top of page

Have you had a quiet yarn with your LLM about primary attack surfaces yet?

We put four AI platforms to the test - ChatGPT, Perplexity, Claude, and Copilot - and asked them all the same question about today's primary attack surface. They didn't hesitate: identity. Here's what the data says, and whether they're right.

If so, you’re not the only security leader to ask your AI platform about the current state of play. We certainly have. We asked ChatGPT, Perplexity, Claude, and Copilot what they consider the primary attack surface right now.


For transparency – we asked each platform the same question: What offensive-security topics are CIOs most likely to be researching, evaluating, or putting on the 2026 security roadmap?


And almost without exception, they said identity – with an emphasis on compromised credentials, privilege escalation, token theft, lateral movement, and identity-focused testing.


So what exactly did they say – and are they right?


According to ChatGPT: Identity attack paths and privilege escalation


ChatGPT ranked ‘Identity Attack Paths and Privilege Escalation’ third in its top ten offensive-security issues CIOs are currently researching – framing the core question as: 'If an attacker gets one identity, how far can they move?'


It's a simple question. But the answer isn’t.


Identity-based attacks target user credentials like usernames, passwords, and authentication tokens to gain unauthorised access to systems or data. They exploit identity security weaknesses through phishing, credential stuffing, MFA bypass, and session hijacking, allowing attackers to impersonate legitimate users and move laterally through networks.


Critically, five of the top ten MITRE ATT&CK tactics are identity-based – and identity attacks are extremely hard to detect. When an adversary compromises a valid user's credentials and masquerades as that user, it’s often difficult to distinguish their behaviour from the real thing.


According to CrowdStrike's 2025 Global Threat Report, 79% of detections were classified as malware-free, and valid account abuse became the primary initial access method in 35% of cloud intrusions. The 50% year-on-year rise in access broker advertisements signals surging demand for valid credentials on criminal marketplaces. Credentials are a hot commodity in the criminal underworld.


Put simply: today's attackers don't break in. They log in.


Perplexity’s callout: Identity-First Offensive Testing


Perplexity went a step further, naming ‘Identity-First Offensive Testing’ as its number two priority for CIOs – and defining it with precision.


The focus is on red teaming and adversary simulation across identity pathways: MFA bypass, token theft, session hijacking, privileged access abuse, and lateral movement via identity. The driver? Industry guidance is explicitly telling security leaders to 'shift focus from perimeter to identity' and treat identity as the new attack surface.


In short: the perimeter is gone. Identity is what's left.


Lateral movement is what happens when an attacker turns an initial foothold into broader access across your environment. It's the stage where a compromised account becomes a business risk.


CrowdStrike's 2026 Global Threat Report spells it out: the average eCrime breakout time fell to just 29 minutes in 2025, with the fastest observed breakout occurring in only 27 seconds. In one intrusion, data exfiltration began within four minutes of initial access.


If you're still testing your identity defences quarterly, you're already behind.


Claude and Copilot: Cloud Identity and Attack Simulation


Claude took the broadest view, identifying ‘Cloud and Identity Attack Paths’ as a primary CIO investment theme for 2026. Its focus extended beyond credential theft to the convergence of identity and cloud infrastructure, highlighting Entra ID and Okta misconfigurations, token theft, privilege escalation, and cloud-native attack path mapping across multi-cloud environments.


Copilot approached the problem from a more operational perspective, ranking ‘Identity Attack Simulation’ alongside Continuous Threat Exposure Management (CTEM), red teaming, cloud red teaming, breach-and-attack simulation (BAS), and AI-powered threat testing. While Claude focused on where the risk lives, Copilot focused on how organisations should test it.


Both tools pointed to the same reality: cloud and identity security have become inseparable.


The data supports that conclusion. According to CrowdStrike's 2026 Threat Hunting Report, adversaries are increasingly abusing legitimate authentication flows to turn a single compromised identity into rapid SaaS and cloud access, often without malware or traditional exploitation techniques. The report cites a 171% increase in eCrime cloud-conscious activity and a 15-fold increase in device code phishing attempts over six months.


Real-world examples are stark. eCrime groups including CORDIAL SPIDER and SNARKY SPIDER have used vishing techniques to compromise single sign-on accounts and access SaaS environments, with one incident progressing from account takeover to data theft in under five minutes.


Attackers increasingly authenticate with valid credentials and operate interactively inside environments, blending into legitimate activity. Once authentication succeeds, most identity systems don't reassess that trust as context changes – making it harder to detect compromise and giving attackers more time to move. Simulating identity attacks before real attackers run them is no longer a best practice. It's a baseline.


The challenge is no longer stopping attackers from getting in. It's understanding what happens next and how far a compromised identity can travel before detection.


So what does all of this mean for you?


The tools approached the question differently. But they all landed in the same place: identity remains the dominant attack surface.


As CrowdStrike's head of counter adversary operations, Adam Meyers, put it: "This is an AI arms race. Breakout time is the clearest signal of how intrusion has changed. Adversaries are moving from initial access to lateral movement in minutes. AI is compressing the time between intent and execution while turning enterprise AI systems into targets. Security teams must operate faster than the adversary to win."


The AI tools that help attackers move faster are the same tools defenders can use to detect, respond to, and shut down identity-based threats before they escalate.


The verdict is unanimous: identity is the primary attack surface.


The question is: are you testing it like it is?


If you'd like to understand what identity attack simulation looks like in your environment, let's talk. Human to human.

bottom of page