TL;DR: IBM’s 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million and shows phishing, social engineering, and valid-account abuse still dominate initial access, according to Enzoic’s analysis. The real issue is that successful authentication can no longer be treated as proof of trust, because compromised credentials can behave like legitimate users for months.
NHIMG editorial — based on content published by Enzoic: The Rising Cost of Trusted Access Credential Screening
By the numbers:
- The global average cost of a data breach reached $4.99 million in IBM’s 2026 report, up 12% year over year.
- The average time to identify and contain a breach increased to 247 days, reversing a five-year downward trend.
- Breaches involving valid-account abuse averaged $5.07 million and took 243 days to identify and contain.
Questions worth separating out
Q: How should security teams limit access after credentials are compromised?
A: Security teams should use identity-based policies that constrain what the compromised identity can reach across applications, APIs, services, and data.
Q: Why does valid-account abuse increase breach costs so much?
A: Because it suppresses the signals teams rely on to spot intrusions.
Q: How can organisations tell whether trusted access is still trustworthy?
A: By combining lifecycle screening with behavioural monitoring.
Practitioner guidance
- Reassess trust after authentication Treat successful login as a starting signal, not a trust decision.
- Expand credential screening to the lifecycle Screen credentials at creation, on reset, and continuously after issuance so new exposure data can trigger revocation, reset, or additional controls before abuse persists.
- Tighten help desk and recovery verification Add stronger identity proofing and callback rules for password resets, MFA re-enrolment, and account recovery because those paths are frequent social-engineering targets.
What's in the full article
Enzoic's full analysis covers the operational detail this post intentionally leaves for the source:
- IBM 2026 breach-cost breakdowns by attack vector and lifecycle duration for board-level reporting.
- The article’s discussion of credential screening at creation, reset, and continuous monitoring across the credential lifecycle.
- Practical interpretation of valid-account abuse costs and why trusted access remains hard to distinguish from legitimate use.
- The relationship between AI-driven impersonation, phishing scalability, and identity control failure points.
👉 Read Enzoic’s analysis of trusted access and the IBM 2026 breach-cost findings →
Trusted access abuse and rising breach costs: what IAM teams need to know?
Explore further
Trusted access is now a lifecycle problem, not a point-in-time authentication problem. IBM’s data reinforces a basic identity truth: a credential can be valid at login and compromised an hour later. That means the security question is no longer only whether access was issued correctly, but whether it still deserves trust at the moment it is used. IAM programmes that treat authentication as a one-time control miss the lifecycle risk that attackers exploit.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
A question worth separating out:
Q: What should IAM teams prioritise to reduce phishing-driven account abuse?
A: Strengthen recovery flows, step-up verification, and post-authentication monitoring before focusing on broader policy changes. The most effective controls are the ones that stop a stolen credential from becoming sustained access with legitimate-looking behaviour.
👉 Read our full editorial: Trusted access is the new breach cost multiplier in identity security