Most organizations still trust more than they verify. Risk is building in that gap, and it's getting wider.
This Index maps where trust breaks down across the identity journey, and where it matters most to act.
Authors and Contributors
Andre Durand | CEO & Founder, Ping Identity
Lynette Hushen | Sr. Market Research Manager
Dustin Maxey | VP, AI Transformation & GTM Strategy, Marketing
Identity Is Now the Primary Target for Risk and Attack
Attackers are no longer limited to breaking through the network perimeter. They are increasingly attacking identity, targeting the moments that determine who gets access and when. Password resets, account recovery, and helpdesk approvals have become common entry points. In many cases, they are not forcing their way in. They are being let in.
At the same time, the nature of attacks has changed. What was once largely human driven is now a constant stream of automated activity. AI assisted attacks, synthetic identities, and automated account takeover attempts are probing identity systems at scale.
These attacks succeed by exploiting trust gaps where identity is assumed rather than verified.
This research builds on that reality, examining how identity-based threats are expanding. Based on responses from nearly 500 identity decision makers, the 2026 State of Trust Index shows where identity programs are strong, where gaps expose risk, and how leaders are starting to close them. In doing so, organizations are already seeing measurable outcomes like lower fraud, faster onboarding, and higher conversion.
Modern attacks increasingly target the identity layer — the accounts, credentials, and decisions that govern every digital interaction. Threats and attackers include:
- Account Takeover (ATO)
- Synthetic IDs
- Compromised bots & AI Agents
- Third-party & Partner Abuse
- Credential Stuffing & Phishing
- Deepfake Onboarding & Recovery
These threats operate across the digital environment — spanning the Identity Layer (accounts, credentials, policies, permissions), data, cloud SaaS, and apps.
Identity Is Shifting Away from Verify Once, Trust Always
Trust cannot stop at login. It has to follow every identity, human or agent, across the entire journey.
Most organizations have the components, but they don't operate as a system. Identity capabilities often function in silos, leading to disconnected decisions and gaps in how trust is established and maintained over time.
These gaps tend to show up in the moments that matter most:
- When account recovery changes ownership or access
- When new users, partners, or AI agents are onboarded into critical systems
- When privileged access is granted, extended, or not fully removed
- When access changes for partners, contractors, or customers
The State of Trust Index evaluates six categories: identification, identity management, access, governance, risk signals, and integration. Together, these determine whether trust is consistently verified across every interaction.
When these categories work together, every critical interaction connects back to a verified identity. Trust becomes something that is continuously proven.
The real question is how consistently these capabilities are applied, and how wide the gap is between what is possible and what is actually happening today.
Where is the biggest gap between where your identity program is today and where it needs to be?
Most Organizations Have Started the Journey, but Few Have Completed the Transformation
The State of Trust Index reveals how organizations assess their current identity maturity based on how well their systems work together. Most have made progress and moved beyond siloed tools, but the majority are still operating in the middle stages of maturity. Only a smaller group have reached what can be considered a truly transformative state — a unified, adaptive identity layer that enables real-time, risk-aware decisioning at scale.
Identity Operating Level
Organizations have made real investments in identity and connected many of their key systems. What is still missing for most is identity that operates as a single adaptive layer. One that can make real-time decisions, respond to changing risk, and orchestrate a consistent experience. Many programs now have more tools and more data, but decisions remain slow, manual, and ticket-based.
The Wider the Trust Gap, the More You Are Guessing Who to Trust
Where Exposure to Risk Is Highest Across the Identity Journey
Exposure to risk is not uniform. Where the trust gap is greater, reliance on implicit trust increases, extending risk across the full identity journey.
Higher exposure reflects larger trust gaps, where continuous verification is not consistently applied and trust is still assumed.
Exposure to Risk Follows a Clear Pattern as Identity Programs Mature, but These Categories Do Not Operate in Isolation. Gaps in One Area Create Downstream Risk in Others.
Progress is strongest in categories like Access, where authentication, authorization, and privilege controls are more established. But without consistent Identity Management, those decisions lack context: who the user is, how access should evolve, and what relationships matter.
As a result, Governance struggles to keep pace. Access reviews and policy enforcement become inconsistent when identity data is incomplete or disconnected.
Risk Signals follow a similar path. The data exists, but without integration into decisions, it rarely influences outcomes in real time.
These challenges compound in Identification and Integration, where exposure remains highest and identity programs are hardest to unify at scale. Without confidently tying identities to real, verified users, downstream decisions — from Access to Governance and Risk — begin to operate on incomplete or weak assumptions.
Identification requires moving beyond one-time verification to continuous assurance across every interaction.
Integration is what makes this assurance actionable, connecting identity tools across fragmented systems and enabling decisions to be applied consistently across channels, environments, and identity types.
These differences show why trust is difficult to apply consistently across the identity journey, and where investment decisions matter most.
The next sections examine each interrelated category, what drives the gaps between them, and how to close those gaps to create a more cohesive path to Verified Trust.
Is This a Real Identity, Verified by a Trusted Source?
Deepfakes and synthetic identities expose a core challenge: verification is often too weak to stop risk or too repetitive to avoid friction, making Identification the largest Trust Gap in the identity journey.
Most organizations still treat identification as a one-time hurdle at onboarding or recovery, rather than a continuous signal that informs decisions across the identity journey. After initial verification, identity is either assumed to remain valid or rechecked repeatedly, creating a mix of weak assurance and unnecessary friction.
Closing the Trust Gap requires shifting to ongoing identification: establishing verification as a trusted foundation, then using credentials and biometric authentication to tie back to that proof across the journey.
What We Heard
"Identity is still handled in a fragmented way across systems, with no centralized visibility or control."
– IT Leader
"We manage logins well, but lack real time controls to restrict what users or services can do after they sign in."
– Security Leader
Are Identities and Relationships Kept in Sync?
Fragmented lifecycle processes and complex relationships leave identities, entitlements, and context out of sync, making Identity Management a persistent source of risk.
Lifecycle events (joiners, movers, leavers) are still too manual and fragmented across HR, IT, business platforms (including CRM), and partner systems. Access often lags real world changes, leaving stale or orphaned accounts, excess privileges, and blind spots across workforce, partners, customers, and agents.
As B2B ecosystems, customer relationships, and agentic-driven interactions grow more complex, organizations need a single view of identities so lifecycle, context, and entitlements stay aligned with real-world relationships.
What We Heard
"The biggest gap is the lack of a unified, automated identity lifecycle that consistently manages access across all systems."
– IAM Architect
"We still rely on clunky, manual processes instead of a fully automated identity program."
– IT Operations Leader
Are We Authenticating and Authorizing the Right Way?
Access shows the lowest exposure in the Index, but uneven authentication, scattered authorization logic, and over-privileged accounts still create critical gaps for both human and non-human identities.
Most organizations have invested heavily in SSO and MFA, but controls are applied unevenly. Some apps sit outside federation, some journeys still rely on passwords, and authorization rules are buried in individual services.
That leaves users with very different levels of protection depending on which app they use, while attackers look for the weakest path in. Closing the Trust Gap means making access decisions continuous, risk aware, and consistent across channels, not something that changes from app to app — but remains consistent across the identity journey.
What We Heard
"The biggest gap in identity programs today is moving beyond basic authentication to real-time visibility and control over all identity behaviors."
– Identity Leader
"We manage logins well, but are exposed because we lack real-time systems to control what users can do after they sign in."
– Security Architect
Who Has Access to What — and Should They?
Revoking temporary privileges remains one of the hardest governance problems, and admin-time processes make it difficult to see and control who has access to what and why.
Many organizations still treat governance as a set of periodic, admin-driven checkpoints such as access requests, reviews, and segregation of duties, rather than a continuous, risk-aware control across the identity journey.
From spreadsheets to risk-based reviews: Roles and approvals are often set up and then left to run, so over time human oversight and role changes can lead to excess and long-lived access, while only a small share of cloud entitlements have known usage. Closing the Trust Gap requires real-time visibility and continuous remediation so temporary and high-risk privileges are tracked, adjusted, or removed as conditions change before they introduce risk.
What We Heard
"The program lacks clear, coordinated policies and is managed in a fragmented way across systems and departments."
– Compliance Leader
"We don't have a centralized governance framework to define roles, enforce policies, or ensure compliance."
– Risk & Compliance Leader
Are We Using What We Know to Stop Threats in Real Time?
Most organizations drown in alerts and logs, but without a unified risk view, attacks still slip through while trusted users see unnecessary friction.
Organizations collect plenty of alerts, logs, and fraud indicators, but these signals live in different tools and rarely drive identity decisions in real time, especially as bots, AI agents, and automated workflows create new patterns.
Closing the Trust Gap means treating threat protection as a continuous, identity-centric layer: aggregating risk signals across the journey, scoring them in real time, and feeding that into authentication, authorization, and session controls so high risk activity is stopped quickly while low risk users move with less friction.
What We Heard
"We lack mature, integrated systems for real-time behavioral anomaly detection and automated threat response, leaving us overly reliant on manual processes."
– IT Leader
"Integrating real-time risk signals into automated, cross-platform access enforcement."
– Identity Leader
Does Identity Act as a Connected Control Layer?
Fragmented tools and "systems that don't talk to each other" keep identity from acting as a connected control layer, making Integration one of the highest Trust Gaps.
Today, most environments are a patchwork. Critical apps, SaaS platforms, cloud services, and non-human identities such as APIs, bots, and AI agents each have their own access models and partial integrations. Identity capabilities exist, but they are wired together with brittle, point-to-point connections and manual workarounds. Closing the Trust Gap means turning identity into a connected control layer, where policies, signals, and decisions are shared and orchestration gives teams a consistent way to apply verification, access, governance, and risk controls across channels, journeys, and human and non-human identities.
What We Heard
"The biggest gap is limited integration and automation across identity tools, resulting in manual processes and lack of real time, risk based access control."
– IT Leader
"Connected old systems which don't talk to each other."
– Line of Business Leader
Identity Isn't a Single System. It Touches Everything.
Yet 31% still treat identity as a compliance exercise instead of a strategic capability woven throughout the business.
Progress Stalls When Identity Is Siloed
Progress is happening, but the hardest parts of identity still stall: automating workflows, integrating systems, and applying trust consistently across environments. At the root, identity is not one platform or team. It runs through every system and process, and that is where gaps appear when it is treated as a checkbox instead of a strategic capability.
Leaders Describe Manual, Fragmented Identity Workflows
"The reliance on manual processes for user permission allocation and access management is a huge gap. We are moving towards automation, but integration issues between platforms are a major headache."
– IT Leader
"Programs that should talk to each other do not. We are still working through the integration process."
– IT Leader
"We do not yet have a full understanding of who can access what resources and why, which introduces some uncertainty regarding compliance and security policies."
– IT Leader
What's Getting in the Way
- 53% — Automation more complex than expected
- 52% — App boarding and integration took longer than planned
- 34% — Identity data quality slowed progress
- 31% — Identity is still treated as a compliance exercise
Leaders Transform Identity into a Cohesive, Adaptive System
The previous section explored what's getting in the way: friction, fragmentation, and the complexity of making identity work at scale. Across the Index, a clear pattern emerges: the organizations making the most progress aren't the ones with the most tools, they're the ones applying identity more consistently across systems, users, and interactions.
They've moved beyond isolated controls and treat identity as a connected capability that supports security, experience, and decision-making across the business.
Leaders don't just deploy identity capabilities. They make the deliberate choice to apply them consistently across every interaction, human and machine.
What Leaders Do Differently
Leaders turn identity from a set of capabilities into a system that works together.
- They verify with confidence. Instead of relying on a single authentication event, leaders layer identity proofing, step-up verification, and real-time risk signals — making trust decisions continuous, not one-time.
- They automate lifecycle decisions. Onboarding, role changes, and offboarding are policy-driven and connected to HR, IT, and business systems — not dependent on manual handoffs and periodic reviews.
- They right-size access continuously. Rather than annual certification campaigns, leaders embed governance into day-to-day operations — adjusting access as roles, risk, and context change.
