Talk to us Risks to Watch

ARCON hosts exclusive webinar for East Africa on Privileged Access Management

On 28th July 2020, at 11:30 am EAT, ARCON Tech Solutions organized an exclusive webinar for the East Africa region. The topic was: Predict, Protect, Prevent: Modern Security Paradigm for Modern Enterprises. 150+ attendees from India, Kenya, Nigeria and South Africa attended the webinar. Aditi Jain, from the product development team, represented ARCON and delivered a presentation on the importance of Privileged Access Management (PAM) in modern enterprises.

Key Takeaways from the Webinar

The session was on the modern security paradigm, hence the exponential growth of privileged identities was the most crucial part of the discussion. The entire session revolved around the importance of ARCON | Privileged Access Management (PAM) where the below facets were discussed:

Headline-making data breach incidents across the globe every now and then are ringing the alarm bell to the IT risk management teams from all enterprises to adopt adequate security measures. More than 71% of organizations today have confessed that they have suffered unusual data breach attempts in the recent past. If not now, then when should we find out the root cause?

Why is the threat surface expanding? 47% of organizations store data on IaaS, MSP or hybrid environments which expands the threat surface. Organizations, very often, leave the vulnerabilities around the access control mechanism of privileged identities. These are exploited by the malicious actors.

The Rapid growth of IoT leads to an increase in the number of privileged identities, the number of applications and the number of devices which require seamless monitoring to detect any kind of anomaly in the network.
Why are Privileged IDs the major area of concern? 72% of organizations admit that their major concern remains with the access control and seamless monitoring of the privileged IDs and the privileged user activities. These IDs are the gateways to most of the confidential business information and thus, are always vulnerable to threats.

Who are the Privileged users? Privileged users are the elevated users who possess the privileged rights to access, create, delete or modify the configuration of critical systems, data centers, databases, applications or even network servers.

What is the reason behind the vulnerability of Privileged Passwords? Privileged IDs with poor password management is one of the biggest loopholes in IT security. While 70% of organizations admit that their default admin passwords are managed manually, ARCON | PAM ensures a robust password management with Password Vault.
ARCON | PAM now mandates all the standard regulatory requirements across the world including EU GDPR, HIPAA, PCI DSS, GLB, SOX, ISO 27001 etc.

ARCON | PAM offers an array of features that includes Granular level access control, Single Sign-On, Multi-factor Authentication, Password Vault, Just-In-Time Privilege, PEDM (Privilege Elevation & Delegation Management), Session Monitoring, Audit trails, Virtual Grouping, Live Dashboard, Customized reporting with Text & Video logs.
In addition to ARCON | PAM, the other two solutions namely ARCON | User Behaviour Analytics (UBA) and ARCON | Secure Compliance Management (SCM) mitigates malicious activities and assesses security vulnerabilities respectively.

ARCON envisages comprehensive security under one roof with all the three solutions and protects the organizations from targeted attacks and zero-day threats.

Privileged Access Management – An Overview

In the geography of Africa, most of the organizations emphasize on the awareness of modern IT security and thus, the importance of Privileged Access Management (PAM) is rising rapidly. To meet the demands and reach out to more key people in the industry at a single point of time, ARCON organized this exclusive region-specific webinar. In a nutshell, this webinar paved the way for more similar sessions in the coming days, thanks to the overwhelming response. Till then, stay tuned.

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.

Banyan Tree and Privileged Accounts: Tales of two uncontrolled expansions

Have you ever heard about 250 years old ‘The Great Banyan Tree’, in the AJC Bose Botanical Garden, Kolkata, India? The vastness of the tree is almost the size of a Manhattan city block with 80 ft high and an area of 14,500 square ft. The number of roots and prop-roots of this banyan tree has surpassed 3600 and it has been a real botanical wonder since ages.

The growth of a banyan tree never depends on the changing weather. The number of prop-roots of a banyan tree keeps on increasing to meet the demand for adequate nutrition and so are its branches. This growth is uncontrollable and is surprisingly similar to the growing IT infrastructure of a modern-day organization, where the number of privileged accounts and the types of privileged accounts are ever-expanding.

Both banyan tree and privileged accounts are vulnerable to human greed
A rising human intervention majorly due to greed and callousness disrupts natural habitat. Deforestation not just affects banyan trees, but any tree in the world of flora. However, the prop roots of a banyan tree are always targeted more by axes because of the quality of wood from a single tree. In a similar way, the escalating number of malicious insiders, unauthorized third party users and organized cybercriminals target privileged accounts. These suspicious actors compromise privileged credentials to access critical systems and breach confidential business information. This way the organizations face continuous threats of heavy financial losses, data loss and reputation damage.

Privileged Access Management – An Overview

Only human awareness, preventive measures, consciousness and realization of the adverse effects of deforestation can save banyan trees from being extinct. A tree itself doesn’t have any control over this probable destruction since humans are a greedy lot.

Likewise, unpredictable activities in the enterprise IT infrastructure can be controlled by preventive IT security measures with the help of Privileged Access Management (PAM) and User Behaviour Analytics (UBA). Privileged Access Management (PAM) solution offers seamless monitoring of the privileged activities in the network and ensures a rule and role-based access control policy to keep unauthorized users at bay. Similarly, User Behaviour Analytics (UBA) helps in building up a robust detection mechanism in the IT infrastructure where suspicious user profiles are notified to the IT administrators, which allows nip the threat in the bud arising out of malicious insiders.

What’s so common between the kingdoms and IT ecosystems?

Do you remember the infamous historical character from the battle of Plassey? The chief commander of the Nawab of an East Indian province became an embodiment of betrayal after the historic loss in the battle. The culprit misused the blind trust and faith that his nawab kept on him and eventually allowed the British troops to conquer the land. Who knows if the Nawab would have verified this trustworthiness, maybe the history would have been different? Trust, once lost, can never be retrieved – similarly, the loss which incurs from a mistrust is rarely recovered.

What is the moral of the story?… never assume the ‘trust’ but always reassess it.

A modern IT ecosystem is no different from a fallen empire where a major part of the infrastructure security relies on reassessing the trust. For any IT ecosystem, privileged identities hold the key to the ‘kingdom’ of confidential business data. If any of those identities breach the ‘trust’, it could result in a catastrophic IT incident.

The IT environment that is capable of defending both internal and external threats and can continuously re-assess the trustworthiness of privileged identities, is the strongest “commander” of the organization. Therefore building a Zero Trust architecture, wherein the ‘trust’ of every identity is continuously evaluated is of utmost importance.

As the global organizations are prioritizing health and safety due to the on-going pandemic, employees and employers are increasingly getting accustomed to remote work culture. It’s a huge security challenge especially when end users remotely access business-critical information. Traditional firewalls can no longer offer the same extent of IT security for employees who are logging remotely.

Further, distributed data centers, adoption of cloud environments and integration of IT operations with third-party service providers have expanded the threat surface. This is where the Zero Trust security framework becomes crucial.

Why does your enterprise need ARCON | Privileged Access Management?

The crux of ‘Zero Trust’ security model

Banking, Government, Insurance… Almost all industry verticals are adopting this new security architecture. So what exactly is it? How different is the Zero Trust framework from the others?

The Zero Trust security model is a conventional shift from a perimeter-centric security approach to the data-security centric model. This model challenges the conventional model, which is more inclined towards perimeter (network) security… focus is on firewalls and advanced tools like network intrusion detection systems.

More importantly, the conventional models assume that there is no threat inside the inner IT realm. That notion is wrong. If that’s the case then why are we witnessing the abuse of privileged identities so often?

On the other hand, the Zero Trust model never assumes ‘trust’ but it continuously assesses ‘trust’ using risk-based assessments available from information gathered. Secondly, the model rightly assesses a modern-day enterprise IT ecosystem, which is distributed. Users access to databases and applications is not only happening from on-premises data centers, but from remote and third-party environments as well.

Resultantly, the model says there is an urgent need to have a unified data security policy for all applications and databases, which can be done by constructing semi-perimeters and semi-segmentations, so that access to every database and application is secure, controlled, and documented. ‘Deny all access, until the identity’s trust is verified’… that’s the need of the hour.

ARCON | Privileged Access Management (PAM) solution helps organizations to build the foundation of Zero Trust architecture. The tool is built on the credo which is ‘Assessment of trust is not a one-time task, it is a continuous process’ and therefore, “we trust you, but we will continuously assess the trust’.