TL;DR: Identity security spending topped $18.5 billion in 2024, yet account compromise remains the most common attacker entry point and over 800 million stolen credential sets were added this year, according to Gartner and the source article. Legacy, fragmented controls keep organisations reactive when modern identity threats demand proactive containment.
NHIMG editorial — based on content published by Silverfort: Identity security v2 and the case for proactive control
By the numbers:
- Despite spending more than $18.5 billion on identity security products in 2024, identity remains the most common entry point for attackers.
- This year alone, there have been over 800 million new sets of stolen credentials compromised as a result of the explosion of infostealers.
- 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
Questions worth separating out
Q: How should security teams reduce account takeover risk in digital identity programmes?
A: They should treat takeover as a lifecycle problem, not only an authentication problem.
Q: Why do identity security programmes keep falling behind account compromise?
A: Because many programmes still optimise for compliance and operational convenience instead of real-time security control.
Q: What problem does ownership attribution solve for service accounts and API keys?
A: It closes the gap between exposure detection and accountable remediation.
Practitioner guidance
- Define a control-plane target state Document where identity policy must be enforced at the point of authentication, not only in downstream reviews or incident response.
- Reduce standing privilege first Prioritise the accounts with the broadest reach, including admin accounts, service accounts, and API credentials that remain valid beyond a single task.
- Block legacy and insecure authentication paths Identify protocols, trust sources, and login flows that allow access without modern policy checks.
What's in the full article
Silverfort's full article covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of the Identity Security v1 to v2 argument and the business case behind it.
- The specific control examples used to illustrate deny-by-default identity policy in practice.
- The article's explanation of how identity teams can move from fragmented tools to measurable control.
- The surrounding context on why account compromise persists even with higher identity security spend.
👉 Read Silverfort's analysis of why identity security v2 is needed now →
Identity security v2: are your controls keeping up with account compromise?
Explore further
Identity Security v2 is a control-plane shift, not a tool refresh. The article is right that layered detection and isolated remediation are not enough when attackers treat identity as the fastest route into the environment. Security teams need a model where authentication policy, privilege scope, and trust boundaries are enforced continuously. The practitioner conclusion is that identity must operate as a runtime control plane, not a cleanup queue.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when identity risk causes measurable business impact?
A: Accountability sits with the teams that own identity governance, privileged access, and security risk decisions, not with the alerting tool alone. Organisations should define who can translate identity findings into financial exposure, who approves remediation, and who is responsible for containment when a privileged identity is compromised.
👉 Read our full editorial: Identity security v2 means control before compromise, not after