Insights
Thinking
Real incidents, industry research, and our perspective on identity architecture.
The Reality
Identity by the numbers
The data is clear. Identity is the primary attack surface, and most organizations aren't ready.
79%
of initial-access attacks are malware-free
Up from 40% five years ago. Attackers do not need malware when they have your credentials.
CrowdStrike GTR 2025 ↗67%
of ransomware victims tie the incident to their most significant identity attack
Sophos State of Identity Security 2026, 5,000 organisations surveyed across 17 countries.
Sophos Identity Security 2026 ↗95%
of organisations have experienced a browser-based attack
Palo Alto Networks research. The browser is where most work happens and where most attacks land — the policy enforcement point belongs there.
Palo Alto / Cybersecurity Dive ↗41%
of successful human logins use breached passwords
Cloudflare network telemetry. Roughly half of legitimate logins are indistinguishable from credential-stuffing — design CIAM accordingly.
Cloudflare Research 2025 ↗98%
of cloud-identity permissions are never used
Sysdig 2024 Cloud-Native Security and Usage Report. Over-permissioned service accounts and machine identities are the cleanest attack surface a credential thief could ask for.
Sysdig 2024 Report ↗8.5M
Windows devices knocked offline by a single faulty update
CrowdStrike Falcon, 19 July 2024 — confirmed by Microsoft. Identity-recovery paths that depend on the same control plane that fails are not recovery paths.
Microsoft Blog (Jul 2024) ↗Identity Incidents
The Evidence
Real incidents that demonstrate why identity architecture matters. Every one was preventable.
5.5M
ADT: Vishing → Okta SSO → Salesforce, 5.5M Records
Voice phishing of a help-desk operator compromised Okta SSO credentials. The attacker walked into Salesforce as a legitimate user and exfiltrated 5.5 million customer records. No malware, no zero-day, no credential stuffing — just a phone call.
Source: ADT 8-K filing / BleepingComputer reporting
78.6M
Rockstar Games: Snowflake Breach via Third-Party Anodot Tokens
ShinyHunters stole authentication tokens that the analytics vendor Anodot held for its customers' Snowflake environments. The attacker queried Rockstar Games' data warehouse using those tokens — looking, to Snowflake, like a normal analytical workload. Over a dozen Anodot customers were caught in the same wave.
Source: TechCrunch / Help Net Security
$150M
LastPass Breach Leads to $150M Crypto Theft Years Later
Federal prosecutors linked a $150M cryptocurrency heist to the 2022 LastPass breach. Seed phrases stored in Secure Notes were compromised.
Source: KrebsOnSecurity
Microsoft Entra ID July 2024 Outage: The IdP as Single Point of Failure
A regional Azure / Entra ID disruption in July 2024 blocked sign-ins for thousands of tenants. Microsoft 365, third-party SSO apps, and downstream services that federated to Entra ID all degraded together — exactly because they federated.
Source: Microsoft service health post-mortem
8.5M
CrowdStrike Falcon Outage: When Identity Recovery Also Goes Down
A single Falcon sensor content update bricked an estimated 8.5 million Windows endpoints worldwide. The recovery story exposed a quieter problem: identity recovery paths assume the endpoints, MFA devices, and IdP integrations are all working.
Source: CrowdStrike Preliminary Post-Incident Review
165
Snowflake: 165 Customers Breached via Stolen Credentials
Threat actor UNC5537 used infostealer-harvested credentials to access 165 Snowflake customer environments. 80%+ had prior credential exposure. None had MFA.
Source: Mandiant / Google Cloud
Non-Human & AI Identity
The Expanding Surface
Service accounts, API keys, tokens, and AI agents now outnumber human identities by a wide margin. Most are unmanaged.
45:1
The Governance Vacuum Around AI and Non-Human Identity
A Cloud Security Alliance whitepaper finds non-human identities outnumber humans roughly 45 to 1, rising as high as 144 to 1 in cloud-native estates, while only about 15% of organisations feel highly confident they can prevent an NHI-based attack. AI agents make the gap qualitatively worse.
