Kriss Stephen | Principal Solutions Architect

In our blog series exploring the Minimum Viable Company (MVC) strategy, we have followed Megakorp, a developer and manufacturer of enterprise-grade industrial automation components relied upon by manufacturers worldwide, as the organization navigated the realities of modern cyber resilience.

In Part 1 of our series (Why True Cyber Resilience Starts with Identity), the company recognized that identity was not simply another IT dependency, but the operational foundation of the business itself. Active Directory and Entra ID became central to Megakorp’s Minimum Viable Company strategy. These identity platforms provided the authentication, administrative control, and operational services required to restore critical business functions during a major cyber incident.

The second stage of that journey (Cyber Resilience Lessons from Beyond the Breach) expanded beyond recovery alone, exploring how cyber resilience required coordination across cloud identity, operational recovery, communications, and executive decision-making under pressure.

However, as Megakorp’s leadership reflected on the organization’s resilience strategy, a difficult question emerged: Why wait until a crisis to think about resilience at all?


Strengthening the MVC core: Principles for controlling security posture

The company had invested heavily in recovery planning and MVC capabilities, but uncertainty still existed across its identity platforms. Security teams struggled to fully understand exposure caused by misconfigurations, excessive privilege, and risky identity relationships spanning both Active Directory and Entra ID.

At the same time, administrators were making changes to critical identity infrastructure every day, often without centralized visibility into what had changed, who changed it, or the operational risk those changes introduced.

Megakorp realized that resilience could not begin at recovery.

It had to start much earlier, through stronger visibility, tighter control, and the operational resilience required to rapidly correct issues before they became business-disrupting events.

Following a strategic review of the organization’s identity security posture, the Megakorp board defined three core principles that would underpin the company’s identity resilience strategy across both Active Directory and Entra ID:

  • Visibility: The ability to continuously understand exposure, misconfiguration, identity risk, and operational change activity across the identity estate.
  • Control: The ability to introduce guardrails, alerting, and response mechanisms around critical identity changes and privileged operations.
  • Identity resilience: The ability to rapidly contain, reverse, and recover from unwanted or unauthorized identity changes before they escalated into wider operational disruption.

Due to Megakorp’s role as a manufacturer of critical components, these capabilities needed to extend beyond the traditional IT environment and into operational technology (OT) systems.

And because significant portions of the OT environment operated within isolated or non-internet-connected networks, the organization also required on-premises monitoring and protection capabilities capable of functioning within disconnected or restricted environments.


Visibility: Understand where security posture risk exists

Megakorp wanted to approach visibility through two distinct channels. The first phase focused on understanding what weaknesses already existed within the identity environment while ensuring the organization was continuously alerted when new weaknesses or exposures were introduced (Figure 1).

Figure 1. Security indicators help the organization understand vulnerabilities.

This included identifying misconfigurations, legacy settings, excessive privilege, and risky identity relationships that could allow an attacker to gain access to the environment or move laterally once inside. For Megakorp, this visibility was critical not only for reducing immediate exposure (Figure 2) but also for understanding how years of operational change had introduced hidden risk across both Active Directory and Entra ID.

Figure 2. Exposure detection and severity ratings help the security team prioritize mitigation activities.

The second visibility phase focused on gaining a deep operational understanding of change activity across the identity estate. Megakorp needed to know exactly who, or what, was making changes within the environment, when those changes occurred, and the potential operational or security impact they introduced. Without the level of visibility that Figure 3 shows, unauthorized modifications, configuration drift, or malicious activity could remain unnoticed until they resulted in service disruption or broader compromise.

Figure 3. Automated change monitoring enables teams to spot suspicious activity in real time.

To support these requirements, Megakorp expanded its identity resilience platform by deploying Semperis Directory Services Protector (DSP). This provided the organization with visibility across both connected and isolated networks, enabling security and operational teams to continuously monitor identity exposure, configuration changes, and privileged activity throughout the enterprise.

Additional misconfigurations and exposure paths identified across the identity estate were assessed and mapped against short-term, medium-term, and long-term remediation strategies. This allowed Megakorp to prioritize immediate risk reduction activities while also developing structured plans to address more complex legacy configurations and operational dependencies over time.

By taking a proactive approach to remediation, the organization could continuously strengthen the security of its environments before weaknesses could be identified and exploited by attackers.


Control: Staying ahead of identity-focused threats

The second pillar, control, became the natural progression from visibility. By understanding both the configurations that existed across the identity estate and who or what was responsible for making changes, Megakorp was able to introduce operational guardrails, detection logic, and automated response actions (like those that Figure 4 shows) designed to reduce identity risk before it could escalate.

Figure 4. Rules in DSP establish guardrails and trigger automated notifications and mitigation actions so that gaps can be closed quickly.

For example, Figure 5 shows a rule that defines a specific AD change that triggers a specific action. With this rule, if changes were accidentally made to Megakorp’s identity tiering organizational units by an over-permissioned administrator, Semperis DSP would automatically detect the modification, revert the unauthorized change, and alert the appropriate operational and security teams.

Figure 5. DSP enables teams to specifically define changes that trigger actions such as automated rollback.

The Megakorp team implemented additional controls to detect and respond to activities such as new user accounts created outside of the organization’s approved Identity Lifecycle Management (ILM) process. These controls ensured that all newly created identities remained governed, auditable, and aligned to Megakorp’s operational security standards.

Rather than relying solely on manual review or post-incident investigation, Megakorp shifted toward continuous identity control, allowing the organization to rapidly identify unauthorized activity, contain risky changes, and maintain operational stability across both Active Directory and Entra ID.


Operational resilience: Reduce the extent and impact of cyber incidents

With visibility across its identity platforms and operational guard rails providing stronger identity control, Megakorp naturally evolved into the third pillar: operational resilience.

The organization could now rapidly identify, contain, and reverse unwanted identity changes before they escalated into larger operational incidents.

For example, as Figure 6 shows, if an automated process or overzealous admin accidentally modified the SMTP proxy address attribute across several hundred user accounts, administrators could quickly identify the affected changes and revert them without searching through historical records or restoring previous backup sets.

Figure 6. DSP makes it easy to find and correct risky changes.

As Figure 7 shows, by leveraging Semperis’ transactional, timeline-based visibility into identity activity, both OT and IT teams gained the ability to rapidly understand what changed, who made the change, and how to safely undo it.

Figure 7. DSP’s saves teams time by enabling them to rapidly see and filter changes—and identify which to undo.

Adding these automated capabilities significantly reduced the operational impact and duration of administrative mistakes, configuration drift, or malicious identity changes across the enterprise.


Evolving to a more mature MVC model

By combining visibility, control, and operational resilience across its identity platforms with the recovery, backup, and enterprise resilience capabilities established earlier in its journey, Megakorp had fundamentally evolved its approach to cyber resilience.

The organization was no longer focused solely on recovering from a major incident after the damage had already occurred. Instead, it could continuously identify and reduce risk before disruption, enforce operational guard rails during day-to-day operations, and rapidly recover or reverse unwanted changes when incidents occurred.

Through this layered identity-first strategy, Megakorp positioned itself to operate resiliently before, during, and after a cyberattack.

For Megakorp, identity resilience was no longer a capability reserved for crisis recovery.
It had become a continuous operational discipline embedded across the enterprise.

Further Reading