Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

Access and credential management: risk through the front door

· 7 min read · Network Secure

Many incidents do not start with a sophisticated technical flaw but with a valid login: a former employee's account nobody disabled, a "temporary" admin privilege that became permanent, a reused password that leaked from another service. For an attacker, getting in with a legitimate credential is cheaper and quieter than exploiting a vulnerability. For the company, it is a risk that only surfaces as an audit finding or an incident.

Below are both ends of the problem (access that piles up inside the organization and credentials obtained from outside), what to do about it and how to prove it was done.

The hidden cost of poorly managed access

In almost every environment that has been running for a few years, the same patterns repeat:

  • Orphaned accounts. Accounts of former employees, contractors whose engagements ended and retired projects stay active because nobody owns revocation.
  • Privilege creep. People who change roles receive the access of the new job and keep the access of the old one.
  • Exceptions that never expire. Admin access granted "just for this migration" rarely has an end date.
  • Shared privileged accounts. Admin passwords known by several people, with no record of who used them, when or why.

The relevant question is not only who has access, but who has access to what they should no longer reach — something hard to see when management depends on spreadsheets and memory.

Offboarding and role changes: the weakest moments

Two events account for a large share of failures. At offboarding, if revocation is not immediate and complete, including SaaS applications, VPN, cloud accounts and API keys, the company is exposed to both malicious and unintentional misuse. In internal moves, promotions and temporary projects create additional access that rarely goes through the same rigor when it should be removed.

The risk is higher when the person leaving holds privileged access, such as a security manager or an infrastructure administrator: during the handover, the previous owner may still have access while the new one does not yet know the environment.

How it shows up in audits

In ISO 27001, PCI DSS and SOX audits, or in assessments related to Brazil's data protection law (LGPD), access governance is one of the most scrutinized areas. Typical findings are predictable: no traceability of who approved an access, no periodic reviews, mismatches between job role and permissions, privileged accounts without formal control or evidence of use.

How attackers obtain and crack credentials

From the outside, the goal is to get a username and password that work. MITRE ATT&CK catalogs the use of valid accounts (T1078) and brute force (T1110) as techniques of their own. The main routes:

  • Phishing. Urgent messages, by email or SMS, lead to pages that imitate the login screen of a well-known service. Scams targeting streaming accounts, for example, use the "account suspended" warning.
  • Breaches and password reuse. Credentials exposed in one service are sold and tested on others. This is the basis of credential stuffing, which OWASP describes as the automated testing of leaked username/password pairs against other sites.
  • Infostealers. Malware that harvests saved passwords, session cookies and tokens from the infected device. A stolen session cookie may allow access without going through MFA.
  • Brute force and password spraying. Trying many passwords against one account, or a few common passwords against many accounts, to avoid triggering lockouts.
  • Offline hash cracking. When a password database leaks, the attacker tries to recover passwords from the hashes. Passwords stored in plain text or with fast, unsalted hashes, such as plain MD5 or SHA-1, fall quickly to precomputed tables ("rainbow tables") and GPUs rented in the cloud. Short, predictable passwords go first.

Whoever stores the password is also responsible. NIST SP 800-63B requires passwords to be stored salted and hashed with a password hashing scheme that has a cost factor, making each guess expensive. Internal systems still using fast hashes or reversible storage are a finding to fix before any user-facing policy.

What to do

Least privilege and PAM

Every person and every service account should have only the access the job requires, for as long as it requires it. For privileged access, the most valuable target, a PAM (Privileged Access Management) program adds a credential vault, automatic rotation of admin passwords, just-in-time access (granted on demand and revoked when the task ends) and session recording. The gain: less standing privilege to steal and a record of what was done with it.

Lifecycle and periodic review

  • Joiner, mover and leaver processes tied to HR. A termination or transfer should trigger revocation instead of relying on someone remembering. IGA (Identity Governance and Administration) tools automate this cycle.
  • Periodic reviews. Managers confirm, on a defined cycle, that each access is still needed; privileged and third-party access on a shorter cycle.
  • Inventory of non-human accounts. Service accounts, API keys and tokens also need an owner, a purpose and an expiry.

MFA and a modern password policy

CISA recommends MFA for all access, prioritizing phishing-resistant methods such as FIDO2/WebAuthn keys. SMS codes are better than nothing, but they are the weakest link.

For passwords, revision 4 of NIST SP 800-63B, published in July 2025, goes against several old practices:

  • Length over complexity. A minimum of 15 characters when the password is the only factor (8 when it is part of MFA), and support for at least 64 to allow passphrases.
  • No composition rules. Do not require a mix of uppercase letters, numbers and symbols, which produces predictable patterns.
  • No mandatory periodic changes. Force a change when there is evidence of compromise, not every 90 days.
  • Blocklist. New passwords should be checked against lists of common, expected or previously breached passwords.

For users, the habit that cuts the most risk: a unique password per service, kept in a password manager protected by a long master password and MFA.

Detection

Preventive controls can fail. Spikes in failed logins, authentication from unlikely locations and privileged account use outside business hours are signals a SOC should monitor.

Audit evidence

In ISO/IEC 27001:2022, the topic is concentrated in these Annex A controls: 5.15 (access control), 5.16 (identity management), 5.17 (authentication information), 5.18 (access rights), 8.2 (privileged access rights) and 8.5 (secure authentication). The auditor will ask for policy and evidence of execution: access approvals, review reports showing the removals made, timely revocation after terminations, an inventory of privileged accounts and usage logs.

The practical test. Can your company prove, today, that every active access is necessary, was approved by someone and is traceable? If the answer depends on building spreadsheets in audit week, the control exists only on paper.

Structuring this governance, from policies to evidence, is part of GRC work.

Frequently asked questions

What is an orphaned account?

An account that remains active without a legitimate owner: a former employee's, a contractor's whose engagement ended, or one belonging to a system that no longer exists. That is why its use tends to go unnoticed.

What is the difference between IGA and PAM?

IGA handles the lifecycle and governance of all access: granting, reviewing and revoking. PAM focuses on privileged access, with a credential vault, on-demand access and session recording. The two complement each other.

Does changing passwords every 90 days still make sense?

According to NIST SP 800-63B, no. Mandatory periodic changes lead to predictable passwords. The recommendation is to require long passwords, block common or breached ones and force a change when there is a sign of compromise.

Does MFA solve the stolen credentials problem?

It reduces it a lot, but does not eliminate it. SMS or push-based MFA can be bypassed through phishing, and session cookies stolen by infostealers skip the login altogether. That is why phishing-resistant MFA, privilege management and monitoring are still needed.

Sources consulted on 10 October 2026: NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (password requirements, storage and authentication assurance levels); OWASP, Credential Stuffing Prevention Cheat Sheet; CISA guidance on multifactor authentication; MITRE ATT&CK, techniques T1078 (Valid Accounts) and T1110 (Brute Force); ISO/IEC 27001:2022, Annex A. This article is educational, does not replace reading the official standards and does not evaluate specific products.

Official references

Read next