of coordinated chains of strikes, engineered to find the path of least resistance across an ever-expanding attack surface. And identity has become the most prevalent path for attacker success, research suggests. During the past year, identity weaknesses played a material role in 90 percent of the security breaches investigated by Unit 42, the research arm of Palo Alto Networks.”In our caseload, identity shaped intrusions end to end. It served as the way in, the path to privilege escalation and the mechanism for lateral movement using valid access,” said Unit 42 in its most recent Global Incident Response Report. As organizations move deeper into SaaS, cloud and hybrid environments, the network perimeter matters less, argued the report. Identity – or the linkage between users, machines, services and data – has become the practical perimeter. “In many cases, threat actors don’t need a sophisticated exploit chain. They log in with stolen credentials, hijacked sessions or mis-scoped privileges,” said Unit 42 researchers. These types of “authenticated accesses” let adversaries move faster, blend into normal activity and expand their area of impact with fewer obstacles. “This trend is accelerating as machine identities, embedded AI applications and fragmented identity estates expand the number of access paths attackers can exploit,” the report continued. Unit 42 case data shows that 65 percent of initial access is driven by identity-based techniques. Which security capabilities are important to your organization today? (Among in-house IT teams) Identity security 93% Email and phishing protection 92% Cloud and SaaS security 91% Incident response readiness 90% Compliance and reporting 88% MDR / 24x7 monitoring 84% Source: Cynet What are you doing differently or plan to do differently for threat detection to combat the use of AI by threat actors? Select all that apply. What cybersecurity products are being bought? Past 12 Months Next 12 Months Endpoint security 36% AI security 30% Network security 35% Security operations 29% Email security 32% Identity access management 28% Identity access management 29% Data security posture management 26% Data security 25% Application security 25% Security operations 24% Threat intelligence 24% Application security 23% MSSP 23% Security analytics 23% Security analytics 22% Cybersecurity training 22% Fraud prevention 19% MSSP 21% Cybersecurity testing 15% Threat intelligence 20% Endpoint security 14% IoT security 19% Governance, risk & compliance 13% Fraud prevention 18% IoT security 12% Cybersecurity testing 16% Cybersecurity testing 11% Governance, risk & compliance 15% Deception technology 8% Deception technology 14% Data security 6% Data security posture management 11% Network security 6% AI security 8% Email security 5% Source: The Hoffman Agency; Coleman Parkes Research 22 CHANNELVISION | SUMMER 2026
RkJQdWJsaXNoZXIy NTg4Njc=