Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity and human risk management: what changes for IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Behavior-only human risk programs miss the access side of exposure, and correlating identity, access, and behavioral signals reveals privilege creep, MFA fatigue, and provisioning errors more accurately, according to Living Security Human Risk Management Platform. The practical implication is that human risk scoring now depends on IAM data, not awareness data alone, and access review must become part of risk management.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: The Access Equation: Identity Meets Human Risk

By the numbers:

Questions worth separating out

Q: How should security teams combine identity data with behavioural risk scoring?

A: Start by linking user entitlements, access changes, and authentication events to behaviour telemetry in the same risk model.

Q: Why does privilege creep make human risk programmes less accurate?

A: Privilege creep changes the impact of a user's behaviour even when the behaviour itself stays the same.

Q: How can organisations tell whether MFA fatigue is becoming a control problem?

A: Look for repeated push prompts, approval rates that rise after multiple challenges, and privileged users receiving the same friction as low-risk users.

Practitioner guidance

  • Correlate IAM data with behavioural risk signals Build a single scoring model that combines entitlement breadth, recent access changes, MFA events, and behavioural indicators so security teams can see true exposure rather than isolated alerts.
  • Treat privilege creep as a measurable risk driver Include mover and leaver entitlements in risk review cycles, and escalate any account whose access no longer matches current role, department, or system ownership.
  • Tune MFA controls to reduce fatigue-driven approval risk Review repeated push patterns, throttle noisy prompts, and increase challenge strength when privileged access or anomalous sign-in context is present.

What's in the full article

Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:

  • How the 200+ risk indicators are grouped across identity, behaviour, and threat signals for scoring.
  • The HRMCon 2025 session context and the Labcorp examples behind the correlation approach.
  • How automated interventions are selected for different risk combinations in a live programme.
  • The compliance and audit angle for demonstrating access effectiveness in regulated environments.

👉 Read Living Security Human Risk Management Platform's analysis of identity and human risk correlation →

Identity and human risk management: what changes for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Identity risk cannot be measured correctly without access context. Behavioural signals alone describe intent or reaction, but they do not describe blast radius. When access state is omitted, a low-risk behavioural profile can mask a high-impact identity. Practitioners should treat identity and behaviour as a single risk equation, not parallel programmes.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when identity data is not synchronised?

A: Accountability sits with the team that owns identity governance, because synchronisation is a control outcome, not an optional convenience. If identity data is inconsistent across directories, no downstream application can reliably know which record to trust. That makes identity governance accountable for the failure, even if the symptom appears in authentication.

👉 Read our full editorial: Identity data and human risk management are converging



   
ReplyQuote
Share: