The Identity Economy: Why Every Modern Attack Starts With Trust

The Identity Economy: Why Every Modern Attack Starts With Trust

Ten years ago, organisations invested primarily in protecting networks.

Five years ago, the focus shifted to devices, endpoints, and cloud infrastructure.

Today, the asset under constant attack is something far less visible: identity.

Most modern cyberattacks no longer begin by exploiting a vulnerability in a firewall or server. They begin with legitimate credentials, trusted sessions, or authenticated access.

Attackers rarely break in anymore. They log in.

Identity Has Become the New Perimeter

Cloud adoption, SaaS platforms, remote work, third-party integrations, APIs, and now AI agents have fundamentally changed how organisations operate. The traditional network perimeter has gradually disappeared, replaced by thousands of interconnected identities that enable everyday business.

Microsoft’s 2025 Digital Defense Report, based on telemetry from more than 600 million daily attacks, illustrates how dramatic that shift has become. Identity compromise now sits at the centre of the modern threat landscape, while most initial access broker activity relies on stolen or abused credentials rather than sophisticated exploits.

The perimeter did not disappear.

It simply moved from infrastructure to identity.

The Identity Economy

Every organisation now depends on an ecosystem of identities.

Employees are only one part of it. Contractors, suppliers, privileged accounts, service accounts, API keys, OAuth tokens, certificates, cloud workloads and AI agents all require identities to operate.

The surprising reality is that people are no longer the majority.

Industry estimates suggest that non-human identities already outnumber human users by as much as one hundred to one. Large enterprises routinely manage hundreds of thousands of machine identities, many of them holding privileged access to critical systems.

Yet visibility has not evolved at the same pace.

Many organisations know exactly how many employees they have. Far fewer can confidently answer how many service accounts, API keys or machine credentials exist across their environments, who owns them, or whether they are still required.

That gap has quietly become one of cybersecurity’s largest attack surfaces.


Attackers Realised This Before Defenders Did

Some of the most disruptive incidents in recent years were not driven by sophisticated malware or previously unknown vulnerabilities.

They were driven by trust.

At MGM Resorts, attackers simply convinced the help desk to reset an employee’s credentials after gathering publicly available information. The result was ransomware, widespread operational disruption and losses estimated at around $100 million.

The Snowflake breaches followed a similarly familiar pattern. Attackers gained access using valid credentials that had often remained unchanged for years. More than 160 organisations were ultimately affected, including AT&T, Santander and Ticketmaster.

Neither incident demonstrated a failure of perimeter security.

Both demonstrated what happens when trusted identities are compromised.

AI Is Changing the Economics of Identity Attacks

Artificial intelligence is not replacing traditional identity attacks.

It is making them dramatically easier to execute at scale.

Voice cloning has made help desk impersonation more convincing. Large language models generate phishing emails that no longer resemble the poorly written scams organisations trained employees to recognise. Deepfake video has introduced entirely new forms of executive fraud. Automated tooling continuously improves credential stuffing and password spraying campaigns.

What previously required experienced operators can increasingly be automated, personalised and deployed at industrial scale.

The barrier to entry is falling while the quality of attacks continues to improve.

The Bigger Challenge Isn’t People

Ironically, the greatest identity risk today often has little to do with employees.

Machine identities now authenticate continuously across cloud platforms, applications, containers and AI systems. They rarely take holidays, rarely change passwords voluntarily and often accumulate privileges over time.

As organisations experiment with AI agents, the problem grows even faster. Every useful AI system needs access to data, applications and internal services. To perform meaningful work, those agents must inherit permissions from someone.

That creates a new class of identities operating continuously and at machine speed.

Most organisations are still learning how to inventory them, let alone govern them.

Identity Security Needs to Evolve

For years, identity security focused on authentication.

Verify the user.

Require multi-factor authentication.

Grant access.

That model is becoming insufficient.

Modern identity security is increasingly centred on continuous verification rather than a single login event. Behavioural analytics, risk-based authentication, session monitoring, just-in-time privilege management and identity intelligence are becoming as important as passwords and MFA ever were.

The question is no longer whether someone authenticated successfully.

The question is whether their behaviour still deserves trust.

This Is No Longer Just a Security Problem

Identity compromise now translates directly into operational disruption, financial loss and regulatory exposure.

The Verizon Data Breach Investigations Report 2026 found that half of ransomware victims with a known credential leak were compromised within just 95 days. Europol’s latest IOCTA report describes stolen credentials and infostealer malware as one of the primary engines of today’s cybercriminal economy.

There is now a mature marketplace where one group steals identities, another sells access, and a third carries out the intrusion.

Credentials have become a commodity.

Long before an organisation is deliberately targeted, its identities may already be circulating through criminal marketplaces.

Conclusion

Cybersecurity spent decades protecting infrastructure.

The next decade will be defined by protecting trust.

Modern organisations are no longer built around networks. They are built around identities, permissions and relationships between people, machines and services. That is where business happens, and increasingly, that is where attacks begin.

Most security programmes still invest heavily in vulnerabilities, endpoints and infrastructure. Those investments remain essential, but they no longer tell the whole story.

An attacker using legitimate credentials often bypasses every control designed to stop someone breaking in.

Because they never needed to break in at all.

They simply logged in.

Get your pass

The most exclusive Cyber Security EVENTS in the world.

Exclusive C-level cybersecurity gatherings across Europe. Limited seats, maximum impact.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security · East Central
Main Conference Ticket
€495
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. September 30, Belgrade.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Workshops — Sold Separately
Workshop 1 Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans. Participants work through actual compliance gaps, build a self-assessment framework, and leave with a prioritised action list — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Capacity
Limited seats
Workshop 2 Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment. Participants map their own shadow AI exposure and build a proportionate governance framework.
Time
11:15 – 13:15
Format
Masterclass + case analysis
Duration
2 hours
Capacity
Limited seats
Workshop 3 Chapter 3 · Vendor Dependency & Sovereignty
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations. Participants conduct a structured dependency audit, evaluate viable European alternatives, and leave with a vendor risk strategy that is operationally grounded.
Time
13:15 – 15:15
Format
Masterclass + structured audit
Duration
2 hours
Capacity
Limited seats
Workshop 4 Chapter 4 · Cybercrime in a Borderless Threat Landscape
Cross-Border Cybercrime: What Private Sector Security Leaders Need to Know
A practitioner-led masterclass bridging private sector incident response and the realities of cross-jurisdictional law enforcement. Participants learn how cybercrime investigations unfold across borders and how to build an incident posture that works with — not against — public sector constraints.
Time
15:30 – 17:30
Format
Masterclass + Q&A
Duration
2 hours
Capacity
Limited seats
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials