Join our Newsletter — 33% off our NHI Course

Identity threats are beating containment: what should teams fix first?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20707
Topic starter  

TL;DR: SANS’s 2026 identity threats and defenses survey finds that 68% of organisations detect identity attacks within 24 hours but only 55% contain them that fast, while post-authentication abuse, non-human identities and AI agents are driving the sharpest control gaps, according to P0 Security. The gap is no longer detection alone; containment, lifecycle governance and privilege scope now define identity resilience.

NHIMG editorial: based on content published by P0 Security: Resource | Report 2026 SANS State of identity threats and defenses survey insights

By the numbers:

Questions worth separating out

Q: What breaks when identity governance stops at login events?

A: Teams lose visibility into the actions that happen after authentication, including token reuse, secret harvesting, and privilege escalation.

Q: Why do long-lived credentials create more operational risk in multi-environment NHI estates?

A: Long-lived credentials increase risk because they expand the window for misuse, persistence, and lateral movement across cloud, SaaS, and on-premises environments.

Q: How should organisations govern AI systems that need credentials?

A: Organisations should place AI systems inside the non-human identity inventory and assign each one a clear owner, scope, and offboarding path.

Practitioner guidance

  • Measure containment separately from detection Track the time from identity-alert creation to actual restriction of sessions, tokens and delegated permissions.
  • Inventory and assign ownership for every NHI Build a complete register of service accounts, API keys, tokens and certificates, then assign a named owner for rotation, revocation and offboarding.
  • Bind AI agent credentials to task scope Limit agent access to the exact systems, data and actions needed for a specific workflow, and require clear revocation when the workflow ends.

What's in the full report

P0 Security's full report covers the operational detail this post intentionally leaves for the source:

  • Survey methodology behind the 2026 identity threats and defenses findings
  • More granular breakdowns of post-authentication abuse patterns across sessions, tokens and OAuth
  • Additional context on NHI credential rotation failure and AI agent governance maturity
  • The full set of survey insights on where identity resilience is breaking down in practice

👉 Read P0 Security’s report on 2026 identity threats and defenses survey insights →

Identity threats are beating containment: what should teams fix first?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20298
 

Containment has become the real identity-security benchmark: the gap between 68% detection within 24 hours and 55% containment shows that many programmes can see identity abuse faster than they can stop it. That matters because identity incidents now compound after authentication, where tokens, sessions and delegated access keep working. The practitioner conclusion is simple: resilience is defined by how quickly valid access is constrained, not how quickly an alert is raised.

A question worth separating out:

Q: How do you know if an identity programme is actually resilient?

A: A resilient programme can shorten the gap between seeing identity abuse and stopping the identity from acting. If an organisation detects faster than it contains, it still has a post-authentication exposure problem. The practical test is whether sessions, tokens, service accounts and agent credentials can be constrained before damage spreads.

👉 Read our full editorial: Identity threats outpace resilience as NHI and AI governance lag



   
ReplyQuote
Share: