"The impact of cyberattacks is playing out in boardrooms and operations centres across the region right now."
The blast radius: boardrooms to operations centres
Sarah Cecchetti, Director of Product Management at Semperis, warns that identity infrastructure compromises do not produce isolated outages but can "collapse an organisation’s ability to authenticate users, authorise access, and run business-critical systems." In APAC, Active Directory (AD) underpins the majority of enterprise environments; when attackers gain control there, Cecchetti says, "they’ve got everything and it’s game over." The real-world consequences are measured: recovery timelines for identity-based incidents are often “measured in weeks,” ransom demands and forensic costs compound losses, and sectors such as financial services, healthcare, and logistics can face contractual penalties and permanent customer attrition after as little as 48 hours of disruption.
AI-driven social engineering and autonomous attacks
Cecchetti describes a rapid shift in attacker economics driven by generative AI. Phishing and voice impersonation have advanced fastest: AI now produces highly personalised, grammatically flawless lures that reference job titles, LinkedIn activity and internal business context. Voice cloning and deepfake video are being used in the field to synthesize executive voices to authorise credential resets or wire transfers. Microsoft data cited by Cecchetti from its 2025 Digital Defense Report shows more than 7,000 password attacks being blocked per second, and she warns that intelligent automation is enabling autonomous AI agents to execute multi-stage identity campaigns with minimal human oversight.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadPersistent infrastructure gaps: AD misconfigurations, privilege sprawl, MFA, and machine identities
Cecchetti identifies five recurring gaps that leave identities exposed. First, excessive and unreviewed privilege: organisations accumulate domain admin accounts, legacy service accounts, and never-revoked project privileges that act as stepping stones for lateral movement. Second, AD misconfigurations—unconstrained delegation, weak Kerberos settings, outdated password policies and unprotected tier-zero assets—persist because continuous visibility into AD posture is lacking. Third, multi-factor authentication (MFA) gaps remain common: legacy applications, VPN endpoints and operational-technology systems often fall outside MFA coverage. Fourth, weak identity threat monitoring: many organisations use general-purpose SIEM tools rather than identity-focused detection that understands AD and Entra ID normal behaviour. Fifth, machine identities (service accounts, APIs, certificates and AI agents) are the fastest-growing identity category and are often less well governed than human identities.
Operational failures: detection without response and identity recovery shortfalls
Beyond tools, Cecchetti stresses operational discipline. A common failure is "detection without response"—monitoring flags suspicious activity but teams lack defined playbooks, allowing attackers time to escalate privileges and establish persistence. Identity recovery is also under-resourced: many organisations have not figured out how to back up and restore identity infrastructure after malware or destructive attacks. Without a tested, isolated AD backup and rebuild plan, recovery can be prolonged and reinfection more likely. Cecchetti asks a pointed question every AD operator should be able to answer: "If our domain controllers were wiped today, how long would it take us to restore identity services, and are we confident our backup is also not compromised?" She reports that very few organisations can answer with confidence.
What this means for technologists, policymakers, and affected enterprises (financial services, healthcare, logistics)
- Technologists and security teams: adopt continuous, identity-focused risk assessment tooling covering AD misconfigurations, privileged access sprawl and MFA coverage gaps; prioritise visibility across human and machine identities and enforce consistent policies across on-premises and cloud environments.
- Policymakers and regulators: expect incidents to reach executive leadership and regulatory scrutiny—Cecchetti notes leadership accountability is "very real" once impersonation, privileged system access or long undetected intrusions become public.
- Affected enterprises in financial services, healthcare and logistics: prepare for operational and contractual consequences from short outages—48 hours can trigger penalties and customer attrition—and invest in Tier 0 protection of domain controllers, privileged access workstations and identity management systems.
Concrete steps recommended
Cecchetti outlines practical measures organisations in APAC should prioritise: perform an identity risk assessment with automated, continuous visibility; implement a Tier 0 asset protection programme for domain controllers and privileged workstations; and test identity-specific incident response and recovery plans with isolated AD backup infrastructure that an attacker in production cannot reach. She also recommends red team exercises that target identity infrastructure and regular purple team exercises to validate detection and response against real attack techniques. Privileged Access Management with time-bound, just-in-time access for third parties and treating machine identities with the same governance as human identities are further specific mitigations she highlights.
The overarching message is operational: prevention and detection alone are not enough. Identity security, Cecchetti says, must be run as a continuous discipline with tested recovery paths—otherwise the next attack may not merely be costly; it may be unrecoverable for some organisations.




