What makes identity gnarly?
Critiquing the lens of an IANS report that shows IAM diseconomies of scale

IANS Research published its 2025 Benchmark Summary Report on Security Software and Services last October, and I missed seeing it until early in 2026.
IANS CEO Phil Gardner commented at the time on one particular stat:
Interesting…IAM gets gnarlier with size. IAM was the only software category that had NEGATIVE economies of scale.

So IAM takes only 8% of security budget in orgs with ≤$400M revenue but 14% of security budget in orgs with ≥$10B revenue? Yikes. This needs unpacking.
It took me a while, but I finally tried out my thoughts on the CISO Retreat crowd in the vicinity of Black Hat earlier this week (fitting, as it was event organizer Ross Young who originally drew my eye to the research). Everybody just accepted it as a reality — which worried me more than the number did.
The larger context of the report
Average IAM spending, at 10%, is right in the middle of the security pack. SecOps absorbs 16% of security budget and product security takes 6%.
Identity is actually starting to get its due in investment as Zero Trust becomes universally accepted (and with agentic security worries now proving to need new IAM-flavored solutions).
IAM isn’t strictly alone in the negative-economies-of-scale spotlight. SecOps is at 19% of spend for the largest orgs vs. 16% for the smallest. But SecOps spend growth is driven by price increases just to maintain current capabilities, while IAM’s top motivation is new tech adoption.

