Talk to us Risks to Watch

Modern IT Infrastructure demands Low Friction and High Security

ARCON’s marathon with the virtual summits continues! To expand IT security awareness among global enterprises amid digital transformation, ARCON participated at the CIO Axis Roundtable Summit 2020 on 20th August 2020. Mr. Anil Bhandari, the Chief Mentor of ARCON was the speaker of a keynote session discussing the transformation of the current state of cybersecurity by reducing the friction and striking the right balance between IT security and user experience.


Key Takeaways from CIO Axis Summit

While speaking on “Bridging the Gap between Low-Friction and High-Security Identity Management” at the summit, Mr. Bhandari enthralled more than six hundred attendees in his concrete 20 minutes session. The major takeaways from the summit are as follows:

  • Identity with a VPN and device-based security is getting obsolete in today’s user behaviour-centric security technologies. The recent advent of a remote workforce is driving the core of IT security more towards suspicious user behaviour rather than just restricting access to critical systems/ devices.
  • Today CIO community agrees on “More the authentication that you require, more the challenges a user has to go through” – which means the trend is taking us towards more of a state where less number of user authentication processes provide more access control security. This means, just because you have multiple authentication mechanisms it doesn’t mean that there is strong security in your IT environment. It can lead us towards a high friction zone where the robustness of Identity Security might turn low.
  • The most interesting model of IT security today is an outcome-based model where organizations get inclined more towards a fruitful result than just deploying a traditional security mechanism. For instance, in banks, we no longer just deposit our money just to keep it safe, we calculate and check out the amount of return we can get from just depositing it for a certain period. Another interesting use case is from the education industry where the students are more targeted as per their skills and key expertise rather than just providing general education to one and all.
  • The entire world is getting inclined towards an automated IT security model where the users, privileged users, super admins – all are monitored in real-time and their access to critical systems is time-bound.
  • In the virtual world, Low-friction is a necessity today. We are dwelling in an era where high-security is prioritized by any and every organization everywhere. Low-Friction ideally means the ability of the end-users or rather the daily IT operations team to have an experiential outcome whatever application or critical systems they access inside the organization very seamlessly. That would raise productivity towards a high level with a robust IT security. ARCON as a brand with advanced risk-preventive solutions always improvises on the solution features according to this “Low-friction and High-security” model.
  • Just-In-Time Privilege Security tool offers the best Privileged Access Management practices by removing the risk of standing privileges with the principle of least-privilege principle. It nullifies the chances of data breach incidents majorly by malicious insiders or unrecognized third-party by misusing privileged rights.

Privileged Access Management – An Overview


Key Takeaways from IndoSec 2020

The latest trends in adopting digitalization continue to happen across the globe. At the same time, security vulnerabilities are also arising rapidly and simultaneously. The digital ecosystem is turning worrisome day by day. Recently Mr. Anil Bhandari, the Chief Mentor of ARCON was the speaker of the keynote session on “NextGen Approach to Digital Identities & Vaults” at IndoSec 2020 virtual conclave on 26th August 2020. The key takeaways from the session are –

  • Today, data breach is a common incident. Hacking techniques are turning sophisticated day by day and even big names are not spared. Both on-prem and cloud infrastructure today are prone to cyber threats. Almost 47% of organizations store data on the cloud, third-party servers and hybrid environments which expands the threat surface.
  • Password Management has been observed to be the most discussed yet most neglected part of IT security. Almost 70% of organizations even today manage passwords manually which increases risks.
  • Low-friction High-Security” methodology has become the need of the hour due to WFH scenarios across the globe. The entire world is working on virtual access where people are working remotely, earning from home and students are learning from virtual classrooms. In this backdrop, as ARCON experienced with most of its customers, VPN access, slow internet, IT security remains the major areas of concern.
  • During the pandemic, organizations had to spend thousands on laptops and are struggling to overcome various access challenges such as limited access licenses, slow access, user access permissions, critical data access, privileged access, just-in-time access etc. As a result, the “High-Friction Low-Security” methodology has taken the front seat with a lot of daily IT operations challenges across the enterprise network.
  • High-frequency authentication might not lead to higher security. This results in immense frustration from the user point of view because once the authentication processes happen at multiple levels with multiple times, the robustness of the security might turn low especially in the remote workforce.
  • ARCON recommends ring-fencing critical identities in an enterprise to ensure smooth IT operations. The conventional controlled access suggests end-users to be on software applications and super-users on software Apps. The attackers always try to gain access to super-user passwords because super users provide complete control of the critical systems.
  • Almost 72% of the respondents agreed that privileged identities are major areas of concern. Even in today’s time, when the entire CIO community shouts for robust privileged access security, the organizations are still way behind materializing the necessary deployments. Multiple data centers, critical systems, database servers, business applications, operating systems or even critical devices are accessed through privileged identities which multiples the risk each and every day.
  • The device population is exploding significantly across the globe. While the world has 7 billion people, the number of devices has gone up to 15 billion and is expected to reach 50 billion in the next ten years. IoT, APIs, BOTs are coming up significantly across the globe and the number of identities is going to skyrocket in no time. Hence, protecting these identities from malicious elements is the last thing that we would look forward to.
  • Work From Home (WFH) practice has necessitated the implementation of secured remote accesses to business-critical applications and systems. Organizations require a robust IT security mechanism to manage, control, monitor remote access and the IT risk management team is more agile in establishing trustworthiness.
  • Social Media is one of the simple yet critical areas where organizations are spending bombs to ensure secured access to the accounts. If the social media activities are controlled and managed by third-party agencies then the risk increases exponentially. But are they taking adequate measures to secure the shared credentials? Organizations allow external agencies to handle the social media activities and a single mistake anywhere might lead to a massive cyber catastrophe.
  • ARCON even discussed high digital investments where business models, business modules and overall IT security are taking a different turn. With outcome-based models, organizations are more inclined towards user behaviour centric security rather than conventional device-centric security. In the age of automation, monitoring the users and their activities is drawing more attention rather than just preventing them from accessing business-critical applications or systems.
  • Lastly, keeping the demand for Zero Trust security infrastructure in mind, ARCON’s security solutions are always a step ahead with the robustness of risk-predictive mechanisms rather than risk-preventive ones. The Predict | Protect | Prevent model of ARCON enables us to build a Zero Trust framework around privileged identities.

