
No IAM program has ever delivered full control. Not because the tools are wrong or the teams are not capable. But because full control was never really the design goal. Compliance was.
Governing SOX applications feels like a significant achievement. And in the context of the effort required, it is. But it is also a false summit. The applications tied to audit and compliance requirements represent the most justified, most funded, most visible slice of the application estate. Reaching the top of that hill and calling it done is not a security victory. It is a reminder that SOX was written because security failed. Governing SOX applications is not the answer to that failure. It is the acknowledgment of it. The real answer is what identity governance was always meant to deliver: security across everything, not compliance across a subset.
The applications that sit outside that perimeter are not forgotten. They are just not where the program is pointed. The budget is justified by SOX. The team is measured by SOX. When everything points in one direction, the things sitting in every other direction stop being visible. Not because they disappeared. Because the compliance model trained everyone to look away from them.
And that is where the entry points accumulate.
The Target data breach is the most referenced example of this. Not because it was the most sophisticated attack. Because it was not. A vendor with legitimate credentials. A system nobody thought was worth governing. A network path nobody had mapped. The entry point was not the target. It was just the door that was open. And nobody was watching it because nothing about it suggested it needed to be watched.
The lesson is not about HVAC systems. It is about the category of applications that share the same characteristics. Network access. Valid credentials. No governance oversight. In most enterprise environments that category is larger than anyone has formally counted.
The compliance model asks what an application contains. The security model asks what an application connects to. Those are not the same question and they do not produce the same answer. An application with no sensitive data scores low on the first and gets excluded from the governance program. But network access and valid credentials are all an entry point needs. Sensitive data is optional.
Organizations have asked both questions and still made the decision not to govern. Not because the risk was invisible but because the cost and time could not be justified against everything else competing for the same budget and the same team. That is not a security failure. That is a cost benefit decision made inside a broken economic model. And the risk does not disappear when the budget runs out. It just goes unmanaged.
I have sat in that conference room. Twelve hundred applications on the screen. Ten months to do the work. A set of criteria to decide what makes the cut. The math does not work and everyone in the room knows it. So the exercise begins. This one makes it. This one does not. This one gets deferred. And the ones that do not make the list do not go anywhere formal. They do not get a risk acceptance document or an executive sign off. They just stop being talked about. The roadmap moves forward. The leftover apps stay exactly where they are. On the network. With credentials. Ungoverned. Waiting.
Think about every application that was removed from the onboarding roadmap because the budget ran out. Every risk that was formally accepted because governing it could not be justified. Every business unit that pushed back on onboarding and won because the effort was too high. Every board conversation where partial coverage was presented as the best available outcome. Every one of those decisions made sense inside the economic model that existed at the time. None of them need to stand if that model has changed.
Leaving any application outside the governance program is not a calculated risk. It is an unexamined one. And the time to reexamine it is before it becomes an entry point, not after.