Overig · Overig
Ransomware and IAM – why identity security is your first line of defense

Dylan Klümann · Project Manager · 4 min read
It is still early when the IT department of a medium-sized organisation receives an alarming notification. An unknown process suddenly tries to encrypt hundreds of files. Access to critical systems is swiftly blocked, but not quickly enough. A single compromised account turns out to be the cause. No data breach due to an advanced hack, no physical break-in, but one password that fell into the wrong hands.
This kind of story is now familiar to many organisations. Ransomware attacks are becoming smarter, faster, and more people-focused. It is not the firewall or the network that is attacked, but the identity. And that's precisely why Identity and Access Management (IAM) is today the most important first line of defence.
The shift: from network security to identity security
Where organisations once relied on traditional perimeter security, that model is now outdated. Employees work hybrid, applications run in the cloud and data is spread across multiple environments. The network no longer has clear boundaries.
Cybercriminals have also realised this. They no longer focus on infiltrating networks, but on exploiting identities. A stolen password, a misconfigured access, or a dormant account is now enough to introduce ransomware.
IAM thus becomes not just a security function, but a strategic necessity. It determines who gains access, when, how, and under what conditions.
Why ransomware often starts with an identity problem
Ransomware attacks almost always exploit the same vulnerabilities:
compromised accounts through phishing or password reuse
too much privilege on accounts that have more rights than needed
lack of control over inactive or forgotten accounts
It's simple: if an attacker gains access to an identity, they automatically assume the trust linked to that identity. Without strong IAM processes, one account can be the key to the entire business.
How modern IAM helps stop ransomware before it starts
Effective IAM does more than just create users. It forms a dynamic security shield that continuously checks whether users are who they say they are, and whether they have the correct access.
With modern identity security, you create multiple layers of protection:
Minimal access through strict authorisation models
Employees only gain access to what they truly need. An attacker taking over an account can, therefore, cause little damage.Continuous monitoring and detection of abnormal behaviour
IAM systems recognise unusual login locations, strange times, or abnormal request volumes. Suspicious behaviour is automatically blocked.Automatic deactivation of accounts
Accounts of former employees, temporary staff, or external suppliers are immediately deactivated once they are no longer needed. No more dormant accounts to exploit.
Together, these measures ensure that an attacker, even with a password, cannot get anywhere.
The story of organisations that are prepared
Organisations that have implemented IAM well notice something remarkable: ransomware attacks often fail before they can begin. Whether it’s an employee accidentally clicking on a phishing email or a data breach at a supplier, the damage is limited because identities are not blindly trusted.
Moreover, employees don't need to follow complex procedures. They log in as usual; the security happens behind the scenes. IAM is thus not an obstacle, but a silent force that reduces risks without disrupting day-to-day operations.
IAM as the foundation of modern cybersecurity
Ransomware will not disappear. The techniques are changing, the attacks are becoming more sophisticated, and organisations remain attractive targets. But as attackers get smarter, so can organisations.
A strongly implemented IAM landscape means:
less risk of account misuse
better protection of critical systems and data
less reliance on human error
a robust foundation for all other security measures
IAM is no longer a supporting IT function but the basis of your cyber resilience.
Joinly makes identity security practical, scalable, and effective
At Joinly, we help organisations manage identities safely and efficiently. No complex projects, but clear processes, smart automation, and immediate results. So that employees can work safely, organisations remain resilient, and ransomware has no chance of getting through.
Would you like to know how your organisation can better protect identities? We are happy to think along with you.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.