When the keys fall into the wrong hands
Most organisations spend a fortune fortifying the front door while leaving the master keys on a desk inside. Those master keys are privileged accounts.
In 2022, an attacker bought a contractor’s stolen credentials. They then wore down the contractor’s MFA defences before finding a PowerShell script on a network share. That script contained hard-coded admin credentials for Uber’s privileged access management system. That single discovery handed over AWS, Google Workspace, Slack and more. The tool designed to protect privileged access became the single point of failure because its credentials were never vaulted or rotated.
Target’s 2013 breach tells the same story from the opposite direction. Attackers stole network credentials from HVAC contractor Fazio Mechanical. They then walked straight into Target’s network, because there was no segmentation between vendor access and payment systems. As a result, they exfiltrated 40 million card accounts and personal data on around 70 million customers. The total cost reached $291 million. Both the CEO and CIO resigned. One vendor’s unmanaged privileged access brought a global retailer to its knees.
The uncomfortable truth about Privileged Access Management
Privileged access management best practices are critical, yet in practice they are rarely followed consistently. Gartner predicted that 75% of security failures would stem from inadequate management of identities, access and privileges. However, in one Centrify survey, 52% of organisations still had no password vault in place.
In regulated sectors, financial services, healthcare, and legal, that gap is not just a security risk. It is a compliance failure. DORA, the FCA’s operational resilience rules, HIPAA and SOX all demand demonstrable control over who can access critical systems. The NCSC’s 10 Steps to Cyber Security treats privilege management as a foundational control, not an optional extra. The OCC fined Morgan Stanley $60 million for failing to oversee access to decommissioned data. Hoping you will not be next is not a strategy.
Three steps to take right now
Discover and govern every privileged account
You cannot protect what you cannot see. Start by mapping every privileged account — human and machine — across your on-premises and cloud estate. Then apply least privilege immediately. Eliminate standing admin rights in favour of just-in-time access that auto-expires. If your team does not know how many privileged accounts exist today, that is where you begin.
Vault, rotate and enforce MFA
Credential vaulting and automatic rotation eliminate the hard-coded, shared passwords that brought Uber down. In addition, enforce mandatory MFA on every privileged login — at the point of elevation and on the PAM console itself. Privileged session monitoring feeds your SIEM with the audit evidence regulators require. Therefore, vaulting and monitoring need to be treated as a single, linked control rather than separate workstreams.
Review, segment and repeat
Access rights accumulate silently, through role changes, onboarding, M&A activity and one-off grants that are never revoked. Quarterly access reviews are non-negotiable. For your highest-privilege accounts, review monthly. Equally, isolate third-party and vendor connections from sensitive environments. Target’s attackers moved from an HVAC system to a POS network because no one had drawn that boundary.
Is your organisation truly in control of privileged access?
If you operate in a regulated sector, financial services, legal, healthcare or the public sector, the question is not whether a regulator will ask about your privileged access management controls. It is when.
At Northdoor, we have helped organisations across the UK gain full visibility and governance over their privileged estate, without disrupting day-to-day operations. Find out more about our privileged access management solution or speak to our team today for a no-obligation Privileged Access Assessment. We will identify the gaps, size the risk and give you a clear, prioritised roadmap. Contact us or call 020 7448 8500.