Skip to content

Cyber Security

The control plane for humans, workloads and agents

Identity is where authorisation decisions are made and where most intrusions now begin. This domain covers workforce, customer, machine and autonomous-agent identity - issuance, authentication, entitlement, elevation, certification and revocation.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    Identity Fabric Strategy & Directory Consolidation

    On-PremCloudHybridAdvise

    One coherent identity plan across the directories, tenants and clouds the organisation accumulated.

    • Directory, tenant and authoritative-source assessment
    • Target identity fabric with authentication and authorisation topology
    • Consolidation, migration and legacy-directory decommissioning roadmap
  2. 02

    Federation & Single Sign-On Engineering

    On-PremCloudHybridBuild

    One centrally revocable login across the application estate, including the awkward legacy tail.

    • SAML and OIDC integration patterns per application class
    • Header-based, Kerberos and thick-client bridging for legacy systems
    • Session lifetime, token binding and single-logout policy
  3. 03

    Phishing-Resistant Authentication

    On-PremCloudHybridBuild

    Authentication that survives the adversary-in-the-middle kits currently in circulation.

    • FIDO2, passkey and certificate-based credential rollout
    • Risk-based conditional access and step-up policy
    • Legacy protocol, fallback factor and MFA-bypass path elimination
  4. 04

    Privileged Access Management & Just-in-Time Elevation

    On-PremCloudHybridBuildRun

    No standing administrative access anywhere, with every privileged session accounted for.

    • Privileged account discovery, vaulting and credential rotation
    • Just-in-time elevation with approval, duration and scope binding
    • Session isolation, recording and privileged-activity analytics
  5. 05

    Identity Governance & Administration

    On-PremCloudHybridBuildRun

    Joiner, mover and leaver handled by process and event rather than by ticket and memory.

    • Role model, entitlement catalogue and segregation-of-duties ruleset
    • SCIM-based automated provisioning and deprovisioning
    • Access certification campaigns with risk-weighted reviewer routing
  6. 06

    Customer Identity & Access Management

    CloudHybridBuild

    Registration and sign-in that is fast, resistant to abuse, and lawful in every market you sell in.

    • Registration, authentication, recovery and progressive-profiling flows
    • Consent, preference and cross-border transfer handling
    • Bot, credential-stuffing and account-takeover defence
  7. 07

    Non-Human & Workload Identity

    On-PremCloudHybridAdviseBuild

    Service accounts, tokens and workloads brought under the same lifecycle discipline as people.

    • Non-human identity discovery, ownership and criticality mapping
    • Workload identity and secretless authentication patterns
    • Short-lived credential issuance, rotation and orphan reclamation
  8. 08

    AI Agent Identity, Delegation & Authorisation

    CloudHybridAdviseBuild

    Autonomous agents get registered identities, bounded authority and an auditable chain of delegation.

    • Agent registry with human owner, purpose and blast-radius classification
    • Delegated-authority model with scoped, short-lived, revocable credentials
    • Action logging, policy-based tool authorisation and stop controls
  9. 09

    Identity Threat Detection & Response

    On-PremCloudHybridBuildRun

    Catch the intrusion that arrives holding valid credentials and a valid token.

    • Detections for token theft, session hijack, consent abuse and persistence
    • Directory attack-path monitoring and privilege-escalation alerting
    • Identity-specific containment playbooks with session and token revocation
  10. 10

    Directory & Domain Attack-Path Hardening

    On-PremHybridAdviseBuild

    Close the escalation paths every operator finds first, and be able to rebuild if they are used.

    • Tiered administration model and privileged workstation design
    • Attack-path remediation, delegation cleanup and legacy protocol removal
    • Forest or tenant recovery plan with rehearsed restoration
  11. 11

    Cloud Infrastructure Entitlement Management

    CloudHybridBuildRun

    Right-size the tens of thousands of cloud permissions nobody has ever reviewed.

    • Effective-permission computation across accounts, roles and resource policies
    • Least-privilege policy generation from observed usage
    • Continuous entitlement drift detection and toxic-combination alerting

Technical deep dive

Defeating adversary-in-the-middle session theft when the password and MFA are both correct

Applies to every organisation using federated sign-in with push or one-time-code MFA - the technique is commodity, sold as a service, and works against any factor a user can relay.

