Identity Attacks in the AI Age: What UK CISOs Must Do Now
AI-powered identity attacks have overtaken perimeter breaches as the primary threat vector facing UK organisations in 2026, with adversaries using machine learning to exploit legitimate credentials at a scale and speed that traditional access controls were not designed to detect.
The threat landscape shift is now documented at scale. According to PwC’s Annual Threat Dynamics 2026 report, identity-centric attacks — where adversaries compromise or abuse legitimate user credentials rather than exploiting vulnerabilities in systems — have surged as AI lowers the barriers to credential theft, social engineering, and privilege escalation. Ransomware gangs have adapted accordingly: the majority of major ransomware campaigns in 2026 now begin with compromised identities, not technical exploits. Ransomware attacks on critical industries grew 34% year-on-year in 2025, according to Security Week’s Cyber Insights 2026 report, and AI is accelerating the discover-exploit-weaponise cycle to a pace that human security operations cannot match without tooling upgrades. For UK CISOs, the implication is precise: an identity-first security architecture is no longer a strategic aspiration. It is the baseline defence against the dominant attack pattern of 2026.
How Is AI Changing the Identity Attack Threat Model?
Three AI-enabled attack patterns are now the operational norm for sophisticated threat actors. First, AI-accelerated credential harvesting: machine learning models analyse leaked credential databases, dark web data, and corporate directory information to construct highly targeted phishing campaigns at industrial scale, with personalisation and timing that defeats legacy email filtering. Second, deepfake-assisted social engineering: generative AI voice and video synthesis is being used to impersonate executives and finance staff in authorisation fraud — UK Finance reported multiple confirmed deepfake-assisted payment fraud cases in 2025, a trend that has continued into 2026. Third, AI-driven privilege escalation: once initial access is achieved through a low-privilege credential, AI tools automate the lateral movement and privilege escalation process, reducing the dwell time between initial compromise and high-value data access from weeks to hours.
The NCSC’s 2026 guidance has been explicit on this point: the majority of significant cyber incidents reported to the agency now involve identity as the primary attack vector, not technical vulnerability exploitation. CISOs who continue to prioritise perimeter-first investment over identity-first architecture are misallocating their security budgets against the threat profile their organisations actually face. Under the UK Cyber Security and Resilience Bill, currently progressing through Parliament, organisations designated as critical national infrastructure will face new obligations to demonstrate that their identity and access management controls meet defined standards. The trajectory for all large UK employers is tighter identity control requirements, not looser ones.
- Executive Action: Commission an identity attack surface assessment covering privileged access accounts, service accounts, third-party access credentials, and remote access pathways — this is the ground-level inventory that a zero trust architecture requires.
- Test your organisation’s resilience to deepfake-assisted social engineering by running a controlled voice or video impersonation exercise targeting finance and executive assistants — document the outcome and brief the board.
- Review your current dwell time metrics for detected identity-based incidents — if you cannot answer this question, your detection capability is insufficient for the 2026 threat environment.
What Does Zero Trust Architecture Mean in Practice for UK CISOs?
Zero trust is the architectural response to identity-first attacks, and its core principle is operationally straightforward: no user, device, or system is trusted by default, regardless of network location. Every access request must be continuously authenticated and authorised against defined policy, with least-privilege access enforced at the session level rather than assumed from network position.
In practice, zero trust implementation for UK enterprise organisations in 2026 requires four foundational components. First, identity-first authentication: multi-factor authentication must be enforced universally — not just for remote access — with phishing-resistant MFA (FIDO2/passkeys) replacing SMS and app-based OTP for privileged and high-value access. Second, continuous authentication: session-level behavioural analytics must be in place to detect anomalous activity within authenticated sessions, not just at login. Third, micro-segmentation: network segmentation must be implemented at a sufficiently granular level to limit lateral movement once initial access is achieved — flat network architectures are incompatible with zero trust principles. Fourth, device posture validation: every device requesting access must be validated against a current compliance baseline before access is granted, with automated quarantine of non-compliant devices. Access the INFORMD cyber risk assessment to evaluate your organisation’s current zero trust maturity against NCSC and NIST guidance.
- Executive Action: Audit MFA coverage across all user populations — identify any access pathways that do not yet enforce phishing-resistant MFA and prioritise these for uplift before year end.
- Review your network segmentation architecture against the NCSC’s zero trust guidance — confirm that lateral movement from a compromised identity is constrained by micro-segmentation.
- Implement continuous authentication session monitoring for privileged access accounts — if anomalous session behaviour is not generating alerts in real time, your controls are insufficient for the current threat environment.
How Should CISOs Brief the Board on Identity Risk?
UK boards are increasingly being held accountable for cyber resilience outcomes under the UK Corporate Governance Code 2024 and the proposed UK Cyber Security and Resilience Bill. Under the DORA framework — applicable to UK financial services firms with EU operations — identity and access management controls are a named component of ICT risk management requirements. Under ISO 27001:2022, Annex A.5.15 (access control) and A.5.18 (access rights) have been strengthened to require ongoing review of access rights, not just initial provisioning. The CISO who presents identity risk to the board in terms of technical controls rather than business impact — regulatory exposure, operational disruption, reputational consequence — is not giving the board what it needs to discharge its governance obligations.
A board-level identity risk briefing should cover: the current threat landscape (AI-enabled credential attacks, deepfake fraud, privilege escalation at speed); the organisation’s current control posture (MFA coverage, zero trust implementation status, dwell time metrics); the regulatory context (DORA, UK Cyber Security and Resilience Bill, ISO 27001); and the investment case for uplift (cost of identity control investment versus cost of a confirmed breach at the organisation’s current revenue and reputational exposure). Use the INFORMD cybersecurity and resilience briefing library for intelligence on DORA, the UK Cyber Security and Resilience Bill, and operational resilience frameworks. The INFORMD project review checklist can help CISOs structure identity security programme delivery for board accountability.
- Executive Action: Prepare a board-level identity risk briefing using the four-element structure above — threat landscape, control posture, regulatory context, investment case — and schedule it for the next risk committee meeting.
- Confirm that your incident response plan has been updated to reflect identity-first attack scenarios, including deepfake-assisted social engineering and AI-accelerated privilege escalation.
- Engage your cyber insurance provider to confirm that your current policy coverage includes AI-enabled identity attacks — many legacy policies were written before this threat vector became dominant and may exclude specific scenarios.
What Role Does AI Play in Defending Against AI-Enabled Attacks?
The asymmetry of AI-enabled attacks — where automated tooling allows adversaries to operate at machine speed while defenders rely on human analysts — is only partially addressable through traditional security operations. The security industry response is AI-assisted defence: using machine learning to detect anomalies in identity behaviour, automate response to confirmed credential compromise, and correlate signals across identity, endpoint, network, and application telemetry at the speed that the threat requires.
For UK CISOs, 73% of whom see AI as more of an opportunity than a risk for cybersecurity according to Security Brief UK, the practical imperative is to invest in AI-enhanced Security Operations Centre (SOC) capabilities — specifically identity threat detection and response (ITDR) tooling that can identify and contain compromised credentials within minutes rather than hours. Organisations that have not yet evaluated ITDR tooling are operating with a detection gap that the current threat environment actively exploits. Under the operational resilience requirements that apply to UK financial services, this is not a future investment — it is a current compliance requirement.
- Executive Action: Evaluate identity threat detection and response (ITDR) tooling against your current SOC capability — produce a gap assessment and investment case for the risk committee within the next 90 days.
- Run a tabletop exercise simulating an AI-accelerated identity attack — from credential compromise to ransomware deployment — and document response time, escalation paths, and communication protocols.
- Review your AI security investment roadmap and confirm that defensive AI (ITDR, behavioural analytics, automated response) has the same budget priority as offensive AI threat monitoring.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
AI has dramatically lowered the cost and complexity of credential theft, social engineering, and privilege escalation. According to PwC’s Annual Threat Dynamics 2026, identity-centric attacks now dominate the threat landscape because adversaries exploit legitimate access rather than breaching perimeters — making traditional network security controls insufficient as a primary defence.
Zero trust for identity requires: phishing-resistant MFA enforced universally (not just for remote access), continuous session-level behavioural authentication, micro-segmentation to limit lateral movement after initial compromise, and device posture validation before access is granted. All four must be in place for zero trust to function as an identity defence.
ITDR is a category of security tooling that uses AI to detect compromised or abused identity credentials within active sessions — identifying and containing threats in minutes rather than hours. Given that AI-enabled attacks now operate at machine speed, ITDR is essential for UK organisations that cannot absorb the dwell time a human SOC allows.
Yes. Under DORA — applicable to UK financial services firms with EU operations — identity and access management is a named component of ICT risk management requirements. CISOs at in-scope firms must demonstrate that access controls, privileged access management, and identity monitoring meet DORA’s ICT risk framework standards.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
