Episode summary
Identity systems sit at the center of enterprise security, but they are also one of the first places attackers look when launching ransomware and other disruptive cyberattacks. In this eSecurityPlanet video podcast, Marty Momdjian, Global Field CTO at Semperis, joins the conversation to discuss how attackers compromise Active Directory and Entra ID, what warning signs security teams should watch for, and how organizations can contain and recover from identity-based breaches before they become full-scale business crises.
The discussion will explore why identity has become Tier 0 infrastructure, where incident response plans often fall short, and how organizations can improve cyber crisis readiness by preparing for identity recovery before an attack occurs.
Key takeaways
- Identity is Tier 0 infrastructure. Active Directory, Entra ID and other identity systems underpin access to critical applications, data and security tools.
- Attackers target identity early. Compromised user, administrator and machine accounts can enable reconnaissance, lateral movement and privilege escalation.
- Fast containment depends on visibility. Security teams need to quickly understand affected identities, business impact and hybrid environment dependencies.
- Identity recovery must be tested. Realistic simulations can expose gaps that traditional tabletop exercises and general backup plans may miss.
FAQs
Why have identity systems become a primary target for cyberattackers?
Identity systems control access to applications, infrastructure, data and business services. Attackers know that compromising an identity can be more effective than breaking into a single endpoint or application. By logging in as a legitimate user, administrator or machine account, they may be able to move through an environment, conduct reconnaissance and remain undetected.
What are attackers trying to accomplish during the first hours of an identity-based attack?
Attackers typically look for privileged accounts, opportunities for lateral movement and paths to domain administrator access. A compromised privileged account can give an attacker broad access to systems and data while also allowing them to disable security controls, interfere with incident response and expand the scope of the attack.
Why are identity-based attacks especially difficult to contain in hybrid environments?
Hybrid environments connect on-premises identity systems, cloud platforms, SaaS applications, machine accounts and nonhuman identities. An account with on-premises access may also have access to critical cloud applications. This interconnectedness makes it harder for security teams to understand attack paths, identify dependencies and determine what can be safely disabled without causing wider business disruption.
Why should identity recovery be a priority during incident response?
If employees and responders cannot log in, they may not be able to access backups, security tools, communication platforms, incident response playbooks or other recovery resources. Restoring identity services such as Active Directory, Entra ID, multifactor authentication and the organization’s identity provider may be necessary before the broader response and recovery effort can begin.
What is the most important step organizations can take to prepare for an identity-based attack?
Organizations should move beyond discussion-based tabletop exercises and conduct realistic recovery simulations. These exercises should test whether teams can restore identity systems, security tool accounts, machine accounts and critical applications in an isolated environment. Simulations can reveal technical dependencies, communication gaps and recovery delays that may not surface during a traditional tabletop exercise.
Episode Transcript
Ken Underhill: Welcome to the eSecurityPlanet podcast. I’m Ken Underhill. I’ve spent more than 20 years in IT and cybersecurity. Today, we’re going to talk about a critical issue: What happens in the first 24 hours of an identity-based attack?
Joining me is Marty Momdjian, general manager of Ready1 and strategic initiatives at Semperis. Marty helps organizations prepare for and recover from the types of incidents we’ll be talking about today. We’ll also discuss what security teams need to watch for, how they can contain damage and how to recover quickly.
Marty, thanks again for taking time out of your busy day to join me.
Marty Momdjian: Absolutely. Thank you for having me, Ken.
Underhill: I want to jump right into it. For several years now, we’ve heard the narrative that identity is the new perimeter. Why do you think identity systems have become such a critical focus for attackers? As a second part of the question, why should enterprises now look at Active Directory and Entra ID as tier-zero infrastructure?
Momdjian: The simple answer is that everything we do revolves around logging in.
I look at it this way: Every day when we wake up in the morning, whether it’s a workday or not, what’s the first thing we do? We take out our phones. We log in to check email. We log in to our phones. We log in to check our calendars.
