<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Baptiste Cianchi, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/baptiste-cianchi/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/author/baptiste-cianchi/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 31 Mar 2026 08:59:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Baptiste Cianchi, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/author/baptiste-cianchi/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Overview of Active Directory security tools – version 2026 </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/#respond</comments>
		
		<dc:creator><![CDATA[Baptiste Cianchi]]></dc:creator>
		<pubDate>Tue, 31 Mar 2026 08:59:36 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Active directory]]></category>
		<category><![CDATA[AD Backup & Recovery]]></category>
		<category><![CDATA[AD Discovery]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[Vulnerability Discovery]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29578</guid>

					<description><![CDATA[<p>  In 2026, Active Directory remains at the heart of the now hybrid identity infrastructure of most large companies and is still widely used as an on-premises identity provider, even when organisations migrate to the cloud.  Wavestone incident response teams note that 38% of attacks begin with...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/">Overview of Active Directory security tools – version 2026 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">In 2026, Active Directory remains at the heart of the now hybrid identity infrastructure</span></b><span data-contrast="auto"> of most large companies and is still widely used as an on-premises identity provider, even when organisations migrate to the cloud.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Wavestone incident response teams note that</span><b><span data-contrast="auto"> 38% of attacks begin with identity compromise </span></b><span data-contrast="auto">(vs. 20% in 2024).</span><b><span data-contrast="auto"> </span></b><span data-contrast="auto">More broadly,</span><b><span data-contrast="auto"> attackers frequently exploit on-premises identities to move laterally into cloud environments </span></b><span data-contrast="auto">(Microsoft Digital Defence Report 2025 [1]).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In a context where the </span><b><span data-contrast="auto">hybridisation of identities increases an already vast attack surface</span></b><span data-contrast="auto">, companies must be able to understand the challenges and equip themselves effectively.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Through this </span><b><span data-contrast="auto">new 2026 overview of Active Directory security tools</span></b><span data-contrast="auto">, we offer you:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol style="text-align: justify;">
<li><b><span data-contrast="auto">An updated map of Active Directory security tools</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">An overview of major market trends</span></b><span data-contrast="auto"> (consolidation, transition to platforms, cloud hybridisation)</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Feedback on operational implementation challenges</span></b><span data-contrast="auto"> and key success factors</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><span data-contrast="none">An overview of AD 2026 security tools, which has been further enhanced </span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">By analysing the market, we have identified four main use cases for these tools:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol style="text-align: justify;">
<li><b><span data-contrast="auto">Analysis and audit</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Hardening and maintaining security </span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Detection</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Response and reconstruction</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">A listing of publishers and tools offering features that meet one or more of these four use cases was conducted. It was designed to be as comprehensive as possible, including tools from the best-known and most widely used players on the market as well as those from lesser-known players, proprietary tools and open-source tools, tools with a wide range of features and tools offering a more limited set of features. All relevant tools were thus included in a list, with various information for each one (reputation, description of the tool and use cases covered, hosting, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The following overview selected a number of publishers from this list, for the functional coverage they offer and their large use within organisations.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The Microsoft Entra ID logo is added to tools that offer the possibility of integrating it into their operations in addition to on-premises AD coverage. This is a strong trend in the market.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p> </p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-29566" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1.png" alt="" width="1582" height="890" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1.png 1582w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-768x432.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-1536x864.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/Image2-1-800x450.png 800w" sizes="(max-width: 1582px) 100vw, 1582px" /></span></p>
<h2> </h2>
<h2 style="text-align: justify;"><span data-contrast="none">1. A dynamic market undergoing consolidation</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">The Active Directory market has undergone several changes since 2022, with different major transactions. The </span><b><span data-contrast="auto">aim is most often for publishers to complement their offering </span></b><span data-contrast="auto">or to cover a new need for Active Directory security.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Among other things, we can note :</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Acquisition of PingCastle by Netwrix [2] :</strong><span data-contrast="auto"><strong> </strong>PingCastle, renowned for its expertise in AD security auditing, strengthens Netwrix&#8217;s offering. This acquisition enables Netwrix to expand its portfolio with a lightweight, quick-to-deploy tool that is popular with technical teams, while reaffirming its commitment to providing a unified platform covering the entire AD security lifecycle.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Acquisition of Attivo by SentinelOne [3] :</strong><span data-contrast="auto"> Attivo, a specialist in identity security and lateral movement detection, strengthens SentinelOne&#8217;s offering by integrating advanced AD protection capabilities into a unified platform combining EDR, XDR and identity security.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Acquisition of BrainWave by Radiant Logic [4] :</strong><span data-contrast="auto"> Radiant Logic strengthens identity and governance analysis capabilities. By combining BrainWave&#8217;s detailed rights mapping with Radiant Logic&#8217;s identity federation, the offering becomes more comprehensive in addressing AD challenges.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><strong>Integration of Stealthbits by Netwrix [5] :</strong><span data-contrast="auto"><strong> </strong>By merging with Stealthbits, Netwrix has integrated historical Active Directory auditing and detection components (StealthAUDIT, StealthDEFEND, etc.), strengthening its offering in the protection of identities and sensitive data and moving towards a unified platform focused on AD security.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">2. From specific tools to centralised platforms</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In 2022, our overview of Active Directory security tools mentioned </span><i><span data-contrast="auto">“specialised tools, each addressing part of the equation.” </span></i><span data-contrast="auto">[6]. In 2026, we are seeing the emergence of </span><b><span data-contrast="auto">centralised platforms</span></b><span data-contrast="auto"> capable of covering several needs around Active Directory and, often, Entra ID. This dynamic is </span><b><span data-contrast="auto">primarily driven by publishers</span></b><span data-contrast="auto"> seeking to broaden their value proposition and differentiate themselves with comprehensive platforms rather than specialised tools offering specific features.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">Some publishers build their platforms through successive acquisitions</span></b><span data-contrast="auto">, such as Netwrix (AD auditing, data protection, vulnerability discovery, PingCastle, etc.) or SentinelOne (EDR/XDR enhanced by Attivo on identity), while </span><b><span data-contrast="auto">others are gradually enhancing their existing offerings </span></b><span data-contrast="auto">to provide modular suites, whether they are administration/monitoring tools such as ManageEngine ADAudit Plus or Quest Change Auditor, which add AD auditing, hardening and detection components across the entire Active Directory ecosystem.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">The promises made by publishers are clear:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Centralisation of data</span></b><span data-contrast="auto"> (accounts, groups, rights, security events)</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
<li><b><span data-contrast="auto">Unified view of attack paths</span></b><span data-contrast="auto"> between AD and Entra ID</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
<li><b><span data-contrast="auto">Simplified management</span></b><span data-contrast="auto"> for security, infrastructure and IAM teams via consolidated consoles and dashboards</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
</ul>
<p style="text-align: justify;"><b><span data-contrast="auto">From the customer&#8217;s point of view, the benefits are obvious, but the reality may be more nuanced:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:533,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<ul>
<li><span data-contrast="auto">Consolidation can reduce the number of tools and simplify integrations, but </span><b><span data-contrast="auto">it does not eliminate the need for AD expertise or specialised tools </span></b><span data-contrast="auto">(e.g. for post-incident reconstruction).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
<li><span data-contrast="auto">Environments often remain </span><b><span data-contrast="auto">multi-vendor</span></b><span data-contrast="auto">, with a mix of global platforms (XDR, CNAPP, Identity Security) and targeted AD tools, particularly in large groups or organisations that are already heavily equipped.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1253,&quot;469777462&quot;:[720,1253,3684,6300],&quot;469777927&quot;:[0,0,0,0],&quot;469777928&quot;:[0,8,1,1]}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">In this context, the challenge is not simply to “choose a platform”, but rather to </span><b><span data-contrast="auto">put together a coherent whole</span></b><span data-contrast="auto">, ensuring that:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:708,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<ul>
<li><span data-contrast="auto">The AD/Entra ID scope is well covered throughout the entire lifecycle (prevention, detection, response, reconstruction).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></li>
<li><span data-contrast="auto">The tools can feed </span><b><span data-contrast="auto">existing processes</span></b><span data-contrast="auto"> (SOC, crisis management, PRA, IAM).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></li>
<li><span data-contrast="auto">Dependence on a single publisher is assessed and controlled.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:60,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684,6300],&quot;469777927&quot;:[0,0],&quot;469777928&quot;:[1,1]}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">3. Cloud hybridisation</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">With the rise of Entra ID and SaaS applications, identity hybridisation has become the norm: AD accounts and groups are synchronised to the cloud, and the same credentials are used to access on-premises and cloud resources. Numerous recent incidents show that attackers are exploiting these hybrid architectures to pivot between AD and Entra ID, taking advantage of poor configurations or weak alignment between the two worlds. [7]</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:533}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This translates into several concrete needs:</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:533}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Joint supervision</span></b><span data-contrast="auto"> of AD and Entra ID: ability to correlate signals from the on-premises directory (changes, anomalies, lateral movement attempts) and the cloud (Entra ID Protection signals, connection anomalies, conditional access, etc.). </span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></li>
<li><b><span data-contrast="auto">Security policy alignment</span></b><span data-contrast="auto">: hardening of AD (configuration, delegation, privileged accounts) in line with conditional access policies, MFA and Zero Trust requirements. </span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></li>
<li><b><span data-contrast="auto">Hybrid reconstruction capabilities</span></b><span data-contrast="auto">: in the event of AD compromise, reconstruction and restoration must integrate Entra ID dependencies (synchronisation, service accounts, applications) to avoid side effects on the cloud, and vice versa.</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></li>
</ul>
<p style="text-align: justify;"><b><span data-contrast="auto">Publisher are gradually positioning themselves on this hybridisation. </span></b><span data-contrast="auto">Some are expanding their AD audit engines to include Entra ID (on-premises to cloud) and offer a unified view of identity vulnerabilities: Netwrix Auditor now allows Entra ID to be monitored in parallel with Active Directory with a single view of hybrid threats. Tenable Identity Exposure extends its exposure indicators to specific Entra ID risks, and Semperis Directory Services Protector correlates AD and Entra ID changes in a single console to reduce the hybrid attack surface.</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:533}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Other tools start in the cloud (Entra ID, SaaS) and move down to on-premises AD (cloud to on-premises), using a hybrid identity threat detection and response approach: Microsoft Defender for Identity provides a consolidated inventory of AD and Entra ID identities and new detection capabilities on hybrid components (Entra Connect, AD FS, etc.), while CrowdStrike Falcon Identity Threat Protection analyses hybrid accounts present in both AD and Entra ID/Azure AD.</span><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<h1 style="text-align: justify;"><span data-contrast="none">Operational implementation still has room for improvement</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">The Active Directory security market is seeing growing and structured adoption of sophisticated tools. In many organisations, functional coverage is now adequate, or even advanced, across the various aspects of AD security (auditing, hardening, detection, backup).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">However, technological maturity contrasts with operational implementation that is still incomplete. AD disaster recovery plans (DRPs) often remain theoretical, untested, or disconnected from the backup and reconstruction tools deployed. Regular reviews (of privileges, delegations, approval relationships) are still rarely industrialised: they often depend on a few experts, with a limited level of automation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The effectiveness of implementation is also impacted by the constant evolution of the ecosystem, between the platformisation of tools and the hybridisation of identities. The challenge for the coming years will therefore be to align tools (both existing and future) with robust, documented and tested processes:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol>
<li><b><span data-contrast="auto">Clarify responsibilities</span></b><span data-contrast="auto"> between infrastructure, IAM, security and SOC teams,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Formalise and automate recurring controls </span></b><span data-contrast="auto">(rights reviews, configuration validation, restoration tests).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p style="text-align: justify;"><span data-contrast="auto">Only then will investments in Active Directory security tools, both on-premises and in the cloud, enable true resilience to be achieved.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:1,&quot;335551620&quot;:1}"> </span></p>
<h1><span data-contrast="none">Methodology overview</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">We have identified four main categories for grouping tools:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Analysis and audit:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ul>
<li><b><span data-contrast="auto">Account and Privilege</span></b><span data-contrast="auto">: Inventory of accounts, groups and associated rights to detect excessive or non-compliant privileges.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">AD Discovery</span></b><span data-contrast="auto">: Exploration of the AD structure (OUs, GPOs, objects) to deduce the architecture, relationships and dependencies.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Vulnerability Discovery</span></b><span data-contrast="auto">: Identification of security vulnerabilities (configuration, obsolete accounts, weak passwords, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Attack Path Discovery</span></b><span data-contrast="auto">: Modelling potential attack paths to privileged accounts.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h3><span data-contrast="none">Hardening and management:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ul>
<li><b><span data-contrast="auto">Password Management</span></b><span data-contrast="auto">: Management of password policies, synchronisation, password auditing (strength, reuse, compromise, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Rights &amp; Privilege Management</span></b><span data-contrast="auto">: Delegation, access control, role and permission management.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">GPOs Management</span></b><span data-contrast="auto">: Creation, analysis, modification of group policy objects.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Change Management</span></b><span data-contrast="auto">: Change tracking, traceability, change management and migration tools.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h3><span data-contrast="none">Monitoring:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ul>
<li><b><span data-contrast="auto">Threat Detection</span></b><span data-contrast="auto">: Proactive detection of suspicious behaviour, privilege escalation, lateral movement.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Security Incident Detection: </span></b><span data-contrast="auto">Identification of security incidents, real-time alerts, event correlation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="none">Backup and Recovery:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">AD Backup &amp; Recovery</span></b><span data-contrast="auto">: Partial or complete backup of AD objects, rapid disaster recovery.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Investigation &amp; Forensics</span></b><span data-contrast="auto">: Post-incident analysis, traceability of malicious actions, evidence collection.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:1619}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">For each of the tools classified, a badge (Microsoft Entra ID logo) is added when the tool offers the possibility of integrating Microsoft Entra ID into its operation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"> </span></p>
<h1>Conclusion</h1>
<p> </p>
<p style="text-align: justify;"><span data-contrast="auto">The 2026 overview is based on an analysis of 180 tools, compared to 150 in 2022. It was constructed using a similar approach to that of 2002. It is based on a listing of tools on the market. On this basis, and in line with recurring themes in Active Directory security, a categorisation has been established to facilitate reading.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The list of tools mentioned is not intended to be exhaustive, as the list of tools that can contribute directly or indirectly to Active Directory security is vast. This overview is therefore a summary of the main existing tools, particularly those that Wavestone consultants encounter most often in large organisations (considered, studied, tested or deployed).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p> </p>
<h1 style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}">References</span></h1>
<p style="text-align: justify;"><span data-contrast="none">[1] </span><a href="https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/"><span data-contrast="none">Microsoft Digital Defense Report 2025 | Microsoft</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[2] </span><a href="https://netwrix.com/en/resources/news/netwrix-acquires-pingcastle/"><span data-contrast="none">Netwrix Acquires PingCastle | Netwrix</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[3] </span><a href="https://investors.sentinelone.com/press-releases/news-details/2022/SentinelOne-Completes-Acquisition-of-Attivo-Networks/default.aspx?utm_source=chatgpt.com"><span data-contrast="none">SentinelOne, Inc. &#8211; SentinelOne Completes Acquisition of Attivo Networks</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[4] </span><a href="https://www.radiantlogic.com/news/radiant-logic-signs-definitive-agreement-to-acquire-brainwave-grc/?utm_source=chatgpt.com"><span data-contrast="none">Radiant Logic Signs Definitive Agreement to Acquire Brainwave GRC &#8211; Radiant Logic | Unify, Observe, and Act on ALL Identity Data</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[5] </span><a href="https://netwrix.com/fr/resources/news/netwrix-stealthbits-merge-to-address-demand-for-data-protection/"><span data-contrast="none">Netwrix annonce sa fusion avec Stealthbits | Netwrix</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[6] </span><a href="https://www.riskinsight-wavestone.com/en/2022/05/active-directory-security-tools-radar/"><span data-contrast="none">Radar des outils pour renforcer la sécurité d’Active Directory &#8211; RiskInsight</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p style="text-align: justify;"><span data-contrast="none">[7] </span><span data-contrast="none">Microsoft Incident Response lessons on preventing cloud identity compromise | Microsoft Security Blog</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;469777462&quot;:[3684],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/">Overview of Active Directory security tools – version 2026 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/03/overview-of-active-directory-security-tools-version-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Generative AI applications: risks and mitigations </title>
		<link>https://www.riskinsight-wavestone.com/en/2024/11/generative-ai-applications-risks-and-mitigations/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/11/generative-ai-applications-risks-and-mitigations/#respond</comments>
		
		<dc:creator><![CDATA[Baptiste Cianchi]]></dc:creator>
		<pubDate>Wed, 06 Nov 2024 16:22:04 +0000</pubDate>
				<category><![CDATA[Focus]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[generative AI]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=24514</guid>

					<description><![CDATA[<p>Microsoft has announced that in Q2 2024 &#8220;more than half of Fortune 500 companies will be using Azure OpenAI&#8221;. [1] At the same time, AWS is offering Bedrock [2], a direct competitor to Azure OpenAI.  This type of platform can...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/11/generative-ai-applications-risks-and-mitigations/">Generative AI applications: risks and mitigations </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-contrast="auto">Microsoft has announced that in Q2 2024 </span><i><span data-contrast="auto">&#8220;more than half of Fortune 500 companies will be using Azure OpenAI&#8221;</span></i><span data-contrast="auto">. [<a href="https://synthedia.substack.com/p/microsoft-azure-ai-users-base-rose">1</a>] At the same time, AWS is offering Bedrock [<a href="https://www.usine-digitale.fr/article/amazon-fait-son-entree-sur-le-marche-de-l-ia-generative-avec-bedrock.N2121081">2</a>], a direct competitor to Azure OpenAI.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This type of platform can be used to create applications based on generative AI models such as LLMs (GTP-3.5, Mistral, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Nevertheless, the adoption of this technology is not without risk: from virtual assistants criticizing their companies [<a href="https://www.theguardian.com/technology/2024/jan/20/dpd-ai-chatbot-swears-calls-itself-useless-and-criticises-firm">3</a>] to data leaks [<a href="https://openai.com/blog/march-20-chatgpt-outage">4</a>]; there is no shortage of examples.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">To support the many deployments currently underway, you need to think quickly about your security, particularly when sensitive data is being used. In this article, we take a look at the risks and mitigations associated with using these platforms.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h2 style="text-align: justify;" aria-level="2"><span data-contrast="none">Which model is right for you?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p style="text-align: justify;"><span data-contrast="auto">Three types of generative AI can be used to create an application. The difference lies in the precision of the answers provided: </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Simple</span></b><span data-contrast="auto">: generic AI model (GPT-4, Mistral, etc.) plugged in as such, with a user interface. </span><span data-contrast="auto">It is an internal GPT.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Boosted</span></b><span data-contrast="auto">: generic AI model that leverages the company&#8217;s data, for example via RAG (</span><i><span data-contrast="auto">Retrieval Augmented Generation). </span></i><span data-contrast="auto">These are specialized companions for a particular use, HR GPT, Operations GPT, CISO GPT&#8230;).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li data-leveltext="%1." data-font="" data-listid="14" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">Specialized</span></b><span data-contrast="auto">: the AI model retrained for a particular use. For example, India has retrained Llama 3 for its 22 official languages to make it a specialized translator.