Why identity security still leaves enterprises exposed
https://etimg.etb2bimg.com/thumb/msid-132736852,imgsize-53536,width-1200,height=627,overlay-etciso,resizemode-75/identity-access-management/why-identity-security-still-leaves-enterprises-exposed.jpg

The biggest risk in identity security may not be the sophistication of attackers, but the everyday gaps organisations leave behind. At a recent industry discussion, executives argued that most breaches linked to identity are still avoidable, yet weak coordination, delayed controls and fragmented oversight continue to give attackers room to move.
Rather than treating identity and access management as a narrow technology issue, the panel framed it as a broader governance problem touching leadership, compliance, vendor management and even AI security. Their message was blunt: enterprises can no longer rely on alerts alone when prevention, detection and response all need to work together.
Why the last mile of defence still fails
Mukesh, speaking from Capgemini’s perspective, said attackers only need one successful attempt, while defenders must be right every time. He argued that the gap often appears when security teams postpone controls, leaving systems exposed for longer than intended. In his view, the arrival of AI has made this more urgent because adversaries can test more variations and launch more frequent attempts.
He said the industry should move beyond a reactive mindset and build what he described as a layered model inspired by mistake-proofing in manufacturing. The sequence, as he explained it, should begin with prevention, then move to early detection and rapid mitigation. He added that many organisations still focus too heavily on alerts after the fact, instead of blocking risky access before it becomes a problem.
Mukesh also pointed to the role of AI in defence, saying his team has used it to spot patterns and anomalies that are not obvious to traditional systems. According to him, that approach has helped prevent a large share of attacks for some clients, though he stopped short of endorsing any absolute figure. At the same time, he warned that AI itself can create new exposure if models are not secured properly, because the underlying data used to train them can be inferred or misused.
Tool sprawl is creating blind spots
Krishan said the challenge is not simply the absence of tools, but the way enterprises buy many of them without fully understanding overlap, gaps and ownership. He likened the situation to trying to cover a fixed distance with multiple tools that each solve only part of the problem. In his assessment, organisations may defend against most attacks, but the final sliver of risk remains critical because that is where serious incidents emerge.
He added that identity and access management is often caught between two competing pressures. On one side are regulatory expectations around control and governance. On the other are incident response teams and business units that are trying to preserve operational flexibility and margins. According to Krishan, the real test is whether tools are complete enough to cover the full ecosystem, including the movement of identities across systems and the downstream impact of those movements.
He said the issue becomes more complicated when multiple parties handle different parts of the same workflow. In sectors such as insurance, one partner may run background checks, another may handle credit checks, and another may process claims. If each participant sees only a fragment of the identity journey, no one gets the full picture. That, he argued, creates a structural weakness in the overall control environment.
Third parties, consent and the DPDPA question
The discussion then shifted to third-party risk, which both speakers described as one of the hardest problems in identity management. Mukesh said external vendors and open-source components can leave systems vulnerable, especially when patching creates temporary windows of exposure. He argued that organisations should not depend only on alerts after a risky event has already started. Instead, they should define what can be blocked from day one and create access rules that are tight enough to stop unnecessary entry altogether.
He also suggested that enterprises could use measurable security thresholds to assess how close they are to a target state of resilience. In his view, the aim should not be perfection in theory, but a practical level of confidence that keeps risk within acceptable bounds. He added that some access requests should still be allowed through controlled workflows, such as when a user is travelling and needs temporary approval in another geography.
Krishan said the arrival of the Digital Personal Data Protection Act has made consent-based management more important, especially in sectors where identity data is shared across multiple parties. He argued that every action should be tied to a defined policy and purpose, but said the industry still lacks a fully integrated way to map the complete system. In his view, a piecemeal approach leaves critical exposure unresolved.
Legacy systems are still part of the risk equation
Both panellists agreed that outdated infrastructure remains a stubborn vulnerability. Mukesh said many organisations assume their vendors are operating at a certain level of maturity, but that assumption is often inaccurate. He noted that older platforms and delayed patching can introduce risk at exactly the moment firms believe they are covered.
Krishan went further, saying some incident response environments still rely on obsolete tools and processes. He pointed out that older spreadsheets and legacy workflows continue to exist in parts of the ecosystem, even though they are no longer adequate for modern security requirements. That, he said, makes the case for stronger hygiene, better inventory and more disciplined governance across the stack.
Security literacy is now a boardroom issue
The conversation ended on a broader theme: identity security cannot be solved purely by technology. Mukesh said the industry often treats IAM as an IT hygiene issue, when in reality it is a leadership and literacy problem. He argued that organisations need security awareness at every level, not just among specialists, because senior employees themselves may sometimes assume that convenience should override control.
He said the goal should be to build secure systems from the outset rather than add controls later as an afterthought. Even then, he acknowledged, absolute safety may be unrealistic. What matters, he suggested, is continuous monitoring, regular review and a willingness to tighten access before a weak point becomes an incident.
For enterprises, the takeaway is clear. Identity security is no longer about one tool, one policy or one team. It is about whether leaders can connect governance, vendor oversight, AI controls and user behaviour into a single operating model. As attackers become faster and more adaptive, the cost of delay is likely to rise.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












