Urgent.News

the world's headlines, one feed

Editions

Tech

Identity and attack paths - can you stop hackers getting from A to B?

Attackers use identities to get across networks. How can you secure those identity attack paths first?

Identity and attack paths - can you stop hackers getting from A to B?

Identity management has become a critical aspect of cybersecurity in recent years. While traditional security measures focused on preventing unauthorized access, the primary risk now lies in how long threat actors can remain undetected and the extent of damage they can cause within a network. Attackers exploit the complexity of managing identities and credentials, which are used extensively to facilitate access, provisioning, and software deployment. Simple tokens that provide access and permissions are often targeted by hackers.

To counter this threat, organizations must understand attack paths and prioritize resolving the associated issues. Attackers typically gain initial access through vulnerabilities or phishing emails, then move laterally to valuable assets, exploiting the same identities used by legitimate staff. The sheer complexity of modern networks, with millions of potential attack paths, makes it challenging to identify and address all vulnerabilities.

This complexity is set to increase with the adoption of Artificial Intelligence (AI) and Non-Human Identities, which will lead to a surge in identities per employee, reaching up to 20 or 40 in the near future. This exponential growth will further complicate the task of managing and securing identities.

To effectively defend against these threats, organizations should focus on understanding and securing their most critical assets. Visualizing attack paths and permissions can help identify high-value targets, akin to securing busy transport hubs in a city like London. By fortifying these key points, organizations can limit the number of potential attack routes and reduce the risk of data breaches.

Once these crucial hubs are secured, defenders can progress to address the next major points of vulnerability. This strategy significantly reduces the overall number of attack paths, streamlining the security process and minimizing the chances of successful breaches. Ultimately, managing identities and access permissions effectively is essential to maintaining a robust cybersecurity posture in the face of evolving threats.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech

Terms and Policies

  • CNBC+ offers limited, non-exclusive license to access and use services.
  • Content quality varies based on format, location, internet bandwidth, device.
  • Commercial use prohibited; automatic ad blocking and recording restricted.