TL;DR: Identity now sits at the center of enterprise attack paths, with Arcon arguing that fragmented stacks, standing privilege, machine identity sprawl, and cloud entitlement complexity will make old perimeter assumptions increasingly brittle. The practical shift is toward continuous, policy-driven governance where access, telemetry, and privilege control operate as one system.
NHIMG editorial — based on content published by Arcon: Identity is no longer just IAM, it's the new security perimeter
By the numbers:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
Questions worth separating out
Q: What breaks when identity governance relies only on access reviews?
A: Access reviews assume the reviewable state is a stable entitlement that reflects real risk.
Q: Why do non-human identities complicate zero trust architecture?
A: Because zero trust assumes access can be verified continuously, yet many machine identities are created for automation, reused widely, and left in place long after their original purpose ends.
Q: How do security teams know whether JIT access is actually reducing risk?
A: Look for shorter credential lifetime, fewer always-on permissions, and lower exposure of credentials in code, pipelines, and runtime environments.
Practitioner guidance
- Inventory identity sprawl across all actor types Build a single inventory of human users, service accounts, workload identities, API keys, tokens, and privileged third-party access.
- Convert standing privilege into task-scoped elevation Prioritise administrative accounts and third-party access paths that remain active outside a defined business task.
- Centralise identity telemetry for detection and response Correlate authentication, entitlement changes, token use, and session behaviour in the same monitoring workflow.
What's in the full article
Arcon's full outlook covers the operational detail this post intentionally leaves for the source:
- The full 2026 prediction set behind each identity trend, including converged platforms, JIT, ITDR, machine identities, and continuous entitlement intelligence.
- The source article's own breakdown of how identity telemetry, privilege elevation, and session oversight fit together in day-to-day operations.
- Additional context on the practical shift from periodic compliance to continuous control.
- The article's closing summary of how identity becomes a structural security foundation rather than a supporting function.
👉 Read Arcon's 2026 identity security outlook →
Identity as the perimeter in 2026: what should IAM teams change?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity has become the security perimeter because the old perimeter no longer contains the attack path. The article is right to treat identity as the control plane that now mediates access to cloud, SaaS, and critical systems. Once attackers can move through legitimate credentials, the distinction between network boundary and identity boundary collapses. Practitioners should treat identity governance as the primary enforcement layer, not a supporting control.
A few things that frame the scale:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
A question worth separating out:
Q: Who is accountable when privileged access controls fail in cloud environments?
A: Accountability usually sits with the identity, platform, and cloud operations teams together, because the failure spans authentication, role design, and secret handling. Governance frameworks such as the NIST Cybersecurity Framework 2.0 expect control ownership to be explicit. If no team owns the full path from grant to revocation, the gap persists.
👉 Read our full editorial: Identity becomes the security perimeter in 2026 and beyond