Talk to us Risks to Watch

Security Breaches in 2024: How ARCON Privileged Access Management (PAM) Could Have Prevented Them 

The Context 

Privileged Access Management is quintessentially important for protecting data, but are we doing enough? 

While recapitulating and evaluating the IT incidents in 2024, ARCON found three major IT incidents that could have been avoided if ARCON’s Privileged Access Management (PAM) had been deployed.   

Such breaches are caused by inadequate access control measures or credential abuse, and the most significant vulnerability remains the mismanagement of privileged access.   

It is important to remember that enterprise data security can only be achieved if organizations adopt an identity-centric security approach. IT environments are increasingly digitalized, decentralized, and distributed, and cyberattacks are more sophisticated. The consequences of security breaches are becoming increasingly severe.  

This blog highlights some notable IT security breaches in 2024, where the lack of effective PAM implementation contributed to the attack, and how these incidents could have been prevented with ARCON | PAM solution. 

1. Healthcare Data Breach 

In early 2024, a leading healthcare service provider from the USA fell victim to a massive cyberattack that exposed millions of patients’ personal health information (PHI). The breach occurred when a hacker accessed a privileged account held by an employee in the IT department. After successful access, the attacker was able to navigate the internal network, compromise the system, and steal sensitive data. 

How ARCON | PAM Could Have Prevented It: The healthcare service provider failed to enforce strict access controls around privileged accounts. With ARCON | PAM, the company could have implemented the following: 

  • Access and Command Control: A robust access control module ensures the deepest level of granular control. It helps the admins to control and manage which user has access to which service/ application or resources. They can even restrict or elevate specific processes or commands that can be executed and generate reports on privileged user activities. 
  • Just-In-Time (JIT) Access: ARCON | PAM enforces a just-in-time approach that allows time-bound access to privileged users to reduce the surface of privileged account attacks because privileged rights are revoked immediately after the pre-defined period is over. It denies “always-on” privileges and enforces “Least Privilege” principle. As privileges are granted on-demand, organizations can ensure a strict access control policy and maintain a robust security posture. Moreover, with JIT access on-cloud with ephemeral credentials, it grants/ generates rules to provide access only on a “need-to-know” and “need-to-do” basis. 
  • Multi-factor Authentication: ARCON | PAM supports several MFA options, including the ARCON Authenticator App, Email OTP, SMS OTP, hardware tokens, biometric authentication, facial recognition, and many more. Organizations can select the best and relevant option that meets their security needs while seamlessly integrating with their existing IT infrastructure. 

By enforcing ARCON | PAM best practices, the Healthcare service provider could have reduced the likelihood of a successful attack and better protected sensitive patient data. 

2. Fintech Data Breach 

In November 2024, a significant cyberattack targeted one of the leading financial technology firms serving major banks. The breach revealed that attackers had infiltrated the system in October, stealing almost 400 gigabytes of sensitive data. The compromised data was subsequently offered for sale on darknet forums.  

The breach was attributed to compromised credentials, highlighting vulnerabilities in access management. Implementing a robust Privileged Access Management (PAM) solution could have mitigated this risk by enforcing strict controls over privileged accounts, monitoring access, and promptly detecting unauthorized activities. 

How ARCON | PAM Could Have Prevented It: The organization’s lack of effective PAM controls allowed malicious actors to go undetected. With ARCON | PAM, the organization could have implemented the following safeguards: 

  • Credential Vaulting: Storing and securing administrative credentials in the ARCON | PAM vault would prevent unauthorized users from obtaining privileged credentials. It enables organizations to generate complex, randomized passwords for privileged accounts that cannot be easily interpreted. It also enforces password policies to ensure that the passwords are updated regularly and meet security standards. In the above incident, ARCON PAM’s credentials vaulting would have lowered the risk of credential misuse and eliminated the need for privileged users to remember and share passwords – lowering the risk of any misuse. 
  • Audit Trails and Alerts: Continuous logging and real-time alerts would have notified IT security teams of any suspicious use of privileged credentials, allowing them to respond quickly before data was compromised. 
  • Granular Level Access: With the capability of granular-level access control, the organization could manage every user’s access based on their roles, responsibilities, and tasks. It could have enabled the organization to define and enforce precise access policies for every user, reducing the risk of unauthorized access and misuse of sensitive systems and data. 

Implementing these PAM policies would have given the Fintech organization greater visibility and control over privileged access, preventing data breach. 

3. Air Traffic Control Attack 

A state-owned agency responsible for air traffic control in one of the biggest economies in Europe confirmed that it was the target of a cyber-attack that disrupted its official communications. It affected the organization’s administrative IT infrastructure, that is, air traffic control. 

How ARCON | PAM Could Have Prevented It: The breach happened due to lack of oversight on critical accounts at the aviation office. By deploying ARCON | PAM, they could have had: 

  • ITDR (Identity Threat Detection and Response): ITDR helps to build a proactive security posture against probable threats and is widely discussed in the current IT security context. Since ARCON supports ITDR approach towards security with the help of a unified range of identity security suites, including Privileged Access Management, this incident could have been prevented by timely detection of unusual and abnormal user behaviour with the help of AI/ML-based authentication algorithms. Any kind of IT oversight, unauthorized access, or malicious attempts at account takeovers are detected in real-time. 
  • Role-Based Access Control (RBAC) and Policy-Based Access Control (PBAC): Limiting access based on roles within the organization could have ensured that the admin only had access to the systems needed for their specific duties, preventing the breach of customer data. It has been observed that unrestricted endpoints and no controls over endpoint privileges also result in breaches. ARCON EPM, which has strong integrations with PAM, provides PBAC capability, which ensures access rights and permissions based on policies, especially around the endpoints. This could have prevented the malicious actor from disrupting the official communication. 

With ARCON | PAM, the air traffic Control board could have put stronger controls in place to prevent both insider threats and targeted attacks. 

Conclusion: The Growing Need for PAM in 2025 

The IT security breaches of 2024 highlight a critical fact – the security of an organization’s critical data assets depends largely on how the privileged access environment is managed. In each of these cases, a robust PAM solution could have minimized or even completely prevented the attack by building robust access control mechanism, stringent monitoring, and mandatory policies for privileged accounts.  

As cyber threats continue to evolve, businesses must prioritize managing privileged access as part of their overall security strategy. PAM isn’t just a tool; it’s a critical safeguard that can protect an organization from the dreadful consequences of IT security breaches. 

Webinar – Why an Identity-Centric Security Approach is Essential: Key Takeaways 

ARCON hosted a webinar featuring Forrester to discuss the essence of identity-centric security approach in modern-day context. On November 12th, 2024, Harshavardhan Lale, VP – Business Development, ARCON and guest speaker Geoff Cairns, Principal Analyst, Forrester shared their insights on why and how the proliferation of identities is affecting the IT security infrastructure of modern enterprises. The identities include human identities, machine identities, privileged identities, administrative identities and more.  

During the first half of the webinar, Harshavardhan from ARCON highlighted the identity-first security approach for safeguarding organizations. He also discussed how identity risk management leaders can strengthen their security posture with cutting-edge technologies. Below are the key takeaways from the first half of the session: 

  • Harshavardhan started his session with very basic insights of identities and the variety of identities that exist in IT infrastructure. The evolution of digital identities is not yet over. In fact, a lot more is about to come in the next five years. 
  • Digital identities drive business models with growth, efficiency, and excellence that is directly involved in profit-making and revenue generation. If we try to construct a digital identity, there are several parameters that are considered. Personal thoughts, likes, dislikes, professional details, online activities/ behaviour, which tools are used, where the information is stored/ saved etc. are taken into account. 
  • If we classify the types of digital identities, there are interactive identities and non-interactive identities. Interactive identities include human identities and machine identities (bots). Non-interactive identities include mobile devices, desktops, APIs, web servers, database servers, application servers and more. 
  • The typical challenges that organizations face with identities are – lack of detailed password policies, weak and reused passwords, poor role management, too many admin accounts, auditing and compliance, multiple devices per user and more. 
  • Harshavardhan added that there are different identity-based attacks that are dominant in enterprises. Some of them are – Credential Harvesting, Credential Stuffing, Social Engineering, Password-based attacks, Third/ Fourth party breaches, Attacks on AD, Kerberoasting, Pass-the-hash, Shoulder Surfing and more. 
  • At the same time, he explained why identity is at the core of a Zero Trust approach and Identity Centric Security will have to be built on Convergence of IAM, PAM, and IGA with Contextual Data Models. 

Harsh added his discussion with the reasons why identity-centric security is essential in modern context. They are – 

  • Increased Cyber Threats  
  • Remote Work and Cloud Adoption 
  • Regulatory Compliance 
  • Zero Trust Security Model 
  • User Experience 
  • Dynamic Threat Landscape  
  • Integration of Emerging Technologies: OT, IoT, AI, and machine learning 

According to him, some key features of identity-centric security are – 

  • Certificate-based authentication  
  • Risk-based adaptive step-up authentication  
  • Automated certificate lifecycle management  
  • End-to-end encryption  
  • Multi-cloud ready  
  • Compliance management  
  • Post-quantum-ready solutions  
  • Built-in crypto-agility and certificate authority (CA) resilience  
  • Public and private PKI  
  • Centralized visibility and control of digital certificates 

Before concluding his session, Harshavardhan gave some crucial organizational details of ARCON, a brief introduction of all the IAM solutions of ARCON and how the organization is acknowledged by global analysts’ communities consecutively in the last several years. Nevertheless, Harshavardhan also added that ARCON provides its services to multiple industry segments globally and thus it caters to the essential requirements of identity-centric security approach. 

In the latter half of the webinar, Geoff Cairns from Forrester discussed why securing your organization’s core assets is more critical amid proliferation of human and machine identities. The key takeaways from his session are as follows. 

  • Based on data from Forrester’s 2023 Security Survey, it has been observed that the customers are struggling with the complexity of their IT environment. The challenge is more around centralized visibility that can lead to identity sprawl such as orphan accounts over privileged users and over-permissioned accounts (or over-entitlements).  
  • Geoff added that the evolving threat landscape is both internal and external. The hackers are capitalizing on identity-based attacks where legacy systems often are in tech silos leading to gaps in IT processes. This is further evidenced by organizations that have recently been in the news. United healthcare had acquired Change Healthcare a couple of years ago. During the process unfortunately, the organization failed to put MFA on some externally facing servers, and that resulted in identity abuse by phishing the credentials with the help of social engineering techniques. 
  • Referring to the Forrester Security Survey once again, Geoff presented some primary drivers that resulted in purchasing of IAM solutions in the last 12 months. 26% of respondents (security decision makers responsible for IAM security) indicated that a top driver was replacing an existing IAM solution that was ineffective or too costly. 25% responded that cloud migration requires new IAM solutions to meet the necessary security and compliance requirements in the organization. 
  • Continuing with the legacy IAM technology, it is a fact that with the passage of time, any IAM solution becomes less secure, inadequate robustness of the features, difficult to upgrade and costly to operate. Interestingly, it is increasing every year. The technology replacement trends that are seen in 2022, have turned more challenging in 2023 and onwards. 
  • Adding to what Harsh discussed earlier, Geoff emphasized that identity-centric security is the key to adherence to the core principles of Zero Trust. 

Geoff also discussed the dynamic accelerators for identity security namely – 

  • Cloud and SaaS adoptions 
  • DevOps methodology 
  • Machine Identities 
  • Extended third parties 
  • Organizational amendments 

Adding some essentials for identity-centric security approach, Geoff discussed the key areas – 

  • Visibility and Governance 
  • Identity Lifecycle Automation 
  • Just-In-Time Access and Zero Standing Privileges 
  • Identity Threat Intelligence 
  • Integrated response 

Conclusion 

Before the final wrap, the webinar concluded by discussing several questions raised by the participants and moderated by Apratim Maity from ARCON’s marketing team. Both Geoff and Harsh shared their valuable insights and recommendations while answering the questions one by one. 

ARCON Privileged Access Management: Why the Solution is Obvious Choice of Modern Enterprises?  

Privileged Access Management (PAM) is a foundational security requirement. The solution is crucial to secure elevated (privileged) access to critical IT resources; and PAM offers adequate safeguards against privileged credentials abuse or misuse, data breaches and ever lurking insider and third-party threats.    

The importance of having PAM solution in place has increased significantly amid growing hybrid or remote work cultures. Indeed, in parallel with Covid 19 pandemic, organizations felt more and more need for secure remote access. Nevertheless, traditional tools such as Virtual Private Networks (VPNs) and Virtual Desktop Infrastructures (VDIs) were exposed to security vulnerabilities. Moreover, these tools are resource hungry. An advanced solution such as ARCON PAM helped global organizations to overcome challenges. The solution’s secure web gateways are lighter than traditional tools, enabling secure administrative and third-party access to data, systems, and machines.  

Furthermore, the solution’s key features include: 

  • An integrated ticketing flow for managing access requests 
  • End-to-end secure privileged sessions 
  • Comprehensive audits and reporting capabilities 
  • A dynamic dashboard for real-time visibility 
  • Seamless integration with Active Directory 

Additionally, ARCON PAM for remote access employs role-based access control (RBAC) to ensure that users have appropriate access to only the resources and applications necessary for their roles, reducing the risk of unauthorized access or privilege misuse.  

Another driver for increased demand for PAM solutions is cloud computing. Most modern organizations have their workloads and data spread across IaaS, PaaS and SaaS infrastructure. Access to cloud resources- applications, databases, developer tools and administrative consoles- have increased significantly. 

These have necessitated the need for Cloud Infrastructure Entitlement Management capabilities that offer comprehensive visibility over cloud entitlements, access paths, and over privileges and required risk mitigation. 

However, the pace at which identities- both human and non-human- are created to manage tasks, controlling them in terms of access with static controls provided by CSPs is very difficult and this is where a modern PAM solution like ARCON accelerates cloud journey. In addition to a gamut of CIEM features, ARCON offers classic PAM capabilities like, Just-in-time Privileges, on cloud to safeguard data and cloud resources.  

In addition to secure remote access and PAM on-cloud capabilities, security and technology leaders find merit in PAM for its advanced capabilities. Identity-based attacks are the most dreaded IT incidents. ARCON with its highly advanced Identity Threat Detection and Response (ITDR) capabilities, like detecting anomalous behavior patterns, activities and risky identities on near real-time basis helps organizations to build proactive security posture and ensures business resiliency.  

And finally, by implementing ARCON PAM, IAM leaders and IT heads can optimize the strategic value and business outcomes. ARCON has the largest connector stack, which ensures rapid implementation across hybrid IT environment. Besides, on-the-fly connectors ensure out-of-box integration. ARCON PAM’s micro-service-based architecture is another reason why the deployments are rapid and easier, the TCO is low, the ROI is high.   

While the product architecture, the broad range of features and functionalities makes ARCON PAM an industry thought leader, a high degree of customer-centricity ensures that it is the most lovable brand in the PAM market. Testimony to this fact is ARCON | Privileged Access Management has been recognized as the Customers’ Choice in the Gartner Peer Insights for PAM for four years in a row- 2021,2022, 2023 and 2024.  

Here are some testimonies from our esteemed customers.