Saudi Aramco. Stuxnet. The Flame virus. Red October. Subway Restaurants. Global Payments. Utah and South Carolina. U.S. Chamber of Commerce. Pacific Northwest National Laboratory. These are just a few of the recent, high-profile cyber attacks and sophisticated malware that targeted and leveraged privileged accounts. Despite repeated warnings and plenty of examples to learn from, privileged accounts have become the primary attack vector for all enterprise assaults – originating from both inside and outside an organization. Privileged accounts, often thought of as only the privileged and administrative accounts used internally by IT and sys-admin staff, actually also includes default and hardcoded passwords, application backdoors and more. All these accounts act as a gateway to an organization's most sensitive data. And even though they're often protected by weak passwords, they are seldom replaced. Thus they are increasingly being used by cyber attackers to perpetrate some of the most devastating advanced attacks. So if you don't want your company played out in headlines across the country for similar incidences, learn to protect against advanced threats. This requires a new approach to security – starting on the inside and working out. This doesn't mean that the world doesn't need firewalls or perimeter security – it means a change in priority. Identifying all of these privileged access points and locking them down should be the first priority for any organization that is serious about security.