BeyondTrust Research: 75% of Cyberattacks Trace Back to Identity and Privilege Exposure
Research linking a large share of cyberattacks to identity and privilege exposure reinforces a point security teams already see in incident response: attackers do not need to exploit every layer when one trusted account can open the door to critical systems. Privileged access management is the discipline that limits the blast radius when identity controls are tested.
Why privilege exposure persists
Privilege is often granted for operational speed and then left in place. A support engineer may retain access after a project ends, a service account may accumulate permissions as applications change, or a remote access tool may provide broad reach without sufficient session oversight. These gaps are difficult to see when entitlement reviews and infrastructure logs are managed separately.
Attackers understand this fragmentation. Credential theft, phishing, token abuse and social engineering can all become more damaging when accounts have standing administrator rights. The initial compromise may be ordinary; the escalation path is what turns it into a business crisis.
Controls that reduce exposure
A strong PAM architecture begins with discovery. Organisations need an inventory of privileged human and machine identities, the resources they can reach and the owners responsible for them. This should include cloud roles, local administrator rights, database accounts, secrets in pipelines and third-party support access.
Least privilege is more effective when combined with time limits. Just-in-time access, approval and automatic expiry reduce the window in which a stolen identity can be used. Credential rotation and vaulting address the risk of exposed secrets, while workload identity can remove static credentials from application paths.
Session management supplies accountability and detection. Recording privileged connections, applying command restrictions and correlating activity with change tickets can expose abnormal behaviour earlier. High-risk sessions should be subject to stronger authentication and, where appropriate, live intervention.
Turning research into a programme
Security leaders should translate identity exposure into measurable controls: fewer standing administrators, greater coverage of critical assets, faster revocation and more sessions tied to named owners. Prioritise domain control, production cloud, backup, security tooling and remote support because compromise in these areas can accelerate recovery failure or lateral movement.
The strongest programmes connect PAM with identity governance, endpoint security and incident response. That combination lets teams prevent unnecessary privilege, detect misuse and remove access quickly when an identity or session becomes untrusted.