[{"data":1,"prerenderedAt":568},["ShallowReactive",2],{"\u002Fblog\u002Fevaluating-identity-before-attackers-do":3,"blog-all-posts":492},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"titleLines":10,"descriptionLines":13,"bodyLeadTitle":16,"publishedAt":17,"updatedAt":18,"tags":19,"coverImage":23,"coverAlt":24,"heroLayout":25,"heroTitleSize":26,"featured":6,"draft":6,"body":27,"_type":486,"_id":487,"_source":488,"_file":489,"_stem":490,"_extension":491},"\u002Fblog\u002Fevaluating-identity-before-attackers-do","blog",false,"","Evaluating Identity Before Attackers Do","An IAM assessment evaluates authentication, access controls, user behavior, and identity resilience before attackers can exploit them.",[11,12],"Evaluating Identity","Before Attackers Do",[14,15],"Modern attackers don't break in,","they log in.","The New Security Perimeter","2026-06-07","2026-06-20",[20,21,22],"identity security","IAM assessment","access management","\u002Fblog\u002Fevaluating-identity-before-attackers-do\u002Fcover.jpg","Open cyber vault displaying identity security controls and authentication monitoring","overlay","compact",{"type":28,"children":29,"toc":474},"root",[30,38,43,48,55,68,77,82,87,102,107,113,118,124,129,134,140,145,151,156,161,166,189,194,199,204,232,237,243,248,257,262,267,272,277,282,310,315,321,326,331,336,341,369,374,379,385,390,395,448,453,459,464,469],{"type":31,"tag":32,"props":33,"children":34},"element","p",{},[35],{"type":36,"value":37},"text","For many organizations, Identity and Access Management (IAM) has become the new security perimeter. As businesses migrate applications to the cloud, adopt hybrid workforces, and enable remote access, user identities have become the primary target for cybercriminals.",{"type":31,"tag":32,"props":39,"children":40},{},[41],{"type":36,"value":42},"The login to your cloud is your new \"firewall\".",{"type":31,"tag":32,"props":44,"children":45},{},[46],{"type":36,"value":47},"While organizations often invest heavily in endpoint protection, firewalls, and vulnerability management, compromised credentials remain one of the leading causes of successful breaches. Modern attackers frequently bypass technical defenses altogether by simply logging in with valid credentials.",{"type":31,"tag":49,"props":50,"children":52},"h2",{"id":51},"walking-through-the-front-door",[53],{"type":36,"value":54},"Walking Through the Front Door",{"type":31,"tag":32,"props":56,"children":57},{},[58,60,66],{"type":36,"value":59},"FBI Special Agent John Hammond illustrated this in the FBI's ",{"type":31,"tag":61,"props":62,"children":63},"em",{},[64],{"type":36,"value":65},"Ahead of the Threat",{"type":36,"value":67}," podcast:",{"type":31,"tag":69,"props":70,"children":71},"blockquote",{},[72],{"type":31,"tag":32,"props":73,"children":74},{},[75],{"type":36,"value":76},"\"Attackers don't break in, they log in.\"",{"type":31,"tag":32,"props":78,"children":79},{},[80],{"type":36,"value":81},"He explained that this is because attackers increasingly use stolen credentials obtained through phishing, credential theft, or purchased from other criminals, rather than exploiting sophisticated technical vulnerabilities.",{"type":31,"tag":32,"props":83,"children":84},{},[85],{"type":36,"value":86},"This aligns with a broader point the FBI regularly makes:",{"type":31,"tag":88,"props":89,"children":90},"ul",{},[91,97],{"type":31,"tag":92,"props":93,"children":94},"li",{},[95],{"type":36,"value":96},"Many compromises begin with valid credentials that have been stolen or purchased.",{"type":31,"tag":92,"props":98,"children":99},{},[100],{"type":36,"value":101},"Initial access is often achieved through phishing, password reuse, infostealer malware, or compromised VPN\u002FRDP credentials rather than \"Hollywood-style hacking.