Layla turns the breach into a PAM programme of strategy, ownership, lifecycle processes, enforced controls and a maturity path.
The Monday after the incident, Layla inherits a crisis and a board mandate. Her first finding is that nobody owned privileged access: Ahmed didn't fail, the organisation did. She builds a strategy, an operating model, joiner-mover-leaver processes and five mandatory controls, then measures Abby Steel's climb from chaos to control.
Layla reconstructs the breach and Priya's findings: 47 orphaned accounts and 89 over-privileged users. The root cause is that everyone touched PAM and no one owned it, so what's needed is a programme, not a tool.
Strategy comes before tools. Abby Steel's five pillars (Visibility, Control, Governance, Automation, Audit) are tied to business risk and compliance, given clear ownership and success metrics, and shaped with stakeholders before board approval.
IT is the hands, security the eyes and the business the judgement. The business owner approves, security reviews and IT provisions, through a documented request process and a same-day leaver process, rolled out with proper change management.
The joiner-mover-leaver lifecycle is completed with the often-forgotten mover step. It is wired to HR for automation and matured in stages, on the principle that access is based on role, not seniority.
Five mandatory controls enforce the strategy: least privilege, RBAC, segregation of duties, just-in-time access and MFA. They extend to machine identities, third parties and break-glass accounts, and the section ends by showing strategy, operating model, processes and controls as one system.
Abby Steel was not unusual. Industry evidence, three converging pressures (identity-based attacks, cyber insurers and regulators) and the cost of inaction show that doing nothing is the most expensive option.
A five-stage maturity model (Chaos, Visibility, Control, Automation, Governance) and a 12-month roadmap measure progress. Layla then hands the discovery mandate to Priya.