Skip to content
KEDBYTE
How Identity Works
Chapter
60

What Breaks and What It Costs

Part V · Identity, Society and the Law|15,259 words|about 66 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

60.0 What this chapter gives you#

  1. You will be able to name the five ways an identity system fails - false accept, false reject, exclusion, leak and lock-out - define each one in a single precise sentence, and place any real incident you meet into one or more of them without hesitating.
  2. You will be able to explain why a false accept and a false reject are not two independent faults but two readings of one setting, and show on a curve what moving that setting does to each of them.
  3. You will be able to attach a sourced money figure to a false accept, using per-complaint arithmetic from the FBI Internet Crime Complaint Center 2025 report and the Javelin identity fraud figures published in April 2026, and say plainly what each figure does and does not measure.
  4. You will be able to attach a sourced money figure to a false reject, using the Baymard Institute abandonment research current in 2026 and Microsoft’s published sign-in success rates, and calculate the annual revenue a login funnel is destroying.
  5. You will be able to identify who a given design excludes, name the specific mechanism that excludes them - the device assumption, the name rule, the document rule, the biometric threshold - and put a number on the population affected.
  6. You will be able to cost a data leak in three separate currencies: the regulatory fine, the remediation bill, and the part that is permanent because the leaked attribute cannot be reissued.
  7. You will be able to convert an identity provider outage into money using a revenue-rate calculation, and cite what real outages have actually cost in duration, from the Azure Active Directory key rotation failure of March 2021 to the Google Cloud and Amazon Web Services incidents of 2025.
  8. You will be able to build a support cost table per authentication method, using published helpdesk figures and published per-message list prices as of August 2026, and show why the cheapest method to deploy is often the most expensive to run.
  9. You will be able to state the accessibility requirements that are also identity requirements, quote WCAG 2.2 success criteria 3.3.7, 3.3.8 and 3.3.9 correctly, and recognize the authentication designs that fail them.
  10. You will be able to put all of it on one page as an annual cost sheet, and argue from that page that an identity system is infrastructure, with the duties that word carries.

This is the last chapter of the book. It is about failure, which is a strange place to end, and it ends there on purpose. Everything in the preceding fifty-nine chapters was a mechanism: a signature, a seal, a password, a hash, a certificate, an assertion, a token, a directory, a wallet, a law. Mechanisms are interesting. But no mechanism is chosen on its merits. It is chosen because of what happens when it is absent, and what happens when it is present and goes wrong, and the difference between those two, priced.

The claim of this chapter is narrow and testable. Identity systems do not fail in a hundred ways. They fail in five, and every incident you will ever read about is one of those five or a chain of them. Somebody wrongly got in. Somebody rightly should have got in and did not. Somebody could never have got in at all, by design, and nobody noticed. The store of who-is-who was copied out. Or a legitimate person lost their means of getting back and there was no honest way to restore it. That is the whole list. It is short enough to memorize and it is exhaustive enough to use.

The second claim is harder and it is the one this chapter spends its weight on. Each of the five has a price, the price is measurable, and it is paid by a specific party who is frequently not the party that chose the setting. This asymmetry is the central fact of the subject. The organization that tightens a fraud threshold books the reduced fraud loss in its own accounts within a quarter. The cost of the people that threshold now turns away is booked nowhere, because a person who gives up does not file a ticket. The cost of a leak lands on the organization as a fine and on the individual as a permanent condition, and only one of those two appears in any financial statement. A chapter about what breaks is therefore also a chapter about accounting, and about which harms the accounting is built to see.

A word on what this chapter is not. It is not a survey of famous breaches; chapter 58 covers those, incident by incident, with what each one changed. It is not a design guide; chapter 59 lists the eleven decisions that fix an identity system’s shape. This chapter takes both as given and asks the question that comes after: when this thing fails, and it will, what is the bill and who receives it.

The plain version#

Five ways a village post office goes wrong#

Imagine a small post office in a village. Every Thursday morning it pays out the state pension in cash. Four hundred people come through the door over the course of the day, and each one collects around a hundred and eighty pounds. That is seventy-two thousand pounds handed across a wooden counter in eight hours by one clerk called Meera.

Meera’s whole job, for those eight hours, is to answer one question four hundred times. Is the person in front of me the person this money belongs to. She has a few things to work with. Each pensioner has a small red book with their name and number in it. Most of them she knows by sight, because it is a village. Some she does not, because people move, and because a son or a neighbour sometimes comes in to collect on behalf of someone who is ill.

There are exactly five ways this can go wrong, and every one of them costs somebody something.

The first way is that Meera pays the wrong person. Somebody comes in with a red book that is not theirs, or with a plausible story about collecting for their aunt, and walks out with a hundred and eighty pounds that was not theirs to take. The money is gone. Nobody gets it back. The real pensioner comes in on Friday and there is nothing in the account. Call this paying the wrong person.

The second way is that Meera refuses the right person. Mrs Anand has been collecting her pension here for eleven years, but this week she has left her red book on the kitchen table, and there is a new relief clerk who does not know her face, and the answer is no. Mrs Anand goes home without her pension. She is seventy-eight and it is raining. She may come back tomorrow. She may not. Call this refusing the right person.

The third way is different in kind, and it is the one that is easiest to miss. There is a woman living at the far end of the village who has never collected a pension at all. She is entitled to one. But she has no red book, because to get a red book you need a birth certificate, and hers was in a house that burned down in 1979, and the office that could reissue it wants a document she does not have either. She is not being refused at the counter. She never reaches the counter. There is no record of her anywhere in the post office’s books, and if you asked Meera how many people she turned away this year she would say four, and she would be telling the truth. Call this shutting people out.

The fourth way has nothing to do with the queue. Under the counter there is a ledger listing every pensioner in the village: names, addresses, dates of birth, account numbers, and the names of the people authorized to collect on their behalf. One night somebody photographs every page of it. Nobody is refused anything. No money moves. But the contents of that ledger are now in the world permanently, and every one of those four hundred people is now slightly easier to impersonate, everywhere, forever. Call this the ledger being copied.

The fifth way is the one that turns into all the others. Mr Sethi has lost his red book down a drain. He needs a new one. What does Meera do. If she issues a new book to anyone who can name a pensioner’s date of birth, then the front door is irrelevant, because the thief will simply come in and lose a book too. If she issues a new book only on production of a passport, then the third of her pensioners who have never owned a passport are now permanently outside the system, and she has quietly converted a lost book into shutting people out. Call this being locked out, and notice that the way you handle it decides the strength of everything else.

That is the list. Paying the wrong person. Refusing the right person. Shutting people out. The ledger being copied. Being locked out. There is no sixth.

Somebody always pays, and it is rarely the same somebody#

Now put a price on each one, because that is where this gets interesting.

When Meera pays the wrong person, the post office loses a hundred and eighty pounds. It is a clean, visible, immediate loss. It appears in a reconciliation at the end of the week. Somebody has to write it down and explain it. Because it is visible, it gets attention, and because it gets attention, it gets resources.

When Meera refuses the right person, the post office loses nothing at all. Mrs Anand is the one who loses. She loses a wet morning, a bus fare, and possibly a week of food money. If she gives up entirely and starts asking her nephew to collect for her instead, the post office will never learn that anything happened. There is no line in any ledger anywhere that reads “Mrs Anand went home empty-handed.” The cost is completely real and completely invisible to the only party in a position to change the rule.

That asymmetry is not a quirk of the village. It is the central mechanism of this entire subject. Losses from paying the wrong person are counted. Losses from refusing the right person are absorbed by people who have no way to report them. So systems drift, year after year, in the direction of refusing more people, because refusing is free to the person deciding.

The third failure is worse still. When somebody is shut out entirely, the post office does not merely fail to see the cost; it does not know the person exists. You cannot measure a queue that never forms. The only way to find out what shutting people out costs is to go outside the system and count, deliberately, the people who are not in it. Almost nobody does this, and it is the single most common reason a well-run identity system is quietly doing harm.

The fourth failure, the copied ledger, has a strange shape. Most of its cost arrives later, and it lands on different people from the ones who caused it. The post office may be fined. It will certainly have to write to four hundred people, which costs postage and time. But the part of the cost that never ends belongs to the pensioners, because a date of birth cannot be changed and a mother’s maiden name cannot be reissued. Some things you can replace after a leak, like a password. Some things you cannot, like a fingerprint or a family tree.

The fifth failure, being locked out, has the most interesting economics of all, because it is where the money actually goes. Every lost red book costs Meera twenty minutes. Twenty minutes is not much. Multiply it by the number of people who lose a book each year and it turns out to be a substantial fraction of what the post office spends on Meera at all. In most real identity systems, the largest single running cost is not authentication. It is helping people who cannot authenticate.

The dial that cannot be turned two ways#

Here is the fact that beginners find hardest, and it is worth taking slowly.

Suppose the post office wants to reduce the number of times it pays the wrong person. There is an obvious answer: be stricter. Insist on the red book, always, no exceptions, plus a second piece of paper with the pensioner’s name on it. Do that and the number of wrong payments will fall.

The number of correct payments will also fall. Not by accident and not because the rule is badly written, but because the two are the same rule read from two sides. A rule strict enough to stop a stranger with a plausible story is also strict enough to stop a real pensioner having a bad morning. There is one dial in the room, marked “how convinced do I need to be”, and it has exactly two directions. Turning it one way pays more wrong people. Turning it the other way refuses more right people. There is no setting at which both numbers go to zero, and any product that claims otherwise is either lying or has quietly moved the problem into a third place, usually into shutting people out.

What you can do is buy a better dial. If Meera gets a photograph in every red book, then at any level of strictness she will both pay fewer wrong people and refuse fewer right ones, because she now has better evidence to work with. That is what improving an identity system actually means: not choosing a better setting on the old dial, but obtaining better evidence so that every setting is better than it was. Choosing a setting is a policy decision. Obtaining better evidence is an engineering one. They are constantly confused, and the confusion is expensive.

The morning the post office does not open#

There is one more cost, and it is not a failure of judgement at all.

Some Thursdays the post office does not open. The line to the central computer is down, or the power is out, or the clerk is ill and no relief arrived. On those days, nobody is paid wrongly and nobody is refused wrongly, because nobody is anything. Four hundred people walk to the post office and walk home again.

For the post office this looks like a small operational blip. For the village it is seventy-two thousand pounds that did not arrive on the day it was needed, spread across four hundred households that had budgeted for it. And here is the part that matters: the cost of the closed door is not proportional to how badly it failed. It is proportional to how much depends on it. A post office that pays four hundred pensions is not a building; it is a piece of the village’s plumbing. When plumbing stops, the cost is measured in what stops with it.

Every identity system reaches that condition eventually. The moment enough things depend on being able to prove who you are through one particular door, that door has stopped being a product feature and started being infrastructure. Nobody announces the transition. It is visible only from the outside, on the day it is shut.

The shop we will actually price#

We will carry one example through the rest of this chapter and put real arithmetic on every claim.

Whitfield and Company sells kitchen and household goods over the internet in Britain and Ireland. It is not a real company; it is a worked example. Every figure attached to it is either arithmetic you can check on paper or a published number from a named source, and the figures that are invented are labelled as the example’s own so that nobody quotes them as an industry benchmark.

Whitfield has 2.4 million registered customer accounts. It takes 210,000 orders a month at an average order value of 62 pounds, which is 156.24 million pounds of revenue a year. Customers sign in about 640,000 times a month; the rest of the orders come from people who never make an account at all. Roughly 41,000 of the registered accounts have no mobile telephone number on file. About 780,000 accounts place at least one order in a given year.

Over the rest of this chapter we will work out, in pounds, what each of the five failures costs Whitfield every year, what an hour of its identity provider being down costs, and what it spends on helping people who cannot sign in. Then we will put the whole thing on one page, and the page will not look like what most people expect.

Where the plain version stops being true#

The five categories are clean; real incidents are not#

The taxonomy is a tool for thinking, not a classification of events. Almost every incident of any size is a chain that runs through several categories, and arguing about which box it belongs in is a waste of a meeting.

The honest version: the five are failure modes, not failure events. A single event usually contains a lock-out failure that enabled a false accept that produced a leak that will cause more false accepts for years. The Change Healthcare intrusion of February 2024 is the cleanest illustration available. Attackers signed in to a Citrix remote access service using credentials that were valid and that had no second factor attached; that is a false accept. The consequence was the exposure of records belonging to about 190 million people, later revised upward to 192.7 million; that is a leak. The leaked records will be used for years to impersonate those people at other organizations; those will be further false accepts, elsewhere, paid for by parties who had nothing to do with the original decision. Use the taxonomy to enumerate what can go wrong and to make sure you have priced each mode. Do not use it to label incidents.

False accept and false reject are not properties of a system#

The plain version said there is one dial. That is right as far as it goes and wrong in an important way.

The honest version: an error rate is not a property of a system at all. It is a property of three things together - the system, the operating point you have chosen on it, and the population you are running it against. Quoting a false accept rate without the other two is meaningless, and vendors do it constantly.

The population term is the one that gets forgotten and it is the one that causes harm. The National Institute of Standards and Technology published NISTIR 8280 on 19 December 2019, the third part of its Face Recognition Vendor Test, and its central finding was that false positive rates across demographic groups often varied by factors of ten to beyond a hundred, depending on the algorithm. That is not a single system with a single error rate. That is one system with a different error rate for each group of people who use it, at exactly the same setting. A threshold chosen to give an acceptable false accept rate on the population as a whole can be giving a rate a hundred times worse for one group inside it, and the aggregate number on the dashboard will look fine.

The cost is not paid by the party that chooses the setting#

The village version said this and it is true, but the mechanism deserves stating exactly, because it is the reason this chapter exists.

Costs that fall inside the organization are measured, because measuring them is how organizations work. Costs that fall outside are not measured unless somebody outside builds an instrument to measure them. This means that in the ordinary course of business, a rational, well-governed, honest organization will systematically over-invest in preventing false accepts and systematically under-invest in preventing false rejects and exclusion, and every individual decision along the way will look defensible.

The correction is not moral exhortation. It is instrumentation. If you want an organization to weigh a false reject properly, you have to put a number on it and place that number in the same report as the fraud loss. The technical version below shows how to do that. Until it is done, the argument is between a measured quantity and an anecdote, and the measured quantity wins every time, correctly.

The average breach cost is the wrong number for your breach#

You will see a single figure quoted for what a data breach costs. As of the 2026 edition, published on 29 July 2026, the IBM and Ponemon Institute Cost of a Data Breach Report gives a global average of 4.99 million US dollars, a twelve per cent rise on the previous year and the highest in the report’s twenty-one year history.

The honest version: that number is an average of a heavily skewed distribution drawn from a specific sample, and it is almost never the right number for the breach you are trying to reason about. The 2026 report is based on 602 organizations that suffered breaches between March 2025 and February 2026. The distribution behind the mean is enormously wide - the same report puts healthcare at 6.64 million US dollars and financial services at 6.29 million, and separately reports that breaches with a lifecycle over 200 days cost an average of 5.65 million against 4.32 million for those contained faster. The United States average was reported at more than double the global figure.

Use the report the way it is meant to be used: for the shape of the cost, the direction of the trend, and the relative effect of controls. For your own exposure, model your own record count against your own regulatory maximum and your own notification cost, which the technical version does below.

An identity provider’s uptime is not your uptime#

Every hosted identity provider publishes an availability figure and a status page. Both are honest and both mislead if read as a statement about your service.

The honest version: your availability is the availability of the whole path from your user to a live session, and the identity provider is one term in a product of terms. If sign-in requires the provider to be up, the user’s network to work, a mobile network to deliver a one-time code, and a push notification service to reach a handset, then the sign-in success rate is the product of all of those, and it is always lower than the best number in the chain.

Worse, the failure modes are correlated in a way the arithmetic hides. The Azure Active Directory outage of 15 March 2021 is the canonical case. Microsoft’s own account is that between roughly 19:00 UTC on 15 March and 09:25 UTC on 16 March, customers could not perform authentication operations for Microsoft or third-party applications that depended on Azure AD. The cause was an automated key rotation system that removed a signing key which had been deliberately marked to be retained. Microsoft noted in the same summary that its backup authentication system did not help, because that system covered token issuance and the failure was in token validation. A backup that shares an assumption with the primary is not a backup.

Not every leak is equally permanent#

The plain version said some things cannot be reissued. It is worth being precise about which.

The honest version: leaked data divides into three tiers by reissuability, and the cost model for each is completely different. Tier one is data you can replace on Tuesday: passwords, session tokens, API keys, card numbers. The cost is the operational cost of replacement plus whatever damage occurred before replacement. Tier two is data you can replace with difficulty and disruption: telephone numbers, email addresses, account numbers, in some countries the national identifier. Tier three cannot be replaced at any price: date of birth, place of birth, biometric templates, genome, family relationships, and the historical fact of who you were connected to on a particular date.

The United Kingdom Information Commissioner’s Office made this point in plain language when it fined 23andMe 2.31 million pounds on 17 June 2025 over a credential stuffing attack that ran from April to September 2023 and exposed information belonging to 155,592 UK residents. The Commissioner quoted an affected person directly: once this information is out there, it cannot be changed or reissued like a password or credit card number. Any cost model that treats a tier three leak with the same discount rate as a password dump is wrong by an amount that does not converge.

Exclusion is invisible in the metrics that exist#

The plain version said you cannot measure a queue that never forms. That understates the problem.

