By | Posted on: 7 May 2026
Why training and policy will never stop agent credential sharing
When HCL Technologies disclosed in October 2023 that unauthorised access had compromised client data across multiple service accounts, the breach highlighted a persistent vulnerability that training programmes and policy documents cannot address: the fundamental architecture of how credentials work in business process outsourcing.
The incident, affecting one of India's largest IT services companies, exemplified a pattern seen repeatedly across the BPO and managed services sector. Despite comprehensive security awareness programmes and stringent access policies, the underlying problem persists because organisations continue to operate on a flawed assumption: that users can be trusted to create, manage and protect their own credentials.
The credential sharing epidemic in managed services
In BPO and managed services environments, credential sharing operates as an unofficial standard practice. Service desk agents routinely share login details to expedite client support. Operations teams distribute administrative passwords through messaging platforms to maintain service continuity during shift changes. Project managers circulate system access credentials to temporary staff to meet client deadlines.
This behaviour persists not despite security training, but because the operational demands of managed services create irresistible pressures to circumvent individual credential management. When a client-critical system requires immediate attention at 3am and the designated administrator is unavailable, service delivery teams will share credentials to maintain contractual SLAs.
The practice becomes institutionalised through practical necessity. Teams develop informal protocols for credential distribution that operate parallel to official security policies, creating shadow access management systems that remain invisible to security audits and compliance reviews.
The scale of credential compromise
Recent data illustrates the magnitude of this challenge. Verizon's 2023 Data Breach Investigations Report found that stolen credentials were involved in 49% of all security incidents, with the professional services sector experiencing credential-related breaches at rates 23% higher than the cross-industry average.
IBM's Cost of a Data Breach Report 2023 revealed that compromised credentials contributed to breaches costing an average of $4.62 million per incident in the business services sector. The report identified credential theft as the second most expensive attack vector, behind only phishing.
Specifically within managed services environments, Ponemon Institute's 2023 Third-Party Risk Management Study found that 67% of organisations experienced at least one data breach caused by a third-party vendor in the past 12 months, with credential compromise representing the primary attack vector in 34% of cases.
The UK's Information Commissioner's Office reported that financial penalties for data breaches in the business services sector increased by 156% between 2022 and 2023, with inadequate access controls cited as a contributing factor in 78% of investigated incidents.
Why existing security frameworks fail
Current identity and access management solutions operate on the principle that users should control their own credentials. Single sign-on platforms, privileged access management systems, and multi-factor authentication tools all assume that individuals can be trusted to create, store and protect their authentication secrets.
Zero Trust architectures, despite their comprehensive verification protocols, still rely fundamentally on user-controlled credentials for initial authentication. The "never trust, always verify" principle breaks down when the verification mechanism itself depends on credentials that users can freely share, copy or distribute.
Multi-factor authentication adds layers to the authentication process but cannot prevent credential sharing when operational pressures demand it. Teams simply share both passwords and authentication devices, or distribute MFA bypass codes through unofficial channels.
Privileged access management systems attempt to control high-value credentials through vaulting and session recording, but these solutions typically cover only a subset of system access points. The majority of business application credentials remain under user control, maintaining the fundamental vulnerability.
Identity governance platforms provide visibility into access patterns and can identify anomalous behaviour, but they operate retrospectively. By the time suspicious credential usage is detected and investigated, the operational damage has typically occurred.
The structural solution: organisational credential control
The persistent failure of training and policy to prevent credential sharing indicates that the problem requires a structural rather than behavioural solution. Instead of attempting to modify user behaviour through education and enforcement, organisations must remove the ability for users to create, access or share credentials entirely.
This approach involves shifting credential generation, distribution and management from individual users to organisational systems. Rather than allowing users to create passwords, passphrases or authentication tokens, the organisation generates all credentials centrally, distributes them in encrypted form, and maintains exclusive control over their lifecycle.
Under this model, users never see or handle their own credentials. Authentication occurs through encrypted credential injection that bypasses user visibility entirely. Users cannot share what they do not possess, and credential theft becomes impossible when the target credentials exist only in encrypted organisational vaults.
MyCena's patented technology implements this structural approach by intercepting authentication requests and injecting encrypted credentials directly into login processes. Users authenticate to systems without ever seeing or controlling the underlying credentials, making sharing technically impossible rather than merely prohibited.
This architectural shift addresses the root cause of credential sharing rather than its symptoms. Instead of relying on user compliance with security policies, the system eliminates the technical capability for users to compromise credentials through sharing, copying or theft.
Implications for managed services organisations
For BPO and managed services providers, implementing organisational credential control offers several strategic advantages beyond security improvement. Client audit requirements become significantly easier to satisfy when credential management can be demonstrated through technical controls rather than policy documentation.
Regulatory compliance with frameworks including SOC 2, ISO 27001, and sector-specific requirements becomes more straightforward when credential access can be logged, monitored and controlled at the organisational rather than individual level.
Operational efficiency improvements emerge when teams no longer need to manage password complexity requirements, rotation schedules, or recovery processes for forgotten credentials. Service delivery teams can focus on client requirements rather than credential administration.
Most importantly, the shift removes the inherent tension between security requirements and operational demands that drives unofficial credential sharing practices. When secure access becomes technically simpler than credential sharing, organisational behaviour aligns naturally with security objectives.
The evidence suggests that training and policy approaches to credential security have reached their effectiveness limit. Organisations that continue to rely on user behaviour modification while maintaining user-controlled credential architectures will continue to experience the security incidents that such approaches cannot prevent.
By | Posted on: 7 May 2026
Why IAM, PAM, and Zero Trust all leave the same credential gap
When Medibank's systems were breached in October 2022, exposing the personal health information of 9.7 million customers, investigators traced the attack's origin to compromised credentials. Despite multi-million-dollar investments in identity and access management systems, privileged access management tools, and emerging zero-trust architectures, the fundamental vulnerability remained unchanged: users controlled their own credentials, making them inherently susceptible to social engineering and phishing attacks.
The persistent credential problem in financial services
Financial institutions face a structural paradox. They implement sophisticated security frameworks—identity and access management (IAM) for user authentication, privileged access management (PAM) for critical system access, and zero-trust architectures for network security—yet credential compromise remains the primary attack vector. The 2023 Verizon Data Breach Investigations Report found that stolen credentials were involved in 49% of breaches across all sectors, rising to 55% specifically within financial services.
This vulnerability stems from a fundamental design flaw: organisations authenticate identity but delegate credential control to users. Whether accessing core banking systems, insurance underwriting platforms, or customer databases, employees create, remember, and manage passwords themselves. This human element introduces systemic risk that no amount of perimeter security can eliminate.
Regulatory frameworks acknowledge this reality. The Financial Conduct Authority's operational resilience requirements mandate that firms "identify, monitor and manage" operational risks, explicitly including cyber threats. Similarly, Solvency II requires insurers to maintain "effective system of governance" over operational risks, while PCI DSS standards demand "strong access control measures" for payment processing environments.
The scale of credential vulnerability
Recent data illustrates the magnitude of this challenge. IBM's 2023 Cost of a Data Breach Report found that compromised credentials were the most common initial attack vector, present in 16% of all breaches and resulting in an average cost of $4.62 million per incident. For financial services specifically, this figure rises to $5.90 million—the highest across all industries.
The European Banking Authority's 2023 risk assessment identified credential compromise as a "high-priority risk" for EU financial institutions, noting a 78% increase in successful phishing attacks targeting banking credentials between 2022 and 2023. Within insurance, Lloyd's of London reported that 68% of cyber insurance claims in 2023 originated from compromised user credentials, representing £2.1 billion in total payouts.
Perhaps most concerning is the persistence of this vulnerability despite security investments. Gartner estimates that global spending on IAM solutions reached $16.9 billion in 2023, yet credential-based attacks continue to increase. The Ponemon Institute found that 65% of organisations experienced credential-related security incidents within the past 24 months, despite implementing multi-factor authentication and privileged access management systems.
