With the increasing size of organizations in cloud, DevOps, and automation-driven infrastructure, a new category of identities has risen to power in the background. The new category is non-human identity. They comprise service accounts, applications, APIs, scripts, and bots. These are entities that do not require any kind of interaction but possess significant privileges for accessing critical infrastructure.
Data breaches don't always make it clear when they happen. Instead, they start out as small things like strange login activity, small changes to settings, strange outbound traffic, and so on. The companies that do the best job of limiting the damage from a breach are not the ones that didn't have one in the first place, but the ones that find it quickly and deal with it well. This blog is a practical, operations-focused framework your security team can follow.