Spirit Managed Services is now branded Infotrust.
Cyber Emergency Number:
IT Support Number:
Blog

From Identity Management to Identity Security

Tim Sim, Head of Identity Security
September 4, 2026
Home

Let's Get STARTED

APRA and ASIC have called on regulated entities to move from awareness to action. As frontier AI increases the speed, scale and sophistication of cyber threats, strong identity and access controls are now fundamental to cyber resilience. While the guidance was directed at regulated entities, the message is relevant to all Australian businesses.

For many years, organisations have approached identity through the lens of Identity Management. The primary objectives were provisioning users, managing directories, enabling single sign-on and ensuring employees had access to the systems they needed. Success was measured by operational efficiency, user experience and administrative automation.

While these capabilities remain important, they are no longer sufficient.

Today’s attackers do not need to breach a firewall when they can log in with stolen credentials. They do not need to exploit software vulnerabilities when they can abuse excessive privileges, compromised service accounts, weak authentication controls or unmanaged third-party access. As AI-powered attacks evolve, identity has become both a primary target and a critical control point for defending the organisation.

This shift demands a move from Identity Management to Identity Security.

Identity Security extends beyond managing who has access. It continuously assesses whether access should exist, whether it is being used appropriately, whether it introduces unacceptable business risk, and gives you the observability and control to respond to improper access. The goal is no longer simply to manage identities. It is to protect the organisation through identities.

What the evolution requires:

  • Reduce privileged access risk
  • Secure human, machine and AI identities
  • Continuously govern access and entitlements
  • Detect anomalous identity behaviour
  • Protect third-party access pathways
  • Enforce adaptive, risk-based access controls

These priorities directly support the regulators’ call-outs: strong identity and access controls, protection of critical assets, better third-party risk management and readiness for compressed incident response timeframes.

Most importantly, Identity Security elevates Identity to a key pillar of business resilience, and gives the business the assurance to execute on growth initiatives with confidence. Boards and executives need to understand risk exposure before a crisis, including risk appetite, escalation authority, and recovery priorities. Identity provides a practical lens because every user, application, service account, privilege assignment and third-party connection represents a potential pathway to critical assets.

The question must change from “Can we manage identities efficiently?” to “Can we trust every  action of every identity that has access to our business?”.

Frontier AI is accelerating the need for change. Attackers are becoming faster, more automated and more adaptive. Defensive strategies must evolve at the same pace. Strong Identity Security reduces attack surface, strengthens resilience, improves governance and enables organisations to respond with confidence when incidents occur.

The future is not just Identity Management. The future is Identity Security.