The honest version: standard identity metrics are structurally incapable of detecting exclusion, because they are all computed over people who attempted something. Sign-in success rate has attempts in the denominator. Verification pass rate has submissions in the denominator. Every one of these goes up when an excluded population stops trying, because the people most likely to fail have removed themselves from the sample. A dashboard can improve monotonically while the system is shedding users, and there is no alert that fires.

Detecting exclusion requires a measurement taken outside the funnel: a comparison against a population you believe you should be serving. The World Bank’s Identification for Development programme does exactly this at global scale. Its 2025 Global Dataset estimates that approximately 800 million people worldwide have no official proof of identity, down from around 850 million in 2021 and just over one billion in 2017, and that at least 2.8 billion more have no government-recognized digital identity with which to transact online. Roughly one person in ten cannot prove who they are. No sign-in dashboard on earth contains that fact, because none of those 800 million people ever generated an event.

The technical version#

The five failures, defined exactly#

Here are the five, stated precisely enough to argue about. The first two have formal definitions in the biometric vocabulary standard ISO/IEC 2382-37; the last three do not have standardized definitions and are used here as this book uses them.

A false accept is a decision by the system that a presented identity claim is valid when the claimant is not the subject the claim names. In biometric terms the underlying rate is the false match rate, FMR, measured on comparisons; the system-level figure that includes attempts which never produced a comparison is the false accept rate, FAR. The distinction matters because a system that fails to capture a sample and then falls back to a weaker check has produced a system-level error that the matching subsystem never sees.

A false reject is a decision that a presented claim is invalid when the claimant is in fact the subject. The matching-level rate is the false non-match rate, FNMR; the system-level rate, which includes failure to acquire, is the false reject rate, FRR. Two further rates matter operationally and are routinely omitted from vendor material: failure to enrol, FTE, the proportion of the population that cannot be registered at all, and failure to acquire, FTA, the proportion of attempts that never produce a usable sample.

Exclusion is the condition of a person who cannot succeed at enrolment or authentication under any correct behaviour, because of a property of themselves or their circumstances rather than of their conduct. It is not a rate over attempts. It is a count over a population, and it must be measured against an external denominator. Failure to enrol is the biometric special case of exclusion; there are many non-biometric cases, which the section on mechanisms below enumerates.

A leak is the disclosure of identity data to a party not authorized to hold it. Note that it is defined on the data, not on the accounts: a leak can occur with no false accept anywhere, through a misconfiguration, an insider, a backup, or a supplier.

A lock-out is the condition of a legitimate subject who has lost the means of authenticating and has no path back that satisfies the system’s own assurance requirements. A lock-out is not a false reject, because the system is behaving correctly. It is a design gap, and it is the single most reliable route into every large organization, because the path you build to resolve it is by definition the path with the weakest evidence.

Here is where each one arises in the pipeline.

  ENROL            AUTHENTICATE          AUTHORIZE
    |                   |                    |
    |-- FTE ------------|-- FTA -------------|
    |   cannot          |   no usable        |
    |   register        |   sample           |
    |                   |                    |
    |-- exclusion       |-- false accept     |-- over-grant
    |   (population)    |   (FMR / FAR)      |   (wrong scope)
    |                   |                    |
    |-- proofing        |-- false reject     |-- under-grant
    |   refusal         |   (FNMR / FRR)     |   (blocked task)
    |                   |                    |
    +---- STORE --------+---- RECOVER -------+
             |                    |
             |-- leak             |-- lock-out
             |   (data out)       |   (no way back)
             |                    |
             +--> both feed back into false accept
                  at every other organization

The last line of that diagram is the one to keep. A leak here becomes a false accept somewhere else, at an organization that made none of the decisions and receives none of the warning.

The threshold, and why the two rates are one number#

A matcher does not output a decision. It outputs a score, and a threshold turns the score into a decision. Move the threshold and you move both error rates in opposite directions along a single curve. The curve plotting false match rate against false non-match rate as the threshold sweeps is the detection error tradeoff curve; the point where the two are equal is the equal error rate, which is a convenient summary and almost never a sensible operating point.

  FNMR
  (false rejects)
   ^
   |*
   |  *
   |    *          A = loose threshold
   |      *            few rejects, many accepts
   |        *
   |   B      *    B = the operating point you pick
   |            *
   |              *
   |         A       *
   |                    * * *
   +-------------------------------> FMR
                              (false accepts)

  Better evidence moves the WHOLE curve toward the
  origin. Changing the threshold only slides you
  ALONG it. These are different projects with
  different budgets.

Three practical consequences follow, and all three are routinely got wrong.

First, any requirement written as “the false accept rate must be under one in ten thousand” is incomplete until it also states the false reject rate you will accept at that setting and the population you measured on. A supplier can meet any false accept target you name by refusing everybody.

Second, because the curve is steep at both ends, the marginal cost of tightening rises very fast. Going from one in a thousand to one in ten thousand may cost you a small number of extra rejections. Going from one in ten thousand to one in a hundred thousand on the same evidence may cost you an order of magnitude more, because you are now on the steep part.

Third, the operating point is a business decision expressed as a number, and it should be derived from the costs on each side rather than chosen by feel. If a false accept costs you C-accept and a false reject costs you C-reject, the total expected cost at a threshold t is:

  cost(t) = N * [ P(impostor) * FMR(t) * C_accept
                + P(genuine)  * FNMR(t) * C_reject ]

  N            attempts in the period
  P(impostor)  base rate of attack attempts
  P(genuine)   1 - P(impostor)
  FMR(t)       false match rate at threshold t
  FNMR(t)      false non-match rate at threshold t

The base rate term is what makes real systems counter-intuitive. If one attempt in ten thousand is an attack, then even a very good matcher generates far more false accepts among impostors than intuition suggests, and simultaneously a small false non-match rate applied to the other 9,999 attempts dominates the total cost. Most consumer login systems are in exactly this regime, which is why their real expense is on the reject side.

The price of a false accept#

The best available per-incident figures for the English-speaking world come from the FBI Internet Crime Complaint Center. Its 2025 annual report records 1,008,597 complaints and reported losses of about 20.9 billion US dollars, the highest in the twenty-five year history of the centre. Dividing loss by complaint gives a per-incident figure for each category. These are reported losses from self-selected complainants, which biases toward larger harms and toward the United States; treat them as an upper-middle estimate rather than a mean over all incidents.

Category, IC3 2025 Complaints Loss per complaint
Business email compromise 24,768 123,004 US dollars
Personal data breach 67,456 19,493 US dollars
Identity theft 31,675 5,867 US dollars
Phishing and spoofing 191,561 1,127 US dollars

The ordering in that table is the important part. A single successful false accept against a business email account is worth roughly a hundred times a single successful phishing event, because the phishing event is a step and the business email compromise is a completed theft. When you price a control, price it against the category it actually prevents.

The consumer picture comes from Javelin Strategy and Research, whose 2026 Identity Fraud Study was published on 21 April 2026 from a survey of 5,010 United States adults conducted between 10 November and 3 December 2025. It reports traditional identity fraud losses of 27.3 billion US dollars in 2025, affecting 18 million victims, which is about 1,517 US dollars per victim. Account takeover victims rose 18 per cent, from 5.1 million in 2024 to 6 million in 2025; new-account fraud victims rose 31 per cent, from 4.2 million to 5.4 million.

The figure from that study which almost never gets quoted is the time cost. Javelin reports that victims spent an average of 10.4 hours resolving identity fraud in 2025, against 9.5 hours in 2023, and that account takeover victims averaged 17 hours and new-account fraud victims 17.8 hours. Seventeen hours is more than two working days. Multiply 6 million account takeover victims by 17 hours and you get 102 million hours of unpaid remediation labour performed by members of the public in one country in one year. That number appears in nobody’s accounts, which is precisely the point.

Now Whitfield. Of its 640,000 monthly sign-ins, the example’s own assumption is that one in 2,600 is an unauthorized takeover that results in a loss, which is 246 a month, call it 250, or 3,000 a year. The example’s own per-incident cost is 212 pounds: goods dispatched and not recovered, the payment reversal, and the investigation time. Three thousand at 212 pounds is 636,000 pounds a year. That is the visible number, the one that gets a project.

The other kind of false accept cost is discontinuous rather than annual. Chapter 58 covers the incidents themselves; here we are only interested in the invoice. In September 2023 MGM Resorts International reported an approximately 100 million US dollar impact in its third quarter from an intrusion that began with a social engineering call to an IT help desk, made up of about 84 million US dollars of lost revenue and around 10 million of one-off costs. Caesars Entertainment, hit by the same method days earlier, reportedly paid about 15 million US dollars. And the Change Healthcare intrusion of February 2024, entered through a remote access service with valid credentials and no second factor, produced total cyberattack impacts that UnitedHealth Group revised to approximately 2.87 billion US dollars for 2024 alone, having reported 1.521 billion of direct response costs in the nine months to 30 September 2024. One account. One missing second factor.

