Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Enterprise ServicesSecurity Leadership and ManagementLogical Security

Ensure service account security is top priority this holiday season

By Yaron Kassner
Holiday Lights

Image via Unsplash

December 22, 2023

Security teams have long been aware of the risks associated with service accounts and how they can constitute a major threat to businesses. Although businesses are aware of the risks associated with service accounts, protecting them from malicious actors has not been a priority until recently. As we know from years past, the holiday season is a popular time of year for threat actors to try new tricks to break into an organization’s network.

Now that service accounts have found their way into compliance and regulations conversations and cyber insurance policies, service account security has grabbed the immediate attention of business decision-makers. 

Service accounts are a unique type of dedicated non-human accounts that are created by IT admins to execute applications and run automated services, virtual machine instances, and other tasks within an organization’s network. It is common for service accounts to be assigned a high level of privilege similar to that of an administrator user. Service accounts are typically not required to have admin-level access and are given this overprivileged access merely to ensure that operations remain uninterrupted.

Breaches that utilize compromised service accounts continue to be the MO of most attackers because of the immense amount of access they give to things like customer and financial data, as well as critical business resources. 

In response to the evolving risks associated with service accounts, during the holiday and year-round, we’re seeing increased regulation and cyber insurance requirements relating to protecting service accounts. Rather than waiting until an organization is forced to secure its service accounts, business leaders need to be proactive and get ahead of rising threats. Here are the best practices for protecting service accounts amid today’s growing threat landscape:

  • Conduct regular audits to identify and inventory all service accounts within your network. This determines the purpose and usage of each service account and assesses the permissions and access rights associated with them. Regular audits of the inventory of service accounts will provide businesses with a complete picture of their service accounts and their activities, as well as allow them to identify accounts that are no longer being used. In fact, at Silverfort, we often see more service accounts in their network than our customers think they have, which creates serious security risks.
  • Get a baseline of normal activity, habits and usage to understand when there is abnormal activity worthy of a security flag. Take malicious or abnormal activity such as a service account that is designed to only run one automated task a day and then suddenly has over 100 access attempts over two days. This would be a red flag and call for further investigation. When activity is regularly monitored and the correct safeguards are in place, the environment’s hygiene is improved and attacks can be stopped.
  • Honor the principle of ‘least privilege’ to reduce access to sprawling service accounts. Recent data shows that access to privileged accounts increases security risks for organizations due to the potential impact of compromise and attackers gaining elevated access. Establish a process for regularly reviewing the requirements and permissions associated with service accounts to ensure they have only the necessary permissions and identify any potential security gaps or unauthorized access rights. As a result, identity and security teams will save themselves from playing catch-up later on and they will be ready to combat security issues when they arise.
  • Focus on monitoring and alerting of abnormal or malicious behavior. In order to ensure that the activities of service accounts are monitored and alerted in the event of suspicious activity, organizations should create and apply specific access policies for each service account. Identity protection solutions can help establish baseline behaviors for service accounts and identify deviations that may indicate a compromise. 

Compromised service accounts can be the key to opening the door into your network, which provides unprotected access from servers to servers and apps to apps, many of which were created and deployed decades ago in a network when the right security controls were not in place. By implementing a more proactive approach to service account security this holiday season and next year, businesses can fend off the risk of compromised service accounts that are being utilized by malicious actors in their ongoing cyberattacks. Don’t let sophisticated threat actors be a grinch in your season.

 

KEYWORDS: auditing data breach insurance risk management service

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Yaron headshot

Yaron Kassner is the Co-founder and CTO of Silverfort. Image courtesy of Kassner. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • online shopping

    Four steps to bolster e-commerce software security this holiday season

    See More
  • laptop on desk in front of notebook

    Protecting brands from cyber threats this holiday season

    See More
  • holiday

    A remote holiday season: Top tips to boost security as cyber hygiene diminishes

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing