Eyebrow Text
REPORT
Title
The 2026 State of Trust Index
Subtitle
As AI agents scale and threats evolve, trust must be continuously verified. Discover where identity programs break down — and what it takes to close the gap.
title
Table of Contents
theme
default

Most organizations still trust more than they verify. Risk is building in that gap, and it's getting wider.

This Index maps where trust breaks down across the identity journey, and where it matters most to act.

Authors and Contributors

Andre Durand | CEO & Founder, Ping Identity

Lynette Hushen | Sr. Market Research Manager

Dustin Maxey | VP, AI Transformation & GTM Strategy, Marketing

Identity Is Now the Primary Target for Risk and Attack

stat
$9.5 Trillion
body
Cybercrimes including identity fraud are estimated to have cost the world about $9.5 trillion in 2024, according to Gartner®. That magnitude underscores a shift in how attacks happen and where they succeed.

Attackers are no longer limited to breaking through the network perimeter. They are increasingly attacking identity, targeting the moments that determine who gets access and when. Password resets, account recovery, and helpdesk approvals have become common entry points. In many cases, they are not forcing their way in. They are being let in.

At the same time, the nature of attacks has changed. What was once largely human driven is now a constant stream of automated activity. AI assisted attacks, synthetic identities, and automated account takeover attempts are probing identity systems at scale.

These attacks succeed by exploiting trust gaps where identity is assumed rather than verified.

This research builds on that reality, examining how identity-based threats are expanding. Based on responses from nearly 500 identity decision makers, the 2026 State of Trust Index shows where identity programs are strong, where gaps expose risk, and how leaders are starting to close them. In doing so, organizations are already seeing measurable outcomes like lower fraud, faster onboarding, and higher conversion.

Modern attacks increasingly target the identity layer — the accounts, credentials, and decisions that govern every digital interaction. Threats and attackers include:

These threats operate across the digital environment — spanning the Identity Layer (accounts, credentials, policies, permissions), data, cloud SaaS, and apps.

Identity Is Shifting Away from Verify Once, Trust Always

Trust cannot stop at login. It has to follow every identity, human or agent, across the entire journey.

Most organizations have the components, but they don't operate as a system. Identity capabilities often function in silos, leading to disconnected decisions and gaps in how trust is established and maintained over time.

These gaps tend to show up in the moments that matter most:

The State of Trust Index evaluates six categories: identification, identity management, access, governance, risk signals, and integration. Together, these determine whether trust is consistently verified across every interaction.

When these categories work together, every critical interaction connects back to a verified identity. Trust becomes something that is continuously proven.

The real question is how consistently these capabilities are applied, and how wide the gap is between what is possible and what is actually happening today.

Where is the biggest gap between where your identity program is today and where it needs to be?

Most Organizations Have Started the Journey, but Few Have Completed the Transformation

The State of Trust Index reveals how organizations assess their current identity maturity based on how well their systems work together. Most have made progress and moved beyond siloed tools, but the majority are still operating in the middle stages of maturity. Only a smaller group have reached what can be considered a truly transformative state — a unified, adaptive identity layer that enables real-time, risk-aware decisioning at scale.

Identity Operating Level

Organizations have made real investments in identity and connected many of their key systems. What is still missing for most is identity that operates as a single adaptive layer. One that can make real-time decisions, respond to changing risk, and orchestrate a consistent experience. Many programs now have more tools and more data, but decisions remain slow, manual, and ticket-based.

The Wider the Trust Gap, the More You Are Guessing Who to Trust

centered
true
heading
What Is the Trust Gap?
body
The Trust Gap is the difference between what is implemented and what is possible. The wider the gap, the more trust is assumed instead of verified, increasing exposure to risk. The State of Trust Index quantifies this gap based on what organizations have implemented across key identity categories, compared to what is possible with modern identity capabilities. It shows how much of the attack surface is protected today, where trust breaks down, and where to take action to reduce risk.

Where Exposure to Risk Is Highest Across the Identity Journey

Exposure to risk is not uniform. Where the trust gap is greater, reliance on implicit trust increases, extending risk across the full identity journey.

