Webinars

The Hidden Layer of Cyber Risk: Compromised Credentials Inside Your Environment

Compromised credentials remain one of the most reliable ways into an enterprise, and no amount of MFA or identity governance has made them go away. Attackers don’t need to break in anymore — they just log in. 

That’s the focus of this on-demand webinar from the IT GRC Forum. Silverfort’s Chief Identity Security Advisor, Rob Ainscough, joins a panel of identity security experts — Deron Segel (SpecOps Software), Dirk Schrader (Netwrix), and Alejandro Leal (KuppingerCole) — moderated by Colin Whitaker, to unpack why credential-based attacks keep working and what actually stops them. 

Rob’s core argument: authentication was never built to carry the weight we’ve put on it. Every identity, human or non-human, is a risk, because frontier AI can now chain small, overlooked identity weaknesses — what Rob calls “identity debt” — into a full domain compromise in hours. Traditional IGA and PAM tools are too narrow or too slow, working at “admin time” instead of runtime. The fix isn’t a better password policy; it’s machine-speed, runtime controls that stop one compromised account from cascading into a systemic breach. 

Key topics covered: 

  • Why “hackers don’t break in, they log in” is still true eight years later, and why frontier AI is about to make it worse 
  • Rob’s concept of “identity debt”: the accumulated, unaddressed identity weaknesses that AI can now chain together at machine speed 
  • How Silverfort’s red-team work with Project Glasswing clocked an AI-driven attack path from standard user to production domain admin in under two hours, entirely through compromised credentials 
  • Why traditional PAM and IGA fall short — too narrow in scope (tier-zero, compliance-focused) or acting at admin time instead of runtime 
  • The case for runtime, inline identity protection: controlling risk as it happens instead of reviewing it after the fact 
  • Why non-human identities (service accounts, tokens, AI agents) are the models’ preferred target, and why they can’t be left out of the conversation 
  • Rob’s rule of thumb: identity security isn’t about your best control, it’s about your worst one — “the floor, not the ceiling” of your environment’s integrity 
  • The new baseline Rob argues every organization should adopt: no account, human or non-human, should authenticate on username and password alone without an additional guardrail 
  • Using AI defensively — feeding real-time signals like tickets, incidents, and organizational context into autonomous policy decisions to match attacker speed 

This session is built for security and identity leaders who are tired of passing compliance audits while still wondering if a stolen credential is quietly moving through their network right now. Watch the full conversation on demand to hear Rob Ainscough and the panel break down what it actually takes to stop credential-based attacks once the perimeter is gone. 

Watch on-demand