Insights | Integrity360

What is Identity and why is it critical to cyber security in the age of AI?

Written by Ahmed Aburahal | 28 September 2026, 07:46:29 Z

Cyber security was once built around a clearly defined perimeter. Organisations protected their offices, networks and data centres by controlling what could enter or leave. That model has been transformed by cloud computing, remote working, SaaS applications, mobile devices, third-party access and artificial intelligence.

Today, users can connect to business systems from almost anywhere, while critical data may be spread across numerous cloud platforms and applications. At the same time, employees are no longer the only identities requesting access. Contractors, customers, devices, service accounts, workloads, APIs and AI agents all need to be authenticated, authorised and governed.

This makes identity one of the most important control points in modern cyber security. If an attacker can steal, impersonate or abuse a trusted identity, they may not need to break through an organisation’s traditional defences. They can simply log in.

 

 

What is identity?

Identity is the practice of ensuring that the right people and systems have the right level of access to the right resources at the right time.

It brings together authentication, authorisation, access governance, privileged access controls, identity lifecycle management and threat detection. Its purpose is not simply to manage usernames and passwords, but to understand every identity within an organisation, what it can access, why that access is required and whether its behaviour presents a risk.

A comprehensive identity strategy should cover:

Access Management (AM): Controlling how users authenticate and access applications, systems and APIs.

Identity Governance and Administration (IGA): Managing how identities and permissions are created, changed, reviewed and removed.

Privileged Access Management (PAM): Protecting administrator accounts, service accounts and other highly privileged identities.

Customer Identity and Access Management (CIAM): Securing customer and partner access while delivering a smooth digital experience.

Identity Threat Detection and Response (ITDR): Identifying and responding to credential theft, session hijacking, privilege abuse and unusual identity behaviour.

AI and machine identity: Governing AI agents, applications, devices, workloads and other non-human identities.

Together, these capabilities provide visibility and control across the complete identity lifecycle.

 

 

Why has identity become such an important target?

Attackers have always focused on the routes that offer the greatest chance of success. Instead of deploying easily detected malware or attempting to exploit a heavily protected network perimeter, many now target legitimate accounts, authentication processes and trusted relationships.

CrowdStrike’s 2026 Global Threat Report found that 82% of detections during 2025 were malware-free. This reflects the growing use of legitimate tools, valid credentials and trusted access paths to avoid conventional malware-based detection. The report also found that valid-account abuse was involved in 35% of cloud incidents, demonstrating how valuable, compromised identities have become to attackers.

Once an attacker gains access to a legitimate identity, they may be able to move between systems, escalate privileges, access sensitive information or establish persistence while appearing to be an authorised user. If identity activity is not being continuously monitored, this behaviour can be difficult to distinguish from normal business activity.

The issue is not limited to employee accounts. A compromised administrator account can provide extensive control over an environment, while a poorly governed service account, API key or machine identity may remain active for years without proper oversight. Third-party identities can also create indirect access paths into critical systems.

The traditional perimeter has not disappeared, but identity increasingly determines who or what is allowed through it.

 

 

 

The major identity challenges

Identity sprawl and limited visibility

Most organisations have accumulated a complicated mixture of directories, cloud platforms, applications, legacy systems and identity tools. Different parts of the business may manage access in different ways, making it difficult to build a complete picture of who has access to what.

Without central visibility, dormant accounts, duplicated identities and inconsistent controls can remain hidden. Security teams may not know that a particular identity exists until it is involved in an incident.

Gartner predicts that by 2028, 70% of CISOs will use identity visibility and intelligence capabilities to reduce the IAM attack surface and the risks associated with credential compromise. This reflects the growing need to connect identity information across previously isolated platforms.

Excessive privileges and access creep

People accumulate access as they change positions, join new projects or take on additional responsibilities. Permissions are often added quickly but rarely removed with the same urgency.

Over time, users can retain access they no longer require. This creates privilege creep and toxic combinations, and increases the potential impact of a compromised account. The risk becomes greater when organisations lack effective access reviews, role-based access controls or automated joiner, mover and leaver processes.

Least privilege should be treated as a continuous process, not a one-off configuration exercise. Access must be reviewed regularly and adjusted as roles, risks and business requirements change.

Weak privileged access management

Privileged accounts provide access to the systems, applications and data an organisation depends upon. They are therefore among the most valuable targets for attackers.

Shared administrator accounts, unmanaged service accounts, standing privileges and limited session monitoring can all increase risk. Effective PAM should protect credentials, enforce just-in-time and just-enough access, monitor privileged sessions and provide a reliable audit trail.

The aim is to ensure that elevated access is granted only when it is needed, for a clearly defined purpose and for a limited period.

Unsecure authentication methods

Multi-factor authentication has significantly improved account security, but coverage is often gapped. Legacy applications, service accounts, third-party systems and recovery processes may still rely on weaker methods.

Attackers have also adapted. Adversary-in-the-middle phishing, MFA fatigue attacks, stolen session tokens and social engineering can sometimes bypass conventional authentication controls.

Account recovery represents a particularly important weakness. An organisation may deploy strong phishing-resistant authentication but still allow an attacker to reset access by persuading a service desk employee that they are the legitimate user. Gartner forecasts that by 2028, 30% of organisations will eliminate service desk-led account recovery as they move towards more secure recovery mechanisms.

The growth of non-human identities

Machine identities already outnumber human identities in many technology environments. They include service accounts, applications, workloads, containers, devices, scripts, certificates, secrets and API keys, and lately, AI agents.

