By | Posted on: 7 May 2026
Why training and policy will never stop agent credential sharing
When HCL Technologies disclosed in October 2023 that unauthorised access had compromised client data across multiple service accounts, the breach highlighted a persistent vulnerability that training programmes and policy documents cannot address: the fundamental architecture of how credentials work in business process outsourcing.
The incident, affecting one of India's largest IT services companies, exemplified a pattern seen repeatedly across the BPO and managed services sector. Despite comprehensive security awareness programmes and stringent access policies, the underlying problem persists because organisations continue to operate on a flawed assumption: that users can be trusted to create, manage and protect their own credentials.
The credential sharing epidemic in managed services
In BPO and managed services environments, credential sharing operates as an unofficial standard practice. Service desk agents routinely share login details to expedite client support. Operations teams distribute administrative passwords through messaging platforms to maintain service continuity during shift changes. Project managers circulate system access credentials to temporary staff to meet client deadlines.
This behaviour persists not despite security training, but because the operational demands of managed services create irresistible pressures to circumvent individual credential management. When a client-critical system requires immediate attention at 3am and the designated administrator is unavailable, service delivery teams will share credentials to maintain contractual SLAs.
The practice becomes institutionalised through practical necessity. Teams develop informal protocols for credential distribution that operate parallel to official security policies, creating shadow access management systems that remain invisible to security audits and compliance reviews.
The scale of credential compromise
Recent data illustrates the magnitude of this challenge. Verizon's 2023 Data Breach Investigations Report found that stolen credentials were involved in 49% of all security incidents, with the professional services sector experiencing credential-related breaches at rates 23% higher than the cross-industry average.
IBM's Cost of a Data Breach Report 2023 revealed that compromised credentials contributed to breaches costing an average of $4.62 million per incident in the business services sector. The report identified credential theft as the second most expensive attack vector, behind only phishing.
Specifically within managed services environments, Ponemon Institute's 2023 Third-Party Risk Management Study found that 67% of organisations experienced at least one data breach caused by a third-party vendor in the past 12 months, with credential compromise representing the primary attack vector in 34% of cases.
The UK's Information Commissioner's Office reported that financial penalties for data breaches in the business services sector increased by 156% between 2022 and 2023, with inadequate access controls cited as a contributing factor in 78% of investigated incidents.
Why existing security frameworks fail
Current identity and access management solutions operate on the principle that users should control their own credentials. Single sign-on platforms, privileged access management systems, and multi-factor authentication tools all assume that individuals can be trusted to create, store and protect their authentication secrets.
Zero Trust architectures, despite their comprehensive verification protocols, still rely fundamentally on user-controlled credentials for initial authentication. The "never trust, always verify" principle breaks down when the verification mechanism itself depends on credentials that users can freely share, copy or distribute.
Multi-factor authentication adds layers to the authentication process but cannot prevent credential sharing when operational pressures demand it. Teams simply share both passwords and authentication devices, or distribute MFA bypass codes through unofficial channels.
Privileged access management systems attempt to control high-value credentials through vaulting and session recording, but these solutions typically cover only a subset of system access points. The majority of business application credentials remain under user control, maintaining the fundamental vulnerability.
Identity governance platforms provide visibility into access patterns and can identify anomalous behaviour, but they operate retrospectively. By the time suspicious credential usage is detected and investigated, the operational damage has typically occurred.
The structural solution: organisational credential control
The persistent failure of training and policy to prevent credential sharing indicates that the problem requires a structural rather than behavioural solution. Instead of attempting to modify user behaviour through education and enforcement, organisations must remove the ability for users to create, access or share credentials entirely.
This approach involves shifting credential generation, distribution and management from individual users to organisational systems. Rather than allowing users to create passwords, passphrases or authentication tokens, the organisation generates all credentials centrally, distributes them in encrypted form, and maintains exclusive control over their lifecycle.
Under this model, users never see or handle their own credentials. Authentication occurs through encrypted credential injection that bypasses user visibility entirely. Users cannot share what they do not possess, and credential theft becomes impossible when the target credentials exist only in encrypted organisational vaults.
