Hidden Cyber Risks in Your IT Environment
Cyber threats continue to evolve, but many organisations already have tools available to strengthen their security posture. In this webinar, Martin and Steen share practical insights into how companies can uncover vulnerabilities, improve visibility and take simple steps that reduce cyber risk.
What you already have available
Many organisations already have access to tools that can improve visibility into cyber risks, but often only use a fraction of their capabilities. Martin and Steen explore how solutions such as Microsoft Defender can provide valuable insights into identities, devices and exposures, even with simple read access.
Practical ways to reduce risk
The session highlights concrete actions companies can take immediately. From identifying dormant accounts and MFA gaps to using free tools such as PingCastle, the discussion focuses on practical improvements that are easy to implement and can strengthen security significantly.
Why identity security matters
Identity remains one of the most targeted areas in cyber attacks. Through examples from ransomware incidents and modern privilege management approaches, the webinar explains how organisations can limit exposure, improve resilience and better protect critical systems against attackers.
Hidden Cyber Risks in Your IT Environment
Cyber threats continue to evolve, but many organisations already have tools available to strengthen their security posture. In this webinar, Martin and Steen share practical insights into how companies can uncover vulnerabilities, improve visibility and take simple steps that reduce cyber risk.
What you already have available
Many organisations already have access to tools that can improve visibility into cyber risks, but often only use a fraction of their capabilities. Martin and Steen explore how solutions such as Microsoft Defender can provide valuable insights into identities, devices and exposures, even with simple read access.
Practical ways to reduce risk
The session highlights concrete actions companies can take immediately. From identifying dormant accounts and MFA gaps to using free tools such as PingCastle, the discussion focuses on practical improvements that are easy to implement and can strengthen security significantly.
Why identity security matters
Identity remains one of the most targeted areas in cyber attacks. Through examples from ransomware incidents and modern privilege management approaches, the webinar explains how organisations can limit exposure, improve resilience and better protect critical systems against attackers.
View transcript
So, good morning and welcome to this Cyber Prevention Webinar. Today, we are going to walk through what some of the existing tools that most of the companies in Denmark at least and most of Scandinavia already have available to them. What is sometimes not available but free and can be taken advantage of as a tool that many people can use. So, we're trying to get a little bit behind what people could actually easily find out in their own environment. If they're working with IT security or if they are curious about IT security or if they're in a leadership position and would like to have some more insights on where some of their exposures could be. And I brought Steen here today. Because you work with this every day. So, it's me, Martin and Steen here in the studio. And some of you know us from previous sessions. And today, we decided to do a little bit more relaxed because I realized if I could only pick your brain, I think the audience would get a lot more information. Maybe. So, we're trying that this time. Let's see. And let's try to dive into it. Yeah. So, first, what are we going to get through? We actually have four small topics that we're going to cover in this half hour. And I think the important part is it's going to be a little bit about Defender. Yeah. It's going to be a bit about what Defender can give you of insights already. So, we're going to try to keep it simple. And one of the big things for me was actually to realize how much can be done just with a read access. So, you don't need to be an administrator that sits and works in Defender every day. You can essentially just ask for a read access. Yes. If you should be looking at some of these things. Yeah. And then we're going to talk a bit about your favorite tool, I think it is, Pincastle. Yes. Yeah. And for many people, that's a new tool. So, we're going to dive a bit into that as well. Yeah. And then we're going to have one ransomware case. I mean, what's a webinar without ransomware case? So, that's important. Sure. And then lastly, we're actually going to talk a little bit deeper on the technical side of identity access management with the PIMPAM that a lot of companies are talking about. Have been for many years. Yeah. But I feel it's blooming again. Yes. I felt like five years ago, everybody talked about it. Then it was a bit quiet and now everybody's talking about it again. Yes. So, yeah. Let's get into it. If we start out with Defender. It gets a little bit technical here in what we're showing the audience. There are some observations. We're trying