"Your identity enables you digitally to access all of your different applications and services that are provided by any organization," said Josh Wagman, Director of Cyber Resilience Advisors at Semperis, during a Redmond Magazine tech talk on public sector crisis resilience. The line captures the practical pivot at the center of that discussion: identity is no longer one control among many. It has become the perimeter itself.
Josh Wagman on identity as the new perimeter
Wagman framed identity infrastructure — Active Directory, Entra ID, Okta and similar systems — as the foundational layer public sector organizations now depend on to operate. He warned that when those core systems are compromised, attackers can "establish long-term persistence, escalate privileges to gain widespread access, and move into any application connected through single sign-on." That chain of effects, he said, multiplies quickly: access can be used to exfiltrate highly sensitive personal data or to carry out destructive actions that cripple services citizens rely on.
Why public-sector incidents spread beyond a single system
The tech talk stressed a practical and structural problem: public sector environments rarely behave like single, well-resourced enterprises. Many agencies work with tight budgets and complex, multi-department structures, so an intrusion in one place can cascade into interruptions for emergency services, public health systems and the economic and social supports communities depend on daily. Because identity often ties together SaaS applications, physical building access and other services, a successful attack on identity can remove an agency’s ability to operate across multiple domains at once.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildThree readiness checks every agency should run now
- Can the organization perform simple audit changes to identity stores such as group membership or policy changes to organizational units in Active Directory?
- Are there alerts occurring when something questionable goes on?
- Has the organization ever performed a full recovery of its identity environment?
Wagman said that answering "no" to any of those questions indicates the organization is not ready to withstand an identity-targeted attack.
Isolate crisis response tools from compromised identity systems
A recurring and sharpened point in the talk: crisis plans and response tooling must be independent of the identity systems likely to be targeted. Wagman warned against relying on primary identity infrastructure for plans, contact lists and continuity documentation, because if that infrastructure is gone the planning itself can become unavailable. He also cautioned that single sign-on with an "isolation mode" is not sufficient — a threat actor who has been present in an environment may already be "sitting on the bridge" during incident response calls and listening in as teams plan countermeasures.
Tabletops, business impact assessments, and practical recovery steps
Wagman pressed organizations to move beyond theoretical planning to tested rehearsals. He recommended a mix of technical, executive and cross-functional tabletop exercises, with executive-level tabletops run at least once a year because they are where decision authority and policy gaps typically surface. For organizations building continuity planning from scratch, he offered a simple starting sequence: define the organizational mission; perform a business impact assessment to map which systems support that mission; identify dependencies; and then decide which systems need formal downtime procedures and how long those procedures can sustain operations before a full recovery becomes urgent.
What this means for technologists, policymakers, and the public
- Technologists and security teams: Prioritize identity resilience as the first step in recovery plans. Test simple administrative changes, alerting, and a full identity-environment recovery so that response options remain available if identity systems are compromised.
- Policymakers and executive leaders: Run annual executive-level tabletops to surface decision and policy gaps. Ensure crisis documentation and contact information do not depend on the very identity services that attackers will seek to disable.
- The general public and service users: Understand that disruptions to IT can extend into visible public services — emergency response, public health systems and social supports — when identity systems are attacked, and that resilience requires agencies to rehearse recovery in advance.
Wagman’s central admonition was straightforward: identity resilience is not a side project. It is the first step in any recovery effort, and failure to test that step leaves not just IT systems but entire communities exposed. For public sector organizations that have never recovered a broken identity environment, the question is no longer hypothetical — it is when, not if, they will need that capability.
Source: Redmond Magazine tech talk, as reported by Government Technology Insider




