Logo
Cybersecurity

The Next Identity Skills Gap Is Hiding Behind the Login Screen

Signing in is the visible part. The harder security work begins with everything the application trusts afterwards.

ITSEC AsiaITSEC Asia
|
Sep 23, 2026
The Next Identity Skills Gap Is Hiding Behind the Login Screen

Most people understand authentication as a familiar sequence. Enter credentials, prove who you are and access the application.

Modern systems keep working long after that login screen disappears.

Applications use identity and access tokens to determine what users and workloads are allowed to do. Tokens support capabilities such as single sign-on, federation and API access. NIST describes them as a central part of access management infrastructure and zero trust architectures.

On 15 September, NIST finalized IR 8587 with CISA involvement, providing implementation guidance for protecting tokens and assertions from forgery, theft and misuse. The publication covers identity providers, authorization servers, cryptographic key protection, token verification and lifecycle controls.

For cybersecurity teams, there’s a workforce implication hiding inside that architecture.

Identity Security Has Become an Engineering Skill

IAM can sound administrative: create accounts, assign permissions, remove access when someone leaves.

Those responsibilities remain. Cloud applications, APIs and machine identities have added another technical layer.

Security professionals increasingly need to understand:

  • How tokens are issued, validated, renewed and revoked
  • How SSO and federation move trust between systems
  • Which cryptographic keys protect tokens and how those keys are managed
  • How API permissions are scoped
  • How workload identities differ from human identities
  • What telemetry can reveal token misuse
  • How identity controls behave when applications span multiple cloud services

NIST’s finalized guidance specifically adds workload identity considerations and recommends short-lived tokens rather than relying on static credentials and secrets.

That makes identity security relevant to cloud engineers, application security teams, security architects and SOC analysts alongside dedicated IAM specialists.

Stolen Credentials Aren’t the Whole Story

Training also needs to reflect how identity attacks can work after authentication.

An analyst investigating suspicious cloud activity may find that the account’s password was never used by the attacker. A stolen or forged token can potentially provide access without repeating the original authentication process.

That changes the investigation.

Teams need to examine token issuance, permissions, signing infrastructure, session activity and revocation. Application developers need to understand how their systems validate tokens. Architects need to design trust relationships carefully. SOC teams need telemetry that helps them identify unusual use.

Even logout deserves more thought than its humble button suggests. NIST’s Digital Identity Guidelines note that access and refresh tokens can remain valid beyond the original authentication session.

Put Identity Into the Lab

Identity security is well suited to practical training because the relationships become clearer when people can see them working.

Give learners several applications, an identity provider and an API. Let them trace authentication, inspect permissions and observe how tokens move between components. Then introduce a misconfiguration or compromised token and ask them to investigate what access becomes possible.

The exercise connects cloud security, application security and incident response around one identity chain.

That approach fits ITSEC Cyber & AI Academy, where hands-on environments can help learners understand how security controls behave across realistic systems rather than treating IAM as a diagram to memorise.

Passwords still matter.

The identity system around them has become a considerably bigger subject.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: NIST: Protecting Online Identity and Access Tokens From Misuse, 15 September 2026 · NIST IR 8587: Protecting Tokens and Assertions · NIST Digital Identity Guidelines · ENISA NIS Investments 2025

Share this post

You may also like

How IoT Devices Are Expanding the Cybersecurity Attack Surface
Cybersecurity

How IoT Devices Are Expanding the Cybersecurity Attack Surface

INTRODUCTION When people hear “IoT security, [https://itsec.asia/services/ot-ics-cybersecurity]” they often assume it’s something only IT teams need to worry about. In reality, IoT security affects everyday users, households, and businesses alike.* From smart home devices to office surveillance systems, connected devices are now part of critical daily operations. The more devices we connect, the wider the potential attack surface becomes. Here’s the part no one really talks about: Many IoT environments are deployed quickly for convenience, not necessarily designed with security as the top priority. It’s not negligence. It’s just how fast technology moves. Source: aciano.net [https://aciano.net/blog/iot-security-risks/], cio.com [https://www.cio.com/article/3990581/iot-security-challenges-and-best-practices-for-a-hyperconnected-world.html?] THE IOT LANDSCAPE NOWADAYS Security used to focus on protecting networks with firewalls and perimeter defenses. Today, attackers are shifting their focus to easier targets: user credentials, weak device authentication, misconfigured cloud dashboards, and unpatched firmware.  Today, attackers are more interested in: * User credentials * Weak device authentication * Misconfigured cloud dashboards * Unpatched firmware IoT devices often rely on cloud platforms for monitoring, analytics, and control. That means IoT security is no longer just about the

ITSEC AsiaITSEC Asia
|
Mar 06, 2026 — 5 minutes read
Calculating the Cost of Securing Your Business
Cybersecurity

Calculating the Cost of Securing Your Business

Tips

As the strategic importance of information security continues to grow for organizations of all sizes, and the complexity of information security increases across industries, business decisions are increasingly driven by the need to protect their intellectual assets and safeguard their IT infrastructure from evolving cybersecurity threats. Securing customer records, protecting sensitive financial information, and complying with regulatory requirements can create significant pressures on IT decision-makers and their resources. While many organizations have traditionally outsourced critical elements of their IT operations to managed service providers, more and more businesses are proactively outsourcing their security functions to specialized information security service providers. This has led to a need for evaluating the benefits of outsourcing security elements and comparing them to managing these processes internally. I wrote this article to help business leaders understand the best way to approach Managed Security Service Providers (MSSPs) in the context of Total Cost Ownership (TCO), a subject that is frequently discussed and of interest to both technical and non-technical leaders. INTERNAL SOLUTIONS OR OUTSOURCING? The key to evaluating

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 — 8 minutes read
The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore
Cybersecurity

The Cybersecurity Skills Gap Indonesia Can’t Afford to Ignore

As businesses, government institutions and other organizations accelerate digital adoption, the need for cybersecurity professionals continues to grow. At the same time, the skills required to protect increasingly complex environments are changing. Cloud security, threat intelligence, security operations, penetration testing and artificial intelligence are becoming part of the modern cybersecurity skill set. The gap between available talent and the capabilities organizations actually need is becoming harder to ignore. CYBERSECURITY NEEDS ARE CHANGING FASTER THAN SKILLS The global cybersecurity workforce is facing a skills shortage alongside its broader talent challenge. The 2025 ISC2 Cybersecurity Workforce Study found that 95% of cybersecurity professionals surveyed reported at least one skills need within their teams, while 59% described those needs as critical or significant. The study also found that 88% had experienced at least one significant cybersecurity consequence because of skills shortages. For Indonesia, the implication is clear: building a cybersecurity team isn't simply about filling vacancies. Organizations need professionals who can apply their knowledge to real security problems. The skills required are also changing rapidly. The World

ITSEC AsiaITSEC Asia
|
Agu 24, 2026 — 5 minutes read

Receive weekly
updates on new posts

Subscribe