to show them what Defender looks like. Can you maybe start by just giving people one second fly over what is Defender? And if you're not used to working in it, what kind of access do you need? Yeah. And what can you see in there in very general terms? Yeah. Yeah. So, by the core foundation of what Defender is, it's different features within the Microsoft platform that gives you telemetry. It gives you a modernized EDR tool. And correlating all that telemetry from different devices, Martin, you can get recommendations, you can get KPI scores in certain angles around your security posture. Okay. So, that would be something around security of your devices, security of your identities, software as a platform service and such as. Yeah. So, also, if you buy like software that you have from third parties, it's located in your platform. Yes. If you're running servers or virtual machines, these kind of things. Yeah. Yeah. And what about access? So, if you're not a IT technician, but for example, let's say you are the CFO of a mid-sized company or maybe you're a compliance manager or something like that. Yeah. And you think it should be part of your job to at least know what things look like. Yeah. So, you don't want to like jack around on there, but you want to know. So, can you do something? Yeah. So, on the Defender platform, if you get just a security reader access. Okay. So, security reader is like you can get all the telemetry by default, but you're not allowed to manage or change anything settings wise. So, you don't by mistake screw up the whole thing? No, no, no. You don't. So, you got only read access, but then you can see all the KPI scores. You can get all the recommendations based on all the telemetry that is deployed out there in your environment. And actually, I think quite interesting. I'm not that deep technically myself and I'm often sitting with clients. It could be, for example, the CFO we mentioned before. Yeah. And they'd be like for a lot of people, they think IT is still something where you're sitting in a dust prompt and you have to write everything into a prompt. And actually, this is a super user-friendly interface. So, if you are a CFO or if you are a compliance manager or by some means think it's in your job to actually know some of these KPIs, ask your IT department for a security reader access. And once you get in there, it's very intuitive. A lot of like scores that you can see immediately very readily available. Yeah, but you also see like you see the telemetry over time. Yeah. Which means that you can see like are your KPIs going up or is it going down? Yeah. Also based on like are you, when you are making changes in environment, does it have a benefit on your security posture? That will be shown in the KPIs but also shows like are you in control? Yeah. So, if your KPI scores keep dropping or rising, well, that kind of means that you might not be so much in control. Yeah. So, it lacks maybe maturity. So, once in a while, the administrators go in and fix something. But then they lack maturity. So, it will drop again. Exactly. Okay. So, easy to get access. Get yourself a security reader. You can see most of these scores. Yeah. You won't mess anything up. So, that's not dangerous for anyone. And actually, I spoke to a person not too long ago who also have access. And I realized that it matters a lot what licenses you have. So, that may be one thing to mention that if you have a, for example, a business license, a normal business license without the security suite, then you will see very high scores even though you might not actually have that good a security posture. Exactly. What it means that, yeah. So, the larger the license. So, let's say you have a business license, E3 or E5 as the bigger one. And now, we are talking about E7 license. Yeah. It opens up for more features. It opens up for more visibility. Yeah. In regards to recommendation. Which means that, of course, if you have one of the more cheaper license as the business license, of course, the amount of visibility will be limited. Which means that your score will also look really, really good. But it might not show the entire attack surface on a given device. So, if you get in there and you have a score of say 70%. Yeah. And you're thinking that's great. Yeah. It could be because you have a small license. Yeah. And if you jacked it up to a bigger license, you might actually have a score of 60 or 50 or even lower. Exactly. So, that's important to be aware of. But anyways, let's jump a little bit into it before it gets too boring here. So, essentially, if I gave you five minutes in the Defender. Yeah. I just logged in. It's the first time you're in the platform. It's a mid-sized company. What's the first thing you'd do? I would look at my dormant accounts. When I say dormant accounts, so these are accounts that are not been active for let's say three to six months. Making sure that those are either removed or disabled. So, we know that attackers are targeted identities. So, that would be. And I think the easiest things would be to target the ones that are dormant. Which means that they are there. They are active in