TL;DR: Identity systems are now being bypassed through help desk resets, replayed session tokens, and unmanaged machine or agent identities, according to Newcore’s analysis of recent breaches and governance gaps. The old model assumes a human-first, perimeter-backed population, but that assumption no longer holds and the control plane has become the target.
NHIMG editorial — based on content published by Newcore: Identity Security Attack Surface and the changing core of identity
Questions worth separating out
Q: What breaks when account recovery can be used as an attack path?
A: When recovery is easier to trigger than to verify, attackers can turn support into an identity issuance channel.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect.
Q: How do security teams know whether session governance is actually working?
A: They should test whether sessions can only be created after strong authentication, whether privileged accounts are reauthenticated at sensitive steps, and whether abnormal session use is visible in logs.
Practitioner guidance
- Harden help desk recovery workflows Move account recovery into a privileged workflow with step-up verification, callback restrictions, approval logging, and post-action review.
- Treat session tokens as sensitive secrets Inventory where tokens are stored, logged, copied, or attached to support cases, then restrict access and shorten their useful lifetime.
- Build continuous discovery for non-human identities Create a living inventory of service accounts, API keys, certificates, and agent principals across cloud and directory systems.
What's in the full article
Newcore's full analysis covers the operational detail this post intentionally leaves for the source:
- How the Secure Split Key approach changes trust assumptions in provider-hosted identity systems
- The article's discussion of discovery across human and agentic identities already present in the stack
- The specific way Newcore positions agent identity as a first-class principal in delegated workflows
- The operational distinction the vendor draws between support recovery, session trust, and platform compromise
👉 Read Newcore's analysis of identity core failure paths and agentic trust →
Identity core design: are your controls keeping up with attackers?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity core design is now the control plane attackers want, not just the place where users sign in. The article is right to treat identity as the centre of the attack surface rather than a background utility. Once support, token handling, and discovery failures all point to the same layer, IAM becomes a primary security control, not an administrative service. That changes procurement, governance, and ownership decisions across human IAM and NHI programmes alike, because the identity core must now be treated as a defended system.
A few things that frame the scale:
- The 2024 ESG report found that 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
A question worth separating out:
Q: Who is accountable when a support process creates the breach?
A: Accountability sits with the identity governance owner, the help desk process owner, and the security team that approved the recovery design. If a reset or token handling flow can create access beyond intent, it is not merely an operations issue. It is a control failure that belongs in IAM and risk governance.
👉 Read our full editorial: Identity core design is failing human, NHI and agentic threat models