Skip to content
Insights
Request Services
State
Live benchmarks · updated monthly

The State of Identity — live, citable, updated monthly.

Workforce IAM coverage, privileged-access posture, audit-evidence cadence, breach economics, and AI-agent identity adoption — drawn from public studies (IBM, Verizon, FIDO Alliance, vendor research) and direct askmeidentity practice observations across 240+ engagements. Free to cite under CC BY 4.0.

Cite this pageDownload JSONTrack changes (RSS)

Version

2026.05.2

Last reviewed May 20, 2026 · 26 stats tracked

Workforce · Workforce IAM & Access

5 stats
Featured stat

87%

Workforce MFA coverage (large enterprises)

Share of organizations with 10,000+ employees that have rolled out workforce MFA. SMB adoption sits closer to 34%. Coverage gaps remain on legacy on-prem apps and admin accounts.

JumpCloud MFA Trends + Microsoft Digital Defense Report (2025)Reviewed May 20, 2026
Stat

14%

Phishing-resistant MFA share

Share of workforce passwordless authentication using phishing-resistant factors (FIDO2, passkeys). Up from 8.6% the prior year — a 63% YoY jump driven primarily by Okta FastPass and platform passkeys.

Okta Secure Sign-in Trends Report 2025 (2025)Reviewed May 20, 2026
StatObservation

67%

SSO catalog coverage

Average share of an enterprise SaaS catalog behind SSO. The long tail of un-federated apps remains the single largest off-boarding risk.

askmeidentity practice observations (2026)Reviewed May 20, 2026
StatObservation

41%

HRIS-triggered JML automation

Share of regulated enterprises with fully HRIS-triggered joiner/mover/leaver workflows on Tier-1 systems. Manual ticketing still drives the majority of access provisioning.

askmeidentity practice observations (2026)Reviewed May 20, 2026
StatObservation

38 min

Median time to deprovision

Median elapsed time from HR offboarding event to access revocation on a Tier-1 system. Best-in-class organizations hit < 5 minutes via Lifecycle Workflows.

askmeidentity practice observations (2026)Reviewed May 20, 2026

Privileged · Privileged Access & PAM

5 stats
Featured stat

91%

Privileged access that is always-on

Share of organizations where at least half of privileged access is "always-on" — providing unrestricted, persistent access to sensitive systems. Just-in-time elevation remains the exception, not the default.

CyberArk 2025 Identity Security Landscape (2025)Reviewed May 20, 2026
StatObservation

58%

PAM vault coverage

Average share of privileged credentials brought under vault management at enterprises with a deployed PAM platform. The remaining 42% sit in spreadsheets, password managers, or untracked admin tooling.

askmeidentity practice observations (2026)Reviewed May 20, 2026
Stat

1%

Full JIT elevation adoption

Share of organizations that have fully implemented just-in-time privileged access. CyberArk attributes the gap to legacy systems built for time-bound access, tool sprawl (88% of orgs manage 2+ identity tools), and weekly discovery of unmanaged privileged accounts.

CyberArk 2025 Identity Security Landscape (2025)Reviewed May 20, 2026
Stat

80:1

Machine-to-human identity ratio

Median ratio of machine (non-human) identities to human identities in mid-large enterprises. 68% of orgs lack identity security controls for AI agents specifically.

CyberArk 2025 Identity Security Landscape (2025)Reviewed May 20, 2026
StatObservation

34%

Privileged session recording

Share of privileged sessions on PHI- or PCI-adjacent systems that are recorded by default. Required by HIPAA Security Rule administrative safeguards but inconsistently enforced.

askmeidentity practice observations (2026)Reviewed May 20, 2026

CIAM · Customer Identity (CIAM)

4 stats
Featured stat

75%

Consumers with at least one passkey

Share of consumers who have enabled a passkey on at least one of their accounts. 49% use passkeys regularly when offered. 5 billion passkeys are now in use worldwide.

FIDO Alliance — State of Passkeys 2026 (2026)Reviewed May 20, 2026
Stat

87%

Enterprise passkey deployment

Share of organizations that have either deployed or are currently deploying passkeys for workforce sign-ins — 47% deployed, 40% in active rollout. Up from a small minority two years ago.

FIDO Alliance — State of Passkeys 2026 (2026)Reviewed May 20, 2026
StatObservation

63%

B2B SaaS using Organizations

Share of B2B SaaS products with an Auth0/Okta CIC tenant that have adopted the Organizations multi-tenancy pattern. The remaining sites carry custom tenancy that creates upgrade debt.

askmeidentity practice observations (2026)Reviewed May 20, 2026
Stat

29%

US adults hit by ATO (annual)

Share of US adults who experienced an account takeover in 2024 — roughly 77 million people. ATO fraud losses hit $2.9B, the fastest-growing identity-fraud category. Akamai recorded 193+ billion credential-stuffing attempts in one year.

