man in grey shirt logging into a protected site

Identity & Access Management 101: Most Attackers Don’t Break In. They Log In.

Newtec Services · Identity and Access Management 101

The attacker who gets into your business most often doesn’t hack anything. They just log in, with a password that still worked, for an account nobody remembered to close.

Cloud platforms and remote work moved the real boundary of your business. It’s no longer your network perimeter; it’s identity: who can log in, to what, from where, and with how much access. When that boundary isn’t governed, the failures are quiet and completely ordinary: a former employee’s account never revoked, an admin account with more permissions than the role needs, a password reused elsewhere and now sitting in a breach dump. None of that is a sophisticated attack. It’s an open door.

What Is Identity and Access Management, Really?

IAM is the discipline of making sure the right people have access to the right systems, with the right permissions, for exactly as long as they need it. It covers how people prove who they are, how their access is governed day to day, and how it’s shut off completely the moment they leave.

Why This Should Matter at Leadership Level

Compromised credentials are involved in the majority of security breaches: not exotic exploits, but access that simply should have been switched off. Under GDPR, an access-governance failure like this is a potential data breach; under NIS2, in-scope organisations must demonstrate structured identity controls, not an informal offboarding checklist. Ireland’s Data Protection Commission has published decisions citing inadequate technical measures (including insufficient multi-factor authentication) as GDPR failings, underlining that this is an active enforcement area, not a theoretical risk.

What Structured IAM Actually Does

  • Multi-factor authentication (MFA): requires a second proof of identity beyond a password, so a compromised credential alone isn’t enough to get in.
  • Privileged access management: administrator and elevated accounts get just-in-time access, session monitoring, and credential rotation. The highest-value targets get the most oversight.
  • Zero trust and role-based access: access decisions are based on verified identity and role, not assumed trust. People get only what their job requires, nothing accumulated over time.
  • Identity lifecycle management: structured joiners-movers-leavers processes mean access is provisioned correctly at onboarding and revoked completely and immediately on departure.

What Ungoverned Access Looks Like

A pattern seen across many organisations: former staff with accounts still active, contractor logins left over from a project that ended years earlier, MFA enforced on some systems but not others, offboarding handled informally with no record that access was actually removed. None of it is a confirmed breach on its own, but each is a live GDPR exposure, and together they’re difficult to defend under regulatory scrutiny.

Quick Answers (IAM FAQ)

Q: We have passwords and a basic login policy. Isn’t that enough?

Password-only authentication isn’t considered sufficient on its own. If a password is compromised anywhere, even on an unrelated service, it can be reused against your systems. MFA is the control that stops a compromised credential from being enough by itself.

Q: What’s the single highest-risk gap most businesses have?

Offboarding. Access created for someone starting a role is usually done carefully; access removed when they leave is often handled informally, if a checklist exists at all. That’s exactly where accounts get left active.

Book a cyber security consultation with Newtec and request an access governance review.

Dublin: (01) 531-3777
Shannon: (061) 708-820
Limerick: (061) 708-821
Website: newtecservices.ie

Further Reading (Primary Sources)

Related Posts