Privileged Access Management: The keys to the kingdom

17th July 2026BlogAJ Thompson

Are you ready to get in touch?

Request a Call back

Privileged Access Management (PAM) best practices are how organisations control who can reach their most sensitive systems — admin credentials, service accounts and root access. Get it wrong and a single stolen login can hand an attacker the entire estate. This article explains why privileged access management failures are so costly, what two major breaches teach us, and three concrete steps to close the gaps.

Key takeaways

  • Forrester estimates at least 80% of data breaches involve compromised privileged credentials, yet 52% of organisations have no password vault in place, according to Centrify.
  • Uber’s 2022 breach began with a hard-coded admin credential sitting inside its own privileged access management tool, exposing AWS, Google Workspace and Slack.
  • Target’s 2013 breach, which started with a stolen vendor credential and no network segmentation, cost $291 million and both the CEO and CIO their jobs.
  • DORA, NIS2 and the UK Cyber Security and Resilience Bill all treat privileged access management as a demonstrable control, not an optional policy.

When the keys fall into the wrong hands

Most organisations spend a fortune fortifying the front door while leaving the master keys on a desk inside. Those master keys are privileged accounts.

In 2022, an attacker bought a contractor’s stolen credentials. They then wore down the contractor’s MFA defences before finding a PowerShell script on a network share. That script contained hard-coded admin credentials for Uber’s privileged access management system. That single discovery handed over AWS, Google Workspace, Slack and more. The tool designed to protect privileged access became the single point of failure because its credentials were never vaulted or rotated.

Target’s 2013 breach tells the same story from the opposite direction. Attackers stole network credentials from HVAC contractor Fazio Mechanical. They then walked straight into Target’s network, because there was no segmentation between vendor access and payment systems. As a result, they exfiltrated 40 million card accounts and personal data on around 70 million customers. The total cost reached $291 million. Both the CEO and CIO resigned. One vendor’s unmanaged privileged access brought a global retailer to its knees.

A single key connected to four padlocks, showing one privileged credential unlocking multiple systems.

The uncomfortable truth about Privileged Access Management

Privileged access management best practices are critical, yet in practice they are rarely followed consistently. Gartner predicted that 75% of security failures would stem from inadequate management of identities, access and privileges. However, in one Centrify survey, 52% of organisations still had no password vault in place.

In regulated sectors, financial services, healthcare, and legal, that gap is not just a security risk. It is a compliance failure. DORA, the FCA’s operational resilience rules, HIPAA and SOX all demand demonstrable control over who can access critical systems. The NCSC’s 10 Steps to Cyber Security treats privilege management as a foundational control, not an optional extra. The OCC fined Morgan Stanley $60 million for failing to oversee access to decommissioned data. Hoping you will not be next is not a strategy.

Three steps to take right now

Discover and govern every privileged account

You cannot protect what you cannot see. Start by mapping every privileged account — human and machine — across your on-premises and cloud estate. Then apply least privilege immediately. Eliminate standing admin rights in favour of just-in-time access that auto-expires. If your team does not know how many privileged accounts exist today, that is where you begin.

Vault, rotate and enforce MFA

Credential vaulting and automatic rotation eliminate the hard-coded, shared passwords that brought Uber down. In addition, enforce mandatory MFA on every privileged login — at the point of elevation and on the PAM console itself. Privileged session monitoring feeds your SIEM with the audit evidence regulators require. Therefore, vaulting and monitoring need to be treated as a single, linked control rather than separate workstreams.

Review, segment and repeat

Access rights accumulate silently, through role changes, onboarding, M&A activity and one-off grants that are never revoked. Quarterly access reviews are non-negotiable. For your highest-privilege accounts, review monthly. Equally, isolate third-party and vendor connections from sensitive environments. Target’s attackers moved from an HVAC system to a POS network because no one had drawn that boundary.

Is your organisation truly in control of privileged access?

If you operate in a regulated sector, financial services, legal, healthcare or the public sector, the question is not whether a regulator will ask about your privileged access management controls. It is when.

At Northdoor, we have helped organisations across the UK gain full visibility and governance over their privileged estate, without disrupting day-to-day operations. Find out more about our privileged access management solution or speak to our team today for a no-obligation Privileged Access Assessment. We will identify the gaps, size the risk and give you a clear, prioritised roadmap. Contact us or call 020 7448 8500.


AJ Thompson All Author's Posts
1

Our Awards & Accreditations