How attackers enter corporate networks through employee accounts
Hybrid work has not only reshaped operating models — it has fundamentally altered the architecture of corporate risk. An increasing share of attacks now unfolds through ordinary user accounts, familiar access routes, and employees’ own devices. In many scenarios, attackers no longer need to breach external defenses if they can instead leverage a legitimate account.
Timofey Kostin, international expert and former CRO at Una Financial Group, frames the problem through the interplay of internal and external security layers. At the core of his approach is a dual focus: protecting infrastructure from external threats while maintaining visibility and control over what happens inside — how access rights evolve, where connections originate, which actions deviate from established patterns, and at what point a regular employee becomes the entry point into the entire system.
Why the traditional perimeter no longer works
We are used to thinking of corporate security as protection of the external boundary. That logic still holds — but it is no longer sufficient.
Where IT environments were once predominantly office-based — with centralized network perimeters, on-premise infrastructure, and controlled corporate devices — the reality today is different. Remote and hybrid work, cloud services, a mix of personal and corporate devices, and distributed access points have redefined the landscape.

In this environment, security operates across two distinct layers.
The external layer is responsible for defending against attacks originating outside the organization — preventing intrusion, protecting the perimeter, and detecting suspicious activity approaching the infrastructure.

The internal layer governs what happens once access has been established. Here, the focus shifts to access rights, data integrity, user behavior, account creation, data movement, and deviations from normal operating patterns. This layer becomes critical when attackers do not break in — but log in.
What such an intrusion looks like
The attacker’s initial objective is typically to gain access to an employee’s device. The specific role is not always decisive — it may be someone in sales, support, development, or risk. However, roles with broader technical privileges and greater visibility into systems — administrators, support staff, and employees with remote access to other workstations — present higher-value targets.

What follows is a phase of reconnaissance. From the compromised device, attackers can extract credentials, map authentication mechanisms, determine whether multi-factor authentication is enforced, identify restrictions on access locations, and understand the scope of the user’s permissions and systems.
If authentication relies solely on login and password, the path forward becomes straightforward. Where access is restricted by location, control over the physical device may be required. This can occur unnoticed — for instance, during off-hours when activity on a workstation does not raise immediate suspicion.
Even multi-factor authentication is not a guaranteed safeguard. In one observed scenario, attackers initiate a parallel session at the exact moment a legitimate user logs in. The employee approves the authentication request, assuming it relates to their own session — but in reality, they authorize the attacker’s. Two sessions are established: one legitimate, one malicious. Detecting such anomalies is precisely where monitoring systems must prove effective.
Why these attacks are hard to detect
The defining characteristic of such intrusions is that they are rarely immediate.
Attackers typically move deliberately, spending weeks or even months studying the internal structure of an organization — mapping services, understanding access distribution, identifying control points, and locating sensitive assets. During this period, they may create shadow accounts, escalate privileges, and establish more resilient footholds before initiating active operations.
This is precisely what makes these attacks more dangerous than direct external breaches. Sudden attacks tend to trigger alerts due to clearly abnormal activity. By contrast, when attackers operate under the guise of legitimate users, it becomes significantly harder to determine how long they have been inside, what data has been extracted, and which actions have already been taken. Investigations in such cases can extend for months — or even years.
What this means for the business
The most immediate risk is the leakage of customer data — contact details, identity information, phone numbers, email addresses, account numbers, and, in some cases, transaction histories, balances, and cash flows.
But the implications extend far beyond data exposure.