The price of a false reject#

A false reject costs money in two places: the transaction that did not happen, and the customer who did not come back. Both are measurable, and almost nobody measures them.

The public evidence base for the second is the Baymard Institute’s abandonment research. Its aggregate of 50 separate studies gives an average documented online cart abandonment rate of 70.22 per cent, last updated 22 September 2025. Its own quantitative survey, of 1,083 United States adults who had shopped online in the prior three months, asks why. As published in the 2026 edition of that research, 42 per cent said they were browsing and not ready to buy, 40 per cent that extra costs were too high, 19 per cent that they did not trust the site with their card details, and 18 per cent that the site wanted them to create an account. A further 17 per cent cited a checkout that was too long or too complicated.

Read that 18 per cent precisely, because it is widely misquoted. It does not mean that 18 per cent of checkout sessions are lost to account creation. It means that 18 per cent of surveyed shoppers report having abandoned at least one purchase in three months for that reason. It is a prevalence figure across people, not a rate across sessions. Quoted correctly it still supports a strong claim: requiring an account is, on this evidence, a larger cause of lost orders than distrust of the payment page.

The other public figure worth having is Microsoft’s, published in its security blog on 12 December 2024 and repeated on 1 May 2025. Microsoft reports that users signing in with passkeys are about three times more successful at getting into their account than password users, at about 98 per cent against 32 per cent, that signing in with a passkey is three times faster than with a password, and eight times faster than a password plus traditional multi-factor authentication. Again, read it precisely: this is a session success rate across Microsoft consumer accounts, not a per-attempt match rate, and it includes every reason a password sign-in fails, forgetting chief among them. That is exactly what makes it useful. From a business point of view the reason does not matter; the person is not in.

Now Whitfield, with the example’s own funnel figures.

  Sign-in attempts per month            640,000
  x  fail to reach a session   4.1%      26,240
  x  do not return in 30 days  31%        8,134
  x  order rate for a session  22%        1,790
  x  average order value       GBP 62   110,980  per month
                                    ------------
  Annual revenue lost to false reject  1,331,760

One million three hundred thousand pounds a year, against 636,000 pounds a year of fraud loss. The failure that nobody measures is costing Whitfield slightly more than twice the failure that everybody measures. That ratio is not a general law and this is a worked example, not a benchmark. But it is the right order of magnitude for a consumer service with a password-based login, and the exercise of computing it for your own funnel takes an afternoon.

Two further notes on the arithmetic. First, the 31 per cent non-return figure is the one that dominates the result and it is the hardest to obtain honestly, because it requires linking a failed sign-in to the absence of a later one. If you cannot compute it, compute the answer for 10 per cent and for 50 per cent and present both; a range that is correctly derived is worth more than a point estimate that is not. Second, this model counts only registered customers. It does not count the people who never registered because the registration itself was the obstacle, which is the Baymard 18 per cent, and which belongs in the next section rather than this one.

The price of exclusion, and the mechanisms that cause it#

Exclusion is not a threshold problem. You cannot fix it by moving a dial, because the excluded person generates no score to compare against a threshold. It is caused by specific, enumerable assumptions built into a design, and the productive way to work on it is to list the assumptions and count the people each one removes.

Here are the ten mechanisms that account for nearly all of it in practice.

  1. The device assumption. The design requires a smartphone, or a camera, or a near-field communication reader, or a browser released in the last three years. Everyone without one is out, and that population correlates strongly with age, income and disability.
  2. The network assumption. The design requires a one-time code to arrive by text message. Delivery is not guaranteed, is worse on some networks than others, and is worse when roaming, in rural coverage gaps, and on pay-as-you-go numbers that have lapsed.
  3. The document assumption. The design requires a passport or a driving licence. In every country a substantial minority of adults hold neither, and that minority is not randomly distributed.
  4. The name model. The design assumes a given name and a family name, in Latin script, with no apostrophes or hyphens, between two and thirty characters, and stable across a lifetime. People with one name, with patronymics, with names in other scripts, with names longer than the field, and people who have changed their name after transition or marriage or fleeing violence, all fail on data entry.
  5. The address model. The design requires a fixed, postally-formatted address with a recent utility bill attached to it. This excludes people with no fixed address, people in shared or institutional accommodation, and people in the many places where addressing is informal.
  6. The biometric assumption. The design requires a fingerprint that has ridges, an iris that is unclouded, a face that matches an old photograph. Manual labour wears fingerprints down; cataracts and surgery change irises; age changes faces. This is a failure-to-acquire and failure-to-enrol problem and it lands hardest on the oldest and poorest users.
  7. The credit-file assumption. The design verifies identity by asking questions only a credit bureau could answer. Recent arrivals, young adults, and people who have never borrowed have thin files and cannot be verified at all.
  8. The capacity and delegation assumption. The design assumes one competent adult acting for themselves. Children, people acting under power of attorney, and people with cognitive impairment do not fit, and the workaround is usually to share a credential, which destroys the property the credential was for.
  9. The literacy and language assumption. The design presents instructions in one language at a reading age well above the population median.
  10. The cost assumption. The design is free to the organization and not to the user: mobile data to upload a document, a bus fare to an enrolment centre, a day of lost wages to queue.

The scale of the resulting harm is best seen from outside. The World Bank Identification for Development Global Dataset published in 2025 estimates that approximately 800 million people have no official proof of identity, down from around 850 million in 2021 and just over one billion in 2017, and that at least 2.8 billion people have no government-recognized digital identity for online transactions, down from 3.3 billion in 2021. Over half of those without any official identification are children whose births were never registered.

India provides the largest natural experiment, and chapter 50 covers the Aadhaar system properly; the point here is only the cost mechanism. On 18 July 2025 the Public Accounts Committee of the Indian Parliament, chaired by K. C. Venugopal, examined a 2021 report of the Comptroller and Auditor General on the Unique Identification Authority of India and took oral evidence from the Ministry of Electronics and Information Technology and from UIDAI. Members across parties reported that failures of fingerprint and iris verification were blocking eligible beneficiaries from subsidized food rations under the Public Distribution System and from work under the Mahatma Gandhi National Rural Employment Guarantee Scheme, specifically citing worn fingerprints among manual labourers and changed iris patterns among elderly citizens. The committee directed UIDAI to submit an action plan within six weeks covering biometric failure reduction, data security and deactivation of records of the deceased. That is mechanism six, in the largest identity system ever built, still unresolved fifteen years in. [UNVERIFIED: a single official national Aadhaar authentication failure rate current as of August 2026]

And Whitfield. About 41,000 of its 2.4 million accounts, 1.7 per cent, have no mobile number on file. There is a proposal on the table to make a text-message code mandatory at sign-in. Of those 41,000, the example’s own figure is that 23,000 ordered at least once in the last year, averaging 2.1 orders at 62 pounds, which is 130.20 pounds each, or about 3.0 million pounds of annual revenue. Those customers are not currently excluded. They will be excluded by a decision that has not yet been taken, and the paper proposing it does not contain that number, because the fraud reduction was easy to model and the exclusion was not. Adding one line to that paper is the entire intervention.

The price of a leak#

A leak is billed in four separate currencies and they must be modelled separately, because they arrive at different times and from different directions.

The first is the regulatory fine. Under Article 83(5) of the General Data Protection Regulation, and the equivalent provision as retained in United Kingdom law, the maximum for a security failing of this class is 20 million euros, or in the United Kingdom 17.5 million pounds, or four per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. For Whitfield, four per cent of 156.24 million pounds is 6.25 million, so the applicable maximum is the fixed figure of 17.5 million pounds.

Maxima are not outcomes. The record of actual regulatory practice is much lower and much more variable, and the gap between the notice of intent and the final penalty is where the real information is.

Case Notice of intent Final penalty
British Airways, 2019 to 2020 183.39 m pounds 20 m pounds
Marriott, 2019 to 2020 99.2 m pounds 18.4 m pounds
23andMe, 2025 4.59 m pounds 2.31 m pounds

The British Airways penalty was issued on 16 October 2020 and the Marriott penalty on 30 October 2020, each after representations, mitigation credit, and a further four million pound reduction that the Information Commissioner applied in view of the pandemic. The 23andMe penalty was issued on 17 June 2025, following a joint investigation with the Office of the Privacy Commissioner of Canada, and reduced from the preliminary figure for cooperation and the company’s financial position. Note what 23andMe was actually fined for: failing to implement appropriate authentication and verification measures, including mandatory multi-factor authentication, secure password protocols and unpredictable usernames, and failing to control access to raw genetic data. That is an identity design finding, issued by a data protection regulator, and it is the clearest signal available that authentication choices are now directly enforceable.

