Identity Protection deep dive
Your password is the new perimeter — and it has already been breached.
Stolen credentials are the single most common starting point for cyberattacks against SMBs. Verizon's Data Breach Investigations Report puts the use of stolen credentials in the top three causes of breaches every year of the past decade. Once an attacker has a working username and password — bought on the dark web, harvested in a phishing campaign, reused from another site's breach — they walk in the front door of your Microsoft 365 tenant, your Google Workspace, your VPN, your CRM, your bank portal. From the inside, they look like the user. They read email. They impersonate the user to wire money. They set up forwarding rules to siphon mail to a personal account. They request password resets. The first sign of trouble is often a $50,000 invoice your CFO never approved.
99.2%
Per Microsoft
Of automated account-compromise attempts are blocked by multi-factor authentication. The remaining 0.8 percent is what AMTech identity-threat detection covers.
How attackers actually get in
Three patterns dominate identity attacks against SMBs. The common thread: every one starts with valid credentials. Your password, working as designed.
Credential stuffing
Automated login attempts using usernames and passwords leaked from other companies’ breaches. If anyone in your organization reuses passwords (and someone always does), every public breach is also potentially yours. Attackers run millions of these attempts per hour against Microsoft 365 and Google Workspace tenants because the math works.
Phishing for credentials
The email looks like a Microsoft 365 password-expiration alert. The login page looks like office.com. The user types their password. Now the attacker has it. Modern attacker-in-the-middle phishing kits even relay the multi-factor prompt in real time and steal the session token, defeating older one-time-code MFA.
Business email compromise (BEC)
Once inside, the attacker reads enough mail to learn how the company communicates, who pays whom, what wire-transfer language sounds normal. Then a perfectly framed email goes to accounting asking for a vendor payment to be redirected to a new account. No malware, no obvious anomaly — just an email "from the CEO" requesting an urgent wire.
Defense in depth — four layers, not just a password
Each layer below catches the attacks the previous one missed. MFA alone stops 99 percent of automated attempts. The full stack is what closes the gap on the targeted, sophisticated attacks specifically engineered to defeat technical filters and exploit human pattern-recognition.
Password
Something you know
Strong, unique, vaulted. The first layer — and the one that gets compromised every day.
MFA / 2FA
Something you have
Phishing-resistant: number-matching, FIDO2 keys, Windows Hello — not just SMS codes that attackers can intercept.
Conditional access
Where you are + risk
Trusted device, expected location, sensible time-of-day. Risky signals trigger a stricter prompt or block the login.
ITDR
What you do after login
Continuous behavior monitoring — impossible-travel, mass downloads, rogue forwarding rules. Detected threats trigger automatic mitigation.
Three identity partners — one platform-agnostic deployment
AMTech deploys MFA across the platforms your business already uses, working with the three major identity providers. Whichever stack you live in, modern phishing-resistant MFA is available and we know how to roll it out without breaking the user experience.
Microsoft
Entra ID + AuthenticatorPhishing-resistant MFA via Microsoft Authenticator (number matching, not just push approval)
Windows Hello for Business — biometric authentication on every Windows device
FIDO2 hardware keys for executives and high-risk roles
Conditional access policies driven by risk: untrusted device, foreign country, leaked-credential intelligence, anonymous IP
Cisco
Duo SecurityBroad-coverage MFA across third-party apps, VPN, server logins, and legacy systems that don’t speak modern SSO
Risk-based authentication adapts the prompt to the situation — routine office login is one tap, 2 AM login from a new IP gets a stricter check
Device-trust posture check before login: is the laptop patched? Is disk encryption on? Is the EDR agent running?
Built-in 2-Step Verification on every Workspace account, with Google Authenticator and Titan Security Key support
Context-aware access policies: condition login on device security posture, location, IP range, and time-of-day
Google Identity for federated SSO into hundreds of third-party SaaS apps from one identity store
What AMTech adds on top
The vendors ship the platform. AMTech operates it — turning identity protection from “configure and hope” into a continuous program that closes the gaps the platforms do not catch on their own.
MFA enrollment campaign
Every user enrolled, no exceptions. New hires get MFA on day one — built into onboarding, not a separate task. We run the holdouts to ground: the executive who keeps deferring, the field tech who said the prompt is annoying, the contractor whose account you forgot to require. Until everyone is enrolled, identity defense has a hole.
Conditional access policy library
Vertical-tuned policies built and maintained by AMTech: no out-of-country logins for healthcare practices, restricted hours for financial services, mandatory FIDO2 hardware keys for executives, blocked logins from anonymous IPs and known-bad ASNs. Policies are reviewed quarterly and updated as the threat landscape evolves.
Identity Threat Detection & Response
Continuous monitoring for impossible-travel logins, anomalous mailbox activity, suspicious forwarding rules, leaked-credential alerts, and mass-download events. Detected threats trigger automated mitigations — disable the account, revoke active sessions, force a password reset, alert AMTech on-call. The 0.8% of attacks MFA does not stop is what ITDR catches.
Peace of mind
Sleeping at night versus waking up to a $200,000 wire your CFO never authorized.
MFA matters for an SMB owner because it converts “we hope nobody clicks the wrong link” into a defense in depth. Even if someone gives away a password, the attacker still needs the second factor. Even if the second factor is defeated (rare, but it happens), the conditional-access risk engine still has to be fooled. Even if all three layers fall, ITDR is watching for the post-login behavior that signals someone unauthorized is inside — and shuts the door before damage compounds. AMTech runs identity protection so that the password breach you do not yet know about does not become the ransomware event you are explaining to your board.
99.2%
MFA blocks automated attempts
4 layers
Defense in depth, not just a password
3 partners
Microsoft · Cisco · Google
24/7
ITDR active monitoring
- Phishing-resistant MFA
- FIDO2 hardware keys
- Conditional access
- Risk-based authentication
- ITDR auto-mitigation
- Leaked-credential monitoring
- Impossible-travel detection
- Microsoft · Cisco · Google