The Next Major Breach May Not Exploit Your Firewall. It May Exploit Your Approval Process.

The Next Major Breach May Not Exploit Your Firewall. It May Exploit Your Approval Process.

Modern attackers increasingly benefit from weak access reviews, delayed escalation and fragmented ownership long before they need to defeat a technical control.

Cybersecurity teams spend enormous effort strengthening the technical perimeter.

Firewalls are hardened. Endpoints are monitored. Vulnerabilities are scanned. Multi-factor authentication is deployed. Security Operations Centres watch thousands of alerts every day.

All of this matters.

But there is another part of the attack surface that receives far less attention: the business processes sitting behind those controls.

An attacker does not always need to break through sophisticated security technology. Sometimes they simply need an account with permissions that should have been removed, an approval that nobody properly reviewed, or an incident that sits too long between two teams because nobody clearly owns the next action.

In those situations, the weakness is not the firewall. It is the workflow.

 

Attackers Don't Care About Your Organizational Chart

Consider what happens when suspicious activity is detected on an employee account.

The identity platform generates an alert. Security investigates. The application belongs to another team. Disabling access requires approval. The employee's manager needs to confirm something. IT Operations owns another part of the response.

Suddenly, a security event becomes an organizational coordination problem.

Every handoff consumes time. And attackers benefit from time.

This is why CISOs need to look beyond whether controls exist and examine how quickly those controls can actually produce action.

A technically sophisticated security environment can still respond slowly when ownership is fragmented.

 

Credentials Make Process Weaknesses More Dangerous

The threat is not theoretical.

Verizon's 2025 Data Breach Investigations Report analysed more than 12,000 confirmed breaches and found that credential abuse accounted for 22% of known initial access vectors.

Once valid credentials are compromised, the question becomes: what can that identity reach?

That is where process design becomes critical.

Imagine an employee who moved from Finance to Operations six months ago. New permissions were approved immediately, but nobody removed the old ones.

An attacker compromising that identity does not need to exploit a vulnerability to gain Finance access. The organization already provided the path.

This is why NIST's least-privilege guidance explicitly calls for organizations to regularly review privileges and remove or reassign access that is no longer necessary.

 

An Approval Is Only a Control If Someone Is Actually Making a Decision

There is another uncomfortable problem.

Enterprises sometimes confuse the existence of an approval with the existence of effective governance.

Consider a privileged-access request requiring three approvals. That sounds secure.

But what happens if the first approver does not understand the requested permission? The second assumes the first has checked it. The third has dozens of requests waiting and approves based largely on precedent.

Three approvals occurred. Very little risk evaluation did.

The question for a Risk or Compliance Head therefore should not simply be: "Was this request approved?" It should be: "Did the approval process meaningfully determine whether this access was appropriate?"

Adding more approval stages does not automatically create stronger security. Sometimes it creates slower security.

 

Delayed Escalation Is a Security Exposure

The same principle applies to incident response.

Imagine a security tool detects suspicious activity at 10:00 AM. Security reviews it at 10:15. At 10:30, another team is asked to validate the affected system. At 11:20, the request is escalated. At noon, someone identifies the system owner. At 12:30, approval is finally received to restrict access.

The security technology may have detected the threat almost immediately. The enterprise took hours to act. That gap between detection and coordinated action deserves far more attention.

The next stage of security maturity is therefore not simply better detection. It is connecting detection, ownership, decision-making, escalation and remediation into a reliable workflow.

 

Former Accounts Show How Dangerous the Gap Can Become

One real-world example makes the point particularly well.

A joint CISA advisory documented a threat actor gaining initial access to an organization using a former employee's compromised account. The guidance that followed specifically recommended prompt removal of unnecessary accounts, continuous user-management processes, least privilege, and just-in-time access for administrators.

The lesson is straightforward.

Offboarding is not merely an HR process. Account removal is not merely an IT task. Both are cybersecurity controls.

The same is true of access reviews, contractor management, privileged-access approvals, change authorization and incident escalation.

When these workflows fail, security weakens.

 

What CISOs Should Look For

Instead of reviewing only technical-control performance, security leaders should start examining the processes connecting those controls.

  • How quickly is access removed after an employee leaves?
  • Who owns a suspicious identity from detection through containment?
  • How many privileged-access requests are automatically renewed?
  • Where do security incidents wait for another team's approval?
  • How many critical processes depend on email or manual escalation?

Can Security, IT Operations, Identity, Risk and application teams see the same case and its current status?

These questions reveal something vulnerability scans cannot: whether the organization can translate security information into coordinated action.

 

In Conclusion

Firewalls still matter.

MFA matters.

Endpoint security matters.

Vulnerability management matters.

CISA continues to recommend phishing-resistant MFA, role-based access controls, periodic account reviews and least privilege as important protections against unauthorized access.

But technology alone cannot compensate for weak operational processes. A security control is only as effective as the workflow surrounding it.

If ownership is unclear, approvals become routine, access survives longer than its business purpose, and escalation depends on people manually chasing one another, attackers inherit opportunities that no security product was designed to solve.

The next major security question for enterprises may therefore be surprisingly simple:

Where does our security process become slower than the attacker?

That is where the next control improvement may need to begin.

 

FAQs

1. How can an approval process become a cybersecurity risk?

An approval process becomes risky when requests are approved without enough context, ownership is unclear, or access remains active longer than necessary. The approval may technically satisfy policy while still allowing excessive or outdated permissions to remain in the environment.

2. Why are compromised credentials dangerous even with strong security tools?

Valid credentials can allow attackers to operate as legitimate users. The potential damage then depends heavily on what permissions that identity holds. Excessive privileges, outdated access and weak access reviews can significantly increase the impact of a compromised account.

3. Can adding more approval stages make security stronger?

Not necessarily. More approvals can create delays without improving decision quality. A stronger process gives approvers the right context, clearly identifies who owns the decision, applies risk-based rules, and automatically escalates unusual or high-risk requests.

4. What should CISOs measure beyond security alerts?

CISOs should also monitor operational metrics such as time from detection to containment, access-revocation time, privileged-access duration, unresolved access-review findings, escalation delays and the number of security processes dependent on manual handoffs. These reveal whether the organization can actually act on the threats its tools identify.

5. How can organizations reduce security risk within business workflows?

Start by connecting identity, security, IT operations and business processes. Apply least privilege, automate joiner-mover-leaver workflows, use time-bound privileged access where appropriate, establish clear ownership, and create defined escalation paths for high-risk events.

6. Does this mean technical cybersecurity controls are becoming less important?

No. Firewalls, MFA, endpoint protection, vulnerability management and other technical controls remain essential. The point is that technical controls and operational workflows must work together. Detecting a threat quickly provides limited protection if organizational processes delay the response.