\"",{"type":31,"tag":32,"props":103,"children":104},{},[105],{"type":36,"value":106},"Strong authentication (especially phishing-resistant MFA), least privilege, and credential protection are therefore among the most effective defenses.",{"type":31,"tag":49,"props":108,"children":110},{"id":109},"assessing-the-new-front-door",[111],{"type":36,"value":112},"Assessing the New \"Front Door\"",{"type":31,"tag":32,"props":114,"children":115},{},[116],{"type":36,"value":117},"A comprehensive IAM assessment evaluates whether an organization's identity controls can withstand real-world attack techniques. Rather than focusing solely on technical vulnerabilities, these assessments measure the resilience of authentication systems, password policies, user behavior, and security awareness.",{"type":31,"tag":49,"props":119,"children":121},{"id":120},"why-identity-has-become-the-primary-attack-surface",[122],{"type":36,"value":123},"Why Identity Has Become the Primary Attack Surface",{"type":31,"tag":32,"props":125,"children":126},{},[127],{"type":36,"value":128},"Attackers understand that exploiting software vulnerabilities can be difficult, time-consuming, and noisy. Stealing or guessing legitimate credentials is often much easier.",{"type":31,"tag":32,"props":130,"children":131},{},[132],{"type":36,"value":133},"Once an attacker successfully authenticates using valid credentials, many traditional security controls become significantly less effective. The activity often appears to be a normal user login, making detection substantially more difficult.",{"type":31,"tag":49,"props":135,"children":137},{"id":136},"addressing-the-iam-risk",[138],{"type":36,"value":139},"Addressing the IAM Risk",{"type":31,"tag":32,"props":141,"children":142},{},[143],{"type":36,"value":144},"This is why organizations should regularly evaluate the effectiveness of their identity security controls using controlled assessments that simulate the techniques employed by real-world adversaries.",{"type":31,"tag":49,"props":146,"children":148},{"id":147},"password-spraying",[149],{"type":36,"value":150},"Password Spraying",{"type":31,"tag":32,"props":152,"children":153},{},[154],{"type":36,"value":155},"Password spraying is one of the most common attacks used against enterprise authentication systems.",{"type":31,"tag":32,"props":157,"children":158},{},[159],{"type":36,"value":160},"Unlike traditional brute-force attacks, which repeatedly attempt many passwords against a single account, password spraying reverses the strategy. An attacker attempts a small number of commonly used passwords across a large number of user accounts.",{"type":31,"tag":32,"props":162,"children":163},{},[164],{"type":36,"value":165},"For example, an attacker might test passwords such as:",{"type":31,"tag":88,"props":167,"children":168},{},[169,174,179,184],{"type":31,"tag":92,"props":170,"children":171},{},[172],{"type":36,"value":173},"Spring2026!",{"type":31,"tag":92,"props":175,"children":176},{},[177],{"type":36,"value":178},"CompanyName123",{"type":31,"tag":92,"props":180,"children":181},{},[182],{"type":36,"value":183},"Welcome1",{"type":31,"tag":92,"props":185,"children":186},{},[187],{"type":36,"value":188},"Password123",{"type":31,"tag":32,"props":190,"children":191},{},[192],{"type":36,"value":193},"against hundreds or thousands of usernames.",{"type":31,"tag":32,"props":195,"children":196},{},[197],{"type":36,"value":198},"Because only one or two attempts are made against each account, password spraying often avoids account lockout thresholds and other brute-force protections.",{"type":31,"tag":32,"props":200,"children":201},{},[202],{"type":36,"value":203},"A comprehensive IAM assessment evaluates:",{"type":31,"tag":88,"props":205,"children":206},{},[207,212,217,222,227],{"type":31,"tag":92,"props":208,"children":209},{},[210],{"type":36,"value":211},"Password policy effectiveness",{"type":31,"tag":92,"props":213,"children":214},{},[215],{"type":36,"value":216},"Account lockout configurations",{"type":31,"tag":92,"props":218,"children":219},{},[220],{"type":36,"value":221},"Detection and alerting capabilities",{"type":31,"tag":92,"props":223,"children":224},{},[225],{"type":36,"value":226},"Multi-factor authentication enforcement",{"type":31,"tag":92,"props":228,"children":229},{},[230],{"type":36,"value":231},"Identity monitoring effectiveness",{"type":31,"tag":32,"props":233,"children":234},{},[235],{"type":36,"value":236},"The objective is to determine whether weak passwords or insufficient authentication controls could allow unauthorized access without triggering security alerts.",{"type":31,"tag":49,"props":238,"children":240},{"id":239},"credential-stuffing",[241],{"type":36,"value":242},"Credential Stuffing",{"type":31,"tag":32,"props":244,"children":245},{},[246],{"type":36,"value":247},"Credential stuffing has become increasingly successful due to one simple reality:",{"type":31,"tag":32,"props":249,"children":250},{},[251],{"type":31,"tag":252,"props":253,"children":254},"strong",{},[255],{"type":36,"value":256},"People reuse passwords.",{"type":31,"tag":32,"props":258,"children":259},{},[260],{"type":36,"value":261},"Every year, billions of usernames and passwords are exposed through breaches involving online retailers, social media platforms, forums, and cloud services. These credentials quickly become available on criminal marketplaces and underground forums.",{"type":31,"tag":32,"props":263,"children":264},{},[265],{"type":36,"value":266},"Attackers automate the process by taking known email\u002Fpassword combinations from previous breaches and attempting to authenticate against other organizations.",{"type":31,"tag":32,"props":268,"children":269},{},[270],{"type":36,"value":271},"Even if the organization itself has never experienced a breach, users who reuse passwords across multiple websites may unknowingly expose corporate accounts.",{"type":31,"tag":32,"props":273,"children":274},{},[275],{"type":36,"value":276},"A credential stuffing assessment determines whether previously compromised credentials could be used to access enterprise resources.",{"type":31,"tag":32,"props":278,"children":279},{},[280],{"type":36,"value":281},"Typical objectives include:",{"type":31,"tag":88,"props":283,"children":284},{},[285,290,295,300,305],{"type":31,"tag":92,"props":286,"children":287},{},[288],{"type":36,"value":289},"Identifying reused passwords",{"type":31,"tag":92,"props":291,"children":292},{},[293],{"type":36,"value":294},"Measuring password hygiene",{"type":31,"tag":92,"props":296,"children":297},{},[298],{"type":36,"value":299},"Validating MFA protections",{"type":31,"tag":92,"props":301,"children":302},{},[303],{"type":36,"value":304},"Testing authentication monitoring",{"type":31,"tag":92,"props":306,"children":307},{},[308],{"type":36,"value":309},"Evaluating account compromise detection",{"type":31,"tag":32,"props":311,"children":312},{},[313],{"type":36,"value":314},"Organizations are often surprised to discover that credentials leaked years earlier remain valid because users never changed their passwords or reused them across multiple systems.",{"type":31,"tag":49,"props":316,"children":318},{"id":317},"phishing-using-a-site-clone",[319],{"type":36,"value":320},"Phishing Using a Site Clone",{"type":31,"tag":32,"props":322,"children":323},{},[324],{"type":36,"value":325},"Technology alone cannot eliminate identity risk.",{"type":31,"tag":32,"props":327,"children":328},{},[329],{"type":36,"value":330},"Phishing remains one of the most effective methods for stealing credentials because it targets human behavior rather than technical vulnerabilities.",{"type":31,"tag":32,"props":332,"children":333},{},[334],{"type":36,"value":335},"In a controlled phishing assessment, users receive a realistic email designed to resemble legitimate organizational communication. The email directs recipients to a professionally cloned login page that closely mirrors the organization's actual authentication portal.",{"type":31,"tag":32,"props":337,"children":338},{},[339],{"type":36,"value":340},"The objective is not to collect production credentials for malicious purposes, but to evaluate:",{"type":31,"tag":88,"props":342,"children":343},{},[344,349,354,359,364],{"type":31,"tag":92,"props":345,"children":346},{},[347],{"type":36,"value":348},"User susceptibility to phishing",{"type":31,"tag":92,"props":350,"children":351},{},[352],{"type":36,"value":353},"Security awareness effectiveness",{"type":31,"tag":92,"props":355,"children":356},{},[357],{"type":36,"value":358},"Email security controls",{"type":31,"tag":92,"props":360,"children":361},{},[362],{"type":36,"value":363},"Authentication protections",{"type":31,"tag":92,"props":365,"children":366},{},[367],{"type":36,"value":368},"Incident reporting procedures",{"type":31,"tag":32,"props":370,"children":371},{},[372],{"type":36,"value":373},"Important to note: the new phishing attacks defeat MFA through the use of a malicious interception proxy.",{"type":31,"tag":32,"props":375,"children":376},{},[377],{"type":36,"value":378},"Organizations with mature security awareness programs may already perform recurring phishing simulations using dedicated security awareness platforms. In those environments, phishing exercises within an IAM assessment may be unnecessary or tailored to evaluate specific high-risk user populations instead.",{"type":31,"tag":49,"props":380,"children":382},{"id":381},"looking-beyond-authentication",[383],{"type":36,"value":384},"Looking Beyond Authentication",{"type":31,"tag":32,"props":386,"children":387},{},[388],{"type":36,"value":389},"An effective IAM assessment evaluates more than whether users can successfully authenticate.",{"type":31,"tag":32,"props":391,"children":392},{},[393],{"type":36,"value":394},"It examines the complete identity ecosystem, including:",{"type":31,"tag":88,"props":396,"children":397},{},[398,403,408,413,418,423,428,433,438,443],{"type":31,"tag":92,"props":399,"children":400},{},[401],{"type":36,"value":402},"Password policies",{"type":31,"tag":92,"props":404,"children":405},{},[406],{"type":36,"value":407},"Multi-factor authentication coverage",{"type":31,"tag":92,"props":409,"children":410},{},[411],{"type":36,"value":412},"Password reuse",{"type":31,"tag":92,"props":414,"children":415},{},[416],{"type":36,"value":417},"Account lockout policies",{"type":31,"tag":92,"props":419,"children":420},{},[421],{"type":36,"value":422},"Identity monitoring",{"type":31,"tag":92,"props":424,"children":425},{},[426],{"type":36,"value":427},"Conditional access policies",{"type":31,"tag":92,"props":429,"children":430},{},[431],{"type":36,"value":432},"Single Sign-On (SSO)",{"type":31,"tag":92,"props":434,"children":435},{},[436],{"type":36,"value":437},"Privileged account protections",{"type":31,"tag":92,"props":439,"children":440},{},[441],{"type":36,"value":442},"Identity lifecycle management",{"type":31,"tag":92,"props":444,"children":445},{},[446],{"type":36,"value":447},"Security awareness maturity",{"type":31,"tag":32,"props":449,"children":450},{},[451],{"type":36,"value":452},"Together, these controls determine how resistant an organization is to identity-based attacks.",{"type":31,"tag":49,"props":454,"children":456},{"id":455},"identity-is-the-new-perimeter",[457],{"type":36,"value":458},"Identity Is the New Perimeter",{"type":31,"tag":32,"props":460,"children":461},{},[462],{"type":36,"value":463},"Modern cyberattacks increasingly begin with a legitimate login rather than a software exploit.",{"type":31,"tag":32,"props":465,"children":466},{},[467],{"type":36,"value":468},"Password spraying, credential stuffing, and phishing continue to be among the most successful attack techniques because they exploit weaknesses in identity rather than technology.",{"type":31,"tag":32,"props":470,"children":471},{},[472],{"type":36,"value":473},"A comprehensive IAM assessment provides organizations with a realistic understanding of how their authentication systems, identity controls, and users would perform against the same techniques employed by today's threat actors. By identifying weaknesses before they are exploited, organizations can strengthen authentication, improve user awareness, reduce account compromise risk, and significantly enhance their overall cybersecurity posture.",{"title":7,"searchDepth":475,"depth":475,"links":476},2,[477,478,479,480,481,482,483,484,485],{"id":51,"depth":475,"text":54},{"id":109,"depth":475,"text":112},{"id":120,"depth":475,"text":123},{"id":136,"depth":475,"text":139},{"id":147,"depth":475,"text":150},{"id":239,"depth":475,"text":242},{"id":317,"depth":475,"text":320},{"id":381,"depth":475,"text":384},{"id":455,"depth":475,"text":458},"markdown","content:blog:evaluating-identity-before-attackers-do.md","content","blog\u002Fevaluating-identity-before-attackers-do.md","blog\u002Fevaluating-identity-before-attackers-do","md",[493,505,515,526,536,544,556,558],{"_path":494,"title":495,"description":496,"cardTitle":497,"publishedAt":498,"tags":499,"coverImage":503,"coverAlt":504,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two","Understanding