The Threat Model, Stated Honestly
What privileged access management defends against, what it does not, and why the insider framing is both overstated and damaging.
Analysis
Programmes are frequently justified against a threat they do not address and undersold against the one they do.
What it defends against well
Credential compromise. An attacker who obtains a privileged credential finds it rotated, scoped, or valid only during an active grant. This is the primary case and the strongest argument.
Lateral movement and escalation. Tiering and credential hygiene close the paths that escalation relies on.
Shared credential exposure. A leaver, a contractor, a password in a document โ all addressed by vaulting and rotation.
Absence of attribution, which is a genuine gap that individual accounts and brokering close.
Undetected administrative change, which recording and alerting address after the fact.
What it does not defend against
A compromised administrator workstation. Actions taken through a legitimate session are recorded as legitimate. This is the largest remaining gap in most deployments.
An administrator acting within their granted rights. Someone authorised to do a thing who does it maliciously is not prevented by any of this.
Supply chain compromise of the broker or agent itself.
Physical and console access, unless separately controlled.
Anything on systems not onboarded, which is why the residual-risk list matters.
Application-level privilege in business systems, which infrastructure-focused programmes routinely omit.
The insider framing
Programmes are frequently sold on preventing malicious insiders. It is worth being accurate about this.
Credential compromise is overwhelmingly the more common case. Most privileged access incidents involve an external actor using legitimate credentials, not a dishonest employee.
The insider framing damages the deployment. Administrators who believe they are the threat model cooperate less, and their cooperation is what determines whether the path is enforced or bypassed.
Recording does deter, and deterrence is a legitimate benefit. It is a secondary one, and stating it as primary is both inaccurate and counterproductive.
Say the accurate thing: the threat is that someone else obtains your credentials, and these controls limit what that is worth.
The residual risk
Worth writing down, because a programme that claims to have eliminated privileged access risk will be found out.
Systems that cannot be onboarded, with compensating controls.
Standing rights that cannot be removed, with reasons.
The workstation gap, unless dedicated devices are deployed.
The broker itself as a concentration of risk.
Application-level administration outside the programme's scope.
Review this list annually and report it alongside the coverage figures. It is what makes the coverage figures believable.
What to say to an executive
Before: any of forty people could obtain full control at any time, using credentials that had not changed in years, leaving no record of what they did, and we could not have rotated them quickly.
After: eight people can obtain it, on request, for a limited period, with a record, and we have rotated the entire tier zero population in a timed drill.
That is a defensible claim and it does not require asserting that a breach was prevented.
The workstation gap, stated
The largest remaining exposure in most mature deployments, and it deserves naming rather than omitting.
A compromised administrator endpoint defeats brokering, recording and just-in-time simultaneously, because the actions are performed through a legitimate session.
Multi-factor authentication does not help once the session exists.
The mitigations are dedicated devices, session brokering so credentials never reach the endpoint, and endpoint detection.
None is complete.
Say so in the residual-risk list, because a programme claiming to have addressed privileged access risk while leaving this open will be found out at the worst moment.
What an incident would look like anyway
A useful exercise for calibrating what the programme actually buys.
Assume an administrator's workstation is compromised tomorrow.
Trace what the attacker can reach, given your current controls.
Which credentials are available to them, and for how long.
What would be recorded, and would anyone see it.
How long to detect, and how long to rotate everything exposed.
Do this before and after each phase. The change in the answers is the programme's value, stated in terms an executive understands and without claiming any breach was prevented.
Also in this section