Hackers don’t break in, they login: Why Identity Security Requires Your Attention
Dhivya Balasubramanian (Cybersecurity IAM Manager · Southwest Airlines)
SAINTCON 2025 · Day 3 · Main Track 1
Overview
In this compelling SAINTCON presentation, Dhivya Balasubramanian, Cybersecurity IAM Manager at Southwest Airlines, dissects the critical, yet often underestimated, domain of identity security. Her talk, aptly titled "Hackers don’t break in, they login," underscores a fundamental truth in modern cybersecurity: the vast majority of breaches exploit compromised credentials rather than sophisticated zero-day vulnerabilities. Balasubramanian passionately argues that while organizations invest heavily in perimeter defenses and advanced security tooling, the foundational elements of identity and access management (IAM) are frequently neglected, leaving the digital "front door" wide open.

Key moments
- 0:00 Speaker introduction and talk agenda
- 3:50 Verizon DBIR: Stolen credentials as top attack vector
- 4:48 Defining the goal of Identity and Access Management (IAM)
- 5:15 Introduction to the four main pillars of IAM
- 5:40 Pillar 1: Directory Services and its evolution
- 6:30 Pillar 2: Identity Governance and Administration (IGA)
- 7:20 Pillar 3: Access Management for runtime enforcement
- 8:00 Pillar 4: Privileged Access Management (PAM) explained
Hackers don’t break in, they login: Why Identity Security Requires Your Attention
Speakers: Dhivya Balasubramanian, Cybersecurity IAM Manager, Southwest Airlines
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=yxy3qSLH9so
Overview
In this compelling SAINTCON presentation, Dhivya Balasubramanian, Cybersecurity IAM Manager at Southwest Airlines, dissects the critical, yet often underestimated, domain of identity security. Her talk, aptly titled "Hackers don’t break in, they login," underscores a fundamental truth in modern cybersecurity: the vast majority of breaches exploit compromised credentials rather than sophisticated zero-day vulnerabilities. Balasubramanian passionately argues that while organizations invest heavily in perimeter defenses and advanced security tooling, the foundational elements of identity and access management (IAM) are frequently neglected, leaving the digital "front door" wide open.
Balasubramanian's presentation serves as a vital wake-up call for security professionals, business leaders, and even individuals, emphasizing that robust identity security is not merely a technical checkbox but a strategic imperative. She meticulously traces the evolution of IAM's four core pillars—Directory Services, Identity Governance and Administration (IGA), Access Management, and Privileged Access Management (PAM)—demonstrating how each has adapted to an increasingly complex threat landscape. Through historical context, real-world breach analyses, and forward-looking insights, the talk illuminates why identity security is the "quiet hero" of cybersecurity, deserving far more attention and investment than it currently receives.
This article provides a comprehensive exploration of Balasubramanian's key arguments, technical deep dives, and practical recommendations. It aims to distill the essence of her message: that by understanding and diligently implementing strong identity security practices, organizations can significantly reduce their attack surface and protect against the most common and damaging cyber threats. The insights shared are particularly valuable for those looking to deepen their understanding of IAM, embark on a career in identity security, or seeking actionable strategies for securing small and medium businesses.
Background
▶ Watch: Speaker introduction and talk agenda (0:00)
The premise of Dhivya Balasubramanian's talk is rooted in a stark reality confirmed by industry reports: attackers overwhelmingly prefer to log in rather than break in. This fundamental truth is powerfully illustrated by data from the Verizon Data Breach Investigations Report (DBIR), an annual analysis of security incidents and breaches. Balasubramanian highlights that while a superficial glance at the report might show "privilege misuse" at a seemingly low 6%, a deeper dive reveals the pervasive role of compromised identities across almost all attack categories.
Specifically, the 2024 DBIR data, gathered between November 2023 and October 2024 from 139 countries and analyzing 22,000 security incidents (12,000 confirmed breaches), reveals alarming statistics:
- System intrusion: 20% of attacks attributed to stolen credentials.
- Social engineering: 40% of attacks attributed to suspicious logins, often stemming from compromised credentials.
- Basic web app attacks: A staggering 88% attributed to stolen credentials used at scale.
These figures underscore that stolen credentials remain one of the most common initial attack vectors year after year. Balasubramanian emphasizes the sheer scale of this problem, noting that in 2024 alone, approximately 2.8 billion passwords (hashed or otherwise) were available for sale or free on the dark web. This availability renders even the most sophisticated and expensive security infrastructure ineffective if the basic "keys" to the kingdom are easily obtained. As she eloquently puts it, "We can build the tallest walls by the most expensive security gear. But if our credentials are being handed out like free samples at Costco, then none of that matters." In such scenarios, attackers don't need advanced AI or zero-day exploits; they merely require patience and a keyboard to exploit fundamental security hygiene failures.