Identity Journey Category
Risk Exposure Level
Identification
HIGH
Identity Management
MEDIUM
Access
LOW
Governance
MEDIUM
Risk Signals
MEDIUM
Integration
HIGH

Higher exposure reflects larger trust gaps, where continuous verification is not consistently applied and trust is still assumed.

Exposure to Risk Follows a Clear Pattern as Identity Programs Mature, but These Categories Do Not Operate in Isolation. Gaps in One Area Create Downstream Risk in Others.

Progress is strongest in categories like Access, where authentication, authorization, and privilege controls are more established. But without consistent Identity Management, those decisions lack context: who the user is, how access should evolve, and what relationships matter.

As a result, Governance struggles to keep pace. Access reviews and policy enforcement become inconsistent when identity data is incomplete or disconnected.

Risk Signals follow a similar path. The data exists, but without integration into decisions, it rarely influences outcomes in real time.

These challenges compound in Identification and Integration, where exposure remains highest and identity programs are hardest to unify at scale. Without confidently tying identities to real, verified users, downstream decisions — from Access to Governance and Risk — begin to operate on incomplete or weak assumptions.

Identification requires moving beyond one-time verification to continuous assurance across every interaction.

Integration is what makes this assurance actionable, connecting identity tools across fragmented systems and enabling decisions to be applied consistently across channels, environments, and identity types.

These differences show why trust is difficult to apply consistently across the identity journey, and where investment decisions matter most.

The next sections examine each interrelated category, what drives the gaps between them, and how to close those gaps to create a more cohesive path to Verified Trust.

Is This a Real Identity, Verified by a Trusted Source?

Deepfakes and synthetic identities expose a core challenge: verification is often too weak to stop risk or too repetitive to avoid friction, making Identification the largest Trust Gap in the identity journey.

Most organizations still treat identification as a one-time hurdle at onboarding or recovery, rather than a continuous signal that informs decisions across the identity journey. After initial verification, identity is either assumed to remain valid or rechecked repeatedly, creating a mix of weak assurance and unnecessary friction.

Closing the Trust Gap requires shifting to ongoing identification: establishing verification as a trusted foundation, then using credentials and biometric authentication to tie back to that proof across the journey.

item-1-icon
item-1-icon-alt
item-1-title
Verification: From One-Time Checks to a Trusted Foundation
item-1-description
Verification is often front-loaded at sign-up, then weakens to passwords, basic MFA, or manual checks. High-risk moments like account recovery, password resets, privilege changes, and transactions remain exposed. Closing the gap requires phishing-resistant, device-bound credentials that maintain assurance over time without constant re-verification.
item-2-icon
item-2-icon-alt
item-2-title
Credentials: From Shared Secrets to Reusable Proof
item-2-description
Most credentials are easy to steal, reuse, or replay, weakening earlier proofing. Many programs rely on shared secrets that can be phished or bought at scale. Closing the gap requires continuous, risk-based verification anchored in high-assurance identity proof. After a trusted verification step, credentials should let users prove only what's needed and reuse that proof across channels without oversharing data.
item-3-icon
item-3-icon-alt
item-3-title
Biometric Authentication: From Simple Matches to Deepfake-Resistant Proof
item-3-description
Biometrics are widely used, but often rely on simple matching without strong liveness detection or spoof resistance, leaving them vulnerable to deepfakes and synthetic media. Closing the gap requires privacy-preserving biometric authentication with robust liveness that confirms identity without exposing raw data and reinforces trust across interactions.

What We Heard

"Identity is still handled in a fragmented way across systems, with no centralized visibility or control."

– IT Leader

"We manage logins well, but lack real time controls to restrict what users or services can do after they sign in."

– Security Leader

Are Identities and Relationships Kept in Sync?

Fragmented lifecycle processes and complex relationships leave identities, entitlements, and context out of sync, making Identity Management a persistent source of risk.

Lifecycle events (joiners, movers, leavers) are still too manual and fragmented across HR, IT, business platforms (including CRM), and partner systems. Access often lags real world changes, leaving stale or orphaned accounts, excess privileges, and blind spots across workforce, partners, customers, and agents.

As B2B ecosystems, customer relationships, and agentic-driven interactions grow more complex, organizations need a single view of identities so lifecycle, context, and entitlements stay aligned with real-world relationships.

item-1-icon
item-1-icon-alt
item-1-title
Lifecycle: From Checklist to Event-Driven Change
item-1-description
Lifecycle is still often driven by checklists and tickets, resulting in workforce joiners waiting for access, movers accumulating excess privileges, and leavers retaining accounts or tokens longer than they should. For customers, partners, contractors, and agents, access is often granted case by case, but not updated consistently as roles and relationships change. A stronger approach ties lifecycle to HR and business systems so provisioning and deprovisioning respond more consistently to changes in roles, relationships, and risk.
item-2-icon
item-2-icon-alt
item-2-title
Relationships: From Opaque Hierarchies to Modeled Reality
item-2-description
Complex B2B ecosystems and customer relationships make it hard to see who is acting for whom and what that should allow. Modeling these relationships clearly and applying them in policy helps ensure access reflects real-world roles and responsibilities.
item-3-icon
item-3-icon-alt
item-3-title
Directory and Context: From Scattered Stores to a Single View
item-3-description
Most environments still rely on multiple directories and application-specific user stores. Identity data is scattered, attributes do not align, and there is no single view of how a user or agent appears across systems. Discovery and reconciliation, combined with a central directory and shared context such as role, organization, and device posture, give teams a consistent view to support access and governance decisions across the identity lifecycle.

What We Heard

"The biggest gap is the lack of a unified, automated identity lifecycle that consistently manages access across all systems."

– IAM Architect

"We still rely on clunky, manual processes instead of a fully automated identity program."

– IT Operations Leader

Are We Authenticating and Authorizing the Right Way?

Access shows the lowest exposure in the Index, but uneven authentication, scattered authorization logic, and over-privileged accounts still create critical gaps for both human and non-human identities.

Most organizations have invested heavily in SSO and MFA, but controls are applied unevenly. Some apps sit outside federation, some journeys still rely on passwords, and authorization rules are buried in individual services.

That leaves users with very different levels of protection depending on which app they use, while attackers look for the weakest path in. Closing the Trust Gap means making access decisions continuous, risk aware, and consistent across channels, not something that changes from app to app — but remains consistent across the identity journey.

item-1-icon
item-1-icon-alt
item-1-title
Authentication: From Strong Front Doors to Adaptive Journeys
item-1-description
Authentication is strongest at a few entry points, but access occurs across many flows, including recovery, helpdesks, APIs, and third-party integrations for both human and non-human identities. Passwords and static prompts still carry much of the load, creating risk and user fatigue, while high-risk actions often look like any other login. Closing the gap requires phishing-resistant, passwordless methods and adaptive, risk-based challenges that respond to context and support consistent decisions.
item-2-icon
item-2-icon-alt
item-2-title
Authorization: From App-Specific Rules to Shared Policy
item-2-description
Authorization is often hard-coded in individual applications and APIs, each with its own roles and entitlements. This makes it difficult to see who can do what across systems or adapt policies as risk and regulations change across the identity journey. Closing the gap requires centrally managed, policy-based authorization that expresses business rules once and applies them consistently across channels and services.
item-3-icon
item-3-icon-alt
item-3-title
Privileged Access: From Standing Privileges to Just-in-Time Access
item-3-description
Privileged access is often overprovisioned and persistent, with broad entitlements that extend beyond what's needed. This is where small gaps become big incidents, making high-risk access difficult to control or adapt as roles, risk, and context change. Closing the gap requires just-in-time access, strong controls, and centralized policies that limit privilege to what's needed and apply it consistently across systems.

What We Heard

"The biggest gap in identity programs today is moving beyond basic authentication to real-time visibility and control over all identity behaviors."

– Identity Leader

"We manage logins well, but are exposed because we lack real-time systems to control what users can do after they sign in."

– Security Architect

Who Has Access to What — and Should They?

Revoking temporary privileges remains one of the hardest governance problems, and admin-time processes make it difficult to see and control who has access to what and why.

Many organizations still treat governance as a set of periodic, admin-driven checkpoints such as access requests, reviews, and segregation of duties, rather than a continuous, risk-aware control across the identity journey.

From spreadsheets to risk-based reviews: Roles and approvals are often set up and then left to run, so over time human oversight and role changes can lead to excess and long-lived access, while only a small share of cloud entitlements have known usage. Closing the Trust Gap requires real-time visibility and continuous remediation so temporary and high-risk privileges are tracked, adjusted, or removed as conditions change before they introduce risk.

item-1-icon
item-1-icon-alt
item-1-title
Access Request: From Broad Exceptions to Right-Sized Asks
item-1-description
Access requests are still ticket-driven and role-based: users ask for broad roles "just in case," approvers rubber-stamp without context, and temporary access rarely has a clear end date. Closing the gap requires policy- and context-driven requests that present right-sized options based on role and relationship, require stronger justification for sensitive access, and enforce time-bound admin and break-glass privileges so excess access does not linger.
item-2-icon
item-2-icon-alt
item-2-title
Access Review: From Spreadsheet Exercises to Continuous Oversight
item-2-description
Access reviews are often periodic spreadsheet exercises: managers see long lists of entitlements they do not recognize and approve most of them, leaving too much standing privilege in place. Reviews work better when they highlight unused, temporary, or high-risk access, make it easy to remove in context, and support timely, policy-driven revocation when access is no longer needed.
item-3-icon
item-3-icon-alt
item-3-title
Segregation of Duties: From Static Rules to Continuous SoD Checks
item-3-description
Segregation of duties is where small overlaps create big risk. Static SoD rules in documents or spreadsheets quickly fall out of date, and as roles, service accounts, bots, and agents grow, it becomes harder to spot risky combinations of access. A live view that maps who or what has which rights and runs checks before and after access is granted helps prevent any single human or non-human identity from accumulating access that should not sit with one actor.

What We Heard

"The program lacks clear, coordinated policies and is managed in a fragmented way across systems and departments."

– Compliance Leader

"We don't have a centralized governance framework to define roles, enforce policies, or ensure compliance."

– Risk & Compliance Leader

Are We Using What We Know to Stop Threats in Real Time?

Most organizations drown in alerts and logs, but without a unified risk view, attacks still slip through while trusted users see unnecessary friction.

Organizations collect plenty of alerts, logs, and fraud indicators, but these signals live in different tools and rarely drive identity decisions in real time, especially as bots, AI agents, and automated workflows create new patterns.

Closing the Trust Gap means treating threat protection as a continuous, identity-centric layer: aggregating risk signals across the journey, scoring them in real time, and feeding that into authentication, authorization, and session controls so high risk activity is stopped quickly while low risk users move with less friction.

item-1-icon
item-1-icon-alt
item-1-title
Detect: From Login Checks to Journey-Wide Signals
item-1-description
Most teams still rely on a narrow slice of risk data, like login events and IP reputation at authentication. But risk does not start or stop at login. Attacks such as bots, MFA fatigue, and account takeover often emerge during registration, recovery, or high-value actions. Closing the gap requires continuous risk detection across the identity journey, using signals from devices, networks, sessions, and behavior, and correlating them to users in real time.
item-2-icon
item-2-icon-alt
item-2-title
Decide: From Static Rules to Risk-Based Decisions
item-2-description
In many environments, risk decisions still depend on static rules or manual review. Signals exist, but they are not combined consistently, so responses are either blunt or slow. A risk engine that aggregates multiple signals into a single risk level and maps that to clear policies can decide when to allow, step up, or block, and when to trigger adaptive controls such as biometric re-verification, step-up authentication, or additional verification based on risk.
item-3-icon
item-3-icon-alt
item-3-title
Direct: From Dashboards to Real-Time Responses
item-3-description
Threat tools often stop at dashboards. Teams can see spikes and high-risk activity but get limited help deciding what to change. Closing the gap means using risk signals to directly shape journeys, surfacing attack patterns and high-risk users, applying the right mitigation in real time, and feeding outcomes back into the risk engine to continuously improve decisions.

What We Heard

"We lack mature, integrated systems for real-time behavioral anomaly detection and automated threat response, leaving us overly reliant on manual processes."

– IT Leader

"Integrating real-time risk signals into automated, cross-platform access enforcement."

– Identity Leader

Does Identity Act as a Connected Control Layer?

Fragmented tools and "systems that don't talk to each other" keep identity from acting as a connected control layer, making Integration one of the highest Trust Gaps.

Today, most environments are a patchwork. Critical apps, SaaS platforms, cloud services, and non-human identities such as APIs, bots, and AI agents each have their own access models and partial integrations. Identity capabilities exist, but they are wired together with brittle, point-to-point connections and manual workarounds. Closing the Trust Gap means turning identity into a connected control layer, where policies, signals, and decisions are shared and orchestration gives teams a consistent way to apply verification, access, governance, and risk controls across channels, journeys, and human and non-human identities.

item-1-icon
item-1-icon-alt
item-1-title
Orchestration: From One-Off Flows to Reusable Journeys
item-1-description
Many flows are still built one at a time. Onboarding, recovery, step-up, and helpdesk each have their own logic, often hard-coded inside apps. A reusable orchestration layer lets teams design patterns once and reuse them across use cases like verified onboarding, passwordless access, verified recovery, and agent delegation, applied consistently across apps, channels, and the identity journey.
item-2-icon
item-2-icon-alt
item-2-title
Connected Systems: From Fragile Links to Identity Fabric
item-2-description
Identity, fraud, HR, CRM, and custom apps often rely on fragmented, brittle integrations, so even 'connected' systems do not work together in practice. Closing this gap requires treating identity as a shared platform capability: using standard connectors, APIs, and events to bring SaaS, cloud, on-prem, and legacy applications into a common identity fabric where attributes, signals, and decisions move reliably in both directions.
item-3-icon
item-3-icon-alt
item-3-title
AI for Identity: From Expert Bottlenecks to Assisted Automation
item-3-description
Integration still depends on a small group of specialists who understand both legacy systems and modern identity platforms. As environments grow and non-human identities emerge, that bottleneck creates new trust gaps. Using AI to assist identity teams can suggest orchestration patterns, highlight inconsistent policies, surface orphan integrations, and automate routine configuration so identity operates as a unified, adaptive layer.

What We Heard

"The biggest gap is limited integration and automation across identity tools, resulting in manual processes and lack of real time, risk based access control."

– IT Leader

"Connected old systems which don't talk to each other."

– Line of Business Leader

Identity Isn't a Single System. It Touches Everything.

Yet 31% still treat identity as a compliance exercise instead of a strategic capability woven throughout the business.

Progress Stalls When Identity Is Siloed

Progress is happening, but the hardest parts of identity still stall: automating workflows, integrating systems, and applying trust consistently across environments. At the root, identity is not one platform or team. It runs through every system and process, and that is where gaps appear when it is treated as a checkbox instead of a strategic capability.

Leaders Describe Manual, Fragmented Identity Workflows

"The reliance on manual processes for user permission allocation and access management is a huge gap. We are moving towards automation, but integration issues between platforms are a major headache."

– IT Leader

"Programs that should talk to each other do not. We are still working through the integration process."

– IT Leader

"We do not yet have a full understanding of who can access what resources and why, which introduces some uncertainty regarding compliance and security policies."

– IT Leader

What's Getting in the Way

Leaders Transform Identity into a Cohesive, Adaptive System

The previous section explored what's getting in the way: friction, fragmentation, and the complexity of making identity work at scale. Across the Index, a clear pattern emerges: the organizations making the most progress aren't the ones with the most tools, they're the ones applying identity more consistently across systems, users, and interactions.

They've moved beyond isolated controls and treat identity as a connected capability that supports security, experience, and decision-making across the business.

Leaders don't just deploy identity capabilities. They make the deliberate choice to apply them consistently across every interaction, human and machine.

What Leaders Do Differently

Leaders turn identity from a set of capabilities into a system that works together.

Organizations That Commit to Trusted Experiences See Measurable Gains

Proven Business Impact

Based on findings from an IDC White Paper sponsored by Ping Identity, IDC's survey of 794 organizations found that organizations adopting continuous, contextual identity verification achieved:

heading
Measurable Outcomes from Continuous Identity Verification
stat-1-value
51%+
stat-1-description
Improvement in customer conversion
stat-2-value
47%+
stat-2-description
Improvement in workforce onboarding efficiency
stat-3-value
43%+
stat-3-description
Improvement in compliance readiness and fraud loss reduction

IDC also found that 94% of leaders operate at scale.

