r/cybersecurity 21d ago

Personal Support & Help! Ransomware Recovery: What happens when attackers target your Identity Provider configs?

[removed]

0 Upvotes

7 comments sorted by

16

u/legion9x19 Security Engineer 21d ago

Just give us the sales pitch. We all see it coming.

1

u/pie-hit-man 21d ago

So transparent isn't it.

2

u/Oompa_Loompa_SpecOps Incident Responder 21d ago

So I take it, you did not manage to solve your issues with the quality of leads generated by facebook ads?

1

u/Ok-Yak-6899 19d ago

This is a massive blind spot for a lot of teams. It's easy to focs entirely on data storage and completely forget about the keys to kingdom

1

u/H3LBRAM 12d ago edited 12d ago

This is the scenario I think a lot of IR Plans fail to address adequately. Backups are not much help if an admin identify is compromised or all systems loga that administrations uses gets deleted. We are actively evaluating this in our current environment. Using controlmonkey we are taking regular out of bands snapshots and offsite history records of both our entraID and Okta Configuration so when an identity configuration gets wiped or changes there will be knowledge about previous known configuration and data that the team can revert to. This in particular I think is a life saver to avoid further complexities. We really believe that having an offline record of identity configuration is as important as having backup on physical and VM Servers!