Your True Attack Surface: Part Two","Few companies understand how they look to an attacker. Your Internet attack surface is exactly what attackers see first.","Understanding Your True Attack Surface Part Two","2026-07-28",[500,501,502],"attack surface","internet security","cybersecurity strategy","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-two\u002Fcover.jpg","Cyber operations control tower monitoring a connected city and its Internet-facing attack surface",{"_path":506,"title":507,"description":508,"publishedAt":509,"tags":510,"coverImage":513,"coverAlt":514,"featured":6},"\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026","Top Cyber Threats Facing Businesses in 2026","Businesses face AI-assisted hacking, interception-proxy phishing, dark web breach data, and API attacks in 2026.","2026-06-26",[511,512,502],"cyber threats","business security","\u002Fblog\u002Ftop-cyber-threats-facing-businesses-in-2026\u002Fcover.jpg","A city skyline beneath a massive storm cloud embedded with cybersecurity symbols and lightning",{"_path":516,"title":517,"description":518,"publishedAt":519,"tags":520,"coverImage":524,"coverAlt":525,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two","Challenges Facing AI Frontier Models Part Two","Frontier AI models must overcome constraints in context, agent design, data quality, energy, and open-source competition.","2026-06-25",[521,522,523],"artificial intelligence","frontier models","AI safety","\u002Fblog\u002Fchallenges-facing-ai-frontier-models-part-two\u002Fcover.jpg","A humanoid robot ascending a snowy mountain ridge toward the sunset",{"_path":527,"title":528,"description":529,"cardTitle":530,"publishedAt":531,"tags":532,"coverImage":534,"coverAlt":535,"featured":6},"\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one","Understanding Your True Attack Surface: Part One","The modern attack surface extends far beyond the corporate firewall.","Understanding Your True Attack Surface Part One","2026-06-21",[500,533,502],"network security","\u002Fblog\u002Funderstanding-your-true-attack-surface-part-one\u002Fcover.jpg","Security leader reviewing an enterprise attack surface dashboard spanning cloud, applications, remote offices, devices, patching, identities, and internet exposure",{"_path":537,"title":538,"description":539,"publishedAt":540,"tags":541,"coverImage":542,"coverAlt":543,"featured":6},"\u002Fblog\u002Fchallenges-facing-ai-frontier-models","Challenges Facing AI Frontier Models Part One","Frontier AI models face a series of challenges that threaten their viability","2026-06-12",[521,522,523],"\u002Fblog\u002Fchallenges-facing-ai-frontier-models\u002Fcover.jpg","A humanoid robot standing among clouds beneath a blue sky",{"_path":545,"title":546,"description":547,"cardTitle":548,"publishedAt":549,"tags":550,"coverImage":554,"coverAlt":555,"featured":6},"\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation","Executive Operational Security Part One: Setting the Foundation","Executive OPSEC protects senior leaders, privileged access, sensitive information, communications, travel, and personal activity from targeted threats.","Executive Operational Security Part One","2026-06-10",[551,552,553],"executive security","OPSEC","risk management","\u002Fblog\u002Fexecutive-operational-security-opsec-part-one-setting-the-foundation\u002Fcover.jpg","Executive reviewing his phone beside a laptop in a private office",{"_path":4,"title":8,"description":9,"publishedAt":17,"tags":557,"coverImage":23,"coverAlt":24,"featured":6},[20,21,22],{"_path":559,"title":560,"description":561,"publishedAt":562,"tags":563,"coverImage":566,"coverAlt":567,"featured":6},"\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment","The Necessity of an Enterprise Risk Assessment","Effective Cybersecurity is both a Technical and Procedural Endeavor","2026-05-26",[564,553,565],"enterprise risk assessment","cybersecurity governance","\u002Fblog\u002Fthe-necessity-of-an-enterprise-risk-assessment\u002Fcover.jpg","CISO in an aircraft cockpit overlooking clouds with technical and procedural cybersecurity displays",1785277054252]