What this is

An identity control plane where the credential is bound to the origin and the device, the issued token is bound to the client that requested it, and post-authentication behaviour is monitored as its own detection surface. The design assumes the user will be phished and removes the value of what the phishing captures.

The problem being solved

A reverse-proxy phishing kit sits between the user and the real identity provider. The user sees a genuine sign-in page because it is the genuine sign-in page, proxied. They enter the password; the proxy relays it. The provider sends an MFA challenge; the user approves it. The provider issues a session token; the proxy captures it and replays it from its own infrastructure. Every control reports success: correct password, satisfied MFA, valid token. The attacker is now inside the session, and the first material action is usually a mailbox rule and an OAuth grant that survives a password reset.

Why it is hard

  • Every user-relayable factor fails. Push, one-time codes and SMS are all relayable by definition, because the user can be induced to hand them to a proxy.
  • Token replay looks like the user. The token is legitimately issued; without binding, nothing distinguishes replay from a location change.
  • Persistence outlives credential reset. Mailbox rules, application consent grants and registered devices survive a password change, so containment that stops at reset is incomplete.

Reference architecture - step through it

all
ACTORSAUTHENTICATIONAUTHORISATIONDETECTION & RESPONSEWorkforce userbrowser + hardwareauthenticatorAiTM proxyrelays credentials and tokensAdministratorprivileged operationWorkload / agentnon-human principalOrigin-bound credentialassertion signed over originDevice posturemanaged, compliant, attestedToken bindingtoken tied to client keyJIT elevationno standing privilegeIdentity providerpolicy decision pointContinuous evaluationrevoke mid-session on signalConsent governanceapp grants require approvalRelying applicationstoken consumersITDR analyticsimpossible travel, tokenanomalyPersistence detectionmailbox rules, new grantsAutomated containmentrevoke sessions and tokensUnified identity loghuman and non-humansigns assertionorigin mismatch → failsrevoke
Authentication policy that assumes the user will be phishedyaml
policy: workforce-signin
  authentication:
    allowed_methods: [webauthn_platform, webauthn_roaming, cert_based]
    disallowed:  [sms, voice, push_approve, totp]   # all user-relayable
    legacy_protocols: blocked                       # no basic-auth fallback
    factor_registration_requires: existing_phishing_resistant_factor

  token:
    binding: client_key_required        # stolen token is non-portable
    access_token_lifetime: 15m
    refresh_binding: device_key
    continuous_evaluation:
      revoke_on: [risk_elevated, device_noncompliant, account_disabled,
                  network_change_to_untrusted]

  conditional_access:
    - if: {app_class: privileged, action: any}
      require: [phishing_resistant, compliant_device, jit_elevation]
      max_session: 8h
    - if: {device_state: unmanaged}
      require: [phishing_resistant, browser_isolation]
      block: [file_download, token_persistence]

  detections:                          # post-authentication, high fidelity
    - id: IDN-011  on: mailbox_rule_created
      where: action in [delete, move_to_rss, forward_external]
      severity: high  respond: contain_identity
    - id: IDN-014  on: oauth_grant_created
      where: scope contains [Mail.ReadWrite, offline_access]
        and publisher_verified == false
      severity: high  respond: revoke_grant + contain_identity

  containment_playbook: # order matters - reset alone leaves persistence
    1: revoke_refresh_tokens
    2: terminate_active_sessions
    3: remove_attacker_registered_factors
    4: revoke_oauth_grants_created_in_window
    5: delete_malicious_inbox_rules
    6: force_credential_reset

Measured change

MeasureBeforeAfter
Relayable authentication factors in use3 (push, code, SMS)0
Value of a captured session tokenfull account accessnon-portable, bound to client key
Mean time to contain a compromised identity4.5 hoursunder 60 seconds, automated
Persistence artefacts surviving containmenttypically 2–30 - playbook removes before reset

The design stops trying to prevent the user from being phished, which is a losing objective, and instead removes the value of everything the phishing captures.

Talk to an identity & access management specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours