Sophos State of Identity Security Reveals Hidden Crisis

The Sophos state of identity security report reveals how identity attacks are becoming the new gateway to ransomware, financial theft, and critical infrastructure cyber attacks as AI-driven systems rapidly expand across enterprises.

author-image
DQChannels Bureau
New Update
Sophos State of Identity Security Reveals Hidden Crisis

The latest Sophos state of identity security report highlights a major shift in how cyberattacks are evolving across enterprises. Instead of attacking systems directly, cybercriminals are increasingly targeting identities, both human and machine, to gain access to sensitive networks, applications, and business operations. For Indian organisations, the numbers are becoming difficult to ignore.

According to Sophos, nearly 77% of organisations surveyed in India experienced at least one identity-related breach in the past year. Even more concerning, 79% of ransomware victims said their attacks began through compromised identities. The findings point to a growing identity crisis where access management weaknesses are quietly becoming the foundation of larger cyber incidents.

AI Growth Is Expanding the Attack Surface

The report shows that the rapid adoption of AI-driven systems, APIs, cloud services, and automated workflows is creating new security blind spots. One of the biggest concerns is the rise of non-human identities, machine accounts, service accounts, API keys, and AI agents that operate without direct human involvement.

Sophos notes that weak non human identity security vulnerabilities are now playing a major role in cyberattacks globally. Many organisations still fail to regularly rotate credentials or monitor service accounts, even as AI systems automatically create new access layers across enterprise environments.

This becomes especially risky as agentic AI systems continue scaling. AI agents can generate additional sub-agents and credentials autonomously, creating access points that often escape traditional monitoring systems.

Critical Infrastructure Faces the Highest Exposure

The report also reveals that critical infrastructure cyber attacks are accelerating across sectors like energy, oil and gas, utilities, and government institutions. These industries recorded some of the highest breach rates globally, showing how identity compromise is no longer just an IT problem but a broader operational and national security concern.

Sophos also found that organisations struggling with compliance requirements experienced significantly higher breach rates. The data suggests that fragmented governance and weak visibility into identity activity are leaving enterprises vulnerable even before attacks begin.

Why Detection Still Remains Weak

One of the clearest patterns from the report is the lack of continuous monitoring. Only a small percentage of organisations globally constantly track unusual login behaviour, while many review identity activity only once every few months.

This delay creates a major detection gap. By the time suspicious access is identified, attackers may already have moved deeper into enterprise systems. Financial losses remain steep, with global recovery costs averaging over US$1.6 million per incident.

The Push Towards Zero Trust and Identity Governance

Sophos believes organisations now need a layered identity strategy that covers both human and machine identities equally. The company recommends stronger Multi-Factor Authentication, least-privilege access policies, continuous monitoring, and faster removal of inactive accounts.

For enterprises expanding AI adoption, the focus is also shifting towards Identity Threat Detection and Response platforms, secrets management systems, and Zero Trust security models. The report makes it clear that as AI ecosystems grow, identity protection is becoming central to enterprise resilience.

The larger message from the Sophos state of identity security report is simple: in the AI era, identities are fast becoming the new security perimeter. Organisations that fail to secure them may find ransomware, financial theft, and operational disruption following closely behind.

Read More:

Pelorus Technologies Varonis partnership targets AI-Era threats

AMD unveils Ryzen AI Max PRO 400 Series to power next-gen local agent computers

NewgenONE enterprise orchestration layer pushes AI beyond automation

Wellknown Computers hosted Lenovo India leadership focusing on channel retail strategy

Advertisment