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p style="text-align: justify;"><span data-contrast="auto">All three deployment methods entail risks. We will begin by describing the different modes. We will then look at the risks, and the associated mitigations</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img decoding="async" class="aligncenter wp-image-24518 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/1-Risks-and-models.jpg" alt="" width="1280" height="720" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/1-Risks-and-models.jpg 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/1-Risks-and-models-340x191.jpg 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/1-Risks-and-models-69x39.jpg 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/1-Risks-and-models-768x432.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/1-Risks-and-models-800x450.jpg 800w" sizes="(max-width: 1280px) 100vw, 1280px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">Risks and models</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p> </p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Simple model</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">This model is the simplest to deploy. It allows users to interact with the AI models proposed by the platforms. It simplifies the integration of sending prompts and receiving responses in an application. </span><span data-contrast="auto">It is an internal ChatGPT, with the advantage of limiting the leakage of sensitive data inserted into a prompt, unlike the web version. Also, in this case, exchanges with users are not used to re-train and improve the model. Your data is protected. The Cloud platforms offered by Azure, AWS or GCP enable these solutions to be deployed rapidly.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Examples of use: text summary, development assistant.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> <img decoding="async" class="aligncenter wp-image-24520 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/2-How-the-simple-model-works--e1730990068519.jpg" alt="" width="1075" height="582" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/2-How-the-simple-model-works--e1730990068519.jpg 1075w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/2-How-the-simple-model-works--e1730990068519-353x191.jpg 353w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/2-How-the-simple-model-works--e1730990068519-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/2-How-the-simple-model-works--e1730990068519-768x416.jpg 768w" sizes="(max-width: 1075px) 100vw, 1075px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">How the simple model works</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Boosted model</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">This model remains generic, but will have access to selected company data. The AI could, for example, consult the group&#8217;s PSSI to provide the password policy.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Examples of use: enterprise chatbot, data analysis.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24522 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/3-How-the-boosted-model-works--e1730990097453.jpg" alt="" width="1256" height="552" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/3-How-the-boosted-model-works--e1730990097453.jpg 1256w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/3-How-the-boosted-model-works--e1730990097453-435x191.jpg 435w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/3-How-the-boosted-model-works--e1730990097453-71x31.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/3-How-the-boosted-model-works--e1730990097453-768x338.jpg 768w" sizes="auto, (max-width: 1256px) 100vw, 1256px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">How the boosted model works</span></i></p>
<p> </p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Specialized model</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">The application is no longer based on a generic model (GPT-4, Mistral, etc.). Before using it, you will need to train your own model on your company&#8217;s data. It will always be able to consult the company&#8217;s data and will have a better understanding of it to generate its response.</span><span data-ccp-props="{}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Examples of applications: fault detection on a production line, medical diagnostics.</span><span data-ccp-props="{}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24524 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/4-How-the-specialised-model-works--e1730990131373.jpg" alt="" width="1280" height="678" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/4-How-the-specialised-model-works--e1730990131373.jpg 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/4-How-the-specialised-model-works--e1730990131373-361x191.jpg 361w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/4-How-the-specialised-model-works--e1730990131373-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/4-How-the-specialised-model-works--e1730990131373-768x407.jpg 768w" sizes="auto, (max-width: 1280px) 100vw, 1280px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">How the specialized model works</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h2 style="text-align: justify;" aria-level="2"><span data-contrast="none">What risks are you exposed to?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p style="text-align: justify;"><span data-contrast="auto">Regardless of the model selected, there are a number of transversal or specific risks. It is important to take these into account to ensure that the solution is securely integrated.</span><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Hijacking the model</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">AI models are exposed to the risk of misuse. Imagine a scenario where someone uses this technology to generate harmful content. This could lead to real consequences such as the propagation of toxic content. </span><span data-contrast="auto">One known attack for this purpose is </span><i><span data-contrast="auto">Prompt Injection </span></i><span data-contrast="auto">[<a href="https://www.riskinsight-wavestone.com/en/2023/10/language-as-a-sword-the-risk-of-prompt-injection-on-ai-generative/">5</a>].</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24526 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/5-Example-Model-hijacking-Prompt-Injection--e1730990299679.jpg" alt="" width="1064" height="573" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/5-Example-Model-hijacking-Prompt-Injection--e1730990299679.jpg 1064w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/5-Example-Model-hijacking-Prompt-Injection--e1730990299679-355x191.jpg 355w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/5-Example-Model-hijacking-Prompt-Injection--e1730990299679-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/5-Example-Model-hijacking-Prompt-Injection--e1730990299679-768x414.jpg 768w" sizes="auto, (max-width: 1064px) 100vw, 1064px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">Example &#8211; Model hijacking (Prompt Injection)</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Hallucination</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">When AI asserts information that is false, it hallucinates. Think of it as &#8220;daydreaming&#8221;: if it doesn&#8217;t have the answer, it will &#8220;invent&#8221; things to fill the void. This can be particularly problematic in situations where accuracy is crucial: generating reports, making decisions, etc. Users could unknowingly spread this false information, or make bad decisions. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24528 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/6-Example-Model-hallucination--e1730992007979.jpg" alt="" width="1077" height="573" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/6-Example-Model-hallucination--e1730992007979.jpg 1077w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/6-Example-Model-hallucination--e1730992007979-359x191.jpg 359w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/6-Example-Model-hallucination--e1730992007979-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/6-Example-Model-hallucination--e1730992007979-768x409.jpg 768w" sizes="auto, (max-width: 1077px) 100vw, 1077px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">Example &#8211; Model hallucination</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Data leakage</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">There are several ways in which data can be leaked. An attacker can inject a malicious prompt to retrieve it, or an employee can be given more rights than necessary and access sensitive information (e.g. strategic minutes of an executive committee meeting). The security of the underlying database must therefore be proportional to the amount of data stored.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The model has access to certain company data. If, for example, its rights are too extensive, it will be able to consult confidential data. These responses will therefore include sensitive information that should not be disclosed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24530 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/7-Example-Data-leak--e1730992041787.jpg" alt="" width="1269" height="569" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/7-Example-Data-leak--e1730992041787.jpg 1269w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/7-Example-Data-leak--e1730992041787-426x191.jpg 426w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/7-Example-Data-leak--e1730992041787-71x32.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/7-Example-Data-leak--e1730992041787-768x344.jpg 768w" sizes="auto, (max-width: 1269px) 100vw, 1269px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">Example &#8211; Data leak</span></i></p>
