Why IAM Has Become the Security Bottleneck

Yossi Barishev
Co-Founder & CEO

I'll say the quiet part out loud: most enterprise identity programs are still on square one.

The teams are excellent. The tools are fine. The stack is deployed, licensed, and celebrated in the board deck. And still, it enforces almost nothing.

I came to identity through incident response, inside Fortune 500 environments on their worst days. Whatever the attack looked like, the bottleneck was always the same: figuring out which identities were compromised, who had access to what, who approved it, and how to cut the attacker's footprint out of the environment. The data was never where it should have been. My teams spent the worst hours of a breach scouring for context that should have taken seconds to pull.

Later I watched the same scavenger hunt happen in peacetime. When the data is missing during a breach and on a quiet Tuesday, the foundation is broken. The emergency just made it visible.

The Implementation limbo

Your IdP, your IGA, your PAM: every one of them is an empty box until it's enforced on an application and an identity. Until then, the stack does a net total of nothing. Zero governance. Zero compliance. Zero security.

Enforcement is exactly where programs stall:

  • Extending the stack to a single application is a weeks-to-months project, and there are hundreds in the queue: legacy apps that don't speak SAML or SCIM, homegrown tools, schemas no vendor ships a connector for.

  • Onboarding an app is only the entry ticket. The controls still have to hold: joiner-mover-leaver flows that match reality, access and MFA policies enforced without breaking production, reviews that reflect who actually has access.

  • New apps land faster than the stack extends to old ones. So teams write brittle scripts, hand-build connectors, and do manually what the platforms were bought to automate.

That's the implementation limbo: world-class tools on top, an estate they mostly don't touch underneath. You paid for the full stack. You're enforcing it on the easy third.

The illusion of coverage

Most identity leaders I meet can't answer one question with confidence: what share of your estate does your stack actually enforce, in production, today?

The dashboard says green because it only reports where the stack has reached. Everywhere else, your MFA, conditional access, lifecycle automation, and access reviews simply don't exist. Those apps don't show up as red. They don't show up at all. That's the illusion of coverage, and audits make it worse. By the time access data is pulled, reviewed, and acted on, the reality behind it has moved. You end up certifying a snapshot of the past. Compliance theater, performed quarterly.

M&A turns this from chronic to acute. A merger is two IT stacks, two identity systems, and two half-enforced estates colliding. The integration drags on for years, and that gap is exactly where attackers live.

AI didn't create this problem. It made it impossible to ignore.

Every vendor pitch right now says AI will fix identity. I don't buy it. AI's main limitation is whatever you feed it. Feed it fragmented, stale, half-enforced identity data and it will confidently produce the wrong answer, and then you'll act on it. Garbage in, garbage out, now at machine speed.

If I could spend just $1 on this problem, it goes to identity data: complete, current, and drawn from an estate your stack actually enforces. Every other dollar you've already spent depends on that one.

Identity doesn't have a tooling problem. It has an infrastructure problem. Forty years into IAM, there is still no standard way to enforce the stack you own on every application and identity you own. Tool number sixteen just adds another empty box to the pile.

Three questions to ask this week

  1. What share of our application estate does our stack enforce in production: SSO, MFA, provisioning, lifecycle, reviews, all of it?
  2. How many people-hours went into connectors, scripts, and manual enforcement work last quarter?
  3. Of the controls we report as "deployed," which ones actually hold on our fifty hardest apps?

If those answers make you uncomfortable, the fix is a layer above the stack, not another box in it: one standardized path to enforce the IAM you already own on every application and every identity, and to see exactly where your controls hold and where they stop.

That's what we built Way to do. Your Okta, Entra, SailPoint, and CyberArk stay right where they are. We make them do the job you bought them for, everywhere.

Explore All Resources

Explore
All Resources

Meet Way Security. We're Done Being Quiet.
The Last Mile of IAM: How to Fully Extend Your Identity Stack So it Reaches Everywhere
Why IAM Has Become the Security Bottleneck