I don’t think any practitioners would debate that identity has become a dominant initial access vector for attackers, with several years of incident response data and headline breaches pointing in the same direction.
The industry spent two decades hardening the perimeter, pursuing approaches such as Zero Trust, and attackers responded by simply acquiring a working credential and walking through the front door as a legitimate user.
As the saying goes, hackers don’t hack in, they log in.
That said, most of the conversation around identity risk stays at the level of controls, such as MFA coverage, privileged access, session management, and so on, and rarely gets translated into what the gap actually costs an organization when it goes unaddressed.
Resilient Cyber’s partner Nametag recently published a report titled “The Cost of Doing Nothing: What Unverified Identity Costs Enterprises Every Year,” which attempts to do exactly that, breaking the cost of unverified workforce identity into four dimensions and modeling it across six industries.
In this article I will walk through the report’s core argument, the four cost dimensions, the industry-level figures, and where I think this connects to the agentic identity problem I have been writing about for much of this year.
So, let’s check it out!
Logging In, Not Breaking In
The report opens with a framing that will be familiar to anyone following the incident data.
It cites Sophos analysis of 661 incident response cases across 70 countries and 34 industries between November 2024 and October 2025, in which identity-related root causes drove 67% of successful intrusions, with compromised credentials alone accounting for 42% of root causes. Sophos also found MFA absent or misconfigured in 59% of identity-related incidents, and where MFA was correctly deployed, attackers adapted with adversary-in-the-middle proxies and infostealers that lift active session tokens after authentication completes.
The report pairs this with figures from Cloudflare’s 2026 Threat Report, which found that 63% of logins involve credentials already compromised elsewhere and that 94% of login attempts originate from bots rather than humans.
The economic logic here is straightforward, as it is simply cheaper to use a credential that already works than to develop a new exploit or need to compromise a system. A valid username and password pair is a commodity, and the report’s summary of the situation, “the attackers are not breaking in, they are logging in,” is one I would expect most practitioners to nod along with at this point, as we’re used to hearing it, but it also doesn’t make it less true.
None of this is new to security teams, and the report acknowledges as much.
MFA is deployed, the IdP is in place, and the helpdesk has a runbook for password resets. The argument is that this foundation was built to confirm which account is acting, and it cannot confirm which human is acting. That distinction is the entire premise of the report, and everything downstream flows from that core point.
Accounts Versus Humans
The framing I found most useful is what Nametag calls the workforce identity gap, defined as the structural gap between authenticating an account and verifying the human behind it.
Authentication confirms a credential, but does not confirm the person presenting it, and every downstream control, from role-based access to privileged approvals, inherits that assumption without ever testing it.
The report lays out a four-stage maturity framework for closing that gap.
Stage 1 is manual verification, where helpdesk staff use their best judgment and the organization carries its full loss exposure.
Stage 2 is what Nametag calls compliance-grade verification, meaning point-in-time selfie matching bolted onto custom integration logic, which the report estimates retains 50 to 60% of baseline exposure.
Stage 3 adds 3D liveness, cryptographic device binding, and identity orchestration, reducing residual exposure to 15 to 25% of baseline.
Stage 4 is continuous assurance across the entire workforce lifecycle, with residual exposure in the single digits as a percentage of baseline.
Nametag’s view is that most organizations sit at Stage 2, and that the cost of waiting is the difference between Stage 2 and Stage 4, multiplied by every week the gap stays open.
I would add that many organizations I have seen are honestly closer to Stage 1 than they would like to admit, with verification for high-risk actions like credential recovery still coming down to whether the person on the phone sounds plausible and knows a manager’s name.
The report also argues that compliance-grade identity verification clears the audit checkbox without closing the actual gap, and anyone who has watched a homegrown verification workflow accumulate human resource system webhooks and custom logic over a few years will recognize the maintenance burden it describes.
Four Ways Inaction Shows Up on the Books
The heart of the report is a breakdown of the cost of inaction into four separate dimensions, each owned by a different executive, each accruing in a different part of the budget, and each paid whether or not the others are.
These are four distinct bills rather than one cost that compounds on top of another, which is part of why the exposure is easy to miss, since no single owner sees the whole picture.
The figures throughout are illustrative for a 15,000-employee organization, which matters for how you read them, since Nametag notes they scale roughly linearly with workforce size.
Operational efficiency is the IT labor and overhead of running manual identity verification. The report uses HDI’s benchmark of $25 per helpdesk ticket in labor and tooling, and Nametag’s own deployment data puts the enterprise identity verification figure at $3.45 per ticket, roughly an 86% reduction, primarily from routing verification events through self-service workflows that never touch the helpdesk.
At the modeled scale that works out to $1.25M annually in IT labor at the manual baseline. The report also calls out the hidden costs here, such as custom integration work running into tens of thousands of dollars per use case with roughly 20% annual maintenance on top, and the fact that helpdesk headcount scales linearly with the workforce, so every new employee adds verification volume that has to be absorbed somewhere.
