Category /

Identity Is the Perimeter, Governance Hasn’t Caught Up

Identity Is the Perimeter, Governance Hasn’t Caught Up

The perimeter security model is functionally obsolete for most organisations. The network boundary that once defined the security boundary has dissolved, replaced by a distributed architecture in which users, services, and data operate across environments that no firewall can meaningfully contain.

Identity has become the effective perimeter. Credentials determine what can be accessed, from where, and by whom. This is widely understood at the technical level. What has not kept pace is the governance model that identity security requires. The result is a control domain that is technically sophisticated and organisationally ungoverned.

What identity governance actually means

Identity governance is not the same as identity management. Identity management is the technical discipline of provisioning accounts, enforcing authentication, and controlling access. It is largely a solved problem for mature organisations, at least in its basic form.

Identity governance is the organisational discipline of making and maintaining decisions about who should have access to what, on what basis, and for how long. It requires that someone owns those decisions, that there is a process for reviewing them over time, and that the outcome of that process is visible to the people accountable for the organisation’s risk posture.

Most organisations have the first. Very few have the second in a form that would withstand regulatory scrutiny. The most common identity failures in regulated environments are governance failures: excessive permissions that were never reviewed, service accounts that outlived the projects they were created for, privileged access that was granted for a specific purpose and never revoked.

How the governance gap forms

Identity governance gaps are structural. They form through a combination of speed, fragmentation, and misallocated ownership, and they are predictable, the same pattern shows up almost everywhere.

Access is provisioned quickly because the business requires it. Access reviews are scheduled periodically but treated as administrative exercises. The people conducting reviews often lack the context to assess whether access is still appropriate. They approve what they cannot easily explain, which means they approve most of it.

Cloud adoption compounds the problem. Cloud environments provision access at a scale and velocity that manual governance processes cannot match. Infrastructure-as-code creates permissions through automated pipelines. Service-to-service access accumulates without the same visibility as human user access. The identity estate grows faster than the governance model designed to manage it.

The result is an organisation whose technical identity controls are sound and whose effective access posture is unknown, because nobody has a current, accurate picture of who has access to what, whether that access is appropriate, or whether it has been reviewed.

What regulators see

Identity and access management is one of the most scrutinised control domains in regulatory examinations of cloud environments. Regulators examine it because it is where the most consequential failures concentrate.

What they look for is evidence of a governance process: the decision-making structures that determine whether technical controls reflect the organisation’s actual access requirements. They ask who owns access decisions for privileged accounts. They ask what triggers an access review outside the scheduled cycle. They ask how the organisation would know if a service account had been compromised and used to move laterally.

Answers that describe technical capabilities without describing governance processes do not satisfy these questions. A well-configured identity platform without a functioning access governance process is a control that exists on paper and erodes in practice.

The governance model identity security requires

Identity governance requires ownership at the business level, not just the technical level. Access decisions are business decisions, they determine who can affect what outcomes in the organisation’s systems. Delegating those decisions entirely to IT or security functions disconnects them from the context required to make them well.

It requires a review process that is genuinely risk-driven. High-privilege access, access to sensitive data, and access that crosses organisational boundaries warrant more frequent and more rigorous review than standard user access. Treating all access reviews with the same cadence and the same level of scrutiny produces a process that is thorough in appearance and superficial in effect.

It also requires that the organisation accepts an uncomfortable operational constraint. Access that cannot be justified should be revoked, even when revocation creates friction. That friction is recoverable. A compromised account holding unreviewed access is a much harder problem to walk back.

Identity is the perimeter. The governance model that perimeter requires is not yet standard practice. For regulated organisations, that gap is already live.

Share the Post:

More Posts

The SOC Has a Shadow AI Problem, and It Is the SOC

Shadow AI governance programmes are built to find the marketing team pasting customer data into a chatbot, or the finance analyst running a model through an unapproved tool. Almost none of them are built to look at the security operations centre itself. That is the gap. The team writing the

Read More

Segmentation Was a Project; It Needed to Be a Programme

Most organisations that have “done” network segmentation completed a project. They didn’t build a capability. The architecture deck shows clean zones, defined trust boundaries, clearly labelled traffic flows between them. The environment on the ground stopped resembling that diagram roughly around the time the project closed out. This isn’t usually

Read More

Threat Intelligence Reports Are Not the Same as Threat Intelligence

Most organisations subscribing to threat intelligence feeds are subscribing to notification. A feed tells you what happened somewhere else, to someone else, on infrastructure that may or may not resemble yours. Knowing that is not the same as knowing what threatens you. The distinction sounds pedantic until you sit in

Read More

The Board Asked About Cyber Risk. Nobody Had a Good Answer

Board members are asking better questions about cyber risk than they were five years ago. The answers they are receiving have not kept pace. That gap is structural, not a knowledge problem, and it produces consequences that extend well beyond uncomfortable boardroom conversations. The mismatch between what boards need to

Read More