By NHI Mgmt Group Editorial TeamBased on Silverfort: “Don’t fear the Red Team: Why quantifying identity risk in the real world is the key to resilience” (November 6, 2025)

TL;DR: A red team exercise showed that a phishing click and a long-forgotten privileged account were enough to reach domain access while SOC and SIEM tooling stayed blind for weeks, according to Silverfort. The lesson is that identity risk cannot be managed by assumption, because visibility and credential misuse now determine whether perimeter controls actually hold.


At a glance

What this is: This is an analysis of why identity visibility gaps leave cyber defence programmes blind to credential misuse, with a red team exercise showing that phishing and an overlooked privileged account enabled domain access without detection.

Why it matters: IAM, PAM, and NHI teams need measurable identity visibility because perimeter controls can hold on paper while credential misuse still creates the real path to compromise.


Context

Identity visibility is the ability to see which accounts exist, how they are used, and where privileged access can be abused. The article’s core problem is that many organisations have strong perimeter reporting but weak identity-layer data, so they cannot quantify exposure in the place attackers most often exploit.

The red team example shows why that gap matters: phishing created the initial foothold, and a long-forgotten privileged account provided the route to domain access while monitoring stayed blind. For identity programmes, that means the issue is not only prevention but whether identity use can be measured, investigated, and governed at all.


Key questions

Q: What breaks when identity visibility is too weak to quantify exposure?

A: What breaks first is governance, because teams cannot distinguish known risk from assumed safety. Without a reliable inventory of identities, privileges, and authentication behaviour, security leaders cannot prioritise remediation, verify control coverage, or prove that monitoring is seeing the right events. The result is defence by belief rather than evidence.

Q: Why do privileged accounts create outsized breach risk?

A: Privileged accounts can change configurations, access sensitive data, and disable controls, so a single compromise often has disproportionate impact. If those accounts are broad, poorly monitored, or left active after use, attackers can move from initial access to system-wide disruption far faster than with ordinary user accounts.

Q: How do teams know if identity security controls are actually working?

A: Identity security controls are working when teams can show a current view of high-risk entitlements, detect privilege drift quickly, and remove access before exposure spreads. A useful sign is reduced time between entitlement change and policy review. Another is fewer unresolved conflicts between approved access and actual production permissions.

Q: How should organisations decide which MFA approach to use for different access scenarios?

A: Start by matching the MFA pattern to the risk, user experience, and business criticality of the action being protected. Always on MFA suits broader account protection, while step-up authentication and time-sensitive re-authentication are better for higher-risk or sensitive moments. The right choice depends on whether you are protecting routine sign-in, privileged actions, or access to sensitive data.


Technical breakdown

Why identity-layer telemetry fails when visibility is fragmented

Identity telemetry becomes ineffective when account data, privilege data, and authentication events are split across legacy systems, directory services, and monitoring stacks. In that state, teams can report on perimeter activity or infrastructure health while remaining unable to answer the basic question of which identities are high risk. The article describes a common failure mode: mature SOC and SIEM operations can still miss identity misuse if the underlying identity inventory is incomplete or stale. Practical implication: unified identity visibility has to become a source of control data, not just a reporting layer.

Practical implication: build a consolidated view of privileged and high-risk identities before assuming your existing monitoring stack can govern them.

How privileged account misuse bypasses defensive assumptions

Privileged account misuse is often the decisive step because the attacker does not need to break every control, only to land on an identity that already carries excess authority. Once that account exists and remains viable, the attack path shifts from initial access to operational reach, including domain-level control. The article’s point is that defence programmes fail when they treat privileged identities as static assets rather than active attack surfaces. Practical implication: privilege scope and account age matter as much as the strength of the perimeter.

Practical implication: audit long-dormant privileged accounts and treat them as live exposure until they are proven necessary and monitored.

Why MFA coverage and NHI ring-fencing still leave gaps

MFA coverage is not universal, especially in legacy systems, file shares, and command-line interfaces where authentication controls can be inconsistent or absent. The article also notes that non-human identities need ring-fencing so they can only be used where intended, because misuse of privileged accounts, human or not, is central to successful attacks. That creates a governance problem as well as a technical one: identities must be constrained by context, not just by issuance. Practical implication: access control design has to account for both human and NHI execution paths.

Practical implication: identify where MFA does not apply and where NHI usage is not context-bound, then close those paths as separate control gaps.


Threat narrative

Attacker objective: The objective was to obtain domain-level administrative access without triggering detection.