Speaking of which… CIAM counts as “new tech” that’s worth spending more on. Outside the identity industry bubble, CIAM is getting some nice recognition. Dave Shackleford is quoted as saying:
… When it comes to rapidly changing technology areas such as IAM and AppSec, many organizations discover they need new tools like customer IAM and improved web application firewall services to properly meet security requirements.
Why (it’s said) identity gets gnarlier for bigger orgs
Company revenue, per the report, is suggestive as a proxy for complexity. Company revenue does correlate strongly with employee numbers, and thus workforce IAM “load” if not exactly certain for other kinds of complexity. The comments on the LinkedIn post made these interpretive cases:
“This is due mainly to the fact that most enterprises have only really invested in about 25% of their real identity need (authentication), not governance, privileged user management, federation or identity detection and response. With identity being the new perimeter, expect to see massive amounts of additional spending in the IAM space as firewalls mean less and less and federated identity means more and more for security teams.”
This is a fair comment on the moment when an org finds it has to move up the maturity curve, though the connection to enterprise size is implicit. It’s likelier that a crisis of some sort — security, fraud, customer trust, compliance — or a big product strategy opportunity ends up driving that move.
As orgs get larger, their systems and processes get more complex. IAM has to deal with that complexity, and complexity is always expensive.
This is possibly true, but many other areas of security spending got cheaper as a percentage.
A few researchers and commentators have put the issue of IAM diseconomies of scale out there before.1
One big culprit seems to be not using actual modern IAM solutions, instead sticking with manual processes. This article is a good example. Cherrypicking a little, it discusses password resets, audit complexity given overprovisioning, onboarding delays, and manual access reviews as examples that have diseconomies of scale. Indeed. The bigger your org gets, the more painful all this gets.
That article calls it “IAM mismanagement” — so you might say “identity” gnarliness definitely grows as enterprises get larger when you’re not using effective, automatable IAM solutions. That will typically contribute to having some sort of crisis event that motivates a sudden larger investment.
So what is keeping these solutions from being used? It’s not about technology, natch, it’s about people and process. This Ponemon report makes the case that “high performers” — 23% of organizations with highly effective IAM investments — are seeing material gains in platform unification, new tech adoption, process automation, and prevention of security incidents.
That’s good data, and a fantastic business case for a CISO to make. But as we’re about to see, it sets up identity budgeting as a security zero-sum game against other enterprise needs. If you’re an IAM-owning CISO, you probably resent having to fight for identity budget at all. The alternative isn’t fighting harder — it’s other leaders arguing for that investment from their own side, out of pure self-interest. No compromises needed.
What if a rising investment curve reflects IAM’s growing strategic role?
The report surveyed CISOs, and CISOs are also its target audience. But do all CISOs own all IAM budget? What I learned in putting together my book, Mastering Digital Identity: From Risk to Revenue, was that CISOs are IAM owners roughly half the time. Who else might own IAM or at least elements of it, particularly in large orgs? IT, Risk/Audit, Fraud, HR, Product/Technology, and even Marketing.
And if CIAM is considered an example of new tech, the surveyed list of reasons for spending growth is likely incomplete. An interesting list of options was offered to respondents:
New tech adoption
Price increases
Infrastructure expansion
Prioritizing threat response
Changes to the strategy
Rising threat risk
Regulatory compliance
M&A
Increased outsourcing
IPO preparations
This covers some key motivations, but as the list of real-life IAM owners attests, it must serve many other purposes as well. My book uses a Four Ps framework for analyzing identity’s “jobs to be done” (Clayton Christensen’s concept): Protection, Personalization, Payment, and People. Security isn’t even the only type of Protection; others include privacy and financial fraud, with different owners and KPIs. The other Ps are similarly diverse.
Finally, the report discusses trends towards unified platforms, and unsurprisingly identifies Microsoft as one of three top platform choices. Microsoft’s all-you-can-eat E5 licensing option is a great example of how digital identity is your organization’s business model in disguise. Talk about a unified platform! Not only is IAM already part-security and part-other-stuff, but it infuses digital products that enable productivity apps, collaboration, and even “digital storytelling.”
My own hypotheses
Here are some real-world contributing factors I collected in my book interviews, which range well beyond enterprise size.
Is your industry highly regulated? Whole categories of IAM requirements come from compliance drivers. The “Regulatory compliance” spending reason could look wildly different for a bank vs. a retailer.
How many jurisdictions do you operate in? Global and multinational organizations deal with heavier, overlapping, and even conflicting regulations, as well as other coordination challenges. “Latency” isn’t just about system pings and responses — time zones play a big role. Some large enterprises are firmly anchored in one country due to their business model (though many are not).
How big is your partner ecosystem? How complex is your supply chain (”upstream” partners)? How massive is your institutional customer base or your channel partner network (”downstream” partners)? These impact demand for ever greater sophistication in IAM these days.
How many apps are you hooking up to a unified (or not yet unified!) identity provider? The number of internal-facing apps you’re using will, in part, scale with org size — while SaaS apps are easy for everyone, even smaller enterprises, to have too many of, bespoke apps do grow like weeds in larger ones. But when it comes to consumer-facing apps, you can’t tell from revenue or headcount at all. You could face 500 million end-users with a single, simple app — or a thousand institutional customers in a complex regulatory environment.
How loosely coupled are your lines of business? What’s your org’s history of M&A? The “M&A” spending reason looked surprisingly low to me at 3%, but an acquisitive, rapidly growing, still-small enterprise could be in that category. Is the main organization a big holdco with dozens of consumer-facing brands, and if so, have customer identities already been unified in some fashion, or not? I got acquainted with quite a few of these at ForgeRock. And what’s the culture around empowering — and possibly duplicating — management and operational functions in different LOBs?
Relatedly, how strategic is IAM considered to be inside the org? If it’s managed in unified fashion by a senior leader managing a roadmap — what my book calls an Identity Product Owner — higher investments could reflect measurable value to more parts of the org (and that IPO may also have identified interesting savings based on reuse of technology across departments). Companies managing identity as “authentication” over here and “access control” over there and “PAM” in that other corner have already sold it off for parts.
Gnarliness is multi-factorial
No single factor tells the whole story about IAM investment. “How big are you?” was never going to work as the big predictor. There’s new evidence of this in the fact that unified IAM has been pushing downmarket of late, wherever identity has turned out to be a revenue multiplier — and I’ll be interested to see how the IANS research ultimately reflects that reality.
You might have thought of consumer headcount as the most tempting proxy of the lot because the numbers can get really big. But it’s the one that fails hardest because it tells you nothing about how many of those consumers touch how many apps, under how many regulators, across how many brands and countries.
What predicts gnarliness isn’t any one of these factors — it’s the unique combination your org lives with. That’s a profile you have to assemble.
What to do about it
For the CISO Retreat crowd, I prepared a workbook that helps identify sources of CIAM gnarliness in particular, along with likely sources of cross-org support they could be leveraging. If you could use a tool like that, reach out and let’s talk it through. I’ll send you the workbook beforehand so you arrive with your own diagnostics already filled in — then we can get right to the good stuff. Just respond to this emailed post, or drop me a note here.
Thanks to Linda Romain for pointing me to some studies!

