• ABOUT
  • CONTACT
  • BLOG
techpinions_logo_transparent techpinions__white_logo_transparent
  • TECH SECTOR PERFORMANCE HEATMAP
  • UPCOMING TECH IPOs
  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
Reading: Scott Aldridge on Identity Threats and the Hours That Saved Patient Records
Share
TechpinionsTechpinions
Font ResizerAa
  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
Search
  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
Follow US
© Copyright 2026, Techpinions. All Rights Reserved.
Home » Blog » Scott Aldridge on Identity Threats and the Hours That Saved Patient Records
Technology

Scott Aldridge on Identity Threats and the Hours That Saved Patient Records

david_graff
Last updated: August 12, 2026 12:46 PM
David Graff
Published: August 12, 2026
Share

Identity vulnerabilities are becomig a new way for cyberattackers to access organizations. It is often done through legitimate accounts and logins.

While many organizations evaluate cybersecurity through visible controls such as email security, firewalls, and compliance audits, many of today’s cyberattacks begin in a less visible place: the identity layer.

Compromised credentials have become some of the most common ways attackers gain access to networks. Rather than exploiting software vulnerabilities, attackers are increasingly logging in with legitimate accounts obtained through phishing attempts, password reuse, and third-party breaches. Organizations that continue to move critical operations into cloud environments have found that user identity is one of their newest primary security boundaries.

Scott Alldridge, Founder, President & CEO of IP Services and Co-Founder & President of IT Process Institute (ITPI), believes that organizations that invest in traditional security controls often overlook one of today’s fastest-growing vulnerabilities.

“Identity has become one of the least visible, but most important areas organizations need to monitor,” he says.

Identity Threat Detection and Response (ITDR) addresses these challenges in several ways. These include monitoring user identities, authentication systems, and privileged accounts for suspicious activity. This may help detect when legitimate access is being abused, and allows ITDR to serve different but complementary roles in modern cybersecurity strategies.

When Legitimate Accounts Become Active Threats

When attackers gain access to legitimate accounts, swiping information from servers and cloud environments becomes that much easier, especially when they can navigate a system under the guise of legitimacy. For one healthcare organization, endpoint protection, email security, and access controls were already in place when there were no obvious indicators of compromise.

However, when identity-focused monitoring was introduced into the healthcare organization’s systems, security analysts discovered suspicious activity that involved two employee accounts. They then realized that their credentials had been compromised, and that the attackers were preparing to deploy ransomware.

Because the attackers were operating with legitimate user accounts, their activities blended into normal network behavior. As a result, their actions were less likely to trigger traditional security alerts.

“The danger isn’t always malware,” Alldridge explains. “Sometimes it’s someone quietly using valid credentials while blending into everyday network activity.”

When Cybersecurity Becomes a Business Risk

The above incident highlights a challenge for security teams, one that is only continuing to grow. As healthcare organizations adapt to the growing needs and services that cloud systems provide, the shift has implications beyond IT departments.

“Healthcare organizations often think about cybersecurity as an IT expense,” Alldridge notes. “In reality, it’s becoming an operational resilience issue that directly affects patient care, revenue, and organizational trust.”

While cybersecurity incidents are often discussed as technical events, executives evaluate them in terms of business consequences. The HIPAA Journal has recently reported that data breaches exposed more than 289 million individual records in 2024, a 58% increase over the previous year.

For many organizations, calculations should now focus on the potential cost of failing to detect an attack before it disrupts operations, rather than on the cost of implementing additional security controls.

Why Threats Often Go Undetected

Though some organizations assume that deploying respected security protocols will automatically create resilience, the reality is that effective cybersecurity often depends on people, processes, governance, and the technologies they all utilize working together. This principle is reflected in the CIS Controls, which emphasize account management, continuous monitoring, and governance alongside technical safeguards.

In the healthcare organization’s case, they did not primarily suffer from a lack of tools. Instead, they lacked visibility into identity activity. This is because without monitoring how trusted accounts behave, attackers can operate without immediately raising concern.

Visibility also remains a growing challenge. The Identity Theft Resource Center’s 2024 Annual Data Breach Report found that nearly 70% of cyberattack-related breach notices failed to identify the attack method or even the vector.

Without understanding how attackers gain access to their systems, organizations often leave blind spots that make it harder to identify recurring weaknesses, prioritize security investments, and strengthen future defenses. This reinforces the importance of monitoring a user’s identity behavior rather than relying solely on traditional indicators of compromise.

The Questions Leaders Should Be Asking

Rather than assuming that existing controls are sufficient, Alldridge encourages organizations to evaluate how cybersecurity teams monitor identity activity. Questions that teams should be asking include:

  • If a security team detects abnormal behavior from a legitimately authenticated employee account.
  • Do monitoring efforts extend beyond endpoints into cloud identity platforms?
  • Is there a documented response process for when employee credentials are exposed in a breach?
  • Are there teams that monitor identity-related alerts outside of business hours?
  • Are identity controls regularly tested and validated rather than being documented?

As businesses continue to expand their usage of cloud platforms and allow employees to work remotely, gaining visibility into identity activity has become an important part of a mature security strategy. For this reason, it is important to question how meaningful assessment of an organization’s security system can help it remain protected, rather than simply counting the number of protocols deployed.

Looking Beyond the Network

While organizations continue to adopt cloud services into their systems, identities have become valuable targets for cybercriminals. In this sense, attackers are not breaking into networks but are logging in using legitimate credentials.

For Scott Alldridge, the lesson extends beyond the healthcare organization example. Companies should not only ask if their systems are protected, but whether they can recognize when trusted identities are misused.

“The organizations that respond fastest are usually the ones that have visibility into identity activity before attackers have the opportunity to turn access into disruption.” Alldridge concludes.

Cyber threats will undoubtedly continue to evolve, and understanding identity behavior will become as important as protecting networks and endpoints. For today’s security teams, one of the most important lessons is not whether attackers can gain access, but if their presence will be detected.

Perseid meteor shower peaks this weekend: How to catch a glimpse
Gigantic molecular cloud discovered in hidden region of the Milky Way’s center
Linux 6.16 features faster file systems, improved security, and more Rust support
Koei Tecmo confirms 30 FPS for Dynasty Warriors: Origins on Nintendo Switch 2
Elon Musk’s xAI accuses Apple and OpenAI of stifling competition in new lawsuit
david_graff
ByDavid Graff
Follow:
David is the editor-in-chief of Techpinions.com. Technologist, writer, journalist.
Previous Article Is AI a Bubble or a Revolution? The Honest Answer Is Both — and That’s the Danger
Next Article best free church accounting software The Free Church Accounting Software I’d Recommend to a Treasurer

Listen to The Techpinions Podcast

Spotify Podcast

Join thousands of followers on X

X-twitter
techpinions_logo_transparent techpinions__white_logo_transparent
Insight, Perspective, and Analysis from influential and respected industry analysts.

About Techpinions

  • About
  • Contact
  • Editorial Policy
  • Financial Disclaimer
  • Follow us on X
  • Privacy Policy
  • Terms of Service

Topics

  • AI
  • Technology
  • Invest
  • Future
  • Opinions
  • Podcast
© Copyright 2026, Techpinions. All Rights Reserved.