the environment. Or sorry, they're not active in the environment, but they're still enabled. Which means that for them to be targeted and maybe not being that much visible in regards to if they're being attacked. Those are the ones that are at least for target. Okay. So, five minutes, you just go in and look at that. And that means anybody out there could actually go and open their Defender right now with a reader access. Yes. Try to find their way around and find out about dormant accounts. Yes. Dormant accounts. Yes. That's a good one. In the slide when you made it, you also mentioned gaps in the MFA. Yeah. And you mentioned it on admin accounts. Now, I'm a little bit surprised to see that. Because I thought that MFA was just rolled out everywhere. And when we speak to our clients and companies around Europe, they would always say, Oh, we have MFA on everything. Yeah. So, what do you mean here? So, what I mean is that I think it's a little bit different between if you're talking about on-premise environments, so like the old school of dealing with identities, or the more modernized version when you're talking about Intro ID. So, with Intro ID, you already have MFA as a built-in solution where you can easily adopt into it. Where if we're talking about the old school of on-premise environments, those are not features that are part of the Microsoft portfolio. So, you have to go out and purchase third-party solution, which we rarely see being done. And when we see it, it often only enforces MFA on if you are, let's say, RDPing into a server. While if I do other types of log on, those are not being enforced. So, it kind of opens or shows a gap. Yeah. So, when we talk to clients and they say, Oh, don't worry, we have MFA on everything. That's often not actually the full picture. No. It's not the full picture. And it's also, even though it's deployed, it doesn't cover all the way of how you can authenticate to a device. Because I have heard over the past couple of years, some companies who like relaxed a little bit on general security. Because they said after MFA, we kind of just use that as our main security. But it's maybe a place to be a little bit aware. Yeah. So, let's jump a little bit into something else here. So, in the Defender platform, you like to talk about something called MDI. Yes. Maybe before we confuse everyone out there with the details of what's on this slide, give us a two-second fly-in on MDI. Yeah. So, Microsoft Defender for Identity. So, a feature part of the identity portfolio, which lies within the Defender suite as general. And these are small sensors you will deploy in your environment. So, that would be on your domain controls. It would be on your certificate authority environments. ADFS servers, intra-ID sync servers and such as. And they will give you all sorts of telemetry around identities. Mm-hm. And they will map out user behaviors. Which means that a given user will act in certain ways over time. If they suddenly shift to doing a more offensive approach in the environment. Yeah. That would immediately flag an alert. And how will like the untrained non-technical user who just got their security reader. Yeah. How will they see this? So, what is it they would notice in the platform when they get in? So, they would notice that when you log into the KPI scores. Yeah. You will see some visibility around your identity score. Okay. So, that will show that, okay, well, these accounts are dormant. These service accounts are not being used anymore. These are Kerberosable as it's called. These are administrative accounts that are also dormant. So, this is some of the visibility that it will show. Okay. And you mentioned up here specifically on slide something you call pass the hash. Yeah. As an attack type. Now, it gets extreme technically. I think for a lot of the listeners and viewers today, they don't know what you're talking about. So, give us a fly in on what does that mean and why should they be particularly worried about this particular? Yeah. So, when I authenticate to a device or log into a device, I get what is called a Kerberos ticket. Yeah. So, this is my ticket of showing who I am and what permissions I have. And then I can take that ticket and I can show it to other devices saying, well, I'm allowed to access these resources on this device. Yeah. So, that's essentially how the infrastructure works. Exactly. That's how it works, right? Yeah. So, if I an attacker, let's say, steal your Kerberos ticket, I can take your ticket. I can take it onto another device. That is what is called pass the hash. So, I take the ticket somewhere else and then I abuse it. Yeah. To gain whatever permissions you have. Yeah. So, if people log into their platform and they use their security reader and they see a risk of this thing called pass the hash. Yes. That means that they have not protected themselves against an attack that is similar to this, which is a very common type of attack. That's very, very common. Yeah. And you will see that immediately be flagged in the defender portal as an alert. What is called pass the hash. And then they will show you, well, this type of account or this