Threat Intelligence

Why Knowing Who Has Access Is the New Frontline of Cyber Defence

The Hacker News · 19 Sept 2026
Key Takeaway Regularly review not just who has been granted access to your systems, but who is actually using that access, and remove or investigate anything that looks unused, unowned, or unnecessary.

Stolen or misused login credentials continue to be one of the most common ways attackers break into organisations, according to breach research including Verizon's annual Data Breach Investigations Report. A new analysis highlights that many businesses have a dangerous blind spot: they know what access was granted on paper, but not what access is actually being used day to day.

The issue, described as 'identity dark matter', includes forgotten local accounts, embedded service credentials, outdated login methods, and third-party integrations that were never properly registered with a central identity system. These gaps tend to grow naturally as businesses adopt more cloud apps, SaaS tools, and automated systems faster than their security teams can track them.

This matters because attackers have adapted. Rather than relying on obvious malware that security tools are designed to catch, many now use legitimate, compromised credentials to move around inside a network using permissions that already exist. This activity can look just like normal staff behaviour, making it far harder to detect. Standard access reports often only show what permissions were granted, not whether they are still needed, still owned by an active employee, or even being used at all.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.