← Back to PAM Best Practice main site
PAM Academy › Module 1 — PAM Foundations

Module 1: PAM Foundations

A forgotten service account lets an attacker into Abby Steel, showing why unmanaged privileged access is a business risk, not just an IT one.

Story: “It Started on a Monday”
~30 minutes
Lead: Ahmed, Senior Infrastructure Engineer
Privileged AccessThreat ActorsBusiness RiskGovernancePeriodic Table of PAM
Included
Part of the PAM Best Practice Academy curriculum
Start Module 1 →
  • 7-part narrated slide module
  • Follows Ahmed at Abby Steel
  • Practical, vendor-neutral PAM guidance
  • Key facts and real-world examples
  • 10-question knowledge check
Overview
Curriculum
Instructors
1
Module Number
7
Story Parts
30
Minutes
10
Quiz Questions
The question this module answers
Why does privileged access matter?

An attacker finds a forgotten service account with admin rights at Abby Steel and moves quietly from web servers to the domain controller, with no MFA, session recording or SIEM alert to stop them. Following the breach and its fallout, you see why privileged access management is a continuous business process rather than a tool. Leadership concludes the problem was bigger than Ahmed: it was weak governance, and the fix is to discover, govern and automate.

What you will learn
▶
Explain how one forgotten privileged account can give an attacker access across an entire environment
▶
Describe the business impact of a privileged access breach, from incident response to regulatory, financial and reputational damage
▶
Outline privileged access management as a continuous cycle: discover, request, approve, monitor, review and revoke
▶
Recognise the five threat actors and why every one of them depends on uncontrolled access
▶
Use the Periodic Table of PAM Security to map processes, compliance standards, tools, business constraints and threats
Module curriculum
1
Part 1: How the Breach Unfolded
Narrated slides
2
Part 2: From Technical Problem to Business Catastrophe
Narrated slides
3
Part 3: One Key, Unlimited Access and Thinking Like a Bank
Narrated slides
4
Part 4: Your Map of Control and the Five Threat Actors
Narrated slides
5
Part 5: Before and After, and the Real-World Cost
Narrated slides
6
Part 6: The Problem Was Bigger Than Ahmed
Narrated slides
7
Part 7: Reading the Map
Narrated slides
8
Knowledge Check10 questions · pass mark 8/10
Quiz
Part 1: How the Breach Unfolded

A temporary admin account outlives its purpose and is forgotten. An attacker uses it to move from web servers to the domain controller, and no MFA, session recording or SIEM alert stops them.

Part 2: From Technical Problem to Business Catastrophe

The first 48 hours bring systems offline, projects paused and executives on hourly updates. PAM is presented as a business continuity decision, not a checkbox.

Part 3: One Key, Unlimited Access and Thinking Like a Bank

An analogy about a contractor who keeps collecting house keys shows how access piles up. The bank analogy then presents PAM as a layered, monitored process: discover, request, approve, monitor, review, revoke.

Part 4: Your Map of Control and the Five Threat Actors

The Periodic Table of PAM Security groups risk factors, compliance standards, processes, tools and business constraints. Five very different threat actors all depend on the same weakness: uncontrolled access.

Part 5: Before and After, and the Real-World Cost

Controlled access is set against uncontrolled access, and the Equifax chain and the six-domino model show how small governance gaps turn into regulatory and financial damage.

Part 6: The Problem Was Bigger Than Ahmed

Leadership finds manual processes, unknown access, delayed reviews and poor lifecycle management, and treats it as a business problem. Abby Steel invests in discovery, just-in-time access, session recording, lifecycle automation and governance.

Part 7: Reading the Map

The Periodic Table returns as a readable map of 112 elements. It introduces the people who build, sell, support and lead PAM, and hands over to Layla's strategy work in Module 2.

