• Home
  • Opinion
  • Why credential protection is the foundation of cyber resilience

Why credential protection is the foundation of cyber resilience

Aslam Tajbhai, Head of Solutions at Data Management Professionals South Africa.
Aslam Tajbhai, Head of Solutions at Data Management Professionals South Africa.

Identity protection must be integral to cyber resilience. Although organisations continue to invest heavily in data protection and backup strategies, most breaches begin with compromised credentials, often privileged Active Directory (AD) accounts that give attackers unfettered access.

Treating backups as a safety net is no longer enough. Without strong identity controls, recovery efforts can simply re-enable the same pathways attackers used to infiltrate the environment.

AD serves as the gateway to an organisation’s infrastructure, systems and data. When it is compromised or offline, business operations can grind to a halt, making it a prime target for attackers. Once a threat actor obtains a legitimate privileged credential, they can operate as a trusted user and bypass many security controls.

Backups and granular recovery capabilities are essential, but they cannot prevent identity compromise. Strong identity protection is therefore the first line of defence against attackers seeking to turn AD into a single point of failure.

Strengthen identity controls

For modern enterprises, the immediate priority is to strengthen identity controls across the environment. Core measures such as multi‑factor authentication (MFA), privileged access management and strict least‑privilege policies must be enforced without delay.

Organisations also need deeper visibility into their identity posture. AD vulnerability assessments can identify misconfigurations and risky conditions before attackers exploit them, while real-time auditing provides continuous insight into changes and activity across the environment. These capabilities help security teams identify weaknesses early, monitor activity is real time and close the gaps that enable credential compromise.

Continuous monitoring should be designed to detect credential misuse as early as possible, including suspicious logins, unexpected account changes and unusual activity across identity systems. Incident playbooks should then provide clear, rapid steps to isolate compromised accounts and contain lateral movement before it escalates.

AD recovery procedures should be clearly documented and regularly rehearsed so teams can restore trusted services quickly during an attack. Combining proactive monitoring with tested response procedures reduces the time attackers have to operate. 

Key metrics to quantify identity risk

At the same time, boards, IT risk officers and security leaders need clear, quantifiable measures of identity risk and the return on identity‑focused investments. Key metrics include MFA adoption rates, the time required to detect and respond to credential‑related incidents, the number and exposure level of privileged accounts, and the success of regular AD recovery tests.

These measures should be supported by ongoing AD recovery validation, including testing in an isolated environment, to provide a realistic view of organisational readiness. Collectively, these metrics and test results provide a practical measure of identity maturity and help leaders determine whether their controls are effectively reducing risk.

Effective identity-first security also depends on close collaboration between organisations and their managed service providers (MSPs). They must monitor identity risks, review privileged access and test recovery plans under real-world pressure. MSPs can also help customers deploy and automate recovery runbooks, streamlining a process that is often manual and time-consuming under traditional procedures.

Jointly operationalising controls

Operationalising these controls collaboratively, validating them regularly and aligning them with compliance requirements enables organisations and service providers to build a resilient and repeatable identity-centric defence model.

Backups remain essential, but true cyber resilience requires identity resilience to sit at the centre of recovery strategy. An organisation’s ability to regain control after an attack depends on protecting and restoring AD through granular and full-forest recovery capabilities that are simple, repeatable and accessible under pressure.

Prioritising identity protection and streamlining AD recovery strengthens organisational resilience, enabling faster and more trustworthy recovery when incidents occur. This ultimately forms the foundation of modern cyber resilience.

Share

Read more


ITWeb proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to enquiries@ombudsman.org.za. Contact the Press Council on 011 484 3612.
Copyright @ 1996 - 2026 ITWeb Limited. All rights reserved.