01
1. Strengthen authentication
Prefer phishing-resistant methods where available.
- Phishing-resistant MFA for sensitive and administrative accounts
- Reduce push-fatigue exposure and weak fallbacks
- Protect enrolment and recovery processes
02
2. Limit compromise impact
An account should not hold more privilege than required.
- Least privilege and regular permission review
- Separate privileged administrative roles
- Fast offboarding and account lifecycle controls
03
3. Add visibility
Strong login without detection still leaves blind spots.
- Logging of material identity events
- Alerts for risky changes and privileged activity
- Incident procedure for a compromised account