Workforce productivity is the flip side of the same friction. Every hour the helpdesk spends verifying someone is an hour that employee spends waiting, and the report values those hours at fully loaded compensation, ranging from roughly $37 an hour in hospitality and retail to nearly $90 in technology.
Annual productivity loss lands between $1.92M in Hospitality, Retail & Consumer and $4.48M in Technology. The healthcare figure is the one stated in concrete terms, at 22,500 clinical hours lost per year, which the report equates to 5,400 primary care visits. Nametag estimates enterprise identity verification recovers roughly 80% of those hours.
Annual Loss Expectancy (ALE) is where the CISO and CFO share ownership. This is standard actuarial math, the probability of an identity-based breach in a given year multiplied by the average cost when it happens.
The report anchors the cost side on IBM’s 2025 Cost of a Data Breach Report, which puts the U.S. average at $10.22M and the global average at $4.4M, with Healthcare at $7.42M for the fourteenth consecutive year as the most expensive sector.
Baseline ALE ranges from $1.27M in Transportation to $4.97M in Healthcare, and Nametag models a 92% reduction in annual rate of occurrence with enterprise IDV, based on its own deployment data.
The report is direct that this constant comes from Nametag deployments rather than independent research, and applies it uniformly across industries, which is something to keep in mind when reading the residual figures. That said, it is refreshing to see that transparency from a vendor, which isn’t often so common.
Hiring fraud is the fourth dimension, and the one I suspect will be new territory for many readers, so it gets its own section below.
The report’s preferred way of reading all of this is by the week rather than the year.
Taking the four costs together, Healthcare carries roughly $150,000 a week in identity exposure, Technology $134,000, and Industrial Manufacturing $126,000. The annual figure is the headline, but the weekly rate is a more honest way to think about the cost of a deferred decision, since every procurement cycle that slips a quarter has a number attached to it.
Hiring Fraud and Strict Liability
Hiring fraud is the identity risk that arrives before an employee’s first day, and the past two years have made it a mainstream concern rather than a niche one, with the rise of deepfakes and nation state fraud campaigns.
The report cites a Gartner survey finding that candidate fraud makes up roughly 25% of application volume in remote technology roles in 2026, most of it automated AI-generated applications and resume fraud.
The smaller and far more dangerous slice is sophisticated identity impersonation, and here the report leans on Mandiant’s M-Trends 2026, which documents North Korean IT worker operations as a persistent insider threat throughout 2025 with a median dwell time of 122 days before detection and some cases running undetected for over a year.
Those of us who have followed the Treasury, FBI, and DOJ advisories on this know the playbook, with AI-generated profiles, deepfake interview tooling, and U.S.-based laptop farms used to embed operatives directly into Western corporate payrolls. The report notes a single 2025 federal case that named 309 U.S. companies which had unknowingly placed North Korean operatives on payroll, including Fortune 500 firms in technology, aerospace, automotive, and media.
Nametag breaks the cost into three buckets.
The first is recruiter labor spent investigating suspect applicants, roughly 2,600 hours a year at $43 an hour fully loaded, or about $112,000 annually whether or not a fraudulent hire is ever caught.
The second is the economics of placements that succeed, with roughly eight fraudulent placements a year at a typical enterprise drawing about $625,000 in salary against the 122-day median dwell plus another $415,000 in ramp and vacancy loss, for roughly $1.08M annually.
The third bucket is categorical rather than operational. Civil penalties for paying a sanctioned individual are strict liability under federal law, so intent and awareness do not matter.
The report puts the penalty at up to $377,000 per paycheck issued, with each paycheck treated as a separate violation, and a 122-day median dwell generates roughly nine paychecks. That is a maximum civil exposure of $26.7M per fraudulent placement, before any criminal exposure or remediation cost.
The point the report makes about existing hiring controls is a fair one.
A background check confirms that records match a candidate’s stated history, and a video interview confirms a face matches the documents, but neither confirms the person presenting those records is real or that the face on camera is the one that shows up on day one.
State-sponsored operatives use stolen identities from actual U.S. citizens whose records pass every standard check cleanly, which is precisely why the standard checks do not catch them.
What Doing Nothing Costs By Industry
Taking the four separate costs together and excluding OFAC exposure, the report puts the annual cost of inaction for a 15,000-employee organization at:
$7.8M in Healthcare, $6.96M in Technology
$6.54M in Industrial Manufacturing, $5.25M in Education
$4.31M in Transportation
$4.12M in Hospitality, Retail & Consumer
Each industry chapter pairs the numbers with a breach the reader will recognize, and the common thread across all of them is that none began with a software exploit.
Change Healthcare began with credentials on a Citrix portal that lacked MFA, with attackers operating for nine days before deploying ransomware and UnitedHealth Group reporting an $872M financial impact in the first quarter following the attack.
Snowflake began with credential stuffing against customer accounts lacking MFA, with data exfiltrated from more than 160 enterprise customers.
MGM and Caesars began with a ten-minute social engineering call to the helpdesk. The Diesel Vortex cargo theft operation in the transportation chapter began with voice-AI impersonation of freight brokers and dispatchers and generated $725M in cargo losses.
The sector-specific structural conditions are what make each chapter worth reading on its own. Healthcare runs on identity at a scale no other sector matches, with physicians carrying dozens of active logins and affiliate clinicians moving through the same identity stack with weaker governance.
Technology concentrates the cost in its most expensive labor, and the report notes identity-driven breaches there average 210 days of dwell, the longest of any sector, because the same DevOps access patterns that enable velocity also make anomalous behavior harder to spot. Hospitality and retail run 70 to 100% annual frontline turnover, which turns the helpdesk into the attack surface of choice.
Over a 24-month horizon, the report models a healthcare organization absorbing roughly $15.7M across the four costs by leaving the gap open, versus $1.3M with enterprise IDV in place and $8.6M with compliance-grade verification, which only closes about half the gap. The costs do not build on one another over that period, they simply keep accruing in parallel for as long as the gap stays open.
Where This Meets the Agentic Identity Problem
The section of the report I want to spend the most time on is the shortest one, a brief aside titled “AI Agents and the Authorization Question.”
Nametag’s argument is that enterprise AI agents act on credentials, authenticating as a human user, holding the same access rights, and executing workflows that move money, change records, and grant access. When an agent’s action triggers a high-consequence outcome, the question of who authorized it has to be answerable, and the verified human layer that closes the workforce identity gap is the same layer that makes agent actions accountable.
I have spent much of this year on exactly this problem. In “Identity Is the Agentic AI Problem Nobody Has Solved Yet“ I argued that the IAM industry built decades of infrastructure on the assumption that requests come from humans or from predictable service accounts, and that agents fit cleanly into neither category.
In “Identity as Infrastructure in the Agentic Era,” Karl McGuinness and I walked through why the problem is less about authentication and more about delegation, or as Karl put it, “agents don’t need your passport, they need your authority”.
Now, to be clear about what this report is and is not, it is a workforce identity verification report, and the agentic material occupies a page. It does not attempt to solve delegation chains, scoped authority, revocation, or any of the substrate problems Karl and I discussed. That said, I think the connection it draws is the right one, and it clarifies something I have been circling for a while.
Every delegation chain terminates in a human.
An agent acting on my behalf carries my authority, and the entire governance model for that agent, from the initial grant through every subsequent tool call, rests on the assumption that the “me” who granted it was actually me.
If the account that provisioned the agent, approved its scope, or authorized the high-consequence action was itself operated by someone who socially engineered a helpdesk reset last Tuesday, then every downstream control built on that grant is governing an attacker’s intent with full fidelity. The identity gap the report quantifies for workforce actions today gets inherited wholesale by every agent those workers stand up, and the volume multiplies with it.
This is why I think the “verify at login” mental model is running out of road.
The report frames verification around four moments where the existing stack assumes a human is present, recovery, helpdesk, hiring, and elevated-privilege approvals, and I would argue that agent provisioning and scope expansion belong on that list as a fifth.
Knowing that the human behind the account is the same human behind the request, every time, is the root of trust that agentic security will have to be built on, and we do not get to skip that step.
There is a budgeting implication in that as well. The report frames these four costs as IT, HR, and security line items, which is where they land today, but if the verified human layer is what makes agent actions attributable, then the spend to close the gap belongs in the AI budget alongside the platforms and tooling it is meant to govern.
Most organizations standing up agents are already carving out a responsible use or AI governance line, and I would argue that human identity verification is a more defensible entry on that line than much of what currently sits there, since it is the control every other agent control depends on.
Also, if you are interested in the rise of Deepfakes, identity and the role of AI, Nametag’s CEO Aaron Painter has a new book coming out called “Deepfaked”, be sure to check it out here!
Closing Thoughts
This is far from an exhaustive discussion identity challenges or its intersection with Agentic AI, and the usual caveats apply to any vendor-modeled cost report.
The figures are illustrative for a 15,000-employee organization, the reduction constants come from Nametag’s own deployments, and the report itself says the numbers are a starting point for an internal modeling exercise rather than a substitute for real-world analysis tied to your incident history and I would treat them that way.
That said, the underlying inputs are public, the external anchors (IBM, Verizon, Sophos, Mandiant, HDI, and the OFAC penalty schedule) are the ones most of us already cite, and the core argument holds regardless of how the constants shake out.
Authentication confirms an account, and nearly everything we do in security downstream of that assumes it also confirmed a human. The incident data says that assumption is where most intrusions now start, and we are about to hand the same unverified assumption to autonomous systems operating at machine speed.
The status quo, as the report puts it, is an expensive option that does not show up that way on any single budget line, which is why it stays in place. Whether the exact number is $4M or $8M a year for your organization, it is a number, and it is worth knowing before the next procurement cycle slips another quarter. You can read the full report, including the industry chapters, here.









