Securing identity end to end
For CISOs, identity leaders, and the platform owners who hold the directories
3 June 2026
The modern breach rarely opens with an exploit. It opens with a login — a phished password, a reused credential, a service account nobody remembered — and from that point the attacker is not breaking anything. They are using the systems exactly as designed, as someone the systems trust. Which means identity is not one control among many; it is the terrain the whole defence stands on. This playbook is about holding it end to end.
1. The coverage gap
Most organisations have MFA. Almost none have it everywhere — and everywhere is the standard, because attackers do not queue at the protected front door. The gaps are predictable: legacy applications and protocols that cannot speak modern authentication, administrative interfaces reached from inside the network, command-line and machine access paths that never met a prompt. Map real authentication traffic against MFA enforcement and treat every uncovered path as what it is: the door that will be used. The Essential Eight puts MFA near the top for a reason; the maturity levels are a coverage question, not a purchase question.
2. The identities that are not people
For every human identity, a mature estate carries several that are not: service accounts, application identities, integration credentials, scheduled jobs. They are the worst-governed population in most directories — unowned, unrotated, over-privileged, and invisible until one is compromised. Inventory them, name a human owner for each, scope them to least privilege, and rotate or vault their secrets. Then hold the line as AI agents join the population: an agent with credentials is a non-human identity with initiative, and it inherits every discipline on this list before it inherits any access.
3. Cutting off lateral movement
The first credential an attacker lands on is rarely the one they want. The campaign is sideways: from workstation to server, from user to admin, on legitimate credentials that raise no alarm. The counters are structural. Tier the estate so administrative credentials never touch the machines where ordinary work — and ordinary phishing — happens. Scope admin rights to the task and the hour, not the person and the year. And make privileged paths the most heavily authenticated journeys in the organisation, because they are the destination the whole attack is walking towards.
4. Watching identity in use
Prevention leaks; watching catches what leaks. Identity misuse has a shape — logins at machine speed, from new places, in impossible sequences; service accounts doing interactive things they have never done; dormant identities waking. The directory and the authentication logs already record most of it. The work is turning that record into questions someone actually asks: which identities behaved out of character this week, and who checked?
5. The obligations frame
None of this is optional posture. CPS 234 expects controls commensurate with the criticality of the information assets identities can reach; the Essential Eight makes MFA and privileged-access restriction explicit; and every breach-readiness plan in the building assumes the access map is known. Identity work is the rare investment that shows up in every one of those conversations at once — and the first one a serious incident review will ask about.
6. The first 90 days
Map authentication coverage honestly and list the uncovered paths — that list is the program. Inventory the non-human population and name owners for the twenty most privileged. Break the flattest lateral path with tiering or scoped admin. Stand up one identity-misuse question on a weekly cadence. And when the first AI agent requests credentials, treat the request as the test of everything above: scoped, owned, watched, or not issued.
The perimeter did not disappear. It moved into the directory — and it logs in.