The 2025 IDSA identity security report shows improvement across many identity-risk metrics, with identity-related incidents plateauing or declining and phishing still the most common threat. It also highlights the growing impact of AI and non-human identities on identity management, alongside continued adoption of Zero Trust and strong interest in digital wallets. #IDSA #ArtificialIntelligence #ZeroTrust #DigitalWallets #NonHumanIdentities
Keypoints
- Annual cybersecurity reports like this one typically begin with an introduction, then present the current threat landscape, followed by dedicated sections on emerging technologies or priority domains, a section on persistent challenges, and finally methodology and organizational background.
- The introduction usually explains why the topic matters, defines the report scope, and summarizes the most important year-over-year shifts. In this report, the standout theme is the rapid rise of agentic AI and non-human identities.
- The βstate of identity and securityβ section usually covers incident frequency, common attack types, and changes from prior years. Here, 14% of organizations reported no identity-related attacks in the past year, nearly doubling from 2024.
- Phishing remained the top identity-related threat by a wide margin, but it declined from more than two-thirds of organizations in 2024 to just over half in 2025.
- Other common identity threats also fell, including stolen credentials, brute force attacks, and social engineering. Insider threats and supply chain compromises were less common and landed in the mid-to-low teens.
- The decline in incidents was mirrored by fewer invocations of incident response plans, suggesting that improved defenses and awareness may be reducing operational impact.
- The AI section shows that 30% of respondents experienced an AI-generated identity-related incident, making AI a real and growing concern in identity security programs.
- Executive respondents reported more AI-related incidents than managers and far more than individual contributors, indicating a perception or visibility gap that may need attention in future surveys.
- More than half of respondents said their organizations have some controls in place for AI, but most of those controls still need work. Only 11% said they have all the right controls.
- Respondents were generally less enthusiastic about AI/ML for identity-related use cases than expected, especially outside niche environments, suggesting skepticism about practical value.
- The non-human identity section highlights that NHIs outnumber human identities on the internet by more than eight to one, and two-thirds of respondents now see NHI management as a top-five priority.
- Zero Trust is now mainstream, with the report indicating very high adoption and increasing recognition of its benefits for isolating and protecting critical identities.
- The report emphasizes that Zero Trust investments are producing real business value and operational benefits, reinforcing it as a core identity-security strategy.
- Digital wallets are still in relatively early-stage adoption, but usage is growing for payments, government identities, and some cross-border identity scenarios.
- Close to three-quarters of respondents have a positive opinion of digital wallets issued by neutral third parties, signaling potential for broader acceptance over time.
- Despite progress, 91% of businesses still face barriers to identity security, showing that identity protection remains difficult even in improving conditions.
- Complex environments were the top barrier at 44%, followed closely by identity-framework complexity at 40% and budget shortfalls at 32%.
- Compared with 2024, more respondents said nothing prevents them from improving identity security, which suggests gradual maturation in people, process, and technology readiness.
- The most effective preventive measure identified was revoking access after detecting a high-risk event, followed by access reviews and other access-control practices.
- Access-control measures dominated the list of actions that could have prevented incidents, underscoring that identity security still depends heavily on foundational governance and access hygiene.
- A recurring theme across the report is that identity security is improving, but the increasing complexity of AI, NHIs, and modern architectures is creating new risks that require stronger controls and coordination.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)