Authorised and unchecked: Credentialed access is banking's real cyber risk
Fri, 28th Aug 2026 (Today)
Cybersecurity has long been built around a simple idea: keep attackers out. But that model is breaking down. Perimeter defences still matter, yet they rely on an assumption that no longer holds - that attackers won't get in. In reality, they likely already have.
Access is now routinely established through legitimate credentials. Once inside, the perimeter is irrelevant, as employees – and now hackers – are free to roam. In many banks, that's where visibility drops off and control weakens. In highly interconnected environments, a single credential can open paths across entire systems,
This is not theoretical, but is already playing out around the world. The Singapore government last year disclosed that the cyber espionage group UNC3886 targeted critical infrastructure, operating with legitimate tools and credentials to persist undetected. In the U.S., North Korean operatives generated hundreds of millions of dollars by working inside companies under false identities. Iranian actors have deployed destructive malware through stolen administrator credentials.
These attacks succeed not by breaking in, but by blending in.
Authorised access is being weaponised
At the recent RSA Conference, Capital One's Chief Technology Risk Officer Andy Ozment warned that North Korean operatives are securing remote roles in financial institutions using stolen identities. They pass background checks, receive corporate devices, and operate as trusted insiders from day one.
Others take a more direct route - phishing administrator credentials, logging into systems like Microsoft Intune, and executing large-scale disruption with legitimate access.
The pattern we are seeing emerge is attackers being authorised, credentialed, and moving freely. This is what makes credentialed access so dangerous. It removes friction. Sensitive systems can be reached faster, lateral movement is easier, and traditional controls, designed to detect intrusion, often fail. Attackers no longer need to evade defences, but operate within them.
Banking's Structural Blind Spot
Insider risk is not new, but it is evolving. The Ponemon Institute's 2026 Cost of Insider Risks report highlights cases of bank employees using legitimate access to support criminal activity, from data exfiltration to financial fraud.
The flaw is structural. Banks have invested heavily in defending the perimeter of their networks, but far less in controlling what happens after access is granted. Identity is still treated as a proxy for trust, when in practice it is only a starting point for risk.
This extends beyond technology into governance. Hiring, onboarding, and access provisioning often sit outside core security controls. Yet these processes determine who enters the environment, and under what level of access.
Fraud systems, meanwhile, are designed to detect transactional anomalies, not a well-behaved insider moving laterally with legitimate credentials. That gap is now being actively exploited.
Containment Is the New Control Plane
Regulators are already shifting expectations. The Monetary Authority of Singapore's Technology Risk Management framework emphasises least-privilege access, continuous monitoring, and resilience under attack as baseline requirements.
Those controls are essential, but they do not address a fundamental reality: valid access does not equal trusted behaviour. Once an attacker obtains authorised access, whether through stolen credentials, compromised accounts, or insider abuse, traditional security measures often provide little resistance to lateral movement.
This is why containment has become a foundational element of cyber resilience. The question is no longer whether a threat actor can gain access, but whether they can move beyond it.
Meeting these expectations requires more than incremental controls. Microsegmentation
By enforcing granular, identity-aware access between workloads, systems, and users, it defines what "normal" connectivity looks like and prevents anything outside it. This changes the security model from detection to containment. Even if an attacker gains valid access, their ability to move laterally is restricted by design. The blast radius is minimised. Critical systems remain isolated. Operations continue
Three questions banks CISOs must answer
The critical question banks need to ask themselves is no longer how to stop attackers getting in, but what happens when they are already inside.
If a credentialed user began moving laterally across your environment right now:
- How far could they go?
- How quickly would you detect it?
- What would actually stop them?
Increasingly, regulators, boards, and customers expect clear answers. In an era where attackers increasingly operate with legitimate access, resilience is defined not by preventing every breach, but by limiting its impact. Containment is no longer optional. It is the control that defines modern resilience. Microsegmentation