Zero Assumptions · Week 6 of 25 · Pillar 2: Software stack & contextual risk
Your annual pen test showed no critical findings. So your identity posture is under control.
A penetration test is a point-in-time snapshot. Your identity risk changes daily — new users, new devices, drifting permissions, unchecked access accumulation. The gap between the snapshot and today is where most incidents begin.
|
|
Welcome to Pillar 2 — Software stack & contextual risk
Pillar 1 covered the adversary tactics targeting your identity controls. Pillar 2 examines the software and operational layer that determines whether your controls can actually respond to those threats in real time. Volumes 6–10 cover risk integration, session authentication, boardroom accountability, signal orchestration, and physical/logical convergence.
|
Most organisations measure their security posture with instruments that are calibrated to the past. Annual penetration tests, quarterly vulnerability scans, biannual compliance audits — all of them tell you what your environment looked like at a fixed point in time. The security team completes the assessment, files the report, closes the findings, and returns to operations.
The assumption: a clean assessment means a controlled posture.
The reality: identity risk is continuous and dynamic. Permissions accumulate. Users leave systems without full deprovisioning. Service accounts proliferate. Access drifts. None of these changes generate an alert in a point-in-time assessment framework — but all of them generate opportunity for an attacker operating between assessment cycles.
|
59%
Of organisations increased their security budget and investment as the most common response to a breach — meaning almost 60% were operating reactively, spending on security after the incident rather than before it.
Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026
|
The identity drift problem your assessments cannot see
Identity drift is the gradual accumulation of access entitlements, credential states, and authentication configurations that diverge from policy over time. It is not caused by attacks. It is caused by normal operations: a user changes roles and retains access to their previous systems; a contractor's account is not deprovisioned on their last day; an application is configured with a service account that shares credentials with three other systems.
Each of these creates a window that an attacker can exploit. None of them trigger a security alert, because from a technical perspective they are all legitimate access events — they just reflect a state that should not exist.
|
43%
Of passwordless adoption deployments are currently limited to specific user personas — primarily executives and privileged IT staff — leaving the majority of the workforce outside the scope of continuous identity assurance controls.
Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026
|
The fragmented ownership of identity security compounds the drift problem. In most organisations, provisioning is managed by HR, access control by IT, privileged access by the security team, and application permissions by individual development teams. Without a unified identity governance layer, no single team has visibility into the complete access state of any given user — let alone the ability to detect when it drifts.
|
The blueprint — continuous identity risk integration
Replace point-in-time with continuous: Deploy identity governance tooling that surfaces access entitlement state in real time — not quarterly. Every user's access footprint should be visible and queryable at any moment, not just on the day of the assessment.
Instrument the employee lifecycle: Provisioning and deprovisioning should be automated events triggered by HR system signals — not manual processes completed by IT tickets. A user who leaves on Friday should have their access state changed that afternoon, not the following Monday when someone processes the request.
Baseline and alert on drift: Define the expected access state for each role and user type. Alert when a user's actual entitlements diverge from that baseline — not when they use those entitlements in a suspicious way, but when the entitlements themselves are out of policy. Catching the drift prevents the exploitation.
|
One control that continuous monitoring cannot drift around
Governance tooling closes the entitlement drift gap. But there is one class of credential that eliminates the credential risk entirely, regardless of what governance layer sits above it — the hardware security key. When authentication is anchored in a physical device with asymmetric cryptography, there is no password to harvest, no session to hijack, and no hash to replay. The drift that matters — credential exposure — disappears at the hardware level.
Not all hardware keys deliver the same assurance. The two questions that determine whether a key is the right fit for a given deployment:
| Question |
What it determines |
| Who manufactured the chip and where? |
Supply chain sovereignty and nation-state risk exposure |
| Does it support biometric verification on-device? |
Whether PIN sharing and physical key handover remain a residual risk |
|
Two keys worth understanding — for different deployment contexts
NeoWave (ANSSI-certified, EU sovereign supply chain)
French-engineered and ANSSI Security Visa certified — the only EU-sovereign hardware authentication standard that formally validates the supply chain, not just the protocol. The relevant context: regulated industries, defence supply chains, and environments where the manufacturer's national jurisdiction is a material procurement consideration. CC EAL6+ secure element. No biometric sensor — authentication is PIN-bound to the device, not biometric-bound to the user.
Feitian BioPass K49 (CC EAL6+, on-device fingerprint)
Built on the FT-JCOS secure element certified to CC EAL6+ — the highest assurance level available in production hardware authentication today. The K49 adds on-device biometric verification: the fingerprint template never leaves the chip, authentication is user-bound rather than device-bound, and PIN-sharing or physical key handover ceases to be a residual risk. The relevant context: workforce-scale deployment where usability and biometric binding matter as much as cryptographic depth. PQC-ready via dedicated ML-KEM/ML-DSA hardware co-processor.
|
Both keys are available through Ciptor. The right choice depends on your deployment context, regulatory environment, and risk profile — not on which has more features. If you're evaluating both, the free audit is the right place to work through the decision.
|
Series recap — where we are
Pillar 1 — Adversary tactics (Weeks 1–5): EDR blind spots, AiTM bypass, deepfake helpdesk attacks, hardware supply chain risk, hybrid Kerberos blindspots.
Week 6 — Risk assessment integration: Annual assessments vs continuous identity monitoring. Catching drift before exploitation.
Week 7 (next): Continuous authentication vs static sessions. Your morning login doesn't mean you're still who you were at 09:00.
|
Coming up next week
Week 7 — Continuous authentication vs static sessions
Identity is verified at morning login. But session tokens get hijacked, not phished — and an authenticated session from 09:00 is still valid at 17:00 even if the user who created it is long gone.
Week 8 — Boardroom accountability shift
Cyber liability no longer stops at the CISO's desk. NIS2 puts it on the executive team personally — and most boards don't know what that means for their individual liability yet.
|
Free passwordless audit
When did you last review your actual identity entitlement state — not the policy, but the reality?
In a free 30-minute passwordless audit we'll review your current authentication stack, surface the three highest-probability identity drift scenarios in your environment, and show you what continuous risk integration looks like operationally.
No sales deck. No follow-up unless you ask.
|
Point-in-time assessments are better than nothing. Continuous identity monitoring is what makes the assessment findings defensible — because it means the controls you validated last quarter are still the controls operating today.
Mikael Rodin
Managing Director, Ciptor
P.S. If your last identity risk assessment was more than 90 days ago — book a free 30-minute audit. We'll tell you what's likely drifted since then and what to prioritise first.
New to the series? Start at ciptor.com/zero-assumptions/zero-assumptions-vol-1/