TL;DR: Identity security practitioners still use X as a fast signal channel, but signal quality depends on following the right analysts, researchers, and community voices rather than feed volume, according to Oasis Security. The practical issue is not social media itself, but whether identity teams can turn high-noise commentary into usable context for IAM, NHI, and security decisions.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “TOP 15 Identity Security Accounts to follow on X (formerly Twitter)”.
Key questions
Q: How should identity teams build a useful X watchlist?
A: Start with a small set of accounts that consistently add analysis, incident context, or practitioner experience, then review them against the identity topics your team actually owns.
Q: Why do social media feeds become noisy for IAM and NHI teams?
A: Because they mix promotion, opinion, incident commentary, and research in the same stream.
Q: What do security teams get wrong about following experts on X?
A: They often equate follower counts with authority or assume that frequent posting means useful insight.
Practitioner guidance
- Build a curated identity-security watchlist Include a small number of analysts, practitioners, researchers, and journalists who consistently publish relevant identity commentary, then review the list on a fixed schedule.
- Separate signal from promotion Classify accounts by the kind of value they provide, such as breach context, research depth, or implementation experience, and deprioritise feeds that mainly repost or self-promote.
- Route social insights into governance workflows Capture relevant posts in the same review path you use for incidents, control gaps, and access-risk discussions so they can be validated and acted on.
Bottom line: The article’s core message is that identity teams need curated signal on X, not a larger or noisier feed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Curated social signal is now part of identity governance hygiene. Identity teams cannot rely only on formal reports and quarterly reviews when access patterns, breach commentary, and control failures move faster than governance cycles. A disciplined X watchlist gives practitioners a way to track emerging themes without mistaking volume for value. The implication is that signal curation belongs in programme hygiene, not personal preference.
A question worth separating out:
Q: Should organisations treat X as a source of security intelligence?
A: Yes, but only as an informal signal source that still requires validation. X can help teams spot emerging identity issues earlier, yet any operational change should be confirmed through internal telemetry, incident review, or formal research before it influences policy or control decisions.
👉 Read our full editorial: Identity security voices worth following in a crowded X landscape