MyCena's patented technology implements this structural approach by intercepting authentication requests and injecting encrypted credentials directly into login processes. Users authenticate to systems without ever seeing or controlling the underlying credentials, making sharing technically impossible rather than merely prohibited.
This architectural shift addresses the root cause of credential sharing rather than its symptoms. Instead of relying on user compliance with security policies, the system eliminates the technical capability for users to compromise credentials through sharing, copying or theft.
Implications for managed services organisations
For BPO and managed services providers, implementing organisational credential control offers several strategic advantages beyond security improvement. Client audit requirements become significantly easier to satisfy when credential management can be demonstrated through technical controls rather than policy documentation.
Regulatory compliance with frameworks including SOC 2, ISO 27001, and sector-specific requirements becomes more straightforward when credential access can be logged, monitored and controlled at the organisational rather than individual level.
Operational efficiency improvements emerge when teams no longer need to manage password complexity requirements, rotation schedules, or recovery processes for forgotten credentials. Service delivery teams can focus on client requirements rather than credential administration.
Most importantly, the shift removes the inherent tension between security requirements and operational demands that drives unofficial credential sharing practices. When secure access becomes technically simpler than credential sharing, organisational behaviour aligns naturally with security objectives.
The evidence suggests that training and policy approaches to credential security have reached their effectiveness limit. Organisations that continue to rely on user behaviour modification while maintaining user-controlled credential architectures will continue to experience the security incidents that such approaches cannot prevent.
By | Posted on: 7 May 2026
Why OT and IT credential convergence is the energy sector’s defining vulnerability
The February 2021 attack on Oldsmar's water treatment facility in Florida began with a single compromised credential. Within minutes, an attacker had gained remote access and attempted to poison the water supply for 15,000 residents by increasing sodium hydroxide levels to dangerous concentrations. Only quick intervention by an on-site operator prevented catastrophe.
This incident crystallises a fundamental shift in critical infrastructure security. As operational technology (OT) systems converge with IT networks, the traditional air-gap defence has dissolved. What remains is an authentication architecture designed for office environments, now protecting systems that control power grids, refineries, and water supplies.
The convergence problem
Energy sector organisations face an unprecedented authentication challenge. Legacy OT systems, designed for isolation and reliability, now require connectivity for efficiency and monitoring. Meanwhile, IT systems demand flexibility and user convenience. The result is a hybrid environment where industrial control systems share network infrastructure with corporate applications, each governed by incompatible security models.
The complexity multiplies across typical energy infrastructure. A single facility might host distributed control systems managing turbines, SCADA networks monitoring transmission lines, enterprise resource planning systems tracking maintenance, and cloud-based analytics platforms optimising performance. Each system requires authentication, yet none were designed to work together securely.
This convergence creates what security researchers term "credential sprawl" – the proliferation of usernames, passwords, certificates, and tokens across systems. Workers managing both IT and OT systems often reuse credentials or store them in accessible locations to maintain operational efficiency. The result is an expanded attack surface where compromise of any single credential can cascade across both domains.
The scale of exposure
Recent data reveals the magnitude of this vulnerability. The 2023 Verizon Data Breach Investigations Report found that 49% of breaches involved stolen credentials, with critical infrastructure sectors experiencing a 13% increase year-over-year. Within energy specifically, the Industrial Control Systems Cyber Emergency Response Team reported 70 incidents in 2022, with 43% attributed to credential-based attacks.
More alarming is the convergence trend itself. Dragos Inc.'s 2023 Industrial Cybersecurity Year in Review found that 74% of industrial organisations now have some level of IT-OT network convergence, compared to 52% in 2020. Yet only 31% have implemented unified authentication policies across both domains.
The financial implications are substantial. According to IBM's Cost of a Data Breach Report 2023, critical infrastructure breaches cost an average of $5.04 million – 4.5% above the global average. For energy companies specifically, operational disruption costs can exceed security remediation by a factor of ten, as extended outages trigger regulatory penalties and customer compensation requirements.
