NCSC issues new advice on implementing high-risk and ‘break-glass’ accesses in cloud services

Businesses are increasingly using the cloud because it offers greater flexibility and efficiency while reducing the burden of managing infrastructure. And as technology continues to evolve, cloud adoption is expected to grow further.

However, it is as important to protect your cloud environment as it is to protect your on-prem systems. Whether for data security, regulatory compliance, business continuity or overall organisational stability, there are many reasons why it’s vital that your cloud environment is secure.

And this is where admin accounts come in. An admin account, or administrative account, is a user account with elevated privileges and permissions with the authority to perform various administrative tasks and configurations that regular user accounts cannot. 

The importance of protecting admin access to your cloud account 

Admin accounts are essential for system management and maintenance, especially in complex environments. However, due to their elevated access, admin accounts are also attractive targets for attackers, and if they are breached, this could lead to significant security issues and potential damage to your systems and data. 

This is why it’s crucial to secure admin accounts with strong passwords, multi-factor authentication, and limit their use only to those who genuinely require administrative privileges for their specific roles. 

Additionally, implementing the principle of least privilege ensures that admin accounts only have access to the resources and functions they need to perform their administrative tasks, reducing the attack surface and potential risks.

Due to the high risk admin accounts pose to businesses, the NCSC has issued new advice on implementing high-risk and ‘break-glass’ accesses in cloud services.

The updated guidance is around secure system administration, focusing on high-risk access (where access is needed to administer a critical component of your system during normal operation) and emergency access (where access is needed when the normal ways of administering your system are not available, also known as ‘break-glass’ access).

Here is the NCSC’s advice:

Protecting high-risk access

Some basic management of a cloud service can be achieved with constrained (that is, tier 3) admin access, keeping the impact of compromise relatively low. An example task might be support staff resetting a standard user’s credentials, or managing access to a development sandbox. However, higher-risk admin access is often necessary for managing features and capabilities of a cloud service, such as:

  • Creating, changing, and disabling other administrative identities as individuals join, move role, or leave (the JML process)
  • Changing how your users authenticate to the service, such as updating your single sign-on configuration
  • Removing or loosening access controls on a critical or highly sensitive set of data

This kind of high-risk access occurs when you manage a cloud service, but they are the same activities that attackers also take after initial compromise, such as when trying to move laterally. This makes accurate detection of malicious admin access much more difficult, so preventing it in the first place becomes even more important.

For users with high-risk access to a cloud service, it’s a good idea to frequently check that you’re following the latest authentication best practice, such as using a phishing-resistant form of MFA. We talk about this in more detail in our recent guidance on using the cloud securely.

When protecting admin access, don’t overlook the value of a privileged access workstation (PAW). A dedicated PAW is one of the most effective tools for defending your administrators from common attacks, such as credential theft and malware infection. This is why the NCSC recommend you always use a PAW for high-risk access to a cloud service handling sensitive data.

Where a dedicated PAW isn’t an option, you should think about how close you can get to the protection that PAW provides. For example, could your high-risk admins do the majority of their work in a highly locked down device, but use a local or cloud virtual machine to browse-down for more risky activities, such as reading emails and opening complex documents?

You can combine these with other security signals in your access control policies, as described in our Zero trust architecture design principles.

Preparing emergency access

Emergency access, also known as ‘break-glass’ access, describes a form of emergency access that is absolutely necessarily to have in place, but you hope is never required. It allows you to access and administer your systems, even if all your normal IT is unavailable.

Creating and maintaining effective emergency access is hard because it may need to work without depending on any of the other security-enabling systems you’ve built. However, when preparing for emergency access to cloud services, you can leverage your cloud provider to help you solve this effectively. You should discuss with your cloud provider what account recovery options exist, and put preparations in place before you need them.

The important thing to remember here is that, unlike for high-risk access, you probably won’t be able to follow all the normal secure system administration principles to protect emergency access. For example, you may have to use an unmanaged device, or use fewer security signals in your zero trust architecture than you would normally prefer.

As you won’t be able to protect this access in as much depth as high-risk access, one of the most important things to consider is prompt and robust alarms. When any emergency access is triggered (such as signing in to an emergency administrator account), it should send immediate alarms to your operations personnel so that they can investigate. This serves two main purposes:

  • You can ensure that if an attacker compromises an emergency access method, you can take prompt action to limit the damage.
  • You want the use of emergency access to be ‘irritating enough’, so that nobody gets in the habit of using it when it isn’t absolutely necessary.

Not all risks are equal

It’s important to ensure that your security posture is proportionate to your risk appetite. You probably don’t need to be using PAWs and tiered administration for the service that manages your tea club rota. But for your sensitive systems, particularly where you store large volumes of personally identifiable information, make sure the work you invest in securing your cloud estate isn’t undermined by poor admin security.

Questions?

If you have any questions about this guidance from the NCSC, get in touch with our team using the contact form below and we’d be happy to answer any questions you have about securing your cloud environment.