By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: AnomaliPublished March 10, 2026

TL;DR: The geopolitical, cyber, and operational risks around the 2018 Winter Olympics are mapped in a threat brief, according to Anomali. The lesson for security teams is that high-profile events create multi-domain risk requiring intelligence-led preparation, not only perimeter defence.


At a glance

What this is: This is a threat brief on security risks surrounding the 2018 Winter Olympics, with emphasis on cyber disruption, geopolitical tension, and event-driven attack activity.

Why it matters: It matters because major events concentrate brand, infrastructure, and public trust risk, and the same planning gaps that affect venue security also affect identity, access, and incident response governance.

👉 Read Anomali's cyber threat brief on security risks around the 2018 Winter Olympics


Context

High-profile sporting events create a predictable surge in threat activity because they combine global attention, dense partner ecosystems, and time-boxed operational pressure. In that environment, conventional perimeter thinking is too narrow. Security teams need to plan for intelligence-led detection, rapid validation of alerts, and careful governance of access to event systems and supporting services.

The identity angle is indirect but real: event operations depend on temporary workers, contractors, shared platforms, and privileged operational accounts. That means IAM and PAM controls, especially around short-lived access, offboarding, and escalation paths, become part of broader event resilience rather than separate administrative concerns.


Key questions

Q: How should security teams govern temporary access for major events?

A: They should treat temporary access as a lifecycle-managed control, not an ad hoc convenience. That means time-bound provisioning, explicit approval, logging for privileged actions, and verified removal at the end of each operational phase. Event environments are especially vulnerable when contractors, vendors, and volunteers retain access after their work is complete.

Q: Why do major events create unusual identity and access risk?

A: Because they compress many organisations, short timelines, and high privilege into a single operating window. Temporary identities, vendor integrations, and shared administrative workflows become attractive targets when they are needed fast and reviewed slowly. The risk is highest where access is broad, transient, and poorly monitored.

Q: What do teams get wrong about event security?

A: They often focus on venue or network protection while underestimating the identity layer that makes the event run. If access to systems, credentials, and third-party integrations is not governed tightly, attackers can use the operational model itself as an entry point. Security planning must include lifecycle control of every privileged identity.

Q: Which frameworks help structure event security planning?

A: NIST CSF can organise governance, protection, detection, response, and recovery, while IAM and PAM controls address who can do what during the event. Where contractors and vendors are involved, lifecycle controls and access reviews should be treated as core resilience measures, not administrative tasks.


Technical breakdown

Why major events attract coordinated threat activity

Large international events compress political symbolism, media attention, and technical dependence into one operational period. That combination draws espionage, sabotage, and opportunistic intrusion. The technical problem is not just volume of attacks, but diversity of attacker objectives. Some actors want disruption, others want influence operations, and others use the event as cover for credential theft or lateral movement into sponsor and partner environments. For security teams, the architecture question is whether monitoring, access control, and response workflows can absorb a temporary spike without losing fidelity.

Practical implication: pre-stage event-specific detections, escalation paths, and access reviews before the operational window opens.

How event ecosystems expand the identity and access attack surface

Major events depend on a layered ecosystem of staff, vendors, volunteers, media, and technology providers. Each layer introduces credentials, privileged workflows, and service integrations that can outlive the event if not tightly governed. NHI risk appears when short-term accounts, API keys, and shared administrative access are used to speed operations but are not fully lifecycle-managed. This is where IAM and PAM intersect with event security: the same temporary access that enables logistics can also enable abuse if it is not scoped, logged, and removed cleanly.

Practical implication: enforce just-in-time access, strong offboarding, and privileged session logging for all event-linked identities.

What intelligence-led defence means in practice

Threat intelligence is useful only when it changes control decisions. In an event setting, that means translating reporting into watchlists, blocking rules, triage priorities, and response playbooks. Intelligence-led defence is less about collecting more data and more about identifying which actors, infrastructure, and tactics are most relevant to the event environment. A brief like this matters because it frames the event as an operational threat environment, not a publicity backdrop. That is the right starting point for prioritising detection and response capacity.

Practical implication: connect threat intelligence feeds to incident workflows and control enforcement rather than treating them as advisory context.


Threat narrative

Attacker objective: The attacker objective is to disrupt operations or exploit the event's visibility to maximise operational, reputational, or political impact.

  1. Entry can occur through opportunistic phishing, exposed services, or access to partner systems that support event operations.
  2. Escalation often follows when attackers reuse temporary credentials, shared admin accounts, or weakly governed vendor access to move deeper into the environment.
  3. Impact can include disruption of services, public-facing defacement, credential theft, or information operations timed to the event's visibility.

NHI Mgmt Group analysis

Event security is now an identity governance problem as much as a physical one. Large events depend on temporary staff, contractors, vendors, and elevated operational access, which means access governance becomes part of the security plan, not a back-office afterthought. When temporary access is poorly scoped or not removed promptly, the event environment inherits the same lifecycle weaknesses that drive enterprise identity incidents. Practitioners should treat access review, offboarding, and privilege boundaries as operational controls for event resilience.

Threat briefings like this are most valuable when they change control priorities. Intelligence is useful only when it informs what to monitor, which assets to protect first, and which accounts to scrutinise most closely. The field-wide lesson is that event security depends on translation from reporting into enforcement. Practitioners should make sure intelligence, IAM, and response teams are operating from the same playbook.

Temporary access creates a concentrated standing-privilege problem. Event environments often justify speed over precision, but that trade-off leaves elevated credentials in place longer than intended. The governance gap is not just excess access, but the assumption that short-lived operations do not need the same lifecycle discipline as permanent systems. Practitioners should design for rapid provisioning with equally rapid revocation.

Security for global events is increasingly cross-domain by design. Cyber threats, information operations, vendor risk, and operational resilience overlap during the same time window. That means teams cannot isolate identity governance from broader event command structures. Practitioners should align IAM, PAM, SOC, and third-party access oversight before the event begins.

What this signals

Event programmes should expect identity sprawl to peak before the event starts, not during the incident. The practical signal is whether contractors, vendors, and volunteers can be provisioned and deprovisioned with the same discipline as permanent staff, because event risk often begins with temporary access that outlives the work it was meant to support.

Temporary access debt: this is the accumulation of accounts, secrets, and privileged exceptions created for speed and left behind after the event. Teams that cannot inventory and expire this access before operations begin will carry avoidable exposure into the post-event period, especially across vendor and partner systems.


For practitioners

  • Define a pre-event access expiry model Set hard expiration dates for all contractor, vendor, and volunteer access tied to event milestones, with removal verified before the operational window closes. Use separate workflows for privileged and non-privileged accounts so cleanup is not delayed by manual exceptions.
  • Instrument privileged sessions for event-linked identities Require session logging and alerting for administrative accounts used in broadcast, logistics, venue, and ticketing systems. Focus on unusual delegation, unexpected authentication locations, and privilege reuse across support teams.
  • Map intelligence to concrete detection rules Convert threat reporting into actionable detections for phishing, credential abuse, and suspicious partner access. Tie those detections to a named incident owner and a documented decision path so alerts do not stall in triage.
  • Tighten third-party access governance Review vendor accounts, shared service credentials, and integration tokens before go-live, then validate revocation after each operational handoff. This is where temporary convenience often turns into persistent exposure.

Key takeaways

  • Major events turn identity governance into an operational security control, not just an administrative task.
  • The highest-risk weakness is temporary access that is fast to grant and slow to remove.
  • Threat intelligence only helps when it is translated into detections, ownership, and revocation decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Temporary event access and partner accounts make access control central to this brief.
NIST SP 800-53 Rev 5AC-2Account lifecycle control is directly relevant to contractor and vendor access during events.
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe brief's threat model includes credential abuse and movement through partner environments.
NIST Zero Trust (SP 800-207)Zero trust principles fit distributed event environments with many partners and temporary users.

Use AC-2 to manage temporary accounts, approvals, expiry, and offboarding for event operations.


Key terms

  • Temporary access debt: Temporary access debt is the buildup of short-lived accounts, secrets, and exceptions created to support fast-moving operations but not removed on time. In event environments, it becomes a hidden exposure because the identities that made delivery possible remain valid after the operational need has ended.
  • Intelligence-led defence: Intelligence-led defence is the practice of turning threat information into specific security actions such as detections, block rules, triage priorities, and response ownership. It is not about collecting more data. It is about ensuring that threat reporting changes how teams monitor and respond.
  • Privileged Session Monitoring: Privileged Session Monitoring is the recording and review of high-risk access sessions after elevation is granted. It gives security teams visibility into commands, queries, and configuration changes, helping them detect misuse, support investigations, and prove that administrative actions were authorised.

What's in the full article

Anomali's full white paper covers the operational detail this post intentionally leaves for the source:

  • Country-by-country threat context and event-specific geopolitical framing that supports the brief.
  • The full operational threat discussion behind the 2018 Winter Olympics cyber risk assessment.
  • Anomali's supporting resource links and related threat intelligence material for further investigation.
  • The broader white paper context around how the brief fits into the security and IT operations platform.

👉 Anomali's full white paper adds the surrounding context, threat framing, and related resources.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need stronger lifecycle control across identity programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org