A year ago, at Oktane, BeyondID released The Identity Economy Report, our most comprehensive research to date on how identity gaps fuel cybercrime. We argued that identity evolved from just being the attack surface of the modern enterprise to the currency attackers used to move, escalate, and monetize their access.
One year later, we have receipts.
The predictions held and, in many ways, they were conservative. The threat landscape has continued to evolve faster than most organizations can respond. So, this year, we’re doing what any honest researcher should do: we’re revisiting the data, reporting what we got right, what surprised us, and raising the stakes for what comes next.
What We Got Right
Our 2025 research identified three fault lines that were quietly widening beneath enterprise security programs:
The Confidence Paradox hasn’t been resolved, it’s deepened
We found that 85% of security leaders believed they could detect an identity-related breach within 24 hours. Fewer than 30% governed their non-human identities. That gap hasn’t closed. If anything, the rapid adoption of AI agents in 2025 and 2026 has made it worse. Enterprises that felt secure because they had deployed SSO and MFA discovered that those controls don’t extend to the service accounts, bots, and autonomous agents now embedded in their workflows.
Orphaned identities became primary attack vectors
Back in 2025, we highlighted orphaned identities, those forgotten accounts that stay active long after an employee leaves or a project wraps up, as a major, underappreciated risk. Most security teams knew these accounts existed but assumed they were harmless, low-priority issues. Recent events have proven that attackers see things differently. Over the past year, orphaned service accounts and over-permissioned legacy integrations have surfaced in breach after breach, acting as the perfect launching pad or pivot point for devastating network intrusions.
SSO misconfigurations remained a durable, exploitable gap
We spent a significant portion of the Identity Economy report on SSO as a concentration risk. Organizations treat SSO as a security win, and attackers treat it as a master key. That dynamic hasn’t changed, but the blast radius has grown as more applications federate into identity platforms without adequate review of the trust relationships being established.
What Surprised Us
Three things emerged in 2025-2026 that we didn’t fully anticipate in our original research:
The identity-chained attack became the dominant threat pattern
The attack pattern that defined this past year didn’t look like the identity breaches of 2022 or 2023. The new pattern is sequential, not singular: adversaries compromise a human identity, use it to reach a service account with broader permissions, then pivot to an AI agent or automated workflow with system-level access, all within a single kill chain, often within hours. Each step looks like legitimate activity. By the time the anomaly is detected, the damage is done.
AI adoption accelerated the compliance gap faster than anyone modeled
Security leaders surveyed in 2025 were already struggling to govern their non-human identities. Then the pace of AI agent deployment doubled, then tripled. The compliance posture that looked borderline acceptable in early 2025 looks dangerously inadequate in mid-2026. The tools exist to address this,. Tthe will and, in many cases, budget authorization hasn’t kept pace.
The perimeter between ‘our agents’ and ‘their agents’ is already blurring
We anticipated enterprises struggling to govern their own AI agents. What we didn’t fully model was the cross-organizational dimension: partners, vendors, and SaaS platforms deploying agents that interact with enterprise systems. The trust boundary that identity programs were built around is dissolving faster than governance frameworks can adapt.
What’s Coming in 2027
Based on our ongoing research and the patterns we’re seeing in real enterprise deployments, here is what we believe will define the identity threat landscape in 2027:
- Identity-chained attacks will become industrialized: The attack pattern described above will be commoditized and packaged into exploit kits targeting common enterprise identity configurations. The window for organizations to build detection and response capabilities for this pattern is now, not after the first breach.
- Regulatory accountability will arrive before many organizations are ready: The EU AI Act enforcement, SEC cybersecurity disclosure requirements, and emerging US federal AI governance standards will collectively demand that organizations demonstrate auditable identity governance for autonomous systems. Many will find their current programs don’t meet the bar.
- The non-human identity ratio will flip: In many enterprise environments, non-human identities will outnumber human identities before the end of 2027. Governance programs built for human-scale identity populations are not designed for this. The organizations that invested in NHI lifecycle management in 2025 and 2026 will have a structural advantage. Those that didn’t will be scrambling.
- Post-quantum migration timelines will be compressed: NIST’s post-quantum cryptography standards are finalized. Government compliance timelines are set. Private-sector pressure will follow. Identity infrastructure elements like certificates, tokens, and federation protocols will all need to be quantum resistant. The planning horizon is shorter than most security leaders realize.
What to Do Before 2027
We’ll be sharing our full updated research at Oktane this year, including new data on how the identity threat landscape has evolved and a framework for 2027 readiness. But for security leaders who don’t want to wait, here is where to start:
- Audit your non-human identities now. Not next quarter. Now. You cannot govern what you haven’t inventoried.
- Extend your access review processes to include AI agents and service accounts. If your access reviews only cover human identities, they are covering less than half of your actual attack surface.
- Stress-test your SSO trust relationships. Review every application federated into your identity platform and ask whether the trust relationship is still warranted and appropriately scoped.
- Build detection for lateral movement that starts at a human identity and pivots to a non-human one. Most SIEM rules were written for human behavior patterns. Agents behave differently and adversaries know it.
The Identity Economy isn’t a concept we coined for a research report. It’s the operating reality of modern enterprise security. Identity is how attackers move. Identity governance is how you stop them.
We’ll see you at Oktane.










