
The next Identity challenge is not simply managing access. It is proving that access remains secure, appropriate, and aligned to risk.

For more than a decade, Identity and Access Management (IAM) has been a major focus across Australia's financial services sector. Banks, insurers, superannuation funds, mutuals, and other APRA-regulated organisations have invested heavily in Identity platforms, multi-factor authentication, privileged access management, single sign-on, and governance capabilities. In many organisations, Identity programs have matured significantly and are now considered an established part of the technology landscape.
Yet despite these investments, cyber threats continue to evolve, regulatory expectations continue to rise, and organisations are rapidly adopting technologies that were barely considered when many IAM strategies were first developed. As a result, a growing number of organisations are discovering that while identities may be effectively managed, they are not necessarily being effectively secured.
This is becoming one of the defining cybersecurity challenges for APRA-regulated entities. The question is no longer whether users can be provisioned efficiently or whether access requests can be automated. The real challenge is understanding whether identities represent an unmanaged source of operational, regulatory, and security risk.
APRA's CPS 234 Information Security Prudential Standard requires organisations to maintain security capabilities commensurate with the threats they face, implement effective controls, and systematically assure the effectiveness of those controls. Governance, accountability, testing, and ongoing assurance sit at the heart of the standard.
At the same time, regulators are increasingly focused on operational resilience, third-party governance, cyber preparedness, and the safe adoption of emerging technologies such as artificial intelligence. The conversation has shifted beyond whether a control exists and towards whether organisations can demonstrate that the control is operating effectively over time. Recent regulatory guidance and industry discussion consistently reinforce the need for visibility, governance, accountability, and evidence-based risk management.
Identity sits at the centre of nearly every one of these priorities. Whether the discussion relates to privileged access, third-party risk, fraud prevention, operational resilience, data protection, or AI governance, Identity is often the mechanism through which risk is either controlled or exploited.
Historically, workforce IAM programs focused primarily on ensuring that employees received the right access at the right time, and that access was removed when no longer required. While those fundamentals remain important, today's Identity landscape is significantly more complex.
Financial institutions must now manage not only employees, but also contractors, outsourced service providers, administrators, brokers, advisers, cloud workloads, APIs, service accounts, machine identities, and increasingly AI agents. The growth of these non-human identities is reshaping security architectures across the industry.
Research from CyberArk found that machine identities now outnumber human identities by approximately 82 to 1, illustrating how dramatically the Identity landscape has expanded. More concerningly, 42% of machine identities possess privileged or sensitive access, creating a significant attack surface that many organisations struggle to govern consistently. Couple this with the Crowdstrike 2026 finding that 82% of detections involved credential abuse rather than malware, and suddenly the risk represented by the explosion of non-human identities takes on a completely different complexion.
This evolution means that Identity can no longer be viewed solely as an operational or productivity challenge. It has become one of the primary security control planes through which organisations protect systems, data, services, and business operations.
Many APRA-regulated organisations have already invested significantly in IAM. Multi-factor authentication is widely deployed. Provisioning processes are increasingly automated. Identity governance platforms are becoming more common. Privileged access management initiatives have been underway for years.
However, implementing Identity technology does not automatically deliver Identity Security. The distinction becomes apparent when organisations are asked to answer a handful of seemingly simple questions:
These are fundamentally different questions from those traditionally addressed by IAM projects. They focus on visibility, assurance, risk, and evidence rather than lifecycle management, user provisioning, and access management.
The threat landscape reinforces why this distinction matters. According to Verizon's 2025 Data Breach Investigations Report, stolen credentials were the initial access for 22% of breaches, making credential abuse the most common initial access vector observed during the year. In other words, the cyber security community has become increasingly effective at protecting infrastructure, while attackers continue to target identities.
Although all APRA-regulated entities face Identity risk, superannuation funds and insurers share a particularly challenging operating model. Both sectors manage large volumes of highly sensitive personal and financial information. Both depend heavily on complex networks of administrators, service providers, custodians, brokers, advisers, claims processors, medical providers, and outsourced partners. This creates an Identity ecosystem that extends well beyond traditional employee populations and introduces additional challenges around ownership, governance, access reviews, and accountability.
The growing importance of third-party risk is reflected in wider industry data. Verizon's 2025 DBIR found that 30% of breaches involved third parties, highlighting how external relationships are increasingly impacting organisational cyber risk. For superannuation funds and insurers, this reinforces an uncomfortable reality: protecting the organisation means being able to secure identities that are neither owned nor directly controlled by the organisation itself.
As these ecosystems continue to expand, Identity Security becomes closely linked to operational resilience, regulatory compliance, audit readiness, and customer trust.
Artificial intelligence is adding yet another layer of complexity. Much of the discussion around AI focuses on governance, ethics, privacy, and model risk, but a more practical challenge is emerging underneath those conversations. Every AI assistant, automation platform, and autonomous agent requires an identity.
As organisations deploy AI-enabled capabilities across customer service, operations, claims processing, underwriting, investment management, and internal productivity platforms, they must answer three important questions:
These questions are not fundamentally different from those asked about human users. The difference is that the number of non-human identities is growing rapidly, often without the same governance frameworks that organisations have developed for workforce identities. As AI adoption accelerates across the financial services sector, Identity Security will increasingly become the foundation upon which effective AI governance depends.
For many APRA-regulated organisations, the next phase of evolution is not another IAM implementation project. It is the transition from Identity Management to Identity Security. This means moving beyond provisioning and lifecycle processes to focus on visibility, risk identification, continuous assurance, and operational resilience. It means understanding not only who has access, but whether that access remains appropriate, justified, observable, and aligned to business risk.
Most importantly, it means recognising that Identity is no longer an administrative function. It is a security discipline in its own right. The organisations best positioned to navigate increasing regulatory expectations, growing third-party ecosystems, and the rise of AI will not necessarily be those with the most sophisticated IAM platforms. They will be the organisations that can demonstrate effective control over identities across their entire environment, and provide the operational evidence required to support that claim.