Key facts
  • Equifax (2017): a breach exposed 147 million records; attackers escalated privileges and moved laterally through the network for 76 days.
  • Equifax's breach led to a US$575 million settlement; the CEO resigned and the share price fell by around 35%.
  • British Airways faced a proposed £183 million GDPR fine for a single data breach (the final penalty was £20 million).
  • Meta: a US$5 billion privacy settlement, described as the largest in history.
  • The six-domino chain: weak password policy, shared or stale credentials, uncontrolled access, security incident, regulatory investigation, and financial and reputational damage.
  • The Periodic Table of PAM Security maps 112 elements across processes, compliance standards, tools, business constraints, threat actors and success enablers.
Knowledge Check
Q1: How did the attacker first gain privileged access at Abby Steel?
A zero-day exploit in the firewall
A forgotten service account that still held admin rights
A phishing email sent to the board
A misconfigured public cloud storage bucket
Q2: Why could the attacker move through Abby Steel's network without being stopped or noticed?
The attacker used encrypted malware that no antivirus could detect
The network had no firewall
There was no MFA, no session recording and no SIEM alert on the privileged account
The security team switched off monitoring during the migration
Q3: According to the module, where does privileged access management start?
With discovery: find every account and own every lifecycle
With buying a password vault
With annual penetration testing
With disciplining the people involved in past incidents
Q4: What is the main point of the 'Think like a bank' analogy?
PAM should be installed once and left to run
PAM is a layered, continuously monitored business process, not a tool you install and forget
Only financial institutions need privileged access controls
A single strong lock is enough to protect the most valuable systems
Q5: Which sequence matches the continuous PAM cycle described in the module?
Monitor, approve, discover, revoke, request, review
Request, discover, revoke, approve, review, monitor
Approve, request, monitor, discover, revoke, review
Discover, request, approve, monitor, review, revoke
Q6: What do all five threat actors (insiders, hacktivists, nation-states, organised crime and configuration errors) have in common?
They all rely on zero-day exploits
They are all motivated by money
They all depend on the same weakness: uncontrolled access to the organisation's most valuable assets
They can all be stopped by a perimeter firewall
Q7: What is the 'real lesson' of the Equifax case study?
The breach was caused entirely by a single employee's mistake
The unpatched vulnerability was only the door; the damage came from missing least privilege, just-in-time access, session recording and connected monitoring
Credit agencies are more likely to be targeted than other businesses
Settlements are usually lower than the cost of prevention
Q8: In the six-domino model of weak governance, where is prevention most effective?
At the first domino: strong password policies, no shared accounts and continuous access review
At the fourth domino, once the incident has been detected
At the fifth domino, by preparing for regulatory investigations
At the sixth domino, through cyber insurance
Q9: Abby Steel had firewalls, a SOC and monitoring. What does the module say it was missing?
A larger security budget
More advanced antivirus software
A process that asked whether each account should still exist
An external auditor
Q10: After the incident, what did Abby Steel's leadership conclude?
Ahmed was responsible and should be replaced
The breach was bad luck and unlikely to happen again
A new firewall would stop it happening again
The problem was bigger than one person: weak governance made it a business problem, not just a technical one
Requirements
No prior PAM knowledge needed — this is where the course starts
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral
Your instructors
NK
Nabeel Khaliq
IAM & Privileged Access Management SME · Founder, PAM Best Practice Ltd
Practitioner with deep hands-on experience implementing PAM across enterprise environments. Founder of PAM Best Practice Academy, a UK-registered education and community hub for PAM professionals. Arsenal and Middlesbrough fan.
AR
Adrian Russo
IAM & Privileged Access Management Architect
Senior PAM architect with extensive experience designing and deploying large-scale CyberArk and BeyondTrust implementations across enterprise environments globally. Keen cyclist.
ID
Iftikar Din
Manufacturing-focused Cyber Security Engineer
Cyber security engineer specialising in industrial and manufacturing environments. Brings real-world operational technology (OT) security perspective to PAM implementation. Middlesbrough fan who loves gardening.
Your progress
Module 1 — PAM Foundations
Not started0%
Module breakdown
Part 1: How the Breach UnfoldedSlides
Part 2: From Technical Problem to Business CatastropheSlides
Part 3: One Key, Unlimited Access and Thinking Like a BankSlides
Part 4: Your Map of Control and the Five Threat ActorsSlides
Part 5: Before and After, and the Real-World CostSlides
Part 6: The Problem Was Bigger Than AhmedSlides
Part 7: Reading the MapSlides
Knowledge Check10 questions
Up next
Module 2 — PAM Strategy & Operating Model
In Module 2, Layla, Abby Steel's PAM Programme Lead, turns leadership's decision into a PAM strategy and operating model.
PAM Community
Join our network of PAM practitioners, mentors and industry partners across the UK.