Deconstructing Your Privileged Attack Surface
Download resourcesAbout this session
Sam Kumarsamy, head of product marketing at Remediant, argues that standing privileged access is a larger and less visible attack surface than most organisations admit. He opens with an Enterprise Management Associates survey: standing admin accounts are common, non-administrators routinely hold and use privileged access to business servers, and accounts belonging to people who have left the business are found regularly. Remediant's own scans, he says, find hundreds of admins with round-the-clock access to a single workstation in large companies, and one compromised admin account is enough to move laterally across thousands of systems, as the NotPetya cases at Maersk and Merck showed. He then lays out a four-step approach for evaluating any solution: agentless, continuous discovery across Windows, Linux and Mac; dashboards that let executives track sprawl reduction and let practitioners start with the riskiest groups such as domain admins; one-click removal of excessive rights; and just-in-time privileged access fronted by multi-factor authentication to reach zero standing privilege. The talk closes with a short Remediant pitch and an invitation to Q&A.
For years, Identity and
security teams have been challenged with gaining visibility into and managing privileged access sprawl in their organization. Even today, there is no easy or cost-effective way for IT business and technical executives to manage and reduce this privileged access attack surface in systems. The bad guys need to obtain access to just one of these hidden or unknown admin accounts to move laterally from one compromised system to another to access the crown jewels of a company
and cause financial damage. Attend this webinar to learn:
· The challenges of growing privileged attack surface
· Best practices for managing the privileged access risk
· A new approach to measure and reduce your attack surface
Key takeaways
- Inventory privileged access continuously and without agents across Windows, Linux and Mac; point-in-time audits miss accounts added by mergers and never revoked after departures.
- Start remediation with the riskiest group, typically accounts with domain-wide admin rights, and question whether each one truly needs it.
- Replace round-the-clock standing admin rights with just-in-time access scoped to one resource and one time window, revoked automatically afterwards.
- Front every privileged elevation with multi-factor authentication so a stolen password alone does not grant admin rights.
- Give executives a trend view of privileged-account counts so reduction can be tracked weekly or monthly toward zero standing privilege.
Speakers

Sam Kumarsamy brings more than 20 years of experience in marketing, sales and business development at MobileIron, Gigamon, Infoblox, Blue Coat, Check Point, Cisco, Citrix, E&Y as well as successful VC-funded security and networking startups… Read moreRead less
Sam Kumarsamy brings more than 20 years of experience in marketing, sales and business development at MobileIron, Gigamon, Infoblox, Blue Coat, Check Point, Cisco, Citrix, E&Y as well as successful VC-funded security and networking startups. Currently, he is the Senior Director/Head of Product Marketing at Remediant responsible for GTM strategy and marketing of their privileged access management (PAM) solution. He has defined, launched, promoted and sold several disruptive products, services and solutions globally, both directly to customers as well as through channels. Sam has a bachelor’s degree in engineering from India and an MBA from the W.P. Carey School of Business at Arizona State University.
