In our blog series exploring the Minimum Viable Company (MVC) strategy, we have followed Megakorp, a developer and manufacturer of enterprise-grade industrial automation components relied upon by manufacturers worldwide, as the organization navigated the realities of modern cyber resilience.
In Part 1 of our series (Why True Cyber Resilience Starts with Identity), the company recognized that identity was not simply another IT dependency, but the operational foundation of the business itself. Active Directory and Entra ID became central to Megakorp’s Minimum Viable Company strategy. These identity platforms provided the authentication, administrative control, and operational services required to restore critical business functions during a major cyber incident.
The second stage of that journey (Cyber Resilience Lessons from Beyond the Breach) expanded beyond recovery alone, exploring how cyber resilience required coordination across cloud identity, operational recovery, communications, and executive decision-making under pressure.
However, as Megakorp’s leadership reflected on the organization’s resilience strategy, a difficult question emerged: Why wait until a crisis to think about resilience at all?
Strengthening the MVC core: Principles for controlling security posture
The company had invested heavily in recovery planning and MVC capabilities, but uncertainty still existed across its identity platforms. Security teams struggled to fully understand exposure caused by misconfigurations, excessive privilege, and risky identity relationships spanning both Active Directory and Entra ID.
At the same time, administrators were making changes to critical identity infrastructure every day, often without centralized visibility into what had changed, who changed it, or the operational risk those changes introduced.
Megakorp realized that resilience could not begin at recovery.
It had to start much earlier, through stronger visibility, tighter control, and the operational resilience required to rapidly correct issues before they became business-disrupting events.
Following a strategic review of the organization’s identity security posture, the Megakorp board defined three core principles that would underpin the company’s identity resilience strategy across both Active Directory and Entra ID:
- Visibility: The ability to continuously understand exposure, misconfiguration, identity risk, and operational change activity across the identity estate.
- Control: The ability to introduce guardrails, alerting, and response mechanisms around critical identity changes and privileged operations.
- Identity resilience: The ability to rapidly contain, reverse, and recover from unwanted or unauthorized identity changes before they escalated into wider operational disruption.
Due to Megakorp’s role as a manufacturer of critical components, these capabilities needed to extend beyond the traditional IT environment and into operational technology (OT) systems.
And because significant portions of the OT environment operated within isolated or non-internet-connected networks, the organization also required on-premises monitoring and protection capabilities capable of functioning within disconnected or restricted environments.
Visibility: Understand where security posture risk exists
Megakorp wanted to approach visibility through two distinct channels. The first phase focused on understanding what weaknesses already existed within the identity environment while ensuring the organization was continuously alerted when new weaknesses or exposures were introduced (Figure 1).

This included identifying misconfigurations, legacy settings, excessive privilege, and risky identity relationships that could allow an attacker to gain access to the environment or move laterally once inside. For Megakorp, this visibility was critical not only for reducing immediate exposure (Figure 2) but also for understanding how years of operational change had introduced hidden risk across both Active Directory and Entra ID.

The second visibility phase focused on gaining a deep operational understanding of change activity across the identity estate. Megakorp needed to know exactly who, or what, was making changes within the environment, when those changes occurred, and the potential operational or security impact they introduced. Without the level of visibility that Figure 3 shows, unauthorized modifications, configuration drift, or malicious activity could remain unnoticed until they resulted in service disruption or broader compromise.

To support these requirements, Megakorp expanded its identity resilience platform by deploying Semperis Directory Services Protector (DSP). This provided the organization with visibility across both connected and isolated networks, enabling security and operational teams to continuously monitor identity exposure, configuration changes, and privileged activity throughout the enterprise.
Additional misconfigurations and exposure paths identified across the identity estate were assessed and mapped against short-term, medium-term, and long-term remediation strategies. This allowed Megakorp to prioritize immediate risk reduction activities while also developing structured plans to address more complex legacy configurations and operational dependencies over time.
By taking a proactive approach to remediation, the organization could continuously strengthen the security of its environments before weaknesses could be identified and exploited by attackers.
Control: Staying ahead of identity-focused threats
The second pillar, control, became the natural progression from visibility. By understanding both the configurations that existed across the identity estate and who or what was responsible for making changes, Megakorp was able to introduce operational guardrails, detection logic, and automated response actions (like those that Figure 4 shows) designed to reduce identity risk before it could escalate.

For example, Figure 5 shows a rule that defines a specific AD change that triggers a specific action. With this rule, if changes were accidentally made to Megakorp’s identity tiering organizational units by an over-permissioned administrator, Semperis DSP would automatically detect the modification, revert the unauthorized change, and alert the appropriate operational and security teams.

The Megakorp team implemented additional controls to detect and respond to activities such as new user accounts created outside of the organization’s approved Identity Lifecycle Management (ILM) process. These controls ensured that all newly created identities remained governed, auditable, and aligned to Megakorp’s operational security standards.
Rather than relying solely on manual review or post-incident investigation, Megakorp shifted toward continuous identity control, allowing the organization to rapidly identify unauthorized activity, contain risky changes, and maintain operational stability across both Active Directory and Entra ID.
Operational resilience: Reduce the extent and impact of cyber incidents
With visibility across its identity platforms and operational guard rails providing stronger identity control, Megakorp naturally evolved into the third pillar: operational resilience.
The organization could now rapidly identify, contain, and reverse unwanted identity changes before they escalated into larger operational incidents.
For example, as Figure 6 shows, if an automated process or overzealous admin accidentally modified the SMTP proxy address attribute across several hundred user accounts, administrators could quickly identify the affected changes and revert them without searching through historical records or restoring previous backup sets.

As Figure 7 shows, by leveraging Semperis’ transactional, timeline-based visibility into identity activity, both OT and IT teams gained the ability to rapidly understand what changed, who made the change, and how to safely undo it.

Adding these automated capabilities significantly reduced the operational impact and duration of administrative mistakes, configuration drift, or malicious identity changes across the enterprise.
Evolving to a more mature MVC model
By combining visibility, control, and operational resilience across its identity platforms with the recovery, backup, and enterprise resilience capabilities established earlier in its journey, Megakorp had fundamentally evolved its approach to cyber resilience.
The organization was no longer focused solely on recovering from a major incident after the damage had already occurred. Instead, it could continuously identify and reduce risk before disruption, enforce operational guard rails during day-to-day operations, and rapidly recover or reverse unwanted changes when incidents occurred.
Through this layered identity-first strategy, Megakorp positioned itself to operate resiliently before, during, and after a cyberattack.
For Megakorp, identity resilience was no longer a capability reserved for crisis recovery.
It had become a continuous operational discipline embedded across the enterprise.
Further Reading
- Minimum Viable Company Part 1: True Cyber Resilience Starts with Identity
- Minimum Viable Company Part 2: Cyber Resilience Beyond the Breach
- Achieving Operational Resilience with Simon Hodgkinson – Semperis
- Understanding Your Identity Security Posture | Hybrid Identity Protection
- What Is Identity Attack Surface Management? | Semperis Guides
- Identity Security Reduces Risk, Solidifies Resilience for MAIRE
- Operational Resilience: More than Disaster Recovery – Semperis
