Identity spending gets cut more often than it deserves for a reason that has nothing to do with its value. It is presented as one number.

A CFO looking at a line called "identity and access management" that costs more than everything else in the security budget has no way to evaluate it. There is no unit, no comparison, and no visible relationship between the number and anything the business measures. Faced with an opaque number, the rational move is a percentage cut, and that is what happens.

The fix is structural rather than rhetorical. Decompose the line before anyone asks you to.

The four cost centres

The directory and authentication plane. Your identity provider, its licensing tier, multi-factor authentication, and single sign-on coverage. This is infrastructure. It scales with headcount, it has a per-seat price everyone recognizes, and it is the easiest part of the budget to defend because the alternative is visible to every employee.

Workforce lifecycle and access review. Joiner, mover, and leaver automation, entitlement catalogues, certification campaigns. This is the part auditors test and the part that is almost always underfunded, because its failure mode is a finding in a report rather than an outage anyone sees.

Privileged access and secrets. Administrative credential vaulting, session management, secrets for applications and workloads. Highest severity per incident, smallest population, and the one where scope creep does the most damage to the budget.

Customer-facing identity. If the company sells software, the login your customers use is a product line, not a security line, and it should be funded from the product budget. Putting it in the security budget makes the security budget look bloated and makes the product look cheap. I have watched this misallocation start arguments in three separate organizations.

Four centres, four different justifications, four different consequences if cut. That is four separate conversations you can win, instead of one you cannot.

Why the obvious answer is wrong

The obvious defence of identity spend is risk. Credential-based attacks, breach statistics, the cost of an incident.

The problem with that argument in 2026 is that the underlying data moved. Verizon's 2026 report put vulnerability exploitation at 31% of breach entry points, passing stolen credentials for the first time in nineteen years of the report. If your identity budget defence has been a slide about credentials being the number one attack vector, that slide is now factually behind, and somebody in the room will know it.

The honest read is more useful anyway. Entry-point coding records only the first step of a breach, and credential abuse appears far more often across full attack chains than at the front door. Identity is not the way most attacks start. It is the way most attacks move. That is a better argument because it is true, and because lateral movement is the part of an incident that determines whether it is a contained event or a company-ending one.

The discriminating variables

Is customer identity in this budget?

The test: does the number include the login your customers use? If it does, move it to product before the next planning cycle. It is the single largest distortion in most security budgets and it is a bookkeeping fix, not a negotiation.

Can you state the coverage gap in each cost centre?

The test: what percentage of privileged accounts are vaulted, what percentage of applications are behind single sign-on, and how long does deprovisioning actually take? Three numbers. If you cannot produce them, you are asking for money to improve something you have not measured, and that is the request most likely to be cut.

Is the spend growing faster than headcount?

The test: compare identity spend per employee across three years. Growing faster than headcount is not automatically wrong, particularly during a cloud migration, but it needs a stated reason. Unexplained per-head growth is what triggers the audit of your budget rather than the approval of it.

Which cost centre is the audit finding in?

The test: open the last audit report and map each identity finding to a cost centre. Findings concentrate in lifecycle and review, almost never in the authentication plane. That mapping is the strongest budget argument available, because it converts your request into remediation of a documented finding.

What each centre actually contains

Useful when you sit down to split the number, because the boundaries are not obvious and the misfiling is where the distortion comes from.

Directory and authentication. Identity provider licences at whatever tier you are on, multi-factor tokens or hardware keys, the single sign-on connector count if your vendor prices that way, and any directory synchronisation infrastructure. The tell that something belongs here: cost moves with employee headcount and nothing else.

Lifecycle and access review. Governance tooling, the connector or integration work to onboard each application into it, certification campaign tooling, and the internal time that campaigns consume. That last item is real money and it is almost never counted. A quarterly campaign across two hundred managers is several hundred hours a year of somebody's attention.

Privileged access and secrets. Vaulting, session recording, just-in-time elevation, secrets management for applications and workloads, certificate lifecycle if you own it. Cost moves with the number of privileged accounts and the number of workloads, which are different growth curves and should be modelled separately.

Customer identity. Everything in the login your customers use. Belongs in product.

