{"id":6849,"date":"2023-09-27T15:38:42","date_gmt":"2023-09-27T19:38:42","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=6849"},"modified":"2023-09-27T15:41:43","modified_gmt":"2023-09-27T19:41:43","slug":"the-best-defense-against-insider-threats-securing-active-directory","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/","title":{"rendered":"The Best Defense Against Insider Threats: Securing Active Directory"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6850\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg\" alt=\"Active Directory\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory-768x384.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><em><strong>Solutions Review\u2019s\u00a0<a class=\"fui-Link ___1idfs5o f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh ftqa4ok f2hkw1w fhgqx19 f1olyrje f1p93eir f1h8hb77 f1x7u7e9 f10aw75t fsle3fq f17ae5zn\" title=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" href=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Link Contributed Content Series\"><u>Contributed Content Series<\/u><\/a> is a collection of contributed articles written by thought leaders in enterprise software categories. Igor Baikalov of <a href=\"https:\/\/www.semperis.com\/\" target=\"_blank\" rel=\"noopener\">Semperis<\/a> walks us through the ins and outs of an insider attack and why preventing it starts with protecting the Active Directory.<\/strong><\/em><\/p>\n<p>Cybersecurity protections tend to focus on external threats. This approach is understandable, considering the increased sophistication and activity of both nation-state and criminal actors. However, organizations shouldn\u2019t overlook the rise of insider threats, which \u2014 whether intentional or unintentional \u2014 pose just as much danger as external threats to an enterprise, its data, and its ability to operate.<\/p>\n<p>Thinking of malicious outside actors as the enemy, at least in cybersecurity terms, is reasonable. Yet insider threats pose a serious risk to businesses precisely because they are trusted sources. By design, insiders have access to the organization\u2019s critical resources and sensitive data to fulfill their work duties.<\/p>\n<p>Although external malicious actors receive most media attention, insider threats are on the rise, having increased by 44 percent over the past two years. Negligence by employees or contractors accounts for 56 percent of those threats; 26 percent of the threats result from malicious intent. For two-thirds of companies, insider-related incidents occur up to 40 times per year, with each incident incurring an average cost of $484,931\u2014 a high price to pay for those who are unable to catch insider threats in time.<\/p>\n<p>Regardless of intent, many organizations lack the ability to identify vulnerabilities that can result in insider abuse. Furthermore, many are unable to perform post-breach forensics to close backdoors left by malicious insiders. It\u2019s clear that businesses need to improve their defenses against these growing and costly attacks.<\/p>\n<br \/>Widget not in any sidebars<br \/>\n<h2><strong>The Best Defense Against Insider Threats: Securing Active Directory<\/strong><\/h2>\n<hr \/>\n<h3><strong>Start by Securing Active Directory<\/strong><\/h3>\n<p>Access abuse is at the core of most insider threats, whether from employees, contractors, vendors, or partners. Anyone with permission to access critical business assets can potentially abuse that privilege, either through negligence or malicious intent.<\/p>\n<p>A good place to start shoring up identity and access controls is by securing and monitoring Active Directory (AD). AD is a prime target for attackers and is involved in nine out of ten cyber-attacks. Not coincidentally, AD is also the primary identity store for 90 percent of organizations worldwide. A recent survey of IT and security leaders found that 16 percent of enterprises use on-premises AD as their primary data store, and 80 percent use a hybrid of AD and Entra ID (previously Azure AD) or other systems. Only four percent don\u2019t use AD or Entra ID at all.<\/p>\n<p>AD\u2019s prominence in the enterprise means that its weaknesses can be exploited at any point that an employee, contractor, or other user has access. If an AD administrator doesn\u2019t follow all employee offboarding policies, for example, the departing employee\u2019s account could remain active after they\u2019ve left the company. An attacker could exploit that account\u2019s credentials to gain access, escalate privileges, and move through the network. The damage can be serious: 77 percent of the survey respondents classified the impact of AD being down as severe or even catastrophic.<\/p>\n<p>Such findings indicate that organizations need to adopt an identity-first security strategy that involves threat intelligence, behavioral signatures, continuous monitoring, and other techniques to address every phase of the attack cycle\u2014 before, during, and after an attack.<\/p>\n<h3><strong>Before an Attack<\/strong><\/h3>\n<p>Security teams looking to bolster their AD defenses should start with a thorough, realistic view of the identity attack surface. The goal is to uncover security vulnerabilities, such as accounts with expired passwords or accounts that are no longer active. As part of this effort, organizations should scan their IT environment for indicators of exposure (IOEs).<\/p>\n<p>IOEs refer to weaknesses in an organization\u2019s IT environment that an attacker could exploit. These indicators attempt to answer questions such as:<\/p>\n<ul>\n<li>Is AD misconfigured?<\/li>\n<li>Could an attacker exploit anything in your AD environment?<\/li>\n<li>Does anything in the AD environment place you in a more vulnerable state than you would otherwise be in?<\/li>\n<\/ul>\n<p>For instance, an AD misconfiguration could grant administrative privileges to every member of a team or grant privileged access to a vendor that doesn\u2019t need it. IOEs can help an organization find vulnerabilities that increase its susceptibility to an attack.<\/p>\n<h3><strong>During an Attack<\/strong><\/h3>\n<p>Continuous monitoring is also incredibly important to an organization\u2019s ability to identify indicators of compromise (IOCs). In most cases, handling or containing IOCs is more urgent than mitigating IOEs; IOCs can indicate a successful intrusion. These indicators attempt to identify whether any behavior in an organization\u2019s system might indicate an attack in progress. For example, 50 password reset attempts within one minute are atypical behaviors that could indicate an ongoing attack. Overall, IOCs enable organizations to identify whether they are under attack and even the path of the attack.<\/p>\n<p>If you think of an attack as a process rather than as a binary condition, you can better understand the benefits of uncovering these indicators. Launching a full-scale attack is not a one-step leap. An attacker must start from point A to reach point D. Attackers require several steps to, for example, compromise one system, then a security account, then a computer object, and so on, until finally gaining administrative control in Active Directory\u2014 the crown jewel for attackers. Identifying an attack in progress enables an organization to freeze the compromised identity, thus stopping the attack in its tracks.<\/p>\n<p>If an IOC flags an attack underway, organizations should continuously monitor for other IOCs, track risky changes to on-prem AD and Entra ID, and automatically roll back specific changes that could signal an attack. Among the actions to monitor for:<\/p>\n<ul>\n<li>Unauthorized access attempts<\/li>\n<li>Changes to permissions<\/li>\n<li>Abnormal network activity, such as unexplained additions to the Domain Admins group<\/li>\n<\/ul>\n<p>Continuous monitoring of the AD environment is critical, enabling an organization to promptly address potential security issues as they occur and helping to ensure the ongoing security of the environment.<\/p>\n<h3><strong>After an Attack<\/strong><\/h3>\n<p>In the wake of an attack, post-breach forensics are essential to understand the attack\u2019s behaviors and the weaknesses exploited as part of the attack. This step can also help organizations find and fix vulnerabilities, thus preventing them from being exploited in future attacks.<\/p>\n<p>By conducting a thorough post-attack analysis, organizations can answer questions that will help them understand how the attack occurred and where they might need extra protection:<\/p>\n<ul>\n<li>How did the threat actors get in?<\/li>\n<li>How did they compromise AD?<\/li>\n<li>How did they acquire domain credentials?<\/li>\n<li>Could they use additional exposures to regain access?<\/li>\n<li>Were there any back doors that needed to be closed?<\/li>\n<\/ul>\n<p><strong>\u00a0<\/strong>The insider threat is real and on the rise. The best security strategy is to address threats across the entire attack lifecycle\u2014 before, during, and after an attack. Because most advanced attacks use identity-based techniques, it\u2019s essential to continuously and proactively monitor AD to uncover threats and misconfigurations within the IT environment. Doing so will help you prevent insider threats\u2014 and enable you to quickly detect and respond should an attack happen.<\/p>\n<br \/>Widget not in any sidebars<br \/>\n","protected":false},"excerpt":{"rendered":"<p>Solutions Review\u2019s\u00a0Contributed Content Series is a collection of contributed articles written by thought leaders in enterprise software categories. Igor Baikalov of Semperis walks us through the ins and outs of an insider attack and why preventing it starts with protecting the Active Directory. Cybersecurity protections tend to focus on external threats. This approach is understandable, [&hellip;]<\/p>\n","protected":false},"author":918,"featured_media":6850,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,1],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Best Defense Against Insider Threats: Securing Active Directory<\/title>\n<meta name=\"description\" content=\"Igor Baikalov of Semperis walks us through the ins and outs of an insider attack and why preventing it starts with protecting the Active Directory.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Igor Baikalov\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/\",\"name\":\"The Best Defense Against Insider Threats: Securing Active Directory\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg\",\"datePublished\":\"2023-09-27T19:38:42+00:00\",\"dateModified\":\"2023-09-27T19:41:43+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ce28ba0158c26a22eb7cbb2026bd1cc4\"},\"description\":\"Igor Baikalov of Semperis walks us through the ins and outs of an insider attack and why preventing it starts with protecting the Active Directory.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg\",\"width\":800,\"height\":400,\"caption\":\"Active Directory\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Best Defense Against Insider Threats: Securing Active Directory\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Identity and Access Management Solutions | Solutions Review\",\"description\":\"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ce28ba0158c26a22eb7cbb2026bd1cc4\",\"name\":\"Igor Baikalov\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bd715be57844adeb089e782b3e4d1aa8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bd715be57844adeb089e782b3e4d1aa8?s=96&d=mm&r=g\",\"caption\":\"Igor Baikalov\"},\"description\":\"Igor Baikalov joined Semperis as Chief Scientist with more than 30 years of experience in data analysis and enterprise application development in areas, including insider threat and risk monitoring. Igor previously served as Senior Vice President of Global Information Security at Bank of America, where he was responsible for developing security intelligence and risk analytics solutions. Igor also held the role of Chief Scientist at Securonix, where he led the development of behavioral models of cyber-attacks and automated large-scale detection of cyber threats. Igor is the author of nine scientific publications and ten commercial patents. He holds a doctorate in molecular biology from the University of California, Los Angeles (UCLA) and a Master of Science in biophysics from the Moscow Institute of Physics and Technology, and he maintains CISSP certification.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/baikalov\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Best Defense Against Insider Threats: Securing Active Directory","description":"Igor Baikalov of Semperis walks us through the ins and outs of an insider attack and why preventing it starts with protecting the Active Directory.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/","twitter_misc":{"Written by":"Igor Baikalov","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/","url":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/","name":"The Best Defense Against Insider Threats: Securing Active Directory","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg","datePublished":"2023-09-27T19:38:42+00:00","dateModified":"2023-09-27T19:41:43+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ce28ba0158c26a22eb7cbb2026bd1cc4"},"description":"Igor Baikalov of Semperis walks us through the ins and outs of an insider attack and why preventing it starts with protecting the Active Directory.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/The-Best-Defense-Against-Insider-Threats-Securing-Active-Directory.jpg","width":800,"height":400,"caption":"Active Directory"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/the-best-defense-against-insider-threats-securing-active-directory\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"The Best Defense Against Insider Threats: Securing Active Directory"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Identity and Access Management Solutions | Solutions Review","description":"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ce28ba0158c26a22eb7cbb2026bd1cc4","name":"Igor Baikalov","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/bd715be57844adeb089e782b3e4d1aa8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bd715be57844adeb089e782b3e4d1aa8?s=96&d=mm&r=g","caption":"Igor Baikalov"},"description":"Igor Baikalov joined Semperis as Chief Scientist with more than 30 years of experience in data analysis and enterprise application development in areas, including insider threat and risk monitoring. Igor previously served as Senior Vice President of Global Information Security at Bank of America, where he was responsible for developing security intelligence and risk analytics solutions. Igor also held the role of Chief Scientist at Securonix, where he led the development of behavioral models of cyber-attacks and automated large-scale detection of cyber threats. Igor is the author of nine scientific publications and ten commercial patents. He holds a doctorate in molecular biology from the University of California, Los Angeles (UCLA) and a Master of Science in biophysics from the Moscow Institute of Physics and Technology, and he maintains CISSP certification.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/baikalov\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/6849"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/918"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=6849"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/6849\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/6850"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=6849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=6849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=6849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}