So basically, they are the perfect hiding spot for attackers. An orphaned account is kind of like a security camera with the lens taped over it. It exists. It has access, but nobody's watching. They're prime targets for credential stuffing, phishing, and abuse because there's no active owner to raise a flag. And in the age of NIST 2, DORA, and the other legislations, they are going to be the new breach headlines. So letting them linger is risky. So a little while back, I found a Terminator contractor hidden inside our production payment processing system.
It still had admin rights because HR system feed hadn't disabled that particular contractor. And I've also seen orphaned service accounts tied to applications which hired a long time ago, but they were still running batch jobs that nobody actually remembered why they were still running and why they were using these credentials. And they basically turned into ghost processes that we kind of stumbled on or over by accident.
So true visibility looks kind of like you know who the owner of the account is, when it was last used, what it actually does, which system it touches, what risks it pose if compromised. And it is about having correlated information or identity information from your HR, your exit directory, your intra-IADN or other SaaS applications, and even service accounts correlated to potentially a single use case systems or access.
Well, so basically step one is don't present they don't exist. That is the most common mistake we see. So to identify them, you have to work closely with the stakeholders. You have to mitigate them to name accounts. So there's always a real human being owning the account. Then you have to wrap them in MFA where it makes sense, or at least to do some kind of access control on them. That can definitely be hard for legacy systems, but with the newer systems, then it should be possible. Then we went ahead and introduced a PAM. So Privileged Access Management.
So the shared credentials were checked out and we didn't pass away around any passwords or certificates and stuff like that. So that is actually how we managed to do the cleanup. So first step would definitely be to figure out what the lay of the land is. You've got to kind of define what an orphan account is in your context. That might not be the same for everybody. Then you have to set thresholds, say, well, how long time can an account be unused or just linger around? Then you have to agree on a deprovisioning process.
And then you gather all that information and then you basically traverse your Active Directory or Intra-ID or whatever. And you start looking at accounts that fall outside of this threshold you have defined. As a guy who has a background in cybersecurity and then lately transitioned to Identity and Access Management, I would highly recommend that if you do struggle in this particular area, that you join me for my talk with Kubek Akom and I would look forward to seeing you then. Thanks.