account has used this ticket that was used on this device over here has suddenly used it over here. Yeah. So, it becomes very visible. Okay. So, that's a good thing to look for. Yeah. So, then it says here MDI detects things within minutes. Can you please explain what does that mean? What is it that the MDI is actually doing here? So, this comes back to when I said user behavior analytics. So, when you act in a certain way and suddenly, well, that shifted. So, your tickets will have been used over here and suddenly, well, someone took your tickets and used it over here. So, this is how it often will show. Okay. But that also means that the moment a user does something odd. Yeah. That is considered potentially harmful. Yeah. Then it will actually flag in the defender for identity. It will flag in immediately. Yeah. But I think it's also maybe important to mention here that you can deploy the sensors. But if you deploy them just by default settings, it will only show you X amount of visibility. You still need to tune it. You still need to tweak it a little bit. And this is where we often see some of the gaps. Okay. But the reason we get into this in this particular topic is also that this is something that's included in the defender solution for most companies. And it's quite an important way of keeping track of what the users are doing. Including if a user, for example, in a phishing attack or in other means have been compromised. Yeah. Then this is where the behavior will be flagged. Yeah. And also where you can put in automation to essentially prevent some of these things. Yeah. So you can go in and say, well, if your account is deemed by Microsoft to be compromised. And I think the likelihood they say is around 99.7%. Yeah. So they're very sure that you're very compromised. They're very sure. And I would see it's always been a true positive once I've seen it. Then it will immediately go in and they would either disable your account automatically or make sure that you are blocked from accessing devices in that environment. Yeah. So that means what we mean when we talk about this, especially for the non-technical people who are with us today, it means that you can go in with your reader. You can understand what is happening in your Microsoft Defender for Identity scores, which is one of the areas you can see in the Defender platform. And in there, you'll also be able to kind of ask some of the administrators or if you are an administrator, you can go in and tune this and make sure that, for example, it automatically blocks. If it is 99.something percent sure that one of the users have been compromised. Yeah. You sure can. And again, I mean, this is just very simple things that is totally available in most companies platforms. It's relatively easy to tweak, at least it's doable. Yeah. And it has a super big effect because it is the users that the attack surface. Sure it is. Also, if you are a mid-sized company and you maybe not have purchased in to a security provider that is looking into your security environment. So that would be a SOC solution, for instance. So if you don't have that deployed, I would say like at the bare, bare minimum would make sure that you do have that action optimization in place. Yeah. For your Defender, which means that once the attack happens overnight and everybody's like sleeping good at home. Yeah. Well, then at least there is something that can kick in and protect you for certain parts of the attack. Yeah. Because the hackers might not sleep at the same time as your users. They often don't. They tend to like Friday afternoons. They tend to. I'm going to try to catch you a little bit off guard here. Yeah. If you are the CFO we spoke about before or the compliance manager or somebody who's not used to working in Defender, can you see somewhere in the platform if this is not enabled or if these automations are not? So can you just in a simple way say, I'm first time in the platform. I know that you might not remember all the ways around. But I think I do. In hard terms, how do I know if things could need a little more care? Yeah. There is a dashboard or platform for identities around Defender for Identity on its own. It will show you where the gaps are. So it will show you if a sensor is not deployed where it's supposed to be. Okay. It will also show you if certain audit settings which are needed for getting all the right telemetry, if those are not enabled. It will also show you if the Defender sensor is unhealthy. Yeah. If it's not being updated and such as. Okay. Well, that will be shown as an alert in there. And it's quite easy to go in and make sure that you are having these settings and features in place. And the sensor is overall healthy. Okay. And let's remember again that we're talking about people here who might be asking for reader access. Yeah. And that also means you can click around. Yeah. But you can still see this. So don't worry about making issues. Yeah. You will not cause any issues. You will not cause any issues. You can click around and look for these things. Yeah. And ask people to give you some like there will always be an administrator in your