokens, undocumented permission changes, open endpoints, inconsistent documentation, and vendor activity that blends into routine system traffic.
Practitioner guidance
- Tighten credential lifecycle controls Reduce password reuse, enforce stronger authentication for high-risk access, and revoke exposed credentials immediately when compromise is suspected.
- Map and shrink standing privilege Inventory privileged accounts, service accounts, and vendor access paths, then remove access that is no longer tied to an active business purpose.
- Shorten breach detection and containment loops Use identity-focused telemetry to confirm which accounts, tokens, and sessions are active so responders can isolate abused access faster.
Bottom line: Identity failures, not perimeter failure alone, continue to drive a large share of modern breaches because stolen credentials still work.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Credential reuse remains the most practical breach primitive: The article’s numbers show that stolen credentials still dominate real-world intrusion paths, which means identity controls are failing at the point of trust. Password hygiene, reuse prevention, and privileged access limits are not background issues; they are the front line. When 88% of basic web app attacks use stolen credentials, the control question becomes whether authentication is actually proving possession, not merely recognising a known secret.
A question worth separating out:
Q: How do IAM teams reduce blast radius after a cloud credential exposure?
A: IAM teams reduce blast radius by combining least privilege, short-lived credentials, and fast revocation with continuous monitoring. They should also verify whether the exposed identity can enumerate storage, assume roles, or impersonate analytics users. If the access scope is broad, the response must include permission reduction, not only rotation.
👉 Read our full editorial: Data breach statistics show identity controls still fail at scale