Identity used to feel like one line of defense — a username and password, perhaps guarded by a firewall. Today, that line is under siege. As Laura Marx, RSA’s Chief Marketing & Growth Officer, explained, threat actors are becoming more skilled at bypassing traditional controls, leveraging personal data to impersonate trusted users. The result: security systems defending infrastructure may be irrelevant if identity is compromised.
David Bellini, CEO of CyberFOX, points to several converging trends fueling this rise in identity breaches:
-
The shift to remote work and cloud services has massively expanded the attack surface.
-
Many organizations still run legacy identity systems lacking modern protections like multi-factor authentication (MFA) or behavioral analytics.
-
Attackers are exploiting social engineering and help desk bypass tactics, targeting human weaknesses rather than technical holes.
Mark St. John of Neon Cyber adds that years of leaked credentials, password spraying attacks, and rising sophistication in AI-enabled social engineering have set the stage for identity-based exploitation across nearly every organization.
As James Maude of BeyondTrust put it, identity has become the new perimeter — attackers no longer need to breach the firewall if they can impersonate a valid user.
The High Cost When Identity Fails
Identity breaches are especially devastating because they touch everything. According to the RSA survey:
-
45 percent of organizations said the cost of their identity-related breaches exceeded the typical cost of a “normal” breach.
-
24 percent reported damage topping US$10 million, up from the prior year.
Why so steep? Because a compromised identity often links to multiple systems, databases, and privileges. Ambuj Kumar, founder of Simbian, observed that a well-positioned user account can unlock access to numerous data stores — so one breach leads to a sprawling domino effect.
Brad Lassiter, CEO at LastTech, describes identity as the master key. “An identity breach is more than exposed data,” he said. “It enables attackers to control everything that user can access — often without detection.”
Help Desks: The Weak Link
A particularly worrisome insight: 65 percent of organizations surveyed are deeply concerned about attacks on their help desks. More telling: 51 percent consider service desk bypass attacks their top risk.
Why help desks? Because their mission is to provide assistance — to unlock accounts, reset passwords, or grant access. Attackers exploit that helpfulness. They pose as legitimate users or even co-opt help desk processes to gain control. As RSA’s Marx warned, a threat actor pretending to be an employee or technician can manipulate service staff to open doors far wider than an attacker ever could on their own.
Andy Thompson, a senior researcher at CyberArk, emphasized how service desks often operate under pressure and without robust verification protocols — particularly when remote or outsourced. “They’re measured by service-level agreements, not security,” he noted. That pressure can lead to risky decisions around identity validation.
Why the Struggle to Modernize?
Despite the growing threat, many organizations are slow to adopt stronger identity models:
-
57 percent still haven’t made passwordless authentication their default method.
-
90 percent say they face significant challenges in transitioning to passwordless systems.
Bellini points out that entrenched legacy systems, user resistance, and integration complexity are large barriers. Even when organizations want to move forward, their infrastructure often won’t support it.
RSA CEO Greg Nelson warns that identity security failures are too common and too costly to persist. “The likelihood of a breach — and the cost of inaction — are too high for leaders to tolerate the status quo,” he said.
Where to Focus Defenses
Given the urgent risks, organizations must adjust their strategies:
-
Harden the help desk
-
Require strict verification protocols (multiple factors, callbacks, context checks).
-
Train staff to resist social engineering and escalate suspicious requests.
-
-
Adopt strong identity controls end-to-end
-
Make MFA and passwordless methods widespread.
-
Use behavioral analytics, device binding, and continuous authentication.
-
-
Close identity-to-privilege paths
-
Enforce least privilege access.
-
Monitor identity behavior across systems for anomalies.
-
-
Audit legacy systems
-
Identify identity systems lacking modern capabilities.
-
Plan migration toward secure, upgradable platforms.
-
-
Invest in identity-aware incident response
-
Include identity escalation in breach plans.
-
Simulate identity-based attacks (help desk abuse, credential takeover).
-
Identity-related breaches are no longer a fringe concern; they are becoming the norm. When the password or account your users hold is compromised, it can render firewalls, encryption, and network segmentation moot. The new battleground lies at the intersection of people, permissions, and identity systems — and the organizations that secure it proactively will stay one step ahead in an increasingly dangerous landscape.


