Why Knowing Who Has Access Is the New Frontline of Cyber Defence
Stolen or misused login credentials continue to be one of the most common ways attackers break into organisations, according to breach research including Verizon's annual Data Breach Investigations Report. A new analysis highlights that many businesses have a dangerous blind spot: they know what access was granted on paper, but not what access is actually being used day to day.
The issue, described as 'identity dark matter', includes forgotten local accounts, embedded service credentials, outdated login methods, and third-party integrations that were never properly registered with a central identity system. These gaps tend to grow naturally as businesses adopt more cloud apps, SaaS tools, and automated systems faster than their security teams can track them.
This matters because attackers have adapted. Rather than relying on obvious malware that security tools are designed to catch, many now use legitimate, compromised credentials to move around inside a network using permissions that already exist. This activity can look just like normal staff behaviour, making it far harder to detect. Standard access reports often only show what permissions were granted, not whether they are still needed, still owned by an active employee, or even being used at all.