Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • "You Are The Weakest Link - Goodbye!" Reduce External Attacks current page
Link copied

"You Are The Weakest Link - Goodbye!" Reduce External Attacks

Apr 21, 2016
Author:
Mcannard
Martin Cannard
Blog banner default
"You Are The Weakest Link - Goodbye!" Reduce External Attacks
Mcannard
Martin Cannard

Weakest Link

A recent quote from Rob Joyce, Head of the NSA's Tailored Access Operations: “Don’t assume a crack is too small to be noticed, or too small to be exploited” he said when talking about his role in testing security for the nations networks. “We need that first crack, that first seam. And we’re going to look and look and look for that esoteric kind of edge case to break open and crack in.”

It’s not just about compliance.

We tend to think that satisfying compliance makes us secure, when it is really just the minimal amount of due diligence that should be performed.

Time and time again, we see headlines proclaiming extensive attacks on the very organizations that we regularly interact with as part of our personal lives. Shopping, movies, games. It’s very hard not to interact with companies that store even the smallest amount of our personal data these days.

Yet, in most breaches the data we hold so near and dear to our hearts is not always extracted through gaping holes. It’s fair to say that all large organizations have security problems in place, whether through compliance, due diligence, or a mixture of both. It’s the cracks we have to worry about.

It could be an unpatched system, an application susceptible to malware; stolen credentials that allow external access to a single system inside the firewall boundary. Just one system. Just one application. “That first crack, that first seam.”

So hackers have got to that single system. What do they do now?

  1. Look for, and try to attack privileged accounts that are vulnerable.
  2. Establish an attack vector to gain access to the accounts.
  3. Identify privileges that extend beyond the boundary of the system they are on
  4. Rinse and repeat.

Hackers will slowly move through the organization system by system, crack by crack. They may take years to execute, but these low and slow attacks fly under the radar, and with more and more organizations capping log retention to as little as 12 months, I am sure there are many ‘accidents’ just waiting to happen out there.

Privileged Access Management Security Strategies That Can Help

The good news is that you can mitigate the risk of external attack through solid privileged access security management. PowerBroker Password Safe allows you to:

  • Scan your network - Ensure that forgotten privileged accounts on endpoints are discovered, and brought under management.
  • No account gets left behind – Create a common policy framework that makes sure that accounts that get brought under management stay under management.
  • Make sure access is authorized – Leverage Adaptive Workflow Control to restrict network connections to ensure that the people logging onto your systems originate from the correct location.
  • Audit what users are doing – Video record all user interaction to systems potentially exposed to the outside. Log all keystrokes, and allow rapid forensics to pinpoint what was typed and what was seen.

PowerBroker Password Safe allows the dynamic assignment of just-in-time privileges via Adaptive Workflow Control, allowing organizations to lock down access to resources based upon the day, date, time, and location. By limiting the scope to specific runtime parameters, it narrows down the window of opportunity where someone might be exploiting misappropriated credentials. For example, if you normally expect the HVAC contractor to be logging on from particular systems, you can ensure that access is only permitted from predefined allowable address ranges. Similarly you can set up policies to control when the accounts are accessible, and alert when specific access policies are invoked.

On top of granular access controls, PowerBroker Password Safe ensures managed accounts have their passwords regularly rotated, even upon release – every password issued can be a one-time password for security.

The product also has an integrated session manager (at no extra charge) that can automatically log users onto resources without ever revealing the password, record all video and keystrokes for later playback, and allow real-time session monitoring, with options to remotely manage/disconnect active sessions.

To help you identify and address the weak links in your organization, we’ve partnered with Nick Cavalancia at Techvangelism to develop an eBook “External Attacks and Privileged Accounts: 5 Steps to Control the Threat Potential.” Download chapter one, titled "Understanding The Threat Potential: External Attacks and Privileged Accounts” today.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • Deploying Privilege Guard with NetIQ GPA
    Oct 20, 2017 Deploying Privilege Guard with NetIQ GPA
    Blog
    1m
  • Top 20 Most Popular Webinars of 2022 – BeyondTrust Edition
    Dec 21, 2022 Top 20 Most Popular Webinars of 2022 – BeyondTrust Edition
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.