Why current security architectures fail
Traditional security tools address symptoms rather than the underlying structural problem. IAM systems excel at verifying user identities once credentials are provided, but cannot prevent credential theft in the first place. PAM solutions secure privileged accounts through session monitoring and access controls, yet remain vulnerable if underlying credentials are compromised through phishing or social engineering.
Zero-trust architectures represent the most sophisticated approach, continuously verifying access requests and assuming no implicit trust. However, even zero-trust models typically rely on user-controlled credentials for initial authentication. If attackers obtain these credentials through phishing—increasingly sophisticated attacks that can bypass multi-factor authentication—they can potentially satisfy zero-trust verification requirements.
Single sign-on (SSO) solutions, while improving user experience, actually increase risk concentration. A single compromised credential can provide access to multiple systems, amplifying potential damage. Multi-factor authentication adds security layers but remains vulnerable to advanced phishing techniques and SIM-swapping attacks.
A structural approach to credential control
The solution requires fundamentally restructuring credential ownership. Rather than users creating and controlling credentials, organisations must generate, distribute, and manage all authentication materials directly. This approach ensures users never see, store, or transmit credentials—eliminating the human element that enables phishing and social engineering.
Under this model, credentials remain encrypted within organisational control systems, released only for specific authentication events through secure channels. Users authenticate through biometric or hardware-based methods, triggering automated credential release without human intervention. This architecture makes credentials "unphishable"—attackers cannot steal what users never possess.
Implementation requires minimal disruption to existing systems. Current IAM, PAM, and zero-trust investments remain valuable, enhanced by removing their shared vulnerability point. Authentication becomes organisationally controlled while preserving established access management frameworks.
Strategic implications
Financial institutions and insurers face a clear choice: continue investing in perimeter security while leaving the credential gap exposed, or address the structural vulnerability directly. Given regulatory pressures, rising breach costs, and increasing attack sophistication, organisations that fail to control credentials face escalating operational and reputational risks.
The technology exists to eliminate credential-based vulnerabilities entirely. The question is whether financial services leaders will recognise that identity verification and access control, while necessary, are insufficient without organisational credential control.
By | Posted on: 7 May 2026
Why Clinical Staff Controlling Their Own Credentials Is a Structural HIPAA Failure
When hackers breached CommonSpirit Health in October 2022, compromising 623,774 patient records across 142 hospitals, the attack vector was disturbingly familiar: compromised employee credentials. The cybercriminals didn't exploit a sophisticated zero-day vulnerability or breach air-gapped systems. They simply used legitimate clinical staff login details to access protected health information, highlighting a fundamental flaw in how healthcare organisations approach credential security.
The breach underscores a critical structural problem that permeates healthcare cybersecurity: clinical staff creating, controlling, and ultimately compromising their own digital credentials creates an inherent HIPAA compliance failure that no amount of additional security layers can fully address.
The Healthcare Credential Control Problem
Healthcare organisations face a unique challenge in credential management. Unlike other sectors, clinical environments require rapid access to patient data across multiple systems, often in life-or-death situations. This urgency has traditionally justified allowing healthcare workers to create and manage their own passwords, PINs, and authentication methods.
However, this approach creates what security experts term "credential sprawl" – a phenomenon where individual users accumulate dozens of self-created login details across electronic health records (EHR), pharmaceutical databases, medical device interfaces, and administrative systems. Each credential represents a potential entry point for malicious actors seeking access to protected health information (PHI).
The problem extends beyond simple password hygiene. When clinical staff control their own credentials, they inevitably reuse passwords across systems, store them in unsecured locations, or share them with colleagues during shift changes. This behaviour, while understandable given operational pressures, creates systematic HIPAA violations that organisations struggle to detect or prevent.
The Scale of Healthcare Cybersecurity Breaches
Healthcare data breaches have reached epidemic proportions. According to the Department of Health and Human Services' Office for Civil Rights, healthcare organisations reported 707 data breaches affecting 500 or more individuals in 2023, exposing over 133 million patient records – a 141% increase from 2022.
The financial impact is equally severe. IBM's 2023 Cost of a Data Breach Report found healthcare breaches cost an average of $10.93 million per incident, nearly three times the cross-industry average of $4.45 million. More critically, the Ponemon Institute's research indicates that 83% of healthcare breaches involve compromised credentials as either the primary attack vector or a significant contributing factor.
