Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

High-value targeting in pentesting: what IAM teams should notice


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: High-value targeting pushes pentesting to focus on the systems and accounts attackers value most, using business context to prioritise domain controllers, privileged users, and critical servers, according to Horizons.ai. That framing matters because identity and attack-path significance, not raw vulnerability count, now determines blast radius and response urgency.

NHIMG editorial — based on content published by Horizons.ai: Introducing NodeZero High-Value Targeting, Think Like an Attacker, Prioritize What Matters

By the numbers:

Questions worth separating out

Q: How should security teams prioritise identities and systems that matter most to attackers?

A: They should rank identities and systems by blast radius, not just exposure count.

Q: Why do attackers focus on a small number of high-value identities and systems?

A: Because those assets turn limited access into broad control.

Q: What do security teams get wrong about vulnerability prioritisation?

A: Security teams often treat vulnerability scores as if they represent operational risk on their own.

Practitioner guidance

  • Define identity blast radius tiers Classify accounts, services, and systems by the consequence of compromise, not by technical label alone.
  • Feed business context into attack-path prioritisation Add department, environment, and service ownership context to vulnerability and exposure data so prioritisation reflects operational impact.
  • Re-score privileged identities after each new discovery Update attack-path analysis whenever new credentials, trust relationships, or reachable services appear.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The full attack-path workflow showing how the prioritisation engine re-ranks targets as new systems and credentials appear.
  • Examples of hostname, service, and directory signals used to classify high-value systems in practice.
  • The author’s own explanation of AWS Bedrock usage, model handling, and runtime isolation choices.
  • Expanded examples of how business-risk labels are mapped to specific asset and identity classes.

👉 Read Horizons.ai's blog on high-value targeting for attacker-style prioritisation →

High-value targeting in pentesting: what IAM teams should notice?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

High-value targeting is really an identity blast-radius problem. The security question is not which assets exist, but which identities and services can turn one access event into enterprise-wide consequence. That makes domain controllers, privileged service accounts, and executive identities structurally different from the rest of the inventory. Practitioners should treat prioritisation as a blast-radius exercise, not a scanning exercise.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: How should teams decide whether PAM is enough for high-value accounts?

A: PAM is only one control layer. High-value business accounts also need phishing-resistant authentication, strong email and collaboration monitoring, and clear operational ownership. If the risk is business email compromise or fraud, privileged session controls alone will not cover the main attack path.

👉 Read our full editorial: High-value targeting shows why attackers prioritize identity first



   
ReplyQuote
Share: