Category /

Identity Is the Perimeter. Governance Hasn’t Caught Up.

Identity Is the Perimeter. Governance Hasn’t Caught Up.

The perimeter security model is functionally obsolete for most organisations. The network boundary that once defined the security boundary has dissolved replaced by a distributed architecture in which users, services, and data operate across environments that no firewall can meaningfully contain.

Identity has become the effective perimeter. Credentials determine what can be accessed, from where, and by whom. This is widely understood at the technical level. What has not kept pace is the governance model that identity security requires. The result is a critical control domain that is technically sophisticated and organisationally ungoverned.

What identity governance actually means

Identity governance is not the same as identity management. Identity management is the technical discipline of provisioning accounts, enforcing authentication, and controlling access. It is largely a solved problem for mature organisations, at least in its basic form.

Identity governance is the organisational discipline of making and maintaining decisions about who should have access to what, on what basis, and for how long. It requires that someone owns those decisions, that there is a process for reviewing them over time, and that the outcome of that process is visible to the people accountable for the organisation’s risk posture.

Most organisations have the first. Very few have the second in a form that would withstand regulatory scrutiny. The distinction matters because the most common identity failures in regulated environments are not technical failures. They are governance failures: excessive permissions that were never reviewed, service accounts that outlived the projects they were created for, privileged access that was granted for a specific purpose and never revoked.

How the governance gap forms

Identity governance gaps are structural. They form through a combination of speed, fragmentation, and misallocated ownership that is predictable rather than exceptional.

Access is provisioned quickly because the business requires it. Access reviews are scheduled periodically but treated as administrative exercises rather than genuine risk decisions. The people conducting reviews are often not the people with the context to assess whether access is still appropriate. They approve what they cannot easily explain, which means they approve most of it.

Cloud adoption compounds the problem. Cloud environments provision access at a scale and velocity that manual governance processes cannot match. Infrastructure-as-code creates permissions through automated pipelines. Service-to-service access accumulates without the same visibility as human user access. The identity estate grows faster than the governance model designed to manage it.

The result is an organisation whose technical identity controls are sound and whose effective access posture is unknown. Unknown because nobody has a current, accurate picture of who has access to what, whether that access is appropriate, or whether it has been reviewed.

What regulators see

Identity and access management is one of the most scrutinised control domains in regulatory examinations of cloud environments. Regulators do not examine it because it is technically interesting. They examine it because it is where the most consequential failures concentrate.

What they look for is evidence of a governance process, not just technical controls, but the decision-making structures that determine whether those controls reflect the organisation’s actual access requirements. They ask who owns access decisions for privileged accounts. They ask what triggers an access review outside the scheduled cycle. They ask how the organisation would know if a service account had been compromised and used to move laterally.

Answers that describe technical capabilities without describing governance processes do not satisfy these questions. A well-configured identity platform without a functioning access governance process is a control that exists on paper and erodes in practice.

The governance model identity security requires

Identity governance requires ownership at the business level, not just the technical level. Access decisions are business decisions, they determine who can affect what outcomes in the organisation’s systems. Delegating those decisions entirely to IT or security functions disconnects them from the context required to make them well.

It requires a review process that is genuinely risk-driven. High-privilege access, access to sensitive data, and access that crosses organisational boundaries warrant more frequent and more rigorous review than standard user access. Treating all access reviews with the same cadence and the same level of scrutiny produces a process that is thorough in appearance and superficial in effect.

It also requires that the organisation accepts an uncomfortable operational constraint. Access that cannot be justified should be revoked, even when revocation creates friction. The friction of access removal is recoverable. The consequences of unreviewed access in the hands of a compromised account are not.

Identity is the perimeter. The governance model that perimeter requires is not yet standard practice. For regulated organisations, that gap is not a future problem. It is a current one.

Share the Post:

More Posts

Data Residency Decisions Are Architecture Decisions, Not Legal Ones

Most data residency conversations begin in the legal team and end there. A regulator publishes a localisation requirement. Legal reads it. Legal informs the business that data must stay within a jurisdiction. The business instructs IT to make it so. The matter is considered closed. This sequence is wrong, and

Read More

Why Audit Readiness Is Not the Same as Being Secure

Audit readiness and security are not synonyms. Organisations that have spent years optimising for the former often discover, at the worst possible moment, that they have been neglecting the latter. This distinction is not academic. It shapes how resources are allocated, how risks are framed, and how leadership interprets the

Read More

What Regulators actually expect vs. What most organizations prepare for

Most organizations don’t really prepare for regulators. They prepare for audits. That difference sounds minor. In practice, it explains a lot of regulatory frustration, failed examinations, and uncomfortable post-incident conversations. It also explains why organizations that look solid on paper often struggle the moment they are asked to explain themselves.

Read More