ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Cosplayers and the cyber security learnings from Comic Con 2021

alternative identities large.jpg
alternative identities large.jpg

David Higgins at CyberArk explains how cosplayers can shine a light on cyber threat actors’ tactics

 

Comic Con, which took place in San Diego at the end of November, is one of the most prominent events on the calendar of every movie and comic fan and famous all around the world. One of the reasons the event is so well known is the ‘cosplay’ spectacle it produces; tens of thousands of attendees from around the world gather together to impersonate key actors and characters in pursuit of access and attention.

 

Cosplayers can imitate famous actors and characters scarily well. So well that it’s often difficult to know what their true identity is, and who is lurking beneath the costume. It’s a fascinating phenomenon that compares to the identity challenges faced by the cyber-security industry, with threat actors often hiding in plain sight on networks, ‘cosplaying’ as legitimate users.

 

Given the similarities between cosplayers and threat actors, this year’s Comic Con reminds organisations that alternative identities are regularly adopted not just in the physical world but in the digital world too. Continuously strengthening their cyber-security practices to prevent those with malicious intent from causing havoc - using compromised human or even machine identities - should be seen as essential.

 

Cosplay for malice

The security industry has been doubling down on identity as a an essential security control for some time. But before we delve into best practices, let me take a moment to explain why comparing identity security with cosplay can prove valuable for security professionals.

 

Cosplay in itself usually focuses on fictional characters – so, no matter how convincing an assumed identity is, we know the likelihood of the ‘real’ Hulk, Wonder Woman, or Captain Marvel standing in front of us is pretty low.

 

While their motive or end goal might differ, threat actors use these same imitation tactics for more malicious reasons. They look to commandeer ‘privileged’ accounts, escalate access to move across a network, and steal critical data and assets – all without detection as they masquerade as a user or machine, hiding in plain sight within an organisation’s network.

 

This is a privileged escalation cycle we see often, and is difficult to assess whether the identity associated with these behaviours is an employee going about their job as they would normally do, or an attacker with malevolent intent. The ramifications of apathy and not acting in such a scenario can be severe, so action should always be taken to authenticate each and every user on the network.

 

Seeing through the disguise

Like cosplayers, threat actors are also very good at changing character. For example, they use impersonation techniques to gain access into networks through phishing or via a supply chain attack. Attackers will take on multiple identities to progress their attacks.

 

Cyber attackers are always looking for the easiest route of entry. Practising solid cyber hygiene to try and prevent this should be a given, but the reality is keeping attackers outside of a network is difficult. After all, it’s nigh on impossible to tell who the genuine character is from a room full of cosplayers who look exactly the same! Inevitably, someone with a false identity will slip through the net.

 

But to do damage to an organisation, those threat actors that gain initial access will need credentials to move laterally within a network. That’s why identity security is so crucial.  It offers a range of controls for both applications and infrastructure, including automatic rotation of credentials, and strong authentication for the retrieval of valid credentials by authorised users.

 

All of this makes it easier to verify the identity of users and their associated privileges and credentials, lock down access to all high-level administrative accounts with access to infrastructure and, ultimately, make it far tougher for an attacker to carry off a convincing (cyber) disguise.

 

But it’s not just the disguise of how someone looks that must be taken into account. Often those in costume can be identified as being an impersonator by the way they behave, even if they initially look very convincing. In person you might identify them by how they sound or how they walk, and the same should be taken into account when trying to uncover digital imposters.

 

By authenticating based on their location, device and previous activity including geo-velocity (to see whether it’s physically possible for them to have travelled from their last known location to the current), businesses can be much better equipped to weed out the imposters, rather than simply basing decisions on whether someone looks in character. 

 

The final fundamental weapon in the defence against rising threats is that of Zero Trust. Trusting that everyone who has access to an organisation is who they say they are, without verification, is comparable to truly believing that every Hulk spotted at the ‘Con was the real deal.

 

None of us would believe them without asking them to prove their identity, right? In the same way, organisations shouldn’t automatically trust any user with access - whether they’re outside or inside its network perimeter - until they can prove their identity. So, implementing a Zero Trust model, in which user access to applications is protected with controls such as multi-factor authentication and adaptive authentication, adds a further security layer.

 

A battle won before it begins

Cyber-attacks are inevitable, with threat actors continuously accelerating and innovating their tactics, techniques and procedures to target and infiltrate organisations. As a result, the only effective way to defend against cyber-attacks is to take a proactive approach to defending your critical assets and information – don’t wait until attackers take their mask off to launch your defence.

 

Cyber-security protections such as Identity Security tools and a Zero Trust approach need to be integrated into the daily operations of every organisation. As the recent NCSC Annual Report has shown, no sector or organisation size is exempt from the devastating effects of cyber-attacks, so all should be looking to have a well-equipped arsenal at their disposal to defend against nefarious villains posing as everyday heroes.


David Higgins is EMEA Technical Director at CyberArk

Main image courtesy of iStockPhoto.com

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543