Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Cyber resilience and adversary simulation: are your controls really working?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Modern cybercrime groups operate with corporate discipline, use social engineering and MFA fatigue to bypass defenses, and exploit the gap between deployed controls and validated controls, according to SafeBreach. The real issue is not tool coverage but whether those controls still work when attackers adapt, rehearse, and persist.

NHIMG editorial — based on content published by SafeBreach: Lessons from the Dark Web, what hackers teach us about cyber resilience

Questions worth separating out

Q: What breaks when attackers can use MFA fatigue against users?

A: When MFA fatigue succeeds, the second factor stops acting as proof of intent and becomes a pressure point.

Q: Why do cybercrime groups create more operational risk than isolated hackers?

A: Organised groups reduce their own uncertainty by specialising work, vetting recruits, and reusing proven intrusion methods.

Q: How do you know if exposure validation is actually improving resilience?

A: Exposure validation is working when tests show fewer successful attack paths, faster containment, and fewer control exceptions that attackers can exploit.

Practitioner guidance

  • Test authentication under coercion conditions Run controlled simulations of MFA fatigue, helpdesk impersonation, and approval pressure to see whether users, service desks, and escalation paths fail under repeated prompts.
  • Validate controls continuously, not annually Use adversary simulation to check whether security controls still block, detect, or contain realistic attack paths after policy changes, configuration drift, and new exceptions.
  • Map attacker paths to crown-jewel exposure Prioritise simulations that target the systems whose compromise would most disrupt revenue, recovery, or customer operations, then trace which identity and access controls sit on the path to those assets.

What's in the full article

SafeBreach's full blog post covers the operational detail this post intentionally leaves for the source:

  • First-person field observations from dark web forums and ransomware recruitment pipelines.
  • Discussion of how attacker recruitment, vetting, and role specialisation shape intrusion operations.
  • Podcast tie-in with the author and SafeBreach expert breaking down the same themes in more detail.
  • Exposure validation platform context for teams that want to compare simulated outcomes against deployed controls.

👉 Read SafeBreach's analysis of hacker forums, ransomware recruitment, and resilience testing →

Cyber resilience and adversary simulation: are your controls really working?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Attacker discipline has become a governance problem, not just a threat problem. The article shows that cybercrime groups behave like operating businesses, with recruitment, vetting, and role assignment designed to reduce effort and maximise return. That means defenders are not only facing tools and techniques, but an adaptive operating model that can absorb mistakes and iterate quickly. For practitioners, the control question shifts from whether a control exists to whether it still works under organised pressure.

A question worth separating out:

Q: Who is accountable when social engineering defeats identity controls?

A: Accountability sits with the teams that own authentication, support workflows, telecom dependencies, and privileged access, not only with end users. If a reset, SIM swap, or device rebind can grant access without strong verification, the governance gap is structural. Organisations should map those responsibilities before an incident forces the issue.

👉 Read our full editorial: Cyber resilience depends on validating controls against attacker psychology



   
ReplyQuote
Share: