How Hybrid Environments Fuel Identity-First Attacks

In this final installment, the focus shifts to how hybrid environments fuel identity-first attacks and the protection-first measures organizations must take.
Sept. 12, 2025
6 min read

Key Highlights

  • Hybrid environments have expanded the attack surface, making every identity — human and non-human — a potential target.

  • Traditional IAM tools and detect-and-respond strategies are no longer sufficient against fast-moving, automated attacks.

  • Identity security requires a universal “floor” with protection-first measures like MFA and just-in-time access to reduce account compromise at scale.

Attackers have now pivoted to account compromise as their primary method of initial access and exploitation. As Brett Arsenault, Microsoft’s CISO, put it: “Hackers don’t break in, they log in.” It’s not a new phenomenon, but it’s one that we as defenders have yet to address.

About the Author

Rob Ainscough

Chief Identity Security Advisor

Rob Ainscough is Chief Identity Security Advisor, EMEA, at Silverfort, where he helps organizations strengthen their defenses against identity-based threats. He brings extensive expertise in identity security strategy and works closely with enterprises to address risks associated with account compromise, privileged access and evolving attack techniques.

Sign up for SecurityInfoWatch Newsletters
Get the latest news and updates.

Voice Your Opinion!

To join the conversation, and become an exclusive member of SecurityInfoWatch, create an account today!