The Identity Economy: Why Every Modern Attack Starts With Trust

The Identity Economy: Why Every Modern Attack Starts With Trust

The Identity Economy: Why Every Modern Attack Starts With Trust — Next IT Security

Ten years ago, organisations invested primarily in protecting networks.

Five years ago, the focus shifted to devices, endpoints, and cloud infrastructure.

Today, the asset under constant attack is something far less visible: identity.

Most modern cyberattacks no longer begin by exploiting a vulnerability in a firewall or server. They begin with legitimate credentials, trusted sessions, or authenticated access.

Attackers rarely break in anymore. They log in.

Identity Has Become the New Perimeter

Cloud adoption, SaaS platforms, remote work, third-party integrations, APIs, and now AI agents have fundamentally changed how organisations operate. The traditional network perimeter has gradually disappeared, replaced by thousands of interconnected identities that enable everyday business.

Microsoft’s 2025 Digital Defense Report, based on telemetry from more than 600 million daily attacks, illustrates how dramatic that shift has become. Identity compromise now sits at the centre of the modern threat landscape, while most initial access broker activity relies on stolen or abused credentials rather than sophisticated exploits.

The perimeter did not disappear.

It simply moved from infrastructure to identity.

The Identity Economy

Every organisation now depends on an ecosystem of identities.

Employees are only one part of it. Contractors, suppliers, privileged accounts, service accounts, API keys, OAuth tokens, certificates, cloud workloads and AI agents all require identities to operate.

The surprising reality is that people are no longer the majority.

Industry estimates suggest that non-human identities already outnumber human users by as much as one hundred to one. Large enterprises routinely manage hundreds of thousands of machine identities, many of them holding privileged access to critical systems.

Yet visibility has not evolved at the same pace.

Many organisations know exactly how many employees they have. Far fewer can confidently answer how many service accounts, API keys or machine credentials exist across their environments, who owns them, or whether they are still required.

That gap has quietly become one of cybersecurity’s largest attack surfaces.


Attackers Realised This Before Defenders Did

Some of the most disruptive incidents in recent years were not driven by sophisticated malware or previously unknown vulnerabilities.

They were driven by trust.

At MGM Resorts, attackers simply convinced the help desk to reset an employee’s credentials after gathering publicly available information. The result was ransomware, widespread operational disruption and losses estimated at around $100 million.

The Snowflake breaches followed a similarly familiar pattern. Attackers gained access using valid credentials that had often remained unchanged for years. More than 160 organisations were ultimately affected, including AT&T, Santander and Ticketmaster.

Neither incident demonstrated a failure of perimeter security.

Both demonstrated what happens when trusted identities are compromised.

AI Is Changing the Economics of Identity Attacks

Artificial intelligence is not replacing traditional identity attacks.

It is making them dramatically easier to execute at scale.

Voice cloning has made help desk impersonation more convincing. Large language models generate phishing emails that no longer resemble the poorly written scams organisations trained employees to recognise. Deepfake video has introduced entirely new forms of executive fraud. Automated tooling continuously improves credential stuffing and password spraying campaigns.

What previously required experienced operators can increasingly be automated, personalised and deployed at industrial scale.

The barrier to entry is falling while the quality of attacks continues to improve.

The Bigger Challenge Isn’t People

Ironically, the greatest identity risk today often has little to do with employees.

Machine identities now authenticate continuously across cloud platforms, applications, containers and AI systems. They rarely take holidays, rarely change passwords voluntarily and often accumulate privileges over time.

As organisations experiment with AI agents, the problem grows even faster. Every useful AI system needs access to data, applications and internal services. To perform meaningful work, those agents must inherit permissions from someone.

That creates a new class of identities operating continuously and at machine speed.

Most organisations are still learning how to inventory them, let alone govern them.

Identity Security Needs to Evolve

For years, identity security focused on authentication.

Verify the user.

Require multi-factor authentication.

Grant access.

That model is becoming insufficient.

Modern identity security is increasingly centred on continuous verification rather than a single login event. Behavioural analytics, risk-based authentication, session monitoring, just-in-time privilege management and identity intelligence are becoming as important as passwords and MFA ever were.

The question is no longer whether someone authenticated successfully.

The question is whether their behaviour still deserves trust.

This Is No Longer Just a Security Problem

Identity compromise now translates directly into operational disruption, financial loss and regulatory exposure.

The Verizon Data Breach Investigations Report 2026 found that half of ransomware victims with a known credential leak were compromised within just 95 days. Europol’s latest IOCTA report describes stolen credentials and infostealer malware as one of the primary engines of today’s cybercriminal economy.

There is now a mature marketplace where one group steals identities, another sells access, and a third carries out the intrusion.

Credentials have become a commodity.

Long before an organisation is deliberately targeted, its identities may already be circulating through criminal marketplaces.

Conclusion

Cybersecurity spent decades protecting infrastructure.

The next decade will be defined by protecting trust.

Modern organisations are no longer built around networks. They are built around identities, permissions and relationships between people, machines and services. That is where business happens, and increasingly, that is where attacks begin.

Most security programmes still invest heavily in vulnerabilities, endpoints and infrastructure. Those investments remain essential, but they no longer tell the whole story.

An attacker using legitimate credentials often bypasses every control designed to stop someone breaking in.

Because they never needed to break in at all.

They simply logged in.

Related coverage: This article is part of our Supply Chain & Zero Trust coverage.
APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials