Identity

Every identity has value. The question is: to whom?

Because the goal was never to make access harder to get. It's to make sure it doesn't outlive its purpose.

Think about the service account your team set up three years ago for an integration that barely anyone uses anymore. Low risk, right? Minimal permissions. Probably not on anyone’s radar.

Now think about what that account can reach. Maybe it has access to a cloud storage bucket. That bucket is connected to an application. That application shares a trust relationship with a system that holds customer records. The account itself isn’t the prize. But to an attacker, it’s an open door—and doors are exactly what they’re looking for.

An identity is more than a login

Every identity in your environment represents something attackers want: trusted access. An identity is not simply a username and password. It carries permissions, group memberships and trust relationships that have accumulated across cloud platforms, SaaS applications, infrastructure and business-critical systems.

I encourage security teams to think of identity as part of the security perimeter. Unlike a traditional perimeter, however, identity is distributed across systems, providers and administrative teams. Most organizations cannot see all those relationships from one place.

When an attacker takes control of an identity, they inherit the trust already associated with it. That can allow them to operate through legitimate permissions and move through the environment in ways that appear normal. This is one reason identity-based attacks can be difficult to detect: the activity may be malicious even though the access being used is valid.

The account that looks low risk rarely is

The identities that concern security teams most are usually the obvious ones: administrator accounts, privileged users and accounts tied directly to sensitive systems. But attackers look at identity risk differently. They aren’t only searching for high-value accounts. They’re looking for any account that can lead them to one.

This is one of the assumptions I encourage security teams to challenge. An account that appears low risk may be indirectly connected to an administrative role, sensitive data store or critical business application through relationships no one has mapped. An attacker can use those hidden paths to move laterally, gain additional access and escalate privileges until they reach their actual target.

The identity itself is rarely the final objective. Its value lies in where it can take an attacker.

You can’t protect what you can’t see. Discover every identity. Understand every risk. Reduce your attack surface.

The scale of the problem is bigger than most teams realize

Machine identities—including service accounts, workloads, bots, automation tools and AI systems—can vastly outnumber human identities in a modern environment. Each one requires access to systems or data, and that access accumulates over time just as it does for employees and contractors.

The difference is that machine identities often do not follow the same lifecycle as workforce accounts. A service account does not leave the company or change departments. It can remain active long after the application, integration or project it supported has changed. Unless someone is responsible for reviewing it, the account and its permissions may remain in place indefinitely.

Add forgotten accounts, inactive users, unmanaged service accounts and third-party access, and the identity attack surface grows quickly. The challenge is not simply the number of identities. It is knowing who or what owns them, why their access still exists and what they can ultimately reach.

The common thread is visibility. Attackers are very good at finding the identities and relationships defenders cannot see.

What it means to actually understand identity risk

For security leaders, the question is no longer simply who has access. It’s what a compromised identity could reach, which privileges it could inherit, what data it could expose and how far an attacker could travel from that starting point.

Answering those questions requires seeing identities as a network of permissions, relationships and trust paths—not as individual accounts listed in a directory. In my experience, this is where many identity programs have a visibility gap. They can show that an entitlement exists, but not always how that entitlement connects to other systems or contributes to a larger attack path.

Once those relationships are visible, teams can identify where the greatest risk actually exists and prioritize the changes that will have the most impact. A single compromised account can become the starting point for data theft, ransomware, operational disruption or long-term persistence. The organizations in the strongest position are the ones that map those paths before an attacker has the opportunity to use them.

Every identity creates value for the business. The goal is to ensure it does not create more opportunity for an attacker than the business requires.

ConRes works with SpecterOps to help organizations uncover hidden identity relationships, identify critical attack paths and close the doors attackers could use to reach critical systems.

Close the door for good on attackers. Request your identity assessment →

Chief Technologist, Security, ConRes

Speak with an expert

This field is for validation purposes and should be left unchanged.