Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Identity APM Has Gone Mainstream. The Hard Work Is Just Starting.
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | SpecterOps ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Today SpecterOps published the “Trends in Identity Attack Path Management 2026” report. The survey, conducted by Omdia on our behalf, covers more than 500 cybersecurity decision-makers at enterprises across the U.S., U.K., Canada, France, Germany, and Australia.
The numbers show meaningful growth in adoption, budget, and strategic priority. But what I want to talk about is why and how to apply timely pressure to rally cross-functional and executive support to achieve operational maturity.
Adoption is not the story
Seventy-five percent of respondents increased identity security spending this year, up from 57% in 2025, outpacing every other security category in the survey. Thirty-five percent have fully implemented an identity-based APM solution, up from 21% a year ago. Another 30% are actively researching or evaluating one.
Budget movement is a stronger signal than stated interest. Organizations aren’t just saying identity matters; they’re allocating resources to it. So what’s behind this shift?
Adoption figures measure what organizations have acquired, but they do not measure what those organizations can actually do with what they’ve acquired. That distinction is where this year’s data gets more interesting.
The prioritization problem is structural
Organizations have deployed the tools. They have the findings. They are still unable to decide what to fix first.
That is not a technology failure. Prioritization requires a judgment the technology does not make for you: which exposure, if remediated, produces the greatest reduction in attacker freedom of …