Skip to Content

Identity confidence vs. reality: The gap persists

Identity confidence vs. reality: The gap persists

Another week, another industry report - and another reminder that the biggest risks in security are often the ones organizations think they’ve already solved.

The latest research from the FIDO Alliance and HID doesn’t just highlight weaknesses in enterprise identity security - it exposes a fundamental disconnect between what organizations believe is happening and what actually is not. And that gap is wider than many may expect.

On the surface, the numbers are reassuring. In the report, “The State of Physical and Digital Identity in the Enterprise,” nearly all organizations say they can revoke physical and digital access within 24 hours when an employee leaves.

But the reality tells a different story: more than one-third have experienced failures doing exactly that, and 70% report at least one identity-related security incident in the past two years.

That’s not a marginal issue. It’s systemic.

At the heart of the findings is a simple but critical truth: enterprise confidence is outpacing actual capability. This disconnect isn’t driven by a lack of awareness. Most organizations understand the importance of identity security and are investing in it.

The problem is structural. Only half of enterprises have unified reporting ownership across physical and digital identity, and fewer than half have consolidated budget control.

Different teams, systems and priorities are governing what should be a single, coordinated function, creating fragmented environments where no one has complete visibility. In that kind of structure, gaps are almost inevitable - and often invisible until they become incidents.

Fragmentation doesn’t just create inefficiency; it compounds into risk over time. Most organizations are managing multiple identity and credential systems, each with its own workflows for provisioning and revocation. Every additional system introduces another point of failure.

The burden is increased by the fact that lifecycle management is still not fully automated. A meaningful share of credential revocation processes remains manual or only partially automated, introducing delays and increasing the likelihood of human error. In high-risk environments like the public sector, where manual processes are more common, those weaknesses show up clearly in elevated failure rates

What makes the findings more striking is that this is not a knowledge gap - it is an execution gap. The vast majority of organizations already have the strategic pieces in place. Nearly all have incorporated some level of convergence between physical and digital identity into their strategy, and most are actively pursuing passwordless authentication. The intent is clear, and the direction is well understood.

But execution is where the model breaks down. Only a small percentage of organizations have actually deployed passkeys at scale. Partial rollout limits the effectiveness of phishing-resistant authentication, leaving large portions of the organization exposed. Attackers don’t target fully secured environments - they target the gaps. As long as those gaps remain, the overall security posture remains vulnerable, regardless of how advanced individual components may be.

The implications for the electronic security industry are significant. Identity is no longer just about authentication or access control; it is about governance, lifecycle management and maintaining visibility across an increasingly complex ecosystem.

As organizations add more systems, users and credentials, complexity continues to grow. Without stronger integration and automation, that complexity becomes harder to manage - and easier to exploit.

For integrators and solution providers, this shift is redefining where value lies. Customers are no longer just looking for individual tools or technologies. They need solutions that bring together physical and digital identity, automate critical workflows and reduce reliance on manual processes. They need systems that don’t just function but perform reliably under real-world conditions where delays and breakdowns carry real consequences.

The takeaway is clear. Organizations are not as secure as they think they are, and the gap between perception and reality is being exposed in measurable ways. Closing that gap will require more than incremental improvements. It will require treating identity as a unified discipline, automating the full lifecycle of access and moving from limited deployments to enterprise-wide implementation of modern authentication methods.

Until execution catches up with intent, the risk will remain - not as a theoretical concern, but as an active and persistent vulnerability already reflected in the data.

 

Comments

To comment on this post, please log in to your account or set up an account now.