Perhaps most concerning is the persistence problem. Mandiant's M-Trends 2023 report found that attackers maintain access to critical infrastructure networks for an average of 146 days before detection. During this period, they often establish multiple credential-based footholds, making complete remediation extremely difficult.
Why current solutions fall short
Traditional identity and access management approaches prove inadequate for this converged environment. Single sign-on systems, designed for IT convenience, often cannot integrate with industrial protocols. Privileged access management tools may protect high-value accounts but leave standard OT credentials exposed. Multi-factor authentication, while valuable, can be bypassed through credential stuffing or social engineering.
The fundamental problem lies deeper than tool selection. Most authentication systems assume users should create, know, and control their own credentials. This user-centric model prioritises convenience over security, allowing password reuse, weak credential selection, and insecure storage practices.
Zero Trust architectures, increasingly popular in enterprise IT, face similar limitations in OT environments. While continuous verification improves security posture, these systems still rely on initial credential-based authentication. If those underlying credentials are compromised, Zero Trust verification becomes meaningless.
Rethinking credential control
A structural solution requires abandoning user-controlled credentials entirely. Instead of allowing workers to create and manage authentication tokens, organisations must generate, distribute, and revoke every credential through centralised systems. Users should never see, store, or control the credentials that grant them access.
This approach, exemplified by solutions like MyCena's patented credential control technology, inverts the traditional model. Rather than protecting user-held credentials, it eliminates user credential visibility entirely. Access becomes unphishable because workers cannot inadvertently share what they do not possess.
The technology encrypts and distributes credentials automatically based on role requirements and security policies. When access is needed, the system provides temporary, encrypted tokens that authenticate without user knowledge. Revocation becomes instantaneous since credentials exist only within the managed system.
For energy sector applications, this model addresses both IT and OT requirements. IT systems benefit from seamless authentication without password management overhead. OT systems gain modern authentication capabilities without compromising operational reliability. The unified approach eliminates credential sprawl by centralising all authentication tokens under organisational control.
The strategic imperative
Energy sector leaders face a clear choice. The convergence of IT and OT systems is irreversible, driven by efficiency demands and digital transformation initiatives. Traditional credential management approaches, designed for simpler environments, cannot secure this new reality.
Regulatory pressure intensifies this timeline. The EU's NIS2 Directive, effective October 2024, explicitly requires critical infrastructure operators to implement "state-of-the-art" cybersecurity measures. US pipeline operators face similar requirements under Transportation Security Administration directives following Colonial Pipeline's 2021 ransomware attack.
The solution requires recognising that identity and access are distinct concepts. Workers need verified identity to perform their roles, but they do not need to hold the credentials that grant system access. By separating these functions, organisations can maintain operational efficiency while achieving unprecedented security resilience.
The question is not whether credential-based attacks will target converged IT-OT infrastructure – they already have. The question is whether energy sector organisations will abandon vulnerable authentication models before the next Oldsmar incident succeeds.
By | Posted on: 7 May 2026
Why IAM, PAM, and Zero Trust all leave the same credential gap
When Medibank's systems were breached in October 2022, exposing the personal health information of 9.7 million customers, investigators traced the attack's origin to compromised credentials. Despite multi-million-dollar investments in identity and access management systems, privileged access management tools, and emerging zero-trust architectures, the fundamental vulnerability remained unchanged: users controlled their own credentials, making them inherently susceptible to social engineering and phishing attacks.
The persistent credential problem in financial services
Financial institutions face a structural paradox. They implement sophisticated security frameworks—identity and access management (IAM) for user authentication, privileged access management (PAM) for critical system access, and zero-trust architectures for network security—yet credential compromise remains the primary attack vector. The 2023 Verizon Data Breach Investigations Report found that stolen credentials were involved in 49% of breaches across all sectors, rising to 55% specifically within financial services.
This vulnerability stems from a fundamental design flaw: organisations authenticate identity but delegate credential control to users. Whether accessing core banking systems, insurance underwriting platforms, or customer databases, employees create, remember, and manage passwords themselves. This human element introduces systemic risk that no amount of perimeter security can eliminate.
Regulatory frameworks acknowledge this reality. The Financial Conduct Authority's operational resilience requirements mandate that firms "identify, monitor and manage" operational risks, explicitly including cyber threats. Similarly, Solvency II requires insurers to maintain "effective system of governance" over operational risks, while PCI DSS standards demand "strong access control measures" for payment processing environments.
The scale of credential vulnerability
Recent data illustrates the magnitude of this challenge. IBM's 2023 Cost of a Data Breach Report found that compromised credentials were the most common initial attack vector, present in 16% of all breaches and resulting in an average cost of $4.62 million per incident. For financial services specifically, this figure rises to $5.90 million—the highest across all industries.
The European Banking Authority's 2023 risk assessment identified credential compromise as a "high-priority risk" for EU financial institutions, noting a 78% increase in successful phishing attacks targeting banking credentials between 2022 and 2023. Within insurance, Lloyd's of London reported that 68% of cyber insurance claims in 2023 originated from compromised user credentials, representing £2.1 billion in total payouts.
Perhaps most concerning is the persistence of this vulnerability despite security investments. Gartner estimates that global spending on IAM solutions reached $16.9 billion in 2023, yet credential-based attacks continue to increase. The Ponemon Institute found that 65% of organisations experienced credential-related security incidents within the past 24 months, despite implementing multi-factor authentication and privileged access management systems.
Why current security architectures fail
Traditional security tools address symptoms rather than the underlying structural problem. IAM systems excel at verifying user identities once credentials are provided, but cannot prevent credential theft in the first place. PAM solutions secure privileged accounts through session monitoring and access controls, yet remain vulnerable if underlying credentials are compromised through phishing or social engineering.
Zero-trust architectures represent the most sophisticated approach, continuously verifying access requests and assuming no implicit trust. However, even zero-trust models typically rely on user-controlled credentials for initial authentication. If attackers obtain these credentials through phishing—increasingly sophisticated attacks that can bypass multi-factor authentication—they can potentially satisfy zero-trust verification requirements.
Single sign-on (SSO) solutions, while improving user experience, actually increase risk concentration. A single compromised credential can provide access to multiple systems, amplifying potential damage. Multi-factor authentication adds security layers but remains vulnerable to advanced phishing techniques and SIM-swapping attacks.
A structural approach to credential control
The solution requires fundamentally restructuring credential ownership. Rather than users creating and controlling credentials, organisations must generate, distribute, and manage all authentication materials directly. This approach ensures users never see, store, or transmit credentials—eliminating the human element that enables phishing and social engineering.
Under this model, credentials remain encrypted within organisational control systems, released only for specific authentication events through secure channels. Users authenticate through biometric or hardware-based methods, triggering automated credential release without human intervention. This architecture makes credentials "unphishable"—attackers cannot steal what users never possess.
Implementation requires minimal disruption to existing systems. Current IAM, PAM, and zero-trust investments remain valuable, enhanced by removing their shared vulnerability point. Authentication becomes organisationally controlled while preserving established access management frameworks.
Strategic implications
Financial institutions and insurers face a clear choice: continue investing in perimeter security while leaving the credential gap exposed, or address the structural vulnerability directly. Given regulatory pressures, rising breach costs, and increasing attack sophistication, organisations that fail to control credentials face escalating operational and reputational risks.
The technology exists to eliminate credential-based vulnerabilities entirely. The question is whether financial services leaders will recognise that identity verification and access control, while necessary, are insufficient without organisational credential control.
By | Posted on: 7 May 2026
Why Clinical Staff Controlling Their Own Credentials Is a Structural HIPAA Failure
When hackers breached CommonSpirit Health in October 2022, compromising 623,774 patient records across 142 hospitals, the attack vector was disturbingly familiar: compromised employee credentials. The cybercriminals didn't exploit a sophisticated zero-day vulnerability or breach air-gapped systems. They simply used legitimate clinical staff login details to access protected health information, highlighting a fundamental flaw in how healthcare organisations approach credential security.
