A programme is underperforming when confidence is high but incidents, breaches, or weak control adoption keep appearing. Warning signs include repeated cyber events, patching gaps, poor access control, and uneven implementation across business units. If organisations report strong preparedness but still experience frequent compromise, the security model is not matching the real threat environment.
How confidence can diverge from control reality
Leaders can feel confident because dashboards look stable, audits are passing, or a few headline controls have been implemented. Underperformance shows up when those signals do not line up with lived outcomes: incidents keep recurring, risk exceptions keep accumulating, and teams can describe the programme in positive terms without being able to show that exposure is actually shrinking.
A useful warning sign is the gap between declared capability and observable behaviour. If patching remains inconsistent, access reviews do not change permissions, or control adoption varies widely across business units, the programme may be performing as a reporting function rather than a risk-reduction function.
That gap is often visible in the control layer itself. For example, only 5.7% of organisations have full visibility into their service accounts, which is a reminder that confidence in governance can coexist with very limited operational visibility.
Signs the programme is not keeping pace with the threat
Repeated compromise is the clearest signal that the programme is underperforming. If the same weaknesses reappear, or if teams keep finding the same classes of issues after each remediation cycle, then the organisation is not absorbing lessons into durable control change.
Look for evidence that the control model is not matching how the environment is actually used. Common signs include inconsistent patch latency, weak or stale access entitlements, secrets left in vulnerable locations, and uneven implementation of baseline controls across cloud, application, and operational teams.
- Incidents continue despite “mature” governance language.
- Critical remediation work is delayed, deferred, or repeatedly accepted as exceptions.
- Business units interpret standards differently and apply controls unevenly.
- Metrics report activity, but not reduction in exposure.
The persistence of exposed secrets is especially telling. NHIMG research notes that 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, a pattern that usually reflects control failure rather than one-off mistakes. See the broader context in NHI Mgmt Group’s Ultimate Guide to NHIs and The 2025 State of NHIs and Secrets in Cybersecurity.
Risk and Threat Considerations
When confidence outpaces actual control performance, the main risk is blind accumulation of exposure. Attackers do not need the programme to fail everywhere, they only need the neglected parts, the stale exceptions, or the weakly governed assets that leadership is least likely to inspect.
Failure mechanism: The programme optimises for assurance signals, such as policy coverage or completed reviews, instead of reducing real attack surface. That allows known weaknesses, weak access control, and delayed remediation to persist until they are exploited.
Impact: The organisation can become predictable to attackers, with repeated compromise, broader blast radius, and slower detection of control failure. In practice, high confidence can make underperformance harder to challenge because the evidence of failure is fragmented across teams and systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | Programme underperformance is a risk-management failure in practice. |
| ID.IM — Improvement | Recurring issues and uneven adoption indicate weak continuous improvement. | |
| PR.AC — Access Control | Poor access control is a direct sign that the programme is underperforming. | |
| Recommendation — Align programme metrics to risk reduction outcomes, not activity counts. Use lessons learned to drive measurable control changes and close repeat gaps. Review and enforce access decisions so excess permissions are removed promptly. | ||
| CIS Controls v8 | 5 — Account Management | Stale or excessive access and poor recertification show weak account governance. |
| 7 — Continuous Vulnerability Management | Repeated patching gaps are a classic indicator that remediation is not working. | |
| 6 — Access Control Management | Weak access control adoption across business units signals inconsistent enforcement. | |
| Recommendation — Audit accounts regularly and remove inactive or excessive access. Track remediation speed and verify vulnerabilities are actually closed. Standardise access control enforcement and verify exceptions are shrinking. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Secrets stored outside managed vaults are a concrete sign of control underperformance. |
| NHI-02 — Least Privilege and Permission Management | Excessive permissions are a direct manifestation of weak programme enforcement. | |
| NHI-05 — Lifecycle and Offboarding | Failure to revoke or rotate long-lived access shows poor lifecycle control. | |
| Recommendation — Move secrets into managed stores and measure the reduction in exposed credential locations. Reduce standing privilege and recertify permissions until excess access is eliminated. Enforce offboarding and rotation deadlines for all long-lived credentials. | ||
Practitioner Guidance
What to verify: Do not trust programme health claims until you can connect them to outcome data, such as time-to-remediate, repeated issue recurrence, access reduction after reviews, and the percentage of critical assets covered by enforced controls.
Common mistake: Treating passed audits, policy approvals, or executive optimism as proof that the programme is effective. Those are useful inputs, but they are not substitutes for evidence that exposure is shrinking and that weak controls are not being recycled from one cycle to the next.
What practitioners underestimate: Inconsistent execution is often more dangerous than missing policy. A programme with uneven adoption across business units can look mature centrally while leaving the most exposed parts of the environment effectively unmanaged.
Practitioner takeaway: A credible programme should change risk conditions, not just produce reassuring reports, so the key test is whether incidents, exceptions, and weak controls are trending down in the same places leadership believes are already covered.
Related resources from NHI Mgmt Group
- What are the signs that a cybersecurity programme is being reshaped by regulatory pressure?
- What are the signs that a NIST Cybersecurity Framework programme is still immature?
- Why does ransomware still create major business risk even when security teams feel more confident in their defenses?
- What are the signs that a vulnerability testing programme is not giving security leaders enough decision support?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org