These statistics reveal a troubling pattern: despite substantial investments in cybersecurity infrastructure, healthcare organisations remain vulnerable to attacks that exploit the fundamental weakness of user-controlled credentials. The problem isn't technological sophistication – it's structural control.
Why Traditional Security Tools Miss the Mark
Healthcare organisations typically respond to credential-related breaches by layering additional security technologies. Identity and Access Management (IAM) systems promise better user provisioning. Privileged Access Management (PAM) tools monitor high-risk accounts. Single Sign-On (SSO) reduces password fatigue. Multi-Factor Authentication (MFA) adds verification steps. Zero Trust architectures assume breach and verify continuously.
Yet these solutions share a critical flaw: they still permit users to create, know, and control their own credentials. IAM systems may enforce password complexity, but users still choose and remember passwords. PAM tools may monitor privileged sessions, but users still input their own authentication factors. SSO may reduce the number of passwords, but users still control the master credential. MFA may add security layers, but users still possess the primary authentication factor.
This fundamental design assumption – that users should control their own credentials – creates an irreducible security vulnerability. Social engineering attacks, phishing campaigns, and credential stuffing attacks all exploit this user control to gain unauthorised access to healthcare systems.
The Structural Solution: Organisational Credential Control
Addressing healthcare's credential security crisis requires abandoning the assumption that users should control their own authentication factors. Instead, organisations must generate, distribute, and revoke every credential without users ever seeing or controlling them.
This approach, termed "credential custody," ensures that healthcare organisations maintain complete control over access to PHI. When the organisation generates encrypted credentials and distributes them through secure channels, clinical staff can access necessary systems without ever possessing the underlying authentication secrets. When staff leave, change roles, or face security concerns, the organisation can instantly revoke access without relying on user cooperation or password changes.
MyCena's patented credential control technology demonstrates how this structural approach works in practice. Rather than asking clinical staff to create passwords, the system generates encrypted access credentials that users never see. Authentication happens automatically through secure organisational channels, eliminating the possibility of credential compromise through user action or inaction.
This isn't simply an additional security layer – it's a fundamental restructuring of the relationship between identity and access. Clinical staff retain their identity and role-based permissions, but the organisation maintains exclusive control over the mechanisms that grant system access.
The HIPAA Compliance Imperative
For healthcare organisations, implementing credential custody isn't merely a security best practice – it's a HIPAA compliance necessity. The regulation's Administrative Safeguards require covered entities to "assign a unique name and/or number for identifying and tracking user identity." When users control their own credentials, organisations cannot truly verify user identity or track access with the certainty HIPAA demands.
Furthermore, HIPAA's Access Management standard requires organisations to implement "procedures for granting access to electronic protected health information." User-controlled credentials make it impossible to implement genuine access control procedures, since users can modify, share, or compromise their authentication factors without organisational knowledge.
Healthcare CISOs and compliance officers should evaluate their current credential management practices against these HIPAA requirements. Organisations that allow clinical staff to create and control their own credentials may face regulatory exposure that extends beyond cybersecurity concerns to fundamental compliance failures.
The path forward requires recognising that identity and access are separate concepts. Clinical staff identities – their roles, permissions, and responsibilities – can remain unchanged while organisations assume complete control over access mechanisms. This structural shift transforms credential security from a user responsibility to an organisational capability, finally aligning cybersecurity practices with HIPAA compliance requirements.
By | Posted on: 7 May 2026
Why cleared personnel controlling their own credentials is a national security vulnerability
The recent breach of Snowflake's cloud infrastructure, which compromised data from over 165 major organisations including Ticketmaster and Santander Bank, began with a single compromised credential. More concerning for national security professionals: the attack vector wasn't a sophisticated zero-day exploit, but credentials stolen from an employee's personal device through common malware. When personnel with security clearances control their own access credentials, they create systemic vulnerabilities that no amount of training or technology layering can fully mitigate.