Akamai State of the Internet — Security + AARP fraud data (2025)Reviewed May 20, 2026

Audit · Audit, Compliance & Evidence

3 stats
Featured statObservation

~78%

IAM first-pass audit rate (regulated)

Share of regulated US enterprises that pass their annual IAM-related audit on the first cycle without remediation. Findings concentrate on access-cert sampling, JML latency, and stale privileged accounts. Practitioner aggregate, not a single source.

askmeidentity practice observations across FFIEC / FedRAMP / HIPAA engagements (2026)Reviewed May 20, 2026
StatObservation

61%

Audit evidence still manual

Share of IAM audit evidence produced by manual screenshot collection at quarter-end. Evidence-as-code remains the exception in financial services and healthcare.

askmeidentity practice observations (2026)Reviewed May 20, 2026
StatObservation

32%

ConMon-aligned IAM programs

Share of regulated programs that produce IAM evidence continuously rather than at quarter-end. The shift is fastest in FedRAMP-authorized programs.

askmeidentity practice observations (2026)Reviewed May 20, 2026

Risk · Breach Economics & Risk

5 stats
Featured stat

$4.44M

Average breach cost (global)

Global average total cost of a data breach in 2025 — down 9% from $4.88M in 2024. IBM attributes the decline to faster containment powered by AI-driven detection. US ($10.22M) and healthcare ($7.42M) remain well above average.

IBM Cost of a Data Breach Report 2025 (2025)Reviewed May 20, 2026
Stat

16%

Phishing as #1 attack vector

Phishing overtook stolen credentials as the top initial attack vector in 2025 — 16% of breaches. Stolen credentials dropped to #2 but still drive the longest dwell time at 292 days.

IBM Cost of a Data Breach Report 2025 (2025)Reviewed May 20, 2026
Stat

60%

Breaches involving a human element

Share of breaches involving a human element — phishing, social engineering, lost credentials, or misuse. Down from 68% in the 2024 DBIR — but Verizon notes click rates were unaffected by security awareness training.

Verizon Data Breach Investigations Report 2025 (2025)Reviewed May 20, 2026
Stat

22%

Breaches starting with credential abuse

22% of breaches began with credential abuse and a further 16% began with phishing — together accounting for 38% of all breaches. 88% of Basic Web Application attacks involved stolen credentials.

Verizon Data Breach Investigations Report 2025 (2025)Reviewed May 20, 2026
Stat

292 days

Stolen-credentials MTTR

Mean time to identify and contain a breach involving stolen credentials. The slowest-to-contain attack type, attributed to attackers "logging in rather than hacking in."

IBM Cost of a Data Breach Report 2025 (2025)Reviewed May 20, 2026

Market · AI Agent Identity & Market

4 stats
Featured stat

68%

Orgs lacking AI agent identity controls

Share of organizations that lack identity security controls for AI agents specifically. Only 45% apply the same privileged access controls to AI agents as they do to human identities; 33% have no clear AI access policies at all.

CyberArk 2025 Identity Security Landscape (2025)Reviewed May 20, 2026
StatObservation

3.4x

Untracked service accounts

Median ratio of discovered service accounts to documented service accounts on first PAM discovery scan. The undocumented majority is the single biggest privileged-identity gap.

askmeidentity practice observations (2026)Reviewed May 20, 2026
Stat

$25.3B

Global IAM market (2026)

Global identity & access management software market size in 2026 — projected to reach $77.9B by 2034 at a 15.1% CAGR. Multiple firms converge on a $24-28B range for 2026; we use the Fortune Business Insights midpoint.

Fortune Business Insights — IAM Market Report (2026)Reviewed May 20, 2026
Stat

>99%

Identity attacks blocked by phishing-resistant MFA

Microsoft data on the effectiveness of phishing-resistant MFA at blocking unauthorized access attempts. Identity-based attacks rose 32% in H1 2025; 97% are simple password-spray attempts that MFA would have stopped outright.

Microsoft Digital Defense Report 2025 (2025)Reviewed May 20, 2026

Cite this page

Reference our benchmarks in your reporting.

These benchmarks are licensed under CC BY 4.0 — free to cite, quote, and link to with attribution. Pick a format below.

APA

askmeidentity. (2026). The State of Identity, live (v2026.05.2). Retrieved 2026-06-04 from https://askmeidentity.com/resources/state-of-identity/

MLA

"The State of Identity, live." askmeidentity, v2026.05.2, https://askmeidentity.com/resources/state-of-identity/. Accessed 2026-06-04.

BibTeX

@misc{askmeidentity_state_of_identity_2026_05.2, title = {The State of Identity, live}, author = {{askmeidentity}}, year = {2026}, note = {Version 2026.05.2, retrieved 2026-06-04}, url = {https://askmeidentity.com/resources/state-of-identity/} }

Share
CC BY 4.0 license
Methodology

How we keep this page honest.

  • Two source classes only

    Either a published study from a named source (IBM, Verizon DBIR, FIDO Alliance, vendor research) — or a direct practitioner observation from our delivery work, clearly labeled and accompanied by a methodology note. Nothing else makes it onto the page.

  • Monthly review cycle

    On the first business day of each month, every stat is re-verified against its source and the lastReviewed date is bumped. Stats that no longer hold are either updated, replaced, or retired with a redirect note in the change log.

  • Stable URL, evolving data

    The page URL never changes. Year-specific reports live at separate URLs (see the State of Identity 2026 annual report). This page is the perpetual reference, designed to be cited and re-cited.

Want a deeper read?

Numbers tell the trend. Engagements tell the story.

We can map any of these benchmarks to where your program actually sits — and what it would take to move. Same-day reply during business hours.

Request servicesTake the maturity assessment

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility