Purple Teaming on a Budget: Testing Defenses That Actually Fire
May 27, 2025Bill C-8 and the Coming Baseline for Canadian Critical Infrastructure
June 24, 2025Ask incident responders where modern breaches begin and the answer is remarkably consistent: identity. Across the first half of 2025, from credential-driven SaaS breaches to ransomware access brokers, the front door was almost always a stolen or abused login. In a world of cloud services and remote work, identity has become the real perimeter, and it deserves perimeter-grade defense.
Why the network boundary faded
Work no longer happens inside a defensible network. Staff access dozens of cloud applications from anywhere, on a mix of devices. What every one of those services has in common is that access is gated by an identity. Compromise the identity and location becomes irrelevant.
Hardening identity in practice
- Phishing-resistant multi-factor authentication. Move critical accounts to hardware security keys or passkeys.
- Conditional access. Evaluate each sign-in against device health, location, and risk signals.
- Least privilege and just-in-time. Do not leave administrative rights standing.
- Kill the weak paths. Disable legacy protocols that bypass multi-factor authentication.
Watch the machines too
Service accounts, API keys, and automation identities are often more powerful and less monitored than human accounts. Inventory them, scope their permissions tightly, rotate their credentials, and prefer short-lived tokens. Treat your identity provider as critical infrastructure: its logs are among your most valuable telemetry and its compromise can unlock everything downstream.
Takeaway
In the cloud era, identity is the perimeter. Move critical accounts to phishing-resistant multi-factor authentication, apply conditional access, remove standing privilege, and do not forget the machine identities attackers love. Guard your identity provider like the crown jewel it has become.