Then I get to my desk. Most of us work from anywhere. We’re traveling or working in an office, but we’re logging in. Ninety percent of organizations are logging in to Active Directory.
Everything we do in technology requires us to log in to do something—to be productive and to communicate with peers, customers, partners and other organizations.
The main reason identity is such a critical focus right now is that everything revolves around logging in. Machine accounts, applications, infrastructure and other technology must log in to do something.
Threat actors know that. What is the No. 1 impact they could have on you or any organization? Preventing you from logging in and bringing things to a grinding halt.
If you can’t log in, your business can’t continue. At scale, if your entire business can’t log in, you don’t have a business to operate at the end of the day. It’s also one of the most complex areas because of how interconnected technology is.
Underhill: You mentioned the machine aspect—the nonhuman identities—which really expands the attack surface these days.
When you’re responding to ransomware or another type of major incident, how often do you and your team see identity attacked early by threat actors in the attack chain? Especially when we’re thinking about hybrid Active Directory and Entra ID environments, how often are threat actors attacking identity very early in the attack chain?
Momdjian: Almost every time.
There are two aspects to it. Historically, it has been: Why do I need to break in when I can just log in? I come from the world of incident response. Why do I need to break in when I can log in as you?
I can log in as you. I can log in as me. I can log in as a machine account and try to go undetected.
Our detection mechanisms in cybersecurity are built around abnormalities or certain things happening at an endpoint, server, application or sensor. Then we start responding to them.
But if I’m logged in as you from where you’re supposed to be, how do you really detect that?
Threat actors and adversaries know that if they can log in as you, they can sit in your environment, conduct reconnaissance and figure out what you have, where you have it and how you have it. That’s the first aspect.
The second aspect is that we’re seeing a significant evolution right now. Threat actors are not attacking individuals as much as they are attacking the underlying identity infrastructure.
Why would I try to compromise Underhill Inc. as Ken when I could compromise the underlying identity infrastructure and get to every company using that infrastructure in the cloud, especially in a hybrid environment?
Everybody has some kind of hybrid identity provider hosted somewhere else, whether it’s Microsoft, Ping or Okta. Those are great technologies and solutions, but if I can compromise one, I can compromise all. The goal is to remain undetected for as long as possible.
There’s also a significant shift happening now. Historically, we were always worried about dwell time. An adversary logs in as me, bypasses multifactor authentication and remains in the environment without doing anything too extreme so they don’t get detected by endpoint detection and response sensors and tools.
Now, dwell time is shrinking because of AI at scale and the tools threat actors have available. The same tools available to us are also available to threat actors.
Dwell time is shrinking significantly. I don’t have to just log in as you. I can log in as you, pivot, exploit vulnerabilities and pursue a specific attack chain.
Even when I’m detected, I’m still logged in. Now I’m going to gain access to multiple accounts and multiple machine accounts for which detection mechanisms don’t exist at scale.
Underhill: You talked about reconnaissance, pivoting and lateral movement. In the first few hours of an identity-based attack, what are attackers typically trying to accomplish inside the identity infrastructure?
What are some of the warning signs or key things a security team should watch for that could indicate an identity-based incident is occurring?
Momdjian: No. 1 is privileged accounts—lateral movement and privileged accounts.
If I can get my hands on your domain access, domain administrator account or any type of privileged account that can pivot to domain administrator, I can get the keys to your kingdom. That’s No. 1 on the list.
Whether it’s an on-premises or hybrid environment, why would I go after one server or application to obtain critical data for exfiltration when I could go after all of it?
If I were the bad guy—which I’m not—I wouldn’t want to log in as Ken. I would want to log in as Ken’s administrator to gain access to everything Ken can access, as well as everything the other administrators can access, and bypass security controls.
If I obtain a privileged account, I can disable your security controls. That is always one of the first things that happens during the first couple of hours of a major cyber incident.