<p> </p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Model theft</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">If the model is specialized, it is now your company&#8217;s intellectual property. As such, it could be a target for attackers. Confidential training data, for example, could be targeted. The question of trust in the Cloud host may also arise: wouldn&#8217;t it be better to host it locally?</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24532 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/8-Example-Model-theft--e1730992077288.jpg" alt="" width="1280" height="682" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/8-Example-Model-theft--e1730992077288.jpg 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/8-Example-Model-theft--e1730992077288-358x191.jpg 358w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/8-Example-Model-theft--e1730992077288-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/8-Example-Model-theft--e1730992077288-768x409.jpg 768w" sizes="auto, (max-width: 1280px) 100vw, 1280px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto"> Example &#8211; Model theft</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Poisoning the model</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">Without claiming to steal the model, the attacker&#8217;s aim could be to make it unreliable. The responses generated could then no longer be used by the teams.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Poisoning can occur in two ways: </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul style="text-align: justify;">
<li data-leveltext="-" data-font="Calibri" data-listid="21" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Calibri&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;-&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="0" data-aria-level="1"><span data-contrast="auto">Boosted model: the attacker accesses the RAG and modifies the information. The model then relies on poisoned data to provide its answers. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="-" data-font="Calibri" data-listid="21" data-list-defn-props="{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Calibri&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;-&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Specialized model: the attacker poisons the model&#8217;s training data. Either directly on the database that he makes available on a public platform (Hugging face type), or by accessing the training database hosted in your information system.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24534 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/9-Example-Poisoning-the-model--e1730992111840.jpg" alt="" width="1280" height="678" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/9-Example-Poisoning-the-model--e1730992111840.jpg 1280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/9-Example-Poisoning-the-model--e1730992111840-361x191.jpg 361w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/9-Example-Poisoning-the-model--e1730992111840-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/9-Example-Poisoning-the-model--e1730992111840-768x407.jpg 768w" sizes="auto, (max-width: 1280px) 100vw, 1280px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto"> Example &#8211; Poisoning the model</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h2 style="text-align: justify;" aria-level="2"><span data-contrast="none">Main risks: what mitigations?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p style="text-align: justify;"><span data-contrast="auto">Of the 5 risks presented, 3 dominate in the risk analyses carried out by our teams. We suggest you study the associated mitigations.</span><span data-ccp-props="{}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">The novelty of the technology provides an opportunity to build a solid security foundation. Several iterations will be necessary to achieve an effective and secure solution.</span><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Risk #1: Hijacking the model</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24536 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/10-Hijacking-the-model-and-the-key-to-remediation--e1730908671925.jpg" alt="" width="876" height="721" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/10-Hijacking-the-model-and-the-key-to-remediation--e1730908671925.jpg 876w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/10-Hijacking-the-model-and-the-key-to-remediation--e1730908671925-232x191.jpg 232w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/10-Hijacking-the-model-and-the-key-to-remediation--e1730908671925-47x39.jpg 47w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/10-Hijacking-the-model-and-the-key-to-remediation--e1730908671925-768x632.jpg 768w" sizes="auto, (max-width: 876px) 100vw, 876px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">Hijacking the model and the key to remediation</span></i></p>
<p style="text-align: justify;"><b><span data-contrast="auto">We recommend the following measures to prevent the model from being hijacked:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#1 &#8211; Toughen the configuration </span></b><span data-contrast="auto">in two ways. Firstly, management of the </span><i><span data-contrast="auto">master prompt </span></i><span data-contrast="auto">(discussion window with the model). Certain keywords, for example, can be banned to prevent abuse. Secondly, the number of </span><i><span data-contrast="auto">tokens </span></i><span data-contrast="auto">and therefore the size of responses. A less verbose model will have less chance of being hijacked. Other parameters can be taken into account: temperature, language used, etc.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#2 &#8211; Filter responses </span></b><span data-contrast="auto">by applying, for example, a simple response filtering algorithm. To go further, it is possible to deploy specialised LLM firewalls. This would make it possible, for example, to prevent potential abuse (this is known as </span><i><span data-contrast="auto">abuse monitoring).</span></i><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#3 &#8211; Limit the sources </span></b><span data-contrast="auto">to which the model has access to generate its responses. If the model is given access to company data, it can be limited to this data only. In this way, it will not be able to search for other information on the Internet, for example. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p> </p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Risk #2: Hallucination</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class="aligncenter wp-image-24538 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/11-Hallucination-and-the-key-to-remediation--e1730908712943.jpg" alt="" width="934" height="721" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/11-Hallucination-and-the-key-to-remediation--e1730908712943.jpg 934w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/11-Hallucination-and-the-key-to-remediation--e1730908712943-247x191.jpg 247w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/11-Hallucination-and-the-key-to-remediation--e1730908712943-51x39.jpg 51w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/11-Hallucination-and-the-key-to-remediation--e1730908712943-768x593.jpg 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto"> Hallucination and the key to remediation</span></i></p>
<p style="text-align: justify;"><b><span data-contrast="auto">To deal with hallucinations, we recommend the following measures:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#1 &#8211; Train and educate </span></b><span data-contrast="auto">users on how models work, their limitations and best practices. This enables users to use Large Language Models responsibly and to recognise misuse or potential security threats.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#2 &#8211; Toughen the configuration </span></b><span data-contrast="auto">in two ways. Firstly, adjusting the parameters, including setting the model </span><i><span data-contrast="auto">temperature </span></i><span data-contrast="auto">(how creative the model is) and limiting the number of </span><i><span data-contrast="auto">tokens </span></i><span data-contrast="auto">(number of words per question/answer). Secondly, the use of a more recent model (GPT-4 rather than GPT 3.5 for example).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#3 &#8211; </span></b><b><i><span data-contrast="auto">Optional </span></i></b><b><span data-contrast="auto">&#8211; Re-training the model </span></b><span data-contrast="auto">gives it a context. This will have a positive impact on the reliability of responses. Using a wide range of training data can help to cover more scenarios and reduce bias, which helps AI to better understand and generate appropriate responses. Similarly, eliminating errors and inconsistencies in training data can reduce the likelihood of the AI learning and repeating these same errors.</span><span data-ccp-props="{}"> </span></p>
