Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity visibility and posture: what IAM teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Identity risk response breaks when detection is separated from access context, according to Veza, with CrowdStrike and Verizon cited to show that compromised access and stolen credentials remain the dominant footholds. The practical problem is not more alerts but faster decisions about what an identity can actually reach and change.

NHIMG editorial — based on content published by Veza: identity security posture management and access intelligence for identity risk response

By the numbers:

Questions worth separating out

Q: How should security teams use identity context during incident response?

A: Security teams should use identity context to confirm what an identity can access, whether access is excessive, and whether recent authentication behaviour suggests compromise.

Q: Why do posture tools matter if an organisation already has IAM and PAM?

A: IAM and PAM define intended access, but posture tools reveal how that access looks in practice after drift, stale entitlements, and unmanaged assets are accounted for.

Q: What breaks when identity risk is measured only by alerts?

A: Alert-only monitoring breaks when teams cannot tell whether the identity behind the event has meaningful reach.

Practitioner guidance

  • Map alerts to reachable assets Correlate login anomalies, privilege changes, and device signals with the systems and data the identity can actually touch before opening a major incident.
  • Use posture data in access reviews Bring effective access, not just approved access, into recertification so reviews capture dormant roles, exposed credentials, and risky combinations.
  • Prioritise identities with lateral movement potential Rank human and non-human identities by their ability to pivot across environments, especially where shared privileges, unmanaged devices, or broad roles exist.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • How the Access Graph is used to map what an identity can reach across SaaS, cloud, and infrastructure
  • Examples of the risk-aware automation workflow behind Veza Actions and response decisions
  • The integration framing between Veza and CrowdStrike Falcon for identity threat containment
  • The specific identity posture and access intelligence use cases the vendor highlights for active teams

👉 Read Veza's analysis of identity security posture management and access intelligence →

Identity visibility and posture: what IAM teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Identity visibility is now a response control, not a reporting feature: Security teams no longer get enough value from knowing that an identity is risky. The real question is what that identity can reach across cloud, SaaS, infrastructure, and privileged workflows. That makes identity visibility a decision layer that sits between detection and action, and programmes that still treat it as a dashboard feature are under-using it.

A few things that frame the scale:

  • Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to the 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.

A question worth separating out:

Q: Who is accountable when a compromised identity is not contained quickly?

A: Accountability sits with the teams that own identity governance, access administration, and incident response, because those functions determine whether revocation is possible in time. In practice, the question is whether the organisation can prove that one operator can shut off access across systems before the incident escalates.

👉 Read our full editorial: Identity visibility is the missing layer in identity risk response



   
ReplyQuote
Share: