Identity security relates to the practices, frameworks, and tools organizations use to secure both the digital identities they rely on and their underlying infrastructure. The authentication mechanisms used to restrict access to an identity, authorization tools used to control the capabilities afforded to those identities, and services that make it easier to manage and monitor the rest of the identity stack can all fall under the Identity security umbrella.
That stack of identity security solutions has become increasingly critical as organizations have shifted from exclusively relying on internal networks to utilizing cloud-based services or some combination of local and remote deployments. An internal network can use a firewall to clearly separate an organization’s infrastructure from the rest of the world. But cloud or hybrid environments rely on something else to make sure resources can’t be accessed by anyone with an internet connection: identities.
Digital identities have become so ubiquitous that most people don’t even think about them. How do we access our email, streaming platforms, and social media profiles? By using a specific identity—in most cases an individual account—associated with those services. How do organizations enforce restrictions on installing software on managed devices, for example, or viewing certain files stored in the cloud? Using identity-based infrastructure. The same is true for managing digital services and artificial intelligence agents.
Identity security is a broad enough concept to encompass companies operating at various places in the stack. There are some devoted to offering authentication methods that are more difficult for adversaries to exploit, some to making it easier for an organization’s IT department to manage the identities within their environment, and some to finding the ways attackers can exploit identities and the relationships between them as part of their operations, among other things. This is a complex, ever-changing field of cybersecurity.
How identity attacks actually unfold
Identity attacks rarely begin with the compromise of a high-value asset. Instead, adversaries typically find a way to take over a low-value identity, often via stolen credentials or phishing attacks. From there, it’s a matter of learning how the environment has been set up, what other identities are vulnerable to compromise, and how to make it from a low-value identity to a high- value target. This can involve some combination of exploiting software vulnerabilities, abusing misconfigurations within the environment, and taking advantage of trust relationships between identities and infrastructure.
These kinds of attacks can be difficult to detect, especially if the adversary is using valid credentials to access the compromised identity. There are some indicators of malicious activity involving valid credentials, such as a login attempt originating from an unusual location or being made at a strange time, but savvy attackers will consider those factors before they act. Then it’s mostly a matter of disguising their activity to make it harder for defenders to discern between post-exploitation actions and the identity’s usual behavior.
Sophisticated adversaries will also develop their own model of the organization’s environment; it’s not uncommon for attackers to develop a better understanding of an organization’s digital infrastructure than the people charged with maintaining and defending it. That makes it easier for them to resume their attacks if defenders happen to spot them and successfully remove their access to a compromised identity—all they have to do is gain access to another vulnerable identity so they can essentially pick up where they left off.
Modern trends in computing can make exploiting identity-based security flaws easier than ever. The rush to keep up with demands to create identities for additional employees, services, and artificial intelligence agents can lead to identity sprawl: a bounty of insecure access tokens, over-privileged identities, and forgotten accounts being littered across the organization’s environment. System administrators and defenders simply don’t have the resources they need to carefully plan out their infrastructure and, crucially, audit it to confirm their expectations for their environment’s security matches the reality.
Non-human and agentic identity
There’s a difference between how the word “identity” is used in everyday life and how it’s used in the context of identity security. The former usually defines an identity as a person’s name, alias, or self-perception; the latter defines an identity as something that exists within an organization’s digital infrastructure that is unique due to some combination of its identifier, credentials, and the permissions or privileges that have been granted to it. That means it doesn’t necessarily have to refer to a human—it can just as easily be associated with what many people think of as “bots” instead.
Organizations create non-human identities for a variety of reasons. Sometimes they’re setting up a service account that allows a payroll system to maintain a database of financial transactions, for example, or creating a dedicated user for a logging system to make it harder to tamper with the files it generates. Nowadays they’re creating non-human identities meant to be used by artificial intelligence agents that promise to automate an even broader range of tasks. It should come as little surprise, then, that non-human identities often greatly outnumber human identities within an organization’s environment.
This shift in the digital identity status quo has further complicated identity security. There used to be obvious differences between human and non-human identities: people are usually active during predetermined working hours, but digital services can run continuously; it can be harder to predict human behavior than the rote mechanisms of well-designed software; and it’s far less common for a person to be called “Printer Service” than it is for a machine. But agentic computing has blurred the lines between human and non-human identities. AI agents can be most active during normal work hours, especially if they’re being prompted by a person, but they can also work through the night. The predictability of an agent’s behavior is somewhere between the average person and the average digital service. And tens of thousands of people share a first name with one of the most popular AI services in the world.
These changes have required organizations to rethink how they manage AI identity security. Those non-human identities used to be an afterthought—someone made an identity for the office printer because they needed to put ink to paper, or set up a dedicated user for a digital service because it was supposed to automate a tedious task, and then they promptly forgot about them. It’s common for organizations to have long-lived non-human identities that are rarely audited, never rotated, and frequently granted more privileges than their human counterparts. This was never ideal—adversaries often target such identities—but the predictability of most quality software meant that risks of harm arriving as a consequence of their everyday operations were fairly low.
The same cannot be said for agentic computing. On a scale from “least predictable” to “most predictable,” humans would typically rate as “least predictable,” software would be considered “most predictable,” and the currently available AI agents would have to be described with a note written in the margin explaining that they are “less predictable than software and more predictable than humans until they malfunction and do something completely unexpected.” They’ll operate as expected dozens or hundreds of times, only to suddenly misinterpret a prompt or, according to the majority of leading AI providers, become actively malicious with no warning. The identities associated with them being poorly secured or over-permissioned could be disastrous, and that’s before adversaries find ways to exploit them for their own benefit.
The five domains of identity security
We’ve established that identity security is a broad category that encompasses the practices, frameworks, and tools used to safeguard human and non-human identities from adversaries as well as the risks associated with those identities being used in unexpected ways. These are critical aspects of securing modern environments, with identity-based security measures effectively replacing firewalls as the first line of defense for many organizations.
Identity security is also related to five domains of cybersecurity: Identity and Access Management (IAM), Attack Path Management (APM), exposure management, Active Directory security, and enterprise security strategy. There are no firm boundaries between these domains; they’re all interconnected in various ways. They also affect more than just identity security— particularly exposure management, Active Directory security, and enterprise security strategy— but we’ll primarily view them through that lens as we explore each in turn.