Secured by Design - IAM & Cybersecurity Podcast
Great security solution are designed from the ground up..
Secured by Design is a podcast where Santosh shares practical insights, frameworks, and perspectives on identity security and other aspects of cybersecurity.
Each episode breaks down complex concepts into actionable ideas for professionals protecting digital identities, designing secure systems, and leading security initiatives.
Because true security is built and not bolted on...
Secured by Design - IAM & Cybersecurity Podcast
How ITDR Can Prevent the Next Major Data Breach
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Summary
This episode explores the critical importance of Identity Threat Detection and Response (ITDR) in modern cybersecurity. Hosted by Santosh, it covers how identity infrastructure is the most targeted layer in enterprises, the rise of identity-based attacks, and practical strategies to enhance security posture.
Key Topics
The rise of identity-based attacks and their impact
The three pillars of ITDR: visibility, detection, response
Real-world examples: SolarWinds, MGM, Striker attack
How AI is transforming cyber threats and defenses
Practical steps to assess and improve your identity security
Chapters
00:00 The Reality of Data Breaches
02:29 Understanding Identity Threat Detection and Response (ITDR)
06:58 The Urgency of ITDR in Today's Landscape
10:33 Case Study: Learning from the Striker Attack
13:18 Key Takeaways for Organizations
16:09 Identity as the New Perimeter
Keywords
cybersecurity, ITDR, identity security, data breaches, identity attacks, zero trust, cloud security, breach prevention, cybersecurity strategy
Let’s Stay Connected
📧 Email: santosh@getitrightsoln.co.uk
🔗 LinkedIn: linkedin.com/in/kssantosh
Sixty three percent of data breaches last year involved compromised credentials. Not malware, not an unpatched vulnerability, not a sophisticated zero-day exploit, a username and a password. That's it. Think about it, the threat actor could have just gotten without tripping any wires and be sitting within your network. Moving quietly, mapping your environment, looking for the paths, the hidden paths through your identity infrastructure that lead to your crown jewels, your financial systems, your customer data, your active directory, the master set of keys to everything. This isn't hypothetical. This is the story of some of the most devastating breaches of the last five years. Solar wins, MGM resorts, and most recently the striker attack, which is still pending full investigation as we speak. These were huge organizations with big security teams who thought they were protected, but they were not prepared for an attack that came from the inside out. Welcome to Secure by Design, the podcast where we explore how identity and wider cybersecurity shape the foundation of our digital world. I'm Santosh, and in each episode, I'll share insights and practical perspectives on how we can build security into every layer of technology and business. From identity governance and zero trust to the latest in cloud and compliance. Let's dive into what it takes to design security at last. That stolen set of credentials belonging to one of your IT administrators that was exposed through, say, a spear phishing email that bypassed your filters because it was impeccably written using AI. That is the weapon of choice for the majority of the attackers targeting enterprise organizations right now. And the uncomfortable follow-up question that many security leaders can't honestly answer is this. If someone is using student credentials inside a network right now, would you know? If so, how fast would you do? Because for all your traditional security tools, that intruder looks like just like any other employee doing their job. Today we are talking about the emerging discipline in cybersecurity that answers that question. It's called identity threat detection and response or ITDR in short. So, identity threat detection and response. Let me break that down because that name is doing a lot of work. Every organization has an identity infrastructure at different scale that answers one fundamental question: Who are you and what are you allowed to do? This might include your identity provider, your identity governance and administration system, your privileged access management system, etc. Every user account, every service account, every machine identity, every API key, every permission and role and group membership that defines who can access what. This is your identity fabric, and it is, without question, the most targeted layer in the modern enterprise. Not your endpoints, not your network, your identities. Because if I can forge a valid identity, I can walk through your entire environment and I look legitimate doing it. Here's a problem that ITDR solves. Until very recently, identity infrastructure was largely a blind spot for security operations. You had endpoint detection and response EDR watching your laptops and servers. You had network detection and response NDR watching your traffic. You had cloud security tools watching your cloud workloads. But identity? Your active directory might be generating thousands of events per second. And unless someone wrote a very specific SIM rule and happened to be watching at the right moment, sophisticated identity attacks are effectively invisible. Gardner formally identified this gap and named ITDR as a distinct security category in 2022. And the market has responded fast because practitioners have been screaming about this problem for years. So, what does ITDR actually do? Think of it in three pillars. Pillar one is visibility. You cannot defend what you cannot see. ITDR gives you a comprehensive, continuously updated map of your entire identity estate, every account, every permission, and every trust relationship, every delegation. Pillar two is detection. This is where ITDR earns its keep. Using behavioral analytics, machine learning, and critically deep knowledge of how identity attacks actually work, ITDR platforms monitor your identity systems in real time for signs of malicious activity. Not generic unusual login alerts. Things like pass the hash, curb roasting, golden ticket attacks, etc. These are the identity attack playbooks that sophisticated threat actors use and they require specialist detection logic to catch. Logic that a generic siam simply doesn't have out of the box. Pillar 3 is response. Detection without response is just an expensive alarm. Good IDTR platforms let you act fast, automatically isolating a compromised account, revoking active sessions and tokens, forcing step-up authentication on suspicious access attempts, triggering a broader incident response workflow because in identity attacks, speed is everything. Every minute of attacker dwell time is another minute they are moving laterally, escalating privileges and dropping the payload. You want to cut that window from weeks to minutes. Why is this urgent priority? Why is identity a priority for organizations? Let me spend some time on urgency because I know that every CISO and IT leader listening to this has a long shopping list of finite budget. So why does ITDR jump to the top? Start with the data. The Verizon Data Breach Investigation Report, one of the most credible annual studies in our industry, has found year after year that the compromise credentials are involved in majority of data breaches. We are consistently talking about more than 60%. Microsoft's security intelligence data points to identity-based attacks as the single fastest growing attack vector across enterprise environments globally. The reason it's accelerating is structural. Think about what happened to enterprise IT over the last five years. The explosion of remote and hybrid work, mass migrations to cloud, the proliferation of SaaS applications. Your average mid-size enterprise is now running hundreds of SaaS tools, each with its own identity silo. Machine-to-machine identities go through APIs and automation, third-party contractors and supply chain integrations where vendors and partners need access to your systems. Every one of those trends creates more identity sprawl, more attack surface, and most importantly, more identities that nobody is actively watching. Here's another dimension that often gets overlooked in conversations about ITDR: the regulatory pressure, the NIS2 Directive in Europe, DORA for financial services, the SEC's cybersecurity disclosure requirements in the US, to name a few, and increasingly stringent requirements from cyber insurers who are now asking very specific questions about identity security controls when you renew your policy. What are your controls around privileged access? How do you detect anonymous identity behavior? What's your mean type to detect a credential compromise? These questions are showing up in board level reviews. ITDR is no longer just a technical conversation. It's a governance and compliance one. And then there's AI. I want to address this because it changes the threat landscape materially. Attackers are now using generative AI to create spearfishing campaigns at scale. Personalized, contextually accurate, virtually indistinguishable from legitimate communications. We are seeing AI-generated deep fake audio being used in wishing attacks to impersonate executives. Automated credential stuffing tools that can test millions of credential combinations against your login portals in hours. The volume and sophistication of IT-targeted attacks is increasing sharply. Organizations that are not building ITDR capability now are going to find themselves significantly exposed within the next 12 to 18 months. I had mentioned ITDR in my previous podcast detailing the striker attack. Let's see how ITDR could have saved an attack like Striker and prevent a wipeout of 200,000 devices. First, there's identity poster management. Before the attack even starts, ITDR finds the identity debt. It would have flagged if Striker had too many global admins or if certain accounts did not have just-in-time access. If an account doesn't have the power to wipe thousands of devices at a time on a random Wednesday morning, the attack never happens. Second, behavioral detection. When that admin account logged in, was it from a new IP? Was it a 3am? ITDR uses AI to say, hmm, this doesn't look normal. This admin seems to be acting like a stranger. Third, infrastructure monitoring. This is the big one for Stryker. The reports suggest that the hacker created new high-level admin accounts once they were inside. A good ITDR tool would have screamed the second and unauthorized global admin was created. It sees the identity fabric changing in real time. And finally, deception. ITDR can plant honey tokens, which are nothing but fake admin credentials that no real employee would ever touch. The second handler touched those fake keys, the alarm would have tripped before they even reach the in-tune console. The most important part of ITDR is the response. If Striker's SOC, I mean the security operation sector, had ITDR, they could have set up automated guardrails. Think about it. Why should any single human or account be allowed to wipe 200,000 devices in a few hours without a double approval rule or an automatic lockout? ITDR can be configured to say if this account wipes more than 10 devices in 5 minutes, kill the session and lock the account immediately. Striker might have lost 10 laptops in this case. Instead, they lost their entire global fleet. That R, the ability to automatically revoke tokens and kill suspicious sessions is the difference between a minor incident and a company-ending disaster. Look inside. Look inside your own environment before you do anything else. Commission an identity risk assessment. Map your active directory, your cloud identity providers, your privileged and service accounts, your permission structures. I guarantee you not come out of this exercise without being surprised or alarmed. The skeletons in the identity closet are almost always there. Stale accounts, overprivileged roles, misconfigured delegation, shadow admin paths, find them before the attacker does. Assess your gap. Honestly, assess your detection gap. If a threat actor compromised a legitimate set of credentials in your environment right now and started moving laterally, how long do you think it would take for you to know? If your honest answer is days or weeks or I'm not sure, you have a gap that needs addressing urgently. A well-implemented ITDR would close that window from compromise to detection from weeks to minutes. Thirdly, I would say act now. Treat this as a current risk, not a future project. The attackers targeting identity infrastructure are not waiting for your next budget cycle. The breaches happening right now are identity-led attacks against organizations that thought they had adequate security controls. Get an ITDR evaluation started in your environment. Most vendors would run a proof of concept. The insight you gain will make the business case self-evident. You'll be able to show your board and your CFO exactly what is in your environment that you are currently blind to. There are specialized ITDR vendors like CrowStrike, which their product is Falcon Identity Production, and then Sentinel1, which has a product called Singularity Identity, and SiloFort. Some identity vendors also have components within their IAM product that provide ITDR capability. For example, Microsoft has ITDR capabilities protected through their Microsoft Defender for Identity and also on some parts on Microsoft Intra ID protection. Okta provides Okta identity threat protection and Ping Identity delivers adaptive risk-based protection via the Ping One Protect. CyberAc extends its spam roots with the CyberAc Identity Security Platform. Identity is the new perimeter. You have said that as an industry for years. ITDR is what it looks like to actually defend it. Thanks for listening to Secured by Design. If today's episode gave you something to think about, subscribe and follow on your favorite streaming platform for more discussions on identity and cybersecurity. Please do consider taking your time to rate this show. I would really appreciate that. That is one of the best ways for you to support this podcast and help grow this by providing feedback. Please feel free to share it with your team. You can also connect with me on LinkedIn for updates and new episode releases. Until next time, stay secure, stay resilient, and stay secure by design.