This context sets the stage for defining the overarching goal of Identity and Access Management (IAM): to "ensure that the right individuals have the right access to the right resources at the right time for the right reasons." Balasubramanian then introduces the four main pillars of IAM from a market perspective, around which products are built: Directory Services, Identity Governance and Administration (IGA), Access Management, and Privileged Access Management (PAM). She clarifies that this differs from the more technical angle of authentication, authorization, administration, and audit, but both frameworks aim to achieve the same security outcomes.
Key Findings
▶ Watch: Defining the goal of Identity and Access Management (IAM) (4:48)
Dhivya Balasubramanian's talk delivers several key findings that collectively underscore the critical importance and evolving nature of identity security:
- Stolen Credentials as the Primary Attack Vector: The most significant finding, directly supported by Verizon DBIR data, is that compromised credentials are the overwhelming initial access vector for cyberattacks. This reality dictates that any robust cybersecurity strategy must prioritize strong identity protection over solely relying on perimeter defenses.
- The Foundational Nature of IAM: Despite its often-overlooked status, IAM is the bedrock of organizational security. Balasubramanian positions IAM as the "gym membership of cyber"—something almost everyone has, but few use effectively. Its proper implementation prevents the "free samples at Costco" scenario where credentials negate other security investments.
- Evolution of IAM Pillars: Each of the four IAM pillars has undergone significant transformation, driven by technological advancements and evolving threat landscapes. From simple local password files to decentralized identities (Directory Services), from manual access control to AI-driven insights and agentic AI governance (IGA), from basic passwords to passkeys and continuous verification (Access Management), and from sticky notes to zero standing privileges (ZSP) (PAM), the field is constantly innovating to meet new challenges.
- Real-World Consequences of IAM Failures: The Twitter 2020 hack and the Colonial Pipeline 2021 attack serve as stark reminders that even basic IAM lapses—like susceptibility to phishing, inadequate privileged access controls, or failure to deactivate ghost accounts—can lead to severe financial, reputational, and even national security implications. These incidents highlight that "basics" are anything but trivial.
- The Future is Passwordless and Continuous: The talk emphasizes the shift towards passkeys as a phishing-resistant, passwordless, and effortless authentication method. Furthermore, the concept of continuous verification, embodied by Identity Threat Detection and Response (ITDR), is presented as the future of access management, moving beyond one-time login checks to ongoing assessment of user behavior.
- Strategic Investment in Identity Security: Balasubramanian advocates for smart, risk-based investments in cybersecurity, specifically IAM, rather than succumbing to fear of missing out (FOMO) on the latest tools. For small and medium businesses (SMBs), this means prioritizing inventory, MFA, privileged account management, regular access reviews, and user awareness.
- The "Why" in Learning and Application: Beyond technical proficiency, Balasubramanian stresses the importance of understanding the intent and rationale behind security concepts. Encouraging learners to ask "why" (like a 5-year-old) fosters deeper comprehension and enables more effective problem-solving and strategic implementation.
Technical Deep Dive
▶ Watch: Pillar 1: Directory Services and its evolution (5:40)
Balasubramanian’s technical deep dive into the four pillars of IAM provides a historical perspective on their evolution, highlighting key milestones and future directions.
Directory Services
Directory Services began as simple user data stores, evolving to centralize and manage identities.
- 1960s: Systems maintained local copies of usernames and passwords.
- 1980s: NIS Yellow Pages introduced centralization, moving to a client-server model for sensitive information. This quickly proved unscalable.
- 1990s: Novell Directory Services (NDS), later eDirectory, emerged as the first enterprise-level directory, supporting centralized management and hierarchical user/group relationships. The Lightweight Directory Access Protocol (LDAP) was introduced as a standard for accessing these directories.
- 2000s: Microsoft's Active Directory consolidated identity, authentication, and authorization into a single platform, becoming dominant in enterprise environments.
- 2010s: The rise of cloud computing led to hybrid directories, spanning on-premises and cloud environments.
- 2020s and Future: The perspective is shifting towards decentralized identities, where individuals own and control their data, sharing specific information as needed, akin to a "digital passport." This concept challenges traditional organizational data ownership.
Identity Governance and Administration (IGA)
IGA focuses on managing the lifecycle of identities and their access rights, driven by compliance and risk mitigation.
- Pre-2000s: Centralized directories emerged, but organizations often lacked visibility into "who had what access, and who gave them what access." Accounts and access often persisted long after employees left.
