Identity

Boards misunderstand identity risk, says cybersecurity veteran

(Adobe Stock)

In a pointed analysis, Simeio CEO Nick Rowe argues that despite 25 years of cybersecurity evolution and significant investment in tools, compromised credentials remain the root cause of most breaches, according to Forbes.

He contends boards fundamentally misunderstand identity risk, treating it as a technical "project" to be completed rather than a continuous "posture" requiring ongoing visibility and measurement. Rowe notes that fragmented tools, from early password managers to modern AI-powered platforms, operate in isolation, creating blind spots that attackers exploit. He warns that the rapid deployment of AI agents and copilots is multiplying identities to manage, accelerating the risk.

"In breach after breach... the root cause wasn't a zero-day exploit. It was simple. Someone had access they shouldn't have had. And nobody knew it existed," Rowe states.

He urges boards to shift from compliance-focused questions to those about real-time exposure, detection speed, and AI governance. The core problem, he argues, is that organizations "treat identity like a project instead of a posture," with access accumulating and permissions drifting unnoticed. Rowe calls for identity risk to be managed with the same rigor as financial risk, with measurement, transparency, and continuous accountability.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds