Identity Is the New Perimeter - And Most Enterprises Aren't Ready
.png)
.png)
For two decades, enterprise security strategy rested on one assumption: control what enters and exits your network, and you control your risk. Firewalls defined the boundary. VPNs extended it. Network segmentation reinforced it. Identity, in this model, was a mechanism, a lock on a door rather than a domain of strategic focus. The assumption made sense when organisations operated within a defined perimeter, when applications lived in on-premises data centres, and when the workforce sat behind corporate-managed devices on a corporate-managed network.
None of those conditions hold today, and as they eroded, the assumption failed with them.
In 2026, 79% of cyberattacks involve no malware at all. Adversaries are not breaking through walls. They are walking through doors, using valid credentials, legitimate tools, and trusted access pathways. When the attack vector is identity itself, a security strategy built around perimeter control does not just underperform. It is structurally misaligned with the threat it is meant to address.
Understanding why this shift happened, and what it demands of enterprise security architecture, is no longer optional background for security leaders. It is the central question of modern security governance.
.png)
Palo Alto Networks Unit 42 found identity weaknesses in 90% of the incidents it investigated in 2025, not as a side note but as the primary enabler of each breach. CrowdStrike recorded a breakout time of 51 seconds from initial access to lateral movement. That is faster than most SOC teams can even acknowledge an alert, let alone act on it.
The AiTM problem makes this especially uncomfortable. Adversary-in-the-Middle phishing, which intercepts authentication sessions to bypass MFA entirely, rose 146% year over year. The MFA deployment your organisation spent years rolling out may be providing less protection than the board thinks. Standard TOTP codes are now routinely bypassed by toolkits that sell for a few hundred dollars on dark web marketplaces. Phishing-resistant MFA, such as FIDO2 passkeys and hardware keys, is no longer a future upgrade. It is the current baseline.
Then there is the non-human identity problem that almost nobody is governing properly. Machine identities, including service accounts, API tokens, OAuth credentials, and CI/CD pipeline keys, now outnumber human identities 82 to 1 in the average enterprise. Most IGA programmes were never designed to manage them. They are long-lived, over-privileged, and largely invisible to the access governance process. Some of the most consequential breaches of recent years were enabled not by a phished employee but by an unrotated service account token sitting dormant in a system nobody was monitoring.
From what we see across enterprise environments, the gaps tend to cluster in the same places. Lifecycle management runs on manual tickets rather than automated HR-event triggers, which means a departed employee's access can stay active for weeks. Annual access certifications get treated as compliance formalities rather than genuine governance exercises. And IGA coverage stops at the boundary of modern SaaS applications, while legacy systems such as ERP environments, mainframes, and in-house databases sit completely outside the governance perimeter.
Standing privileged access is another quiet risk that deserves more board-level attention than it gets. Permanent administrator rights, assigned to accounts rather than elevated on demand, are an adversary's preferred persistence mechanism. Just-in-time access models are not complex to implement. They simply require the organisational commitment to treat privileged access as exceptional rather than routine.
Here is a gap many organisations have not fully closed: governing who has access is only half the picture. Knowing when that access is being misused is the other half, and most identity governance programmes stop short of it.
Identity Threat Detection and Response is the discipline that fills this space. ITDR correlates identity context, such as what an account normally does, what privileges it holds, and what risk signals exist from threat intelligence, with real-time behavioural signals. It catches what SIEM and endpoint tools miss: the legitimate account that suddenly authenticates from a new geography, the service account that begins accessing resources it has never touched, the privileged user acting outside their operational baseline. Without this layer, governance tells you what should be happening. ITDR tells you what actually is.
The organisations users trust most are not necessarily those with the largest security budgets. They are the ones that have made a clear architectural decision: identity is the perimeter, and everything flows from that. Phishing-resistant authentication. Automated lifecycle management. Continuous access governance rather than annual. Non-human identity visibility. And ITDR capability that bridges governance and detection.
The adversary community made this transition years ago. Their tactics reflect a deep understanding of identity as the most exploitable attack surface in the modern enterprise. The question is whether defensive investment has caught up.
.png)
.png)
.png)