“A threat actor has to be lucky only once. But a security professional defending a financial organization has to be lucky every single time.” Samitha Amarasiri, Simeio Managing Director.
That asymmetry captures the security stakes in an industry where the 2026 RSA ID IQ Report found that 72% of organizations suffered identity-related breaches over the past three years, the second-highest rate anywhere.
The weakness attackers keep exploiting is the mismatch between legacy identity controls and today’s environment, now crowded with non-human identities (NHIs), third-party vendors, and AI agents.
To dig into how organizations can close the identity depth, Simeio and SailPoint co-hosted the webinar “Closing the Identity Risk Gap in Financial Services.” Lori Diesen, Identity Strategist at SailPoint, moderated the 29-minute session that also included Angel Cruz, Head of IAM at MarketAxess, and Samitha Amarasiri. Cruz brought the practitioner view, while Amarasiri mapped the forces reshaping identity risk in financial services, from AI-driven access to inherited third-party trust, and what leaders should do about it.
The gap is between what you think you control and what you can actually see
Diesen opened the conversation with the line that defined the whole session: a gap between the controls organizations believe they have and the identities they can genuinely account for. As third-party vendors and NHIs become essential to doing business, the gap expands.
Amarasiri pointed to AI, both agentic and generative, as the force that has reshaped identity risk most dramatically in the past 18 months. Unlike human users, AI agents are prebuilt with advanced technology to act independently, which makes their governance tricky to handle. “Governing human identity was hard enough for most of us. Now there’s the complexity of agents performing actions on behalf of others,” Amarasiri said about AI agents.
Sophos’ The State of Identity Security 2026 report backs Amarasiri’s point that poor management of AI identity is a weakness: in 2026, 40.6% of organizations reported breaches due to the weak management of NHIs.
Weak management of NHIs was the second-highest reason for breaches in 2026. Source: Sophos
From Amarasiri’s view, AI is hitting identity programs from four directions at once: employees are adopting AI tools internally faster than security teams can keep up, attackers are running parallel AI agents to do in minutes what used to take humans hours, vendor tools are arriving with built-in AI capabilities and no equivalent security controls, and customers are increasingly relying on AI agents to interact with their banks, reshaping consumer identity entirely. To win the identity insecurity, organizations must prepare to cover the loopholes in these angles every single time.
Reframing identity as business resilience
For Cruz, the framing matters as much as the technology. In conversations with peers, he positions identity as a business resilience issue. It sits at the center of how people and systems reach critical applications and data, and when those controls weaken, the consequences hit fast: financial loss and operational disruption, layered on top of a regulatory environment that keeps tightening.
DORA now covers ICT incident management and third-party risk, and broader regulatory pressure on AI governance is building in parallel. The 2026 RSA ID IQ Report reinforces what’s at stake: 45% of organizations said identity-related breaches cost them more than the average data breach, and 70% said the breach caused their organization “significant harm.”
The broader point is that modern identity risk is no longer defined by passwords and accounts. It’s defined by whether an organization can continuously govern every kind of access in the environment, including human accounts, machine accounts, third-party connections, and AI-driven agents, well enough to satisfy regulators and keep the business running.
The most underestimated threat: inherited trust
Cruz pointed to the false sense of trust that sets in once a partner or vendor is onboarded and connected to the environment, calling it the most underestimated identity threat in financial services. The real exposure is everything that gets inherited along with the relationship:
- Consultants and contractors who gain access through the partner
- Fourth parties: the vendors your partners themselves connect to
- The expanding access paths that come with each new integration
Amarasiri shared Cruz’s sentiment about the inherent risk that comes with third-party collaborations, putting it this way: “When you connect to one third party, you’re connecting to all the other third parties that third party connects with.”
That scope and complexity mean a one-time vendor questionnaire isn’t enough to eliminate third-party risk anymore. As external relationships evolve and access expands, governance has to keep pace continuously. Cruz put it directly: “The question is no longer ‘do we trust this partner?’ It is ‘can we continuously govern the identities and access they introduce into our ecosystem?'”
Continuous governance is hard to build inside one organization. A managed identity services provider like Simeio operates across multiple financial services clients globally, delivering what no single organization can replicate on its own:
- 24/7 visibility into the evolving threat environment
- Real-time tracking of what’s working and what’s failing across clients
- Performance insight into the third-party platforms inside each client’s stack
How Simeio managed services improve identity implementation. Source: Simeio
Amarasiri added another dimension: the depth of experience that comes from running identity programs across many financial services organizations at once, where patterns become visible, and approaches that work in one environment inform decisions in another.
What delivers an immediate and demonstrable risk reduction at the start of an identity security program?
Cruz’s unequivocal answer is that organizations need to establish visibility across their highest-risk identities, then build automated lifecycle controls around them. He called these the “golden nuggets,” whether they’re privileged accounts, service accounts, APIs, or AI agents. Getting governance right at that layer delivers the fastest reduction in overprivileged access and creates defensible evidence for regulators in the process. He
Diesen reinforced the point about showing value early, especially when the number and variety of identities under management keep climbing. As Cruz put it, “you can’t govern what you can’t see, and you can’t reduce risk no one owns.”
How to build a business case for identity security to the board
Cruz’s approach to making an identity security program appealing to the board is to frame it as an outcome-based approach, rather than a tool procurement strategy. Cruz explained it like this: “I try to get the conversation away from identity as a technical issue. [Instead] I frame it as a business resiliency issue.”
To pitch identity as a business resiliency issue, he focuses on the three outcomes that would instantly pull the buy-in of the board:
- Enterprise risk going down in measurable ways
- An environment that stays audit-ready as it scales
- Less manual friction across core processes
In his experience, that framing gets attention from leaders who would tune out a procurement pitch.
Amarasiri approached the same problem from a different angle. Major change in any financial services organization is driven by one of three things: revenue, cost, or risk. Identity programs that connect clearly to one or more of those drivers tend to move forward, and the ones that don’t usually stall.
His implementation sequence:
- Build the business case around value. Identity professionals often know intuitively that a program is the right thing to do, but struggle to translate that into language leadership recognizes. That translation is the first step.
- Get stakeholder alignment. Identity touches nearly every function in a bank, so a program can’t survive on executive sponsorship alone. Without alignment across the teams that depend on access, even well-funded programs stall.
- Sort the budget. Once leadership and stakeholders are bought in, funding becomes the gating step before procurement and deployment.
Diesen echoed Cruz’s sentiment, stating that financial organizations need to extend identity security to orphaned accounts. Amarasiri doubled down on NHI protection, arguing that financial organizations must have a dedicated identity security strategy to identify, protect, and govern their identities.
Watch the full webinar on demand here.