The credential control paradox in defence organisations
Defence contractors, government agencies, and cleared facilities operate under a fundamental security contradiction. While physical access to sensitive areas requires strict organisational control—with badges issued, tracked, and revoked centrally—digital access credentials remain largely under individual user control. Personnel create their own passwords, manage their own authentication tokens, and store credentials on personal devices and browsers.
This approach violates basic security principles that govern every other aspect of classified environments. No cleared facility would allow personnel to manufacture their own security badges or choose their own access codes. Yet the digital equivalent happens thousands of times daily across the defence sector, creating attack surfaces that hostile actors actively exploit.
The problem extends beyond weak passwords. Even when organisations mandate complex password policies and multi-factor authentication, the fundamental vulnerability remains: users possess and control the very credentials that grant access to sensitive systems. This possession creates multiple exploitation vectors that sophisticated adversaries understand and target systematically.
The scale of the credential compromise problem
Current breach statistics reveal the magnitude of this vulnerability. According to Verizon's 2024 Data Breach Investigations Report, 68% of breaches involve a human element, with stolen credentials accounting for 31% of all data breaches—making it the second most common attack vector after social engineering. For government and defence contractors, these figures represent more than financial risk; they constitute potential national security compromises.
The Cybersecurity and Infrastructure Security Agency (CISA) reports that in 2023, credential-based attacks increased by 71% compared to the previous year. Their analysis of nation-state attacks shows that 89% began with compromised user credentials, often obtained through phishing campaigns specifically targeting cleared personnel.
More troubling is the persistence of these attacks. IBM's Cost of a Data Breach Report 2024 found that breaches involving stolen credentials took an average of 292 days to identify and contain—nearly ten months during which adversaries maintain unauthorised access to sensitive systems. For organisations handling classified information, this timeline represents an unacceptable window of potential intelligence compromise.
The human factor compounds these risks exponentially. Research from the SANS Institute indicates that 61% of security professionals reuse passwords across multiple systems, including personal accounts that lack enterprise-grade security controls. When these personal accounts are compromised—as occurred in the Snowflake breach—the exposure can cascade into organisational systems.
Why current security solutions fail to address the root cause
Modern security architectures typically layer multiple technologies: Identity and Access Management (IAM), Privileged Access Management (PAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Zero Trust frameworks. While these tools provide valuable security enhancements, they fail to address the fundamental vulnerability because they still rely on user-controlled credentials.
IAM systems excel at managing user identities and permissions but typically allow users to create and manage their own passwords. PAM solutions secure privileged accounts but often through password vaults that users must access—creating another credential-dependent layer. SSO reduces the number of credentials users must remember but concentrates risk in master credentials that users still control.
MFA adds authentication factors but doesn't eliminate credential exposure. Sophisticated attacks increasingly target MFA systems through techniques like SIM swapping, social engineering, and malware that intercepts authentication tokens. The Lapsus$ group's attacks on Microsoft and other major organisations demonstrated how MFA can be bypassed when attackers gain access to user-controlled credentials and devices.
Zero Trust architectures represent a significant advancement in security thinking by assuming breach and continuously verifying trust. However, most implementations still rely on user-controlled credentials for initial authentication, creating a single point of failure that undermines the entire security model.
The structural solution: organisational credential control
The solution requires a fundamental architectural shift: organisations must control the entire credential lifecycle, from generation through distribution to revocation. Rather than allowing users to create or possess credentials, secure systems should generate credentials organisationally, distribute them through encrypted channels, and maintain complete control over their usage.
This approach treats digital credentials like physical security tokens in a classified facility. Users receive access through organisationally controlled mechanisms but never possess or control the underlying authentication materials. When access is required, the system authenticates users through credentials they cannot see, copy, or compromise.
MyCena's patented technology demonstrates how this principle works in practice. The platform generates unique, encrypted credentials for each user and system interaction, but users never possess or control these credentials directly. Access becomes truly unphishable because there are no user-controlled credentials to steal or compromise. The organisation maintains complete oversight of credential generation, distribution, and revocation, creating an audit trail that meets the most stringent compliance requirements.
This approach aligns with regulatory frameworks including NIST 800-53 controls for access management, DoD 8570 requirements for information assurance, and FedRAMP authorization standards. By removing user control over credentials, organisations can demonstrate compliance with principles-based security requirements rather than relying solely on checklist approaches.
Strategic implications for defence organisations
The shift from user-controlled to organisation-controlled credentials represents more than a technical change; it requires a fundamental reimagining of access management strategies. Defence organisations that implement credential control gain several strategic advantages: genuinely unphishable access, complete audit visibility, and simplified compliance demonstration.
For security professionals responsible for protecting classified information, the choice is increasingly clear. Continuing to allow cleared personnel to control their own credentials perpetuates a fundamental vulnerability that sophisticated adversaries understand and exploit. Organisational credential control provides a structural solution that addresses the root cause rather than merely adding additional layers of complexity.
The question facing defence leaders is not whether credential-based attacks will continue—they will intensify. The question is whether organisations will address the fundamental vulnerability or continue attempting to solve it through technological layering that leaves the core problem intact.
By | Posted on: 7 May 2026
The PAM credential problem: why the vault is only as secure as the technician who holds the key
In August 2024, CrowdStrike's incident commander revealed how a single privileged credential had enabled attackers to maintain persistence across their environment for weeks before the global outage. The breach highlighted a fundamental flaw in how managed service providers (MSPs) approach privileged access management: even the most sophisticated vault is worthless if technicians can be tricked into surrendering the keys.
For MSPs managing hundreds of client environments with elevated privileges, this represents an existential threat. Every technician with privileged access becomes a potential breach vector, regardless of how securely those credentials are stored.
The managed services credential conundrum
MSPs face a unique credential challenge. Unlike traditional enterprises managing a single environment, they require privileged access to hundreds or thousands of client systems. A single Level 2 technician might hold administrative credentials for dozens of client domains, cloud platforms, and critical infrastructure systems.
This creates what security professionals term "credential sprawl at scale". Each technician becomes a walking master key to multiple client environments. Traditional privileged access management (PAM) solutions attempt to secure these credentials in vaults, but they fundamentally rely on human operators who must authenticate themselves to retrieve credentials when needed.
The model assumes that verifying a technician's identity is sufficient to grant access. But this assumption proves catastrophically flawed when that technician receives a convincing phishing email or falls victim to social engineering. Once an attacker compromises the technician's authentication method, they inherit access to every client system that technician can reach.
The data tells a stark story
According to Verizon's 2024 Data Breach Investigations Report, 68% of breaches involved a human element, with phishing attacks increasing by 76% year-over-year. For MSPs, these statistics translate into amplified risk across their entire client base.
The Ponemon Institute's 2024 Cost of Insider Threats report found that credential theft incidents cost organisations an average of $4.99 million per breach, with MSPs facing additional liability through their client contracts. More concerning, the report revealed that 60% of insider threat incidents involved privileged users – exactly the technician population that MSPs rely upon for daily operations.
Research from the Cybersecurity and Infrastructure Security Agency (CISA) shows that 90% of successful cyberattacks involve compromised credentials. For MSPs, this means that traditional identity verification – even with multi-factor authentication – creates a single point of failure that can cascade across multiple client environments.
The UK's National Cyber Security Centre reported that MSPs were targeted in 47% of supply chain attacks in 2023, with compromised privileged credentials being the primary attack vector in 73% of these incidents.
Why existing security tools fail the MSP model
Most organisations deploy a stack of identity and access management tools: privileged access management (PAM) vaults, single sign-on (SSO) platforms, multi-factor authentication (MFA), and increasingly, zero trust frameworks. Yet breaches continue to occur with regularity.
The fundamental problem lies in a flawed equation that underpins all these solutions: identity equals access. Every existing tool operates on the principle that verifying who someone is should determine what they can access. Prove your identity through passwords, biometrics, or hardware tokens, and the system grants corresponding access rights.
This approach creates an inherent vulnerability. No matter how sophisticated the identity verification process, once an attacker successfully impersonates a legitimate user, they inherit all that user's access rights. A compromised MSP technician doesn't just represent a single breach – they represent potential compromise across every client environment they can access.
