Firewalls still matter, but most serious incidents today do not begin with someone breaking through one. They begin with a valid username and password, stolen, reused or guessed, used by someone who should not have it. For ministries, banks and companies running critical services, identity is now the control that decides whether an attacker remains a nuisance or becomes a catastrophe.
Start with the identity lifecycle: joiner, mover, leaver
Most access problems are process problems, not technology problems. Accounts are created quickly when someone joins, rarely adjusted when they change role, and forgotten when they leave. A sound lifecycle has three parts:
- Joiner: access is granted from a role-based template approved by the business owner, not copied from a colleague.
- Mover: a change of department triggers a review, and old permissions are removed rather than simply adding new ones.
- Leaver: termination in the HR system drives account disablement on the same day, including VPN, email, cloud consoles and any shared credentials the person knew.
Treat the HR system as the authoritative source, and run periodic access recertification in which managers confirm who still needs what. Orphaned and dormant accounts are a favourite target for attackers, and they are easy to find once you look.
Least privilege and privileged access management
Administrator accounts are the keys to the whole estate. Least privilege means every person and system holds only the access needed for the task, and only for as long as it is needed. In practice:
- Separate daily-use accounts from administrative accounts. Nobody should read email while logged in as a domain administrator.
- Use a privileged access management (PAM) solution to vault credentials, rotate them automatically and record administrative sessions.
- Prefer just-in-time elevation, where admin rights are granted for a limited window with an approval trail, over standing privileges.
- Issue named accounts to administrators so every action is attributable, and avoid shared admin logins.
- Apply the same controls to vendors and third parties: time-boxed, approved and monitored.
ISO/IEC 27001 (Annex A access control), NIST SP 800-53 (the Access Control family) and the CIS Controls all expect this discipline, and both PCI DSS v4.0.1 and the SWIFT Customer Security Programme place particular weight on restricting and monitoring privileged access.
MFA: not all factors are equal
Multi-factor authentication stops most password-only attacks, but attackers have adapted, so it helps to understand the ladder:
- SMS and voice codes: better than nothing, but exposed to SIM swapping and interception.
- Authenticator app codes and push notifications: stronger, yet vulnerable to real-time phishing proxies and to push fatigue, where users approve prompts just to make them stop. Number matching reduces this risk.
- Phishing-resistant MFA: FIDO2/WebAuthn security keys and passkeys, or certificate-based smart cards, bind the login to the genuine site, so a fake page cannot capture a usable credential.
Apply phishing-resistant methods first to administrators, finance and payment staff and remote access, then widen the circle. Plan secure recovery as well: a helpdesk that resets MFA after a simple phone call undermines the whole design.
Do not forget service accounts and machine identities
Service accounts, API keys and certificates often outnumber human users, rarely use MFA and seldom expire. Inventory them, assign an owner to each, remove interactive logon rights, store long random secrets in a vault, rotate them, and alert on use from unexpected locations. NIST SP 800-207 on Zero Trust Architecture treats every identity, human or machine, as something to be verified continuously rather than trusted because of where it sits on the network.
A practical starting sequence
- Inventory all accounts, including privileged, dormant and service accounts.
- Enforce MFA on every remote and administrative access path.
- Vault and rotate privileged credentials.
- Automate the leaver process from the HR source.
- Move high-risk roles to phishing-resistant MFA and review access every quarter.
How Wethaq ICT helps
Wethaq ICT assesses your current identity posture, designs a role-based access model and a PAM and MFA roadmap that fits your systems, and supports implementation and ongoing access reviews. Our SOC can also monitor privileged activity and unusual sign-ins so that misuse is detected early, in line with the frameworks your regulators and auditors expect.
Let’s build a secure foundation for your digital future
It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.

