Why Sovereign Infrastructure Is Emerging as the Next Competitive Advantage
Identity, More Than Software Flaws, Is Driving Today's Costliest Cyberattacks - MIT Sloan Management Review Middle East Identity, More Than Software Flaws, Is Driving Today's Costliest Cyberattacks - MIT Sloan Management Review Middle East

Identity, More Than Software Flaws, Is Driving Today's Costliest Cyberattacks

Two new reports link identity-based attacks to the Middle East's rising breach costs, which reached $8 million in 2026.

Topics

  • [Image: Nomita Samaiyar/MITSMR Middle East]

    The economics of cyberattacks in the Middle East are shifting. Two newly released reports—from BeyondTrust’s Phantom Labs and IBM’s 2026 Cost of a Data Breach Report—point to the same conclusion from different directions. 

    One examines how attackers are gaining access, while the other measures the financial consequences once they succeed. Together, they suggest that identity management has become one of the defining challenges of enterprise cybersecurity.

    BeyondTrust’s inaugural Phantom Labs Research Index found that identity or privilege played a role in 75% of completed investigations. Rather than identifying isolated software vulnerabilities, researchers increasingly traced successful attack paths to interconnected identity relationships and excessive access privileges.

    Credential and secret exposure emerged as the most common root cause, accounting for 18% of all findings. Identity relationship and graph exposure, excessive standing privilege, identity misconfigurations, and lateral movement followed closely behind. Importantly, these issues rarely occurred independently. Standing privilege frequently appeared alongside privilege escalation, while exposed credentials often amplified the impact of other weaknesses. 

    The findings show that organizations deploy AI agents, automate workflows, and connect cloud applications across increasingly distributed infrastructures; identities have multiplied well beyond employees. Service accounts, APIs, machine identities, and autonomous AI systems now authenticate, access data, invoke enterprise tools, and perform tasks that previously required human intervention.

    BeyondTrust’s report argues that AI agents should increasingly be treated as enterprise identities rather than simply software applications. Like employees, these agents authenticate to systems, inherit permissions, access sensitive information, and execute workflows—often with considerably less governance than human users.

    The same identity-related assumptions appeared across a wide range of enterprise platforms. Coordinated vulnerability disclosures involving OpenAI Codex and AWS Bedrock AgentCore illustrated that emerging AI ecosystems continue to inherit longstanding trust and privilege models. Similar patterns also appeared across major cloud and enterprise platforms, including AWS, Microsoft Entra ID and Azure, GitHub, Okta, and Salesforce, suggesting that identity risk extends well beyond AI deployments.

    IBM’s 2026 Cost of a Data Breach Report provides the financial context for these technical findings. According to the study, the average cost of a data breach in the Middle East reached $8 million in 2026, making the region one of the world’s most expensive environments for cyber incidents.

    The report identifies three operational weaknesses that contributed most significantly to higher breach costs: poorly managed secrets and encryption keys, excessive privileges and weak role management, and an inability to prioritize security threats effectively. These findings closely mirror BeyondTrust’s conclusion that governance, rather than software alone, increasingly determines organizational risk.

    Conversely, organizations that combined AI with security automation reported substantially lower breach costs. IBM found that enterprises making extensive use of AI-powered security operations incurred breach costs more than $3 million lower, on average, than organizations without these capabilities. Despite the potential savings, nearly one-quarter of surveyed organizations had yet to adopt AI-driven security automation.

    The financial consequences extended well beyond technical remediation. Lost business represented the largest component of breach costs in the Middle East, averaging $3.57 million per incident, followed by post-breach response expenses, detection and escalation activities, and customer notification requirements. Financial institutions and technology companies experienced the highest average breach costs, exceeding $10.6 million per incident.

    IBM’s findings also suggest that organizations are beginning to adapt their security strategies to account for non-human identities. More than half of the surveyed organizations with security operations centers reported deploying AI agents, while many had implemented machine identity lifecycle management and zero-trust controls designed specifically for autonomous systems. Nevertheless, encryption gaps remain significant, with only about one-third of breached organizations reporting that sensitive data was encrypted both at rest and in transit.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.

    ×