Skip to main content

Aug 7, 2026

When the Attack Looks Like the User

Patricia Titus

The textbook definition of identity is a noun: a fixed descriptor for a person or a system. Patricia Titus, Abnormal AI’s Field CISO with decades of experience across financial services, government, and technology, has a different definition.

 

"CISOs have to have a verb," she says. "Identity is the act of granting trust. And organizations are granting it way faster than we can govern it. The gap really is between the trust grant and the trust governed—and that's where breaches live."

 

That gap is the operating environment for both impersonation and insider risk. In one scenario, an attacker acquires a credential through phishing, social engineering, or outright fabrication and uses it to appear legitimate inside the organization. In the other, someone who already has legitimate access starts using it for illegitimate purposes. From the outside, neither looks like a threat. They look like normal activity, because they're using normal access to do it.

 

"The biggest insider risk isn't a disgruntled employee. It's a legitimate credential doing illegitimate things and nobody's watching it."

— Patricia Titus, Field CISO, Abnormal AI

 

That pattern has a consistent execution path, and it runs straight through the help desk. Attackers don't need a technical vulnerability when they can call IT support, impersonate a panicked employee, and walk away with a freshly reset credential. The help desk is designed to be responsive — which makes it the most reliable non-technical entry point for this kind of attack.


Vishing attacks surged 442% in H2 2024 vs. H1, with help desk social engineering a primary driver. (CrowdStrike 2025 Global Threat Report)


Mick Leach, Abnormal AI's Field CISO, gets to the core of why this is hard to detect. He's spent years doing post-incident analysis on both external ATOs and insider threat cases, and the finding never changes: on the wire, in the logs, an external attacker and an insider threat look exactly the same.

Mike Britton, Abnormal AI's CIO, frames the same dynamic from the defender side: "Once I'm in as your account, I'm a trusted insider — and so it's much easier to pivot, much easier to lateral move." An attacker who has taken over an account isn't pretending to be an insider. They are one, for every purpose the security stack can see.

 

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.