<p> </p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Risk #3: Data leakage</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img loading="lazy" decoding="async" class="aligncenter wp-image-24540 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/12-Data-leakage-and-the-key-to-remediation--e1730908754355.jpg" alt="" width="998" height="721" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/12-Data-leakage-and-the-key-to-remediation--e1730908754355.jpg 998w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/12-Data-leakage-and-the-key-to-remediation--e1730908754355-264x191.jpg 264w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/12-Data-leakage-and-the-key-to-remediation--e1730908754355-54x39.jpg 54w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/11/12-Data-leakage-and-the-key-to-remediation--e1730908754355-768x555.jpg 768w" sizes="auto, (max-width: 998px) 100vw, 998px" /> </span><i style="color: initial;"><span data-contrast="auto">Data leakage and the key to remediation</span></i></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">To deal with leaks of sensitive data, we recommend the following measures:</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#1 &#8211; Ensuring compliance with data protection</span></b><span data-contrast="auto"> laws and protocols by involving</span><b><span data-contrast="auto"> the Data Protection Officer </span></b><span data-contrast="auto">(DPO) in projects accessing Large Language Model platforms is important to protect personal and sensitive data. By adhering to these standards, organizations not only protect individual privacy but also strengthen their defense against data breaches and misuse.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#2 &#8211; Manage rights and access </span></b><span data-contrast="auto">to all components interacting with the model. Understanding which data can be accessed by the model is not trivial. Auditing and recertifying this data over time helps to limit potential discrepancies.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#3 &#8211; Reduce the verbosity of the model </span></b><span data-contrast="auto">by limiting the number of output </span><i><span data-contrast="auto">tokens</span></i><span data-contrast="auto">. The less verbose a model is, the lower the probability that it will inadvertently share confidential data.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#4 &#8211; Anonymize the data</span></b><span data-contrast="auto">, or make it generic, if the use case allows. For example, AI will be able to work on population trends without an explicit name being cited. As well as greatly reducing the risk of data leakage, this will reduce the standards to be complied with (e.g. RGPD).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#5 &#8211; Limit the amount of sensitive data used</span></b><span data-contrast="auto">. Here we need to think about what data is necessary and sufficient for the model to work. The data can be processed beforehand to remove or modify sensitive data and thus reduce exposure (e.g. data anonymization).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<h3 style="text-align: justify;" aria-level="3"><span data-contrast="none">Cross-disciplinary mitigations</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h3>
<p style="text-align: justify;"><span data-contrast="auto">Certain measures apply to all the risks listed above. Two of them are fundamental. </span><span data-ccp-props="{}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#1 &#8211; Integrate security into projects </span></b><span data-contrast="auto">via, for example, contextualized security analysis. This enables organizations to preventively identify and mitigate potential vulnerabilities, ensuring that only secure and verified projects access generative AI applications. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><b><span data-contrast="auto">#2 &#8211; Document each application </span></b><span data-contrast="auto">to establish an operational framework that not only facilitates easier supervision and management, but also reduces the risk of unauthorized or malicious use. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<p> </p>
<p style="text-align: justify;" aria-level="2"> </p>
<p style="text-align: justify;"><span data-contrast="auto">The development of AI applications is accelerated by the platforms available. However, the sophistication it brings is not without risk. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Recognizing these challenges, the priority is to establish robust governance for the platform. This involves delineating roles and responsibilities, ensuring a structured approach to managing and mitigating risks.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">Governance extends beyond the platform itself. Securing the myriads of AI application use cases is just as important. It&#8217;s about ensuring that the application of this AI technology is both responsible and aligned with ethical standards, guarding against misuse and unintended consequences.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This calls for a model of shared responsibility, where all stakeholders &#8211; developers, users and governance bodies &#8211; work together to maintain the integrity and security of AI applications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p> </p>
<p> </p>
<p style="text-align: justify;" aria-level="1"><span data-contrast="none">References</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<ol>
<li data-leveltext="%1." data-font="" data-listid="13" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><a href="https://synthedia.substack.com/p/microsoft-azure-ai-users-base-rose"><span data-contrast="none">https://synthedia.substack.com/p/microsoft-azure-ai-users-base-rose</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><a href="https://www.usine-digitale.fr/article/amazon-fait-son-entree-sur-le-marche-de-l-ia-generative-avec-bedrock.N2121081"><span data-contrast="none">https://www.usine-digitale.fr/article/amazon-fait-son-entree-sur-le-marche-de-l-ia-generative-avec-bedrock.N2121081 </span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li data-leveltext="%1." data-font="" data-listid="13" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><a href="https://www.theguardian.com/technology/2024/jan/20/dpd-ai-chatbot-swears-calls-itself-useless-and-criticises-firm"><span data-contrast="none">https://www.theguardian.com/technology/2024/jan/20/dpd-ai-chatbot-swears-calls-itself-useless-and-criticises-firm</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><a href="https://openai.com/blog/march-20-chatgpt-outage"><span data-contrast="none">https://openai.com/blog/march-20-chatgpt-outage</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li style="text-align: justify;" data-leveltext="%1." data-font="" data-listid="13" data-list-defn-props="{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><a href="https://www.riskinsight-wavestone.com/en/2023/10/language-as-a-sword-the-risk-of-prompt-injection-on-ai-generative/"><span data-contrast="none">https://www.riskinsight-wavestone.com/2023/10/quand-les-mots-deviennent-des-armes-prompt-injection-et-intelligence-artificielle/</span></a><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/11/generative-ai-applications-risks-and-mitigations/">Generative AI applications: risks and mitigations </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/11/generative-ai-applications-risks-and-mitigations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Surviving an Active Directory compromise: Key lessons to improve the reconstruction Process </title>
		<link>https://www.riskinsight-wavestone.com/en/2023/06/surviving-an-active-directory-compromise-key-lessons-to-improve-the-reconstruction-process/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/06/surviving-an-active-directory-compromise-key-lessons-to-improve-the-reconstruction-process/#respond</comments>
		
		<dc:creator><![CDATA[Baptiste Cianchi]]></dc:creator>
		<pubDate>Mon, 05 Jun 2023 09:05:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[AD]]></category>
		<category><![CDATA[Recovery]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20616</guid>

					<description><![CDATA[<p>Active Directory is a critical asset whose failure affects a large portion of your information system  Your company is currently dealing with a major ransomware crisis. Given its central role in managing access, authentication, and network resources within any organisation,...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/06/surviving-an-active-directory-compromise-key-lessons-to-improve-the-reconstruction-process/">Surviving an Active Directory compromise: Key lessons to improve the reconstruction Process </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 style="text-align: justify;">Active Directory is a critical asset whose failure affects a large portion of your information system </h2>
