The old security model defended a building: firewall at the edge, trusted network inside. That building doesn't exist anymore. Your company is a set of cloud services reached from anywhere by anyone holding valid credentials — which means the perimeter is no longer a place. It's an identity. And attackers noticed before most defenders did: the modern breach starts with a login, not an exploit.
The audit worth running this week
Five questions expose most identity risk. Does every human have exactly one account — no shared logins, no "office@" mailbox three people use? Is MFA on everything — email, VPN, admin panels, and the line-of-business app everyone forgets? Do admin rights belong only to people whose job is administration? Can you list every service account and API integration with access to your systems — including the AI tools connected last quarter? And when someone left last month, was their access removed everywhere on day one, or is their account merely "disabled" in one system while six SaaS platforms still remember them?
MFA, but the 2026 version
MFA is table stakes; which MFA now matters. Push notifications fall to fatigue attacks — flood the phone until the user approves. SMS codes fall to SIM swaps. The current standard is phishing-resistant methods: authenticator apps with number matching at minimum, hardware keys or passkeys for admins and finance. And coverage means coverage — the one legacy account without MFA is precisely the one that ends up in an incident report, because attackers look for exactly that account.
Conditional access: context as a control
Modern identity platforms let you make login requirements depend on context: block sign-ins from countries you don't operate in, require stronger verification from new devices, deny legacy protocols that can't do MFA at all. For Microsoft 365 shops, a handful of conditional access policies eliminates whole attack categories — it's some of the highest-leverage configuration work in all of security, and it's sitting in a license most companies already pay for. (Making that license earn its keep is a running theme in our Microsoft 365 practice.)
The unglamorous ones: offboarding and service accounts
Two identity chores cause outsized damage when skipped. Offboarding has to be a checklist covering every system — email, SaaS, VPN, shared credentials rotated — executed the day employment ends, not the Friday after. And service accounts — the non-human identities that integrations, scripts, and now AI tools use — need an inventory, an owner, and scoped permissions, because nobody notices a compromised service account until it's been quietly working for months.
Why this is the priority
Identity work is unglamorous, mostly configuration, and pays off more than any appliance you could buy — it's the control set your insurer weighs most heavily and the foundation both your data protection and your AI security stand on. It's standing work inside our security practice; if the five-question audit above made you wince, that's the conversation to have.