- Post-Enron (2001): The Sarbanes-Oxley (SOX) Act, specifically Section 404, mandated that organizations understand and control access to financial data. This indirectly gave birth to modern IGA, emphasizing access certification reviews, audit reporting, and provisioning/deprovisioning.
- 2010s: With cloud adoption, Gartner formally coined the term IGA, and IGA products became mainstream, handling provisioning, deprovisioning, and syncing across diverse on-prem, cloud, and SaaS systems.
- 2020s: The advent of AI brought AI-driven insights for continuous posture management and better handling of non-human identities (service accounts, RPA bots).
- Future: IGA is evolving to predict access needs, auto-provisioning access based on AI, and crucially, addressing governance for agentic AIs. This involves determining "who to arrest" if an AI agent misbehaves, raising profound questions about accountability and control.
Access Management
Access Management is the runtime enforcement of how identities access resources, encompassing authentication and authorization.
- 1960s: The first computer passwords appeared at MIT for time-sharing machines. This era also saw the first instances of credential theft as students dumped password files to impersonate users for more compute time.
- 1980s: As systems proliferated, Kerberos (from MIT's Project Athena) emerged as a trust delegation model, enabling single sign-on (SSO) within an organization's network.
- 1990s: The inadequacy of single passwords led to the introduction of two-factor authentication (2FA). RSA released SecureID, one of the first hardware tokens for time-based one-time passwords (TOTP).
- 2000s: Organizational expansion beyond internal networks necessitated federation protocols. SAML (Security Assertion Markup Language) allowed organizations to trust each other's authentication without users needing separate accounts in every system, extending the SSO concept. OAuth followed, specifically designed for application-to-application (app-to-app) secure data exchange, without user identity information. Mobile apps and SMS-based OTPs also became prevalent, driving wider MFA adoption due to exploding password breaches.
- 2010s: OpenID Connect (OIDC) was born by adding an identity layer on top of OAuth, making it suitable for user authentication in addition to app authorization. Biometric authentication became common with smartphones. Adaptive MFA gained traction, using context and risk factors (e.g., impossible travel) to dynamically challenge users with additional authentication factors.
- 2020s: The persistent weakness of passwords, even with MFA, led to passkeys. These eliminate passwords by using cryptographic keys stored on devices and authenticated with biometrics, offering superior phishing resistance, passwordless, and effortless access.
- Future: The focus is shifting from one-time login checks to continuous verification. Identity Threat Detection and Response (ITDR) is gaining mainstream adoption, acting as the identity equivalent of Endpoint Detection and Response (EDR), constantly evaluating user identity and access post-login. Quantum-resistant MFA is also an emerging area.
Privileged Access Management (PAM)
PAM focuses on securing and monitoring highly sensitive accounts, often called "the pilots in the cockpit."
- Pre-2000s: Incredibly, sticky notes were sometimes considered a "secure" way to transfer admin passwords.
- 2000s: Realizing the insecurity, organizations moved to password vaulting, where privileged credentials were stored securely and "checked out" by users. This was soon augmented by session monitoring to observe user activity post-checkout.
- 2010s: The concept of just-in-time (JIT) privilege elevation emerged, where admin access is granted only when needed and for a limited duration, eliminating "standing guard mode" access. Cloud environments introduced ephemeral accounts, dynamically created and vanishing after use. The Snowden incident (2013) highlighted the risk of privileged user misuse, leading to privileged user behavior analytics (PUBA) for continuous monitoring and anomaly detection. API-driven secrets management also became important for applications to securely retrieve credentials.
- 2020s: The Zero Trust philosophy profoundly impacted PAM, leading to Zero Standing Privileges (ZSP). This means no static credentials are stored anywhere; admin privileges are dynamically created on the fly and used only when absolutely necessary.
- Future: PAM is converging with IGA and Access Management into a more unified, autonomous identity fabric, streamlining privileged access governance and enforcement.
Demo / Proof of Concept
▶ Watch: Pillar 2: Identity Governance and Administration (IGA) (6:30)
While Dhivya Balasubramanian's talk did not feature a live technical demonstration or a coded proof of concept, she effectively used two high-profile, real-world cyberattacks as "wake-up calls" to illustrate the devastating consequences of neglecting fundamental identity security principles. These incidents served as powerful, real-life case studies of what happens "if we really do not take care of the basics."
The Twitter Hack (2020)
Scenario: In July 2020, Twitter (now X) experienced a significant security incident where high-profile accounts, including those of Elon Musk, Barack Obama, and Bill Gates, were hijacked to promote a Bitcoin scam. The scam encouraged users to send Bitcoin with the promise of receiving double the amount in return.
