Back to Hub

Podcast: The First 24 Hours of an Identity-Based Cyberattack, featuring Semperis CTO Marty Momdjian

Transcription

Welcome to the ecurity planet podcast. I'm Ken Underh Hill. I've spent over 20 years in IT and cyber security. And today we're going to be talking about a critical issue. What happens in that first 24 hours of an identitybased attack? And so joining me is Marty Mumjen. He's general manager of ready 1 and strategic initiatives at Serus. Marty helps organizations prepare for and recover from the types of incidents we'll be talking about today. And we're also going to be talking about what security teams need to watch out for, how they can actually contain damage, and how to recover quickly.

So Marty, thanks again for taking some time out of your busy day to join me. >> Absolutely. Thank you for having me, Ken. >> So I wanted to just jump right into it. For several years now, we've heard the narrative, you know, identity is a new perimeter. So why do you think that identity systems have become such a critical focus for attackers? And second part of the question, why should enterprises now look at active directory and entra ID as tier zero infrastructure? >> I mean simple answer is everything we do revolves around logging in right.

Um, I kind of look at it this way. Every day when we wake up in the morning, work day, non-work day, what's the first thing we do, right? We take out our phones. We log in to check email. We log into our phone. We log in to check our calendar. And then I get to my desk or most of us are working, you know, from anywhere. Most of the time are traveling, being in an office, you're logging in. You're logging into, you know, 90% of organizations are logging into active directory.

Our focus on everything that we do in technology is you have to log in to do something to be productive. You know, uh talk to peers, customers, partners, other organizations. The main reason why it's such a critical point right now is everything revolves around logging in for us machine accounts, all the applications, all the infrastructure, all technology has to log in to do something. Thread actors know that, right? What's the number one impact that could cause you or any organization is prevent you from being able to log in to bring things to a grinding halt.

If you can't log in, your business can't continue at scale. If your entire business can't log in, you don't have a real business to operate at the end of the day. And it's also one of the most complex things because of how interconnected technology is. >> 100%. And and you mentioned a little on the the machine aspect there, right? The non-human identities which really really expands the attack surface these days when we're just talking about incidents.

So when you're responding to ransomware or some other type of major incident like how often do you see identity as being attacked early by by threat actors in the attack chain and especially when we're thinking of hybrid environments so those hybrid AD and entra ID environments. How often are you seeing these thread actors like actually attacking identity very early in the attack chain? >> Uh almost every time right there there's two aspects of it.

Historically it's been why do I need to break in? I come from a world of incident response. Why do I need to break in when I can just log in? I can log in as you. I can log in as me. I can log in as a machine account and try to go undetected. Because all of our detection mechanisms in the world of cyber security are built on abnormalities or certain things getting happen happening at an endpoint or a server, an application and a sensor detecting that abnormality and then we start responding to it.

But if I'm logged in as you from where you're supposed to be, how do you really detect that? and threat actors and adversaries know if I can log in as you, I can sit in your environment, I can go do reconnaissance, I can figure out what you have, where you have it, how you have it. That's the first aspect. The second aspect is we're seeing a big evolution right now of thread actors not attacking the individuals as much, but attacking the underlying identity infrastructure.

Why am I going to try to compromise, you know, Underh Hill Incorporated as Ken when I could go compromise the underlying identity infrastructure and get to every single company that's in that underlying identity infrastructure that's out there in the cloud, especially in a hybrid environment. Everybody has some kind of hybrid IDP that's hosted somewhere else. You know, whether it's Microsoft Ping, Octa, right? Great technologies, great solutions that are out there.

But if I can compromise one, I can compromise all is kind of the end goal and go as long as I can undetected. And there's also a big shift right now where historically we were always worried about dwell time, right? Adversary logs in as me, they bypass MFA, they're kind of in the environment not doing anything too crazy so they don't get detected based off the EDR sensors and tools that are out there. uh now that dwell time is shrinking because of the advent of just AI at scale the tools they have available same things we have available so do the threat actors right dwell time is significantly shrinking so now I don't have to just log in as you I could log in as you pivot go after vulnerabilities go after a very specific attack chain and even when I get detected I'm still logged in and now I'm going to gain access to multiple accounts multiple machine accounts that detection mechanisms don't exist for at scale >> you talked a little bit about recon and the pivoting of the lateral movement in the first few hours of an identity based attack.

What are attackers typically trying to accomplish inside of that identity infrastructure? And what are some of the the warning signs or key things that a security team should be looking out for to kind of see like, hey, we might be having an identity based incident right now. >> Number one is privileged accounts, right? Lateral movement privilege account. If I can get my hands on my your domain admin account or any type of privilege account that can pivot to domain admin, I can get the keys to your kingdom.

Number one on the list, whether it's onrem hybrid environment, why am I going to go after one server or application to get your critical data for Xfiltration? What I could go after all of it, right? If I was the bad guy, which I'm not, but if I was, I don't want to log in as Ken. I want to log in as Ken's administrator to gain access to everything that Ken has access to and all the other administrators and bypass any security controls because if I get a privileged account, I can disable your security controls.

That is always in the first couple of hours of a major cyber incident. Second part, Christian, it's not no longer are the days of hey, I'm going to go detect something at an endpoint and see how a bad actor got in and gained access. Now it's at the core identity infrastructure, right? it's active directory, it's intra, it's your IDP, they're gaining access somehow. And if it's in the cloud, you don't have the same detection mechanisms anymore. So, we're a lot slower to respond where attackers are coming at organizations, at us, at everybody at machine speed.

We're responding at human speed because of legacy technology than what we have available. We have to shift that mindset to say, you know what, when there is some kind of abnormal behavior, we have to detect and respond a lot faster and figure out what that attack chain looks like before the threat actors do. It's all now coming down to privileged access, privilege escalation, and attack paths for identity. And it's all over the place, especially with hybrid environments.

I don't know anybody that doesn't have a hybrid environment. If an identity has access on prem, it probably has access to some kind of application that's a critical business application in some fashion in the cloud somewhere. Whether it's my private cloud or not, whether it's public cloud, it's SAS. And it all comes back down to I can have all the segmentation security tools and everything in place. But if a thread actor is logged in as an individual that you can't really detect and it's hybrid, it becomes infinitely more complex.

So now I have to before they do figure out what my attack paths are and put controls into place in the texture mechanisms on my attack path to each one of my applications, my SAS infrastructure, my on-prem infrastructure and where are the code dependencies on prem and in the cloud for that identity and then all the 50 million machine accounts that we spin up and the non-human identities behind that for all the workloads. >> Let's pivot a little to the security leadership side.

If we're looking at just the first 24 hours of an incident, what are the the most important things in your opinion that an enterprise security leader needs to quickly understand to allow them to assess a scope? Um the overall business impact, overall operational risk of the incident, like for them to get the data they need to then go report to other leaders on the executive team or even to the board. What do they actually need to be looking at in that first 24 hours?

My go-to is don't treat it as specific business applications or business processes that impact people or revenue. Um, treat it as, you know, you do tabletop exercises and simulations and now it's coming down to speed to respond and what information do I need in that first 15 minutes of an incident occurring that I can make decisions and take those decisions to leadership. If A, B, and C happens, here's the information that I need to really determine the business impact very quickly because I got to react very quickly.

Historically, over the years of incident response and crisis response, it was always, hey, I have all these metrics for severity, escalation paths. I have an hour to stand up, incident, respond, and then I have two, three hours to figure out, do some quick forensics, figure out my impact, or I can make a business impact analysis, document, have a process. All that's gone out the window. Right nowadays, it's yeah, you did have 24 hours to figure out what is happening before you respond.

Now, you probably have like an hour or two max when an adversary or if it's a, you know, nation state sponsored threat actor who's very, very advanced and a real persistent threat in your environment. Now, it's minutes to hours to respond, right? Each organization needs to figure out how fast can I detect more importantly how fast can I stand up my IR team notify who needs to be notified collect that information and start making decisions very very very quickly and what information do I need to make those decisions is it what's the impact to my business or hey if I do a b and c I am going to impact the business at a smaller scale you know I'm gonna sever the hand to save the body and turn something off to cut off the adversar's access will I figure out what's going on but 80% or 70% of my business is going to continue. >> You mentioned a little bit on the visibility challenges of of the hybrid identity environments.

How how does that complexity overall of the hybrid environments impact you know of course you mentioned a little on visibility but you can expand on that but also containment as well as those actual response decisions when we've got that live incident. >> My mindset is the faster you detect, the faster you respond, the faster you contain, the faster you can recover. You should never compromise on the time it takes to containment and wait for approvals.

