Loading
July 21 2026

Identity resilience lessons: Top 6 things security leaders need to know

Experts with over 30 years of experience discuss identity security and incident response best practices.

Identity resilience: Top 6 things security leaders need to know

The average organization takes five weeks to recover from an attack on their identity systems. For many companies, even just a few weeks of downtime can destroy the business for good—which is why identity resilience has become an urgent priority in enterprise security.  Cohesity's Cyber Event Response Team (CERT) finds that roughly 80% of the cyberattacks it responds to involve a compromised identity. 

That alarming statistic is a result of the deliberate strategy employed by threat actors. After three decades of identity-based attacks (largely targeting Active Directory), we know that modern adversaries rarely "break in" anymore. Instead, they log in, move quietly, and escalate privileges. 

Experts from Cohesity and Semperis recently discussed the growing frequency and impact of identity threats. They also discussed best practices and antipatterns based on their experiences over thirty years of incident response. Here are the top takeaways from a recent webinar with Aditya Vasudevan (Cohesity), Alex Weinert (Semperis), and Marty Momdjian (Semperis)—some of the most experienced practitioners in identity security and incident response:

1. New frontier models can expose the vulnerabilities you've been planning to address "eventually"—address these now.

Threat actors will have the capability to operate at machine speed. Skilled adversaries used to spend days of profiling the weaknesses of a potential target. Now, this reconnaissance happens in minutes. At the same time, AI-generated phishing campaigns are based on detailed profiles of specific human targets. Emails to your employees are so contextually precise that even diligent employees click through. Finally, your organization almost assuredly has weak credentials, over-provisioned access, and abandoned apps. While these vulnerabilities are rarely systematically exploited, the chances of a breach in the AI era go up dramatically. 

  • Action Item: Harden your identity infrastructure by regularly monitoring your identity infrastructure for misconfigurations and vulnerabilities. Deploy phishing-resistant credentials (passkeys, FIDO2), deploy MFA everywhere, and eliminate over-provisioned accounts.

2. When identity-based attacks execute in seconds, you need rapid detection to respond and recover.

By the time security operations centers flag identity threats, attackers may have already infiltrated and compromised your networks. The gap between attacker execution speed and defender detection speed adds to your risk. Identity-specific threats require identity-specific detection operating at comparable speeds.

  • Action Item: Deploy continuous identity threat detection that monitors Active Directory and Entra ID changes in real-time. Machine-speed attacks require machine-speed detection.

3. 99% of your employee and service accounts are over-permissioned.

Recent studies from Unit 42 show that 99% of employees and service accounts have more permissions than they need. Further, 80% of applications are not used regularly in many organizations. And IT teams still maintain access rights to these abandoned apps. Your forgotten accounts, abandoned applications, and legacy infrastructure are active attack paths. 

  • Action Item: Conduct attack path analysis to understand what identities have access to your tier 0 workloads. Identity risk changes daily as employees come and go; applications are deployed, and permissions evolve. Map and remediate privilege paths before attackers find them.

4. Your incident response team can’t respond if they can’t log in.

When identity systems are compromised, response and recovery is much harder. Many organizations have discovered mid-crisis that their incident response teams couldn't coordinate efforts because their email and collaboration tools relied on the compromised identity infrastructure. Setting up a response bridge on Microsoft Teams or Zoom was futile when the attacker had access to the same systems. You need a way to communicate and recovery capabilities that are separate from your production identity environment.

  • Action Item: Implement identity backup solutions that don't depend on Active Directory to recover Active Directory. Your identity recovery solution must operate independently of the systems it's designed to restore. Establish incident response infrastructure with separate identity systems that don't rely on corporate Active Directory or Entra ID. When your primary identity infrastructure is compromised, you need a parallel path to coordinate recovery.

5. Simply restoring identity isn’t enough–you must remediate the threat first.

If you do not understand how attackers got in and what they changed, a restoration isn’t going to bring your teams back online. In fact, when organizations attempt to restore their identity infrastructure from a backup, systems are often compromised (again) within hours. The attacker's accounts, permissions, and backdoors were all faithfully restored along with the legitimate data. Recovery isn't enough. To get back to business as usual, you need to conduct forensics, detect malicious changes, remove attacker footholds, and perform validation before you attempt to bring systems back online.

  • Action Item: Don't restore from the most recent backup and hope for the best. Test and ensure that your identity recovery system can recover identity without bringing malware or compromised accounts back. Implement forensic analysis of capabilities that can identify attacker changes, remove them surgically, and validate the clean state before restoration.

6. When identity systems are compromised, your agentic systems are also compromised.

Organizations are rapidly deploying AI agents for security operations, incident response, and business automation. These systems usually depend on OAuth or SAML tokens—which require functioning identity infrastructure. When identity systems are compromised, agentic workflows stop. They can't authenticate to each other, can't access the resources they need, and can't perform their tasks. Your autonomous SOC fails when you need it most. As you build agentic systems, recognize that identity infrastructure is a single point of failure. Your automated defenses are only as resilient as your identity layer.

  • Action Item: Include identity resilience in your AI strategy discussions. If you're building autonomous security operations, you need to ensure identity systems can withstand targeted attacks.

Take the next step–because identity isn't just “another workload”

Identity is the glue that holds everything else together—and when it fails, so does the rest of your environment, including the tools you'd use to recover it. AI-accelerated attacks, accumulated security debt, and complex hybrid identity environments are converging. The organizations that survive are the ones that prepare now—with purpose-built resilience solutions that operate independently, detect at machine speed, and recover cleanly.

Want to dive deeper into identity security learnings? Watch the webinar to hear three leading identity and incident response experts discuss detailed case studies, real attack walk-throughs, and a Q&A that gets into the specifics of malware-free AD recovery, ITDR (Identity Threat Detection and Response), and how to validate the integrity of your restored environment.

Learn more about Cohesity Identity Resilience, or get a free security assessment of your AD vulnerabilities.

Written By