Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should organisations respond when consumer behaviour does…
Identity Beyond IAM

How should organisations respond when consumer behaviour does not change after a breach?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Identity Beyond IAM

They should not assume customers will materially change passwords, devices, or authentication habits after an incident. The safer response is to strengthen risk-based authentication in the highest-risk channels, because breach awareness alone rarely reduces takeover risk. Security teams should use behavioural and contextual signals to raise assurance where it matters most, while preserving a workable customer experience.

Why customer behaviour should not drive the response

Post-breach communication rarely produces a dependable shift in consumer security habits. Many users will not change passwords, enrol stronger factors, or alter device behaviour quickly enough to reduce takeover risk at the point where the business is most exposed. The practical response is to assume the old behaviour persists and to compensate in the transaction path, not to wait for customer self-correction.

That is why the control decision belongs in the NIST Cybersecurity Framework 2.0 style of risk-based governance: identify where customer accounts are most likely to be abused, protect those paths more aggressively, and adapt assurance dynamically rather than uniformly. It also fits the incident pattern seen in the 52 NHI Breaches Report, where compromise often persists because defenders rely on one-time remediation instead of durable control changes.

A useful operational statistic here is that Zacks breach exposed 12M customer records including credentials, which underscores a common reality: breach notification alone does not neutralise stolen-data reuse or downstream account abuse. The response needs to target the fraud and takeover pathways that remain active after disclosure.

Where to concentrate control after disclosure

The highest-value move is to strengthen risk-based authentication in the channels that matter most, such as account recovery, password reset, device enrolment, high-value payments, profile changes, and support-assisted identity proofing. These are the places where an attacker can convert leaked data into durable account control, so they deserve tighter contextual checks than ordinary logins.

  • Raise assurance only when the transaction is sensitive, unusual, or high impact.
  • Use behavioural and contextual signals, such as device continuity, IP reputation, session history, velocity, and geography, to decide when step-up is justified.
  • Keep the stronger controls focused on takeover-prone paths so the wider customer journey stays usable.

For identity teams, the same logic is consistent with NIST Cybersecurity Framework 2.0 and with implementation guidance in the NIST Privacy Framework, because both reward proportionate safeguards that reduce harm without over-collecting or over-challenging every user. Where transaction risk is highest, step-up should be the default response, not a blanket password-reset campaign.

Breaches that expose credentials also justify treating exposed access material as operationally relevant, not just informational. NHIMG’s Ultimate Guide to Non-Human Identities is useful background on why secret exposure, rotation failure, and overprivilege produce long-tail access risk that notification does not remove.

What practitioners should verify before they trust the control

Risk-based authentication only works if the rules reflect actual fraud and takeover conditions. Teams should verify that the scoring model is tuned to the channels where abuse happens, that false positives are tolerable for legitimate customers, and that recovery flows cannot be bypassed by weaker assurance than the primary login path.

What to verify: confirm that step-up is triggered by meaningful signals, that the highest-risk actions are protected consistently, and that exception handling does not quietly recreate the original weakness. If the model challenges users but still lets attackers pivot through support, email reset links, or stale devices, the control has failed in practice.

Practitioner takeaway: after a breach, do not measure success by whether customers say they will change behaviour; measure it by whether the highest-risk account actions now require stronger, context-aware assurance than before.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernBreach response needs risk-based control decisions and governance over high-risk customer paths.
PR.AA — Identity Management, Authentication and Access ControlThe answer centres on strengthening authentication where customer account abuse is most likely.
DE.CM — Continuous MonitoringBehavioural and contextual signals require ongoing monitoring to detect suspicious account activity.
Recommendation — Prioritise risk-based controls for the customer journeys most exposed to takeover. Apply adaptive authentication on high-risk channels and sensitive actions. Use monitoring signals to trigger step-up when session or device risk changes.
CIS Controls v86.3 — Access Control ManagementSensitive account actions need tighter access decisions after a breach.
5.1 — Account ManagementAccount recovery and lifecycle paths are common takeover points after credential exposure.
8.5 — Account Monitoring and ControlBehavioural signals and anomaly detection are core to risk-based authentication.
Recommendation — Restrict high-risk account operations with stronger access checks. Harden recovery and account-change workflows against abuse. Monitor account behaviour and escalate assurance on suspicious activity.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org