
When we think about cybersecurity in our companies, we mainly think about protecting physical infrastructure, user identities, and end devices. Here and there, training sessions are organized for employees to highlight potential threats and encourage them to follow best practices and strictly adhere to internal company policies. Meanwhile, more and more incidents are starting elsewhere—with accounts that never belonged to any human being.
Quiet accounts with huge gainsequations
Service accounts, application accounts, Active Directory scripts, and API integrations are what are known as non-human identities (NHI). In a typical organization, there are several times more of them than human accounts, and yet almost no one treats them as a priority. The reason is simple: these accounts have „just been working” for years, no one remembers who created them, changing a password risks taking down a critical service, and it even happens that administrators don’t monitor what tasks these service accounts are performing. As a result, for years they retain unchanged passwords, excessive permissions, and zero visibility for security teams. In this area, the well-known adage „it works, so why change it” takes on even greater significance and… illustrates a lack of awareness of threats that may already be lurking around the corner.
The problem is exacerbated by the fact that it is virtually impossible to secure them with standard MFA—the organization’s cloud-based solution doesn’t work here, and there’s no one to confirm the notification on their phone, and password rotation via PAM is often postponed indefinitely out of fear of downtime. This creates a vulnerability: privileged accounts operate without any of the security measures applied to human users.
RReal-life examples, not theory
In the SolarWinds attack (2020), a compromised Orion service account—which had accumulated privileges over the years—allowed the attacker to move laterally across the infrastructure of an organization with nearly 18,000 employees, making the activity appear to be legitimate administrative work. In the case of Uber (2022), the attacker found a PowerShell script on a shared resource containing hard-coded credentials for a privileged account and gained access to critical systems. Another example: a forgotten service account within Starwood’s infrastructure was exploited in one of the largest hotel data breaches. The common denominator: an account that no one remembered, with privileges that no one verified.
How to Effectively Secure Service Accounts
The first step is a comprehensive inventory—without knowing how many NHI accounts exist and what they’re linked to, it’s impossible to manage them. Modern identity protection platforms detect such accounts automatically, based on their repetitive behavior, without the need to manually tag each one.
The key change is the shift from static security (passwords, rotation) to real-time behavioral security. Silverfort—the solution in question—learns about a user’s daily account activity—which resources they access and where they log in from—and uses this information to create an automated access policy. This is therefore a practical solution to the concerns mentioned at the beginning of this text—enabling additional protection for old and neglected service accounts will not create additional problems but will help safeguard a significant portion of the infrastructure. In practice, it takes just a few hours for the Silverfort solution to „learn” the behavioral patterns of service accounts on its own and, based on the policies created, grant or block access. In this way, the system will detect any anomalies; for example, a login attempt from an unusual host will be blocked or flagged with an alert.
This approach, which integrates natively with Active Directory and the cloud, provides protection for accounts that were previously inaccessible to traditional MFA and PAM solutions—without the need for password rotation or the risk of downtime. The scale of the problem is so significant that it’s worth treating it as a priority before it becomes the entry point for another incident.
Schedule a Silverfort demo:
https://outlook.office.com/book/KonsultacjaSilverfort@ISCG.onmicrosoft.com/?ismsaljsauthenabled


