Skip to main content

Identity is the front door to data

Have you ever tried to account for every key to your home?

Probably not, and not because anything seems suspicious. Most of them have perfectly good explanations. Your young college-going child has a set, which is exactly as it should be. A neighbor has one, and you were glad of it the week you were away and the boiler failed. Those are not the problems.

The problem is much quieter.

There was the key you misplaced two years ago and never found, so you had another one cut. That solved your problem at the time. It didn’t affect the original, wherever it now is. There is the window upstairs whose key has not been seen since you moved in, so it stays shut and nobody thinks about it. And there is the skylight you wanted open all through the summer. The key turned halfway and stopped. You think about it most days, usually when the room is too warm, and then something else claims your attention and the thought fades away.

You lock the front door every night. You are careful about it. But if someone asked how many keys exist, who holds them, and which still work, you may not be able to answer.

Nothing has gone wrong. Yet. And that is precisely the point.

Now replace the house with your data estate, and the keys with credentials.

For over thirty years, protecting information meant protecting a place. Data sat inside a network, and security was a question of who could cross the boundary. That boundary has gone. Data now sits across multiple clouds, collaboration tools and analytics environments, and increasingly inside AI systems that read and reason over it. Now what stands in front of it is no longer a wall, but a lock and a claim about who holds the key.

That claim is identity. The key is its only evidence, and the lock will turn for whoever presents it.


Identity is the front door to data. And as with the house, there is never just one. There are thousands, most opened by something that is not a person.

Solving access problems by issuing more access?

Consider the misplaced key. The instinct was to restore function, not to close exposure. Cutting a new key was quick; changing the lock meant re-keying everyone who legitimately holds one.

Organizations do this constantly, at scale. An integration breaks, so a new service account is created. A migration needs elevated rights, so a credential is issued with every intention of tidying up later. Each decision is defensible alone.

But identity programs were built around people like joiners, movers and leavers, managers who certify access, colleagues who notice an absence. None of that applies to a non-human identity, a service account, a workload, a pipeline authenticating to another machine with nobody in the loop. Ithas no manager and no leaving date. That population grows quietly in a direction governance was never designed to address.

What has actually shifted

Attackers rarely break in. They use keys that work.

Verizon’s 2026 Data Breach Investigations Report (DBIR) found credential abuse present at some point in 39% of breaches, while vulnerability exploitation became the leading initial access vector at 31%. Exploitation gets an intruder onto the estate; credentials give them access to the data.. It also found 73% of ransomware victims had an associated infostealer or credential leak in the preceding year, half within 95 days. The key was usually copied long before the door was tried.

Visibility has become the limiting factor.

Gartner’s 2026 Hype Cycle for Digital Identity describes a landscape reshaped by AI agents, identity visibility and identity threats, and names workload identity management as an emerging discipline because non-human identities are growing faster than the human identities. An unowned credential acquires a protected status: nobody knows what depends on it, so nobody touches it. The window stays shut, and we quietly call that safe.

The risks we already know about are the ones we live with.

The skylight is not an unknown risk. It is a known one, thought about often and never closed. Every estate has its equivalents: the shared service account everyone recognizes, the legacy authentication exception, the audit finding carried into a fourth quarter. These are failures of prioritization more than of intelligence, and they persist because nothing in the calendar forces the decision.

Some keys are held by people we never counted as insiders.

When the lock jammed, the locksmith was alone with the mechanism for twenty minutes. He was never given a key; he was given access to the entire lock to cut another key, and nobody asked what he did with that. Enterprises grant that access routinely – to integrators, auditors, the vendor whose platform issues the credentials. Third-party involvement now features in 48% of breaches, a 60% year-on-year rise, according to the above-mentioned Verizon 2026 DBIR. The difficulty is not that these relationships exist, but that questioning them at the time would have felt discourteous.

We have begun delegating judgement, not just access.

Before you bought the house, a real estate / letting agent held a key and showed strangers round on afternoons the owner knew nothing about. Every visit was legitimate. The owner had not authorized the individuals; only the arrangement. That is delegated authority.

The same arrangement is now forming inside enterprises. An AI agent does not simply log in and act for itself; it acts on behalf of a user, across systems, in sequences nobody wrote down in advance. Researchers anticipate more than 1.3 billion AI agents in operation by 2028. Authenticating them is easy. The harder question is whose authority each one carries, how far it extends, and who answers for what it does.

Leadership connect and decisions

Identity has become an entire infrastructure rather than a supporting function. It governs how safely an organization adopts automation and how credibly it describes its exposure to a board. It is also where Zero Trust becomes concrete. The lock that turns for whoever presents the key is exactly the model Zero Trust exists to replace: one check at the threshold, then trust. Verifying continuously and granting every identity (human, workload or agent) only the access it needs, is what stops the lock being the only check.

Three questions reveal more than any maturity score can:

  1. Who owns the non-human population? Workforce identity usually has a clear owner. Machine identity is spread across platform, application and cloud teams, with no single accountable view. That is a governance decision before it is a technical one.
  2. Can we describe access in terms of data rather than systems? Boards do not ask which entitlements different groups hold. They ask what a compromise of a given credential would expose. Knowing who came through the door is not the same as knowing what is in the room.
  3. Does our lifecycle discipline extend to things that never leave? Standing access is the compounding risk in most estates. Time-bound access is hard to retrofit, far easier to design into agent and workload programs now.

None of this argues for moving more slowly. It argues for building identity capability at the same pace as the automation it is expected to govern, because the alternative is not caution. It is unmanaged trust.

Looking ahead

Let’s return to the house one last time. The unsettling part was never the prospect of a burglary. It was realizing you could not answer a simple question about your own front door, and that nothing in your routine would have prompted the question.

Most organizations are in the same position with considerably more at stake. The next few years will not be won by whoever accumulates the most controls, but by those who can answer three questions about any identity in their environment – a person, a workload or an agent:

What is this for?

What can it reach?

And how would we know if that changed?

These are the three questions that Atos is building its identity work around. They may sound plain, but are much harder than they look, and we would rather be early to them than fluent about them afterwards.

Let’s talk about how we can get there faster. Write to us.

Share this article

X IconLinked-in Icon

Anubhav Banerjee

Cybersecurity Global Product Director – Identity Security

View detailsof Anubhav Banerjee >
  • Follow Anubhav Banerjee on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Protecting what matters most in the AI economy