The alleged Nike breach did not begin with smashed glass. Attackers claimed 1.4 terabytes—enough internal material to turn product files, operating documents and employee artifacts into an extortion library. The precise contents remain disputed, as they often do when criminals double as press officers.

Not great.

Then came Instructure’s Canvas, where the scale of the reported theft placed an education platform used by schools and universities into breach-history roundups; UpGuard describes the incident disclosed in May as the largest recent U.S. breach based on Identity Theft Resource Center estimates UpGuard. Public accounting is still incomplete, and claims made by threat actors deserve skepticism. Yet the security lesson does not depend on accepting every advertised record count. A stolen credential with broad access can make a well-defended network behave like an open file share.

A useful distinction. These were not demonstrations that firewalls stopped working; they were demonstrations that perimeter controls become spectators once an attacker obtains trusted access.

What actually changed? The economic center of a breach moved from entry to traversal: whose identity was compromised, which permissions came with it, what data those permissions exposed and whether anyone noticed the resulting download before the lawyers did.

Verizon’s latest Data Breach Investigations Report continues to frame credentials, human behavior, exploited vulnerabilities and third-party access as recurring paths into enterprise systems Verizon DBIR. The useful part is not another taxonomy chart. It is the reminder that “inside” and “outside” have become accounting labels for systems spread across SaaS applications, contractors, cloud workloads and machine identities. The perimeter survives—just not as the organizing principle.

Identity is the new budget magnet.

For vendors, that redirects spending toward phishing-resistant authentication, privileged-access controls, identity-governance software, session monitoring and tools that map machine accounts nobody remembers creating. Data-security platforms get the adjacent wallet: discovery, classification, entitlement analysis, data-loss prevention and controls governing which SaaS user can export an entire repository. You can see where this is going. The winning pitch is no longer, “We block bad traffic”; it is, “We can prove who touched the crown jewels, and we can revoke access before breakfast.”

But deployment is the rub. Buying identity software is easy compared with persuading finance, engineering and outside contractors to surrender accumulated permissions, particularly when nobody wants to own the application that issued them (the service account usually belongs to someone who left during the last reorganization).

Harder work.

This is a mistake many investors make: treating identity and data governance as clean software categories with frictionless expansion revenue. The products can be excellent, yet implementations expose broken directories, duplicated roles, undocumented integrations and political arguments over who should see what. Credit where it’s due — vendors that automate entitlement cleanup without interrupting production have built something genuinely valuable. The rest are selling a dashboard for an organizational dispute.

The buyer incentives matter more than the slide deck. CISOs historically found it easier to fund visible defenses—another endpoint agent, another network sensor—than to request a prolonged access-remediation program whose successful outcome is that nothing happens.

Breach economics are changing that calculation. IBM places the global average breach cost at $4.99 million—roughly the payroll of a capable security team disappearing into response work, legal bills and operational disruption. Once directors see exfiltration as a data-control failure rather than merely an intrusion, identity owners and data stewards gain budget authority that previously sat with network security. Wall Street noticed, eventually.

The response process reinforces the shift. The Federal Trade Commission tells breached businesses to determine what was taken, stop further loss, preserve evidence, contact affected parties and assess legal obligations FTC. None of that becomes easier because the company bought a better appliance at the network edge. It becomes easier when the company already knows where sensitive data lives, who can reach it and which access path produced the copy.

For allocators, the implication is selective rather than thematic. Identity-security vendors should gain relevance, but category labels are cheap; durable value will accrue to products wired deeply enough into customer workflows that removing them would reopen access risk, while data-governance providers must prove they can enforce policy rather than merely discover alarming quantities of forgotten data.

And consolidation will be messy. Microsoft, Palo Alto Networks, CrowdStrike, Okta, CyberArk, SailPoint, Rubrik and a long tail of specialists all want some version of the control plane, leaving buyers to decide whether integration convenience outweighs correlated vendor risk. Three words: too many agents.

The Nike and Canvas cases may be revised as investigations progress; breach narratives usually become less cinematic under forensic review. Criminal claims are marketing, too, and the wider incident record cataloged by the Center for Strategic and International Studies shows how routinely attribution and scope change after disclosure CSIS. Still, the spending direction is difficult to miss. The next breach will not ask whether the wall was high—it will ask why everyone inside had a key.