Our recent informal LinkedIn poll together with a lively Bletchley Park dinner discussion among cybersecurity leaders, led by Sir Dermot Turing, revealed some fascinating details around the challenges associated with Identity. We wanted to share the insights we gathered with you.
In summary we have learned:
- According to CrowdStrike’s Global Threat Report of 2024, in 75% of cases, recent detections were malware-free. This means that traditional signature-based A/V tools would have missed detecting them. We need to use ML at the host to analyse behaviour and stop threat actors before they move laterally.
- Because so many breaches are performed using stolen credentials, it is difficult to spot because it looks like a legitimate user logging in.
- Service Accounts are a real problem. No proper naming convention; people create them and then leave the organisation; no one wants to delete them in case they are used for something important.
- The enemy is not just outside but can be inside. Employment checks can stop some of this.
- It is easy to get hold of lists of stolen credentials for nefarious use.
- One vendor collected an incredible 20 billion username/password pairs from stolen data that was then used to inform organisations of possible issues.
- PAM is not enough. What about non-privileged accounts? If >70% of breaches were perpetrated using a regular user’s stolen credentials, we need to be looking at normal users.
- We need to monitor baseline behaviour and quickly spot and stop anomalous behaviour. Some false positives are better than a breach.
- Is there a better way to identify people than by using a username and password?
Do these resonate with your experience? We would very much like to hear about the challenges you are seeing – do get in touch and register your interest in our next discussion event here.