PAM vaults exemplify this problem. They secure credentials behind robust authentication, but ultimately rely on human operators to retrieve and use those credentials. The vault protects credentials at rest, but cannot prevent a compromised technician from accessing and misusing them. SSO and MFA simply move the vulnerability to different authentication factors, while zero trust frameworks still depend on identity verification as their foundation.
Separating identity from access
The solution requires abandoning the identity-equals-access paradigm entirely. Instead of asking "who is this person and what should they access?", the question becomes "how do we enable necessary business functions without exposing credentials to human operators?"
This approach, termed "credential-less access", ensures that users never see, hold, or control the credentials that grant them system access. Rather than storing credentials in a vault for retrieval, the organisation generates, encrypts, and manages every credential centrally. When a technician needs to access a client system, the credential is transmitted directly to the target system without ever being visible to the user.
MyCena's patented solution demonstrates this principle in practice. When an MSP technician needs administrative access to a client's domain controller, they don't retrieve a password from a vault. Instead, the system generates an encrypted credential, transmits it directly to the target system, and establishes the session without the technician ever seeing the authentication material.
This makes phishing attacks fundamentally impossible. An attacker who compromises a technician's device or account finds no credentials to steal. The technician themselves cannot accidentally expose credentials because they never possess them. Social engineering attacks fail because there are no secrets for the technician to reveal.
From a regulatory compliance perspective, this approach addresses requirements across multiple frameworks. SOC 2 Type II controls around credential management become demonstrable through technical architecture rather than policies and procedures. ISO 27001's requirements for privileged access management shift from administrative controls to automated technical controls. For MSPs serving regulated industries, this provides auditable evidence of credential security without relying on human behaviour.
The path forward for MSPs
The credential problem facing MSPs requires architectural change, not additional layers of identity verification. organisations that continue to operate on the identity-equals-access model will find themselves vulnerable regardless of their security investment.
MSPs should evaluate their current credential exposure across their technician workforce. How many client environments could be compromised if a single technician fell victim to a phishing attack? What would be the financial and reputational impact of a breach that cascaded across multiple client environments?
The transition to credential-less access represents a fundamental shift in security architecture, but it addresses the root cause rather than symptoms. For MSPs facing increasing regulatory scrutiny and client security requirements, this approach provides demonstrable protection against the attack vectors that have proven most successful against their sector.
The question is not whether MSPs will face credential-based attacks, but whether they will implement solutions that make such attacks impossible before they become the next headline.
By | Posted on: 7 May 2026
The BPO credential problem every financial services firm is carrying
When Medibank's customer data breach exposed 9.7 million records in October 2022, investigators traced the attack vector to compromised credentials at a third-party provider. The incident crystallised a growing concern across financial services: Business Process Outsourcing (BPO) arrangements create credential exposure that traditional security frameworks cannot adequately address.
The hidden liability in your supply chain
Financial institutions have spent the past decade hardening their internal security posture, deploying sophisticated identity and access management systems, implementing zero-trust architectures, and enforcing multi-factor authentication across their estates. Yet a critical vulnerability persists in plain sight: the credentials managed by Business Process Outsourcing partners.
BPO arrangements in financial services typically involve sensitive operations—customer service, claims processing, transaction monitoring, compliance reporting, and data analytics. These partnerships require BPO providers to maintain administrative access to core banking systems, trading platforms, customer databases, and regulatory reporting tools. Each access point represents a credential that, if compromised, can provide attackers with a direct pathway into the financial institution's most sensitive systems.
The challenge extends beyond simple access management. BPO environments often operate under different security standards, employ staff with varying levels of security awareness, and maintain credential practices that would be considered inadequate within the financial institution itself. Yet these same credentials can access systems containing customer financial data, trading information, and regulatory filings.
The scale of exposure
Recent industry analysis reveals the extent of this exposure. According to the Financial Conduct Authority's 2023 operational resilience survey, 78% of UK financial services firms rely on critical BPO arrangements, with an average of 12 third-party providers having access to systems classified as important business services.
