TL;DR: 51% of identity implemented across European enterprises sits in an unmanaged layer it calls identity dark matter, while 48% of applications store credentials in cleartext and 44% bypass the corporate identity provider, according to Orchid Security. That gap means traditional IAM coverage, not just policy intent, now defines real exposure.
NHIMG editorial — based on content published by Orchid Security: identity dark matter, IAM maturity, and application-level exposure across European enterprises
By the numbers:
- 51% of all identity implemented throughout European enterprises is unmanaged and often invisible.
- 48% of applications store credentials in cleartext.
- 44% of applications have authentication paths that bypass the corporate Identity Provider.
Questions worth separating out
Q: How should security teams find the identities that traditional IAM tools miss?
A: Use continuous discovery across cloud, SaaS, on-premises, and directory sources, then correlate each identity with ownership, entitlements, and last activity.
Q: Why do unmanaged apps and machine identities increase identity risk?
A: Because they can authenticate to critical systems without going through the same lifecycle controls used for human users.
Q: What do organisations get wrong about IAM maturity?
A: They often confuse tool adoption with control coverage.
Practitioner guidance
- Discover identity outside the control plane Build a catalogue of applications that authenticate locally, use alternate login paths, or store credentials outside the corporate identity provider.
- Measure control drift inside applications Continuously test for changes in permissions, protocol use, and access enforcement after patches, upgrades, or mergers.
- Prioritise exposed credential stores and bypass paths Start remediation with cleartext credentials, weak hashing, and authentication flows that bypass the corporate Identity Provider.
What's in the full report
Orchid Security's full article covers the operational detail this post intentionally leaves for the source:
- The application-by-application discovery approach used to surface hidden authentication flows and local identity paths.
- The full checklist of identity control questions for mapping coverage across thousands of applications.
- The detailed breakdown of European identity dark matter findings, including cleartext credentials, IdP bypass, and access-control gaps.
- The remediation workflow that follows discovery, including onboarding and resolution steps across hybrid estates.
👉 Read Orchid Security's analysis of identity dark matter and application-level IAM gaps →
Identity dark matter: what IAM teams are missing in practice?
Explore further
Identity dark matter is not an edge case. It is the operating reality of large application estates. The article's 51% figure shows that more than half of implemented identity can sit outside the governed control plane. That means programme maturity cannot be inferred from IdP coverage alone, because the decisive controls live inside applications. Practitioners should treat application-level identity discovery as a baseline requirement, not an advanced capability.
A few things that frame the scale:
- 51% of all identity implemented throughout European enterprises is unmanaged and often invisible, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how limited many identity programmes remain in practice.
A question worth separating out:
Q: Who is accountable when agent-based identity controls miss an application?
A: Accountability sits with the identity and application owners who approved the operating model, not with the agent alone. If an access path is outside coverage, the organisation still owns the governance gap. Frameworks such as NIST Cybersecurity Framework 2.0 help assign responsibility across identify, protect, and govern functions.
👉 Read our full editorial: Identity dark matter shows why IAM controls miss real exposure