Introduction
Altria is a Fortune 500 manufacturer in one of the most heavily regulated industries in the US, subject to FDA oversight, the PACT Act, and SEC cybersecurity disclosure requirements. A breach here is not a technology problem. It is a business risk, and in this industry, an existential one.
The way I think about identity risk comes down to one observation: attackers do not go after data first. They go after identity infrastructure. The data is the reward. Active Directory is the key.
The Moment of Fit: Seeing Dependency, Not Just Data
The turning point for me was a specific capability: Orchestrated Recovery. Before, we were recovering data blind and hoping the pieces fit back together. When I saw that Rubrik could show the dependency between different identity objects, the investment decision became clear.
The timing mattered too. Our identity footprint was expanding through acquisitions and international growth, adding complexity across multiple companies and platforms. The need to recover fast under those conditions was not hypothetical.
One thing that sharpened the urgency: on-premises Active Directory and Entra ID are two different identity planes, and recovery order matters. Bring systems back in the wrong sequence and access breaks across the board. Most organizations protect one plane and assume the other is covered. We needed a platform that handled both, in the right order.
Practitioner Tip "Fragmentation across identity platforms is invisible until you need to recover from one. If your AD, Entra ID, and IAM tools cannot show you dependency relationships between objects, you end up correlating identities manually during the exact moment you need speed most." |
Funded by the CISO, Not Infrastructure
We did not frame Rubrik as a backup tool. From day one, we treated it as a cyber resilience platform, and that framing determined where the funding came from. Instead of routing the investment through infrastructure or CTO budgets, the project was sponsored by our CISO and funded through IT Risk Management. That sponsorship is a key reason the implementation moved forward at the pace it did.
100% Compliance, and an Existential Risk Taken off the Table
On the on-prem data center deployment, we achieved 100% compliance. The more meaningful change was operational: our team moved from a multi-step manual recovery process spanning multiple days to recovering directly from backup, with identity object dependencies visible within the platform. What used to take days of forensic work now happens in hours.
The harder problem is not the attack itself. It is realising mid-recovery that you do not know when your identity infrastructure was first compromised. Having verified, clean recovery points across both AD and Entra ID changes that. The question shifts from "which snapshot can we trust" to "we know exactly where clean is."
"There's a difference between having an identity recovery plan and knowing your recovery plan works. We know ours works."
Invest in Recovery, Not Just Detection
Practitioner Tip "My advice to other enterprise architects is simple: most organizations over-invest in prevention and under-invest in recovery. MFA, conditional access, and privileged access management all matter, but none of them answer what happens when an attacker gets through. At Altria, we went from days of manual forensic recovery to hours of orchestrated restoration. In a regulated industry, that difference is significant, and framing it as a cyber resilience decision rather than a backup line item is what gets the right funding and the right urgency." |
The same principle applies as organizations expand into AI and deeper SaaS integrations. Protecting AI environments means covering three layers: the model artifacts themselves, the source systems the AI reads from, and the production systems it writes to. As service principals and managed identities multiply across SaaS platforms, identity resilience is an expanding problem, not a solved one.
Contributed by

Kiran Pakkir
Sr Manager, Enterprise Architecture, Altria Group




