Identity security has emerged as a distinct third discipline in information security, alongside traditional host-based and network-focused approaches. The shift is driven by cloud migration and adversary behavior — from state-sponsored actors like Storm-0558 compromising Microsoft's cloud signing keys to financially motivated business email compromise (BEC) schemes costing over $2 billion in 2022. As organizations move critical infrastructure to third-party providers, they lose direct visibility into identity-related threats. Defenders must adapt by demanding greater monitoring access from providers, ingesting available telemetry from cloud tenants, and treating identity as a primary security domain rather than a subset of host or network security.

6m read timeFrom huntress.com
Post cover image
Table of contents
Expanding the FrameworkReal-World Wake-Up CallsAdapting to the New NormalThe Call to Arms