IT department. You can ask them to give you some more insights if you're in doubt. Or you can ask them to see if they could fix some of these things. Yeah. If it turns out that they've been too busy with other things to maybe focus on this. Which is what we see. We see quite often that these sensors are being deployed by default. And then we can see that the audit settings are not enabled as they should. We see that there is a tendency to at least that sensors only deployed on domain controllers. Yeah. But then they're left out on for instance certificate authority environments which are now highly targeted. Yeah. Also which means that then well then you get not get all the telemetry which are needed. Yeah. And then you have certain let's say blind spots in your coverage. Okay. That's good. I think that will teach our listeners today quite a lot of new things they can do. And this is tool that are already available. So the two topics we've talked about now is the general defender. And then we talk about this MDI which is part of the defender suite. So here's a lot that companies can do. Readily available there are reader accesses just to recap what we got through so far. Yeah. Then if we dive into the next slide then we're talking a little bit about something here where we talk about identity access management. And this is particularly for the on-prem environment. And the reason we mentioned this I guess is because a lot of companies they like to say are weak onto the cloud. Obviously in most cases so let's say 95% of the cases in Europe they still have an on-prem environment. Yes. And that means if you are an attacker you're likely going to go for the on-prem environment because it's too annoying for an attacker to fool around in the cloud environment. If there is an on-prem environment that is usually less hardened. Yeah. So Pincastle it says here it's free. Yeah. And Active Directory here we call it AD. Yeah. Active Directory is everywhere I mean 95% of the companies or maybe even more. Yeah. Still have an Active Directory. Tell us about this Pincastle free thing. What does it mean? What is Pincastle? Yeah. So Pincastle is a free tool which you can download and then you can run it up against your what is basically called Identity Store. Identity Store is most often an Active Directory. I think it's maybe more a little bit important to mention here that from the on-premise environment. So Active Directory by default a regular user non-privileged can read in 99% of all objects and accesses in an Active Directory. This is not the case when we talk about cloud environments. This is something else. So when we know that I as a low level user can run a free tool against my own Identity Store Active Directory then I can also get the full technical visibility. Yeah. How does my security posture actually look like on what is Attackers Target the most which are the Identity Store. And maybe I can just add one comment here because this is something I experienced quite a lot. I sit with somebody let's say it's a CFO again or it could be a Compliance Manager or someone else. And they say to me that they have no clue how things are looking in their IT in terms of securities. And we talk about the on-prem which is the older part of their IT environment. I'm not recommending that people out behind the screens now download Pink Castle by themselves and just go ahead and run this. They could. Yeah. But it's probably a good idea to ask the IT department first. But I have been sitting in cases where for example a CFO don't feel they get proper insights from the IT department when they ask for information. They get like blurry like descriptions of how the situation is and where we've essentially just downloaded Pink Castle together with a CFO and together run it. Yeah. And try to understand what it is and then have a conversation with the IT department. It's not best practice but it's doable. No, no. But you get an honest discussion. When I say honest you get more data driven because normally you as a CFO for instance as you mentioned Martin you can go and ask in the IT department well how does my security posture look like in my Active Directory. Yeah. Most often they will say it looks really really good. Yeah. Which is might be true. Let's hope. But I think it's more important that you get like a technical deep dive in all the coverage in all the angles of that IH3 and Pink Castle can give you that. Yeah. And I think I mean again the middle way could also be to know that the tool exists. Yeah. Write to your IT head of IT and say I insist I want to see this tool. Yes. I want to see the report. Yeah. It's a very simple report lot of colors. Yeah. So if the IT department pulls the report for you. Yeah. Then at least they can send it to you and you'll have something to have a discussion. Yes. Okay. Then let's talk about we have mentioned some things here on the slide. And one of the things you mentioned and I hear you talk about that a lot is something called stale accounts or stale objects. Tell us a little bit about that because that's one of your. Yeah. So this would be basically a little bit the same as dormant