You should contain as quickly as possible, even if that includes stopping certain business services to figure out what is happening before it's too late. The faster you detect, we know detection mechanisms are in place. Then the complexity hits of yes, I have my account. I have my applications that I use every day, which are essentially the basics of what I'm doing at work dayto-day, right? I'm communicating and collaborating and doing certain things.

But what else is my account tied into? It's tied into probably 10 different non-human identities, all the stuff that I have to run my agents, all the stuff that I have in the background that I'm spinning up that could be governed or not. And most organizations still haven't wrapped their head around identity governance. When it comes to non-human identities, it's still so new and expanding so rapidly. It's really understanding what's the governance around that and then if I am gonna disable or stop something so I can do forensics and respond quickly as possible instead of saying hey this is the business impact it's going to cause it's how fast can I notify those folks that are going to be impacted so they can go to downtime and technolog is changing on a weekly and monthly yearly basis it's whatever you document now is going to be outdated in 6 months put in processes in place to say I'm going to notify the stakeholders immediately and they should probably know what to do, right?

Instead of focusing on I'm going to create all this documentation that will probably be outdated. >> From your experience, where do enterprise incident response as well as crisis management plans where where's where are those most common areas where those typically break down when we're talking about identity based incidents, >> the threat actors will target the [snorts] incident responder account. Right? Again, back to if I was the bad guy and I gain access to an account and I want to gain access to what applications, infrastructure, stuff that you have, I'm not going to go digging around and try to discover and find something anymore because I'm probably going to get detected.

What I'm essentially going to go after is I want the incident responders or the IT person's account. When I gain access to that account, I want to literally gain access to your incident response playbooks, your documentation for your contacts, so I can know what you're doing. And we're seeing this in the wild where threat actors are going to gain access and get your IR runbook, figure out what your bridges look like, try to join those bridges. They're going to get to your response documentation, your downtime documentation that you have.

If they're not offline, if they're on SharePoint, if they're on Teams, if Cyber has access to it or your users do, so do the bad guys more than likely. And when they gain that level of access, they're going to go in and they're going to say, "Okay, here's the bridge that they're on. I'm going to join it and I'm going to stay one step ahead or I'm going to wipe out your runbooks and playbooks so you don't even have them at the end of the day." >> A lot of organizations out there have a good handle on restoration of more traditional infrastructure, right?

So applications, my endpoints go down. Why do you think that identity recovery is often more difficult than a lot of these organizations expect compared to that more traditional restoration of of you know different infrastructure? number one rule is if I can't log in, I can't do incident response, right? We always forget about the fact that there's all these great incident response plan escalation steps, you know, create all these matrices of things that we have to do depending on the type of incident.

But you forget if identity goes offline, my IR team can't log in. They can't actually do a response. I can't get to my backups. I can't get to my, you know, playbooks or runbooks and my logs and things that I need to get to. All of the cyber tools that we have require some kind of machine account in the background, right? If those machine accounts and service accounts go offline, I don't have my responder tools. Same thing for the crisis management team, right?

We always have this thing in our head of, oh, if I go down, I'm going to go to my offline communication. We're discovering more and more that relies on your production IDP to work because you have to verify the identity. They don't have a way to communicate. Now, we have to shift our focus to say the first thing we're going to do is restore identity. So I could log in, get to what I need to talk to whoever I need to talk to and communicate with and make sure my tools for response are actually working in the worst case scenario so I could start doing incident response.

Right? We always skip over that phase and say I'm going to go to my backups. Great. My machine account gets compromised for all my applications that are doing my backups. I'm going to restore those machine accounts. What do I need for that? Active directory and intra. I need my IDP, right? I need MFA to actually function so I can log in. All of that requires identity to function. All of that requires somebody to be able to log into something to start doing the response to start sending out notifications to start doing X Y and Z and we keep forgetting about the part.

None of that works if my IR team can't log in and other people can't log in. >> You mentioned earlier about table topping. just to kind of expand on on that a little bit because you talked about here's when an incident is is kind of becoming something around um you know like downtime etc. So for example you were talking about table topping to know when your particular business when you should cut off you know the attack and you know keep maybe 70 80% of the business still operating while while dealing with that.

So the question I wanted to ask is at what point like is there a specific point that's kind of a generic point organizations watching this can can take away but at what point does an identity based attack become more than just like a a basic security incident and kind of turns into that broader business crisis where we're talking about the extended downtime potential compliance issues where we might need to pull in executive leadership or even you know there's there's a discussion of board level risk like is there a certain point that that your generic organization could take away out there or is it too specific to a particular organization? >> It's a mix of both.

It is specific to organizations where they look at it as if this application or business or this data gets compromised. It's hey I got to actually escalate this up because it's privileged information not just privileged access it's IP information it's corporate information their consumers and so on. I look at it as a more simple aspect of if an identity is compromised that has some kind of access to privileged data, corporate data that is specific to them, automatic escalation, right?

Because you got to make a quick decision to shut some type of access off, stand up incident response, do forensics, do whatever you need to do. And if there's regulatory and compliance and stuff you have to adhere to on the state, federal, whatever level that you have to adhere to should be one circuit breaker. My go-to has always been on the cyber side. If a privileged account is compromised or if an account or an identity is compromised that has access to some kind of cyber security tool or collaboration tool that is involved like my SIM, my sore, my edr, my firewalls, whatever immediate escalation because you need maximum and quick response to that because if a thread actor gained access to a responder account or a privilege account that means they have a lot more access than we think they do and at that point you know skip the pleasantries it's incident response escalate to crisis response and say get on standby.

We have a thread actor in the network. We know where it's coming from, but we got to figure out what else they got access to. And I got to start shutting services down, which means I got to notify the business stakeholders in x amount of time, which means sooner or later it's going to become public, right? Why did I shut these services down? Are my consumers impacted? Yeah. I remember when I did IR for healthcare, a lot of times if the EMR system was impacted, we immediately killed it and went to paper charting until we could figure out what what exactly was going on in the scope.

Um, and you mentioned compliance and that ties directly to HIPPA and other compliance for healthcare. From your experience, what separates the organizations that are able to recover quickly from these types of identity based attacks from those that are maybe have like a prolonged operational disruption or they've got different types of challenges in just the recovery itself. >> The organizations that recover very quickly that you don't even hear about have purpose-built solutions for identity recovery and they have the processes in place, right?

The ones that you see on the news, a lot of the ones that I've worked on didn't think about having identity specific recovery mechanisms and processes and solutions in place. Right? A company what the reason why seers even exist, right? Purpose-built recovery to say when the worst possible thing happens, I know I could get active directory intra octa identities back online as quickly as possible so I can start responding and recovering everything else. the organizations that just say I have my generic backup solution or some kind of backup solution who also happens to do just identity stuff that's amazing great but that recovery probably relies on your identity infrastructure to function and you're not going to be able to recover identity right you because I can't log into it because it's behind my IDP which relies on active directory it's this big circular thing we kind of go through the other part is there's the organizations that recover very quickly are the ones that make decisions big giant major events that I've worked on when we made a decision to respond very quickly and to isolate as quickly as possible.

We were able to recover a lot faster because we're stopping, you know, we're kind of I come from the world of healthcare, right? We're kind of pulling the tourniquet as hard as we can to try to save the leg at that point and we're saying, you know what, I might lose a couple of fingers or toes, but I know I'm going to save part of the leg because I can respond a lot faster. I just cut off my access, but I also cut off their access and 80% of things are still functioning.

I'm hobbling along, but my team has time to do response and forensics and get the logs and do what they need to versus the organizations that are still kind of like, well, let's go see how what the area of impact for this is. What's the splash damage? What's the, you know, what's impacted? Is it small? Is it large? Like, by the time you figure that out, the adversaries are probably causing a lot of damage. And the number one thing is let me cause the damage, exfiltrate what I can.

Take out your ability to be able to restore from your legacy backup infrastructure and be able to restore your hybrid environments and then I just have to knock out identity and I know it's going to take you 30 days to rebuild that from scratch. Those are the ones that you're seeing on the news whether it's healthcare or anything else, right? They don't have a way to actually get back to being able to log in and start doing something. So if there was one change that you would recommend, so if you had to pick one change and you can separate it by size of organization if you want to, but for the organizations out there that are maybe watching this, if there was one change they can make to improve their overall readiness for identity based attacks, like what is that that one change that that you would recommend for them? >> Move away from tabletop exercise and actually do simulations.

Right? It's great sitting around the table and discussing the things that could go wrong and how you're going to do restoration actually go and do a quarterly annual whatever you need to and plan an actual downtime and see how long it will take you to restore identity in an environment secure cloud infrastructure actually go through your backups and say I'm going to restore active directory I'm going to restore intra I'm going to restore my IDP my MFA I need to restore my identities for my cyber security tools that can help me do incident response and go do it.

Go do it in an isolated environment and see how complex it is and how long it takes because that's the first thing you have to do before you can do everything else. Most organizations still say, "Oh, I have this stuff. I own this stuff. I have this process." That's amazing. That's if you can log in and actually do it. But until you actually test that out and get everybody into a room, go through the technical aspect of it and see what's going to work and what's not, and then escalate that to the business owners and tell them, "Hey, it's going to take me this long to restore identities, get this application back online, make sure it's sanitized, make sure I have the forensic logs, right?

This takes a lot longer time than people expect." and actually sit around and do it and then take it to the business owner and say, "When I'm done with this, I need you business owner to be able to log into it and tell me if this application is working before you let anybody else back in." There's a big difference between RTO and RPO when it comes to sitting around the table and discussing it. It's like fantasy football versus actually going to play football and there's a 350lb dude barreling down at you while you're running for your life, right?

It's a whole different ball game. Most organizations need to move away from just doing traditional tabletops and saying, you know what, let's simulate it and let's make cause the chaos in our environment and see what it's really going to look like. Who are my vendors I need involved? What do I need to do? We don't we don't cause enough of that chaos. We just kind of theorize about it. We check off a box whether it's for cyber insurance, compliance, legal risk, or somebody.

And then when that bad thing happens, you don't want to just show up and say, "H, we did a tabletop. We checked off that box, but the 350lb dude is still barreling down at me right now trying to make sure I don't get to the end goal. So I long story short, like tabletops are great. Go do it. Go actually cause some chaos, right? Don't break the business, but do it in an environment that you can and show others that are not it or cyber security. Most nonidentity people don't understand the complexity of restoring identities, right?

That's why purpose-built solutions exist out there to help you kind of do the leg work of it. But even on the seer side, I talk about all the time. Yeah, you can use our solutions to restore identity from weeks and get it down to hours. But there's a bunch of work that needs to happen after. You still got to do forensics. You still got to restore machine accounts, non-human identities. We're introducing AI everywhere without understanding the complexities of the identities around it.

And businesses are relying on those, right? Like a tabletop can't suffice for that. You got to actually go do it. >> I think that's great advice. I also like the football analogy because I I was thinking back to as a kid. I thought I was really strong and tough and I was going to block everybody and you described a 350lb person. Uh there was like a 300lb kid that came barreling at me and I got knocked unconscious. So it it brought back memories. So thanks Mark for that. >> That's exactly what happens though.

Like I've been in the middle of incident response like day number four. Somebody walks up and goes, "Why is this taking so long?" Because there is a freight train coming at me right now. the minute I turn the light back on that freight trade is going to break through the wall and run us all over, right? I got to there's a lot of work that needs to happen. And most organizations don't realize it until it happens to them. And now you got to bring out the external experts, which then we cause an even bigger problem because those responders and the experts like when we do IR even, we we don't know your business.

What we know is very specifically we can get you to be able to log back in >> and then you got to get your business back online. You got to reach out to your consumers, your employees. It's very very complex. Moral of the story, tabletops are not good enough anymore, right? You got to cause that chaos to understand what the pain of it is so you can fix the problems. And it always comes back to, oh, I forgot about identity. I forgot about active directory.

Oh, wait. I can't log in because my IDP doesn't work. Well, it relies on active directory. Oh, why is my XYZ cyber solution not working or my outband communications? Because it has a machine account, right? 50 things have to happen for that machine account to be able to log in. Yeah, I think you you brought up a good point besides just testing things, the communication, right? Like showing here's how long it actually takes us. I think that visibility, especially for senior leadership, it kind of helps get everyone in the company on the same page.

Marty, thanks for joining us today and sharing your expertise. You shared a lot of good information and several actionable steps for organizations out there. Thanks for everyone that listened and we'll see you next time on the Ecurity Planet podcast. >> Awesome. Thank you, Ken.

This transcript was generated automatically from the video's captions and may contain errors.

Sponsored By Semperis Logo
The following is sponsored content. It may not reflect the views of our editorial staff.
Aug 4, 2026
19 minute read
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.