TL;DR: Identity security spending topped $18.5 billion in 2024, yet account compromise remains the most common attacker entry point and over 800 million stolen credential sets were added this year, according to Gartner and the source article. Legacy, fragmented controls keep organisations reactive when modern identity threats demand proactive containment.
NHIMG editorial — based on content published by Silverfort: Identity security v2 and the case for proactive control
By the numbers:
- Despite spending more than $18.5 billion on identity security products in 2024, identity remains the most common entry point for attackers.
- This year alone, there have been over 800 million new sets of stolen credentials compromised as a result of the explosion of infostealers.
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
Questions worth separating out
Q: How should security teams reduce account takeover risk in digital identity programmes?
A: They should treat takeover as a lifecycle problem, not only an authentication problem.
Q: Why do identity security programmes keep falling behind account compromise?
A: Because many programmes still optimise for compliance and operational convenience instead of real-time security control.
Q: What problem does ownership attribution solve for service accounts and API keys?
A: It closes the gap between exposure detection and accountable remediation.
Practitioner guidance
- Define a control-plane target state Document where identity policy must be enforced at the point of authentication, not only in downstream reviews or incident response.
- Reduce standing privilege first Prioritise the accounts with the broadest reach, including admin accounts, service accounts, and API credentials that remain valid beyond a single task.
- Block legacy and insecure authentication paths Identify protocols, trust sources, and login flows that allow access without modern policy checks.
What's in the full article
Silverfort's full article covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of the Identity Security v1 to v2 argument and the business case behind it.
- The specific control examples used to illustrate deny-by-default identity policy in practice.
- The article's explanation of how identity teams can move from fragmented tools to measurable control.
- The surrounding context on why account compromise persists even with higher identity security spend.
👉 Read Silverfort's analysis of why identity security v2 is needed now →
Identity security v2: are your controls keeping up with account compromise?
Explore further