[weglot_switcher]
Know the terrain
THE 2026 SPYCLOUD

IDENTITY
THREAT REPORT

Benchmarks, blind spots, and strategies for detecting, remediating, and reducing identity threats across human and non-human identities

1+ TRILLION

recaptured identity assets

65.7 BILLION

distinct identity records

17+ BILLION

session cookies

63+ MILLION

recaptured API keys and tokens
INTRODUCTION

Mapping the new identity terrain

Identity exposure is measurable and fixable – yet most organizations are still navigating with an outdated map, drawn for marked trails rather than the backcountry attackers now roam.

The terrain has expanded past employee credentials to session tokens, non-human identities, and third-party ecosystems, and closing the gap means surveying what’s exposed beyond the camp’s edge before attackers get there first.

This year’s Identity Threat Report [1] – a survey of security leaders and practioners acorss North America, UK and select European Markets – benchmarks how enterprise organizations detect, remediate, and govern identity threats – and what separates the most mature programs from the rest.

Table of Contents

Executive summary

Key takeaways

Insights and highlights from 750+ security respondents. Dig in by expanding each section. 

01 Identity-based events are now a routine reality

More than two-thirds (68%) of organizations experienced an identity-based event in the past year, with affected organizations averaging eight events confirming that identity compromise has become an operational reality rather than an isolated incident.

68%
experienced an identity-based event

NHI-related misuse or compromise was the top reported identity-based event type (42%), while exposed or overprivileged NHIs were cited by 50% as a common access path for attackers launching identity-based events.

42% NHI misuse/compromise
50% Most common path

Organizations that experienced identity events were significantly less likely to have visibility into stolen session cookies (37% vs. 50%) and personal devices (40% vs. 52%), suggesting that blind spots continue to fuel successful attacks.

91% of organizations use AI tools or agents with internal access, but only 56% have formal governance and ownership for AI- and NHI-related privileges.

91% use AI with internal access
56% have formal governance

C-suite leaders were far more confident in their NHI visibility than frontline operators (66% vs. 50%). While the U.S. and Canada largely tracked the global baseline, the UK reported the highest confidence (53%) despite experiencing the highest identity event rate (77%) – demonstrating that confidence does not necessarily reflect coverage. 

Government sector reported experiencing a much higher frequency of identity events (92.3% vs. 68% total), and government orgs reported the highest average event volume (10 events vs. 8 total average).

Manufacturing organizations, on the other hand, were significantly less likely to have experienced an identity-based event (58% vs. 68% total), but when they did, the fallout was worse, reporting customer or partner trust loss as a business impact (56.9% vs. 40.2% total) and higher average impacts across the board – a classic “fewer, but costlier” pattern.

Third-party malware infections (23%) and API key/application exposures (22%) were cited as the leading causes of supply chain identity events across respondents. 

Vendor remediation validation is uneven, even across technology-heavy sectors. Telecommunications leads with the highest active validation rate at 68%, while Technology / Software organizations report the lowest rate at 38%, revealing meaningful differences in third-party identity governance.

Germany emerged as a benchmark for third-party identity governance, with 76% of organizations actively confirming vendor remediation, demonstrating that stronger operational practices can substantially improve supply chain visibility.

76% of German orgs actively confirm vendor remediation

Large enterprises (5,000+ employees) reported significantly higher confidence in their identity visibility than mid-market organizations, but confidence alone did not consistently translate into better outcomes.

Organizations relying on manual remediation reported higher incident response costs (39%) and customer trust loss (47%) compared to their peers who report using high levels of automation (32% and 36%, respectively).

Know the terrain

Mapping the path to operational maturity

The data in this year’s report suggests that operational maturity is more closely associated with resilience than company size, industry, or geography. Organizations with more mature identity threat protection programs report lower identity-based event rates and stronger visibility, monitoring, remediation, governance, and automation practices.

The Identity Threat Protection Maturity Trail

To benchmark organizational readiness, respondents were grouped into four maturity tiers: Reactive, Building, Operational, and Optimized based on their identity exposure across visibility, monitoring, governance, automation, and remediation capabilities.

Map showing four stages of cybersecurity threat response process.
01

Reactive

Limited visibility, manual processes, and
inconsistent remediation

SHARE OF RESPONDENTS

9%

02

BUILDING

Building foundational processes but still challenged by visibility and operational consistency
SHARE OF RESPONDENTS

37%

03

OPERATIONAL

Repeatable workflows, measurable outcomes, and increasing use of automation.
SHARE OF RESPONDENTS

45%

04

Optimized

Repeatable workflows, measurable outcomes, and increasing use of automation.
SHARE OF RESPONDENTS
9%

45%

CHARTING THE PATH

Identity-based event rates by maturity tier

Organizations in the Building tier experience the highest incident rate, likely reflecting greater visibility into identity exposures before mature processes and automation begin reducing risk. From there, the data shows a clear maturity effect: identity-based event rates decline substantially as organizations move from Building ultimately up to Optimized.

CHARTING THE PATH
BLID SPOTS

Confidence vs. identity-based event rate by market

Across the regional segments, organizations report relatively high confidence in their visibility, yet identity-based events remain common. The disconnect is most pronounced in the United Kingdom, which reports both the highest visibility confidence (53.3%) and the highest identity-based event rate (76.7%), reinforcing a central finding of this report: confidence does not equal coverage.

MARKETCONFIDENCE >> EVENT RATEGAPUNITED KINGDOM0.010.018.626.032.337.541.845.247.949.951.352.352.953.253.353.30.014.326.837.446.554.060.165.168.971.873.975.276.176.576.776.70.04.48.211.414.216.518.319.921.021.922.523.023.223.323.423.4POINTSNORTH AMERICAUnited States & Canada0.08.616.122.427.932.436.139.041.343.144.345.145.645.946.046.00.012.723.733.241.247.953.357.761.163.665.566.767.567.868.068.00.04.17.710.713.315.517.218.719.820.621.221.621.821.922.022.0POINTSEUROPEAN MARKETSSpain, Germany, the Netherlands,Austria, Switzerland0.07.714.420.125.029.032.334.937.038.639.740.440.941.141.241.20.011.721.930.638.044.249.253.356.458.860.561.662.362.762.862.80.04.07.510.513.115.216.918.319.420.220.821.221.421.521.621.6POINTSFIGURE S2.2020406080100%CONFIDENCE GAPVERY CONFIDENT IN VISIBILITYEXPERIENCED AN IDENTITY-BASED EVENT

Attackers exploit what organizations can't see

Organizations that avoided identity-based events consistently monitored more exposure types than those that experienced incidents.

Visibility into two areas stood out most in affecting whether an organization experienced identity-based events:

Stolen session cookies

WITHOUT VISIBILITY
50%
WITH VISIBILITY
37%

PERSONAL DEVICES WITH CORPORATE ACCESS

WITHOUT VISIBILITY
52%
WITH VISIBILITY
40%
Trail marker

Phishing and malware remain persistent access paths

Phishing and malware continue to create boundless opportunities for bad actors, providing them with stolen session cookies, credentials, refresh tokens, and more to carry out session hijacking, ransomware, account takeover, and other attacks.

PHISHING & SOCIAL ENGINEERING AS A COMMON ACCESS PATH
68%
INCOMPLETE
VISIBILITY ON PHISHING EVENTS
40%
MALWARE EXPOSURE VISIBILITY ON MANAGED DEVICES ONLY
53%
Know the terrain

The attack map extends beyond the perimeter

AI tools, agents, applications, vendors, and partners are creating new identity paths into the business. As these connections expand, identity risk increasingly comes from privileged access that sits outside traditional governance and visibility.

Nearly every organization surveryed (91%) now uses AI tools or agents with access to internal systems, applications, or data. Yet only 56% have formal policy and clear ownership for managing AI- and NHI-related privileges. Another 41% rely on informal processes or partial ownership.

Pie chart showing 95% perceived visibility in cybersecurity organizations.
Pie chart showing 95% perceived visibility in cybersecurity organizations.

NHIs are now the leading route for initial access

The visibility gap has real consequences. NHI-related misuse was the most commonly reported identity-based event (42%). Meanwhile, 50% of affected organizations cited exposed, compromised, or overprivileged NHIs, including API keys, tokens, and service accounts, as common access paths, and 31% identified them as the single most common initial access vector.

Primary entry points chart Animated reproduction of the supplied chart. The seven bars reveal from left to right on load.

Governance helps bring the trail into view

Formal governance doesn’t just assign ownership. It improves visibility across the broader identity ecosystem.

For example, 49% of organizations with formal AI governance have visibility into personal devices with corporate access, compared with 36% of organizations relying on informal governance.

Topographic map showing traditional governance and overprivileged NHIs with access levels.
Trail marker

The malware-to-supply-chain pipeline

Many supply chain identity incidents begin with common exposure-hygiene failures rather than sophisticated attacks.

