






















Business Security
Identity is effectively the new network boundary. It must be protected at all costs.
04 Dec 2025 • , 4 min. read

What do M&S and Co-op Group have in common? Aside from being among the UK’s most recognizable high street retailers, they were both recently the victims of a major ransomware breach. They were also both targeted by vishing attacks that elicited corporate passwords, providing their extorters with a critical foothold in the network.
These identity-related breaches cost the two retailers over £500 million (US$667 million), not to mention an incalculable reputational damage and impact on end customers. The bad news for organizations operating in various verticals, including critical infrastructure providers, is that they’re just the tip of the iceberg.
Why has identity become such a popular attack vector? Part of it stems from the way companies work today. There was a time when all corporate resources were safely located behind a network perimeter and security teams defended that perimeter with a “castle-and-moat” strategy. But today’s IT environment is way more distributed. A proliferation of cloud servers, on-premises desktops, home working laptops and mobile devices mean the certainties of old have evaporated.
Identity is effectively the new network perimeter, which makes credentials a highly sought-after commodity. According to Verizon, credential abuse was a factor in nearly a quarter (22%) of data breaches last year. Unfortunately, they’re imperilled in several ways:
It’s not hard to find examples of catastrophic security incidents stemming from identity-based attacks. Aside from the M&S and Co-op Group cases there’s Colonial Pipeline, where a likely brute-force attack let ransomware actors compromise a single password on a legacy VPN, causing major fuel shortages on America’s East Coast. Also, KNP, the British logistics firm was forced into bankruptcy after hackers simply guessed an employee’s password and encrypted critical systems.
The risks posed by identity compromise are amplified by several other factors. Least privilege is a critical best practice whereby individuals are given just enough access privileges to perform their role and no more, often for a limited time. Unfortunately, it is often not applied correctly, leading to overprivileged accounts.
The result is that threat actors using compromised credentials can reach further into the breached organization – moving laterally and reaching sensitive systems. It makes for a much larger “blast radius” following a breach, and potentially greater damage. The same issue can also exacerbate the risk posed by malicious or even negligent insiders.
Identity sprawl is another major challenge. If IT doesn’t properly manage the accounts, credentials and privileges of its users and machines, security blind spots inevitably emerge. This increases the attack surface for threat actors, makes brute-force attacks more successful and overprivileged accounts more likely. The advent of AI agents and continued growth of IoT will greatly increase the number of machine identities that must be centrally managed.
Finally, there’s the threat from partners and suppliers to consider. That could mean an MSP or outsourcers with access to your corporate systems, or even a software supplier. The bigger and more complex your physical and digital supply chains are, the greater the risk of identity compromise.
A considered, multi-layered approach to identity security can help mitigate the risk of serious compromise. Consider the following:
Most of the above recommendations form a Zero Trust approach to cybersecurity: one posited around the notion of “never trust, always verify.” It means that every access attempt (human and machine) is authenticated, authorized and validated – whether inside or outside the network. And systems and networks are continuously monitored for suspicious activity.
This is where a managed detection and response (MDR) tool can add tremendous value. A 24/7/365 team of experts keep a close eye on your network, flagging any potential intrusion rapidly so it can be contained and managed. Best practice identity security starts with a prevention-first mindset.
Sign up for our newsletters
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。