The breach underscores a critical structural problem that permeates healthcare cybersecurity: clinical staff creating, controlling, and ultimately compromising their own digital credentials creates an inherent HIPAA compliance failure that no amount of additional security layers can fully address.
The Healthcare Credential Control Problem
Healthcare organisations face a unique challenge in credential management. Unlike other sectors, clinical environments require rapid access to patient data across multiple systems, often in life-or-death situations. This urgency has traditionally justified allowing healthcare workers to create and manage their own passwords, PINs, and authentication methods.
However, this approach creates what security experts term "credential sprawl" – a phenomenon where individual users accumulate dozens of self-created login details across electronic health records (EHR), pharmaceutical databases, medical device interfaces, and administrative systems. Each credential represents a potential entry point for malicious actors seeking access to protected health information (PHI).
The problem extends beyond simple password hygiene. When clinical staff control their own credentials, they inevitably reuse passwords across systems, store them in unsecured locations, or share them with colleagues during shift changes. This behaviour, while understandable given operational pressures, creates systematic HIPAA violations that organisations struggle to detect or prevent.
The Scale of Healthcare Cybersecurity Breaches
Healthcare data breaches have reached epidemic proportions. According to the Department of Health and Human Services' Office for Civil Rights, healthcare organisations reported 707 data breaches affecting 500 or more individuals in 2023, exposing over 133 million patient records – a 141% increase from 2022.
The financial impact is equally severe. IBM's 2023 Cost of a Data Breach Report found healthcare breaches cost an average of $10.93 million per incident, nearly three times the cross-industry average of $4.45 million. More critically, the Ponemon Institute's research indicates that 83% of healthcare breaches involve compromised credentials as either the primary attack vector or a significant contributing factor.
These statistics reveal a troubling pattern: despite substantial investments in cybersecurity infrastructure, healthcare organisations remain vulnerable to attacks that exploit the fundamental weakness of user-controlled credentials. The problem isn't technological sophistication – it's structural control.
Why Traditional Security Tools Miss the Mark
Healthcare organisations typically respond to credential-related breaches by layering additional security technologies. Identity and Access Management (IAM) systems promise better user provisioning. Privileged Access Management (PAM) tools monitor high-risk accounts. Single Sign-On (SSO) reduces password fatigue. Multi-Factor Authentication (MFA) adds verification steps. Zero Trust architectures assume breach and verify continuously.
Yet these solutions share a critical flaw: they still permit users to create, know, and control their own credentials. IAM systems may enforce password complexity, but users still choose and remember passwords. PAM tools may monitor privileged sessions, but users still input their own authentication factors. SSO may reduce the number of passwords, but users still control the master credential. MFA may add security layers, but users still possess the primary authentication factor.
This fundamental design assumption – that users should control their own credentials – creates an irreducible security vulnerability. Social engineering attacks, phishing campaigns, and credential stuffing attacks all exploit this user control to gain unauthorised access to healthcare systems.
The Structural Solution: Organisational Credential Control
Addressing healthcare's credential security crisis requires abandoning the assumption that users should control their own authentication factors. Instead, organisations must generate, distribute, and revoke every credential without users ever seeing or controlling them.
This approach, termed "credential custody," ensures that healthcare organisations maintain complete control over access to PHI. When the organisation generates encrypted credentials and distributes them through secure channels, clinical staff can access necessary systems without ever possessing the underlying authentication secrets. When staff leave, change roles, or face security concerns, the organisation can instantly revoke access without relying on user cooperation or password changes.
MyCena's patented credential control technology demonstrates how this structural approach works in practice. Rather than asking clinical staff to create passwords, the system generates encrypted access credentials that users never see. Authentication happens automatically through secure organisational channels, eliminating the possibility of credential compromise through user action or inaction.
This isn't simply an additional security layer – it's a fundamental restructuring of the relationship between identity and access. Clinical staff retain their identity and role-based permissions, but the organisation maintains exclusive control over the mechanisms that grant system access.
The HIPAA Compliance Imperative
For healthcare organisations, implementing credential custody isn't merely a security best practice – it's a HIPAA compliance necessity. The regulation's Administrative Safeguards require covered entities to "assign a unique name and/or number for identifying and tracking user identity." When users control their own credentials, organisations cannot truly verify user identity or track access with the certainty HIPAA demands.