Despite the clear benefits of automation, most organizations remain in a transitional phase. While relatively few still rely entirely on manual processes, only about one in five have reached fully optimized remediation and investigation capabilities.

23%

cite malware-infected third-party devices

as the leading cause of supply chain identity incidents

22%

CITE EXPOSED API KEYS OR APP ACCESS

involving vendors or partners
THE ATTACK MAP
THE ATTACK MAP

Identity Exposure Remediation Maturity

Fully automated remediation remains rare until organizations reach the Optimized tier. The sharp increase from 24% of Operational organizations to 81% of Optimized organizations highlights automation as one of the defining capabilities that separates trail leaders from the rest of the market.

SpyCloud report cover showing identity threat levels and remediation strategies.
Know the terrain

Charting The Path Forward

Identity exposure can’t be addressed through a single technology, process, or policy. The strongest programs build operational maturity over time, strengthening visibility, accelerating remediation, and validating outcomes across an expanding identity ecosystem.

Top planned investments over the next 12–18 months:

35%
plan to automate identity-related incident response workflows
32%
plan to enhance supply chain and vendor risk management
32%
plan to reduce identity exposure across employees
CHARTING THE PATH FORWARD

The organizations making the greatest progress focus on three operational priorities.

Fully automated remediation remains rare until organizations reach the most mature, Optimized tier. The sharp increase from Operational organizations (24%) to Optimized organizations (81%) highlights automation as one of the defining capabilities that separates trail leaders from the rest of the market.

01

Get the full picture:

Expand visibility beyond the perimeter

Leading organizations continuously monitor identity exposure across employees, vendors, any and all devices accessing work applications, session cookies and tokens, AI tools, and NHIs.

02

SHORTEN THE TRAIL:

AUTOMATE RESPONSE & REMEDIATION

Visibility without action creates more alerts, not better outcomes. Trail leaders reduce exposure faster through automated investigation, remediation, and validation workflows, reducing the time attackers have to exploit exposed identities.

Key capabilities include:

03

Close the loop:

Verify vendor remediation

Nearly 40% of organizations lack a consistent process to verify vendor remediation, leaving them vulnerable to unresolved identity exposures across third-party ecosystems.

Verifying remediation closes the loop between detection and response, helping make sure identity threats are actually eliminated rather than simply identified.

Know the terrain

The Journey Ahead

No organization ever reaches a final, fixed vantage point – the terrain keeps shifting as new trails open and old ones erode. What separates the organizations ahead of the pack isn’t a completed map, but a commitment to resurveying it: watching for new routes attackers carve out, marking blind spots as they’re found, and moving with the confidence that comes from knowing the ground beneath you rather than assuming it. Identity threat protection isn’t a summit to reach – it’s a trail maintained one season at a time.

This report is based on a survey of 750 cybersecurity decision-makers and practitioners conducted in June 2026. Results are reported at a 95% confidence level with a ±3.58% margin of error.

01

RESPONDENTS

Security architect or engineer: 23%  ·  Identity and access management (IAM) director, manager,
or specialist: 22%  ·  Security director, manager, or team lead: 20%  ·  CIO, CISO, or IT security
executive: 19%  ·  Security operator, analyst, or incident responder: 11%  ·  Security
administrator: 3%  ·  Other role in IT security: 2%

02

Company Size

1,000–4,999 employees: 42%  ·  5,000–9,999 employees: 29%  ·  500–999 employees: 19%  · 
10,000–25,000 employees: 8%  ·  More than 25,000 employees: 1%

03

GEOGRAPHY

United States: 26.5%  ·  Canada: 20.1%  ·  United Kingdom: 20.0%  ·  Spain: 6.7%  · 
Germany: 6.7%  ·  The Netherlands: 6.7%  ·  Austria: 6.7%  ·  Switzerland: 6.7%

04

INDUSTRIES

Manufacturing: 13%  ·  Healthcare: 12%  ·  Energy, Extraction and Utilities: 11%  ·  Insurance: 11%  · 
Retail & Ecommerce: 11%  ·  Financial Services / Banking: 10%  ·  Professional Services: 8%  · 
Technology / Software: 8%  ·  Telecommunications: 5%  ·  Education: 4%  · 
Government – Federal: 3%  ·  Government – State/Local: 2%  ·  Travel & Hospitality: 2%

NEW RESEARCH: Over 2/3 of orgs had an identity event last year – NHIs were the top cause. Read on

X