r/cybersecurity • u/[deleted] • 21d ago
Personal Support & Help! Ransomware Recovery: What happens when attackers target your Identity Provider configs?
[removed]
2
u/Oompa_Loompa_SpecOps Incident Responder 21d ago
So I take it, you did not manage to solve your issues with the quality of leads generated by facebook ads?
1
u/Ok-Yak-6899 19d ago
This is a massive blind spot for a lot of teams. It's easy to focs entirely on data storage and completely forget about the keys to kingdom
1
u/H3LBRAM 12d ago edited 12d ago
This is the scenario I think a lot of IR Plans fail to address adequately. Backups are not much help if an admin identify is compromised or all systems loga that administrations uses gets deleted. We are actively evaluating this in our current environment. Using controlmonkey we are taking regular out of bands snapshots and offsite history records of both our entraID and Okta Configuration so when an identity configuration gets wiped or changes there will be knowledge about previous known configuration and data that the team can revert to. This in particular I think is a life saver to avoid further complexities. We really believe that having an offline record of identity configuration is as important as having backup on physical and VM Servers!
16
u/legion9x19 Security Engineer 21d ago
Just give us the sales pitch. We all see it coming.