Furthermore, HIPAA's Access Management standard requires organisations to implement "procedures for granting access to electronic protected health information." User-controlled credentials make it impossible to implement genuine access control procedures, since users can modify, share, or compromise their authentication factors without organisational knowledge.
Healthcare CISOs and compliance officers should evaluate their current credential management practices against these HIPAA requirements. Organisations that allow clinical staff to create and control their own credentials may face regulatory exposure that extends beyond cybersecurity concerns to fundamental compliance failures.
The path forward requires recognising that identity and access are separate concepts. Clinical staff identities – their roles, permissions, and responsibilities – can remain unchanged while organisations assume complete control over access mechanisms. This structural shift transforms credential security from a user responsibility to an organisational capability, finally aligning cybersecurity practices with HIPAA compliance requirements.
By | Posted on: 7 May 2026
Why cleared personnel controlling their own credentials is a national security vulnerability
The recent breach of Snowflake's cloud infrastructure, which compromised data from over 165 major organisations including Ticketmaster and Santander Bank, began with a single compromised credential. More concerning for national security professionals: the attack vector wasn't a sophisticated zero-day exploit, but credentials stolen from an employee's personal device through common malware. When personnel with security clearances control their own access credentials, they create systemic vulnerabilities that no amount of training or technology layering can fully mitigate.
The credential control paradox in defence organisations
Defence contractors, government agencies, and cleared facilities operate under a fundamental security contradiction. While physical access to sensitive areas requires strict organisational control—with badges issued, tracked, and revoked centrally—digital access credentials remain largely under individual user control. Personnel create their own passwords, manage their own authentication tokens, and store credentials on personal devices and browsers.
This approach violates basic security principles that govern every other aspect of classified environments. No cleared facility would allow personnel to manufacture their own security badges or choose their own access codes. Yet the digital equivalent happens thousands of times daily across the defence sector, creating attack surfaces that hostile actors actively exploit.
The problem extends beyond weak passwords. Even when organisations mandate complex password policies and multi-factor authentication, the fundamental vulnerability remains: users possess and control the very credentials that grant access to sensitive systems. This possession creates multiple exploitation vectors that sophisticated adversaries understand and target systematically.
The scale of the credential compromise problem
Current breach statistics reveal the magnitude of this vulnerability. According to Verizon's 2024 Data Breach Investigations Report, 68% of breaches involve a human element, with stolen credentials accounting for 31% of all data breaches—making it the second most common attack vector after social engineering. For government and defence contractors, these figures represent more than financial risk; they constitute potential national security compromises.
The Cybersecurity and Infrastructure Security Agency (CISA) reports that in 2023, credential-based attacks increased by 71% compared to the previous year. Their analysis of nation-state attacks shows that 89% began with compromised user credentials, often obtained through phishing campaigns specifically targeting cleared personnel.
More troubling is the persistence of these attacks. IBM's Cost of a Data Breach Report 2024 found that breaches involving stolen credentials took an average of 292 days to identify and contain—nearly ten months during which adversaries maintain unauthorised access to sensitive systems. For organisations handling classified information, this timeline represents an unacceptable window of potential intelligence compromise.
The human factor compounds these risks exponentially. Research from the SANS Institute indicates that 61% of security professionals reuse passwords across multiple systems, including personal accounts that lack enterprise-grade security controls. When these personal accounts are compromised—as occurred in the Snowflake breach—the exposure can cascade into organisational systems.
Why current security solutions fail to address the root cause
Modern security architectures typically layer multiple technologies: Identity and Access Management (IAM), Privileged Access Management (PAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Zero Trust frameworks. While these tools provide valuable security enhancements, they fail to address the fundamental vulnerability because they still rely on user-controlled credentials.
IAM systems excel at managing user identities and permissions but typically allow users to create and manage their own passwords. PAM solutions secure privileged accounts but often through password vaults that users must access—creating another credential-dependent layer. SSO reduces the number of credentials users must remember but concentrates risk in master credentials that users still control.
MFA adds authentication factors but doesn't eliminate credential exposure. Sophisticated attacks increasingly target MFA systems through techniques like SIM swapping, social engineering, and malware that intercepts authentication tokens. The Lapsus$ group's attacks on Microsoft and other major organisations demonstrated how MFA can be bypassed when attackers gain access to user-controlled credentials and devices.
Zero Trust architectures represent a significant advancement in security thinking by assuming breach and continuously verifying trust. However, most implementations still rely on user-controlled credentials for initial authentication, creating a single point of failure that undermines the entire security model.
The structural solution: organisational credential control
The solution requires a fundamental architectural shift: organisations must control the entire credential lifecycle, from generation through distribution to revocation. Rather than allowing users to create or possess credentials, secure systems should generate credentials organisationally, distribute them through encrypted channels, and maintain complete control over their usage.
This approach treats digital credentials like physical security tokens in a classified facility. Users receive access through organisationally controlled mechanisms but never possess or control the underlying authentication materials. When access is required, the system authenticates users through credentials they cannot see, copy, or compromise.
MyCena's patented technology demonstrates how this principle works in practice. The platform generates unique, encrypted credentials for each user and system interaction, but users never possess or control these credentials directly. Access becomes truly unphishable because there are no user-controlled credentials to steal or compromise. The organisation maintains complete oversight of credential generation, distribution, and revocation, creating an audit trail that meets the most stringent compliance requirements.
This approach aligns with regulatory frameworks including NIST 800-53 controls for access management, DoD 8570 requirements for information assurance, and FedRAMP authorization standards. By removing user control over credentials, organisations can demonstrate compliance with principles-based security requirements rather than relying solely on checklist approaches.
Strategic implications for defence organisations
The shift from user-controlled to organisation-controlled credentials represents more than a technical change; it requires a fundamental reimagining of access management strategies. Defence organisations that implement credential control gain several strategic advantages: genuinely unphishable access, complete audit visibility, and simplified compliance demonstration.
For security professionals responsible for protecting classified information, the choice is increasingly clear. Continuing to allow cleared personnel to control their own credentials perpetuates a fundamental vulnerability that sophisticated adversaries understand and exploit. Organisational credential control provides a structural solution that addresses the root cause rather than merely adding additional layers of complexity.
The question facing defence leaders is not whether credential-based attacks will continue—they will intensify. The question is whether organisations will address the fundamental vulnerability or continue attempting to solve it through technological layering that leaves the core problem intact.
By | Posted on: 7 May 2026
The PAM credential problem: why the vault is only as secure as the technician who holds the key
In August 2024, CrowdStrike's incident commander revealed how a single privileged credential had enabled attackers to maintain persistence across their environment for weeks before the global outage. The breach highlighted a fundamental flaw in how managed service providers (MSPs) approach privileged access management: even the most sophisticated vault is worthless if technicians can be tricked into surrendering the keys.
For MSPs managing hundreds of client environments with elevated privileges, this represents an existential threat. Every technician with privileged access becomes a potential breach vector, regardless of how securely those credentials are stored.
The managed services credential conundrum
MSPs face a unique credential challenge. Unlike traditional enterprises managing a single environment, they require privileged access to hundreds or thousands of client systems. A single Level 2 technician might hold administrative credentials for dozens of client domains, cloud platforms, and critical infrastructure systems.
This creates what security professionals term "credential sprawl at scale". Each technician becomes a walking master key to multiple client environments. Traditional privileged access management (PAM) solutions attempt to secure these credentials in vaults, but they fundamentally rely on human operators who must authenticate themselves to retrieve credentials when needed.
The model assumes that verifying a technician's identity is sufficient to grant access. But this assumption proves catastrophically flawed when that technician receives a convincing phishing email or falls victim to social engineering. Once an attacker compromises the technician's authentication method, they inherit access to every client system that technician can reach.
The data tells a stark story
According to Verizon's 2024 Data Breach Investigations Report, 68% of breaches involved a human element, with phishing attacks increasing by 76% year-over-year. For MSPs, these statistics translate into amplified risk across their entire client base.