The second part is that the days of detecting something at an endpoint and determining how a bad actor entered and gained access are gone.
Now, attacks are targeting the core identity infrastructure. It’s Active Directory, Entra ID and your identity provider. Attackers are gaining access somehow, and if the infrastructure is in the cloud, you don’t have the same detection mechanisms anymore.
We’re much slower to respond, while attackers are coming at organizations, at us and at everybody at machine speed. We’re responding at human speed because of the legacy technology available to us.
We have to shift that mindset. When there is abnormal behavior, we have to detect and respond much faster and determine what the attack chain looks like before the threat actors do.
It all comes down to privileged access, privilege escalation and identity attack paths. It’s everywhere, especially in hybrid environments. I don’t know anybody who doesn’t have a hybrid environment.
If an identity has access on-premises, it probably has access to a critical business application in the cloud, whether that is a private cloud, public cloud or software-as-a-service environment.
I can have segmentation, security tools and everything else in place. But if a threat actor is logged in as an individual and you can’t detect it—and the environment is hybrid—it becomes infinitely more complex.
I have to determine what my attack paths are before the attackers do. I have to put controls and detection mechanisms in place along the attack paths to each application, my SaaS infrastructure and my on-premises infrastructure.
I also have to understand the codependencies on-premises and in the cloud for each identity, along with all the machine accounts we spin up and the nonhuman identities behind those workloads.
Underhill: Let’s pivot to the security leadership side. If we’re looking at the first 24 hours of an incident, what are the most important things an enterprise security leader needs to understand quickly to assess the scope, overall business impact and operational risk?
What data do they need to report to other members of the executive team or even to the board? What should they be looking at during those first 24 hours?
Momdjian: My go-to is: Don’t treat it as specific business applications or business processes that affect people or revenue.
Think about your tabletop exercises and simulations. It now comes down to the speed of the response.
What information do I need within the first 15 minutes of an incident so I can make decisions and take those decisions to leadership?
If A, B and C happen, what information do I need to quickly determine the business impact? I have to react very quickly.
Historically, incident response and crisis response involved metrics for severity and escalation paths. You might have had an hour to stand up incident response and another two or three hours to conduct quick forensic analysis, determine the impact or produce a business impact analysis document.
All of that has gone out the window.
Organizations used to have 24 hours to figure out what was happening before responding. Now, you probably have an hour or two at most.
If it’s a nation-state-sponsored threat actor that is highly advanced and represents a persistent threat in your environment, you have minutes to hours to respond.
Each organization needs to determine how quickly it can detect an incident and, more importantly, how quickly it can stand up its incident response team, notify the necessary people and collect information.
Then it must start making decisions very quickly.
What information do I need to make those decisions? What is the impact on my business? If I take actions A, B and C, will I affect the business on a smaller scale?
I may have to sever the hand to save the body and turn something off to cut off the adversary’s access while I determine what is happening. But perhaps 70% or 80% of the business can continue operating.
Underhill: You mentioned the visibility challenges of hybrid identity environments. How does the complexity of those hybrid environments affect visibility, containment and the response decisions that must be made during a live incident?
Momdjian: My mindset is: The faster you detect, the faster you respond. The faster you respond, the faster you contain. The faster you contain, the faster you recover.
You should never compromise on the time it takes to contain an incident while waiting for approvals. You should contain it as quickly as possible, even if that includes stopping certain business services while you determine what is happening before it’s too late.
Once you detect something, the complexity becomes apparent.
Yes, I have my account and the applications I use every day. Those are the basics of what I do at work. I’m communicating, collaborating and performing certain tasks.
But what else is my account tied to? It’s probably tied to 10 different nonhuman identities, all the things required to run my agents and everything operating in the background that I’m spinning up, whether it is governed or not.
Most organizations still haven’t wrapped their heads around identity governance for nonhuman identities. It’s still new and expanding rapidly.
Organizations need to understand the governance around those identities.
