SASIGNAL ATLASCross-industry intelligence / Research desk
SIGNAL ATLAS / RESEARCH DESK

Identity is the contested perimeter, and machine identities now dominate it

Signal report · Cybersecurity & digital trust · Original Phase 1 research

Identity is the contested perimeter, and machine identities now dominate it

Cybersecurity & digital trust · Sector 04 (rank 10 of 25) · T-04-01
Score 86.1/100 · Evidence factor 0.80 · Confidence high · triangulated · Last verified 2026-09-15

In one sentence. Identity compromise — stolen credentials, session-token theft, help-desk social engineering and MFA bypass — remains the attack path defenders spend most on, even though the 2026 Verizon DBIR recorded stolen credentials slipping to second place behind vulnerability exploitation for the first time in nineteen years.

Why it matters

Identity is where the sector's money, its M&A and its breach post-mortems all converge, so it sets the reference architecture every other control has to fit. A buyer who treats identity as a directory problem rather than an entitlement-and-session problem will keep paying for detection of attacks that authorised themselves.

What is happening

Identity compromise — stolen credentials, session-token theft, help-desk social engineering and MFA bypass — remains the attack path defenders spend most on, even though the 2026 Verizon DBIR recorded stolen credentials slipping to second place behind vulnerability exploitation for the first time in nineteen years. What changed in 2026 is the denominator: the population being authenticated is now overwhelmingly non-human. Palo Alto Networks, launching its Idira identity platform in May 2026, cited machine and AI identities outnumbering humans 109 to 1 and 61% of privileged access still granted as standing privilege. The category's capital markets verdict came in February 2026 when Palo Alto closed its acquisition of CyberArk, the privileged-access incumbent.

First observable signal. MGM/Caesars help-desk social engineering (Sept 2023) and the CISA/FBI Scattered Spider advisory AA23-320A (Nov 2023) established that a competent attacker no longer needs malware. The machine-identity leg is newer: Okta's non-human identity announcements (April 2025) and CyberArk's absorption into Palo Alto (Feb 2026).

Evidence

Claim Type Date Source
Stolen credentials fell to the second-ranked initial access vector in the 2026 DBIR, displaced by vulnerability exploitation at 31%, the first such change in 19 years fact 2026-05-19 Verizon (B)
Machine and AI identities outnumber human identities 109 to 1, and 61% of privileged access requests are fulfilled with standing rather than just-in-time privilege marketing 2026-05-12 Palo Alto Networks (B)
Palo Alto Networks completed its acquisition of CyberArk on 2026-02-11 at $45.00 cash plus 2.2005 PANW shares per CyberArk share, explicitly framed around securing 'every identity — human… fact 2026-02-11 Palo Alto Networks (A)
Phishing was the initial access vector in roughly 60% of ENISA's curated EU incident set for July 2024-June 2025 fact 2025-10-01 European Union Agency for Cybersecurity (A)
Business email compromise cost US complainants $3.046bn across 24,768 complaints in 2025 fact 2026-04-01 FBI Internet Crime Complaint Center (A)

Where sources disagree

  • Primary initial access vector — Verizon DBIR 2026: Vulnerability exploitation 31%, credentials second vs ENISA Threat Landscape 2025: Phishing ~60% of incidents; vulnerability exploitation 21.3%. Likely reason: Different populations and definitions: DBIR counts confirmed breaches contributed by IR firms, insurers and law enforcement globally; ENISA curates publicly reported EU incidents including a very large hacktivist DDoS tail. Neither is wrong; they measure different things.

Companies and products

Companies. Palo Alto Networks, CyberArk, Okta, Microsoft, CrowdStrike, Saviynt, Oasis Security, SailPoint, Ping Identity
Products. CyberArk Privileged Access Manager, Palo Alto Idira, Microsoft Entra ID, Okta Identity Governance, Auth0, Saviynt Identity Cloud
Funding. Saviynt ~$700M Series B (Dec 2025, per Crunchbase aggregation); Oasis Security $120M Series B (March 2026); Palo Alto/CyberArk closed Feb 2026 as a cash-and-stock deal widely reported around $25bn at announcement.

