A forgotten service account lets an attacker into Abby Steel, showing why unmanaged privileged access is a business risk, not just an IT one.
An attacker finds a forgotten service account with admin rights at Abby Steel and moves quietly from web servers to the domain controller, with no MFA, session recording or SIEM alert to stop them. Following the breach and its fallout, you see why privileged access management is a continuous business process rather than a tool. Leadership concludes the problem was bigger than Ahmed: it was weak governance, and the fix is to discover, govern and automate.
A temporary admin account outlives its purpose and is forgotten. An attacker uses it to move from web servers to the domain controller, and no MFA, session recording or SIEM alert stops them.
The first 48 hours bring systems offline, projects paused and executives on hourly updates. PAM is presented as a business continuity decision, not a checkbox.
An analogy about a contractor who keeps collecting house keys shows how access piles up. The bank analogy then presents PAM as a layered, monitored process: discover, request, approve, monitor, review, revoke.
The Periodic Table of PAM Security groups risk factors, compliance standards, processes, tools and business constraints. Five very different threat actors all depend on the same weakness: uncontrolled access.
Controlled access is set against uncontrolled access, and the Equifax chain and the six-domino model show how small governance gaps turn into regulatory and financial damage.
Leadership finds manual processes, unknown access, delayed reviews and poor lifecycle management, and treats it as a business problem. Abby Steel invests in discovery, just-in-time access, session recording, lifecycle automation and governance.
The Periodic Table returns as a readable map of 112 elements. It introduces the people who build, sell, support and lead PAM, and hands over to Layla's strategy work in Module 2.