Non-Human Identities and AI Agents: The New Blind Spot in Your IAM Program

By Navneet Lounsberry The numbers tell a story most security leaders aren’t prepared to hear. In enterprise cloud environments, non-human identities now outnumber human users on average at a 50 to 1 ratio, and some organizations have significantly higher ratios. A recent study found that 85% of identity-related cloud breaches involve compromised non-human identities. I’ve […]
Official RPO Status: What It Means for Our CMMC Clients—and What Comes Next

For organizations across the Defense Industrial Base (DIB), cybersecurity is no longer optional. It’s a prerequisite for winning and retaining contracts. At Idenhaus, we have been helping clients meet that standard for years—well before CMMC formalized those expectations. Now, we are pleased to share an important milestone in that work: Idenhaus is a Registered Provider […]
Why Your MSP Choice Matters for CMMC: Trust, Scope, Proof

This post is for federal contractors pursuing CMMC certification and are concerned about choosing the right managed service provider. With regard to CMMC compliance this is not a purchasing decision, it is a governance decision with legal, operational, and assessment consequences. Under the CMMC framework, the organization seeking certification is responsible for protecting controlled unclassified […]
CMMC Asset Scoping: How to Categorize Your IT Environment for Level 2 Compliance

Every asset within your CMMC assessment boundary must fit into one of five categories defined in the Level 2 Scoping Guide.
Laying the Identity Foundation: Building Your Digital House

Building a strong house requires a solid foundation and a well-thought-out design. The same principle applies to your organization’s digital identity foundation. Just as a physical house protects its inhabitants and valuables while allowing authorized comfort and access for a growing family, a robust Identity Management (IdM) system safeguards your digital assets and seamlessly controls […]
Strategies for RBAC Alignment: Pre-Go-Live Baselining and Automation

By Richard Hawes In a previous blog, I discussed the challenges of implementing a Role-Based Access Control (RBAC) framework that will almost surely not be perfectly aligned with all users’ real access for practical reasons. Misaligned entitlements complicate RBAC and access certification, leading to inefficiencies and potential security gaps. This second part of the series explores […]
Key Takeaways from Identiverse 2025

Last week, Identiverse 2025 in Las Vegas brought together more than 3,000 identity professionals, 250+ expert speakers, and industry vendors to exchange knowledge and explore the forces shaping the future of digital identity. The Identiverse keynote speakers did an excellent job setting the stage, with Andre Durand, CEO of Ping Identity, raising the issue of […]
How to Define Your Path to Identity Management Success

An IAM Assessment helps guide your program to Identity Management success, the first time around. The most common benefit from Identity Management is moving from high-touch, human-driven processes to a policy-driven, automated approach for identity lifecycle management. Considering that more than fifty percent (50%) of IAM implementations fail the first time around, this isn’t a […]
7 Powerful Characteristics of a Strategic IAM Assessment

Identity and Access Management (IAM) systems have revolutionized how IT departments and businesses operate. Historically, companies were guilty of using multiple management tools that don’t interact with each other to manage user access from worker onboarding through separation. While this model can work for smaller organizations, it typically leads to bad data quality, processing errors, […]
Why an IAM Assessment Boosts Chances of Implementation Success

The world is in a new era defined by full-time, always-on connectivity. Today, customers expect to be able to transact business when they want, not necessarily when it’s convenient for a company. This new operating model has changed the way people work, and this uninterrupted, always-on environment presents new challenges for business to provide secure, […]