- They connect signals to decisions. Risk data isn't just collected and logged — it feeds directly into authentication, authorization, and step-up decisions in real time.
- They reduce fragmentation. Critical apps, SaaS platforms, and non-human identities are brought into a unified identity fabric — closing the pockets where implicit trust creates exposure.
Organizations That Commit to Trusted Experiences See Measurable Gains
Proven Business Impact
Based on findings from an IDC White Paper sponsored by Ping Identity, IDC's survey of 794 organizations found that organizations adopting continuous, contextual identity verification achieved:
IDC also found that 94% of leaders operate at scale.
Ping Identity Takeaway
These findings reinforce the value of connecting verification, governance, risk signals, and automation across every interaction.
The Trust Gap Is Real, and It Can Be Closed.
Closing the trust gap starts with continuously validating the verified human behind the account throughout the identity journey, using contextual signals and risk-aware decisions to maintain trust over time.
Organizations on this path share a common approach:
- They make deliberate choices about where to close gaps first
- They align teams and investment around outcomes, not just compliance
- They move from isolated tools to a connected identity layer, applied consistently across every interaction
The organizations closing the Trust Gap today are not waiting for a perfect solution. They are making deliberate moves, investing where exposure is highest, connecting what they have already built, and treating identity as the foundation for every trust decision their business makes.
The next step is understanding where your organization stands.
Where Are You on the Path to Trusted Digital Experiences?
Every organization in this study is somewhere on the spectrum between traditional identity models and trusted digital experiences. Some are just beginning to connect identity capabilities across systems. Others are already operating identity as a unified, adaptive layer. Most are somewhere in between — making progress, but with gaps still to close.
Understanding where you stand — across all six domains — is the first step toward closing those gaps with intention.
The identity maturity spectrum spans the following dimensions: Identity-Led Growth, Adaptive Operations, Agentic & AI, Workforce, Trusted Access, Customer, and B2B Partners.
Find the Trust Gaps in Your Environment and Prioritize What to Close Next.
The Identity Maturity Assessment provides a structured way to evaluate your organization's current position — where identity is being applied effectively, where gaps remain, and where focused investment will have the greatest impact.
Whether you're building foundational capabilities, advancing toward integration, or driving transformation across your identity environment — there's a clear path forward.
Take the Next Step
In a world where AI agents, non-human identities, and automated decisions are multiplying faster than policies can keep up — the human decisions you make about identity will define your organization's trust posture.
Assess your identity maturity and uncover the moves that will make the biggest difference.
Authors and Contributors
CONTRIBUTOR
Andre Durand
CEO & Founder, Ping Identity
Andre Durand is Founder and CEO of Ping Identity, where he leads the company's mission to define identity as the core security and control plane for the modern enterprise. A pioneer in digital identity for more than two decades, Durand has helped shape the evolution of the category from workforce access to customer identity and now AI agents and non-human identities. He also created Identiverse, one of the industry's leading identity conferences, and has guided Ping through multiple phases of growth across venture, public, and private ownership. Today, Ping's platform secures billions of digital identities worldwide. Durand is a frequent voice on the future of identity, with a focus on user experience, delegated authority, and runtime control in an AI-driven world.
LEAD AUTHOR
Lynette Hushen
Sr. Market Research Manager
Lynette Hushen specializes in market research, customer insights, and data-driven storytelling. At Ping Identity, she leads research initiatives that bring an outside-in perspective to go-to-market strategy, product direction, and messaging. Her work integrates primary and secondary research and is enriched through close collaboration with competitive intelligence and analyst relations to deliver actionable insights that drive business impact.
CO-AUTHOR
Dustin Maxey
VP, AI Transformation & GTM Strategy, Marketing
Dustin Maxey is a product and solutions marketing leader with deep experience in identity and access management. At Ping Identity, he drives AI transformation across go-to-market strategy, helping operationalize AI and embed it into how teams plan and execute. Building on a strong foundation in product marketing, his work connects market signals, emerging technology, and identity expertise to shape strategy, influence market narratives, and guide organizations through modern identity challenges.