Zero Assumptions #5: Your cloud is hardened. Your on-premises network is the open door.


Zero Assumptions · Week 5 of 25

Your cloud SSO is hardened.
So your identity perimeter is secure.

92% of enterprise employees still authenticate via username and password — mostly against on-premises systems outside your cloud MFA scope. Attackers target the seam between the two environments, and it is almost never monitored.

Cloud-first security programmes have driven significant investment into securing Microsoft 365, Okta, Azure AD, and the SaaS applications behind them. Conditional access policies, phishing-resistant MFA for cloud services, and SSO federation are deployed and working. The security team's attention has followed the organisation's data — into the cloud.

On-premises infrastructure — legacy ERP systems, manufacturing execution platforms, local Windows domain authentication — is considered a secondary concern, scheduled for eventual modernisation.

The reality: threat actors deliberately target the authentication seam between modern cloud SSO and legacy on-premises infrastructure — precisely because it is where enforcement is inconsistent and monitoring is sparse.

92%

Of enterprise employees still rely on usernames and passwords as their primary authentication method — the majority accessing legacy on-premises systems explicitly excluded from cloud MFA policies.

Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026

The Golden Ticket — the attack your cloud MFA cannot stop

The Golden Ticket and Silver Ticket attack techniques target the Kerberos authentication protocol underpinning Active Directory. An attacker who compromises a single domain controller can forge authentication tickets for any user in the domain — granting access to every Kerberos-protected resource regardless of what cloud MFA policies are in place for those users' cloud accounts.

These techniques remain among the most effective post-compromise lateral movement tools available precisely because on-premises Kerberos infrastructure is rarely included in cloud-era security hardening programmes. Your conditional access policy in Azure AD has no visibility into a forged Kerberos ticket on your on-premises network.

76%

Of organisations still use username and password as the dominant authentication method — with the majority of those password-authenticated sessions occurring against on-premises or legacy systems outside cloud MFA scope.

Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026

The monitoring blindspot compounds the problem. When cloud and on-premises authentication events live in separate logs with no shared identifier, impossible-travel detection and anomalous access alerts cannot correlate across the boundary. An employee who authenticates to cloud services from Stockholm at 09:00 and to an on-premises system from a different location at 09:15 generates no alert — because neither system can see the other's events.

The blueprint — one credential, three access layers

FIDO2 for cloud SSO: Phishing-resistant authentication for Microsoft 365, Okta, SaaS applications. Origin binding defeats AiTM. Already covered in Weeks 2 and 3.

PIV smart card for on-premises: The same hardware token supports PIV (Personal Identity Verification) for Windows domain authentication, legacy ERP login, and VPN access — replacing the password-based Kerberos authentication that Golden Ticket attacks target.

Unified audit trail: When cloud and on-premises authentication events share a hardware credential identifier, impossible-travel detection and lateral movement alerts work across the boundary for the first time. The monitoring blindspot closes by design.

Pillar 1 complete — adversary tactics & validation

Week 1 — The endpoint illusion: EDR blind spots & credential harvesting.
Week 2 — Network-delivered codes: AiTM toolkits & FIDO2 origin binding.
Week 3 — The helpdesk open door: Deepfakes & cryptographic recovery.
Week 4 — Sovereign hardware risk: Supply chain & certification hierarchy.
Week 5 — Hybrid infrastructure blindspot: Kerberos seams & unified credentials.
Week 6 (next): We move into Pillar 2 — Software stack & contextual risk. Annual checklists vs continuous identity monitoring.

Next week — Pillar 2 begins

Week 6 — Risk assessment integration
Annual penetration tests and compliance checklists tell you what your security posture looked like on the day of the assessment. Continuous identity risk tracking tells you what it is right now. The gap between those two things is where most incidents begin.

Free passwordless audit

Running cloud MFA alongside legacy on-premises systems?

In a free 30-minute passwordless audit we'll map the specific cross-boundary attack paths in your hybrid environment and show you what a unified FIDO2/PIV deployment looks like operationally for your organisation.

No sales deck. No follow-up unless you ask.

Organisations have hardened the front door and left the connecting corridor unmonitored. One hardware credential that governs cloud, on-premises, and physical access closes the seam — not by replacing infrastructure, but by unifying the credential that spans it.

Mikael Rodin
Managing Director, Ciptor

P.S. If your environment runs cloud SSO alongside on-premises Active Directory — book a free audit. We'll identify your specific Kerberos exposure paths and show you what closing them looks like without replacing your legacy infrastructure.

New to the series? Start at ciptor.com/zero-assumptions/zero-assumptions-vol-1/

Kungsporten 4A, 427 50 Billdal, Sweden
Unsubscribe · Preferences

Ciptor

The 2026 threat landscape doesn't care about your 2024 budget. It only cares about your vulnerabilities. Join 10,000+ infrastructure leaders securing the future.

Read more from Ciptor

Zero Assumptions · Week 9 of 25 · Pillar 2: Software stack & contextual risk Your SIEM fired an alert at 09:14.Your EDR caught the same attack at 09:24. Two tools. Same attacker. Ten minutes apart. Neither told the other. Your analyst saw two separate alerts in two separate consoles and triaged them as two separate incidents. The attacker had already moved. In weeks 6, 7, and 8 we covered the operational gaps between assessment cycles, session windows, and board oversight. This week we move...

Zero Assumptions · Week 8 of 25 · Pillar 2: Software stack & contextual risk Your board approved the security budget.That means they've fulfilled their NIS2 obligation. NIS2 Article 20 does not ask your board to approve a budget. It requires management bodies to oversee, be trained in, and be personally liable for your organisation's cybersecurity risk management. Most boards have done none of these things. Most CISOs have not told them. In every previous volume of this series, the assumption...

Zero Assumptions · Week 7 of 25 · Pillar 2: Software stack & contextual risk Your morning login was legitimate.So the session running at 17:00 must be too. Session tokens are hijacked, not phished. Once an attacker has your token, they don't need your password, your MFA, or your hardware key. They already passed authentication. The question is whether your SOC finds them before they find what they came for. Last week we covered identity drift — the entitlement state that diverges from policy...