The same standard at seven reviewers — and a very different score.
The submitted artifact is a privileged-access standard, not an incident postmortem, so it cannot document accountability, impact, causality, response, or corrective-action completion for a specific event. As a standard, it has meaningful controls but material gaps in IdP resilience, non-human identities, elevation safeguards, RMM fan-out controls, and measurable assurance.
BP-STD-021 lacks an incident summary, scope and impact, timeline, root cause, containment/recovery record, and owned corrective actions. It cannot support learning or accountability for a specific incident.
Raised by Incident Response and Operations Reviewer
Federation centralizes revocation across consoles but also centralizes failure. The standard addresses IdP unavailability, not tenant compromise, malicious app registrations, or compromised global administrators.
Raised by Principal Software Architect
Service principals, API keys, and automation accounts are outside the human-focused access model, leaving likely MSP fan-out paths without least privilege, strong authentication, rotation, or audit requirements.
Raised by Security and Reliability Reviewer
Out-of-hours self-approval is only reviewed after the fact and may be usable with stolen sessions. The 25-endpoint RMM approval threshold can be evaded through rapid sub-threshold batches.
Raised by Security and Reliability Reviewer
Reported KPIs lack definitions, sources, lineage, refresh expectations, and breakdowns. Embedded point-in-time values will become stale, while key controls have no measurable review or detection targets.
Raised by Data and Analytics Reviewer
Majority view: Prioritize documented postmortem deficiencies and established privileged-access gaps; add AI controls when such systems are in scope or deployed.
The decision is whether this submission can be accepted as an incident postmortem; it cannot. Scored 18/100, the document is a privileged-access standard rather than a record of a specific incident, leaving accountability, impact, causality, response performance, and remediation completion undocumented.
An 18/100 indicates serious deficiencies in the document itself, not merely opportunities to improve its underlying controls. It is materially unfit for its stated purpose and leaves high-consequence privileged-access risks insufficiently governed.
There was disagreement on whether AI-specific controls for AI-initiated privileged actions, audit trails, human review, and client-data/model safeguards should be added now. The prevailing view was to prioritize the missing postmortem content and established privileged-access gaps unless such systems are in scope or deployed.
Document ID: BP-STD-021
Version: 4.2
Owner: Chief Information Security Officer
Approved by: Executive Team, 2026-05-19
Effective: 2026-06-01
Review cadence: Every 6 months, or within 10 business days of any privileged-access incident
Next scheduled review: 2026-12-01
---
A managed service provider holds privileged access to every client it serves.
That concentration is the reason clients hire us and the reason we are a target:
an attacker who compromises one Brightpath technician account can reach several
hundred client tenants at once. Published incidents in our sector have followed
exactly this path — compromise of provider tooling or provider identity,
followed by fan-out through legitimate management channels.
This standard therefore assumes **the attacker is already inside a Brightpath
identity** and asks what limits the damage. Controls are selected to reduce
blast radius, not only to reduce likelihood.
Applies to all Brightpath personnel and contractors with any administrative
access to a client environment, and to the tooling that carries such access:
RMM, PSA, backup console, EDR console, identity management, and any per-client
delegated administration.
Out of scope: access to Brightpath's own corporate systems, covered by
BP-STD-007. Client staff privileges within their own tenant, which the client
governs and we advise on.
one named human.
another.
remembering it is a rule we assume is broken.
Control · Requirement · Enforcement
Technician identity · One named account per person, per system. No role or team accounts. · Conditional access blocks unnamed accounts
MFA · Phishing-resistant only — FIDO2 security key or platform passkey · Conditional access; SMS and TOTP are blocked, not discouraged
Device · Privileged access only from a Brightpath-managed, compliant, encrypted device · Device compliance policy; non-compliant devices are denied
Network · No IP allowlist dependency · Deliberate: see §11
TOTP and SMS were removed as acceptable second factors on 2026-03-30 following
a phishing simulation in which 3 of 41 technicians relayed a TOTP code to a
proxy. Zero relayed a FIDO2 assertion, because the protocol makes it impossible
rather than making it inadvisable.
No technician holds standing administrative rights in any client tenant.
a Service Desk Lead or above, and granted for 4 hours, after which it is
removed automatically.
business reason. Approval and grant are separate events with separate actors.
recovery being blocked at 03:00. Self-approved elevations are reviewed by the
CISO the following business day, and a self-approval that cannot be tied to a
genuine incident is treated as a policy violation.
Current metric: 96.4% of privileged sessions in the last 90 days were
covered by an approved, time-boxed elevation. The residual 3.6% is break-glass
and self-approved out-of-hours use, all reviewed.
tenant and per role**. Global administrator delegation is not used, and is
blocked at the partner-tenant level rather than discouraged.
generated and rotated automatically every 24 hours, and retrieved from the
vault against a ticket. Retrieval is logged with the retrieving technician,
the device and the ticket.
automated scan that hashes stored credentials and reports collisions.
Last scan 2026-08-03: zero collisions across 4,812 stored credentials.
Our management tooling is itself a privileged path into every client, so it is
treated as production infrastructure rather than as internal software.
a second approver. This is a deliberate brake on the exact fan-out pattern
used in provider-compromise incidents.
global enrolment key exists; one was retired on 2025-11-14.
irreversible for 30 days by vendor-side immutability.
single action rather than four.
Two break-glass accounts exist per critical system, for the case where
federation itself is unavailable.
sealed physical envelopes.
monitored with a dedicated alert on any authentication, routed to the CISO and
the on-call lead simultaneously.
fired in 41 seconds, envelopes resealed and re-witnessed. Next test 2026-10-08.
commands executed through the RMM.
audit window plus one month.
Delivery, is itself logged, and cannot be granted by the person under review.
compromise of the tooling does not grant the ability to erase the evidence of
what was done with it.
Target is complete revocation within 1 hour of termination; measured
median over the last 12 leavers is 11 minutes, longest 47 minutes.
against the HR active-employee list. Discrepancies are tickets, not emails.
Last four reconciliations: zero orphaned accounts.
moving from service desk to projects loses service desk scope on the same day.
beyond the contract end recorded in the PSA.
Stated explicitly so a future reader knows these were decisions rather than
oversights.
IP allowlisting was rejected. It fails open for a stolen session token and
fails closed for a legitimate engineer at a client site during an outage. It
would have added meaningful operational risk during exactly the incidents where
we are most needed, in exchange for stopping an attacker who can rent a VPS.
Device compliance was chosen instead, which binds access to a machine we control
rather than to a network location anyone can be standing in.
**Accepted: 4-hour elevation windows are longer than strictly necessary for most
tickets.** A 1-hour window was trialled in February 2026 and produced 340
re-elevation requests in three weeks, which degraded response times and trained
technicians to request elevation reflexively at the start of every shift. Four
hours is a deliberate trade of theoretical exposure against a behaviour we
judged worse.
**Accepted: session recording does not cover client-side remote sessions
initiated by the client.** We record what we do; we cannot record what the
client's own staff do in their own tenant. Clients are told this in the MSA.
Accepted: two people can, in combination, delete backups. Requiring three
approvers was modelled and would have exceeded our on-call headcount at night.
Vendor-side 30-day immutability is the compensating control.
Exceptions require CISO approval, a documented compensating control, and a
mandatory expiry of no more than 90 days. Exceptions cannot be renewed more
than once without executive review. The exception register is reviewed monthly.
Open exceptions as at 2026-08-01: two. Both relate to a client's legacy
line-of-business application that cannot support delegated administration; both
expire 2026-09-15 and are tracked against the client's migration project.
Metric · Target · Current (90 days)
Privileged sessions under approved elevation · ≥ 95% · 96.4%
Credential collisions across clients · 0 · 0
Median revocation time on termination · ≤ 60 min · 11 min
Orphaned accounts at weekly reconciliation · 0 · 0
Break-glass tests completed on schedule · 4/4 · 4/4
Open exceptions past expiry · 0 · 0
Metrics are reported to the Executive Team monthly and to clients on request.