Your access tool is a vendor with a copy of your infrastructure map
Disclosure: I work on Tessera, which is self-hosted. That is the position I am arguing from, and the costs of that position are in the last section. Security questionnaires ask where customer data is processed. Access-control tools tend to get a shallow answer to that question, because people think of them as gatekeepers rather than as data processors. They are both. Here is what a hosted access…
Your access tool is essentially a vendor that holds a copy of your infrastructure map. Security questionnaires often ask where customer data is processed, but access-control tools tend to receive a cursory answer, as they are perceived as merely gatekeepers rather than data processors. However, they serve both roles. A hosted access broker possesses comprehensive knowledge about your infrastructure, including your infrastructure inventory (such as hostnames, addresses, cluster endpoints, database names, and environment labels), your organizational structure (including access rights and approval processes), session content (such as commands, queries, and output), and timing (such as incident occurrences and escalation procedures).
This information is crucial for an attacker, as it provides a detailed map of your estate, enabling them to determine where to focus their efforts.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.