Glossary

IAM

IAM controls who can access what. It's the system that creates accounts, manages passwords, and decides which employees can see which data. Get it wrong, and the wrong people see the wrong things.

What is IAM?

Identity and Access Management - systems and policies that manage digital identities and control access to organizational resources.

Why Should You Care?

Weak IAM is one of the most exploited attack paths into enterprises. Compromised credentials—whether from phishing, token theft, or credential exposure in code repositories—give attackers legitimate-looking access to sensitive systems, making the breach harder to detect and contain. A single over-privileged account or an identity that wasn't deprovisioned when an employee left can grant attackers a foothold that lasts months before discovery.

Is your business exposed?

Real-World Example

In 2019, a misconfigured web application firewall combined with overly broad cloud permissions allowed an attacker to access roughly 106 million customer records from Capital One via that company's AWS environment. More recently, the LAPSUS$ group in 2022 systematically stole or phished cloud credentials and used them to breach companies including Okta, Microsoft, and Nvidia—showing that even MFA can be bypassed when credentials and sessions are compromised at the source.

How to Protect Against IAM

  1. 1.

    Review all user access rights quarterly

  2. 2.

    Implement least privilege access

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required