Identity is the new security perimeter in the era of hybrid work

Author: Published 4 min de lectura 155 reading

The images in this article were generated with artificial intelligence. How we publish

The combination of hybrid work, personal devices at the post and third-party access has made the identities - human and non-human - the main security perimeter of many organizations. The attackers know this: compromising an account is often faster, quieter and more cost-effective than exploiting infrastructure vulnerability and that reality forces us to rethink how we validate trust in each access.

In recent years we have seen a tactical evolution: it is not enough to steal passwords, now the adversaries point to sessions and the authentication process. Techniques such as the so-called "MFA fatigue" (bombing of notifications until the user accepts) or the interception of session tokens by frameworks of adversary-in- the-middle allow you to evade controls that, on paper, were robust. Successful authentication ceased to be a guarantee of trust on its own.

Identity is the new security perimeter in the era of hybrid work
Image generated with IA.

Another critical vector is endpoints. With employees using unmanaged personal and mobile computers, the risk of infostealers and other malware that extract credentials and session cookies grows in parallel. A compromised device turns a legitimate identity into an open door and many organizations still lack the continuous visibility to detect this condition in real time.

The implications are both technical and commercial: data loss, service interruption, regulatory sanctions and reputational damage. In addition, the need to balance safety and productivity introduces operational dilemmas; blocking default access can paralyze equipment, while allowing too much increases the risk. That is why merely reactive strategies are no longer enough.

The good news is that there are practical and complementary measures to reduce the probability and impact of account hijackings. Instead of relying only on the moment of the login, organizations should adopt continuous verification models incorporating the device's position, session context and behavioral signals throughout the connection. For technical guidance, see recommendations for modern authentication such as those collected by NIST: NIST SP 800-63B.

Implement phishing-resistant authentication methods, such as FIDO2 and physical keys, significantly reduces the effectiveness of campaigns that try to capture credentials or deceive with prompts. At the same time, it is critical to disable and block legacy authentication protocols that do not support modern controls; Microsoft documents how these methods remain a frequent entry path and how to mitigate them in cloud environments: legacy authentication management in Azure AD.

The effective defence combines identity controls with endpoint protection and session detection. EDR / EDRms tools combined with conditional access policies that evaluate device hygiene and user location allow access decisions based on risk, not presumptions. Protecting session cookies and tokens, monitoring behavior anomalies and applying access point mediation are practices that reduce the success of session kidnapping techniques.

No less important is governance: full inventory of identities (including service accounts and automation), minimum privilege principles and regular access reviews. The integration of detailed records into a IMS and continuous threat hunting and attack simulation exercises (team network, controlled phishing) make early detection an operational capacity, not a hope.

Identity is the new security perimeter in the era of hybrid work
Image generated with IA.

The formation must evolve: stop focusing only on "not clicking" and show concrete signs of attacks on MFA, how to react to unexpected prompts and how to report incidents without criminalizing those who warn. The human factor remains vital, but it needs to be empowered by processes and solutions that reduce friction and increase security.

For teams that design a defensive strategy, the path requires combining policies, technology and processes: physical-resistant authentication, continuous device verification, inherited authentication blocking, advanced endpoints protection, session visibility and rigid identity governance. No one can guarantee zero risk, but the sum of these measures transforms an easy objective at a much less attractive operational and tactical cost to the attacker.

Finally, and beyond concrete tools, it is essential to measure. Establishing risk indicators, simulating attacks and reviewing policies according to real metrics allows to adapt investments and prioritize controls with proven impact. For those who want to deepen the nature and scale of the problem, quarterly and annual reports such as the Verizon DBIR provide valuable data on gaps trends: Verizon DBIR.

Coverage

Related

More news on the same subject.