Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity coverage gaps: why investigations and audits stall


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: Identity investigations often stall because ownership, entitlement scope, and recent change history must be assembled manually across disconnected systems, and Hydden argues that this hidden work can stretch response times to a day and a half while regulated filings demand answers in hours. The real gap is assumed coverage, not logging volume: identity recordkeeping has to be continuous, queryable, and available where analysts already work.

NHIMG editorial — based on content published by Hydden: Assumed identity coverage leaves investigations and reporting behind

By the numbers:

Questions worth separating out

Q: What breaks when identity coverage is assumed rather than continuously recorded?

A: When coverage is assumed, teams can see individual systems but cannot answer identity questions without manual reconstruction.

Q: Why do identity investigations take longer than endpoint investigations?

A: Identity investigations are usually about authorisation state, not activity.

Q: How can organisations tell whether identity assurance is actually working?

A: Look for consistency across onboarding, recovery, and re-verification events.

Practitioner guidance

  • Inventory account ownership explicitly Record the owning department, business purpose, and review date for every service account and make that metadata queryable during incident response and audit.
  • Unify entitlement resolution across systems Resolve what an account can reach across directories, applications, and resource layers before an investigation starts.
  • Preserve change history as access changes happen Capture entitlement and ownership changes continuously rather than relying on periodic snapshots.

What's in the full article

Hydden's full analysis covers the operational detail this post intentionally leaves for the source:

  • How Hydden structures identity answers across directories, applications, and operational teams
  • The workflow design behind queryable ownership, entitlement, and change-history lookups
  • How the approach supports incident response and audit timelines without adding another console
  • Why the platform is being positioned as a system of record for identity operations

👉 Read Hydden's analysis of assumed identity coverage and investigation delay →

Identity coverage gaps: why investigations and audits stall?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Assumed identity coverage is a governance failure, not a tooling gap. The article shows that organisations often believe they can answer identity questions because each system appears visible in isolation. That assumption breaks when the account spans multiple directories, applications, or ownership domains, because the answer has to be assembled manually. The practical conclusion is that identity governance must be measured by answerability, not by tool count.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to the same research.

A question worth separating out:

Q: How should security teams structure identity reports for audit evidence?

A: They should structure reports as governed evidence assets, not ad hoc exports. That means versioning each audit-period report, preserving historical snapshots, and ensuring the output can be reproduced without manual spreadsheet edits. The report should map directly to the control question being tested, whether that is access review, privileged access, or joiner-mover-leaver change history.

👉 Read our full editorial: Assumed identity coverage leaves investigations and reporting behind



   
ReplyQuote
Share: