Security posture built on assumptions is not posture. It is a guess.

Something I keep seeing across Active Directory | Entra ID | M365 environments regardless of industry and enterprise size is that the organizations most confident in their posture are often the ones with the most to find.

This issue is about three specific ways that confidence becomes the gap. None of them are exotic. All of them are exploitable.

01 THE ASSUMPTION IS THE ATTACK SURFACE

Your compliance score measures what you configured. Not what exists now.

A Secure Score of 78% means your tenant was set up well at some point. It does not account for the contractor who came in four months ago, got Global Administrator rights “temporarily” and still has them. It does not account for the service account that was provisioned during a migration and has been sitting there logging in every Tuesday through automated process, not a human, until it isn’t.

Configuration and current state are different things. Most organizations monitor the first and call it the second.

WHY THIS MATTERS TO YOU

The next audit will check the same boxes. It will not catch the stale accounts your team has forgotten about because nobody is actively looking. Attackers are not waiting for audits.

02 POSTURE DRIFTS. NOBODY TELLS YOU.

Every hire, offboarding, and acquisition silently changes your identity environment.

Identity drift is not a failure of policy. It is what happens in every Active Directory | Entra ID | M365 when normal business operations run faster than the governance cycle. Someone leaves, their account gets disabled but the mailbox stays live for 90 days “in case.” The 90 days pass. Nobody checks. The mailbox is still there. Accessible. Microsoft’s own data puts 61% of organizations in this category find accounts still active more than 90 days after offboarding. (Microsoft Security Report 2024.)

Multiply that by every employee, every vendor, every integration and every acquisition over the last three years. That is your current directory. Not the clean one you reviewed in Q4. And once someone finds their way into one of those forgotten accounts, the average dwell time before detection is 88 days. (IBM X-Force 2024.) That is nearly three months of access nobody noticed.

WHY THIS MATTERS TO YOU

An attacker who finds a forgotten account does not need to phish anyone. They just need to use it. 88 days is a long time for something to go unnoticed when nobody is watching.

03 THE LEADERSHIP GAP IS A VISIBILITY GAP

Executives are not failing to lead cybersecurity because they don’t care. They’re doing it without a current picture of what they’re leading.

There is a lot of conversation right now about the leadership gap in cybersecurity and the idea that organizations rely too heavily on their CIO or IT director to own a risk that is genuinely a business risk. I think that framing is right although I keep landing on a more specific version of it.

The executives I work with are not disengaged. They ask the right questions. The problem is that the answers they get back are based on the same stale snapshots i.e the last audit, the last pen test or the last quarterly review. So even when leadership is present, the decisions they make are calibrated to a picture of the environment that no longer true.

You cannot own a risk that you cannot see. And in several organizations, leadership not getting a live view of identity specifically who has access, what has changed and what looks wrong right now. This is the gap and not the willingness to lead. It is the data to lead from.

The question I like to leave you with is when your leadership last asked about your identity posture and what were they actually looking at?

WHY THIS MATTERS TO YOU

Better governance programs start with better data. Before the strategy, before the frameworks, before the executive conversations someone needs to know what is actually in the environment. That is where identity visibility fits. It is not the whole answer. It is the prerequisite.