Ping Identity Takeaway

These findings reinforce the value of connecting verification, governance, risk signals, and automation across every interaction.

The Trust Gap Is Real, and It Can Be Closed.

Closing the trust gap starts with continuously validating the verified human behind the account throughout the identity journey, using contextual signals and risk-aware decisions to maintain trust over time.

Organizations on this path share a common approach:

The organizations closing the Trust Gap today are not waiting for a perfect solution. They are making deliberate moves, investing where exposure is highest, connecting what they have already built, and treating identity as the foundation for every trust decision their business makes.

The next step is understanding where your organization stands.

Where Are You on the Path to Trusted Digital Experiences?

Every organization in this study is somewhere on the spectrum between traditional identity models and trusted digital experiences. Some are just beginning to connect identity capabilities across systems. Others are already operating identity as a unified, adaptive layer. Most are somewhere in between — making progress, but with gaps still to close.

Understanding where you stand — across all six domains — is the first step toward closing those gaps with intention.

The identity maturity spectrum spans the following dimensions: Identity-Led Growth, Adaptive Operations, Agentic & AI, Workforce, Trusted Access, Customer, and B2B Partners.

Find the Trust Gaps in Your Environment and Prioritize What to Close Next.

The Identity Maturity Assessment provides a structured way to evaluate your organization's current position — where identity is being applied effectively, where gaps remain, and where focused investment will have the greatest impact.

Whether you're building foundational capabilities, advancing toward integration, or driving transformation across your identity environment — there's a clear path forward.

Take the Next Step

In a world where AI agents, non-human identities, and automated decisions are multiplying faster than policies can keep up — the human decisions you make about identity will define your organization's trust posture.

Assess your identity maturity and uncover the moves that will make the biggest difference.

Authors and Contributors

CONTRIBUTOR

Andre Durand

CEO & Founder, Ping Identity

Andre Durand is Founder and CEO of Ping Identity, where he leads the company's mission to define identity as the core security and control plane for the modern enterprise. A pioneer in digital identity for more than two decades, Durand has helped shape the evolution of the category from workforce access to customer identity and now AI agents and non-human identities. He also created Identiverse, one of the industry's leading identity conferences, and has guided Ping through multiple phases of growth across venture, public, and private ownership. Today, Ping's platform secures billions of digital identities worldwide. Durand is a frequent voice on the future of identity, with a focus on user experience, delegated authority, and runtime control in an AI-driven world.

LEAD AUTHOR

Lynette Hushen

Sr. Market Research Manager

Lynette Hushen specializes in market research, customer insights, and data-driven storytelling. At Ping Identity, she leads research initiatives that bring an outside-in perspective to go-to-market strategy, product direction, and messaging. Her work integrates primary and secondary research and is enriched through close collaboration with competitive intelligence and analyst relations to deliver actionable insights that drive business impact.

CO-AUTHOR

Dustin Maxey

VP, AI Transformation & GTM Strategy, Marketing

Dustin Maxey is a product and solutions marketing leader with deep experience in identity and access management. At Ping Identity, he drives AI transformation across go-to-market strategy, helping operationalize AI and embed it into how teams plan and execute. Building on a strong foundation in product marketing, his work connects market signals, emerging technology, and identity expertise to shape strategy, influence market narratives, and guide organizations through modern identity challenges.

title
Close the Trust Gap Before It Closes In on You
body
Most organizations still trust more than they verify. The 2026 State of Trust Index shows where identity programs break down — and what leaders do differently to build continuous, verified trust across every interaction.
Supporting text
See how Ping Identity helps you move from assumed trust to verified trust across your entire identity journey.
primary-link
https://www.pingidentity.com/en/company/contact-sales.html
primary-link-text
Request a Demo
primary-link-title
Request a Demo
use-tertiary-arrow-button-style
secondary-link
secondary-link-text
secondary-link-title
use-tertiary-arrow-button-style-2