Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Enterprise ServicesSecurity Leadership and ManagementLogical Security

Ensure service account security is top priority this holiday season

By Yaron Kassner
Holiday Lights

Image via Unsplash

December 22, 2023

Security teams have long been aware of the risks associated with service accounts and how they can constitute a major threat to businesses. Although businesses are aware of the risks associated with service accounts, protecting them from malicious actors has not been a priority until recently. As we know from years past, the holiday season is a popular time of year for threat actors to try new tricks to break into an organization’s network.

Now that service accounts have found their way into compliance and regulations conversations and cyber insurance policies, service account security has grabbed the immediate attention of business decision-makers. 

Service accounts are a unique type of dedicated non-human accounts that are created by IT admins to execute applications and run automated services, virtual machine instances, and other tasks within an organization’s network. It is common for service accounts to be assigned a high level of privilege similar to that of an administrator user. Service accounts are typically not required to have admin-level access and are given this overprivileged access merely to ensure that operations remain uninterrupted.

Breaches that utilize compromised service accounts continue to be the MO of most attackers because of the immense amount of access they give to things like customer and financial data, as well as critical business resources. 

In response to the evolving risks associated with service accounts, during the holiday and year-round, we’re seeing increased regulation and cyber insurance requirements relating to protecting service accounts. Rather than waiting until an organization is forced to secure its service accounts, business leaders need to be proactive and get ahead of rising threats. Here are the best practices for protecting service accounts amid today’s growing threat landscape:

  • Conduct regular audits to identify and inventory all service accounts within your network. This determines the purpose and usage of each service account and assesses the permissions and access rights associated with them. Regular audits of the inventory of service accounts will provide businesses with a complete picture of their service accounts and their activities, as well as allow them to identify accounts that are no longer being used. In fact, at Silverfort, we often see more service accounts in their network than our customers think they have, which creates serious security risks.
  • Get a baseline of normal activity, habits and usage to understand when there is abnormal activity worthy of a security flag. Take malicious or abnormal activity such as a service account that is designed to only run one automated task a day and then suddenly has over 100 access attempts over two days. This would be a red flag and call for further investigation. When activity is regularly monitored and the correct safeguards are in place, the environment’s hygiene is improved and attacks can be stopped.
  • Honor the principle of ‘least privilege’ to reduce access to sprawling service accounts. Recent data shows that access to privileged accounts increases security risks for organizations due to the potential impact of compromise and attackers gaining elevated access. Establish a process for regularly reviewing the requirements and permissions associated with service accounts to ensure they have only the necessary permissions and identify any potential security gaps or unauthorized access rights. As a result, identity and security teams will save themselves from playing catch-up later on and they will be ready to combat security issues when they arise.
  • Focus on monitoring and alerting of abnormal or malicious behavior. In order to ensure that the activities of service accounts are monitored and alerted in the event of suspicious activity, organizations should create and apply specific access policies for each service account. Identity protection solutions can help establish baseline behaviors for service accounts and identify deviations that may indicate a compromise. 

Compromised service accounts can be the key to opening the door into your network, which provides unprotected access from servers to servers and apps to apps, many of which were created and deployed decades ago in a network when the right security controls were not in place. By implementing a more proactive approach to service account security this holiday season and next year, businesses can fend off the risk of compromised service accounts that are being utilized by malicious actors in their ongoing cyberattacks. Don’t let sophisticated threat actors be a grinch in your season.

 

KEYWORDS: auditing data breach insurance risk management service

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Yaron headshot

Yaron Kassner is the Co-founder and CTO of Silverfort. Image courtesy of Kassner. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • delivery

    Top physical security threats affecting e-commerce this holiday season

    See More
  • online shopping

    Four steps to bolster e-commerce software security this holiday season

    See More
  • laptop on desk in front of notebook

    Protecting brands from cyber threats this holiday season

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing