Initial Access Broker

Also known as:IAB

Initial Access Broker: Actor who obtains and sells compromised access to organizations. The term is relevant for the assessment and design of modern security architectures and should be applied within the specific technical and organizational context.

How it works and where it fits

Technically, Initial Access Broker describes an attack path or a concrete method rather than a single suspicious event. A sound assessment separates prerequisites, entry point, objective, intermediate steps, and expected effect. The same technique can produce very different outcomes depending on system architecture, available privileges, exposure, and existing safeguards.

Practical security relevance

In practice, both preventive measures and observable traces matter. Secure configuration, restricted privileges, robust input and identity checks, and telemetry at affected trust boundaries all contribute. A single indicator rarely proves an attack; reliable detection, containment, and remediation require the combined context of timing, source, target, and observed impact.

  • Threat ActorThreat ActorAn individual, group, or organization that intentionally carries out or supports cyberattacks.: An individual, group, or organization that intentionally carries out or supports cyberattacks.
  • Cyber Threat IntelligenceCyber Threat IntelligenceProcessed information regarding threat actors, tactics, indicators, and risks.: Processed information regarding threat actors, tactics, indicators, and risks.
  • Incident ResponseIncident ResponseA structured process for the preparation, detection, containment, eradication, and post-incident review regarding security incidents.: A structured process for the preparation, detection, containment, eradication, and post-incident review regarding security incidents.
  • Incident TriageIncident TriageRapid classification and prioritization of a potential security incident.: Rapid classification and prioritization of a potential security incident.