As identity attacks rise, the channel has a new managed services play
Rising identity attacks drive demand for IAM-focused managed security services
Identity Access Management (IAM) is a key building block to successful risk management at a time when ID theft is a key route for threat actors into company networks.
Since 2020, successful cyber breaches leveraging identity theft have become widespread, with recent examples such as the Visa, Marks & Spencer, Jaguar, and Harrods cases illustrating how even well-resourced companies are not immune to these types of attacks.
These breaches were linked to the Scattered Spider group, which has undergone a merger with another prolific cybercriminal group known as ShinyHunters. In just four months, the new group has successfully targeted and infiltrated multiple targets across the US and Europe, including the March 2026 breach of the European Commission, resulting in a 350GB data leak.
The anatomy of an identity attack
In these Identity attacks, Social Engineering is the primary initial vector, with cyber criminals leveraging Vishing and Phishing attack vectors to bypass SSO and multi-factor authentication (MFA) identity access controls. Attackers will often masquerade as internal IT, calling users on their work or personal phones to re-enroll or reset their IAM credentials, then send a modified account reset link to bypass non-phish-resistant MFA.
With credentials successfully hijacked, the attacker can then replay the MFA token to access SaaS resources and exfiltrate corporate data for the extortion phase.
The Social Engineering vector is popular as it offers an easy way to understand a company’s internal structure by leveraging social media. Employee names are usually linked to job titles, which reveal potential access privileges. Personal posts, interests, and commentary give insight into effective tactics for acquiring personal data through phishing, and, as corporate email addresses follow well-known conventions, they are easy to determine.
With identity being a pillar of cybersecurity but also a key attack vector, there are some key capabilities that IAM should deliver.
Stay up to date with the latest Channel industry news and analysis with our twice-weekly newsletter
Rethinking IAM for a more complex threat landscape
Identity access management is not a one-size-fits-all solution. Customer environments and business objectives determine which identity controls will be the most effective.
Nevertheless, there are key capabilities an IAM solution should provide:
- Coverage based on thorough integration within the corporate environment ensures a ‘single source of truth’, allowing visibility over the whole network – including legacy systems.
- Correlation of login data used to identify potential anomalies. The more complex the environment, the more important this capability. Automated analysis can flag potential issues to be investigated manually as a second step, to uncover more details.
- Reporting that enables pertinent and concise alerts to be raised by the IAM solution and follow a clear escalation path to ensure key stakeholders have actionable intelligence for decision-making.
Out of these capabilities, it’s the correlation element that is most important for the early detection of potential breaches in IAM integrity.
To improve the chance of early detection, it’s more effective to focus on looking for anomalies within the environment. These could be related to the user identity behavior, such as “Impossible Travel”, the user identity “location” represented by changes in IP address, or the service identities in the environment spiking in activity during off-hours.
There are several strategies that organizations can adopt to identify anomalous sign-ins without disrupting user experience; these fall under the concept of Risk-Based Authentication (RBA). Organizations can implement User and Entity Behavior Analytics (UEBA), which creates a profile of user behavior and can trigger a biometric or MFA check if a user activity falls outside of the baseline of the usual profile.
Conditional Access is another option, triggering authentication when a user activity exceeds a defined risk score threshold. Integrating FIDO2 passkeys, either software-based or hardware tokens, with one of the above RBA methods will greatly improve the efficacy of RBA by eliminating 90% of the common “anomalous sign-in” flags generated by password guessing or phishing.
IAM as a managed service opportunity
With threats on the rise and limited in-house cybersecurity expertise, companies of all sizes increasingly rely on managed cybersecurity services to strengthen and maintain their security posture. The IT channel is in a privileged position to deliver tailored and effective solutions incorporating IAM as an essential element of corporate cyber-resilience. But what should a robust IAM managed service include?
A true managed identity service should include an MFA or Passkey (FIDO2) capability, allow for customized policy management, and be able to deliver identity services to both users and non-human systems. It should also be capable of risk analysis powered by machine learning and AI, and deliver workflow orchestration. The service should be continuously reviewed and updated to keep up with the fast-evolving threat landscape.
For partners building IAM-managed services, it is recommended that they first conduct housekeeping in their own environment. Supply chain compromise is one of the top concerns in 2026, and partners must be able to show that their own environments are secure.
Secondly, if you have access to multiple vendors, you should standardize your solution stack. Ideally, you would have two core identity platforms, with one likely to be Microsoft Entra ID.
Thirdly, you should develop a comprehensive onboarding blueprint. The success of the service will depend on a positive customer onboarding experience, minimizing any outages in the process to ensure business continuity.
Ultimately, identity is no longer just an administrative layer. It is central to how organizations defend their environments.
As attackers increasingly target credentials, access pathways, and identity stores, businesses need IAM strategies that combine visibility, detection, and strong authentication. For partners, the opportunity lies not simply in selling another security tool, but in helping customers build a more resilient and adaptive approach to identity-led risk.

Dean Watson is an experienced network and infrastructure consultant with a demonstrated history of working in the telecommunications industry.
His expertise in network and infrastructure solution design include Health and Social Care Network (HSCN), Wide Area Network (WAN), Local Area Network (LAN), Network Security and Wireless (WLAN).
-
The CISO now owns physical security. Here’s what that means for the channelIndustry Insights Physical security budgets have moved to CISOs, and partners must adapt to this important shift
-
Why software supply chain security is the next accountability challenge for channel partnersIndustry Insights Partners need to be able to confidently answer key client questions relating to supply chain security going forward...
-
Sovereignty is the channel’s next trust testIndustry Insights Data sovereignty has become a key channel priority
-
Why MSPs should rethink the browser as the new security control pointIndustry Insights Enterprise browsers simplify security by consolidating multiple security controls
-
Why quantum-ready data protection belongs in the channel portfolioIndustry Insights Quantum-ready, data-centric protection is the channel’s next major differentiator
-
CMMC phase 2 Is suspended. The liability it created for MSPs isn'tIndustry Insights Why the CMMC regulation is not dead and what MSPs need to do about it
-
Has your security stack become your biggest cyber risk?Industry Insights Ask any organization what their tech stack looks like, and brace yourself for the response...
-
The case for the channel in an AI-driven security marketIndustry Insights AI won't replace channel partners; SMB cybersecurity still relies on trust

