39:51A Hacker’s Dream: Unmanaged Privileges
Download resourcesAbout this session
Chris Hills, deputy CTO at BeyondTrust and a former privileged-access lead at a large brokerage, looks at what the rush to remote work did to privilege hygiene. After describing COVID-themed phishing and smishing, he frames secure remote access as three decisions: how people connect (never RDP or SSH exposed to the internet, and no VPN clients on unmanaged home computers), what they reach (on-prem, cloud or both, and the bandwidth cost of routing everything back), and how the help desk supports them. He then lists the risks: remote access as the top attack vector, unmanaged credentials including service, application and network-device accounts, shadow IT from staff downloading free remote tools, and the difficulty of proving compliance when data is downloaded to a home file system. Using the Lockheed Martin kill chain, he argues the pandemic created a third threat category, the trusted person who is now external. His recommendations are granular access, least privilege, honouring change control, session and keystroke recording for sensitive accounts, VPN logs aggregated into a SIEM, MFA on privileged access, password injection and rotation, and someone actually reviewing the logs. The final third presents BeyondTrust's three PAM pillars.
- In times of crisis, good security practices are often the first thing to go. Organizations are being forced to revisit their “temporary” remote working policies and tools. An expanding remote workforce can increase your security risk, especially if your IT and Support employees use non-secure remote access tools as temporary measures. Are temporary remote access tools making your organization vulnerable to cyber-attacks?
In this session you will learn:
Risks and security considerations related to an extended remote workforce - Vulnerabilities posed by remote working tools, such as BYOD and free Shadow IT solutions
- Practical guide on how to quickly implement and scale strong security protocols to enable long-term remote work
Key takeaways
- Never expose RDP or SSH to the internet and do not hand VPN clients to unmanaged home computers; reserve VPN for corporate-owned, patched, monitored devices.
- Discover and vault every privileged credential, not just domain admins: service accounts, application accounts, scripts with clear-text passwords and default logins on network gear.
- Use password injection and rotation so a remote administrator never types or sees a privileged password on a home machine, and add MFA on top.
- Pick one sanctioned remote-support tool for the whole organisation; free tools chosen by individual staff or branches become an unpatched shadow-IT problem after the crisis.
- Record sessions for sensitive accounts, aggregate VPN and remote-access logs in a SIEM, and assign someone to actually review them for odd geolocations and behaviours.
Speakers

Christopher L. Hills has more than 15 years’ experience as a Senior Security and Architecture Engineer operating in highly sensitive environments. Chris is a military veteran of the United States Navy and started with BeyondTrust after his most… Read moreRead less
Christopher L. Hills has more than 15 years’ experience as a Senior Security and Architecture Engineer operating in highly sensitive environments. Chris is a military veteran of the United States Navy and started with BeyondTrust after his most recent role leading a Privileged Access Management (PAM) team as a Technical Director within a Fortune 500 organization. In his current position, he has responsibilities as a Senior Solutions Architect consulting on PAM implementations and reports to the Office of the CTO as an acting Deputy CTO. In his free time, Chris enjoys spending time with his family on the water with their 32-foot speedboat in the summer and taking to the sand dunes and off-roading in the winter.
