TL;DR: Identity security is shifting from a back-office control to a business enabler as attackers increasingly target identities, third-party access, and privileged pathways, according to SailPoint, and PwC cites a CEO survey showing over half fear their current business model will not be viable in the next decade without transformation. Identity security now has to connect governance, PAM, and access management because business velocity without identity control just expands the breach surface.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “A conversation with PwC: Identity security as a business enabler”.
Key questions
Q: How should security teams govern identity as a control plane?
A: Security teams should treat identity as the layer that decides who can act, how far authority travels, and what context makes an action legitimate.
Q: Why do third-party accounts increase identity risk?
A: Third-party accounts increase risk because they often reach sensitive systems without the same day-to-day scrutiny as internal users.
Q: Where do identity programmes fail when business velocity increases?
A: They fail when access reviews and privilege controls are too detached from real business change.
Practitioner guidance
- Map identity control handoffs Identify where governance, PAM, and access management are disconnected in provisioning, elevation, review, and revocation workflows.
- Inventory third-party identities Create a complete inventory of partner and vendor accounts, then classify them by business system reach, privilege level, and renewal owner.
- Tighten privileged access pathways Review every route that allows elevated access into critical systems, especially where standing privilege or unmanaged exceptions persist.
Bottom line: Identity security is no longer just an access-control function because attackers now target identities, privileged paths, and partner accounts as the shortest route into business systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity security has become the control plane for business risk, not just a control layer for IT risk. When attackers target identities, they are targeting the mechanism that links users, partners, privileges, and business systems. That makes governance, privilege control, and access management part of operational resilience rather than hygiene. The implication is that identity programmes now need to be judged on business continuity impact, not only on compliance coverage.
A question worth separating out:
Q: What does integrated identity security change for PAM and IGA teams?
A: It forces PAM and IGA teams to measure the same thing from different angles: who can reach what, why that access exists, and how quickly it can be removed. The practical shift is from isolated controls to coordinated governance over privileged reach and entitlement sprawl.
👉 Read our full editorial: Identity security is becoming the control plane for business risk