Current IAM controls fail because they assume privilege exists long enough to be reviewed, challenged, and removed through human-paced processes. Attackers using valid identities, dormant accounts, or standing access can often exploit that gap before recertification or ticket-based approval has any effect. The issue is not visibility alone, but the mismatch between attack speed and governance speed.
Why human-paced review breaks down against machine-speed identity attacks
IAM review cycles were built for change that can be observed, queued, and challenged by people. That model weakens when attackers use valid identities, dormant accounts, or standing privilege to act inside the window between approval, recertification, and cleanup. The control may still be well designed on paper, but it loses effectiveness when the adversary can complete the abuse path before the next governance checkpoint.
The core failure is temporal, not purely procedural. If a privilege review happens weekly or monthly, it cannot by itself stop access that is created, abused, or pivoted in minutes. That is why lifecycle discipline, privilege reduction, and continuous detection matter together, as shown in NHIMG’s NHI Lifecycle Management Guide and Top 10 NHI Issues, which both emphasise rotation, offboarding, inactivity, and excess access as lifecycle failures rather than isolated admin tasks.
In practice, the attack succeeds when access is treated as durable enough to review later. Standing privilege, stale entitlements, and accounts that remain valid after their purpose has ended create a gap between policy intent and real exposure. A control that depends on a person noticing the problem after the fact is already behind if the attacker can exploit the same identity faster than the review process can invalidate it.
What changes when the attacker already has a valid identity
The difficult part is that these attacks often do not look like a classic compromise at the control boundary. The access may be legitimate from the system’s perspective, which means the attacker can blend into normal authentication and authorization flows. In that case, the decisive question is not whether the identity exists, but whether it still deserves the authority it has been granted.
That is why identity review alone is not enough. Review cycles can confirm that an account was once approved, but they do not guarantee that the access remains necessary, safe, or appropriately bounded at the moment it is used. When the identity is dormant, overprivileged, or reused across systems, the attacker gets a ready-made path that may be invisible until logs or user complaints reveal the impact.
NHIMG’s Identity Threat Detection and Response (ITDR) Guide is useful here because it frames identity abuse as an active attack problem, not just a governance problem. The more an environment relies on valid accounts, the more important it becomes to detect anomalous use, privilege escalation patterns, token abuse, and lateral movement before the next review cycle can intervene.
How to close the speed gap without pretending reviews can do everything
The control objective should be to shrink the time an attacker can safely use an identity, not to assume quarterly recertification can compensate for active abuse. That means reducing standing privilege, shortening the lifetime of high-value access, and using continuous signals to trigger revocation or escalation when usage no longer matches the expected role or workload.
For practitioners, the best mental model is that review is a backstop, not a real-time defence. NHIMG’s Lifecycle Processes for Managing NHIs and Identity Security Programme Guide both point toward the same operating principle, govern the whole identity lifecycle, make ownership explicit, and treat stale access as a live exposure rather than an audit issue to be handled later.
- Shorten the period between privilege grant and meaningful validation for sensitive access.
- Prefer just-in-time or tightly bounded access where the business task allows it.
- Use recertification to remove excess access, not to justify keeping it.
- Escalate any identity that can reach production, admin planes, or secrets stores without a current operational need.
Risk and Threat Considerations
When review cycles lag behind attacker action, the risk is credential abuse, privilege persistence, and quiet expansion of blast radius. The exposure grows fastest where dormant accounts, reused access paths, or standing roles remain valid long after the original business need has passed.
Failure mechanism: The attacker uses a legitimate identity before governance processes can detect that the access is stale, excessive, or no longer justified. Human review arrives after the access has already been exercised, so the control reacts to history instead of preventing the impact.
Impact: Sensitive systems can be reached with apparently valid access, which increases the chance of data theft, lateral movement, privilege escalation, and delayed incident detection. In a fast-moving identity attack, the operational damage is often done long before the next certification window opens.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Stale identities and delayed removal directly drive this review-cycle gap. |
| NHI-05 — Overprivileged NHI | Standing access and excess privilege are the core exposure when attacks outpace review. | |
| NHI-07 — Long-Lived Secrets | Slow review cycles leave durable credentials usable long enough for abuse. | |
| Recommendation — Remove no-longer-needed identities and access before the next attack window opens. Right-size privileges so valid access cannot exceed current business need. Shorten credential lifetime and rotate secrets faster than review cadence. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle and stale access are the mechanism behind review-cycle failure. |
| Recommendation — Continuously inventory, disable, and review accounts with active access. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle controls determine whether access outlives its valid use. |
| AC-2 — Account Management | Account provisioning, monitoring, and removal must outpace attacker use. | |
| Recommendation — Enforce timely issuance, rotation, and revocation of authenticators. Automate account disablement and periodic review for inactive or excessive access. | ||
Practitioner Guidance
What to prioritise: Focus first on identities that can cause immediate production impact, especially privileged accounts, stale accounts, and any access path that can reach secrets, admin consoles, or cloud control planes. If those identities are only checked in periodic review, the review process is already too slow to be your main defence.
What to verify: Confirm that every high-risk identity has an owner, a current business purpose, and a revocation path that is faster than the attacker’s likely dwell time. The useful test is whether access can be reduced or removed between review cycles when behaviour changes.
Practitioner takeaway: Treat recertification as governance evidence, not as a real-time security control, because identity attacks win when the attacker can act faster than the organisation can review.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org