For years, the enterprise security conversation has centered on authentication. Deploy MFA. Configure your identity and access management platform provider. Enforce MFA. Govern the access lifecycle. It's not bad advice — and it's largely worked. The authentication layer is more hardened than it's ever been.
The problem is post-authentication behavior, and worse: what happens when attackers bypass authentication entirely.
"The gap that I continue to see surface in every single conversation is around post-authentication visibility," says Mick Leach, Abnormal AI’s Field CISO who has spent the last several months talking about identity security with enterprise security teams across financial services, healthcare, manufacturing, and tech. "Everyone has invested heavily in the authentication layer. And candidly, it's working."
But working on authentication, he argues, is only half the problem.
"It's a lot like TSA. We scrutinize someone closely once as they come into the airport. Then once you've made it through, and we at least believe you are who you say you are, off you go. You're welcome to traipse around the terminal at will."
— Mick Leach, Field CISO, Abnormal AI
Enterprise security has built a remarkably good gate. What it hasn't built is any model for normal behavior on the other side of it.
