This website uses cookies

Read our Privacy policy and Terms of use for more information.

It’s no surprise to anyone that AI is making it easier and faster to attack organizations. That means that doing “basic” security well has never been more important.

The first time organizations got caught not doing the basics well was when ransomware hit the scene. If you were not enforcing strong passwords and MFA and your internal network was swiss cheese, you got caught, and it hurt, badly.

The next big shift is thanks to AI.

Threat actors are empowered more than ever to attack faster and against more targets, at the same time. This is made evident when we hear of attacks like this.

But “do the basics” is frustrating advice when you’re the person responsible for actually doing them.

So let’s make it useful.

We can think about doing the basics in the context of coverage, verification, and upkeep.

Does the control cover the systems that matter?

Can you prove it works?

Will you notice when something changes?

Here’s what it may look like in practice:

  • Least privilege: Check tier-0 resources, like Domain Controllers or the Domain Admins group, to ensure there’s no unnecessary or dangerous permissions. If any are found, determine why, then remove/restrict what you can. Then document the rest and monitor for future changes.

  • Credential management: Look for exposed passwords on file shares, document management systems, wikis, ticketing systems, SharePoint, etc. For those found, identify the owner and educate them on the risks. Then purge/restrict access. Potentially rotate credentials if risk of compromise was present.

  • Attack surface reduction: Disable legacy SMBv1/NTLMv1 protocols in the domain. Then setup additional monitoring to catch when those protocols resurface. Monitoring should catch both attempted legacy usage and settings being re-enabled.

AI can help an attacker move faster, but it doesn’t make a recently changed password valid or a removed permission usable.

That’s why this hardening work matters.

You’re reducing the opportunities an attacker can take advantage of, and how much depends on your team reacting in time.

Making your environment harder to attack makes it harder for both humans and AI.

Do the work. Stop attacks. Sleep well at night.

All the best
Spencer

PS - If you’re curious if your defenses would hold up against a real attacker, that’s literally my day job. I’ve performed 1,000s of hours of internal pentesting and I’d love to help you strengthen your Active Directory environment. If you’d like to see if your organization is a fit for how we do internal pentest, book a 30-min call here.