Attack Vector: The attackers, a group of teenagers, used social engineering. They posed as IT support, troubleshooting a VPN issue, and called several Twitter employees. They tricked these employees into entering their usernames and passwords into a fake phishing portal. Crucially, when the real Twitter site prompted for Multi-Factor Authentication (MFA), some employees also entered their MFA codes into the fake portal, allowing the attackers to bypass MFA.
Impact: With compromised credentials and MFA codes, the attackers gained access to Twitter's internal admin tools, which provided "god mode" access. From there, they could reset passwords, change account details, and take over approximately 130 high-profile accounts. While the immediate financial gain from the Bitcoin scam was around $110,000, the long-term impact was a severe breach of trust in a major social media platform, demonstrating how easily such a platform could be manipulated for diplomatic incidents or market manipulation by a more dangerous adversary.
Lessons Learned:
- Phishing Resistance: Employees must be rigorously trained to recognize and resist social engineering and phishing attempts. Elon Musk is not asking for your Bitcoin.
- Defense in Depth: Even MFA can be phishable if not properly implemented or combined with other layers of security.
- Privileged Access Management (PAM): The incident highlighted the critical need for stricter controls over privileged accounts and internal admin tools. Had PAM been more robust, the attackers would not have gained such extensive "god mode" access.
The Colonial Pipeline Attack (2021)
Scenario: In May 2021, the Colonial Pipeline, a major fuel pipeline system in the southeastern United States, was forced to shut down its operations due to a ransomware attack. This led to widespread fuel shortages, panic buying, and a declared state of emergency.
Attack Vector: The root cause was a single, highly vulnerable VPN account. An ex-employee's VPN account had not been fully deactivated, indicating a failure in Identity Governance and Administration (IGA) processes. To make matters worse, the password for this VPN account had been reused from a completely different breach and was available on the dark web. The attackers, the DarkSide ransomware group, obtained this reused password, used it to access the VPN, and then deployed ransomware on Colonial Pipeline's IT systems.
Impact: Colonial Pipeline proactively shut down its Operational Technology (OT) systems (the pipelines themselves) to prevent the ransomware from spreading from IT to OT. This resulted in the shutdown of 5,500 miles of pipeline, affecting over 10,000 gas stations and causing significant economic disruption. The company eventually paid a $4.4 million ransom in Bitcoin to regain access and restore operations, incurring millions more in recovery costs.
Lessons Learned:
- Ghost Accounts: Organizations must implement rigorous lifecycle management (a core IGA function) to ensure that accounts of departed employees are promptly and completely deprovisioned. "If Bob leaves, Bob's accounts leave with him."
- Multi-Factor Authentication (MFA): The attack could have been prevented had MFA been enforced on the VPN account. Even a basic MFA implementation would have significantly raised the bar for the attackers.
- Password Hygiene: The incident underscores the danger of password reuse, even for "complex" passwords. Unique, strong passwords and, ideally, passkeys are essential.
These two examples powerfully demonstrate that foundational identity security is not a theoretical concept but a practical necessity with profound real-world implications, serving as a compelling "proof of concept" for the talk's central thesis.
Defensive Implications
▶ Watch: Pillar 4: Privileged Access Management (PAM) explained (8:00)
Balasubramanian's presentation offers a clear roadmap for organizations to bolster their defensive posture against identity-based attacks. The implications span technical implementations, policy, and organizational culture.
- Prioritize Foundational IAM: The most critical implication is to stop treating IAM as an afterthought. Organizations must recognize that strong identity security is the first line of defense, often more impactful than expensive perimeter solutions. This means allocating appropriate budget, resources, and strategic focus to all four pillars: Directory Services, IGA, Access Management, and PAM.
- Enforce Multi-Factor Authentication (MFA) Universally: MFA should be mandated for all critical systems, especially those protecting "crown jewels" and privileged accounts. For SMBs, even basic MFA is a significant improvement. Organizations should also explore adaptive MFA, which uses contextual factors (e.g., location, device, time of day) to dynamically challenge users, enhancing security without unduly burdening legitimate users.
- Implement Robust Identity Governance and Administration (IGA):
- Lifecycle Management: Establish and enforce strict processes for provisioning, modifying, and deprovisioning user accounts. "Ghost accounts" for ex-employees are a critical vulnerability and must be eliminated promptly.
- Access Reviews/Certifications: Conduct regular, at least quarterly, reviews of who has access to what, particularly for sensitive resources. This ensures that access rights remain appropriate and are revoked when no longer needed.
