Human Error Hampers Identity Lifecycle Management for Many Companies
The identity lifecycle management (JLM) process is a critical component of an organization's overall security posture. However, as revealed in Cisco Duo's CISO Perspectives 2026 report, many companies struggle with this process, particularly when it comes to managing access for users who change roles or leave the company.
A survey of 680 IT and security leaders found that 60% of CISOs lack confidence in their JLM process, specifically at the leaver stage. This is not due to a failure of identity management tools but rather human factors such as manager accountability and HR processes.
Chris Anderson from Cisco Duo notes that while automation has improved significantly, it's the humans around it who are often responsible for the gaps in the JLM process. For example, managers may be unfamiliar with the termination process or delay entering it into HR systems, causing leavers to fall through the cracks.
The report also highlights the issue of 'mover privilege creep,' where users accumulate access as they change roles without proper decoupling of their client access. This is particularly problematic in complex organizations with multiple sub-departments and internal boundaries.
The study emphasizes that contractors and third-party vendors are often the weakest link in the JLM process, with many companies lacking adequate controls for these groups. A hard-line approach to contractor account review, such as automatically terminating accounts if not reviewed within a set timeframe, can help mitigate this issue.