Executive Summary
In every organization, employees are both the greatest asset and the most targeted vulnerability. While security teams invest heavily in firewalls, endpoint protection, and threat intelligence, adversaries increasingly bypass these controls entirely by targeting the human element through the path of least resistance: poor cyber hygiene.
Cyber hygiene refers to the everyday digital habits and configurations that determine how easy or difficult it is to compromise a user’s identity. Weak passwords, inactive MFA, dormant accounts, excessive application permissions, and stale credentials are not exotic threats, they are the mundane realities of most organizations’ environments. Yet these overlooked factors consistently form the foundation of the most damaging breaches recorded each year.
The five hygiene failures highlighted in this report reflect a consistent truth: attackers do not need sophisticated exploits when employees leave doors unlocked. Multi-factor authentication gaps, password reuse, dormant privileged accounts, OAuth over-permissioning, and external mailbox forwarding each represent a discrete attack vector, yet their true danger emerges when they combine into a compound exposure that dramatically amplifies an organization’s risk profile.
This report explores how these hygiene failures manifest in practice, why legacy security controls struggle to surface them, and how Human Risk Intelligence provides the visibility and prioritization organizations need to close these gaps before attackers exploit them.
5 Hygiene Failures Increasing Enterprise Exposure
usecure’s Human Risk Intelligence tool answers a critical question: who is easiest to compromise? It surfaces the digital habits and account configurations that make some employees far more vulnerable than others, regardless of their awareness training scores.
The following failures represent some of the most common cyber hygiene weaknesses observed across organizations today. They are not theoretical risks; they are active exposures present in the majority of mid-market organizations today. Each one lowers the barrier to account compromise; in combination, they create critical compound risk.
Attackers follow a playbook. They target someone valuable, set a trap to deceive them, compromise their access, then cause damage.
MFA Gaps: The Unlocked Front Door
Multi-factor authentication (MFA) is widely regarded as one of the single most effective controls available to defend against account compromise. Studies consistently show that MFA blocks over 99% of automated credential stuffing attacks and more than 96% of bulk phishing attempts. Yet despite this, a significant proportion of users in most organizations operate without any form of MFA, and those users are disproportionately the ones attackers choose to target.
MFA gaps are particularly insidious because they are invisible to traditional security tools. A user without MFA will successfully authenticate with only a username and password — a login that looks entirely normal until the moment an attacker uses stolen credentials to do the same. By the time the intrusion is detected, the attacker may already have established persistence, exfiltrated data, or pivoted to higher-value accounts.
MFA gaps are expected to remain a primary attack enabler of account compromise throughout 2026. As credential theft through phishing, dark web markets, and data breaches continues to accelerate, any account without MFA protection is effectively an open invitation — regardless of how well that user performs in phishing simulations.
Illustrative Attack Scenario: MFA Gap
The following scenario is fictional but reflects techniques commonly used by attackers.
A Finance Manager at a mid-size professional services firm had never enrolled in Microsoft Authenticator despite repeated prompts from IT. The account had full access to the company’s financial systems, accounts payable workflows, and shared drives.
From: finance.update@[legitimate-domain.com]
Subject: Action required: Verify your Microsoft account
Dear [Name],
We have detected unusual sign-in activity on your account. To verify your identity, please click the link below and enter your credentials.
Verify account now
Microsoft Security Team
Because the account had no MFA, the attacker used the harvested credentials to log in directly. Within hours, they had set up inbox rules to redirect payment confirmation emails, modified two pending wire transfers, and exfiltrated a copy of the firm’s accounts payable ledger. The breach was not detected for eleven days.
Detecting MFA Gaps with Human Risk Intelligence
Traditional security tools treat MFA as a configuration checkbox — present or absent. They do not contextualise the risk based on who the user is, what they have access to, or what other hygiene factors compound their exposure.
usecure’s Human Risk Intelligence tool continuously monitors MFA enrollment status across the Microsoft 365 and Google Workspace environments. Critically, it correlates this with the user’s Target Value score: their seniority, data access, and financial authority to surface “MFA absent on high-value account” as a critical compound risk, not merely a configuration gap. Security teams are alerted with actionable tasks that identify the specific users to remediate first.
Password Weakness and Credential Reuse
Despite decades of awareness campaigns, password hygiene remains one of the most persistently poor practices in enterprise environments. Employees reuse passwords across personal and professional accounts, use variations of the same base password across internal systems, and frequently allow credentials to go unrotated for months or years. The consequence is that a single breach can cascade into enterprise account compromise.
The dark web credential market has made this risk tangible and quantifiable. Billions of username-password pairs from prior breaches circulate freely, and automated tools can test them against Microsoft 365, Google Workspace, or VPN portals in minutes. Users who have reused a breached password are perpetually vulnerable until that credential is rotated, and most do not know they are exposed.
Password weakness and credential reuse will continue to be amplified by AI-powered credential stuffing tools in 2026, dramatically reducing the time between a breach disclosure and a targeted attack against organizations whose employees reused those credentials.
password123
Illustrative Attack Scenario: Credential Reuse
The following scenario is fictional but reflects techniques commonly used by attackers.
