Skip to content
← Insights Hub
Cybersecurity4 min read

Identity-First Security: An ITDR Primer

In 2026 the perimeter is identity, and most breaches start with a stolen login — human or machine. A plain-English primer on ITDR and why it now matters to the mid-market.

Identity-First Security: An ITDR Primer

For years, security meant guarding the edge of the network — firewalls, VPNs, a hard shell around a soft centre. In 2026 that model is effectively obsolete. Work happens across cloud, SaaS, and devices that were never inside your walls, and attackers have noticed: the overwhelming majority of incidents now begin not with a broken firewall but with a valid login in the wrong hands.

Industry data keeps repeating the same headline — the large majority of breach investigations involve an identity weakness, and most initial access is identity-driven: phishing, stolen credentials, session hijacking, or abuse of an over-privileged account. The new perimeter is identity. Which is exactly what Identity Threat Detection and Response (ITDR) exists to protect.

What ITDR actually is (in plain English)

You've likely heard of EDR (endpoint detection) and XDR. ITDR is the same idea pointed at identities. It continuously watches how accounts behave — where they sign in from, what they access, when privileges change — and flags the patterns that signal a compromise: a credential suddenly used from a new country, an account escalating its own permissions, one login quietly moving sideways across systems.

Where traditional tools ask "is this device infected?", ITDR asks "is this login really who it claims to be, doing what it should?" In an identity-first world, that's the question that matches how attacks actually happen.

The part most teams miss: non-human identities

Here's the 2026 twist. When people think "identity," they picture employees. But in most organisations, machine identities now outnumber human ones by roughly ten to one — API keys, service accounts, OAuth tokens, pipeline credentials, and, increasingly, the credentials your AI agents carry. Each is a valid login. Each can be stolen. And huge numbers of them are sitting exposed in code and configs right now.

This connects directly to agentic automation: every agent you deploy is a new non-human identity with real access. Treat those identities as first-class citizens — with their own behavioural baselines and least-privilege scope — or they become the softest way into your estate. Identity security and AI governance are two views of the same discipline.

Why the mid-market can't sit this out

There's a myth that identity-based attacks are a big-enterprise problem. The opposite is true: mid-sized organisations often have the same sprawl of SaaS, cloud, and service accounts, but fewer people watching them — which makes them easier targets, not harder. The good news is that the fundamentals don't require a Fortune-500 budget.

A pragmatic starting point

You don't need to buy every tool on the market. You need to get the basics right, in order:

  1. Inventory your identities — human and non-human. You can't protect logins you can't see. Start with privileged accounts, service accounts, and any credentials in code.
  2. Enforce least privilege. Most accounts hold far more access than they use. Trim it — every unused permission is attack surface.
  3. Make phishing-resistant MFA the default, especially for admins and service access.
  4. Add behavioural detection (ITDR) so an abused-but-valid login is caught by how it acts, not just whether the password was right.
  5. Rehearse the response. Know how you'd revoke a token, rotate a key, and lock an account — before you need to.

This is the same identity-first, zero-trust approach behind our Cybersecurity & Resilience work, and it pairs naturally with the governance discipline every AI programme needs.

The bottom line

In 2026, defending the network edge while ignoring identities is guarding the door while leaving the keys under the mat. Assume attackers will arrive with a legitimate login — human or machine — and build so that the behaviour gives them away. Inventory your identities, cut privilege to the bone, make MFA phishing-resistant, and add detection that watches how logins act. It's the highest- leverage security work most mid-market organisations aren't yet doing.

Want a clear-eyed read on your identity exposure — including the non-human ones your AI is creating? Let's talk.


Written by KamSoft Consultants. Have a similar challenge? Talk to us.