When setting up a new computer or logging into cloud email, standard antivirus usually feels like enough protection. I think most of us picture a cyberattack as a highly technical event where a hacker writes complex code to bypass security systems. Modern cybercriminals skip noisy malware and complicated exploits because breaking through a digital wall takes unnecessary effort. Instead, they log in directly using compromised credentials, walking straight through the front door disguised as legitimate employees.
Meet the “Polite Intruder“.
Modern Attackers Target Passwords Instead of Code
Purchasing stolen credentials on the dark web gives attackers immediate, quiet access to corporate networks. In an article titled “No Exploit Needed,” The Hacker News noted that identity-based attacks account for 90% of modern breaches. Because a successful login uses legitimate credentials, it avoids triggering standard endpoint security alarms altogether.
Endpoint protection remains vital for device-level security, but cloud accounts demand a completely different approach. Local security software looks for malicious files on machines, whereas cloud applications require monitoring human activity inside user accounts. When security tools can no longer rely on spotting obvious bad code, cybersecurity requires true instinct to interpret human behaviour. Catching a polite intruder means identifying when a valid password is being used by an unauthorised user.
Active Capability Outweighs Internal Headcount
Building an effective defence against identity threats does not require hiring a massive internal team. The shift comes down to operational capability, moving from static alert notifications to continuous threat hunting.
Consider a Sunday morning incident at 2:00 AM. An account logs in with a stolen password and exports a client database. A passive security tool might flag the off-hours login and generate an automated email. Relying on a simple “Threat Neutralised” alert creates a false sense of security because a passive notification cannot resolve an identity breach on its own. That alert sits in an inbox until Monday morning, leaving the intruder completely uncontested over the weekend.
Continuous threat hunting transforms this outcome. A dedicated security team actively monitors activity across both endpoints and cloud accounts around the clock. When unusual account activity occurs overseas at 2:00 AM, human threat hunters step in immediately to sever the connection and lock down the compromised credentials. You simply wake up on Monday morning to a report detailing an averted crisis.
Is your current security looking for bad code or bad behaviour? Let’s talk about upgrading your response capabilities today.
Sophos Endpoint Brochure | Services | Contact us
Sign up for our newsletter



