BLOG

Why Your Identity Governance Gap Is Your Biggest Penetration Testing Blind Spot (And How to Fix It)

79% of SA organisations can't see who has access to what. Learn how identity governance failures create pen testing blind spots and how to close them.

South Africa holds an unenviable record: the highest cyberattack rate on the planet at 36%, according to recent Zoho research. While that statistic generates alarm, the more telling number sits underneath it. Seventy-nine percent of South African organisations cannot tell you, with confidence, who has access to what across their environments. These two numbers are not coincidental. The access visibility gap is not a side problem or an administrative inconvenience; it is the exact condition that makes successful attacks possible in the first place.

Most security conversations quickly land on tooling, next-gen firewalls, endpoint protection, email gateways. These matter. But an attacker who gains access through a stale contractor credential, an over-privileged service account, or a dormant admin login does not trigger most of those controls. They walk in through the front door with a valid key. And in most organisations, nobody knows that key still exists.

The Identity Visibility Problem That Pen Tests Keep Exposing

Penetration testing results in South Africa tell a consistent story. Across internal penetration testing engagements, the most frequently exploited weaknesses are not exotic zero-days or sophisticated malware chains. They are accounts that should not exist, permissions that should not remain, and access paths that nobody reviewed after the original project ended.

Privilege creep is the slow accumulation of access rights that outpaces any formal review process. An employee joins a project, gets access to a sensitive database, finishes the project, and moves to another team. The access stays. A contractor completes an infrastructure migration, their VPN credentials expire, but their Active Directory account remains active. A developer gets production access to debug an urgent issue and the access is never revoked. Each of these is a low-cost entry point for an attacker who has already gained a foothold elsewhere in your environment.

The problem compounds when you factor in service accounts. Many organisations run dozens of service accounts, often with domain admin or elevated privileges, tied to applications that were replaced years ago. These accounts rarely rotate passwords, rarely appear in user behaviour monitoring, and are almost never flagged during routine IT reviews. From a penetration testing perspective, they are among the highest-value targets in any environment.

Third-party access adds another layer. External vendors, managed service providers, and integration partners often hold persistent access to internal systems, sometimes through shared credentials rather than individual accounts. Few organisations have a formal offboarding process for third-party identities. Fewer still validate that the access actually matches the current service scope. This is a critical element of third-party risk management that most VAPT scopes do not address directly.

How Attackers Move Through Identity Blind Spots

Understanding what attackers actually do with orphaned identities and over-privileged accounts matters more than cataloguing the accounts themselves. An attacker who compromises a standard user account through a phishing email is not immediately dangerous. What makes that compromise catastrophic is the pivot path available from that account.

In Active Directory environments, the most common escalation technique is credential-based lateral movement. Kerberoasting targets service accounts with weak passwords by requesting Kerberos service tickets and cracking them offline. AS-REP Roasting exploits accounts that do not require Kerberos pre-authentication. Pass-the-hash and pass-the-ticket attacks use harvested credential material to authenticate as other users without knowing their plaintext passwords. Every one of these techniques depends entirely on the existence of accounts with weak configurations and excessive permissions.

The attack chain usually follows a predictable sequence: initial access via a low-privileged account, reconnaissance to map trust relationships and group memberships, credential harvesting, and escalation to domain admin. The entire chain can complete in hours when an environment has never been tested for identity-based attack paths. What makes it faster is privilege creep; when users accumulate access across multiple systems over time, their compromised accounts offer lateral movement options that a freshly provisioned account would not.

Organisations that have gone through a comprehensive vulnerability assessment and penetration testing exercise often describe the results as surprising. The firewall rules are clean. The patching is current. The real findings are all in identity: an account from 2019 with domain admin rights belonging to someone who left the company, a shared service account password that has not changed since the system was configured, a developer group with write access to a production financial database. None of these appear in a vulnerability scan. They only surface when a skilled tester actively tries to use them.

What Identity-Focused VAPT Must Actually Validate

Standard pen tests cover network infrastructure, external attack surfaces, web applications, and increasingly cloud environments. But identity validation requires a deliberate scope extension that many VAPT programmes still omit. Here is what that scope must include.

Active Directory enumeration is a starting point, not an advanced technique. A properly scoped internal penetration testing engagement should enumerate all accounts, identify stale and orphaned accounts (those with no recent login activity), document accounts with elevated privileges, and map group membership against actual job function. Any account with domain admin, enterprise admin, or schema admin rights that cannot be justified by a current role should be flagged as a critical finding.

Service account assessment goes further. Every service account should have a documented owner, a known password rotation schedule, and the minimum privileges needed for its function. Accounts running legacy services that are no longer active should be disabled. Password quality for service accounts matters too: Kerberoasting only works because many service accounts were created with weak passwords and have never been required to change them.

Privilege access management validation must verify that privileged sessions are controlled, that access elevation requires justification and approval, and that privileged account activity is logged and reviewed. Pen testers should verify whether those controls can be bypassed, whether logging captures privileged activity in a way that would actually alert a SOC analyst, and whether the logs are protected from tampering by an attacker who has already escalated privileges.

"Every identity-focused assessment we run surfaces the same category of finding: accounts that exist without a current business justification," said [Team Member Name], [Role at Magix]. "The technical controls are often sound. The access governance is where the exposure lives, and it almost always connects directly to the paths that would give an attacker the highest-impact reach into the environment."

External testing must validate what is visible to an unauthenticated attacker before any credential compromise occurs. This includes exposed authentication portals, legacy remote access solutions (RDP, telnet, outdated VPN clients), and APIs that return user enumeration data. An external penetration testing engagement that maps authentication exposure is the first half of the picture; internal testing that validates what a compromised identity can access is the second.

Third-Party Risk and Identity: Where the Gap Gets Wider

Third-party access is one of the least examined dimensions of identity governance, and one of the most exploited. The 2020 SolarWinds compromise demonstrated at a global scale what happens when a trusted vendor's credentials become the attacker's entry point. South African organisations face the same risk at a local level, and third-party risk is now systemic rather than isolated.

Most vendor access arrangements start with a legitimate need: a contractor needs access to the billing system during an ERP migration, or an MSP requires domain-level access to manage endpoint patching. The access is provisioned under time pressure with minimal documentation. The project ends, but the access does not. Multiply this pattern across ten, twenty, or fifty vendors over several years, and the exposure becomes substantial.

Penetration testing must include an assessment of third-party access paths as a distinct scope item. This means reviewing VPN credentials assigned to external parties, assessing whether vendor accounts have individual identities or share credentials, validating that access is scoped to what the current contract requires, and testing whether vendor accounts have been used recently. Accounts with no recent activity but persistent access are prime candidates for an attacker who has compromised the vendor's own environment.

POPIA compliance obligations make this governance gap a regulatory concern, not just a technical one. Section 19 requires operators to take appropriate measures to protect personal information, which includes validating that external parties with access to personal data have appropriate controls in place. An uncontrolled third-party account with access to a customer database is a POPIA breach waiting to happen, and the accountability sits with the responsible party, not the vendor.

Building Zero Trust Validation Into Your Pen Testing Programme

Zero Trust is a frequently cited architecture principle: trust no user, device, or connection by default, and verify every access request explicitly. The challenge is that most organisations have implemented some Zero Trust controls, whether multi-factor authentication, conditional access policies, or microsegmentation, without ever validating whether those controls actually hold under adversarial conditions.

Pen testing is the correct mechanism for Zero Trust validation. A structured approach should cover four areas. First, authentication control testing: can MFA be bypassed through adversary-in-the-middle techniques, session token hijacking, or MFA fatigue attacks? Second, conditional access validation: do access policies correctly deny access from unmanaged devices, unexpected geographies, or anomalous login times? Third, microsegmentation testing: does lateral movement between network segments require a new authentication event, or can an attacker move freely once inside the network perimeter? Fourth, least-privilege validation: does every account have access limited to what its current function requires?

Ongoing vulnerability management provides the continuous monitoring layer that sits around point-in-time testing. Identity configurations drift. A pen test validates the state of your controls at a specific moment; a vulnerability management programme tracks changes that introduce new exposure between tests. These two functions are not alternatives; they are complementary. The pen test proves the controls work. The vulnerability management programme ensures they remain working.

For POPIA compliance, PCI DSS compliance, and the growing expectations of the cyber insurance market in South Africa, the ability to demonstrate identity control validation is increasingly non-negotiable. Insurers are asking detailed questions about access governance during underwriting. Regulators are examining whether Section 19 obligations have been tested rather than assumed. A structured VAPT programme that explicitly includes identity scope gives you the evidence to answer both.

The Framework: What an Identity-Focused VAPT Covers

A practical identity-focused VAPT programme covers five areas, sequenced to build from discovery through validation.

The starting point is access inventory. Before testing, document all account types: human users, service accounts, application accounts, external/vendor accounts, and privileged accounts. Most organisations discover accounts at this stage that IT had no record of. That discovery alone is a significant finding.

The second area is stale and orphaned account analysis. Any account inactive for more than 30 days without a documented business justification should be disabled pending review. Accounts belonging to former employees or contractors should be disabled within hours of offboarding, not days or weeks. A pen test should validate the actual state, not the policy intent.

Third is privilege escalation path mapping. Using Active Directory attack simulation techniques (without causing disruption), testers map every path from a standard user account to domain admin, identifying which path requires the fewest steps and the lowest level of technical sophistication. This gives prioritised remediation guidance rather than a generic list of findings.

Fourth is third-party access validation, as described above: scoped review of all external access arrangements, credential quality assessment, and session logging verification.

Fifth is control validation against real attack techniques. This is where the zero trust validation work sits: MFA bypass attempts, conditional access evasion, session hijacking, and segmentation breakout testing. The output is a penetration test report that maps identity control failures to specific attack paths, with remediation steps ordered by exploitability rather than by technical severity alone.

Start With What You Can Actually See

South Africa's attack rate is not going to fall because organisations improve their firewall policies. The 36% figure reflects a targeting environment where attackers have learned that identity governance gaps are reliable, scalable, and difficult for defenders to close once access proliferation has been allowed to accumulate over years.

Closing the gap starts with an honest assessment of your current identity posture. If you cannot tell a pen tester which accounts have domain admin rights, when they were last reviewed, and who owns them, that is your answer. The organisations that come through penetration testing engagements with the cleanest identity findings are the ones that treat access governance as a continuous operational discipline, not a compliance checkbox that gets attention before an audit.

If your current penetration testing programme does not explicitly include identity scope, stale account analysis, privilege escalation simulation, and third-party access validation, it is missing the category of finding that attackers most consistently exploit. Get in touch with the Magix team to discuss a penetration testing engagement scoped to expose and close your identity governance blind spots before an attacker finds them first.

Related Articles

Top 5 Quick-Win Pentesting Priorities for SA SMEs Facing Skills Shortages and Budget Constraints

Limited budget and no dedicated security staff? These 5 penetration testing priorities give SA SMEs the highest-impact assessments to run first. POPIA-m...
Read More

Cookie Theft & Session Hijacking: The Post-MFA Attack Surface Your Enterprise Is Ignoring

MFA doesn't protect session tokens. Learn what web application penetration testing must cover to catch cookie theft and session hijacking in South Africa.
Read More

Why Your Identity Governance Gap Is Your Biggest Penetration Testing Blind Spot (And How to Fix It)

79% of SA organisations can't see who has access to what. Learn how identity governance failures create pen testing blind spots and how to close them.
Read More