Impact

Industry. Beneficiaries: Palo Alto Networks, Microsoft, Okta, identity governance startups, cyber insurers able to price MFA coverage. Losers: Standalone PAM vendors without an agent story, Organisations with large service-account estates and no rotation programme, Help desks used as an authentication oracle.
Consumer. Deployed at essentially every large enterprise; the open question is not adoption of identity products but coverage of non-human identities, for which no independent measurement exists.
Regulatory. Phishing-resistant MFA is mandated for US federal agencies (OMB M-22-09) and is an implicit NIS2 and DORA expectation; cyber insurers underwrite on MFA coverage. No regulator yet defines an obligation over machine or agent identities.
Geography. US, EU, GB, JP, IN, GLOBAL

Risks and counter-forces

  • Vendor definitions of 'identity' are expanding to cover whatever they sell, making category data unreliable
  • Machine-identity counts such as 109:1 originate from vendor telemetry and have no independent verification
  • Consolidating identity into one platform concentrates a single point of catastrophic failure

Counter-trends. Passkey and phishing-resistant MFA rollout at consumer scale genuinely raises the cost of credential phishing, Identity consolidation into Microsoft Entra reduces the addressable market for standalone identity vendors

Score breakdown

Pillar Score Dimensions
Momentum (30%) 90 velocity 4 · adoption 4 · capital 5 · revenue 5
Reach (25%) 95 breadth 5 · depth 4 · geography 5 · demand 5
Durability (25%) 93 persistence 5 · maturity 4 · strategic 5
Consequence (20%) 60 regulatory 3 · social 3
Evidence 80 quality 4 · diversity 4 → ceiling 88

Stage mainstream · Direction accelerating · Horizon Immediate (0–12 months) · Reading: Act on it

What to watch next

  • T-04-03 Exploitation outpaces patching: remediation is getting slower while exploitation gets faster
  • T-04-13 Governance for agent identities: zero standing privilege applied to non-humans
  • T-04-04 Platform consolidation is winning on revenue while best-of-breed keeps winning on capital
  • T-04-09 AI-orchestrated intrusion campaigns running at machine tempo

Sources

  1. Software vulnerabilities overtake stolen credentials as top breach entry point, 2026 DBIR finds — Verizon, 2026-05-19. Tier B. https://www.verizon.com/about/news/breach-industry-wide-dbir-finds
  2. ITRC: Malicious Insiders Surge as H1 2026 Data Compromises Set Pace for Record Year — Identity Theft Resource Center, 2026-07-22. Tier A. https://www.idtheftcenter.org/post/mega-breaches-malicious-insiders-h1-2026-data-breach-report/
  3. Palo Alto Networks Introduces Idira, the Next-Generation Identity Security Platform Built for the AI Enterprise — Palo Alto Networks, 2026-05-12. Tier B. https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-introduces-idira--the-next-generation-identity-security-platform-built-for-the-ai-enterprise
  4. Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI Era — Palo Alto Networks, 2026-02-11. Tier A. https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era
  5. ENISA Threat Landscape 2025 — European Union Agency for Cybersecurity, 2025-10-01. Tier A. https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf
  6. 2025 Internet Crime Report — FBI Internet Crime Complaint Center, 2026-04-01. Tier A. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

Generated from record T-04-01 via the canonical article template (18-editorial-formats.md). Research date 2026-09-15. Scores per 14-scoring-framework.md. Forecasts are conditional, never certainties.

Research provenance
Source artifact
06-sample-reports/04-cybersecurity.md
Corpus date
15 September 2026
Prepared for this site
16 September 2026
Site publication
18 September 2026
Verification
Inherited; not fully rechecked