The second currency is remediation. This is arithmetic, and it is the part organizations consistently underestimate because it scales with the number of people rather than the number of records. For Whitfield, the example’s own model: notifying 2.4 million people by email, with a posted letter for the subset with no deliverable email address, at a blended 42 pence each, is 1,008,000 pounds. Offering credit monitoring at 8 pounds a head with a six per cent take-up is a further 1,152,000 pounds. That is 2.16 million pounds before a single pound of fine, legal fee, or forensic invoice.

The third currency is the disruption cost, which is bundled into most published averages. The IBM and Ponemon Cost of a Data Breach Report 2026, published 29 July 2026 and covering 602 organizations breached between March 2025 and February 2026, gives a global average of 4.99 million US dollars, up twelve per cent and a record. Two figures in it are more useful than the headline. Mean time to identify and contain rose to 247 days, an increase of about 2.5 per cent and the first rise after five consecutive years of improvement. And breaches with a lifecycle over 200 days averaged 5.65 million US dollars against 4.32 million for those contained inside 200 days. Detection speed, not prevention, is where the marginal money is.

The fourth currency is the permanent one, and it does not have a unit. It is carried entirely by the individual, it does not appear in the IBM average, it is not compensable by a fine, and it does not decay. A leaked password costs its owner an evening. A leaked fingerprint template, family tree, or health inference costs its owner the rest of their life, at an unknown rate, in ways that will be invented by people who do not exist yet. When you are choosing what to collect, this is the only cost line that matters, and it is the argument for collecting less that survives every other argument.

For the annual page we will treat leak cost as an expected value: the example’s own 4 per cent annual probability of a reportable breach across the full account base, at 2.16 million pounds of remediation plus a modelled 1.5 million pound regulatory and legal exposure, giving 3.66 million pounds at 4 per cent, or 146,400 pounds a year.

Availability: what an hour of downtime costs#

Convert availability into money by dividing revenue by minutes. Whitfield’s 156.24 million pounds a year over 525,600 minutes is 297.26 pounds a minute. That single number turns every service level conversation into arithmetic.

Availability Down per year Per 30-day month
99 per cent 3 d 15 h 36 m 7 h 12 m
99.9 per cent 8 h 46 m 43 m 12 s
99.95 per cent 4 h 23 m 21 m 36 s
99.99 per cent 52 m 34 s 4 m 19 s
99.999 per cent 5 m 15 s 26 s

At a constant revenue rate the relationship is exact and worth stating as a rule: a downtime allowance of X per cent costs X per cent of revenue. Whitfield’s 99.9 per cent target permits 525.6 minutes a year, which at 297.26 pounds a minute is 156,240 pounds, which is precisely 0.1 per cent of 156.24 million. Everyone in the room understands the second version.

Now the real outages. These are published incidents with published durations, chosen because each one broke authentication specifically rather than a service that merely happened to be hosted somewhere.

Date Service Down Trigger
15-16 Mar 2021 Azure AD 14 h 25 m signing key removed
4 Oct 2021 Facebook Login about 6 h route withdrawal
12 Jun 2025 Google Cloud IAM 3 h invalid quota update
19-20 Oct 2025 AWS us-east-1 15 h 12 m DNS race condition

The Azure Active Directory incident ran from approximately 19:00 UTC on 15 March 2021 to 09:25 UTC on 16 March. Microsoft’s published summary attributes it to an automated key rotation process that removed a signing key which had been deliberately marked to be retained during a cross-cloud migration; once the public metadata changed, relying applications stopped trusting tokens signed with that key. Microsoft noted that its backup authentication path covered token issuance but not token validation, and referred to a related incident on 28 September 2020 as being in the same class of risk.

The Google Cloud incident of 12 June 2025 began at 10:49 and ended at 13:49 US Pacific time, three hours, global in scope. Google’s own mini incident report attributes it to an invalid automated quota update distributed globally to its API management system, causing external API requests to be rejected; the list of affected products includes Identity and Access Management and Identity Platform. Most regions recovered within two hours; one region took longer because its quota policy database became overloaded during recovery.

The Amazon Web Services incident began at 11:49 pm US Pacific time on 19 October 2025 and all services were confirmed normal by 3:01 pm on 20 October, a total of fifteen hours and twelve minutes. AWS attributes the trigger to a latent race condition in the automated DNS management system for DynamoDB in the us-east-1 region. The identity-relevant detail is in AWS’s own status updates: global services and features that rely on us-east-1 endpoints, explicitly including IAM updates, were affected. A control plane that is global in name can still have a regional dependency, and you will discover which on the day.

For Whitfield those durations price out as follows, at 297.26 pounds a minute of exposed revenue: three hours is 53,507 pounds; fourteen hours and twenty-five minutes is 257,130 pounds; fifteen hours and twelve minutes is 271,101 pounds. Not all exposed revenue is lost revenue - some customers return the next day - but the deferral rate is itself a number you should measure rather than assume, and the portion that never returns is the portion that funds the redundancy work.

Three design conclusions follow, and they are cheap.

First, separate token issuance from token validation in your availability model, because the March 2021 incident shows they can fail independently and a backup for one is not a backup for the other. Cache the provider’s signing key metadata with a long fallback and treat a metadata fetch failure as “keep using the last known good set”, not “distrust everything”.

Second, decide in advance what a degraded mode looks like and write it down before you need it. For a retailer, that is guest checkout with a payment authorization and no account. For a hospital, it is a break-glass path with heavy logging. A degraded mode invented during an incident is invented badly.

Third, if you federate to one external provider, its availability becomes a hard ceiling on yours and you cannot buy your way past it. That is not an argument against federating. It is an argument for knowing the number, writing it into your own service level objective, and telling the people who depend on you.

Support cost per authentication method#

Authentication has two costs: what it costs every time somebody uses it, and what it costs the one time they cannot. The second dominates, and it is the one left out of comparisons.

The most-cited figure in the industry is that a single help desk password reset costs about 70 US dollars in labour, attributed to Forrester Research, alongside a Gartner estimate that password resets account for somewhere between 20 and 50 per cent of all help desk call volume, sometimes quoted as 40 per cent. Both circulate everywhere and both are worth using with a caution stated openly: the 70 dollar figure is repeated far more often than it is sourced to a dated primary publication, and it describes a corporate IT help desk handling an employee, not a consumer contact centre. [UNVERIFIED: the original dated Forrester Research publication behind the widely-quoted 70 US dollar per-reset figure] Use it for workforce, model your own for consumers.

Per-use costs can be taken from published list prices. As of August 2026, Twilio’s published Verify pricing is 0.0583 US dollars per SMS verification, 0.0534 for WhatsApp, and 0.05 for voice, email, push, time-based one-time password and silent network authentication, with carrier fees additional on top.

Method Per verification Recovery path
Password about zero reset link, then agent
SMS code 0.0583 US dollars new number, then agent
Voice code 0.05 US dollars as for SMS
Email code 0.05 US dollars mailbox recovery first
Push approval 0.05 US dollars re-enrol the device
App-based code 0.05 US dollars backup codes, then agent
Passkey about zero second passkey, then agent

Read that table with the recovery column first. The two methods with a per-use cost of about zero are the two whose recovery path is the most dangerous, because the fallback is an agent making a judgement, which is the single weakest link in almost every organization. The methods with a five cent per-use cost are buying you a recovery path that does not route through a human. Whether that is good value depends entirely on your volumes, and you can compute it.

Whitfield’s numbers, with the example’s own volumetrics. Of 640,000 monthly sign-ins, 35 per cent require a text message code, which is 224,000 messages a month at 0.0583 US dollars, or 13,059 US dollars a month, about 157,000 US dollars a year at list price before carrier fees. Password resets run at 21,000 a month, of which 20,300 complete through the self-service email link and 700 reach an agent. At six minutes per contact and a fully loaded agent cost of 46 pounds an hour, that is 4.60 pounds per contact, 3,220 pounds a month, 38,640 pounds a year. Separately, Whitfield’s 900 staff generate the example’s own 1.9 password resets each per year through the corporate help desk; 1,710 resets at the Forrester figure of 70 US dollars is 119,700 US dollars a year for a population one two-thousand-six-hundredth the size of the customer base.

Two additional cost lines belong here and are usually discovered by surprise.

The first is artificially inflated traffic, also called SMS pumping. Fraudsters submit large volumes of telephone numbers on a range controlled by a cooperating mobile network operator, harvest the revenue share from the delivered messages, and leave the organization with the bill. Twilio documents the pattern explicitly in its own help material. The exposure is unbounded on any unauthenticated form that triggers an outbound message, and the standard controls are rate limits per address and per number range, geographic allow lists, and a delivery-cost alarm rather than a message-count alarm.