Verizon's 2023 Data Breach Investigations Report found that 61% of breaches in financial services involved compromised credentials, with 43% of these originating from partner or supply chain access points. The average cost of a supply chain breach in financial services reached $4.8 million in 2023, according to IBM Security's Cost of a Data Breach report.
The regulatory implications are equally concerning. The European Central Bank's 2023 cyber incident reporting data shows that 34% of significant cyber incidents reported by credit institutions involved third-party or outsourcing arrangements. In the United States, the Office of the Comptroller of the Currency cited inadequate third-party risk management in 23% of enforcement actions against national banks in 2023.
Perhaps most tellingly, a study by the Ponemon Institute found that financial services organisations can identify only 57% of the credentials held by their BPO providers at any given time. This visibility gap represents a fundamental control failure in environments where regulatory frameworks demand comprehensive oversight of access to sensitive systems.
Why current security tools miss the mark
The financial services sector has invested heavily in sophisticated access management technologies, yet these solutions fail to address the fundamental issue of credential control in BPO relationships.
Identity and Access Management (IAM) systems excel at managing identities within organisational boundaries but struggle with the distributed nature of BPO credentials. These systems can provision and deprovision access, but they cannot prevent BPO staff from accessing, copying, or sharing the underlying credentials themselves.
Privileged Access Management (PAM) solutions provide session recording and approval workflows, but they still rely on the principle that users hold their own credentials. When a BPO employee receives credentials for a privileged account, PAM systems can monitor how those credentials are used but cannot prevent the credentials from being compromised at source.
Single Sign-On (SSO) reduces credential proliferation but requires extensive integration work and may not be feasible across complex BPO arrangements involving multiple systems and platforms. More fundamentally, SSO still requires users to hold authentication credentials, merely consolidating rather than eliminating the risk.
Multi-Factor Authentication (MFA) adds a layer of security but does not address credential theft. Sophisticated attackers have demonstrated numerous techniques for bypassing MFA, from SIM swapping to real-time phishing attacks that capture both passwords and authentication tokens.
Zero Trust architectures improve security posture by assuming no inherent trust, but they still must grant access based on some form of credential verification. If those underlying credentials are compromised, Zero Trust principles provide limited protection.
The common failure across these approaches is structural: they assume that users must hold credentials to access systems. This assumption creates an inherent vulnerability that no amount of monitoring, encryption, or access control can fully eliminate.
Solving credential control at source
The solution lies in fundamentally restructuring credential ownership and distribution. Rather than allowing BPO partners to create, hold, and manage credentials, financial institutions need systems where credentials are generated, distributed, and controlled entirely by the organisation—with users never gaining direct access to the credential material itself.
Under this model, when a BPO employee needs to access a financial system, they receive encrypted credential material that can only be decrypted and used within a controlled environment. The employee cannot extract, copy, or share the underlying credentials because they never possess them in a readable format. Access becomes cryptographically bound to specific devices and sessions, making credential theft practically impossible.
MyCena's patented credential control technology demonstrates this approach in practice. The system generates unique encrypted credentials for each user and session, distributing them through secure channels without ever exposing the credential material to the end user. BPO employees can access the systems they need to perform their roles, but the underlying authentication mechanism remains entirely under the financial institution's control.
This architectural shift transforms BPO credential management from a risk management exercise into a technical control. Rather than hoping that BPO partners will maintain adequate security practices, financial institutions can ensure that compromise of BPO environments cannot lead to credential theft.
The compliance imperative
For financial services firms, the implications are clear. Regulatory frameworks increasingly require demonstrable control over third-party access to sensitive systems. The EU's DORA regulation, which takes effect in January 2025, explicitly requires financial entities to maintain "full oversight and accountability" for ICT services provided by third parties.
The time for treating BPO credential management as a contractual rather than technical problem has passed. Financial institutions that continue to rely on traditional access management approaches for BPO relationships are carrying a structural vulnerability that regulatory scrutiny and threat actor sophistication will inevitably expose.
The path forward requires recognising that identity and access are separate concepts—and that true security emerges from controlling access without distributing the credentials that enable it.