- Inventory Management: Maintain a comprehensive inventory of all applications, databases, and SaaS systems, along with who has access to them. This is foundational for effective governance.
- Strengthen Privileged Access Management (PAM):
- Eliminate Shared Admin Accounts: Strive to remove shared administrative credentials. If unavoidable, vault them securely and enforce MFA for checkout.
- Just-in-Time (JIT) Privileges: Implement solutions that grant privileged access only when needed, for the duration required, and revoke it automatically afterward.
- Zero Standing Privileges (ZSP): Move towards a model where no static, standing privileged credentials exist. Privileges should be dynamically created on demand.
- Session Monitoring and Analytics: Continuously monitor privileged user sessions and employ privileged user behavior analytics (PUBA) to detect anomalous activities that might indicate misuse or compromise.
- Adopt Passwordless Authentication (Passkeys): Encourage and implement passkeys wherever technically feasible. Their cryptographic nature makes them highly resistant to phishing and credential theft, offering a superior alternative to traditional passwords. For systems still requiring passwords, enforce strong password policies, prevent reuse, and consider password managers.
- Embrace Continuous Verification with ITDR: Shift from a perimeter-centric security model to one of continuous verification. Identity Threat Detection and Response (ITDR) solutions offer real-time monitoring of identity-related events and behaviors after login, allowing for rapid detection and response to compromised accounts or insider threats.
- Invest in Security Awareness Training: Regular, engaging, and relevant security awareness training is crucial. Employees must understand the risks of phishing, social engineering, and poor password hygiene. Training should emphasize the "why" behind security policies and the potential impact of individual actions on the organization.
- Strategic, Risk-Based Security Investments: Avoid "FOMO" (Fear Of Missing Out) when acquiring security tools. Investments should be driven by a clear understanding of business risk and directly address identified vulnerabilities, rather than simply acquiring the latest technology. For SMBs, this means starting with basics like MFA and inventory before scaling to enterprise-grade solutions.
- Prepare for Agentic AI Governance: For organizations exploring or deploying agentic AI, proactively consider the governance implications. Establish frameworks to monitor, control, and hold accountable AI agents to prevent unintended actions or misuse, akin to human access governance.
By meticulously addressing these defensive implications, organizations can move beyond simply reacting to breaches and instead build a proactive, resilient security posture centered on the most critical asset: identity.
Key Takeaways
- Stolen credentials are the leading cause of breaches: Data consistently shows that attackers primarily log in using compromised credentials rather than exploiting complex vulnerabilities, making identity security paramount.
- IAM is the foundational "quiet hero" of cybersecurity: Despite often being overlooked, robust Directory Services, IGA, Access Management, and PAM are essential for protecting organizational assets and preventing costly breaches.
- Continuous verification and passwordless are the future: The evolution towards passkeys and Identity Threat Detection and Response (ITDR) signifies a shift from one-time login checks to ongoing, phishing-resistant, and adaptive identity assurance.
- Basic IAM failures have severe real-world consequences: High-profile incidents like the Twitter hack and Colonial Pipeline attack demonstrate that neglecting fundamental practices like MFA, ghost account deactivation, and privileged access controls can lead to significant financial, operational, and reputational damage.
- Strategic, risk-based investment is crucial: Organizations, especially SMBs, should prioritize IAM investments based on actual business risk rather than succumbing to the allure of every new security tool.
- Understanding "why" enhances learning and effectiveness: Deeply comprehending the intent and rationale behind security concepts, rather than just memorizing facts, empowers professionals to implement and adapt solutions more effectively.
About the Speaker(s)
Dhivya Balasubramanian is a dedicated cybersecurity leader currently serving as the Cybersecurity IAM Manager at Southwest Airlines. Her professional expertise lies specifically in Identity and Access Management (IAM), a field she approaches with a profound personal passion. Beyond her corporate role, Dhivya is a self-described mom with a diverse array of interests, including a love for food and handicrafts, which she balances with her commitment to cybersecurity.
Balasubramanian emphasizes that her presentation at SAINTCON is driven by her personal dedication to advancing identity security and does not represent the views or practices of her workplace. She champions the idea that everyone possesses a "superpower" and encourages individuals to identify and leverage their unique strengths, whether it's an aptitude for automation (like her own "laziness"), strong soft skills, or a talent for questioning the status quo. Her own career trajectory, starting as a project manager in cybersecurity, then moving to product owner, and eventually into leadership, exemplifies her belief that diverse backgrounds can thrive in the cybersecurity domain, especially with a solid grasp of foundational concepts.