If attackers gain controlled access to core infrastructure, they can interfere directly with critical processes: altering access rights, blocking users, influencing financial flows, opening or closing accounts, and executing transactions under legitimate identities. At that point, the issue is no longer a breach — it is a loss of operational control.
What increases risk in a hybrid environment
One of the most acute challenges is the coexistence of personal and corporate devices.
In an ideal scenario, organizations would provide fully controlled corporate devices, restrict unauthorized software, tightly manage environments, and continuously monitor activity. In practice, this is not always feasible. At a minimum, companies must implement baseline safeguards — password standards, phishing protection, and mandatory security controls on any device used to access corporate resources. The level of protection required should be aligned with the user’s level of access.
Additional vulnerabilities stem from the use of cloud services, externally hosted infrastructure, and third-party data processing environments. Each of these expands the external attack surface and increases the number of potential entry points.
Signals that must be detected early
There is no single control that can address this — detection depends on a layered approach.
At the external layer, this includes monitoring for atypical events, tracking domains and IP addresses associated with malicious activity, and scanning the dark web for compromised credentials or leaked datasets.
It also involves deploying decoy assets to detect lateral movement, securing external APIs, and implementing authentication methods that are more resistant to phishing.
Within the internal layer, organizations need visibility into:
- changes in access rights
- creation of new accounts
- account lifecycle events not linked to HR processes
- unusual session patterns
- abnormal data extraction
- access requests inconsistent with a user’s role or current task
A simple example illustrates the point: comparing the number of accounts created and closed against the number of hires and departures on a given day. Even such a basic control can reveal anomalies. In one case, it exposed administrators using unofficial accounts for testing — enabling the process to be formalized and brought under control.
What works in practice inside organizations
Several core principles consistently prove effective.
First — least privilege.
Access should be limited to what is strictly necessary for the task at hand — not what might theoretically be useful.
Second — microsegmentation.
Access rights can be dynamically adjusted. For example, permissions can be revoked at the start of a vacation and reinstated upon return. What was once operationally burdensome can now be automated based on HR events, reducing risk exposure without increasing administrative overhead.
Third — data sensitivity segmentation.
Not everyone who needs access to aggregate reports requires visibility at the level of individual customers. Access models should reflect not only roles, but also the depth of data required.
Fourth — behavioral profiling.
Organizations need a baseline model of normal user behavior and mechanisms to detect deviations. If a user typically accesses a client list eight times per day, with a normal range of six to twelve, eleven accesses may be acceptable — but fifteen should trigger scrutiny. The system can then either alert security teams or temporarily restrict access pending investigation.
Fifth — continuous monitoring and threat hunting.
Persistent observation across endpoints, networks, and cloud environments is essential — precisely because attacks unfold gradually rather than instantaneously.
The role of automation
Without automation and behavioral analytics, sustaining this level of monitoring is no longer feasible.
Previously, signals were aggregated into dashboards, but human operators cannot effectively process large volumes of indicators simultaneously. The emphasis must shift toward systems capable of operating continuously, identifying patterns, and correlating disparate signals in real time.
However, implementation must be carefully managed. Deploying such systems across the entire organization at once can generate excessive false positives, disrupt operations, and erode trust among employees. A phased rollout is essential — starting with selected teams, followed by calibration and refinement. Scaling should only occur once false-positive rates are reduced to approximately 1–2%.
This is not about mistrusting employees
It is important not to conflate security with suspicion.
The overwhelming majority of employees have no intention of harming the organization. However, through lack of awareness, limited experience, or weak digital hygiene, they can become part of an attack chain. The objective, therefore, is not only to control — but to protect employees from being exploited in this way.
This requires structured training, ongoing communication, and practical security education — programs that place individuals in realistic scenarios and clearly demonstrate the consequences of their actions.
Key Takeaway: What companies should do
What companies should do
There is no universal formula — but there is a clear sequence of actions.
First, separate external and internal security layers and abandon the assumption that perimeter protection alone addresses internal access risks.
Second, reassess user access rights based on strict necessity: who needs access, to what, from which device, and at what time.
Third, establish full lifecycle control over accounts — including creation, deletion, temporary access, service accounts, and test environments.
Fourth, detect anomalies not in isolation but in combination: parallel sessions, unexpected privilege changes, large data transfers, unusual access patterns, and activity from unfamiliar devices or locations.
Fifth, define explicit rules for hybrid environments — covering personal devices, cloud services, remote access, and access management during vacations and employee exits.
Sixth, implement automated anomaly detection gradually, validating systems against false positives rather than attempting to block all suspicious activity at once.
Finally, do not exclude employees from the security model. They must be both monitored and supported — because in a hybrid environment, ordinary user behavior increasingly becomes the primary entry point into corporate systems.
The most dangerous scenario for any organization is not a one-time breach, but a situation in which an intruder has already gained access — and remains undetected for months. At that point, the question is not only about security, but about managerial honesty: whether the business is willing to acknowledge that its most critical vulnerabilities often lie not outside, but within — in informal access, implicit trust, and processes that have not been revisited for years.
BI for KPI Monitoring: How to Manage Performance Every Day
Managing KPIs throughout the month takes more than frequent reporting. It requires consistent data, agreed calculation rules and a system that highlights performance gaps while managers can still act. Freedom Bank Kazakhstan built this model step by step, moving from Excel reports to a DWH and the daily use of BI.
How to Build a Mature Anti-Fraud Function
Fraud schemes often evolve faster than internal controls. A mature anti-fraud function does more than investigate losses. It identifies weaknesses early, informs product design, connects signals across accounts and measures whether controls are reducing risk without creating unnecessary friction.