Identity is the New Attack Surface

Identity is no longer just a login: it’s the battleground. Learn how ITDR spots abuse of identities, not just breached machines, and how General Informatics helps lock the doors before damage is done.
Identity threat with compromised login from a hacker
Aaron Lancaster

·

March 4, 2026

·

Firewalls, endpoint protection, and monitoring tools are still important, but they’re no longer where most attacks start…identity.

Today’s attackers don’t break in. They log in with your identity.

Stolen credentials, abused service accounts, and over-permissioned users have become the easiest path into modern environments. That shift is exactly why Identity Threat Detection and Response (ITDR) is gaining so much attention.

What is ITDR?

ITDR focuses on detecting and stopping threats that abuse identities instead of systems.

Rather than asking “Is this device compromised?” ITDR asks a more relevant question: “Does this identity’s behavior make sense?”

ITDR looks at the behavior of:

  • User accounts
  • Administrator privileges
  • Service accounts and API keys
  • Cloud and SaaS identities

Why Traditional Security Misses Identity-Based Attacks

Most security tools were built for a different era. They’re good at spotting malware, suspicious files, or known attack signatures. But identity-based attacks often look legitimate on the surface:

  • A real username
  • A valid password
  • A successful login

By the time something looks “malicious,” the attacker may already have access to sensitive systems or data. ITDR fills this gap by watching how identities behave over time, not just whether access was granted.

To understand identity-based attacks in more detail, what they look like, how they happen, and how organizations can protect themselves, we recently hosted a webinar with the CEO & Co-Founder of Petra Security, Cooper Edmunds. It’s a great resource to see these threats in action and learn more about the solutions General Informatics delivers. You can watch it here.

How ITDR Complements Your Security Strategy

ITDR doesn’t replace IAM, PAM, or MFA; it amplifies them by adding detection and response where it’s most needed.

Think of it this way:

IAM

Identity and Access Management

Controls who can access

PAM

Privileged Access Management

Controls who should have access

MFA

Multi-Factor Authentication

Controls who proves their identity when accessing

ITDR

Identity Threat Detection and Response

Watches who is actually accessing – and whether it makes sense.

Together, they create a stronger, more realistic defense.

Real-World Impact

Identity abuse isn’t hypothetical. Stolen accounts, over-permissioned admin accounts, and misused service tokens are increasingly how attackers breach organizations. These incidents can lead to operational downtime, compliance violations, data exposure, and lost customer trust.

More than two-thirds of organizations worldwide report a rise in identity-based security incidents, and many can’t detect or respond until attackers have already established a foothold. Nearly half of businesses see these attacks making up over 40% of their incidents, and the consequences impact operations, trust, and the bottom line. (BetaNews)

laptop showing identy login with a phishing attack

General Informatics' Approach

General Informatics helps organizations implement ITDR as a practical, ongoing capability by combining our strategic expertise with advanced identity-focused security solutions made possible through our work with specialized partners, including organizations like Petra Security.

This approach provides:

  • Deep visibility into identity activity, not just logs – so suspicious access patterns don’t go unnoticed.
  • Contextual signals that separate normal use from risky behavior, reducing noise and focusing attention where it matters.
  • Rapid response workflows, so threats are contained and mitigated quickly.
  • Actionable insights for business teams, translating technical alerts into understandable steps aligned with operational and compliance priorities.

Most importantly, General Informatics makes these capabilities accessible and manageable for organizations without requiring them to build complex internal ITDR programs from scratch.

What is Petra Security?

Petra Security is a cybersecurity company that specializes in identity-focused threat detection and response solutions. Their platform helps organizations detect suspicious behavior in user accounts, administrative accounts, and service accounts before it leads to major security incidents. Petra Security’s technology powers the identity monitoring and response capabilities that General Informatics integrates for its clients.

The Bottom Line

Identity has quietly become the center of gravity in modern cyberattacks. When attackers gain access through a trusted account, they don’t trigger alarms – they blend in. This reality is why Cybersecurity has shifted. The critical question for organizations is no longer “Can someone get in?” It’s “What happens if a trusted identity is abused?

ITDR provides the missing layer of security: continuous visibility into how identities are being used, clear insight into suspicious behavior, and the ability to stop threats before they spread. Without it, many attacks go unnoticed until damage is already done.

Be on the lookout for our next blog, where we’ll pull back the curtain on the identity-based attacks that operate in plain sight — walking through how they start, what they look like once they’re inside an environment, and why they’re so easy to miss.

Think of General Informatics’ ITDR, powered through Petra Security, like a fire alarm, plus the fire department, plus a CSI forensics team: it doesn’t just tell you there’s a fire. It shows you where it started, what it touched, and helps you put it out safely. In the context of identity security, that means not only detecting when an account has been compromised, but also seeing which emails were read, which files were accessed, and what actions the attacker took. That context lets General Informatics respond quickly, contain the threat, and prevent further damage - all while understanding exactly what happened.

Ready to harden your identity-based defenses?

Book a no-pressure ITDR consult with our security experts.

Name(Required)

Connect With Aaron

Get to Know

Aaron Lancaster

Aaron Lancaster is a security expert with a history of providing superior cybersecurity solutions to clients in numerous industries. With over 16 years of experience in the cybersecurity field, Aaron brings a wealth of knowledge and experience to the table and holds credentials that go beyond most in the industry.

In his current role as General Informatics’ Information Security Officer, Aaron is responsible for leading General Informatics’ Security Consulting Practice. Prior to being acquired by General Informatics, Aaron served as the CEO and Founder of 1 Ping Security. Aaron is a highly sought-after speaker and is often delivering keynotes to national security conferences. He has attained a vast amount of security certifications and holds leadership roles amongst multiple security associations and alliances.

In addition, Aaron is a veteran of the U.S. Army, having served as a scout reconnaissance helicopter pilot and Information Assurance Security Officer. He earned a Graduate Certificate in Pentesting and Ethical Hacking from the SANS Technology Institute and holds a Bachelor of Science degree in Aeronautics from Embry-Riddle Aeronautical University.

Share the Word

Scroll to Top

Name(Required)
Please provide any details that suggests of a possible breach. Do not submit sensitive data.
Name(Required)
Want a "Plus One"?(Required)
Meet Our CEO & President

Don Monistere

Don Monistere is an Entrepreneur, Published Author and Accomplished Executive.

Monistere is the CEO and President of General Informatics. Monistere joined the General Informatics team in 2020 and has been actively growing its reach since. General Informatics is one of the fastest growing IT services providers in the Southeast and is considered the leading IT partner for businesses, schools, government agencies, and for the financial and maritime industry.

Name(Required)
Name(Required)