account. I think I'll dive in a little bit because I've already mentioned dormant account. Yeah. Previously when we talked to Fender for Identity. So let's talk about maybe service accounts. So we see often that service account are being configured with password never expires. Organizations is a little bit in doubt if these accounts are still being used or not. So they just resides there, are enabled and might have not been active for. I've seen the accounts 20 years old never been used. Yeah. But they are configured in a way that they are easy to abuse. Maybe I can just add in here that a service account for those who doesn't know it is an account that doesn't necessarily have a human connected to it. Exactly. So it's an account that does something behind the scenes. So it has a similar setup as a user in your company. It just is without a user. So it's like a little robot account. I can just say that it runs a service. It runs some kind of service. Yeah, exactly. So those are the one I would look at. Yeah. Because we do know that they are highly targeted. If password never expires, it most likely that password was set a long time ago when the password policy was, let's say, less complex, which means that it's easily to abuse. Yeah. Okay. Then you have something here you call ACL misconfigurations. Yeah. What does that mean? It sounds boring. Yes. Access control list misconfiguration. So we often see that in a given Active Directory, we see that people are going on maternity leave. They are going on holiday and vacation and such as. Yes. And then you would say that, well, that user has some extra delegated permissions so they can maybe reset the password on some of their colleagues. Well, that person now goes on maternity leave. Well, I'll just give the same permission that she has. Give it to him over here. Yeah. And then say, well, we'll remove it once you're back from maternity leave. Yeah. But we also see that that never happens. Yeah. So they forget to do that. They forget to do that. And then you end up having like a regular user account which suddenly becomes somewhat privileged. Okay. At least to a level where it becomes like a target for a more lateral move attacks. Yeah. And that essentially means if a hacker comes in, let's take the phishing attack from before. Turns out somehow the MFA is not fully effective. Or maybe they managed to get around the MFA. And now they can actually scan the AD. Yeah. I mean the attacker will scan the Active Directory. And they will also identify these things. Just like if you ran a pincast, they will run similar tooling or do it manually. And then they will realize that this person has very high privileges. This service account has not changed password for 20 years or 10 years or whatever. Yeah. This one has a weak password. This one has this and so on. So essentially they can sit and plan their attack. Yeah. And that's what they can do with tools like this and what you should do before them so to speak. 100% correct. Yeah. 100%. And then if I ask you the tough question here. I've seen in many situations with you and a client where the IT department said we are up to here in work. We will not get these things done. And that's why things are looking the way they are because we have too many things going on. And then we often tell them, well, okay, fair enough. But before Friday, please fix these one, two things. Because there's no reason they look like this and they are so quick to fix. Yeah. What are those things? Take accounts that are considered privileged. And if they have not logged in or authenticated within the last couple of months, make sure those are disabled. Privileged accounts that haven't logged in for a couple of months, disabled. Yes. Okay. Easily done. It's done within, let's say, 30 minutes at a maximum. Okay. So that's one. Do you have another one that you want to say like any of the things on the screen here that you said? We can go through to the Kerberosable accounts. So again, service accounts, same approach, highly targeted accounts, maybe a little bit like overseen because they don't look like an admin account. Yeah. Again, if they haven't logged on for a couple of months, disabled. Okay. So that's a good little hint. Yeah. Easy to do. So again, here we're just trying to make sure there's no excuse for doing things that are like super quick, super easy to do, and has a reasonably big impact. It doesn't give you full security at all. It's just a good step on the road. But low hanging fruits, quick win. Yeah. All right. Let's try to jump to the next one we see here. This is a ransomware case. Here we are in the manufacturing industry. And I think there is some interesting path here in terms of like a very, very short timeline. And I think the reason we brought this case in is because we see it more and more that the timelines of the attacks are getting shorter. Yes. Do you want to walk us through a little bit like what is the takeaway from a case like this? Yeah. So the takeaway is that we see an account being compromised and that it can happen in certain ways. It can be through VPN. It can be phishing mails and such as, right? So we