A "clear transformation delay" must be addressed, according to Thibaud Binétruy, president of InterCert France, an organization that unites more than 130 incident response centers. After a summer described by Anssi, France’s national cybersecurity agency, as "horrible," cybersecurity professionals are being challenged to revise their practices in light of the evolving threat landscape. Attackers, who were initially motivated by recognition, have developed well-known tactics, particularly in data theft, which often relies on compromised accounts through infostealers—malicious programs that extract victims’ identification data. This method was used in the case of the DGFiP breaches, as noted in a recent Senate report. These hackers have also identified a blind spot in corporate cybersecurity: the malicious exploitation of satellite applications integrated into information systems. While defenders may have access to solutions that detect compromised identifiers in infostealer logs, security teams face the challenge of accurately identifying critical accesses. "Often, when someone has been infected in a personal environment, we will also find private accesses," such as a Netflix account, explains Binétruy. Analysts must then sift through these logs to determine which access points could be critical. However, security teams may not have a complete understanding of the third-party applications used within an organization. These applications may not have been declared or documented, creating a knowledge gap that attackers exploit by anticipating a lack of account resets by defenders. "This means we need to treat all these stolen account logs a bit differently," Binétruy notes, emphasizing the need for broader monitoring beyond just closing sensitive accesses like a virtual private network (VPN). To better monitor these satellite applications, security teams must first understand them. This knowledge will help determine whether a user’s behavior is legitimate or suspicious. Additionally, organizations must be able to process the alerts generated by these monitoring efforts. "It is not just about deploying a solution and collecting logs," Binétruy summarizes. Preventive measures are also crucial. Organizations should not neglect the perimeter of accesses granted to their users. "A user who is a customer manager must have a separate access with specific restrictions and security enhancements," he reminds. Unfortunately, this type of architecture is rarely applied, despite being a best practice. The growing complexity of cyber threats requires a more comprehensive approach to cybersecurity. As attackers evolve their tactics, defenders must adapt by expanding their monitoring scope and improving their understanding of the applications and systems they protect. This includes not only detecting threats but also proactively managing access rights and ensuring that all potential vulnerabilities are addressed. The challenge lies in balancing security with usability, ensuring that users have the access they need without compromising the organization’s safety.