<p style="text-align: justify;">Your company is currently dealing with a major ransomware crisis. Given its central role in managing access, authentication, and network resources within any organisation, cybercriminals have compromised the Active Directory in 100% of these crises.  </p>
<p style="text-align: justify;">Your systems are now encrypted if the attackers have activated the malicious payload. They might otherwise be isolated and unavailable. In either case, your company no longer has the necessary resources to function properly, and your activity has either ceased or has been significantly slowed! <br /><br /></p>
<figure id="attachment_20568" aria-describedby="caption-attachment-20568" style="width: 2519px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-20568 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5.png" alt="Perimeter affected by compromise" width="2519" height="1152" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5.png 2519w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5-418x191.png 418w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5-768x351.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5-1536x702.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image5-2048x937.png 2048w" sizes="auto, (max-width: 2519px) 100vw, 2519px" /><figcaption id="caption-attachment-20568" class="wp-caption-text"><em>Perimeter affected by compromise</em></figcaption></figure>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">In this case, trust in your information system has been broken. Your teams begin to feel business pressure, and one question persists: when will we be able to reopen our services? Your goal then becomes clear: you must restore Active Directory with a high enough level of trust to reopen services as soon as possible. </p>
<p style="text-align: justify;">Rebuilding an Active Directory is a difficult step in crisis management. If poorly executed, your organisation exposes itself to two major risks: exacerbating the operational impacts for the business or introducing a new threat to your environment.</p>
<p style="text-align: justify;">The ANSSI has recently published three very comprehensive guides on this subject <a href="#ref1" name="ref1-retour">[1]</a>, which we recommend you read. </p>
<p style="text-align: justify;">In this article, we will go over some of the items that stood out to us during crisis management. Our teams were able to overcome numerous obstacles during their interventions. What are the main issues that have arisen? How can they be fixed?</p>
<h2 style="text-align: justify;">From compromise to reopening: advice to overcome obstacles</h2>
<figure id="attachment_20580" aria-describedby="caption-attachment-20580" style="width: 2972px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-20580 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b.png" alt="Active Directory rebuild - Five main advices" width="2972" height="1544" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b.png 2972w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b-368x191.png 368w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b-768x399.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b-1536x798.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image6b-2048x1064.png 2048w" sizes="auto, (max-width: 2972px) 100vw, 2972px" /><figcaption id="caption-attachment-20580" class="wp-caption-text"><em>Active Directory rebuild &#8211; Five main advices</em></figcaption></figure>
<h3> </h3>
<h3 style="text-align: justify;"><strong>Start remediation efficiently with a proven organization</strong></h3>
<p style="text-align: justify;">Time lost due to poor crisis organisation can exacerbate the consequences of an Active Directory compromise. Teams are frequently unsure of what to do, who to involve, and what goals to pursue. A delayed response will increase remediation costs, revenue losses, and have an impact on the company&#8217;s reputation.</p>
<p style="text-align: justify;"><em>Before the crisis&#8230;</em><br />It is necessary to identify all the key players to involve in the reconstruction of the Active Directory:</p>
<p style="text-align: justify;">The executive committee will resolve fundamental issues. For example, do we prioritise reopening critical services quickly for business reasons or slowly and securely? There are several possible postures, each with advantages and disadvantages [1 &#8211; Strategic Dimension]. The entire remediation plan is based on this decision, so the executive committee must make a decision to begin work immediately.  </p>
<p style="text-align: justify;">Business teams will identify and prioritise the most critical services for restoration. The Active Directory compromise affects the majority of the company&#8217;s services, and your teams will be unable to handle all requests at once. </p>
<p style="text-align: justify;">Intervention teams (technical and security) will be formed to define and implement the remediation strategy. Because of the expertise and human efforts required to rebuild an Active Directory, temporary reinforcement of your teams is required to handle the remediation: mastering configuration review tools (PingCastle, Purple Knight, etc.), prioritising detected vulnerabilities, deployment and control of measures, and so on. </p>
<p style="text-align: justify;">It is critical to define processes and reflex cards in order to optimise each actor&#8217;s reaction time. Simulations and regular exercises should be organised in addition to their writing to train your teams to react effectively. </p>
<p style="text-align: justify;"><em>During the crisis&#8230;</em> </p>
<p style="text-align: justify;">Rapidly implement a project monitoring system that includes regular reports, action tracking, and coordination among the various teams involved. Too often, a lack of communication and information leads to a slowdown in remediation. It is not uncommon for administrators to take initiatives without taking the time to communicate them, such as opening more network ports than necessary, parallelizing two tasks from the remediation plan, and so on. These well-intended initiatives can have a significant impact on remediation, ranging from complicating the work to a distorted view of the true security level following the security work, and thus an increased risk of new lightning compromise. </p>
<p> </p>
<h3 style="text-align: justify;"><strong>Ensure the resilience of <span style="text-decoration: line-through;">b</span>ackups by defining a robust strategy  </strong><strong> </strong></h3>
<p style="text-align: justify;">When dealing with an Active Directory compromise, the unavailability of backups (corrupted or compromised) is a major challenge. Attackers frequently target and disable backups or disrupt backup servers. This complicates and lengthens Active Directory restoration and recovery. </p>
<p style="text-align: justify;"><em>Before the crisis&#8230;</em></p>
<p style="text-align: justify;">Create a resilient backup strategy that takes best practices and recommendations into account (backup on disconnected media, immutable or in the cloud) <a href="#ref2" name="ref2-retour">[2]</a>. There is currently a significant gap between state-of-the-art and implemented backup strategies (for example, Active Directory authentication of backup infrastructures, unsecured domain controller backups, and so on). </p>
<p style="text-align: justify;"><em>During the crisis…</em> </p>
<p style="text-align: justify;">Consider performing Active Directory remediation from a compromised domain controller. This &#8220;double bascule&#8221; method can assist in recovering and securing critical data in order to restore the Active Directory service without the use of a backup. When backups are unavailable and the strategy does not include rebuilding Active Directory from scratch, this scenario is selected. </p>
<figure id="attachment_20572" aria-describedby="caption-attachment-20572" style="width: 3967px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-20572 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7.png" alt="Overview - &quot;double bascule&quot; methodology" width="3967" height="1170" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7.png 3967w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7-437x129.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7-768x227.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7-1536x453.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image7-2048x604.png 2048w" sizes="auto, (max-width: 3967px) 100vw, 3967px" /><figcaption id="caption-attachment-20572" class="wp-caption-text"><em>Overview &#8211; &#8220;double bascule&#8221; methodology</em></figcaption></figure>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;"><strong>Anticipate technical problems such as DNS Active Directory configuration by maintaining your environment</strong><strong> </strong></h3>
<p style="text-align: justify;">The vast majority of Active Directory environments have accumulated technical debt over time (complex network architecture, roles such as DHCP carried out by domain controllers rather than dedicated servers, and so on). Furthermore, Active Directory environments are now synchronised with Azure Active Directory, establishing new technological dependencies that may complicate remediation in the event of an Active Directory compromise (Active Directory/Azure Active Directory synchronisation). These two elements can cause an array of technical issues on the day of the crisis (loss of synchronisation with Azure Active Directory, unavailability of the DHCP service carried by a domain controller that must be turned off, and so on).</p>
<p style="text-align: justify;"><em>Before the crisis&#8230;</em> </p>
<p style="text-align: justify;">Maintain Active Directory technical documentation and inventories (infrastructure, Azure Active Directory synchronisation, etc.). It often proves too difficult to obtain a clear view of the environment and the perimeter to be remediated. Up-to-date inventories will significantly improve remediation work and ensure the establishment of a consistent remediation plan. Additionally, this will allow you to identify and correct bad practises that could cause major issues on the day of the crisis (DNS service configuration, DHCP, and so on). </p>
<p style="text-align: justify;"><em>During the crisis&#8230;</em> </p>
<p style="text-align: justify;">After 30 days of desynchronization with the Active Directory, Azure Active Directory services may become unavailable, resulting in a ticking time bomb. Make sure to assess the consequences of losing Azure Active Directory services and avoid relying on them to handle critical tasks (email communication, for example).  </p>
<p style="text-align: justify;">The crisis will highlight numerous technical flaws (Active Directory configuration report via audit tools, network issues, and so on). Make sure to only deal with problems that are related to the remediation plan&#8217;s objectives (see Advice No. 5 &#8211; Set a course and stick to it during remediation!). </p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;"><strong>Optimize the reinitialization of secrets through processes adapted to your context</strong><strong> </strong><strong><br /></strong></h3>
<p style="text-align: justify;">Active Directory compromise results in a loss of trust in all of its secrets. As such, a reset of these is required to achieve the level of security required to reopen services while avoiding another quick compromise. Resetting a large number of user passwords and service accounts can have significant operational consequences in large environments with several thousand users and more than a hundred applications. To provide the new password for service accounts, you must first understand how the application uses the account. For users, you must devise a secure method of distributing new passwords on a large scale. </p>
<p style="text-align: justify;"><em>Before the crisis&#8230;</em> </p>
<p style="text-align: justify;">It is critical to have a clear understanding of the process of assigning new passwords to users. Several methods are available, depending on the environment studied, such as summoning users with the presentation of an identity card, transmitting the new username/password via physical mail, email, SMS, and so on. Regardless of the method chosen, the user must be required to reset his password on the next connection. Users may also be able to reset their own passwords using solutions that rely on two-factor authentication, for example. </p>
<p style="text-align: justify;">To carry out service account work, it is essential to create an inventory by identifying the associated applications and password reset methods for each of them. Obtaining this inventory by remediation teams is frequently complicated (unavailable, not maintained, etc.) and thus necessitates devoting significant time to tasks that can be completed outside of the crisis. Aside from remediation work, this exercise will help you manage your service accounts on a daily basis. One of the best practices is to change the passwords on these accounts on a regular basis. </p>
<p style="text-align: justify;"><em>During the crisis&#8230;</em> </p>
<p style="text-align: justify;">Once the passwords have been reset, it is necessary to ensure that the security measure has been implemented throughout the environment. This is easily accomplished with a PowerShell script, and it ensures that the attacker no longer has a valid account to exploit. </p>
<p> </p>
<h3 style="text-align: justify;"><strong>Set a course and stick to it during the remediation!</strong><strong> </strong></h3>
<p style="text-align: justify;">During an Active Directory reconstruction, it is frequently difficult to strike the right balance between exposing oneself to risks by reopening too quickly and incurring significant financial losses by reopening too slowly. Take care not to fall into the common pitfalls of managing a ransomware crisis.<a href="#ref3" name="ref3-retour">[3]</a> </p>
<p style="text-align: justify;"><em>Before the crisis&#8230;</em> </p>
<p style="text-align: justify;">It is necessary to consider the various remediation postures: quickly restoring vital services, regaining control of the information system, or seizing the opportunity to prepare for long-term control of the information system. <a href="#ref1" name="ref1-retour">[1]</a> </p>
<p style="text-align: justify;">Beyond defining the posture, ensure that you understand your Active Directory trust core, which is made up of the most critical assets (Tier 0). The remediation actions begin with these components (domain controllers, for example) in order to restore Active Directory&#8217;s vital services and to ensure a level of security that does not allow the attacker to compromise the entire environment again. </p>
<p style="text-align: justify;"><em>During the crisis&#8230;</em> <br />Make sure that your teams stay on track. As the remediation plan is carried out, new issues will emerge (unavailability of the domain controller carrying one of the required FSMO roles for remediation, network problems, and so on). It will be necessary to question the short-term relevance of its remediation in relation to the set objectives (the answer being dependent on the executive committee&#8217;s posture: quick reopening or slower and more secure).  </p>
<p style="text-align: justify;">Consider the opportunities presented by the crisis. For example, if the DHCP service was managed by a domain controller, take advantage of the opportunity to set up a dedicated DHCP server, thereby decoupling the service from the domain controller. </p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Our lessons  </h2>
<figure id="attachment_20574" aria-describedby="caption-attachment-20574" style="width: 2960px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-20574 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8.png" alt="Synthesis - How to prepare the Active Directory rebuild?" width="2960" height="1246" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8.png 2960w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8-437x184.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8-768x323.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8-1536x647.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/06/Image8-2048x862.png 2048w" sizes="auto, (max-width: 2960px) 100vw, 2960px" /><figcaption id="caption-attachment-20574" class="wp-caption-text"><em>Synthesis &#8211; How to prepare the Active Directory rebuild?</em></figcaption></figure>
<p> </p>
<p style="text-align: justify;">The improvement of the reconstruction process before the compromise of Active Directory ultimately rests on three main axes: </p>
<ol style="text-align: justify;">
<li>The drafting of functional processes and reflex cards to be able to: 
<ol style="text-align: justify;">
<li>Mobilize the right people in a timely manner. </li>
<li>Focus on the main objectives. </li>
<li>The maintenance of the Active Directory environment, which requires: </li>
</ol>
</li>
<li>Defining and maintaining an architecture in accordance with best practices. 
<ol style="text-align: justify;">
<li>Having up-to-date inventories. </li>
<li>Ensuring the resilience of backups. </li>
</ol>
</li>
<li>The performance of tests to: 
<ol style="text-align: justify;">
<li>Validate the applicability of theoretical processes in real conditions. </li>
<li>Improve the reactivity and efficiency of your teams in a crisis situation.</li>
</ol>
</li>
</ol>
<p style="text-align: justify;"><a href="#ref1-retour">[1]</a> <a href="https://www.ssi.gouv.fr/actualite/lanssi-publie-pour-appel-a-commentaires-un-corpus-documentaire-sur-la-remediation/" name="ref1">https://www.ssi.gouv.fr/actualite/lanssi-publie-pour-appel-a-commentaires-un-corpus-documentaire-sur-la-remediation/</a></p>
<p style="text-align: justify;"><a href="#ref2-retour">[2]</a> <a href="https://www.riskinsight-wavestone.com/en/2023/02/approaches-to-quick-active-directory-recovery/" name="ref2">https://www.riskinsight-wavestone.com/en/2023/02/approaches-to-quick-active-directory-recovery/</a></p>
<p style="text-align: justify;"><a href="#ref3-retour">[3]</a> <a href="https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/" name="ref3">https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/06/surviving-an-active-directory-compromise-key-lessons-to-improve-the-reconstruction-process/">Surviving an Active Directory compromise: Key lessons to improve the reconstruction Process </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/06/surviving-an-active-directory-compromise-key-lessons-to-improve-the-reconstruction-process/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
