Skip to content
Knightgrid
ServicesIndustriesThe Grid ModelInsightsCompanyGrid ScoreContact
← All insights
Threat Intel30 June 20267 min read

Identity is the perimeter now, and most breaches prove it

Attackers stopped breaking in some time ago — they log in. A look at why identity controls outperform almost every other security investment, and how to sequence the work.

By KnightGrid SOC

Across the incidents our SOC handles, the overwhelming majority begin with valid credentials rather than an exploit. Phished, stolen from an info-stealer log, reused from an unrelated breach, or simply never revoked after someone left. The intrusion is not technically sophisticated. It is an authorised session doing unauthorised things.

That has a straightforward consequence for where security budget earns the most: identity controls consistently outperform additional detection tooling, because they remove the attack path rather than observe it.

Why MFA coverage is usually overstated

Almost every company we assess reports having MFA. Far fewer have it everywhere. The gaps cluster in predictable places: legacy protocols that cannot enforce it, service accounts, contractor access, break-glass accounts, and the one internal admin panel that predates the SSO migration.

An attacker only needs the gap. When we run the assessment, we do not ask whether MFA is enabled — we ask for the list of authentications in the last thirty days that completed without it. That list is the real answer, and it is rarely empty.

Push fatigue and what replaced it

Push-notification MFA has been reliably defeated by simply sending the prompt repeatedly until someone taps approve, and by real-time phishing proxies that relay the code. Neither technique is exotic any more.

Phishing-resistant methods — passkeys and hardware security keys — close both. Full rollout takes time, so sequence it: privileged and administrative roles first, then finance and anyone with production access, then the rest of the organisation.

The unglamorous control that matters most

Offboarding. In our assessments it is the single most common serious finding, and it is the one nobody puts on a roadmap because it is not interesting.

The test is easy to run and worth running this week: take five people who left in the last six months and try to prove that every one of their accesses is gone — including SaaS applications bought on a team credit card, shared vaults, and any API keys issued in their name. If you cannot prove it in an afternoon, that is your next project.

Next step

Find out what an attacker would find first.

Twelve questions, four minutes, and a scored read of where your defences actually stand — or skip it and talk to an engineer directly.