Re: A new 'zero day'?
"We must start making systems genuinely resilient as opposed to just assuming that once inside the perimeter the attacker has free reign."
One of the clients I do some work at, I have admin access, but only over the users and what they can access or use and another login for some more advanced, high level stuff. I don't get admin access over the core systems, and over-use of my higher level creds will be queried, especially if it's used for stuff my lower level should be used for. A colleague, spending time at another client site, has both "standard" user and "admin" creds. His admin creds, for doing the same job as me, let him do pretty much anything, anywhere in the system. Madness! It's like they only have two security levels and absolutely no compartmentalisation.