Who Holds the Keys to Your Organisation's Critical Systems?

Estimated reading time: 8 minutes

Privileged access can open the door to some of an organisation's most important systems and information.

New Australian and New Zealand cybersecurity guidance highlights why understanding who holds that access, what it can reach and how it is protected should be a governance priority.

On 14 September 2026, the Australian Signals Directorate's Australian Cyber Security Centre published updated international guidance on detecting and mitigating Microsoft Active Directory compromises. New Zealand's National Cyber Security Centre published the joint guidance two days later.

Active Directory is widely used to manage identities, authentication and permissions across enterprise environments. ASD describes it as an organisation's digital gatekeeper because it verifies users and controls access to critical systems and data. That makes it valuable to organisations, but also attractive to attackers.

The updated guidance explains how malicious actors can use legitimate permissions, relationships and configurations within Active Directory to understand an environment, escalate their privileges and move across enterprise networks. For business leaders, the lesson extends well beyond Active Directory itself. Do you know who holds significant access across your organisation, what that access can reach and what would happen if it were compromised?

Sources: ASD's Australian Cyber Security Centre, Updated guidance on detecting and mitigating Active Directory compromises, 14 September 2026. New Zealand National Cyber Security Centre, Detecting and Mitigating Active Directory Compromises, 16 September 2026. Full citations in the References section below.

Identity Can Be the Key to Much More Than One System


Access is rarely just about logging into a single application. In many organisations, central identity systems determine who can reach applications, infrastructure, information and administrative functions. This creates efficiency for employees and administrators, but it also means some identities can have considerable reach across the environment.

ASD warns that if malicious actors gain control of Active Directory, they can potentially gain control across an organisation's entire enterprise IT network. Attackers may also begin with permissions available to ordinary users, explore the environment and gradually increase their access over time.

The governance question is not just who has access.
It is what can that access ultimately reach?

Attackers Look for Pathways to Greater Access


The updated guidance demonstrates that attackers do not necessarily need to begin with the organisation's most powerful account. After gaining initial access, malicious actors can examine Active Directory to understand its users, permissions, configurations and relationships. They can then look for weaknesses that allow them to escalate privileges or move laterally through the environment.

The guidance specifically identifies the highest privileged users, including Domain Admins and Enterprise Admins, as important targets because compromising these identities can provide extensive control. It also notes that other identities, including service accounts, can provide significant access.

An account does not need to begin with access to everything to become part of a pathway toward something critical. Understanding access therefore means understanding both individual permissions and how those permissions connect across the organisation.

Access QuestionWhat It Actually Asks
Who has access?Which identities can authenticate to the system or application
What can that access reach?What other systems, data or administrative functions those identities can ultimately touch
How could access be escalated?Whether an attacker with ordinary access could follow a pathway toward higher privileges
Who would notice?Whether unusual authentication, escalation or lateral movement would be detected and investigated

Privileged Access Needs Stronger Governance


Privileged access is necessary. Administrators and other authorised personnel need elevated permissions to maintain systems and perform important business functions. The objective is not to eliminate privileged access. It is to make sure that significant privileges are limited, understood and appropriately protected.

The ASD guidance recommends restricting membership of privileged security groups, limiting access to critical infrastructure to privileged users who genuinely require it and regularly reviewing certain permissions and credentials. For leadership, this creates a broader governance principle. The greater the access, the greater the need for visibility and accountability around it.

Organisations should be able to explain why significant access exists, who is responsible for it and whether it remains appropriate as roles, systems and business requirements change. That accountability sits naturally within the broader governance responsibilities explored in Board Cybersecurity Responsibilities in 2026. At an operational level, this kind of ongoing review is typically part of what virtual ISM support provides, working alongside existing teams to maintain visibility as the environment moves rather than relying on a single review completed months ago.


What Business Leaders Can Learn


Identity is part of cybersecurity risk. Accounts and permissions determine who can reach important systems and information. That makes identity governance a risk conversation, not purely an IT administration matter.

Access should reflect genuine business need. Privileged permissions are sometimes necessary, but they should have a clear reason for existing. When that reason changes or ends, the access should be reviewed rather than left in place.

Access pathways matter. Attackers can potentially move from an initially compromised identity toward accounts and systems with greater privileges. Understanding this requires looking at how permissions connect, not only at what each account can do in isolation. This is the same kind of connected thinking that distinguishes a governance approach from a checklist, as discussed in The Evidence Gap.

Privileged access deserves additional attention. The consequences of compromising a highly privileged identity can extend across an entire enterprise environment. Leadership does not need to manage the technical detail, but it does need assurance that significant access is being monitored and reviewed, which is the kind of visibility that vCISO advisory is often brought in to establish at board and executive level.

