Skip to content
Lorendix

Cybersecurity · Identity and privileged access

Access granted deliberately and removed automatically

Lifecycle automation, phishing-resistant authentication, entitlements derived from real usage, and privileged access that is brokered and recorded rather than permanently held. Identity and privileged access management, engineered rather than administered.

Where this starts

Credentials remain the most reliable way in

Stolen and misused credentials are involved in a large share of breaches every year, and the reason is structural rather than technical. Access is granted quickly because somebody is blocked, removed slowly because nobody is blocked, and reviewed annually by managers approving lists they cannot interpret. The result is an estate where accumulated permission is far larger than anyone intends and nobody can see the shape of it.

What we usually find

  • Leavers retaining access to applications that sit outside the main directory
  • Contractors and service accounts with no owner and no expiry date
  • Access reviews approved wholesale because the entitlement names are unreadable
  • Administrators holding standing privilege because elevation is inconvenient
  • Shared break-glass credentials in a password manager, never rotated after use
  • Machine identities and API keys outnumbering people, and managed by nobody

Our position

Permission granted for one urgent afternoon is usually still there three years later. Access needs an expiry date more than it needs an approval.

What the work covers

People, privilege and machines

Identity programmes go wrong when they cover employees thoroughly and ignore the two populations carrying more risk: administrators and machines.

  1. Lifecycle automation

    Joiner, mover and leaver driven from the human resources system through automated provisioning, so access follows the role and a departure removes it the same day rather than at the next review cycle.

  2. Authentication

    Single sign-on across the estate, including the applications bought outside procurement, with phishing-resistant factors such as passkeys and hardware keys for administrators, and conditional access driven by device posture and risk.

  3. Entitlements and least privilege

    Roles derived from what people actually use rather than from what they once asked for, separation of duties enforced where it genuinely matters, and certification that presents a manager with a decision they can reasonably make.

  4. Privileged access

    Credentials vaulted and brokered, elevation granted just in time and expiring on its own, session recording for the systems that warrant it, and break-glass that is monitored and rotated after every use.

  5. Machine and workload identity

    Service accounts with owners, short-lived credentials in place of static keys, workload identity federation between cloud and pipeline, and certificate lifecycles automated so an expiry is never again an outage.

  6. Directory consolidation

    Reducing the number of places identity is held. Every additional directory is another place a leaver survives and another set of reviews that nobody completes properly.

A practitioner at work

How it stays fixed

Access that expires on its own

The single most effective change in most estates is not a new tool. It is making grants temporary by default, so the system tends towards less access rather than more.

  1. Joiner

    Provisioning driven from the source of truth, so a starter has the right access on their first morning without anyone raising a ticket.

  2. Mover

    A role change revokes the previous entitlements rather than adding to them. This single behaviour is where most accumulated permission comes from.

  3. Leaver

    Same-day revocation across federated applications, with an evidenced trail the auditor can read without an interview.

  4. Elevation

    Privilege requested, approved and granted for a bounded window, then removed automatically. No standing administrator, including ours.

  5. Review

    Certification campaigns generated with usage data attached, so a manager can see what an entitlement has actually been used for before approving it again.

What you are left holding

  • Provisioning and deprovisioning driven from your source of truth
  • Phishing-resistant authentication for administrators, enforced rather than encouraged
  • Just in time elevation, with standing privilege removed
  • An owned inventory of service accounts and machine credentials
  • Access reviews that produce decisions rather than approvals

One question to begin with

If somebody left on Friday, which systems would still let them in on Monday? We usually start by answering that properly.