These identities are often created rapidly to support development, automation and cloud services, but they may not be subject to the same governance as employee accounts. Ownership can be unclear, credentials may be long-lived and permissions may be broader than necessary.

The adoption of AI agents adds another layer of complexity. An AI agent may be able to access data, communicate with other systems, trigger workflows or perform actions on behalf of a person. Organisations therefore need to understand which agent is acting, who owns it, what information it can access and what decisions it is authorised to make.

Gartner has identified adapting IAM for AI agents as a major cyber security trend, particularly in areas such as identity registration, governance, credential automation and policy-driven authorisation.

Balancing security with user experience

Identity controls sit directly between users and the resources they need. Poorly designed controls can create frustration, reduce productivity and encourage people to seek workarounds.

The answer is not to weaken security. Organisations need context-aware controls that can apply stronger authentication when risk is elevated while allowing low-risk access to remain efficient. Single sign-on, passwordless authentication, adaptive MFA and automated access workflows can reduce friction while strengthening protection.

This is especially important in CIAM environments, where a difficult registration or authentication process can cause customers to abandon a digital service.

How can organisations improve identity?

Effective identity begins with visibility. Organisations need an accurate inventory of human and non-human identities, the accounts connected to them and the access each identity holds.

They should then establish clear ownership and governance across the full identity lifecycle. Joiner, mover and leaver processes should be automated wherever possible, while access reviews should focus on actual business requirements and risk.

Priority actions include:

  • Assess the current identity environment. Identify fragmented systems, weak controls, unmanaged accounts and gaps in governance.

  • Strengthen authentication. Extend MFA coverage and move towards phishing-resistant and passwordless methods where appropriate.

  • Reduce standing privilege. Apply least privilege, just-in-time access and monitored privileged sessions.

  • Automate identity lifecycles. Ensure access is provisioned, adjusted and removed when an individual’s relationship with the organisation changes.

  • Govern non-human identities. Assign ownership, rotate credentials and monitor service accounts, workloads, APIs and AI agents.

  • Monitor identity behaviour. Bring identity telemetry into detection and response processes so suspicious access can be identified and contained quickly.

  • Build a practical roadmap. Prioritise improvements according to business risk, regulatory obligations and operational requirements.

Identity should not be treated as a single technology deployment. It is an ongoing programme involving people, processes, governance and technology.

How Integrity360 can help

Following its acquisition of identity specialist CyberIAM, Integrity360 has established a significant Identity services and solutions practice. The combined expertise includes approximately 120 Identity specialists operating across the UK and South Africa, supporting organisations in highly regulated and complex environments.

Integrity360 provides services across Access Management, Privileged Access Management, Identity Governance and Administration, Customer Identity and Access Management, and emerging AI Identity requirements. Its specialists support the complete identity lifecycle, from initial assessment and strategy through to implementation, optimisation, technical support and managed services.

Identity Advisory Services

Integrity360’s Identity Advisory Services help organisations understand their current environment, identify weaknesses and create a practical improvement roadmap.

These services include comprehensive and streamlined Current State Assessments, Rapid PAM Assessments, identity governance engagements and bespoke strategic advisory services. Assessments can evaluate AM, PAM and IGA individually or as a connected identity ecosystem, with findings benchmarked against recognised standards and frameworks.

For organisations adopting AI, the AI Identity Framework helps define how AI agents and other non-human identities should be classified, owned, governed, monitored and decommissioned. It covers identity lifecycles, access principles, accountability, risk, operating models and a prioritised adoption roadmap.

Identity Professional Services

Integrity360’s Professional Services teams design, implement, modernise and expand identity platforms. Services cover new deployments, legacy modernisation, cloud and Zero Trust initiatives, technology migrations, application onboarding, integrations, workflows and automation.

The team has delivered more than 50 PAM projects, more than 30 IGA projects and over 50 Access Management projects across leading technology platforms. Engagements follow a structured methodology covering discovery, design, build, integration, testing, pilot deployment, rollout and knowledge transfer.

Organisations can also access expert services to expand existing platforms, introduce additional use cases and improve the adoption of technology that has already been deployed.

Identity Support and Managed Services

Identity platforms require ongoing maintenance, specialist knowledge and continuous improvement. Integrity360 offers several flexible service models to meet these requirements.

Expert Services Retainers provide access to specialist identity expertise through pre-purchased service hours. Technical Support Services offer on-demand troubleshooting, diagnosis, debugging, corrective actions and vendor escalation, with defined service levels and 24/7 coverage for critical incidents.

Managed Identity Services provide proactive support across AM, PAM, IGA and CIAM environments. This can include platform health checks, configuration and policy management, connector and backup verification, change management, adoption support, reporting, usage analysis and regular service improvement reviews.

These services act as an extension of internal IAM teams, helping organisations maintain control of complex identity environments while continuing to develop their capabilities.

Make identity a foundation of cyber resilience

Every employee, administrator, customer, contractor, application, device and AI agent represents a potential route to critical systems and information. The challenge is no longer limited to confirming that a username and password are correct. Organisations must continuously understand who or what is requesting access, what it is authorised to do and whether its behaviour can be trusted.

A mature identity programme reduces the opportunities available to attackers while helping people, applications and digital services operate securely and efficiently.

Integrity360 combines strategic advisory, experienced implementation teams and ongoing managed services to help organisations assess, transform and operate their identity environments. Whether the priority is improving governance, securing privileged access, modernising authentication, protecting customer journeys or preparing for AI agents adoption, Integrity360 can provide the expertise and support needed to make identity a central part of cyber resilience.