Security has an identity problem

September 2026 Access Control & Identity Management, Information Security


Kumar Vaibhav

Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, defined by cloud use, SaaS platforms, artificial intelligence (AI) tools, and hybrid work, those traditional defences have become less relevant. What remains consistently exposed and often ignored, is identity.

This is not just about login credentials; it is about identity as a living, changing layer of access. Every employee, contractor, device, and application has a digital identity and a set of permissions. The real risk organisations face today is not just that identities can be compromised, but that they are often overextended, poorly managed, and fundamentally misunderstood.

Access is no longer binary; it is behavioural

The old approach to access was straightforward: authenticate once, and you are in. This method assumes that identity is static and trustworthy, which is no longer true. Today, access is continuous. It is influenced by behaviour, context and risk.

An employee logging in at 9 AM from their usual device in Johannesburg poses a very different risk from the same employee accessing sensitive systems at midnight from an unfamiliar location. Yet many organisations still treat these scenarios as the same, relying on one-time authentication to grant broad access.

This is where the idea of identity-first security goes beyond a technical change; it becomes a behavioural shift. Security decisions must now consider how access is used, not just whether it was initially approved.

The quiet danger of access creep

One of the most common and underestimated risks in organisations is ‘access creep’. Over time, employees accumulate permissions as they change roles, work on different projects, or temporarily need elevated access. Rarely is that access completely revoked.

To address this, organisations should implement regular access reviews: either manual or through automated tools. This is to ensure that permissions remain appropriate over time. Periodic reviews help identify and remove unnecessary access, while automated solutions can alert security teams to excessive privileges as they develop. Taking these proactive steps enables companies to keep access tightly aligned with current roles and responsibilities.

Reducing this risk is not about locking everything down; it is about refining access with precision. The principle of least privilege, when applied correctly, ensures that users have access only to what they need and only for as long as they need it. This adds discipline to what can be an uncontrolled process.

Zero Trust, when it means something

Zero Trust is a familiar concept, but its true value lies in its application. At its core, it questions an ingrained assumption that once a user is verified, they can be trusted.

In a modern context, that assumption is risky. Credentials can be stolen, devices can be compromised, and behaviour can change. Zero Trust redefines access as something that must be continuously assessed, not permanently granted.

This means that every interaction among users, devices, and applications is considered potentially risky until proven otherwise. Access is no longer a one-time decision; it is an ongoing process of validation. When done properly, this approach limits attackers' ability to move unnoticed, even if they gain initial access.

Authentication needs context, not just complexity

For years, organisations have tried to strengthen authentication by making it more complex: longer passwords, stricter rules, and additional factors. While these steps are important, they alone are not enough.

What is emerging is a move towards contextual authentication. Instead of treating every login attempt the same, systems assess the surrounding context: location, device, behavioural patterns, and even timing. Low-risk interactions are streamlined, while high-risk attempts trigger extra verification.

This approach not only boosts security, but also enhances usability. Employees no longer face unnecessary hurdles for routine tasks, while genuinely suspicious behaviour is examined more closely. It is a smarter way to balance security and productivity.

The identities you do not see may be the most dangerous

While the focus is often on human users, organisations increasingly include non-human identities, such as service accounts, APIs, automated scripts, and AI-driven processes. These operate in the background with high access levels and minimal oversight.

Because they are not linked to individuals, they are often excluded from governance processes. Passwords are seldom updated, permissions are rarely reviewed, and activity is not always monitored closely. To strengthen governance for non-human identities, organisations should adopt specific best practices. These include assigning clear ownership for each non-human identity, implementing regular credential rotation and reviews, monitoring activity for unusual patterns, and restricting permissions to only what is necessary.

Documenting where and how each non-human identity is used also helps prevent unchecked access. By following these steps, leaders can ensure that non-human identities are managed properly, which also helps prevent unchecked access. By following these steps, leaders can ensure that non-human identities are managed with the same rigour as human ones.

This creates a significant blind spot. In many cases, these non-human identities have access to critical systems. Securing them requires the same discipline applied to human users: clear ownership, defined access boundaries, and ongoing monitoring.

Where strategy meets reality

Implementing identity-first security requires more than just new tools. Organisations must reconsider how access is designed, managed, and reviewed across the business. This is where outside expertise becomes important. IT consultants who work across different industries help organisations turn high-level principles into practical frameworks. They assist in implementing Zero Trust models, improving authentication, and embedding least-privilege access in ways that reflect real-world work practices.

Their role focuses on creating clarity rather than adding complexity, ensuring that identity strategies are secure and sustainable.

A future built on continuous verification

The shift from perimeter-based security to identity-first models is not just a trend; it is a necessity. As organisations continue to change, so too will the ways in which identities are created, used, and exploited.

The challenge is not just to secure identities at a single point in time, but to continuously verify them as conditions shift. This requires a change in mindset as much as a technical adjustment: from static trust to dynamic verification.

Ultimately, security is no longer just about keeping threats out. It is about making sure that every access decision, every time, is the right one.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.