Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when a password programme leaves…
Governance, Ownership & Risk

Who is accountable when a password programme leaves users exposed to phishing and weak credential reuse?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

Accountability usually sits with security and identity leadership, not end users alone. Teams responsible for IAM, GRC, and security awareness should define baseline controls, choose phishing-resistant factors, and monitor whether users are still exposed to risky login patterns. If the programme lacks measurable protections, accountability extends to the group that approved the control design.

Why This Matters for Security Teams

When a password programme leaves people vulnerable to phishing and credential reuse, the issue is not just user behaviour. It is a control-design problem. Security and identity leaders are accountable for choosing authentication methods that resist common attack paths, defining where passwords remain in scope, and proving that the programme reduces real risk. Current guidance from the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls both point toward stronger assurance, monitoring, and least-privilege design rather than relying on user discipline alone.

The practical failure is that password programmes often measure completion, not protection. If phishing-resistant factors are optional, if reuse remains easy, or if exceptions are unmanaged, the organisation has accepted avoidable exposure. NHIMG research on credential exposure patterns shows how quickly attackers move once secrets are available, which is why weak login controls should be treated as a governance issue rather than a training issue. In practice, many security teams discover this only after a phishing wave or account takeover has already shown the programme was designed around compliance, not resilience.

How It Works in Practice

Accountability normally sits with the leaders who approved the authentication design, the control owners who operate it, and the governance functions that signed off on residual risk. That means IAM, GRC, security engineering, and awareness teams all have a role, but not equal responsibility for the outcome. The right question is whether the programme actually reduces phishing success and credential replay, not whether users clicked through training.

Practitioners should expect the control stack to include:

  • phishing-resistant authentication where feasible, especially for privileged and high-value accounts;
  • central policy that limits password reuse and blocks known-compromised credentials;
  • step-up authentication for risky sign-in attempts and impossible-travel events;
  • logging and review that show whether users still rely on weak paths, such as SMS-only recovery or repeated password resets;
  • clear exception handling so any remaining password-based access is time-bound and justified.

NHIMG’s 2024 Non-Human Identity Security Report found that 88.5% of organisations say their non-human IAM practices lag behind or merely match human IAM, which is a useful warning sign for human programmes too: maturity is often claimed before it is proven. The same pattern appears in user authentication. If the programme allows risky factors because they are easier to roll out, accountability remains with the team that accepted that tradeoff, not with the end user who clicked a phishing link. Controls tend to break down in large hybrid environments with legacy apps, because exceptions multiply faster than enforcement can keep up.

Common Variations and Edge Cases

Tighter authentication often increases friction, so organisations must balance user convenience against account takeover risk. That tradeoff is real, especially where legacy systems, call-centre recovery, or contractor access still depend on passwords. There is no universal standard for every environment yet, but current guidance suggests that teams should measure whether the programme actually reduces phishing success and credential reuse rather than assuming awareness will compensate.

Accountability can shift only in narrow cases. If business leadership explicitly accepts residual risk after being shown the exposure, that acceptance should be documented. If a third-party identity platform is misconfigured, vendor operations may share responsibility, but internal owners still remain accountable for due diligence and control monitoring. For more on the persistence of weak credential patterns, see the Guide to the Secret Sprawl Challenge and the 52 NHI Breaches Analysis, both of which show how weak secret handling becomes a repeatable failure mode.

For baseline identity assurance and policy expectations, teams should align with NIST SP 800-63 Digital Identity Guidelines and treat legacy password exceptions as temporary, not permanent. The hardest edge cases are high-friction enterprise environments where recovery flows are weak and operational owners keep expanding exceptions to preserve convenience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Password reuse and weak auth create the same exposure patterns as poor NHI credential handling.
NIST CSF 2.0PR.AC-1Identity proofing and access control govern who can authenticate and under what conditions.
NIST SP 800-63AAL2Assurance levels map directly to whether passwords alone are acceptable for access.
NIST AI RMFGOVERNAccountability for risky access design is a governance issue, not a user-training issue.
CSA MAESTROGovernance of access controls and runtime trust applies to identity programmes with weak factors.

Reduce reusable credentials and enforce stronger authentication paths for any account that can be phished.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org