Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity ransomware: is ISPM the gap your controls are missing?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: Ransomware is increasingly an identity problem rather than a pure malware problem, with 83% of attacks compromising identity infrastructure and 30% of intrusions using identity-based tactics, according to Veza, Semperis and IBM X-Force. That shifts the control point from endpoint response to visibility, entitlement governance, and non-human identity oversight.

NHIMG editorial — based on content published by Veza: Identity Ransomware: Why ISPM Is the Key to Stopping Attacks

By the numbers:

Questions worth separating out

Q: How should security teams limit ransomware spread through identity controls?

A: Security teams should reduce standing privilege, segment admin roles, and require task-scoped elevation for high-risk actions.

Q: Why do service accounts with standing privilege make ransomware worse?

A: Standing privilege gives attackers persistent reach after initial compromise.

Q: What breaks when identity visibility is missing during a ransomware attack?

A: Containment becomes guesswork.

Practitioner guidance

  • Map every high-risk identity to real business ownership Build a live inventory of human and non-human identities that can reach production, backups, and directory services.
  • Review service accounts with backup or admin reach Prioritise accounts that can administer systems, reset credentials, or touch backup repositories.
  • Replace spreadsheet access reviews with graph-based entitlement checks Use an identity-to-data model to show who can access which systems, from where, and through which accounts.

What's in the full article

Veza's full article covers the operational detail this post intentionally leaves for the source:

  • The specific ISPM workflow for mapping every identity to entitlements across SaaS, cloud, and infrastructure
  • The identity-to-data graph approach used to surface dormant, orphaned, and over-permissioned accounts
  • Practical examples of policy simulation before rollout, including how to avoid access changes that break production
  • Audit export examples that turn least-privilege evidence into something teams can hand to auditors quickly

👉 Read Veza's analysis of how ISPM helps stop identity-driven ransomware →

Identity ransomware: is ISPM the gap your controls are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Identity ransomware is a governance failure before it is a malware event. The article’s core point is that attackers increasingly win by abusing legitimate access paths, not by relying on exotic exploits. That means the control failure sits in entitlement visibility, ownership, and lifecycle hygiene across both human and non-human identities. Practitioners should treat ransomware as proof that identity posture is now part of operational resilience.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and 47% reporting partial visibility.

A question worth separating out:

Q: Who is accountable when compromised credentials are used to trigger ransomware?

A: Accountability usually spans identity, infrastructure, and security operations because the failure chain includes authentication design, network trust boundaries, and detection gaps. Frameworks such as NIST CSF and Zero Trust Architecture place responsibility on governance that limits blast radius, not only on the team that owns the portal.

👉 Read our full editorial: Identity security posture management is now central to ransomware defense



   
ReplyQuote
Share: