New research: the Runtime Identity Security category, defined. See how Whiteswan closes the gap →
Start a pilot
Start a pilot

Home / Resources / Industry Data

Industry Data

Why 93% of Organizations Keep Having the Same Breach Twice.

It isn't because the second breach uses a smarter attack. It's because the identity architecture underneath both breaches was never designed to notice the difference between the first one and the next.

Where the Gap Actually Comes From

The Decision Was Made in 1988, and Nobody's Revisited It Since.

In 1988, MIT's Project Athena shipped Kerberos — the authentication protocol that still, in spirit, underpins how most enterprise identity systems decide who gets in. Its central mechanism was the ticket-granting ticket: authenticate once, and the system issues you a credential that stands in for you for the rest of the session. It was a reasonable engineering trade-off for a campus network of workstations and a few thousand users. It was never a security philosophy. It was a way to avoid asking for a password twice.

That single design decision — trust the session once the login succeeds — is still the load-bearing assumption in identity architectures built forty years later, long after the conditions that made it reasonable stopped applying. The industry didn't choose to keep deciding once. It just never had a forcing function to stop.

What Decide-Once Actually Requires

Four Conditions Have to Hold. None of Them Still Do.

Condition 1

Most identities are human.

Machine identities now outnumber human employees 82 to 1 *. The exception swallowed the rule.

Condition 2

Sessions are short and watched.

Standing privileged access, by definition, isn't short — and ~90% of incidents happen in exactly the post-authentication window nobody's watching *.

Condition 3

The perimeter means something.

Cloud infrastructure, remote work, and third-party access dissolved the network boundary Kerberos was designed inside of years ago.

Condition 4

Every identity can explain itself.

Only 18% of organizations are highly confident their identity stack can manage agent identities at all *. Most identities today can't answer for themselves, and the stack wasn't built to ask.

Every product that's patched identity security for the last two decades — MFA, SSO, periodic access reviews — has solved one or two of these conditions. None has solved all four at once. That's the gap that reopens every time an organization has "the same breach twice."

The Numbers, Back to Back

No Transitions. Just What's True.

93% of organizations had two or more identity-related breaches last year.

82 machine identities for every human employee.

~90% of security incidents happen after authentication already succeeded.

87% of 2024 breaches involved identity exploited post-login.

88% of organizations report a suspected or confirmed AI agent security incident.

18% are highly confident they can govern agent identities at all.

68% cannot tell an agent's actions apart from a human's in their own environment.

Every figure sourced below. None of them are ours.

What Whiteswan Does About It

Standing Access Was a Compromise, Not a Design Choice.

Whiteswan replaces the decide-once assumption directly: every access request — human, service account, or AI agent — is decided and enforced in the same motion, at the moment it happens. Nothing stands.

The Gap Widens With Every Agent You Deploy.

The 82:1 ratio and the 68% figure aren't separate problems — they're the same problem compounding. Whiteswan's Agentic Gateway attests every AI agent's identity at spawn and inspects every tool call against policy, so the ratio stops being unmonitored risk.

Evidence Has to Be Built at Runtime, Not Reconstructed for an Audit.

The 93% recurrence figure is what happens when the only record of an access decision is a log entry someone reviews after the fact. Whiteswan's decision engine produces the evidence trail as a byproduct of enforcement — generated the moment access happens, not assembled the week before an audit.

Primary Sources

Where This Data Comes From.

CyberArk 2024 Identity Security Threat Landscape Report

Commissioned by CyberArk and conducted by Vanson Bourne, surveying 2,400 security decision-makers across 18 countries. Cited for the 93% breach-recurrence figure and the 82:1 machine-to-human identity ratio.

Unit 42 Incident Response Report, 2025

Published by Palo Alto Networks' Unit 42 threat intelligence and incident response team. Cited for the post-authentication incident figures (~90% and 87%).

Cloud Security Alliance Agentic Identity Research (CSA / Strata, CSA / Aembit)

Survey research on enterprise readiness for AI agent identity management, published in partnership with Strata Identity (February 2026) and Aembit (March 2026). Cited for the 18% and 68% agentic identity figures.

So Which Condition Is Still Failing in Your Environment?

That's the Question Worth Answering Before the Second Breach.