see a regular user being compromised. Yeah. Then the attacker has a foothold in the environment. And then they start doing what we call reconnaissance. So reconnaissance is like looking for your next target. For example, using Pincastle. That could be using Pincastle or the free tools. It can be within PowerShell and such. Yeah. And then they start querying in the environment because as I said before, regular user has the permissions. Yeah. To go out and say, well, how does the permissions and how can I query in this environment to find like the next target for me to do what we call a lateral movement. So they would be using something more around LDAP queries. So LDAP queries would be the type of technical queries you would use against your Active Directory to see or find those ACLs. Find those accounts that are not being used but are still privileged. Yeah. We see SMB protocols being used. So SMB protocol is a protocol you use for data transfer. We see that being used because either you want to do data infiltration, so data leakage. Or you want to like sniff around and say, well, some of these accounts are the credentials actually written down in a technical document somewhere in the environment. Yeah. So we often see that administrators maybe have a little bit difficulty remembering all the logins they have. So they put them around in some kind of document or in technical documentation. Or scripts even, right? Yeah. We also see that hard coded credentials in a script. The attacker will go out and query. That takes maybe a couple of hours depending on the size and the amount of data that is available. Yeah. And then often they find a target and maybe a couple of targets that would go for. Those are either credentials they have seen or is visible or accounts that are maybe dormant but privileged. Yeah. And then they start the attack and often within the next couple of hours an account has been compromised. And then from moving from there to a sensitive device that would be a backup server. It could be a domain controller somewhere else. When now they have the permission to actually gain a larger foothold and even take control of the entire environment. We only have three minutes left here and we have one more slide we wanted to go through. But at least I wanted you, you put in a snip here from Pink Castle. Yeah. That's a link back to the previous slide. Yeah. There's one thing here that you mentioned is super important and that you can find in a Pink Castle. Yeah. What was it that happened in this case? Yeah. So in this case it's like the administrative account or at least have the permissions to be administrator. But are not being used but are still being enabled. And that's what we see in the picture here. Exactly. We blurred the rest so that's the line that you see there. Yeah. Let's try to just focus at the end here a little bit on PIMPAM. What does it mean and why is it we see organizations moving in this direction? Yeah. So we see it because the old schooler way was that an administrative account always had it like the highest permission. So they would for instance for an on-premise environment there would be domain admin permanent all the time. Now we see and those are the type of accounts that are being targeted. Well if you can take those permission away and only give them once it's needed. Well then your administrative account actually just looks like a regular account. So I think taking that would take like a large attack angle or vector vector away from the environment. Yeah. And we see this a lot of companies asking for this and moving in this direction. Going away from constant privileges over to these like just in time. Yes. Exactly. On the slide we're mentioning that this will take away maybe a 60 to 70% reduction in previous account exposure. Yeah. But that sounds very little. I mean what about the last 30%? Yeah. So I would say the numbers are actually should be higher. Okay. Maybe around 90 to 95%. Okay. So there's only going to be like a break glass account left and then that one maybe a group managed service account that actually has the permission to map other human accounts in there. And those are the two that should only be there. Is Pimpam. I often hear about it in larger companies. Yeah. Larger enterprises. Is it also something for mid and small size companies? Are there solutions out there? Because I also remember back we spoke about different solutions and they were often very expensive. Yeah. But they're not that expensive anymore. Okay. And it's also for small and mid size companies. So this is also a way of kind of avoiding to have to deal with all the legacy. Yeah. I mean I'm not saying you shouldn't but the fact is that many companies never get around to fix everything. Yeah. So sometimes putting a bit of extra security around the privileges can be a way of at least temporarily or maybe long term fix things and make it better. Yeah. Make it more difficult for the attacker. Sure, Cain. Okay. So thanks everyone for listening in. Thanks. That was the topics of today and thanks for sharing your knowledge, Cain. Of course. Yeah. Anytime. Thanks for chipping in. Thank you.