Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Quarterly breach controls: what identity and security teams missed


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20538
Topic starter  

TL;DR: July 2026’s breach wave exposed the same seven failure points, including phishing-resistant MFA, ITDR, immutable backups, third-party access governance, and continuous edge scanning, as 799 ransomware attacks and a 29-minute breakout time compressed defender response windows, according to Anomali. The governing problem is not lack of tools but control mismatch: attackers are using valid credentials, supply-chain trust, and recovery denial faster than periodic defensive models can adapt.

NHIMG editorial — based on content published by Anomali: Seven controls that would have stopped this quarter's biggest breaches and why most orgs still lack them

By the numbers:

Questions worth separating out

Q: What breaks when phishing-resistant MFA is not in place for regulated systems?

A: When phishing-resistant MFA is missing, a single phishing message can expose authenticated access paths that regulators expect to be stronger.

Q: Why do valid-account attacks and token abuse matter more than malware in many breaches?

A: Because many modern intrusions do not need malicious files to execute.

Q: What are the signs that a third-party access breach is in progress?

A: Common warning signs include logins from suspicious IP addresses, repeated 401 and 403 responses, abnormal authentication patterns in vendor logs, and outbound connections to known malicious domains.

Practitioner guidance

  • Prioritise phishing-resistant MFA for privileged access Move high-risk users and administrators onto passkeys or hardware-backed authenticators first, especially where the account can reach cloud, directory, or backup systems.
  • Separate backup administration from production identity paths Use distinct admin accounts, isolated recovery credentials, and restore tests that prove recovery still works when production identities are unavailable.
  • Instrument identity telemetry for token and privilege abuse Feed authentication events, token issuance, privilege changes, and anomalous login patterns into detection workflows so valid-account abuse is visible.

What's in the full article

Anomali's full analysis covers the operational detail this post intentionally leaves for the source:

  • Per-control breach examples showing how each failure mode changed the outcome of recent incidents.
  • The source references behind the July ransomware spike, identity abuse trends, and supply-chain compromise patterns.
  • Practical context for why each control belongs in a live detection, response, or resilience programme.
  • The full references section for the incident and threat reports cited in the article.

👉 Read Anomali's analysis of the seven controls that could have changed Q3 breaches →

Quarterly breach controls: what identity and security teams missed?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20129
 

Identity control failure is now an execution-speed problem, not just a hygiene problem. The article’s breach set shows that periodic review and reactive patching are being outrun by attacker tempo. When breakout time is measured in minutes, controls that depend on next-cycle remediation are already late. Practitioners should treat identity, backup, and exposure management as continuous runtime controls, not quarterly clean-up tasks.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, which matches the governance drift described in this quarter's breach set.

A question worth separating out:

Q: How should teams respond when ransomware targets backups and identity systems together?

A: Treat recovery as part of the attack surface and validate that backup administration is separated from production access. If the same credentials can reach both planes, an attacker can deny recovery before encryption even starts. Restore testing and identity segmentation need to be designed together, not as separate programmes.

👉 Read our full editorial: Seven controls that would have changed this quarter's biggest breaches



   
ReplyQuote
Share: