// BRIEFING

Passwords & identity. Who can get in, and who can do anything. Wachtwoorden & identiteit. Wie kan er binnen, en wie mag alles.

Reused passwords, codes read out over the phone, accounts of people who left, and administrators nobody counts — in plain language: how each one becomes an intruder with a valid badge, and the single control that closes it. Hergebruikte wachtwoorden, codes die door de telefoon worden voorgelezen, accounts van vertrokken collega's en beheerders die niemand telt — in gewone taal: hoe elk daarvan een indringer met een geldige pas wordt, en welke maatregel het sluit.

// STEP 01STAP 01

Their breach becomes our break-in. Hun datalek wordt onze inbraak.

password reuse / credential stuffing wachtwoordhergebruik / credential stuffing
CREDENTIAL STUFFING
🛒
Breached webshopGelekte webshop
🏢
Our loginOnze inlog
Summer2023!
Summer2023!
Summer2023!
🤖TRYING THE LEAKED LISTPROBEERT DE GELEKTE LIJST

A colleague uses the same password for a webshop and for work. The webshop is breached, the list is sold, and within days automated tools try every email-and-password pair against our login page. No exploit, no malware: just the right password on the first attempt. Because the login is valid, it looks exactly like the colleague logging in.

Business impact: one working password is a foothold in mail, files and every application behind the same login. The attacker reads for weeks before acting, and the trail points at our own colleague's account. A single door (single sign-on) with a passkey behind it makes the reused password worthless: there is nothing left to reuse.

Een collega gebruikt hetzelfde wachtwoord voor een webshop als voor het werk. De webshop lekt, de lijst wordt verkocht, en binnen dagen proberen geautomatiseerde tools elke combinatie van e-mailadres en wachtwoord op onze inlogpagina. Geen exploit, geen malware: alleen het juiste wachtwoord bij de eerste poging. Omdat de inlog geldig is, ziet het er precies uit als de collega die inlogt.

Bedrijfsimpact: één werkend wachtwoord is een voet tussen de deur bij mail, bestanden en elke applicatie achter dezelfde inlog. De aanvaller leest weken mee voordat hij handelt, en het spoor wijst naar het account van onze eigen collega. Eén deur (single sign-on) met een passkey erachter maakt het hergebruikte wachtwoord waardeloos: er is niets meer om te hergebruiken.

VALID LOGIN · LOOKS LIKE A COLLEAGUE · NO ALARMGELDIGE INLOG · LIJKT EEN COLLEGA · GEEN ALARM FIX: SINGLE SIGN-ON + PASSKEYSOPLOSSING: SINGLE SIGN-ON + PASSKEYS
// STEP 02STAP 02

The second factor that is not one. De tweede factor die er geen is.

SMS codes / helpdesk fraud / shared mailboxes sms-codes / helpdeskfraude / gedeelde mailboxen
THE CALLHET TELEFOONTJE
👤
EmployeeMedewerker
🎭
AttackerAanvaller
CODE 482 913
🎧“HI, IT HERE. READ ME THE CODE?”“HOI, IT HIER. LEES JE DE CODE VOOR?”

A code by text message feels like security. It is a six-digit number a person can read out loud. A caller who claims to be IT, sounds stressed and knows the colleague's name gets that code in under a minute. Shared mailboxes are worse: five people know the password, nobody owns the phone the code goes to, so the second factor was switched off “temporarily”, years ago.

Business impact: a second factor that can be talked out of someone is not a second factor; it is a delay. The attacker still lands in the account, and the report afterwards will say MFA was enabled. A passkey or hardware key cannot be read out over the phone and only works on our real login page, which ends the helpdesk trick.

Een code per sms voelt als beveiliging. Het is een getal van zes cijfers dat iemand hardop kan voorlezen. Een beller die zegt van IT te zijn, gehaast klinkt en de naam van de collega kent, heeft die code binnen een minuut. Gedeelde mailboxen zijn erger: vijf mensen kennen het wachtwoord, niemand is eigenaar van de telefoon waar de code naartoe gaat, dus de tweede factor is “tijdelijk” uitgezet, jaren geleden.

Bedrijfsimpact: een tweede factor die iemand uit zijn hoofd te praten is, is geen tweede factor; het is uitstel. De aanvaller komt alsnog in het account, en het rapport achteraf zal zeggen dat MFA aanstond. Een passkey of hardwaresleutel kun je niet voorlezen door de telefoon en werkt alleen op onze echte inlogpagina; daarmee is de helpdesktruc voorbij.

READ OUT IN ONE CALL · “MFA WAS ON”IN ÉÉN TELEFOONTJE VOORGELEZEN · “MFA STOND AAN” FIX: PASSKEYS OR HARDWARE KEYS · NO SMS · NO SHARED LOGINSOPLOSSING: PASSKEYS OF HARDWARESLEUTELS · GEEN SMS · GEEN GEDEELDE INLOGS
// STEP 03STAP 03

They left. Their account did not. Zij zijn weg. Hun account niet.

leavers / orphaned accounts vertrekkers / weesaccounts
6 MONTHS LATER6 MAANDEN LATER
👤ACTIVEACTIEF
👤LEFTWEGACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
👤LEFTWEGACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
🛠️LEFTWEGACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
👤ACTIVEACTIEF
👤LEFTWEGACTIVEACTIEF
👤ACTIVEACTIEF

HR closes the file on the last working day. IT hears about it in a monthly export, or never. Meanwhile the leaver's login to the CRM, the cloud console, the payroll tool and three SaaS products keeps working. Contractors are worse: nobody was ever their manager. Some of these accounts are still logging in, from a new employer's laptop, with the best of intentions. Others are for sale.

Business impact: every orphaned account is a valid identity nobody is watching, in systems that hold customer data. Auditors ask for the leaver list first, because that is where the gap always shows. A joiner-mover-leaver process driven by HR's system, not by e-mail, closes every door on day one without anyone having to remember.

HR sluit het dossier op de laatste werkdag. IT hoort het in een maandelijkse export, of nooit. Ondertussen blijft de inlog van de vertrekker op het CRM, de cloudconsole, het salarissysteem en drie SaaS-producten gewoon werken. Bij externen is het erger: niemand was ooit hun manager. Sommige van die accounts loggen nog in, vanaf de laptop van een nieuwe werkgever, met de beste bedoelingen. Andere staan te koop.

Bedrijfsimpact: elk weesaccount is een geldige identiteit waar niemand naar kijkt, in systemen vol klantgegevens. Auditors vragen als eerste om de vertrekkerslijst, omdat daar het gat altijd zichtbaar wordt. Een in-, door- en uitstroomproces dat door het HR-systeem wordt aangestuurd, niet door e-mail, sluit elke deur op dag één zonder dat iemand eraan hoeft te denken.

STILL WORKING MONTHS LATER · NOBODY OWNS ITMAANDEN LATER NOG ACTIEF · NIEMAND IS EIGENAAR FIX: HR-DRIVEN JOINER-MOVER-LEAVEROPLOSSING: IN-, DOOR- EN UITSTROOM VANUIT HR
// STEP 04STAP 04

Forty people can do anything. Veertig mensen mogen alles.

standing privileges / admin sprawl permanente rechten / wildgroei aan beheerders
WHO CAN DO ANYTHINGWIE MAG ALLES
👤👑 ADMIN
👤
👤👑 ADMIN
👤
👤👑 ADMIN
👤
👤👑 ADMIN
👤
👤👑 ADMIN
👤👑 ADMIN
👤
🛠️👑 ADMIN
👤
👤👑 ADMIN
👤👑 ADMIN
👤👑 ADMIN

Administrator rights are handed out to fix a problem and never taken back. The project ended, the person changed roles, the supplier's engineer went home; the rights stayed. Each of those accounts can read every mailbox, change every setting and delete every backup, every hour of every day, whether or not the owner is working. The attacker from step 01 does not need to climb. They just need to land on one of them.

Business impact: the blast radius of any incident is the number of accounts that can do anything, multiplied by the time they can do it. Rights granted for the hour they are needed (just-in-time), and a quarterly review in which a manager has to say “yes, still” for each name, shrink both numbers. The list of who can do anything should fit on one page, and someone should have read it this quarter.

Beheerdersrechten worden uitgedeeld om een probleem op te lossen en nooit ingetrokken. Het project is klaar, de collega heeft een andere rol, de engineer van de leverancier is naar huis; de rechten bleven. Elk van die accounts kan elke mailbox lezen, elke instelling wijzigen en elke back-up wissen, elk uur van elke dag, of de eigenaar nu aan het werk is of niet. De aanvaller uit stap 01 hoeft niet te klimmen. Hij hoeft alleen op één van hen te landen.

Bedrijfsimpact: de schade van elk incident is het aantal accounts dat alles mag, maal de tijd dat ze dat mogen. Rechten die alleen worden verleend voor het uur dat ze nodig zijn (just-in-time), en een kwartaalreview waarin een manager per naam “ja, nog steeds” moet zeggen, verkleinen beide getallen. De lijst van wie alles mag hoort op één pagina te passen, en iemand hoort hem dit kwartaal gelezen te hebben.

ALWAYS ON · NEVER REVIEWED · ONE HOP FROM STEP 01ALTIJD AAN · NOOIT HERZIEN · ÉÉN STAP VAN STAP 01 FIX: JUST-IN-TIME ADMIN + QUARTERLY ACCESS REVIEWOPLOSSING: JUST-IN-TIME BEHEER + KWARTAALREVIEW VAN RECHTEN
// CONTROLSMAATREGELEN

What closes the doors. Wat de deuren sluit.

one login system used as the only door — configuration and process, not a product per step één inlogsysteem als enige deur — configuratie en proces, geen product per stap
DEFENCE STACKVERDEDIGINGSLAGEN
SSO PASSKEYS JOINER-MOVER-LEAVERIN-, DOOR-, UITSTROOM JUST-IN-TIME ADMINJUST-IN-TIME BEHEER ACCESS REVIEWTOEGANGSREVIEW
ControlClosesIn one line
Single sign-onReuse (01), Leavers (03)Every application behind the one company login. One place to switch an account off, one place to watch.
PasskeysReuse (01), Weak factor (02)A login bound to the device and to our real website. Nothing to reuse, nothing to read out.
No SMS, no shared loginsWeak factor (02)Text-message codes retired. Shared mailboxes become shared access from personal accounts, never a shared password.
Joiner-mover-leaverLeavers (03)HR's system creates, changes and closes accounts automatically. Last working day means last working login.
Service accountsLeavers (03)Every non-human account has a named owner, a purpose and an expiry date. Unknown owner means switched off.
Just-in-time adminStanding rights (04)Administrator rights are requested, approved and expire after hours, not years.
Access reviewStanding rights (04)Every quarter each manager confirms or removes every right their people hold. Silence means removal.
Conditional accessAll fourLogins from unknown devices, impossible locations or unmanaged laptops are blocked or challenged, whatever the password.
MaatregelSluitIn één zin
Single sign-onHergebruik (01), Vertrekkers (03)Elke applicatie achter de ene bedrijfsinlog. Eén plek om een account uit te zetten, één plek om te kijken.
PasskeysHergebruik (01), Zwakke factor (02)Een inlog gebonden aan het apparaat en aan onze echte website. Niets om te hergebruiken, niets om voor te lezen.
Geen sms, geen gedeelde inlogsZwakke factor (02)Sms-codes afgeschaft. Gedeelde mailboxen worden gedeelde toegang vanuit persoonlijke accounts, nooit een gedeeld wachtwoord.
In-, door- en uitstroomVertrekkers (03)Het HR-systeem maakt, wijzigt en sluit accounts automatisch. Laatste werkdag is laatste inlog.
ServiceaccountsVertrekkers (03)Elk niet-menselijk account heeft een eigenaar met naam, een doel en een einddatum. Onbekende eigenaar betekent uit.
Just-in-time beheerPermanente rechten (04)Beheerdersrechten worden aangevraagd, goedgekeurd en verlopen na uren, niet na jaren.
ToegangsreviewPermanente rechten (04)Elk kwartaal bevestigt of verwijdert elke manager elk recht van zijn mensen. Geen antwoord betekent verwijderen.
Voorwaardelijke toegangAlle vierInloggen vanaf onbekende apparaten, onmogelijke locaties of onbeheerde laptops wordt geblokkeerd of extra gecontroleerd, wat het wachtwoord ook is.
The board-level point: identity is the perimeter now; the firewall is not. Two questions to ask: how many people can do anything in our systems, and when did someone last read that list, name by name? If the first answer is longer than a page, or the second is “not sure”, that is the finding. De kern voor de directie: identiteit is tegenwoordig de buitenmuur; de firewall niet meer. Twee vragen om te stellen: hoeveel mensen mogen alles in onze systemen, en wanneer heeft iemand die lijst voor het laatst gelezen, naam voor naam? Is het eerste antwoord langer dan één pagina, of luidt het tweede “weet ik niet zeker”, dan is dát de bevinding.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Every organisation has leaked passwords in circulation and leavers who were never fully removed. Attackers try both every day.Elke organisatie heeft gelekte wachtwoorden in omloop en vertrekkers die nooit volledig zijn afgesloten. Aanvallers proberen beide elke dag.

ImpactImpactHighHoog

Takeover of mail and applications, fraud in a colleague's name, and a personal-data breach with notification duties.Overname van mail en applicaties, fraude op naam van een collega, en een datalek met meldplicht.

Residual after controlsRestrisico na maatregelenLowLaag

With SSO, passkeys and HR-driven offboarding, a takeover needs the device itself. Standing admin rights remain the residual to review each quarter.Met SSO, passkeys en uitstroom vanuit HR is voor een overname het apparaat zelf nodig. Permanente beheerrechten blijven het restrisico dat elk kwartaal wordt herzien.

Risk ownerRisico-eigenaarCIO with HRCIO met HR

Identity is shared: IT owns the door, HR owns who is supposed to be inside. Neither can close the gap alone.Identiteit is gedeeld: IT is eigenaar van de deur, HR van wie er binnen hoort te zijn. Geen van beide kan het gat alleen sluiten.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

% of logins through SSO with a passkey · accounts still active more than 24 hours after the leaving date · number of standing administrator accounts · % of rights confirmed in the last quarterly review.% inlogs via SSO met een passkey · accounts die meer dan 24 uur na de vertrekdatum nog actief zijn · aantal permanente beheerdersaccounts · % rechten bevestigd in de laatste kwartaalreview.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Weak or unmanaged identities (reused passwords, phishable second factors, orphaned and over-privileged accounts) allow account takeover, fraud and a personal-data breach.”“Zwakke of onbeheerde identiteiten (hergebruikte wachtwoorden, phishbare tweede factoren, wees- en overgeprivilegieerde accounts) maken accountovername, fraude en een datalek mogelijk.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Access control and multi-factor authentication are named measures. Management approves the policy and must be able to show it applies to everyone, including administrators and suppliers.Ask how the supplier's staff authenticate to your systems and how their leavers lose that access. Put a 24-hour removal duty in the contract.A takeover that touches many users or customer data is a significant incident: early warning within 24 hours, full notification within 72, final report within a month.
DORAFor financial entities: strong authentication and identity and access management are explicit ICT risk requirements. Privileged access must be limited, logged and reviewed.ICT third parties must show how their access to your environment is granted, reviewed and revoked. Your audit rights exist to check exactly this.If the takeover disrupts a critical function or exposes client data it is a major ICT incident, with the DORA reporting timeline to the supervisor.
SOC 2Logical access is the largest control area: provisioning, deprovisioning, MFA and periodic access reviews are tested one by one. Every late removal is printed as an exception.Read the access-review and termination exceptions first. Many late removals means their leavers may still be inside your data.Auditors pull the leaver list and the administrator list for the period. The takeover becomes a deviation and customers ask for your remediation.
ISAE 3402Access controls appear only where they affect financial reporting. Wider identity hygiene can be out of scope entirely.Check whether user access management is a control objective at all. If not, the report is silent on this risk.Disclose to the user auditors if the affected accounts touched in-scope processes. Otherwise it falls outside the report and you must tell customers yourself.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Toegangsbeheer en meervoudige authenticatie zijn benoemde maatregelen. Het bestuur keurt het beleid goed en moet kunnen aantonen dat het voor iedereen geldt, ook voor beheerders en leveranciers.Vraag hoe medewerkers van de leverancier zich aanmelden bij uw systemen en hoe hun vertrekkers die toegang verliezen. Leg een verwijderplicht binnen 24 uur vast in het contract.Een overname die veel gebruikers of klantgegevens raakt is een significant incident: vroegtijdige waarschuwing binnen 24 uur, volledige melding binnen 72 uur, eindrapport binnen een maand.
DORAVoor financiële instellingen: sterke authenticatie en identiteits- en toegangsbeheer zijn expliciete ICT-risico-eisen. Bevoorrechte toegang moet beperkt, gelogd en herzien worden.ICT-derden moeten laten zien hoe hun toegang tot uw omgeving wordt verleend, herzien en ingetrokken. Uw auditrechten bestaan om precies dit te controleren.Verstoort de overname een kritieke functie of legt zij klantgegevens bloot, dan is het een ernstig ICT-incident met de DORA-meldtermijnen aan de toezichthouder.
SOC 2Logische toegang is het grootste controlegebied: aanmaken, afsluiten, MFA en periodieke toegangsreviews worden één voor één getest. Elke te late verwijdering staat als afwijking in het rapport.Lees eerst de afwijkingen bij toegangsreviews en uitdiensttreding. Veel te late verwijderingen betekent dat hun vertrekkers nog in uw data kunnen zitten.Auditors vragen de vertrekkerslijst en de beheerderslijst over de periode op. De overname wordt een afwijking en klanten vragen om uw herstelmaatregelen.
ISAE 3402Toegangsbeheersing komt alleen voor waar zij de financiële verslaggeving raakt. Bredere identiteitshygiëne kan volledig buiten scope vallen.Controleer of gebruikerstoegangsbeheer überhaupt een beheersdoelstelling is. Zo niet, dan zegt het rapport niets over dit risico.Meld het aan de auditors van uw klanten als de getroffen accounts processen binnen scope raakten. Anders valt het buiten het rapport en moet u klanten zelf informeren.