Group Purchasing
Group Purchasing

SANS 2026 ITDR Report

Published by SANS Institute in March 2026, the report draws on insights from SOC analysts to CISOs.  For a decade, the industry assumed SSO and MFA would suffocate the breach epidemic. The 2026 SANS ITDR Report proves that assumption dangerous: 68% of organizations detect identity attacks within 24 hours, but only 55% contain them in that window. Organizations built the sensors to hear the alarm, not the muscle to put out the fire.

Top Takeaways

55%

Orgs detect attacks in 24 hours, but few contain that fast.

92%

Most orgs fail to rotate NHI credentials every 90 days.

35%

Credential phishing now causes only 35% of identity attacks.

73%

Orgs deploy agentic AI or automations needing credentials.

Survey Methodology and Respondent Profile

This analysis draws upon data collected from the 2026 SANS Identity Threat Detection and Response (ITDR) Survey.

Region

Respondents were concentrated in the United States, with additional participation from Europe, Canada, Africa, Asia, and Australia, and included practitioners and leaders from cybersecurity, technology, banking and finance, and government sectors.

Vendor Neutrality

Sponsor support made this research possible, but sponsors had no role in survey design, data collection, or analysis; all findings reflect independent SANS research.

More Key Findings from SANS 2026 ITDR Report 

  • 85% of organizations have deployed ITDR tools, yet 55% still experienced an identity-related breach in the past 12 months. 
  • 68% of organizations detect identity attacks within 24 hours, but only 55% contain them in that window, giving attackers time to escalate privileges. 
  • 75% of organizations report growth in non-human identities like service accounts and API keys, and only 8% rotate most of those credentials every 90 days.
  • Credential phishing accounts for only 35% of attacks; compromised browsers (27%), MFA fatigue (26%), and token hijacking (23%) now make up the majority. 
  • 73% of organizations use agentic AI or automations that require credentials, but no single governance control is used by more than 40% of respondents.

Related Webcast: How Identity Became the New Security Perimeter—And What's Next

Identity has become the new battleground. From SaaS to cloud to legacy Active Directory, it is now the central control point, and attackers know it. Watch the webcast for a closer look at the survey data and what security teams should do next.

Webcast Abstract Image

Meet the Author

Rich Greene
Rich Greene

Rich Greene

Senior Solutions Engineer at SANS Institute

Rich Greene, SANS Senior Solutions Engineer and SEC301 author, brings 20+ years of cyber operations and teaching experience to the classroom. With 15+ GIAC certifications and a passion for mentorship, he equips defenders with real-world confidence and skill.

Read more about Rich Greene

FAQs

55% of organizations experienced at least one identity-related compromise in the past 12 months, even though 85% report active use of ITDR tools, according to the 2026 SANS State of Identity Threats and Defenses survey. 

68% of organizations detect identity attacks within 24 hours, but only 55% contain them in that same window. That gap gives attackers time to escalate privileges before the SOC can intervene.

Only 8% of organizations rotate more than 75% of their non-human identity (NHI) credentials every 90 days, and 59% rotate fewer than half quarterly, leaving most service account keys and API tokens static for months or years.

Credential phishing accounts for 35% of identity attacks, followed by compromised browsers (27%), MFA fatigue (26%), and session token hijacking (23%), according to the survey.

73% of organizations use agentic AI or automations that require credentials, but no single governance control, such as approvals, audit trails, or sandboxing, is used by more than 40% of organizations.

Thank You To Our Sponsors

More Identity Security Research and Resources

Explore the SANS AI Report Archive

2026 marks the third edition of the SANS AI Report. Explore the past few years to track how AI adoption, governance maturity, and adversarial use have shifted year over year.