If I’m going to disable or stop something so I can conduct forensic analysis and respond as quickly as possible, I shouldn’t focus only on the business impact. I should focus on how quickly I can notify the people who will be affected so they can move to downtime procedures.
Technology changes weekly, monthly and yearly. Whatever you document now will probably be outdated in six months.
Put processes in place that allow you to notify stakeholders immediately. They should know what to do, rather than relying on extensive documentation that will probably be outdated.
Underhill: From your experience, where do enterprise incident response and crisis management plans most commonly break down during identity-based incidents?
Momdjian: Threat actors will target the incident responder’s account.
Again, if I were the bad guy and gained access to an account, and I wanted to access your applications and infrastructure, I wouldn’t go digging around and trying to discover things anymore because I would probably get detected.
I would go after the incident responder’s or IT employee’s account.
When I gain access to that account, I want to access your incident response playbooks, documentation and contact information so I know what you’re doing.
We’re seeing this in the wild. Threat actors gain access to incident response runbooks, determine what your conference bridges look like and try to join those bridges.
They access your response documentation and downtime documentation.
If those materials aren’t offline—if they’re on SharePoint or Teams, and cybersecurity personnel or users can access them—the bad guys can probably access them, too.
When threat actors gain that level of access, they can say, “Here’s the bridge they’re on. I’m going to join it and stay one step ahead.”
Or they can wipe out your runbooks and playbooks so you no longer have them.
Underhill: Many organizations have a good handle on restoring more traditional infrastructure. For example, applications or endpoints may go down.
Why is identity recovery often more difficult than organizations expect compared with restoring more traditional infrastructure?
Momdjian: The No. 1 rule is: If I can’t log in, I can’t conduct incident response.
We always forget that there are great incident response plans, escalation steps and matrices detailing what must be done depending on the type of incident.
But if identity goes offline, my incident response team can’t log in. They can’t respond. I can’t access my backups, playbooks, runbooks, logs or the other things I need.
All the cybersecurity tools we use require some kind of machine account in the background. If those machine accounts and service accounts go offline, I don’t have my responder tools.
The same thing applies to the crisis management team.
We always think, “If the system goes down, I’ll move to my offline communication platform.”
We’re discovering more and more that those platforms rely on the production identity provider because users must verify their identities. Without it, they don’t have a way to communicate.
The mindset has to shift. The first thing we need to do is restore identity so I can log in, access what I need, speak with the people I need to communicate with and ensure my response tools are working in the worst-case scenario.
Only then can I begin incident response.
We always skip over that phase and say, “I’m going to my backups.”
Great. But if the machine accounts used by my backup applications are compromised, I have to restore those machine accounts.
What do I need for that? Active Directory and Entra ID. I need my identity provider. I need multifactor authentication to function so I can log in.
All of that requires identity to function. It requires somebody to log in to something to begin the response, send notifications and perform other necessary tasks.
We keep forgetting that none of it works if the incident response team and other personnel can’t log in.
Underhill: You mentioned tabletop exercises earlier. I want to expand on that.
You talked about using tabletop exercises to determine when an incident may cause downtime and when a business should cut off an attack while perhaps keeping 70% or 80% of the business operating.
Is there a specific point organizations can use as a general guideline? At what point does an identity-based attack become more than a basic security incident and turn into a broader business crisis?
That could include extended downtime, potential compliance issues, the need to involve executive leadership or even a discussion of board-level risk.
Is there a general threshold organizations can use, or is it too specific to each organization?
Momdjian: It’s a mix of both.
It is specific to the organization and whether a particular application, business process or set of data is compromised.
An organization may need to escalate because the incident involves privileged information, not just privileged access. It may involve intellectual property, corporate information, consumer information and so on.
I look at it more simply. If an identity with access to privileged or sensitive corporate data is compromised, that should trigger an automatic escalation.
You have to make a quick decision to shut off access, stand up incident response, conduct forensic analysis and do whatever else is necessary.
