Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Experts with over 30 years of experience discuss identity security and incident response best practices.
The average organization takes five weeks to recover from an attack on their identity systems. For many companies, even just a few weeks of downtime can destroy the business for good—which is why identity resilience has become an urgent priority in enterprise security. Cohesity's Cyber Event Response Team (CERT) finds that roughly 80% of the cyberattacks it responds to involve a compromised identity.
That alarming statistic is a result of the deliberate strategy employed by threat actors. After three decades of identity-based attacks (largely targeting Active Directory), we know that modern adversaries rarely "break in" anymore. Instead, they log in, move quietly, and escalate privileges.
Experts from Cohesity and Semperis recently discussed the growing frequency and impact of identity threats. They also discussed best practices and antipatterns based on their experiences over thirty years of incident response. Here are the top takeaways from a recent webinar with Aditya Vasudevan (Cohesity), Alex Weinert (Semperis), and Marty Momdjian (Semperis)—some of the most experienced practitioners in identity security and incident response:
Threat actors will have the capability to operate at machine speed. Skilled adversaries used to spend days of profiling the weaknesses of a potential target. Now, this reconnaissance happens in minutes. At the same time, AI-generated phishing campaigns are based on detailed profiles of specific human targets. Emails to your employees are so contextually precise that even diligent employees click through. Finally, your organization almost assuredly has weak credentials, over-provisioned access, and abandoned apps. While these vulnerabilities are rarely systematically exploited, the chances of a breach in the AI era go up dramatically.
By the time security operations centers flag identity threats, attackers may have already infiltrated and compromised your networks. The gap between attacker execution speed and defender detection speed adds to your risk. Identity-specific threats require identity-specific detection operating at comparable speeds.
Recent studies from Unit 42 show that 99% of employees and service accounts have more permissions than they need. Further, 80% of applications are not used regularly in many organizations. And IT teams still maintain access rights to these abandoned apps. Your forgotten accounts, abandoned applications, and legacy infrastructure are active attack paths.
When identity systems are compromised, response and recovery is much harder. Many organizations have discovered mid-crisis that their incident response teams couldn't coordinate efforts because their email and collaboration tools relied on the compromised identity infrastructure. Setting up a response bridge on Microsoft Teams or Zoom was futile when the attacker had access to the same systems. You need a way to communicate and recovery capabilities that are separate from your production identity environment.
If you do not understand how attackers got in and what they changed, a restoration isn’t going to bring your teams back online. In fact, when organizations attempt to restore their identity infrastructure from a backup, systems are often compromised (again) within hours. The attacker's accounts, permissions, and backdoors were all faithfully restored along with the legitimate data. Recovery isn't enough. To get back to business as usual, you need to conduct forensics, detect malicious changes, remove attacker footholds, and perform validation before you attempt to bring systems back online.
Organizations are rapidly deploying AI agents for security operations, incident response, and business automation. These systems usually depend on OAuth or SAML tokens—which require functioning identity infrastructure. When identity systems are compromised, agentic workflows stop. They can't authenticate to each other, can't access the resources they need, and can't perform their tasks. Your autonomous SOC fails when you need it most. As you build agentic systems, recognize that identity infrastructure is a single point of failure. Your automated defenses are only as resilient as your identity layer.
Identity is the glue that holds everything else together—and when it fails, so does the rest of your environment, including the tools you'd use to recover it. AI-accelerated attacks, accumulated security debt, and complex hybrid identity environments are converging. The organizations that survive are the ones that prepare now—with purpose-built resilience solutions that operate independently, detect at machine speed, and recover cleanly.
Want to dive deeper into identity security learnings? Watch the webinar to hear three leading identity and incident response experts discuss detailed case studies, real attack walk-throughs, and a Q&A that gets into the specifics of malware-free AD recovery, ITDR (Identity Threat Detection and Response), and how to validate the integrity of your restored environment.
Learn more about Cohesity Identity Resilience, or get a free security assessment of your AD vulnerabilities.
Written By
Isabelle Yang
Product Marketing Manager