The second is the enrolment cost of a stronger method. Passkeys have a per-use cost of about zero and a per-user enrolment cost that is not zero, because somebody has to be persuaded to create one, and because a user with exactly one passkey on exactly one device has converted a password problem into a device-loss problem. The rule is that a passkey deployment is not finished until the median user has two, on two devices, and until the recovery path for a user with zero has been designed and priced like any other authentication method.

The accessibility failures that are also identity failures#

An authentication screen that a person cannot operate is a false reject with a legal name. The relevant normative text is the Web Content Accessibility Guidelines version 2.2, a W3C Recommendation of 5 October 2023, republished as an updated Recommendation on 12 December 2024, and three of its success criteria bear directly on login design.

Success criterion 3.3.8, Accessible Authentication (Minimum), is Level AA, which is the level nearly all public procurement and most disability legislation points at. It requires that a cognitive function test is not required for any step in an authentication process unless that step also provides at least one of four things: an alternative authentication method that does not rely on a cognitive function test; a mechanism to assist the user in completing it; a test that consists of recognizing objects; or a test that consists of identifying non-text content the user themselves provided.

Success criterion 3.3.9, Accessible Authentication (Enhanced), is Level AAA and is the same requirement with the last two escape routes removed: only an alternative or an assisting mechanism will do.

The definition of a cognitive function test is the load-bearing part. WCAG 2.2 defines it as a task that requires the user to remember, manipulate or transcribe information, and gives as examples memorization of a username, password, character set, image or pattern; transcription, such as typing in characters; correct spelling; performing calculations; and solving puzzles. It adds, importantly, that name, email address and telephone number are not cognitive function tests, because they are personal to the user and consistent across sites.

Apply that definition honestly to a normal login page and the consequences are immediate. Requiring a password is a cognitive function test, so a conforming page must permit an assisting mechanism, which in practice means it must work with a password manager: fields must accept paste, must carry correct autocomplete attributes, and must not fragment the input. A one-time code that the user must read from one device and type into another is transcription, so it is a cognitive function test, and it needs an alternative or a mechanism such as platform autofill of the code. A puzzle-based CAPTCHA is explicitly a cognitive function test and has no escape route other than object recognition, which most implementations fail because they distort the objects deliberately. A memorable-word challenge asking for the third and seventh characters is transcription plus manipulation and defeats every password manager in existence, which is why it fails both this criterion and, incidentally, most modern security guidance.

Success criterion 3.3.7, Redundant Entry, is Level A, the base level, and forbids requiring information already entered in the same process to be entered again, unless re-entering it is essential, is required for the security of the content, or the earlier information is no longer valid. Multi-step verification flows breach this constantly by asking for the same address three times.

Success criterion 2.2.1, Timing Adjustable, is also Level A and is the one that catches one-time codes. If a code expires in sixty seconds and the user cannot turn off, adjust or extend that limit, the flow needs to satisfy one of the criterion’s exceptions to conform. Anyone using a screen reader, a switch device, or a magnifier is slower than the person who chose sixty seconds, and so is anyone who has to fetch a second device from another room.

How common are the underlying failures. The WebAIM Million analysis of the top one million home pages, in its 2026 edition, found detected WCAG 2 failures on 95.9 per cent of them, up from 94.8 per cent in 2025 and down from 97.8 per cent when the survey began in 2019. Because only automatically detectable failures were counted, the true conformance rate is certainly lower than the 4.1 per cent implied.

Detected failure, 2026 Home pages
Low contrast text 83.9 per cent
Missing image alt text 53.1 per cent
Missing form input labels 51 per cent
Empty links 46.3 per cent
Empty buttons 30.6 per cent
Missing document language 13.5 per cent

Look at rows three and five. Missing form input labels on 51 per cent of home pages, and empty buttons on 30.6 per cent, are not general web hygiene problems. They are exactly the two defects that make a login form unusable with a screen reader: a field the user cannot identify and a submit control that announces nothing. On this evidence, roughly half the web’s front doors cannot be operated by a blind user without guessing.

The cost line is straightforward. Every person who cannot operate the login is a permanent false reject, and if the login is the only route to the service, they are excluded rather than merely rejected. In jurisdictions with enforceable accessibility duties this is also a legal exposure, which chapter 57 covers. But the reason to fix it is not the legal exposure. It is that the design that satisfies 3.3.8 - passkeys, password manager support, autofilled codes, no puzzles - is also the design with the lowest fraud rate and the lowest support cost. This is the one place in the entire subject where the accessible option, the secure option and the cheap option are the same option, and it is remarkable how rarely anybody says so.

One year on one page#

Here is Whitfield and Company’s whole identity cost, at 2.4 million accounts and 156.24 million pounds of revenue, for one year. Every figure is either derived above or labelled as the example’s own.

Line Per year Borne by
False accept, fraud loss 636,000 pounds Whitfield
False reject, lost orders 1,331,760 pounds Whitfield
Downtime at 99.9 per cent 156,240 pounds Whitfield
Leak, expected value 146,400 pounds Whitfield
Reset support, customers 38,640 pounds Whitfield
Exclusion, if SMS mandated 3.0 m pounds the excluded

Four observations, and they are the chapter in miniature.

The first is that the false reject line is more than twice the false accept line, and it is the line that has never had a project. Whitfield has a fraud team. It has no abandonment team.

The second is that the largest number on the page is the one that is conditional, sits outside the company, and is not currently being incurred at all. It becomes real the moment a proposal that looks like a security improvement is approved. The only defence against that is putting the line on the page before the decision, not after.

The third is that the leak line is small in expectation and catastrophic in realization, which is the standard shape of a tail risk and the standard reason it is under-funded. An expected value of 146,400 pounds a year does not justify much. A one-in-twenty-five chance of a 3.66 million pound event, in a year when three of your competitors have one, justifies rather more, and the honest way to present it is both numbers side by side.

The fourth is what is missing. There is no line for the time customers spend recovering from fraud, which Javelin measures at an average of 10.4 hours per victim in 2025 and 17 hours for account takeover victims. There is no line for the anxiety of a person whose genetic data is in the world. There is no line for the pensioner who stops using the service. These are real costs of the system Whitfield operates and they appear nowhere in Whitfield’s accounts, because Whitfield’s accounts are an instrument for measuring Whitfield.

Making the invisible costs visible#

You cannot manage what nobody measures, and four of the five failures produce no natural measurement. Chapter 59 sets out the operational metrics an identity system must emit; the concern here is narrower and different, which is how to make a cost that lands outside the organization appear inside its reporting. Four instruments do most of the work, and all four are cheap.

The first is a completion rate measured over intents rather than attempts. Instrument the intent - the tap on “sign in”, the arrival on the checkout page - and count the sessions that reach a live session divided by the intents, not by the attempts. An attempt-based denominator hides everyone who gave up before attempting; an intent-based one does not.

The second is segmentation by population, always, with the segments fixed in advance. Success rate by authentication method, by device class, by account age, by assisted versus self-service channel, and by any accessibility-relevant proxy you can lawfully hold. An aggregate that is green while one segment is at 60 per cent is not a measurement, it is a disguise.

The third is a return-rate instrument. For every user whose sign-in failed, look thirty days ahead and record whether they came back. This single measurement converts the invisible half of the false reject cost into a number, and it needs nothing but an identifier and a date.

The fourth is an external denominator for exclusion. Pick the population you believe you should be serving, obtain its size from a source outside your own logs - a census, a customer file, a membership list, a benefits roll - and report coverage against it. This is the only one of the four that cannot be computed from your own telemetry, and it is the only one that can detect the failure that generates no events at all.

  Metric                 Denominator      Detects
  ---------------------  ---------------  ------------------
  attempt success rate   attempts         matching errors
  intent completion      intents          give-ups
  30-day return rate     failed users     churn from reject
  coverage vs external   outside source   exclusion

Write a threshold next to each one and an owner beside the threshold. A metric with no threshold is a decoration; a threshold with no owner is a wish.

Identity as infrastructure, and the duty that follows#

There is a moment in the life of every identity system when it changes category, and the moment is never announced.

Before it, the system is a product. People choose it, they can leave it, and if it is bad they use something else. After it, the system is infrastructure: enough other things depend on being able to prove who you are through this particular door that the door is no longer optional. A bank account requires it. A prescription requires it. A wage requires it. A landlord requires it. At that point the ordinary defences of a market - choice, exit, competition - have all quietly stopped working, and the only thing standing between the system and the people inside it is how the system chooses to behave.

Every failure in this chapter changes character at that moment, and it changes in the same direction.

A false accept in a product is a loss. A false accept in infrastructure is a person whose life is being lived by somebody else, at scale, with no natural end point, because the credential cannot be reissued and the fraud follows them between organizations.

A false reject in a product is an abandoned basket. A false reject in infrastructure is a missed medication, a missed shift, a missed benefit payment on the day it was needed.