There are also regulatory and compliance requirements at the state, federal or other levels. Those requirements should serve as another circuit breaker.
My go-to on the cybersecurity side has always been this: If a privileged account is compromised, or an identity with access to a cybersecurity or collaboration tool is compromised, immediately escalate.
That includes access to my security information and event management platform, security orchestration, automation and response platform, endpoint detection and response platform, firewalls or other tools.
You need a rapid and comprehensive response.
If a threat actor has gained access to a responder account or privileged account, the actor probably has much more access than you think.
At that point, skip the pleasantries. Escalate incident response to crisis response and tell the team to stand by.
We have a threat actor in the network. We may know where the activity is coming from, but we have to determine what else the actor accessed, and we may need to start shutting down services.
That means notifying business stakeholders within a certain amount of time. Sooner or later, the incident may become public.
Why did we shut down these services? Are our consumers affected?
Underhill: I remember when I worked in incident response for health care. If the electronic medical record system was affected, we often shut it down immediately and moved to paper charting until we could determine what was happening and assess the scope.
You mentioned compliance, and that ties directly to HIPAA and other health care compliance requirements.
From your experience, what separates organizations that recover quickly from identity-based attacks from those that experience prolonged operational disruption or other recovery challenges?
Momdjian: The organizations that recover quickly—the ones you don’t even hear about—have purpose-built identity recovery solutions and established processes.
The organizations you see in the news, including many I’ve worked with, didn’t think about having identity-specific recovery mechanisms, processes and solutions in place.
That’s why Semperis exists: to provide purpose-built recovery so that when the worst possible thing happens, an organization knows it can restore Active Directory, Entra ID, Okta and other identities as quickly as possible and begin responding to and recovering everything else.
Some organizations say, “I have a generic backup solution, or a backup solution that also handles identity.”
That’s great, but the recovery process probably relies on your identity infrastructure to function. You may not be able to recover identity because you can’t log in to the backup platform. It’s behind your identity provider, which relies on Active Directory.
It becomes a circular problem.
Organizations that recover quickly are also the ones that make decisions.
During major events I’ve worked on, when we decided to respond and isolate systems quickly, we recovered much faster.
We were stopping the bleeding. I come from the health care world, so it’s like tightening a tourniquet as much as possible to save a leg.
I might lose a couple of fingers or toes, but I know I’m going to save part of the leg because I can respond faster.
I may cut off my own access, but I also cut off the attacker’s access. Eighty percent of systems may still be functioning. I’m hobbling along, but my team has time to respond, conduct forensic analysis, collect logs and perform the necessary work.
Compare that with organizations that say, “Let’s determine the area of impact. What’s the splash damage? What’s affected? Is it small or large?”
By the time you figure that out, the adversaries are probably causing significant damage.
Their goal is to cause damage, exfiltrate what they can, eliminate your ability to restore from legacy backup infrastructure and prevent you from restoring hybrid environments.
Then they only have to knock out identity. They know it could take you 30 days to rebuild it from scratch.
Those are the organizations you see in the news, whether they’re in health care or another industry. They don’t have a way to restore the ability to log in and begin working.
Underhill: If you could recommend one change—and you can separate it by organization size—what would it be?
For organizations watching this, what is the one change they could make to improve their readiness for identity-based attacks?
Momdjian: Move beyond tabletop exercises and conduct actual simulations.
It’s great to sit around a table and discuss what could go wrong and how you would restore systems.
But organizations should conduct quarterly, annual or otherwise regularly scheduled exercises. Plan an actual downtime exercise and see how long it takes to restore identity in an isolated recovery environment or secure cloud infrastructure.
Go through your backups and say, “I’m going to restore Active Directory. I’m going to restore Entra ID. I’m going to restore my identity provider and multifactor authentication. I need to restore the identities used by my cybersecurity tools so they can help me conduct incident response.”
Then do it.
Do it in an isolated environment and see how complex it is and how long it takes. That’s the first thing you have to do before you can do everything else.
Most organizations still say, “I have this technology. I own this technology. I have this process.”
That’s great—if you can log in and use it.
Until you test it, bring everybody into a room, work through the technical process and determine what will and won’t work, you don’t really know.
Then escalate that information to the business owners and tell them, “It will take this long to restore identities, bring the application back online, ensure it is sanitized and preserve the forensic logs.”
This takes much longer than people expect. You have to actually do it.
Then tell the business owner, “When I’m finished, I need you to log in and tell me whether the application is working before anyone else is allowed back in.”
There is a big difference between recovery time objectives and recovery point objectives discussed around a table and what happens during an actual incident.
It’s like the difference between fantasy football and playing football while a 350-pound person is barreling toward you and you’re running for your life.
Underhill: Mm-hmm.
Momdjian: It’s a completely different ballgame.
Most organizations need to move beyond traditional tabletop exercises and say, “Let’s simulate the incident, cause some chaos in our environment and see what it really looks like. Which vendors do I need involved? What do I need to do?”
We don’t create enough of that chaos. We theorize about it. We check a box for cyber insurance, compliance, legal, risk or somebody else.
Then, when the bad thing happens, you don’t want to show up and say, “Yes, we did a tabletop exercise. We checked the box.”
The 350-pound person is still barreling toward me.
Long story short, tabletop exercises are great, but you have to actually do the work. Cause some chaos.
Don’t break the business, but conduct the exercise in an environment where you can safely do it. Show people outside IT and cybersecurity what is involved.
Most people who don’t work in identity don’t understand the complexity of restoring identities. That’s why purpose-built solutions exist to help with the work.
Even on the Semperis side, I talk about this all the time. Yes, you can use our solutions to reduce identity recovery time from weeks to hours, but significant work still needs to happen afterward.
You still have to conduct forensic analysis. You still have to restore machine accounts and nonhuman identities.
We’re introducing AI everywhere without understanding the complexities of the identities around it, and businesses are relying on those identities.
A tabletop exercise can’t account for all of that. You have to actually perform the recovery.
Underhill: I think that’s great advice.
I also like the football analogy because it made me think back to when I was a kid. I thought I was strong and tough, and I was going to block everybody.
You described a 350-pound person. There was a 300-pound kid who came barreling toward me, and I was knocked unconscious. It brought back memories, so thanks, Marty, for that.
Momdjian: That’s exactly what happens.
I’ve been in the middle of an incident response, and on day four, somebody walks up and asks, “Why is this taking so long?”
Because there is a freight train coming at me right now. The moment I turn the lights back on, that freight train is going to break through the wall and run us all over.
There’s a lot of work that needs to happen. Most organizations don’t realize it until it happens to them, and then they have to bring in external experts.
That can create an even bigger challenge because the responders and experts conducting incident response don’t know your business.
What we know is very specific: We can restore your ability to log in. Then you have to bring your business back online.
You have to communicate with your consumers and employees. It’s very complex.
The moral of the story is that tabletop exercises are no longer enough. You have to create that chaos to understand the pain so you can fix the problems.
It always comes back to: “I forgot about identity. I forgot about Active Directory. Wait, I can’t log in because my identity provider doesn’t work. It relies on Active Directory. Why isn’t my cybersecurity solution or out-of-band communication platform working? Because it has a machine account.”
Fifty things have to happen for that machine account to log in.
Underhill: You brought up a good point beyond just testing: communication.
Showing how long recovery actually takes creates visibility, especially for senior leadership, and helps get everyone in the company on the same page.
Marty, thanks for joining us today and sharing your expertise. You provided a lot of valuable information and several actionable steps for organizations.
Thanks to everyone who listened, and we’ll see you next time on the eSecurity Planet Podcast.
Momdjian: Awesome. Thank you, Ken.





