I mean there are literally controls for this. PIM? You can build systems where your administrators need approval to literally log into the environment. Where their privilege escalation is logged and alerted on. Change Management? "Hey what are you doing logging in, theres no scheduled change for your account". Social Engineering, even of the most critical elements of your engineering team, is a solved problem. What people lack is the willpower and commitment to implement these solutions.
Applies to users too. I sometimes think that a lot of HN commenters havent read a security doc in 20 years.
>keep them from exfiltrating any information they want by targeting not the system, but the users:
User tries to log in to download sensitive information to hand it to the guy on the phone. IT gets an alert, discusses the situation with the user and begins investigating the incident.
Even just SoD mitigates this risk by like 99%.
https://hightable.io/iso-27001-annex-a-5-3-segregation-of-du...
You throw modern PIM/TBAC/RBAC tools, Logging and Alerting on to that and the LLM is just as busted as any other scammer.
"Hey guys I need to elevate my account privileges to download all our important company data and send it to our CEO who is currently in Russia for some reason"
"No"
The problem isn't that we cant solve these problems, the problem is that most businesses couldnt be assed to even try. Unless they are enforced by compliance, 99% of businesses wouldnt begin implement this stuff. They need the pain of getting busted before they go "Hey lets not lose more money". Your average startup derived business is just some guy with admin rights to everything and a certificate auth if you are lucky.
Most businesses will have a locked box, and registration forms to check out important Keys to access different areas of the building, but you ask them to go through the process of lodging a request to access their most sensitive information and its just "Nah mate just give them god rights".