The Identity Chapter of a Security Program, in Plain Budget Terms
Identity is usually the biggest line in a security budget and the one a CFO understands least. Four cost centres, what each one actually buys, and how to defend the total.
Identity is usually the largest line in a security budget and the hardest one to explain upward. This desk covers the leadership decisions: sequencing IGA, PAM, and ITDR; owning non-human identity before it is a tooling problem; what identity debt costs at scale; and what an auditor will actually open when they test access control.
Identity is usually the biggest line in a security budget and the one a CFO understands least. Four cost centres, what each one actually buys, and how to defend the total.
Three identity categories compete for the same budget line and vendors in each will tell you theirs comes first. The sequence is decided by which failure you can already evidence.
Buy a non-human identity tool first and you get a list of eleven thousand identities nobody owns. The ownership decision has to come before the discovery, and it is unglamorous policy work.
An agent built by an engineer who left still holds credentials and still takes actions. Your offboarding checklist was designed for accounts a human logs into, and this is not one.
Identity debt never arrives as a security incident. It arrives as onboarding that takes nine days, an audit finding that recurs, and a migration estimated at one quarter that takes three.
Auditors do not evaluate your identity architecture. They pick names off a list and ask you to prove what happened. Elegant design earns nothing if the record is missing.