The most dangerous person in your organisation right now is probably not a hacker. It is a former employee whose account was never deactivated, a contractor with more access than their role requires, or an administrator whose credentials were quietly stolen three months ago and have been sitting in a criminal forum ever since.
Identity is the new perimeter. Most organisations have not caught up to what that actually means.
For years, cybersecurity investment followed a predictable pattern: firewalls, antivirus, perimeter defence. The assumption was that the threat lived outside the network, and the job was to keep it there. That model began to break down as cloud adoption moved workloads outside the traditional perimeter. It collapsed entirely when remote work normalised access from unmanaged devices across untrusted networks. What remained was identity, the one control point that follows a user wherever they are or whatever device they use.
Attackers understood this shift faster than most defenders did.
What the data says
IBM’s 2025 Cost of a Data Breach Report identified compromised credentials as one of the leading initial attack vectors in breaches globally. In South Africa, the picture is compounded by the scale of the threat environment. With local organisations facing over 2,100 cyber attacks per week on average, the probability that credential-based attacks are being attempted against your environment continuously is not a theoretical concern. It is a near certainty.
The uncomfortable truth is that many of those attacks succeed not because of sophisticated zero-day exploits, but because of basic access hygiene failures: accounts that should not exist, permissions that were never reviewed, and privileged access that was granted for a project and never revoked.
The privileged access problem
Not all identities carry equal risk. A compromised standard user account gives an attacker a foothold. A privileged account, one with administrative rights, service account credentials, or access to critical systems, gives an attacker leverage. The ability to move laterally, escalate permissions, exfiltrate data, deploy ransomware, or remain undetected for months.
Privileged Access Management, or PAM, exists specifically to address this exposure. It controls who can access critical systems, enforces the principle of least privilege, records privileged sessions for audit purposes, and ensures that administrative credentials are rotated, vaulted and never exposed unnecessarily.
Organisations without a mature PAM capability are operating with a significant blind spot. And in South Africa’s regulatory environment, where POPIA requires demonstrable controls over access to personal information, that blind spot carries both compliance and operational risks.
Where identity programmes typically fail
The problem is rarely that organisations have no identity controls. Most have an Active Directory, some form of access request process, and periodic access reviews on paper. The problem is that these controls degrade over time and nobody notices until something goes wrong.
Joiner, mover, leaver processes break down quietly. A staff member changes roles and retains their previous access permissions indefinitely. A contractor engagement ends and the account sits dormant rather than being disabled. Service accounts accumulate over years of system changes and nobody is certain what they still do or who owns them.
Shadow IT accelerates the problem. When business units provision their own cloud applications outside of IT oversight, identities proliferate across systems that the security team may not even know exist. Each one is a potential entry point.
Multi-factor authentication helps, but it is not a complete answer. MFA can be bypassed through SIM swapping, adversary-in-the-middle phishing kits, and MFA fatigue attacks, in which attackers send repeated authentication requests until a user approves one, simply to stop the notifications. MFA raises the bar. It does not eliminate the risk.
What good looks like
Organisations that manage identity risk effectively treat it as a continuous programme rather than a periodic project. They maintain accurate visibility into all accounts, human and non-human, across their environment. They enforce least-privilege access as a default rather than an exception. They review privileged access regularly and can demonstrate that access rights reflect current business needs. They automatically vault and rotate privileged credentials. And they monitor identity activity for anomalous behaviour in real time, rather than discovering abuse in a forensic investigation after the fact.
They also test their controls. An adversary emulation exercise that specifically targets identity and access pathways, using frameworks like MITRE ATT&CK, will expose gaps that a standard penetration test often misses, since it is designed to find them using the same techniques a real attacker would use.
The question to ask this week
Pull a list of every active account in your environment. Then ask: how many of these belong to people who no longer work here? How many have not been used in the last 90 days? How many have privileged access that has never been formally reviewed?
If you cannot answer those questions with confidence, your identity programme has gaps that need attention before an attacker finds them for you.
Identity is not a technology problem with a technology solution. It is a governance problem that requires policy, process, and technical controls working together. The organisations that get this right are the ones that treat access as something that must be continuously earned and continuously verified, not granted once and forgotten.
SS-Consulting offers Identity and Privileged Access Management services, Adversary Emulations using the MITRE ATT&CK Framework, and Cybersecurity Assessments designed to surface access control gaps before they become incidents. Contact us at sales@ss-consulting.co.za or visit www.ss-consulting.co.za

