Technical Assurance & Offensive Security

Identity, Access & Zero Trust Review

Most breaches are an identity problem wearing a technical costume.

The situation

Identity is the control plane, and in most organisations it is the least governed one: standing privilege, orphaned accounts, service accounts nobody owns, MFA with exploitable fallback paths and joiner-mover-leaver processes that only work on paper.

We review the identity estate end to end and design a realistic path toward zero trust — one that acknowledges legacy systems rather than pretending they can be replaced.

What the client receives

Schedule of deliverables

  1. 01Identity estate and privilege model assessment
  2. 02MFA and SSO coverage analysis including bypass and fallback paths
  3. 03Privileged access management design
  4. 04Joiner-mover-leaver process and access recertification design
  5. 05Zero trust architecture roadmap proportionate to the estate
  6. 06Entra ID / Okta / directory hardening review

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • NIST SP 800-207
  • ISO/IEC 27001 A.5.15–A.5.18
  • NIS2 Art. 21(2)(i) / (j)

Discuss this engagement

Tell us about your directory, privilege model and access review practice and we will set out the scope, the method and the reporting format.

Contact us