Definition ยท External Attack Surface Management

What is Least Privilege?

The principle of least privilege holds that an identity โ€” a person, a service account, a running process, an API token โ€” should be granted the minimum access required to do its job, and no more. Its purpose is containment: it does not prevent credentials being stolen or a service being exploited, it limits what the attacker can then reach.

How it applies beyond user accounts

Least privilege is often discussed as a joiners-and-leavers problem, but the harder cases are non-human:

  • Service accounts and CI tokens with broad, long-lived permissions
  • Cloud roles granted wildcard actions because scoping them was fiddly
  • Database users that can read every table when the application needs three
  • Web servers and application processes running as root or an administrator
  • API keys shared between environments, so a test key works in production

Permissions also accumulate. Access granted for a project, a migration or an incident tends to outlive its reason, so periodic review matters as much as careful initial grants.

The external connection

From the outside you see the consequences rather than the permissions. An exposed admin panel matters far more when the account behind it is over-privileged. Credential stuffing against a login is a nuisance or a breach depending on what the compromised account can do. An exploited public-facing application becomes a foothold or a full compromise depending on what its process and its database user were allowed to touch โ€” and an over-privileged application account is one reason a single flaw turns into a ransomware incident.

Least privilege is a containment control alongside network segmentation, and one layer of defence in depth. It is an explicit theme in Cyber Essentials user access control, in ISO 27001 access control objectives, and throughout the CIS Benchmarks.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.