Logo
Cybersecurity

The Next Identity Skills Gap Is Hiding Behind the Login Screen

Signing in is the visible part. The harder security work begins with everything the application trusts afterwards.

ITSEC AsiaITSEC Asia
|
Sep 23, 2026
The Next Identity Skills Gap Is Hiding Behind the Login Screen

Most people understand authentication as a familiar sequence. Enter credentials, prove who you are and access the application.

Modern systems keep working long after that login screen disappears.

Applications use identity and access tokens to determine what users and workloads are allowed to do. Tokens support capabilities such as single sign-on, federation and API access. NIST describes them as a central part of access management infrastructure and zero trust architectures.

On 15 September, NIST finalized IR 8587 with CISA involvement, providing implementation guidance for protecting tokens and assertions from forgery, theft and misuse. The publication covers identity providers, authorization servers, cryptographic key protection, token verification and lifecycle controls.

For cybersecurity teams, there’s a workforce implication hiding inside that architecture.

Identity Security Has Become an Engineering Skill

IAM can sound administrative: create accounts, assign permissions, remove access when someone leaves.

Those responsibilities remain. Cloud applications, APIs and machine identities have added another technical layer.

Security professionals increasingly need to understand:

  • How tokens are issued, validated, renewed and revoked
  • How SSO and federation move trust between systems
  • Which cryptographic keys protect tokens and how those keys are managed
  • How API permissions are scoped
  • How workload identities differ from human identities
  • What telemetry can reveal token misuse
  • How identity controls behave when applications span multiple cloud services

NIST’s finalized guidance specifically adds workload identity considerations and recommends short-lived tokens rather than relying on static credentials and secrets.

That makes identity security relevant to cloud engineers, application security teams, security architects and SOC analysts alongside dedicated IAM specialists.

Stolen Credentials Aren’t the Whole Story

Training also needs to reflect how identity attacks can work after authentication.

An analyst investigating suspicious cloud activity may find that the account’s password was never used by the attacker. A stolen or forged token can potentially provide access without repeating the original authentication process.

That changes the investigation.

Teams need to examine token issuance, permissions, signing infrastructure, session activity and revocation. Application developers need to understand how their systems validate tokens. Architects need to design trust relationships carefully. SOC teams need telemetry that helps them identify unusual use.

Even logout deserves more thought than its humble button suggests. NIST’s Digital Identity Guidelines note that access and refresh tokens can remain valid beyond the original authentication session.

Put Identity Into the Lab

Identity security is well suited to practical training because the relationships become clearer when people can see them working.

Give learners several applications, an identity provider and an API. Let them trace authentication, inspect permissions and observe how tokens move between components. Then introduce a misconfiguration or compromised token and ask them to investigate what access becomes possible.

The exercise connects cloud security, application security and incident response around one identity chain.

That approach fits ITSEC Cyber & AI Academy, where hands-on environments can help learners understand how security controls behave across realistic systems rather than treating IAM as a diagram to memorise.

Passwords still matter.

The identity system around them has become a considerably bigger subject.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: Protecting Online Identity and Access Tokens From Misuse, 15 September 2026 · NIST IR 8587: Protecting Tokens and Assertions · NIST Digital Identity Guidelines · ENISA NIS Investments 2025

Share this post

You may also like

Calculating the Cost of Securing Your Business
Cybersecurity

Calculating the Cost of Securing Your Business

Tips

As the strategic importance of information security continues to grow for organizations of all sizes, and the complexity of information security increases across industries, business decisions are increasingly driven by the need to protect their intellectual assets and safeguard their IT infrastructure from evolving cybersecurity threats. Securing customer records, protecting sensitive financial information, and complying with regulatory requirements can create significant pressures on IT decision-makers and their resources. While many organizations have traditionally outsourced critical elements of their IT operations to managed service providers, more and more businesses are proactively outsourcing their security functions to specialized information security service providers. This has led to a need for evaluating the benefits of outsourcing security elements and comparing them to managing these processes internally. I wrote this article to help business leaders understand the best way to approach Managed Security Service Providers (MSSPs) in the context of Total Cost Ownership (TCO), a subject that is frequently discussed and of interest to both technical and non-technical leaders. INTERNAL SOLUTIONS OR OUTSOURCING? The key to evaluating

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 — 8 minutes read
Think Your System Is Secure? Penetration Testing Can Prove It
Cybersecurity

Think Your System Is Secure? Penetration Testing Can Prove It

INTRODUCTION Today, almost every organization relies on digital systems to run daily operations, from websites and cloud applications to payment systems and internal databases.  However, as digital infrastructure grows, so do cybersecurity risks. Attackers constantly look for vulnerabilities in applications, networks, and systems that they can exploit to gain unauthorized access or steal sensitive data (Cloudflare, 2024). Because of this growing threat landscape, organizations need ways to test their defenses before real attackers attempt to breach them. One of the most effective methods is penetration testing, often called pen testing, where cybersecurity professionals simulate attacks to identify security weaknesses before malicious actors do (IBM, 2024). In simple terms, penetration testing is authorized hacking designed to improve security rather than cause damage. Source: Cloudflare.com [https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/], ibm.com [https://www.ibm.com/think/topics/penetration-testing] WHAT IS PENETRATION TESTING? Penetration testing is a cybersecurity assessment where security experts simulate cyberattacks on systems to identify vulnerabilities that attackers could exploit. These experts that are often known as penetration testers or ethical hackers use techniques similar to real attackers, but with permission from the organization and with the goal

ITSEC AsiaITSEC Asia
|
Apr 02, 2026 — 6 minutes read
One Compromised System Rarely Stays One Compromised System
Cybersecurity

One Compromised System Rarely Stays One Compromised System

A business application stops working. The server itself is fine. The network looks normal. Authentication is available. Then someone discovers that an external service used by the application is unavailable. Suddenly the incident diagram gets bigger. ENISA’s Threat Landscape 2026, published on 22 September and discussed in a dedicated webinar on 29 September, puts this problem near the centre of its analysis. ENISA says the growing interconnectedness of digital ecosystems is increasing exposure to cyber risk and continues to observe attacks targeting dependencies, including supply chain and third party relationships. ENISA [https://www.enisa.europa.eu/publications/enisa-threat-landscape-2026?utm_source=chatgpt.com] For workforce development, there’s a practical lesson here: cybersecurity professionals need to understand dependencies as well as assets. AN ASSET LIST DOESN’T SHOW THE WHOLE RISK Knowing what systems an organization owns is useful. Knowing what those systems rely on is different. A customer portal might depend on an identity provider, DNS, cloud infrastructure, payment service, API, software library and managed service. Several other applications may rely on exactly the same components. Compromise one shared dependency and the blast radius changes quickly. Security

ITSEC AsiaITSEC Asia
|
Sep 30, 2026 — 3 minutes read

Receive weekly
updates on new posts

Subscribe