The Ponemon Institute's 2024 Cost of Insider Threats report found that credential theft incidents cost organisations an average of $4.99 million per breach, with MSPs facing additional liability through their client contracts. More concerning, the report revealed that 60% of insider threat incidents involved privileged users – exactly the technician population that MSPs rely upon for daily operations.
Research from the Cybersecurity and Infrastructure Security Agency (CISA) shows that 90% of successful cyberattacks involve compromised credentials. For MSPs, this means that traditional identity verification – even with multi-factor authentication – creates a single point of failure that can cascade across multiple client environments.
The UK's National Cyber Security Centre reported that MSPs were targeted in 47% of supply chain attacks in 2023, with compromised privileged credentials being the primary attack vector in 73% of these incidents.
Why existing security tools fail the MSP model
Most organisations deploy a stack of identity and access management tools: privileged access management (PAM) vaults, single sign-on (SSO) platforms, multi-factor authentication (MFA), and increasingly, zero trust frameworks. Yet breaches continue to occur with regularity.
The fundamental problem lies in a flawed equation that underpins all these solutions: identity equals access. Every existing tool operates on the principle that verifying who someone is should determine what they can access. Prove your identity through passwords, biometrics, or hardware tokens, and the system grants corresponding access rights.
This approach creates an inherent vulnerability. No matter how sophisticated the identity verification process, once an attacker successfully impersonates a legitimate user, they inherit all that user's access rights. A compromised MSP technician doesn't just represent a single breach – they represent potential compromise across every client environment they can access.
PAM vaults exemplify this problem. They secure credentials behind robust authentication, but ultimately rely on human operators to retrieve and use those credentials. The vault protects credentials at rest, but cannot prevent a compromised technician from accessing and misusing them. SSO and MFA simply move the vulnerability to different authentication factors, while zero trust frameworks still depend on identity verification as their foundation.
Separating identity from access
The solution requires abandoning the identity-equals-access paradigm entirely. Instead of asking "who is this person and what should they access?", the question becomes "how do we enable necessary business functions without exposing credentials to human operators?"
This approach, termed "credential-less access", ensures that users never see, hold, or control the credentials that grant them system access. Rather than storing credentials in a vault for retrieval, the organisation generates, encrypts, and manages every credential centrally. When a technician needs to access a client system, the credential is transmitted directly to the target system without ever being visible to the user.
MyCena's patented solution demonstrates this principle in practice. When an MSP technician needs administrative access to a client's domain controller, they don't retrieve a password from a vault. Instead, the system generates an encrypted credential, transmits it directly to the target system, and establishes the session without the technician ever seeing the authentication material.
This makes phishing attacks fundamentally impossible. An attacker who compromises a technician's device or account finds no credentials to steal. The technician themselves cannot accidentally expose credentials because they never possess them. Social engineering attacks fail because there are no secrets for the technician to reveal.
From a regulatory compliance perspective, this approach addresses requirements across multiple frameworks. SOC 2 Type II controls around credential management become demonstrable through technical architecture rather than policies and procedures. ISO 27001's requirements for privileged access management shift from administrative controls to automated technical controls. For MSPs serving regulated industries, this provides auditable evidence of credential security without relying on human behaviour.
The path forward for MSPs
The credential problem facing MSPs requires architectural change, not additional layers of identity verification. organisations that continue to operate on the identity-equals-access model will find themselves vulnerable regardless of their security investment.
MSPs should evaluate their current credential exposure across their technician workforce. How many client environments could be compromised if a single technician fell victim to a phishing attack? What would be the financial and reputational impact of a breach that cascaded across multiple client environments?
The transition to credential-less access represents a fundamental shift in security architecture, but it addresses the root cause rather than symptoms. For MSPs facing increasing regulatory scrutiny and client security requirements, this approach provides demonstrable protection against the attack vectors that have proven most successful against their sector.
The question is not whether MSPs will face credential-based attacks, but whether they will implement solutions that make such attacks impossible before they become the next headline.