Identity & Access Risk Posture

Castellan Retail Group – 6,800 employees, 22,000 identity accounts across 47 applications

Last Updated
2024-01-15 08:42 UTC
Privileged Sprawl Index
9.4
per 100 employees
-15% vs Q3
MFA Adoption Rate
94.2%
all auth events
+8.7% vs Q3
Dormant Elimination Rate
74%
SLA 80%
-6% vs target
Excessive Permission Score
38.2
target <30
-11% MoM
Cert Revocation Rate
6.8%
past 8 campaigns
+0.9% MoM
Orphaned Accounts
142
across all apps
+47 vs last month

Identity Risk Composite Score – 12 Month Trend

Lower score = reduced identity-attributed breach probability. Target: <50 by Q2 2024.

MFA Adoption by Authentication Context

Privileged sessions target: 99%+

Excessive Permission Score Breakdown

Users with entitlements exceeding role requirements

Dormant Account Inventory & Remediation Progress – 16 Weeks

Accounts inactive >90 days flagged for review and deprovisioning. Spike in W12 due to contractor project offboarding delays.

Cert Revocation Rate

Past 8 campaigns

Service Account Rotation

Compliance by app tier

Privileged Session Anomalies

Per 1000 sessions

Time-to-Deprovision Distribution

Terminated employee account closure (target <24h). Sample: last 90 days, n=87.

Orphaned Accounts by Application

Top 8 applications with user accounts no longer linked to active employees

Identity Finding Detail – Top 15 by Risk Score

Finding ID Severity Risk Score Category Description Affected Count Owner Age (days)
IAM-2401-047 Critical 94 Orphaned Admin 4 AWS IAM orphaned accounts with AdministratorAccess policy 4 Cloud Ops 23
IAM-2401-033 Critical 91 Orphaned Account 47 Salesforce orphaned accounts (contractor offboarding gap) 47 SaaS Ops 31
IAM-2401-019 High 82 Dormant Privileged 12 dormant privileged accounts in Active Directory (90+ days) 12 Identity Ops 104
IAM-2401-051 High 79 Service Account 8 Tier 1 service accounts with credentials not rotated in 180+ days 8 App Teams 67
IAM-2401-002 High 76 Excessive Permissions 23 finance users with global admin role (role creep) 23 Finance 118
IAM-2401-061 High 71 MFA Gap Privileged access sessions without MFA (CyberArk bypass) 6 PAM Team 14
IAM-2401-028 Medium 64 Orphaned Account 19 Workday orphaned accounts (HR sync lag) 19 HR Ops 22
IAM-2401-044 Medium 58 Certification 134 entitlements pending cert review (overdue 15+ days) 134 Access Cert Team 19
IAM-2401-012 Medium 52 Dormant Account 87 standard user accounts dormant 120+ days 87 Identity Ops 41
IAM-2401-055 Medium 49 Service Account 14 Tier 2 service accounts non-compliant rotation 14 App Teams 33
IAM-2401-038 Medium 46 Excessive Permissions 31 marketing users with production database read access 31 Marketing 56
IAM-2401-070 Low 38 Deprovision SLA 5 terminations exceeding 48h deprovision SLA 5 Identity Ops 8
IAM-2401-022 Low 34 MFA Gap 62 VPN sessions without MFA (legacy config) 62 Network Ops 47
IAM-2401-065 Low 29 Anomaly 3 privileged sessions from anomalous geolocations 3 SOC 2
IAM-2401-009 Low 26 Orphaned Account 12 GitHub orphaned accounts (dev offboarding) 12 DevOps 18

Identity-Correlated SIEM Alert Volume – 16 Weeks

Alerts with identity IOCs. Spike in W12 corresponds to contractor offboarding event.

Program Summary & Next Actions

Privileged Sprawl Index reduced from 11.2 to 9.4 (-15%) via quarterly entitlement review and role rationalization.
MFA Adoption now 94.2% across all auth events; privileged context at 98.1%, on track for 99% target.
Critical Orphaned Accounts: 4 AWS admin accounts and 47 Salesforce accounts from contractor offboarding gap require immediate remediation (Finding IAM-2401-047, IAM-2401-033).
Dormant SLA at 74%, below 80% target. Automation script for AD dormant sweep being deployed W3 to close gap.
Q1 Goal: Achieve Identity Risk Composite Score <50, reduce orphaned accounts to <30, and hit 99% MFA on privileged sessions.