For years, the enterprise security conversation has centered on authentication. Deploy MFA. Configure your identity and access management platform provider. Enforce MFA. Govern the access lifecycle. It's not bad advice — and it's largely worked. The authentication layer is more hardened than it's ever been.
The problem is post-authentication behavior, and worse: what happens when attackers bypass authentication entirely.
The attacker ends up operating inside the environment as a trusted identity. The authentication logs show nothing wrong.
"It's all about getting identity. It's no longer about installing malware. At the end of the day, the only thing you need to do is get access to that identity."
— Piotr Wojtyla, Head of Threat Intel & Platform, Abnormal AI
Mike Britton, Abnormal AI’s CIO, frames the same dynamic from the defender side: "Once I'm in as your account, I'm a trusted insider—and so it's much easier to pivot, much easier to lateral move." The attacker doesn't look like an attacker. They look exactly like the person whose credentials they're using.
This is the structural problem. Most identity security tooling is built to decide whether an action is permitted, not whether the identity executing it is still behaving like itself. The authentication stack confirms the credential. It has nothing to say about whether the session that follows reflects that identity's established patterns.
Adversary-in-the-middle attacks, which bypass MFA by intercepting session cookies in real time, surged in 2026—attackers stole 18.1 million API keys and authentication tokens. (callitdev.com)
Houston Hopkins, Abnormal AI's CISO, describes what that gap means operationally. The most effective attacks, in his experience, are post-authentication: a stolen token or hijacked session that looks valid on its face, with every permission check passing cleanly.
The credential is valid. The session is active. Every permission check passes. There is nothing to alert on—unless you already know what that identity normally looks like.
"The best attacks are post-MFA. You're getting a cookie, a credential, a token—it's on the machine, it can be lifted and used outside of where it was originally intended."
— Houston Hopkins, CISO, Abnormal AI
That gap runs across industries and maturity levels. Leach has had the same conversation with security teams at more than 20 enterprises in the past few months. Regardless of company size, maturity, or tooling sophistication, the finding is the same: post-authentication visibility is the gap no one has closed.