  1. Entry via a crafted phishing attack gave the red team an initial foothold despite existing awareness drills and defensive tooling.
  2. Credential abuse followed when a long-forgotten privileged account provided the access needed to move from foothold to domain reach.
  3. Impact emerged as the team achieved domain access while SOC and SIEM monitoring stayed blind for weeks.
  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
  • CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity visibility, not tooling volume, is the limiting factor in cyber defence. The article shows that organisations can accumulate mature SOC, SIEM, and perimeter controls and still be unable to answer the most basic question about exposure. That means the governance failure is not a lack of alerts, but a lack of trustworthy identity data. Practitioners should treat visibility as the prerequisite for every higher-order control decision.

Long-forgotten privileged accounts create hidden blast radius. The red team reached domain access through an account that had effectively fallen out of governance sight. That is not just privilege creep, it is account invisibility as an exposure state. The practitioner implication is that dormant privilege needs continuous discovery, not periodic assumption that the estate is already known.

Misuse of privileged credentials is the control boundary that matters most. The article’s strongest line is that perimeter loss is survivable only until privileged credentials are abused. Once an identity can act with authority, traditional boundary thinking stops being decisive. For identity security programmes, the real control question is whether access is observable, attributable, and constrained before it is used.

Visibility gaps turn identity security into a measurement problem before it becomes a prevention problem. If teams cannot quantify identity exposure, they are left with confidence without evidence. That undermines IAM, PAM, and NHI governance alike because each depends on knowing which identities exist, what they can do, and whether they are still legitimate. Practitioners need measurement discipline before policy claims can be trusted.

From our research library:

What this signals

Identity security is now a measurement discipline. The organisations that can inventory and score identity exposure will outpace those still relying on assumptions about perimeter strength or SOC coverage. The practical shift is from asking whether tools are deployed to asking whether identity risk can be measured in a way leaders can act on.

Legacy access paths remain the quietest failure point. File shares, command-line tools, and older systems often sit outside modern MFA assumptions, which means the programme gap is not theoretical. Teams should expect that the easiest path into the estate may still be the least visible one, and adjust governance priorities accordingly.


For practitioners

  • Quantify identity exposure with live inventory Create a current inventory of privileged, legacy, and high-risk accounts across all identity stores so exposure is measured rather than assumed.
  • Test identity controls with red teaming Run red team scenarios that include phishing, dormant privilege, and lateral movement paths, not only perimeter and endpoint assumptions.
  • Ring-fence non-human identities Restrict NHI use to the systems and contexts where each identity is intended to operate, and verify that scope remains enforceable.
  • Close MFA blind spots in legacy access paths Map file shares, command-line tools, and older systems where MFA is absent, then prioritise compensating controls for those entry points.

Key takeaways

  • The article shows that strong perimeter controls do not compensate for weak identity visibility when privileged account misuse is still possible.
  • The red team example demonstrates how phishing and dormant privilege can combine to produce domain access while monitoring remains blind.
  • Identity programmes need live measurement of exposure, not just policy assertions, if they are going to reduce attacker reach.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on privileged accounts that remained too powerful and insufficiently governed.
NHI-10 — Human Use of NHIThe article notes that human and non-human identities both become dangerous when privileged credentials are misused.
Recommendation — Reduce standing privilege for NHI accounts and review scope whenever access persists beyond active need. Separate human and NHI usage paths so each identity type is governed in the context it actually operates.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential misuse and incomplete MFA coverage point directly to authenticator lifecycle and enforcement.
Recommendation — Apply IA-5 to inventory, protect, and retire authenticators across legacy and modern access paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about whether identity permissions are visible and governed.
Recommendation — Use PR.AA-05 to validate that entitlements match current identity need and privilege is observable.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe red team path relied on phishing, credential misuse, and movement to domain access.
Recommendation — Map testing and detections to TA0006 and TA0008 so credential abuse and lateral movement are visible.

Key terms

  • Identity Visibility: Identity visibility is the ability to see which identities exist, what they can access, and how those access paths relate across systems. In NHI programmes, it means correlating service accounts, tokens, certificates, and agents into one operational view so governance decisions are based on evidence, not assumptions.
  • Shared Privileged Account: An administrative identity used by more than one operator or system process. These accounts are common in infrastructure and cloud operations, but they create accountability and lifecycle challenges because access must be tightly controlled, rotated and audited.
  • Identity Exposure Path: An identity exposure path is the sequence of systems, permissions, and trust relationships that can be used to reach sensitive identities or their privileges. It describes how an attacker, insider, or misconfiguration could move from one identity control point to another, revealing where identity risk becomes exploitable across accounts, tokens, sessions, and access policies.
  • Red Team Exercise: A red team exercise is a controlled adversary simulation designed to test how an organisation would withstand realistic attack behaviour. It focuses on offensive technique, chaining weaknesses together so defenders can see how an attacker would move from exposure to impact.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org