Exclusion in a product is a lost customer. Exclusion in infrastructure is exclusion from society, and the World Bank’s 800 million is a count of people to whom that has already happened.

A leak from a product is embarrassing. A leak from infrastructure is a permanent change in the conditions under which several hundred million people will have to prove who they are for the rest of their lives.

A lock-out from a product is an inconvenience. A lock-out from infrastructure is a person standing outside their own life with no procedure that will let them back in.

If that transition is real, and this book has spent fifty-nine chapters showing that it is, then four duties follow, and they are duties rather than best practices because the people affected have no exit.

The duty of continuity. If people cannot function without you, your availability target is a public commitment, not an internal aspiration, and it must include a written degraded mode that works when you do not. Publish the number. Publish the incidents. Publish the durations. Every provider quoted in this chapter did, and that is why it was possible to write this chapter at all.

The duty of universality. If you are the way people prove who they are, then a person you cannot serve is a person you have removed from the activity, and it is your obligation and nobody else’s to find them, count them, and build the other route. Coverage measured against an external denominator is not a nice-to-have; it is the only evidence that this duty is being discharged.

The duty of proportion. Collect the least that answers the question, keep it for the shortest period that serves the purpose, and remember when you are choosing what to collect that tier three data - the biometric, the genome, the family tree - imposes a cost on the individual that no fine can compensate and no remediation can undo. The organization’s exposure ends with the fine. The person’s does not.

The duty of exit. Anyone who can be enrolled must be able to leave, to correct what is held about them, to be told what was disclosed and when, and to obtain a decision made by a human being when the machine says no. A system that has become compulsory and has no appeal is not an identity system. It is a gate with a permanent lock, and somebody is standing on the wrong side of it right now.

Those four are the whole argument of this book, arrived at from the direction of cost rather than the direction of principle, which is the direction that persuades people who control budgets. Identity is not a feature. It is the mechanism by which a society decides who counts. Build it as though the person it fails will be someone you know, because at the scale these systems now operate, they will be.

60.98 Common wrong ideas#

Wrong: A secure identity system is one with a very low false accept rate. Right: An error rate is not a property of a system but of a system, an operating point and a population taken together, and any false accept target can be met by refusing everybody. A requirement is only complete when it states the false accept rate, the false reject rate you accept at that same threshold, and the population the measurement was taken on - and when it names the group with the worst rate, since NISTIR 8280 of December 2019 found demographic differentials in false positives of factors of ten to beyond a hundred at a single setting.

Wrong: Tightening the rules reduces fraud, and the only cost is a little user inconvenience. Right: Tightening moves you along one curve, so the reduction in false accepts is bought with a specific, countable increase in false rejects and, at the extreme, with permanent exclusion of people who can never satisfy the new rule. In the worked example in this chapter the false reject cost is over twice the fraud cost before any tightening at all. Better evidence moves the whole curve toward the origin and is a different project with a different budget.

Wrong: We know what a breach costs, because the industry average is published every year. Right: The IBM and Ponemon global average of 4.99 million US dollars in the 2026 report is the mean of a very wide, skewed distribution over 602 sampled organizations, with healthcare at 6.64 million and financial services at 6.29 million, and with breaches over 200 days in duration averaging 5.65 million against 4.32 million for shorter ones. Model your own exposure from your own record count, your own statutory maximum, and your own notification cost per person.

Wrong: The regulator will fine us four per cent of turnover, so that is the number to plan against. Right: Four per cent of worldwide turnover, or 17.5 million pounds in the United Kingdom and 20 million euros in the European Union, is the statutory ceiling, and observed penalties sit far below it: British Airways paid 20 million pounds against a notice of intent of 183.39 million, Marriott 18.4 million against 99.2 million, and 23andMe 2.31 million against a preliminary 4.59 million. Plan against remediation cost, which is arithmetic you can do today, and treat the fine as a distribution.

Wrong: Our identity provider publishes 99.99 per cent availability, so our sign-in is 99.99 per cent available. Right: Your availability is that of the whole path from the user to a live session, which is a product of every dependency including the mobile network carrying the code, and it is always lower than the best term. The Azure Active Directory failure of 15 and 16 March 2021 also showed that a backup can share an assumption with the primary: Microsoft’s backup authentication covered token issuance while the failure was in token validation, so it did not help.

Wrong: Passwords are free, so they are the cheapest method to run. Right: Passwords have a per-use cost of about zero and by far the most expensive recovery path, since the fallback is a human agent making a judgement - the widely-quoted Forrester figure is about 70 US dollars of labour per corporate help desk reset, with Gartner putting password resets at 20 to 50 per cent of help desk volume. Methods costing about five US cents a use, at Twilio’s published August 2026 Verify prices, are buying a recovery path that does not route through a person who can be socially engineered.

Wrong: Requiring a text-message code is a security improvement with no downside. Right: It is simultaneously a fraud control and an exclusion control, and everyone without a working mobile number is removed from the service by it. It also creates an unbounded cost exposure through artificially inflated traffic, in which fraudsters harvest revenue share by pumping one-time-code requests at numbers they control. Both effects must appear in the same paper as the fraud reduction.

Wrong: Accessibility is a compliance matter to be handled after launch by a separate team. Right: An authentication screen that a person cannot operate is a permanent false reject, and WCAG 2.2 success criterion 3.3.8 at Level AA prohibits requiring a cognitive function test - which by its own definition includes remembering a password, transcribing a code and solving a puzzle - without an alternative or an assisting mechanism. On the WebAIM Million 2026 figures, 51 per cent of the top million home pages have unlabelled form inputs, so roughly half the web’s front doors cannot be operated with a screen reader.

Wrong: Our sign-in success rate is rising, so the system is getting better. Right: Every standard identity metric has attempts or submissions in the denominator, so it rises automatically when the people most likely to fail stop trying. Exclusion is structurally invisible to it. Detecting exclusion requires a denominator obtained from outside your own logs, compared against the population you believe you should be serving, which is how the World Bank arrives at approximately 800 million people with no official proof of identity.

Wrong: Once we have fixed the login, the identity system is safe. Right: The assurance of a system is the minimum over every path to a live session, and the recovery path always has the weakest evidence, which is why lock-out handling and not authentication is the most reliable route into a large organization. The September 2023 intrusion at MGM Resorts International, reported at an approximately 100 million US dollar impact in one quarter, began with a social engineering call to an IT help desk.

60.99 Chapter summary in 20 lines#

  1. Identity systems fail in exactly five ways - false accept, false reject, exclusion, leak and lock-out - and every real incident is one of those or a chain running through several of them.
  2. A false accept and a false reject are two readings of one threshold on one curve, so tightening one necessarily loosens the other, and only better evidence moves the whole curve toward the origin.
  3. An error rate is a property of a system, an operating point and a population together, and NISTIR 8280 of 19 December 2019 found false positive differentials across demographic groups of factors of ten to beyond a hundred at a single setting.
  4. False accept costs are visible and get funded, while false reject and exclusion costs land outside the organization where nothing measures them, so systems drift toward refusing people because refusing is free to the party deciding.
  5. Per-incident fraud figures from the FBI Internet Crime Complaint Center 2025 report range from 1,127 US dollars for a phishing complaint to 123,004 US dollars for a business email compromise, over 1,008,597 complaints and about 20.9 billion US dollars of reported loss.
  6. Javelin’s 2026 Identity Fraud Study, published 21 April 2026, reports 27.3 billion US dollars of traditional identity fraud losses in 2025 across 18 million victims, with account takeover victims rising 18 per cent to 6 million.
  7. The cost of a false accept that nobody bills is the victim’s time: Javelin measures an average of 10.4 hours to resolve identity fraud in 2025 and 17 hours for account takeover victims.
  8. Baymard Institute’s aggregate of 50 studies gives an average documented cart abandonment rate of 70.22 per cent as of 22 September 2025, and its 2026 survey of 1,083 United States shoppers finds 18 per cent reporting they abandoned a purchase because the site required an account.
  9. Microsoft reports passkey sign-ins succeeding about 98 per cent of the time against about 32 per cent for passwords, three times faster than a password and eight times faster than a password plus traditional multi-factor authentication.
  10. Exclusion is caused by enumerable design assumptions - device, network, document, name model, address model, biometric, credit file, capacity, language and cost - and is fixed by removing assumptions rather than by adjusting thresholds.
  11. The World Bank ID4D Global Dataset published in 2025 estimates approximately 800 million people with no official proof of identity, down from about 850 million in 2021, and at least 2.8 billion with no government-recognized digital identity for online transactions.
  12. India’s Public Accounts Committee took evidence on 18 July 2025 that Aadhaar biometric verification failures were blocking eligible people from subsidized rations and rural employment, citing worn fingerprints and changed iris patterns, and directed UIDAI to produce an action plan within six weeks.
  13. A leak is billed in four currencies - the regulatory fine, the remediation bill, the disruption cost, and the permanent harm to the individual - and only the first three ever appear in an average.
  14. Statutory maxima are not outcomes: British Airways paid 20 million pounds against a 183.39 million pound notice of intent, Marriott 18.4 million against 99.2 million, and 23andMe 2.31 million on 17 June 2025 for failings that were explicitly authentication design failings.
  15. The IBM and Ponemon Cost of a Data Breach Report 2026, published 29 July 2026 over 602 breached organizations, gives a record global average of 4.99 million US dollars, a mean time to identify and contain of 247 days, and 5.65 million for breaches lasting over 200 days against 4.32 million for shorter ones.
  16. Availability converts to money by dividing revenue by minutes, and at a constant revenue rate a downtime allowance of X per cent costs exactly X per cent of revenue.
  17. Real identity outages are long: Azure Active Directory was unavailable for fourteen hours and twenty-five minutes across 15 and 16 March 2021 after an automated process removed a signing key marked to be retained, Google Cloud’s Identity and Access Management was affected for three hours on 12 June 2025, and the AWS us-east-1 event of 19 and 20 October 2025 ran fifteen hours and twelve minutes and affected IAM updates globally.
  18. Support cost is dominated not by the per-use price of a method but by its recovery path, which is why the two methods costing about nothing per use - passwords and passkeys - both fall back to a human agent who can be socially engineered.
  19. WCAG 2.2, a W3C Recommendation of 5 October 2023 updated on 12 December 2024, prohibits at Level AA under success criterion 3.3.8 any cognitive function test in authentication without an alternative or an assisting mechanism, and the WebAIM Million 2026 report finds 95.9 per cent of the top million home pages with detected WCAG 2 failures including unlabelled form inputs on 51 per cent.
  20. Once enough of life depends on proving who you are through one door, that door is infrastructure rather than a product, and four duties follow that no market discipline will supply - continuity, universality, proportion and exit.

Chapter sources: IBM Security and Ponemon Institute, Cost of a Data Breach Report 2026, published 29 July 2026, covering 602 organizations breached between March 2025 and February 2026, for the global average of 4.99 million US dollars, the twelve per cent year-on-year increase, healthcare at 6.64 million for the thirteenth consecutive year, financial services at 6.29 million, ransomware at 39 per cent of reported incidents, a mean time to identify and contain of 247 days, and lifecycle costs of 5.65 million over 200 days against 4.32 million under, together with the Cost of a Data Breach Report 2025 for the prior global average of 4.44 million US dollars and the United States average of 10.22 million; Baymard Institute, 50 Cart Abandonment Rate Statistics, average of 70.22 per cent across 50 studies, last updated 22 September 2025, and the accompanying 2026 quantitative survey of 1,083 United States adults for the abandonment reasons of 42 per cent browsing, 40 per cent extra costs, 19 per cent card distrust, 18 per cent forced account creation and 17 per cent complicated checkout, together with Baymard’s figure of 23.48 default checkout form elements; Federal Bureau of Investigation Internet Crime Complaint Center, 2025 Internet Crime Report, for 1,008,597 complaints, about 20.9 billion US dollars of reported losses, and the per-category complaint and loss figures for business email compromise, personal data breach, identity theft, and phishing and spoofing; Javelin Strategy and Research, 2026 Identity Fraud Study: The Illusion of Progress, published 21 April 2026 from an online survey of 5,010 United States adults conducted 10 November to 3 December 2025, for 27.3 billion US dollars of traditional identity fraud loss across 18 million victims, account takeover victims rising 18 per cent from 5.1 million to 6 million, new-account fraud victims rising 31 per cent from 4.2 million to 5.4 million, and resolution times of 10.4 hours on average, 17 hours for account takeover and 17.8 hours for new-account fraud; Federal Trade Commission Consumer Sentinel Network Data Book 2024, published March 2025, for 6,471,708 total reports, 1,135,291 identity theft reports and more than 12.5 billion US dollars of reported fraud loss in 2024; NIST Interagency Report 8280, Face Recognition Vendor Test Part 3: Demographic Effects, 19 December 2019, for false positive differentials of factors of ten to beyond one hundred; ISO/IEC 2382-37 for the biometric vocabulary of false match rate, false non-match rate, failure to enrol and failure to acquire; World Bank Identification for Development Global Dataset 2025 for approximately 800 million people without official proof of identity, down from about 850 million in 2021 and just over one billion in 2017, and at least 2.8 billion without a government-recognized online digital identity, down from 3.3 billion in 2021; the Public Accounts Committee of the Parliament of India, evidence session reported 18 July 2025, chaired by K. C. Venugopal, examining the Comptroller and Auditor General report of 2021 on the Unique Identification Authority of India; Microsoft, Azure status history and the Microsoft Q and A summary of tracking identifier LN01-P8Z, for the Azure Active Directory authentication outage from approximately 19:00 UTC on 15 March 2021 to 09:25 UTC on 16 March 2021, its signing key rotation root cause, and the note that backup authentication covered issuance but not validation, with the related incident of 28 September 2020; Google Cloud Service Health incident ow5i3PPK96RduMcb1SsW and its mini incident report of 12 June 2025, for the incident start at 10:49 and end at 13:49 US Pacific, the three-hour duration, the invalid automated quota update to the API management system, and the affected products including Identity and Access Management and Identity Platform; the AWS Health Dashboard record and post-event summary for the us-east-1 event beginning 11:49 pm US Pacific on 19 October 2025 and confirmed recovered at 3:01 pm on 20 October 2025, attributed to a latent race condition in DynamoDB DNS management, with global features including IAM updates affected; Information Commissioner’s Office monetary penalty notices for British Airways of 16 October 2020 at 20 million pounds against a notice of intent of 183.39 million issued July 2019, for Marriott International of 30 October 2020 at 18.4 million pounds against a notice of intent of 99.2 million, and for 23andMe of 17 June 2025 at 2.31 million pounds against a preliminary 4.59 million, the last following a joint investigation with the Office of the Privacy Commissioner of Canada into a credential stuffing attack running April to September 2023 affecting 155,592 United Kingdom residents; Article 83(5) of Regulation (EU) 2016/679 and the corresponding retained United Kingdom provision for the 20 million euro, 17.5 million pound and four per cent of worldwide turnover maxima; MGM Resorts International securities filings for the approximately 100 million US dollar third-quarter 2023 impact comprising about 84 million of lost revenue and about 10 million of one-off costs, with Caesars Entertainment reported to have paid about 15 million US dollars; UnitedHealth Group quarterly reporting for the Change Healthcare intrusion of February 2024, entered through a Citrix remote access service with valid credentials and no multi-factor authentication, with 1.521 billion US dollars of direct response costs in the nine months to 30 September 2024 and total 2024 impacts revised to approximately 2.87 billion, and a victim count of about 190 million reported in January 2025 and revised to 192.7 million in August 2025; Twilio published Verify list pricing as of August 2026 at 0.0583 US dollars per SMS verification, 0.0534 for WhatsApp and 0.05 for voice, email, push, time-based one-time password and silent network authentication, with carrier fees additional, together with Twilio’s own documentation of SMS traffic pumping and artificially inflated traffic; the widely-circulated Forrester Research estimate of about 70 US dollars of labour per help desk password reset and the Gartner estimate that password resets account for 20 to 50 per cent of help desk call volume, both used here as secondary attributions; Microsoft Security blog posts of 12 December 2024 and 1 May 2025 for passkey sign-in success of about 98 per cent against about 32 per cent for passwords, three times faster than a password and eight times faster than password plus multi-factor authentication; W3C Web Content Accessibility Guidelines 2.2, Recommendation of 5 October 2023 and updated Recommendation of 12 December 2024, success criteria 3.3.7 Redundant Entry at Level A, 3.3.8 Accessible Authentication (Minimum) at Level AA, 3.3.9 Accessible Authentication (Enhanced) at Level AAA, 2.2.1 Timing Adjustable at Level A, and the normative definition of a cognitive function test; WebAIM, The WebAIM Million, 2026 report on the accessibility of the top 1,000,000 home pages, for 95.9 per cent with detected WCAG 2 failures against 94.8 per cent in 2025 and 97.8 per cent in 2019, low contrast text at 83.9 per cent, missing image alternative text at 53.1 per cent, missing form input labels at 51 per cent, empty links at 46.3 per cent, empty buttons at 30.6 per cent and missing document language at 13.5 per cent; and the author’s own operating experience at KedByte Technologies Private Limited, marked as such in the text, for the five-failure taxonomy as presented, the Whitfield and Company worked example and every figure labelled as the example’s own, the four measurement instruments, and the four duties set out in the closing argument.