Access governance is ongoing. Roles, systems and responsibilities change. Permissions should be reviewed as those changes occur rather than being treated as permanent decisions. The ASD guidance reinforces this by recommending regular review of privileged group memberships and credentials.

The Privileged Access Test

Choose one system or business function your organisation considers critical.

Who has privileged access to it?

What else can those identities access?

If answering the second question requires significant investigation, there may be an opportunity to improve visibility over privileged access and its potential reach.

Questions Every Executive Should Ask


  • Which identities have the highest levels of access across our organisation?
  • What systems, applications and information can those identities reach?
  • Why does each privileged account require that level of access?
  • How regularly are privileged permissions reviewed?
  • What happens to access when someone changes roles or responsibilities?
  • Are administrative activities separated from normal day to day user activity?
  • How are unusual authentication or privilege escalation activities detected?
  • Could access to one account create a pathway toward more critical systems?
  • Who is accountable for reviewing and approving significant access?
  • If a highly privileged identity were compromised, how much of the organisation could be affected?

If these questions are difficult to answer, the issue may not simply be an access control problem. It may indicate a broader visibility and governance gap around organisational identity.

Identity Should Be Treated as Part of the Security Foundation


Identity systems make modern organisations easier to operate. They allow people to authenticate, access resources and perform their responsibilities without maintaining completely separate identities across every system. But that central role also makes identity infrastructure important to protect.

The updated guidance illustrates that Active Directory compromise can involve privilege escalation, lateral movement and persistence, while detection can be challenging because some techniques exploit legitimate functionality and can resemble normal activity. Effective identity security therefore requires more than authentication. It requires visibility into who has access, what that access can reach, how privileges are granted and whether unusual activity can be identified, a set of questions that naturally falls within the scope of security leadership and broader governance rather than sitting with a single technical team.

SeComPass helps organisations approach cybersecurity through governance, risk and clear accountability. This includes helping organisations understand how access controls relate to business risk, whether responsibilities are clearly defined and whether cybersecurity controls align with recognised frameworks and organisational requirements. Where new controls or review processes need to be put in place, tools and implementation support can help translate those priorities into working practice. The objective is not for leadership to manage Active Directory. It is to provide leaders with enough visibility and assurance to understand whether critical access is being appropriately governed and whether significant identity risks are being managed.

Key Takeaways


  • Privileged access is necessary, but it creates risk that grows with the reach of the identity holding it
  • Attackers do not always need to start with the most powerful account and can follow pathways from ordinary access to critical systems
  • Access governance means understanding not just who has access, but what that access can ultimately reach and how permissions connect across the organisation
  • ASD recommends restricting privileged group membership, limiting access to those who genuinely require it and regularly reviewing permissions and credentials
  • Identity governance is an ongoing responsibility that should change as roles, systems and business requirements change around it

Understand Who Holds the Keys

Do You Know Who Has Significant Access Across Your Organisation?

The Executive Readiness Review helps leadership teams understand where significant cybersecurity access and responsibilities exist, how those controls relate to business risk and whether governance provides enough visibility over critical systems. It includes:

  • Identification of where significant access and privileged accounts exist
  • Review of how access controls relate to business risk and governance requirements
  • Assessment of whether responsibilities for access review are clearly defined
  • Strategic priorities for building ongoing visibility over identity and access governance

Know who has access, understand what it can reach, and govern the risk.

Start the Executive Readiness Review →

References


  • Australian Signals Directorate's Australian Cyber Security Centre. "Updated guidance on detecting and mitigating Active Directory compromises," 14 September 2026 (updated 15 September 2026). cyber.gov.au
  • Australian Signals Directorate's Australian Cyber Security Centre. "Detecting and mitigating Active Directory compromises," updated 15 September 2026. cyber.gov.au
  • New Zealand National Cyber Security Centre. "Detecting and Mitigating Active Directory Compromises," 16 September 2026. ncsc.govt.nz

This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. The ASD and NCSC guidance referenced above is primarily technical guidance for detecting and mitigating Active Directory compromise. The broader governance discussion in this article is an executive interpretation of the risk demonstrated by that guidance, not a claim that the agencies have published a new governance requirement. The article does not suggest that Active Directory itself is insecure, that privileged accounts should be eliminated, or that every organisation using Active Directory is currently compromised.

Jatinder Oberoi

Founder and Principal Consultant at SeComPass, where he helps organisations across Australia and New Zealand strengthen cybersecurity, governance, risk management, and regulatory compliance. With extensive experience in information security strategy, ISO 27001, SOC 2, AI governance, privacy, and virtual CISO (vCISO) services, Jatinder works with executive teams to align cybersecurity with business objectives, improve organisational resilience, and build lasting customer trust.

https://au.linkedin.com/in/jsoberoi
Next
Next

Are Your Security Controls Still Effective?