Source: Cloud Security Alliance
29M
GitGuardian Secrets Sprawl 2026: 29M New Secrets, AI Keys Up 81%
29 million new hardcoded secrets reached public GitHub in 2025 — the largest single-year jump GitGuardian has recorded. Leaks tied to AI services rose 81% year-over-year, with 1.27 million AI-service credentials exposed.
Source: GitGuardian — State of Secrets Sprawl 2026
67%
AI Agents Are the New Non-Human Identity Problem
Sophos's 2026 identity research names weak management of non-human identities — especially the AI agents now multiplying across enterprises — as a primary driver of identity breaches. Two thirds of ransomware victims in the survey traced the incident back to an identity attack.
Source: Sophos / OWASP NHI Top 10 / CSA
ASI03
OWASP's Agentic Top 10 Names Identity Abuse a Core Risk
The OWASP GenAI Security Project's Top 10 for Agentic Applications gives autonomous AI agents a dedicated security benchmark. Identity and Privilege Abuse (ASI03), driven by credential leakage that expands an agent's scope, is named a top category.
Source: OWASP GenAI Security Project
25-50x
Non-Human Identity Is Now Its Own IAM Discipline
KuppingerCole's first Leadership Compass for Non-Human Identity Management treats NHI as a distinct, fast-maturing market segment in its own right, not a feature of workforce IAM. NHIs already outnumber human identities by 25 to 50 times.
Source: KuppingerCole
45B+
Agentic AI: The New Frontier of Identity Risk
The WEF highlights that AI agents autonomously spawn NHIs in security blind spots. Only 10% of executives have a strategy for managing AI identities.
Source: World Economic Forum
Frameworks
Through the Identity Lens
Compliance frameworks read for the identity controls that decide whether the rest works. Authoritative sources linked on each page.
European Union
NIS2
Identity is a NIS2 risk-management measure, an incident-reporting input, and a supply-chain control all at once.
European Union
DORA
DORA is where identity stops being IT plumbing and becomes board-reported operational resilience.
International
ISO 27001
ISO 27001 is the management-system spine that an identity programme can hang on — the controls live in Annex A, but the discipline lives in the system.
United States
SOC 2
SOC 2 is a controls report for your customers, and identity is the largest single control area in it.
European Union
GDPR
Identity is how the data subject is recognised, how their rights are enforced, and how a personal-data breach is detected.
United States
SOX
SOX is where access to financial systems becomes a public-filing risk and weak identity becomes a material weakness.
United States
HIPAA
HIPAA puts identity at the centre of every ePHI access decision — and at the centre of every breach notification when an attacker gets through.
International
PCI DSS
PCI DSS v4.0 raised the identity bar materially — phishing-resistant MFA, scripted user management, and continuous validation are no longer aspirational.
International
NIST CSF 2.0
NIST CSF 2.0 is the framework most other frameworks reference. For identity, it is where the Govern, Identify, Protect, and Respond functions land most heavily.
Industry Research
The Numbers
Key findings from the industry's most authoritative security reports.
22%
Verizon DBIR 2026: Credentials Still #1, Infostealers Industrialised
The 2026 Verizon Data Breach Investigations Report keeps credentials at the top of the initial-access list for the second year running. 88% of web-application attacks use stolen credentials. Infostealers compromised 30% of corporate and 46% of unmanaged devices holding company credentials.
Source: Verizon
71%
Sophos 2026: 71% of Organisations Hit by an Identity Breach
Sophos surveyed 5,000 IT and cybersecurity leaders across 17 countries for its State of Identity Security 2026. 71% suffered at least one identity-related breach in the previous year, with an average of three incidents. 67% of ransomware victims confirmed the incident started with an identity attack.
Source: Sophos — State of Identity Security 2026
99%+
Microsoft: Phishing-Resistant MFA Stops 99%+ of Identity Attacks
Microsoft's Digital Defense Report confirms phishing-resistant MFA (FIDO2/passkeys) stops over 99% of identity attacks. 97% of attacks are password spray.
Source: Microsoft
$4.81M
Credential Breaches Cost $4.81M and Take 292 Days to Detect
Credential-based breaches are the most common, most expensive, and slowest to detect. The worst possible combination.
Source: IBM / Ponemon Institute
47%
Google Cloud: 47% of Cloud Incidents From Weak Credentials
Weak or absent credentials account for nearly half of all cloud compromises. Identity is the dominant cloud attack surface.
Source: Google Cloud Security
18B
SpyCloud 2025: 18 Billion Stolen Credentials Tracked
SpyCloud's intelligence platform tracks credentials harvested by infostealer malware and aggregated into the criminal ecosystem. The 2025 report puts cumulative tracked credentials past 18 billion, with infostealer-derived corporate credentials a fast-growing slice.
Source: SpyCloud Annual Identity Exposure Report
Analyst Insights
The Market View
What Gartner, Forrester, and the major analyst firms are saying about identity security.
KuppingerCole: IAM 2026 and the Rise of AIdentity
KuppingerCole's Research Compass for IAM 2026 advances the Identity Fabric architecture and positions AI as increasingly integral to identity itself. The firm's framing of autonomous, AI-driven identity systems for managing high-volume machine identities puts architecture, not product, at the centre.
Source: KuppingerCole Research Compass (AN82012)
$27.5B
Forrester: IAM Investment to Double to $27.5B by 2029
IAM spending is projected to nearly double from $13.4B (2024) to $27.5B by 2029, driven by machine identity and AI governance needs.
Source: Forrester Research
KuppingerCole Leadership Compass: The ITDR Market Takes Shape
KuppingerCole's November 2025 Leadership Compass on Identity Threat Detection and Response (LC81209, Alejandro Leal) is a vendor comparison of a market that, three years ago, did not have a name. The category's existence is itself the finding worth reading.
Source: KuppingerCole Leadership Compass (LC81209)
IDC FutureScape 2025: Identity Spending to Outpace Network by 2027
IDC's FutureScape research projects that identity-security spending will exceed traditional network-security spending in the enterprise budget mix by 2027. The shift tracks the move of the security perimeter from network to identity.
Source: IDC FutureScape — Worldwide Future of Trust
40%
Gartner: Over 40% of Agentic AI Projects Cancelled by 2027
Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating costs, unclear business value, or inadequate risk controls. The same firm names agentic AI its headline strategic technology trend. Both can be true at once.
Source: Gartner press release (Jun 2025)
KuppingerCole: What CIAM Has to Mean in 2025
KuppingerCole's session on how to do CIAM in 2025 and beyond, led by analyst John Tolbert, defines customer identity broadly: not a login box, but registration, consent, fraud signals, progressive profiling, and identity assurance across the full customer relationship.
Source: KuppingerCole webinar (John Tolbert)
ATLAS Apex Perspective
Our View
Our take on identity architecture, resilience, and the discipline behind the controls. Written in-house, not assembled from analyst summaries.
Identity Recovery Is Its Own Workflow
Most disaster-recovery plans assume identity will be working when the rest of the estate is not. That assumption fails the first time identity itself is the affected service — which now happens every quarter.
Source: ATLAS Apex perspective
The Browser Is the New Endpoint
The endpoint is no longer the place enterprise work happens. The browser is. The control surface that used to live on the device — DLP, posture, session controls, identity-aware enforcement — has to live where the work runs.
Source: ATLAS Apex perspective
Architecture Survives Incidents. Configurations Do Not.
Most identity incidents do not have a root cause in the platform configuration. They have a root cause in the architectural assumption the configuration was implementing.
Source: ATLAS Apex perspective
Identity Mesh Beats Identity Federation
Federation is the old framing: one IdP at the centre, downstream relying parties consuming its decisions. Identity Mesh is the working framing for what is now actually in production: many identity services and the signals between them, composed into a control plane.
Source: ATLAS Apex perspective
The Okta Tenant Resilience Gap
Identity tenants get treated like SaaS — "the vendor will look after it" — until the day a configuration mistake, an insider action, or a token compromise needs to be undone. By then the recovery options are weeks of forensics or a fresh tenant.
Source: ATLAS Apex perspective
Have a perspective to share?
We're always interested in conversations about identity architecture. If you have a view, we'd like to hear it.
Start a Conversation