A software company’s Senior Developer had used the same password for their corporate Microsoft 365 account and a personal project management SaaS tool. When the SaaS tool suffered a breach and credentials were published on a darknet forum, the attacker identified the employee’s corporate email through LinkedIn and attempted a credential stuffing attack.
With no MFA on the account, authentication succeeded immediately. The attacker spent three days quietly enumerating internal SharePoint sites, downloading source code repositories, and cataloguing the organization’s cloud infrastructure — all from within a legitimate, authenticated session that generated no alerts.
Detecting Credential Risk with Human Risk Intelligence
usecure’s Dark Web Monitoring Tool continuously monitors for employee email addresses appearing in known data breach databases. When a credential breach is detected, the security team will be notified. Our Human Risk Intelligence tool also displays user’s current password rotation status, MFA enrollment, and access privilege level. This helps create a comprehensive picture of the user’s risk exposure rather than generating a generic notification buried in a dashboard.
Dormant and Orphaned Accounts
Every time an employee leaves an organization, changes roles, or simply stops using a service, they leave behind an account. If that account is not promptly deprovisioned, it becomes a dormant attack vector — a valid, authenticated identity with no active owner to notice suspicious activity. Dormant accounts are particularly dangerous when they retain legacy privileges from a previous role, hold admin rights that were never revoked, or have credentials that have never been rotated.
Orphaned accounts — those belonging to contractors, partners, or service processes with no clear owner — present a similar risk. They often operate beneath the radar of standard HR offboarding processes and remain active indefinitely. Attackers actively seek out these accounts precisely because they are less monitored, less likely to trigger anomaly detection, and often carry permissions that were generous at the time of original provisioning.
Dormant account exploitation is expected to intensify in 2026 as ongoing workforce churn and organizational restructuring continue to generate a growing inventory of inactive but still-active identities. A single dormant admin account can hand an attacker the keys to an entire Microsoft 365 tenant.
- Retains legacy privileges
- No active owner to detect suspicious activity
- Credentials may never be rotated
- Bypass HR offboarding processes
- Often have elevated or broad permissions
- Fly under the radar of monitoring
Illustrative Attack Scenario: Dormant Account Exploitation
The following scenario is fictional but reflects techniques commonly used by attackers.
A regional logistics company had offboarded a contracted IT consultant twelve months prior, but the consultant’s Microsoft 365 account remained active, complete with Global Administrator privileges granted during an infrastructure migration project.
The contractor’s personal laptop was later compromised in an unrelated phishing attack. The attacker discovered saved credentials in the browser and used them to access the logistics company’s Azure Active Directory. Within four hours they had created two new admin accounts, reset the passwords of senior executives, and established persistent access via a registered OAuth application, all through an account that should not have existed.
Detecting Dormant Accounts with Human Risk Intelligence
The Human Risk Intelligence tool automatically surfaces accounts that have been inactive beyond configurable thresholds and correlates inactivity with privilege levels to prioritize dormant administrative accounts as critical risks. Organizations can use this data to automate access revocation workflows, transforming dormant account remediation from a manual audit exercise into a continuous security process.
OAuth Over-Permissioning
OAuth (Open Authorization) enables users to grant third-party applications access to their cloud accounts without sharing passwords. It is a foundational mechanism of the modern SaaS ecosystem, but also one of its most significant and least understood attack surfaces in modern cloud environments. Users routinely authorise applications with far broader permissions than necessary, often granting write access, the ability to send emails on their behalf, or even the right to consent on behalf of their entire organization.
These consent grants persist indefinitely unless explicitly revoked. An application authorised two years ago, perhaps no longer in active use, may still have full read and write access to a user’s mailbox, calendar, and files. If that application is subsequently compromised — or if a malicious application was granted consent in the first place through a phishing attack — the attacker inherits all of those permissions without needing to steal a single credential.
As organizations deepen their SaaS footprint in 2026, OAuth over-permissioning will emerge as a top-tier hygiene risk. The combination of legitimate-looking consent flows and persistent token access makes this one of the hardest attack vectors for employees to recognize and for legacy tools to detect.
Illustrative Attack Scenario: OAuth Abuse
The following scenario is fictional but reflects techniques commonly used by attackers.
A marketing manager at a financial services firm received a calendar invite appearing to originate from a Microsoft Teams HR notification. On clicking “Join meeting,” she was redirected to a Microsoft-branded OAuth consent screen requesting permissions for an application called “Calendar Sync Pro.” The application requested access to read her email, modify her calendar, and send messages on her behalf.
Because the consent screen used genuine Microsoft branding and the request seemed consistent with a calendar sync tool, she clicked “Accept.” The attacker immediately received an access token and a refresh token, granting silent, persistent access to her inbox. Over the following three weeks, they monitored her communications, identified an upcoming wire transfer approval, and used her account to redirect the payment entirely without her knowledge.
Detecting OAuth Risks with Human Risk Intelligence
Human Risk Intelligence inventories OAuth application consents granted within the Microsoft 365 and Google Workspace environments. It flags applications that hold write-level delegated permissions, applications consented to by users who have since become inactive, and applications with no verified publisher. Security teams receive actionable tasks to audit and revoke suspicious consents grants, transforming what was previously an invisible risk into a monitored and manageable control.
External Mailbox Forwarding
Email forwarding rules are a legitimate productivity tool, but when they route corporate email to an external mailbox, they become a persistent and silent data exfiltration channel. External forwarding rules are routinely established by attackers who have gained temporary account access, enabling them to maintain visibility into an organization’s communications long after the initial compromise has been remediated. They are also occasionally set by employees for convenience. Forwarding corporate email to a personal account, for example, creates an unintended data leakage path.
The danger of external forwarding lies in its persistence and invisibility. Once established, a forwarding rule continues to operate silently in the background, sending copies of every incoming email to an external address. Unless an organization actively audits mailbox configurations, these rules can persist for months, even after a password reset or MFA enrollment has been completed, because forwarding rules are not credential-dependent.
External mailbox forwarding will continue to be a key post-compromise persistence mechanism in 2026, particularly following Business Email Compromise attacks where attackers seek to monitor financial communications and intercept payment workflows over extended periods.
(Corporate)
Illustrative Attack Scenario: External Forwarding Abuse
The following scenario is fictional but reflects techniques commonly used by attackers.
A sales director at a professional services company had their Microsoft 365 account compromised through a credential phishing attack. The attacker, having gained access, immediately created a mailbox forwarding rule sending all inbound emails to an external address hosted on a free consumer email service.
The company’s IT team detected and remediated the phishing compromise within 48 hours, resetting the director’s password and enrolling MFA. However, the forwarding rule was not identified as part of the incident response. For the next four months, every email received by the director, including commercial proposals, contract negotiations, and pricing strategy discussions, was silently copied to the attacker’s mailbox. The breach was only discovered when a competitor appeared to have prior knowledge of a confidential bid.
Detecting External Forwarding with Human Risk Intelligence
Our Human Risk Intelligence tool continuously monitors mailbox configuration settings across the Microsoft 365 and Google Workspace environments, specifically flagging external forwarding rules established on accounts. It correlates forwarding configuration with the user’s role and seniority (an external forwarding rule on a C-suite or finance role is surfaced as a critical alert, rather than a routine configuration finding.) This transforms mailbox auditing from a periodic manual task into a continuous and automated hygiene control.
Defending Against Hygiene-Based Threats
The most effective defense against hygiene-based threats is continuous, automated visibility into the hygiene posture of every identity in the environment. This requires moving beyond static reports and periodic audits to a platform that monitors hygiene signals in real time, correlates them with identity context, and surfaces actionable remediation priorities.
Our Human Risk Intelligence tool provides this capability by connecting human risk signals from across the platform, combining results from security awareness training, phishing simulation, policy management and dark web monitoring, into a unified Human Risk Intelligence dashboard. It evaluates every user across target value, awareness, hygiene, and access level, and automatically identifies where individual risk factors combine into compound exposures that require immediate attention.
Intelligence dashboard
With our Human Risk Intelligence tool in place, organizations gain the intelligence they need to focus remediation where it matters most, before an attacker exploits the gaps that already exist in their environment.
Security awareness training remains a critical component of any human risk program. However, awareness alone cannot close hygiene gaps. An employee can score 100% on a phishing simulation and still have an MFA gap, a breached credential, or a dormant admin account that exposes the organization to catastrophic compromise.
Predictions on Cyber Hygiene for 2026 and Beyond
Glossary
Show definitions
Human Risk Intelligence (HRI): The practice of identifying, measuring, and prioritizing human-centered cybersecurity risks by combining behavioral, identity, access, and security telemetry.
MFA (Multi-Factor Authentication): An authentication method requiring two or more verification factors before access is granted.
Credential Stuffing: An automated attack where stolen username-password combinations are tested against multiple services.
Dark Web Monitoring: The process of identifying employee credentials or organizational data exposed in criminal marketplaces and breach repositories.
OAuth: An authorization framework that enables users to grant applications access to resources without sharing passwords.
OAuth Consent: Permission granted by a user allowing an application to access specific data or services.
Delegated Permissions: Permissions that allow an application to act on behalf of a signed-in user.
Refresh Token: A credential used to obtain new access tokens without requiring the user to authenticate again.
Dormant Account: An account that remains active but has not been used for a defined period.
Orphaned Account: An account that no longer has a clearly identifiable owner.
Privileged Account: An account with elevated permissions capable of accessing sensitive systems or administrative functions.
Target Value: A measure of how attractive a user account is to attackers based on access, authority, and business impact.
Human Attack Surface: The collection of user behaviors, identities, permissions, and configurations that can be exploited by attackers.
Compound Risk: Multiple risk factors that combine to create significantly greater exposure than any single risk factor alone.
External Mailbox Forwarding: A mailbox rule that automatically forwards emails from a corporate account to an external address.
Business Email Compromise (BEC): A form of fraud in which attackers impersonate trusted individuals to manipulate financial transactions or sensitive communications.