Maintaining access is the stage where a tester attempts to keep a foothold after initial compromise, often to evaluate escalation and lateral movement opportunities. In real attacks, this mirrors the persistence an adversary seeks inside a network. It helps reveal segmentation weaknesses and privilege control failures.
Expanded Definition
Maintaining access describes the phase in an intrusion or authorised test where a foothold is preserved after the initial entry point is established. The primary concern is not simply staying connected, but keeping a reliable path for follow-on activity such as privilege expansion, lateral movement, and re-entry after interruption.
In red team and penetration testing contexts, the term is used as a diagnostic lens for whether the environment can detect, contain, or revoke an active presence. It is closely related to persistence, but the two are not identical: persistence usually implies a mechanism designed to survive reboot, credential reset, or account cleanup, while maintaining access can also include short-lived or manual retention of access during an engagement. That distinction matters because some environments are weak at detection and segmentation even when formal persistence is harder to establish.
For a broader control perspective, the concept aligns naturally with NIST SP 800-53 Rev. 5, which frames the importance of boundary protection, access enforcement, auditing, and incident response discipline. You can review the control catalogue in NIST SP 800-53 Rev 5 Security and Privacy Controls.
Examples and Use Cases
- A tester uses an existing remote session to validate whether a single compromised host can be reused to reach adjacent systems without additional authentication.
- An operator confirms that access survives routine endpoint restarts, which helps distinguish a fleeting foothold from a durable intrusion path.
- A security team exercises account review and session revocation procedures to see whether stale tokens, cached credentials, or unmanaged agents still permit access after containment.
- A penetration test checks whether segmented environments actually block movement, or whether trust relationships and permissive rules allow the foothold to expand quietly.
- In a cloud or hybrid environment, the test may reveal that revoking one account does not fully end access because other authorised paths still exist.
The trade-off is practical: the more realistic the test environment, the better it reveals detection and containment gaps, but the more carefully it must be scoped to avoid disrupting live operations or confusing persistence testing with ordinary session continuity.
Where an organisation uses non-human identities to automate privileged work, maintaining access can also expose whether those machine paths are monitored with the same rigor as user accounts. That is especially important when access depends on tokens, service credentials, or delegated automation that outlives the operator who created it.
Security Implications
When maintaining access is poorly understood, defenders may stop at initial compromise and miss the real operational question: what lets an intruder stay long enough to act. The consequence is usually not a single broken login, but a failure to contain the foothold before the attacker can enumerate assets, pivot, or wait for a higher-value moment.
Common failure conditions include overly broad trust relationships, weak session expiry, insufficient logging, delayed account review, and environments where network segmentation exists on paper but not in practice. Those gaps make it easier for an adversary to reuse the original access path, switch to a different authenticated channel, or survive partial remediation.
The observable symptoms are often subtle: unexpected reuse of a remote management channel, access continuing after an apparent reset, lateral probes from a host that should be isolated, or activity that resumes after containment actions that should have been final. In test exercises, those symptoms are useful because they show whether control failures are one-time or systemic.
For NHI-heavy environments, the same issue can arise when service credentials, tokens, or workload permissions are not inventoried and revoked with the same discipline as human access. That is not a separate problem from maintaining access; it is one of the ways the foothold survives.
Domain and Governance Relevance
In cybersecurity governance, maintaining access matters because it exposes whether containment, segmentation, and access revocation are real operational controls or only policy statements. The term is especially useful in assessments that need to prove whether a compromised starting point can be cut off before it becomes an incident with broader blast radius.
For identity and access governance, the concept highlights a simple reality: revocation has to be comprehensive, not symbolic. If one credential, token, session, or delegated path remains valid, the environment may still behave as though compromise is active even after the obvious entry point is closed.
That becomes more important when automation is involved, because machine-operated paths can retain access in ways that are easy to overlook during manual response. In those cases, maintaining access is a signal that ownership, lifecycle control, and cleanup procedures are not yet aligned with how access is actually being used.
NHIMG treats this term as a practical test of control durability. The question is not whether access was gained, but whether the organisation can prove that it can be removed, bounded, and observed before it turns into sustained exposure.
Risk and Threat Considerations
Maintaining access creates material risk because it extends the window in which an intruder can operate after the first compromise. That increases the chance of privilege escalation, credential harvesting, lateral movement, and delayed detection, especially in networks where trust and session handling are fragmented.
Failure mechanism: The risk materialises when access paths are not fully revoked, when sessions remain valid longer than expected, or when a foothold can be re-established through alternate accounts, tokens, or unmanaged automation. Attackers benefit from this by preserving a stable base of operations while defenders believe the initial issue has been closed.
Impact: The practical consequence is broader compromise. A small entry point can turn into persistent control over multiple systems, incomplete eradication, and repeated re-entry after containment actions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1078 — Valid Accounts | Maintaining access often relies on preserved legitimate credentials or sessions. |
| Recommendation — Hunt for reused valid accounts and revoke any preserved access paths immediately. | ||
| CIS Controls v8 | 5 — Account Management | Maintaining access exposes whether accounts and sessions are fully controlled. |
| Recommendation — Remove stale access and enforce timely deprovisioning for all affected accounts. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions Management | The term depends on limiting and revoking access paths after compromise. |
| DE.CM-8 — Vulnerability and Control Monitoring | Maintaining access is often revealed by weak visibility into continued footholds. | |
| Recommendation — Tighten access permissions and ensure compromised paths can be rapidly invalidated. Monitor for continued foothold activity and investigate unexpected access persistence. | ||
| OWASP Non-Human Identity Top 10 | NHI-03 — Secrets and Credential Management | Machine credentials can preserve access long after the original compromise. |
| Recommendation — Inventory and rotate machine secrets so preserved non-human access is eliminated. | ||
Practitioner Guidance
Why practitioners should care: Treat maintaining access as a test of control durability, not just intrusion presence. If a foothold cannot be conclusively removed, incident handling, segmentation, and access governance are not yet doing the job they claim to do.
What to watch for: Pay attention to lingering sessions, secondary authenticated paths, and cleanup that removes the obvious account but leaves another route intact. Those are the places where an assumed containment can quietly fail.
Related resources from NHI Mgmt Group
- Who is accountable for maintaining Oracle EBS access controls during a GRC migration?
- Who is accountable for maintaining continuous compliance in Oracle ERP Cloud access governance?
- Who is accountable for maintaining right-time, right-level access across cloud and business systems?
- Who is accountable for maintaining effective support workflows for identity and access services?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org