The two boundaries people get wrong: secrets management often gets filed under engineering tooling rather than identity, which makes the identity budget look smaller and the picture less honest; and certification campaign time gets filed nowhere at all, which is why access review is chronically under-resourced.

The three coverage numbers to have ready

Whatever else you bring to a budget conversation, have these, and have them as measurements rather than estimates.

Single sign-on coverage. Applications behind SSO as a share of applications in use. The denominator is the hard part and the interesting part: most organizations discover their real application count is between two and four times what the identity team assumed, because software-as-a-service purchases never touched them.

Privileged account vaulting rate. Privileged accounts under management as a share of privileged accounts that exist. Same denominator problem, worse, because the population includes service accounts nobody enumerated.

Deprovisioning time, at the ninety-fifth percentile. Not the average. The average is always fine and the average is not what an auditor samples. The ninety-fifth percentile is the number that tells you whether your stated window is real.

Three numbers, all of them uncomfortable the first time you produce them, and all of them stronger than any argument you could construct without them. A budget request that opens with "we are at 61% single sign-on coverage against a target of 95%, and here is the cost per point" is a different conversation from one that opens with a threat landscape slide.

Decision table

Cost centreWhat it buysCut it andBest justification
Directory and authenticationEvery employee's front doorEveryone notices immediatelyPer-seat, benchmarked, uncontroversial
Lifecycle and access reviewEvidence that access is correctThe next audit finds itA named audit finding
Privileged access and secretsBlast radius controlNothing visible until it matters enormouslyIncident severity, not frequency
Customer identityA product featureRevenue noticesMove it out of this budget entirely

What changes the answer

An acquisition. Two directories, two entitlement models, and a deadline. Integration cost sits in lifecycle, not in the authentication plane, and it is routinely underestimated by a factor of two because the licensing arithmetic is easy and the entitlement reconciliation is not.

A regulated sector. DORA and NIS2 both put obligations on access control with dates attached, which moves lifecycle spend from discretionary to committed. Use the date.

Under two hundred employees. The four-centre split is overhead at that size. One line is fine, and the real risk is spending on governance tooling before there is enough process to govern.

A cloud migration in progress. Expect privileged access and secrets to grow faster than everything else, because workload identity multiplies in a way headcount does not. Say so in advance rather than explaining it afterward.

Where the money usually goes, and where it should

A rough shape from mid-size organizations, offered as a prompt for comparison rather than as a benchmark, because the sample is my own experience and not a survey.

Typical split: directory and authentication takes half to sixty percent, privileged access takes fifteen to twenty-five, lifecycle and review takes ten to twenty, and customer identity is wherever it landed.

The distortion is almost always the same. Directory and authentication is over-weighted because it is the easiest thing to buy and the vendor sells upward through licence tiers. Lifecycle and review is under-weighted because its failure mode is a finding rather than an outage, and nobody is paged for a finding.

Meanwhile the audit findings concentrate in lifecycle, the incidents concentrate in privileged access, and the spend concentrates in the directory. That mismatch is the single most common structural problem in identity budgets and it is visible the moment you split the line, which is the whole argument for splitting it.

If your split looks like the typical one and your findings look like the typical ones, the honest recommendation is to move money from tier upgrades to governance connectors. That is a less exciting purchase and a considerably better one.

The line to expect pushback on

Lifecycle and access review, every time.

It is the least visible of the four, its failure mode is a document rather than an outage, and the tooling is expensive relative to how tangible it feels. A CFO looking at a governance platform quote sees a large number attached to something that produces reports.

The counter that works is not a risk argument. It is the audit finding, plus the deprovisioning number at the ninety-fifth percentile, plus the cost of the manual campaign you are currently running. That third element is the one people forget: the alternative to buying governance tooling is not zero, it is several hundred hours a year of managers doing certification in spreadsheets, and nobody has ever put that number in a budget line.

What to do Monday

Take the identity number in your current budget and split it four ways on one page. Then write the coverage percentage next to each, even if you have to estimate it and mark it as an estimate.

If customer identity is in there, move it. That change alone usually improves how the security budget reads more than any argument you could make about it.