The Bottom-line:
The entire world is gearing up for a digital age where automation is going to take the front seat in every industry. For this, monitoring super-users and their activities are going to be the most-sought security requirement in all geographies. Prediction of cyber risks is more prioritized than preventing risks. ARCON participating in virtual IT conclaves are always emphasizing identification of the trustworthiness of the users rather than just preventing them from accessing critical systems or applications.

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.

ISACA and ISOG: Key Takeaways from Two Major online IT conclaves

ARCON created quite a buzz in a couple of back to back virtual global events recently. The keynote sessions by Mr. Anil Bhandari, the Chief Mentor of ARCON, on both the occasions added immense value to the knowledge-sharing and learning platforms. Here is a brief account of the sessions.

On 29th July 2020, ARCON shared the views on “2025: A Watershed year in Information Security” through the voice of Mr. Bhandari in ISOG (Information Security Officers’ Group) event, Philippines. While Philippines is holding the fifth position on the list of cyber-attacks (as per BusinessWorld report), this virtual event hammered on the awareness of modern IT security solutions in entire south-east Asia. With the IT environments changing rapidly in the region, cyber incidents are also rising exponentially. Virtual ISOG, in this juncture, fueled the security preparedness where ARCON extended its helping hand with the exclusive inputs for a secure modern IT infrastructure. Needless to say, hundreds of attendees warmed up their seats to acquire relevant inputs from this session.

Privileged Access Management – An Overview

Key Takeaways from ISOG

  • Huge transformation of digital habits globally due to the ongoing pandemic. A few industries consider this to be the worst phase of business whereas many take this phase as a ‘business opportunity’. Common users have started to fulfill their common needs through digital means where education (different learning apps) or daily essentials (people bound to order online) are not spared. It resulted in a whopping rise in the usage of apps and portals and thereby generating revenues.
  • More number of users going digital means more amount of data generation. The huge amount of data generated through day-to-day IT operations invariably requires the most stringent cybersecurity solutions to prevent any kind of malicious element to affect data sanctity of the enterprise.
  • How multiple organizations (with examples from different industries) adopted a change of business strategies, IT security policies, incorporation of new technologies to cope up with the ‘new normal’ trends.

On 4th August 2020, ARCON added value to another speaking podium, thanks to Mr. Bhandari again, with his views on “Positioning Privileged Access Management in the Problem Space: Why is it required?” at ISACA (Information Systems Audit & Control Association) South Africa Virtual Conference. The South Africa chapter of ISACA is the largest chapter of the Africa region covering Cape Town, Johannesburg, Pretoria and Durban. Incidentally, South Africa has observed a steep rise of 22% more cyber incidents in the last six months. This gives a clear indication that malicious actors are eyeing on the organizations of this region for lucrative data assets. At this juncture, virtual ISACA offered a much-needed reiteration of IT security awareness among nation-wide enterprises to be acquainted with risk-free IT operations. Hundreds of business leaders in Information Technology, cybersecurity, governance, risk and innovation attended this keynote session.

Key Takeaways from ISACA
This entire session revolved around the importance of ARCON | Privileged Access Management (PAM) and the technological understanding of the USPs of the solution. The below facets were discussed:

  • General introduction of ARCON with business history and corporate values. ARCON is ceaselessly working on the focus of Predict | Protect | Prevent since its inception and how it has created a demand for risk-predictive solutions in every corner of the globe, especially in the last few quarters.
  • Taking through the flagship solutions of ARCON namely Privileged Access Management (PAM), User Behaviour Analytics (UBA) and Secure Compliance Management (SCM) which are driving the security trend towards predictive analytics of user behaviour rather than just device-centric security.
  • Today organizations are making huge investments on advanced technologies based on AI and ML. However, paying scant attention towards IT security aspects after adopting these technologies might drive organizations to face hefty penalties, thanks to the global regulatory bodies. ARCON | PAM complies with all standard regulatory requirements across the world including EU GDPR, HIPAA, PCI- DSS, SOX, ISO 2700.
  • ARCON | PAM offers an array of features that includes Granular level access control, Single Sign-On, Multi-factor Authentication, Password Vault, Just-In-Time Privilege, PEDM (Privilege Elevation & Delegation Management), Session Monitoring, Audit trails, Virtual Grouping, Live Dashboard, Customized reporting with Text & Video logs. These help the organizations to ensure seamless IT operation with zero downtime and no cyber incident.
  • Single Sign-On is a must for the modern IT environment since the Admin IDs, Root IDs, SA IDs are completely distributed and shared including the passwords. These critical IDs have the rights to create, delete, undo and redo activities including the logs which means these IDs can siphon off anything that could lead to downtime. This necessitates the worth of SSO with single-window access.
  • A robust Access Control mechanism where “need-to-know” and “need-to-do” basis access is given utmost priority. The access to the users can be restricted role-wise, day-wise, time-wise or even single-time access which removes the chances of malicious activities in the network. Even elevated rights given to any specific user for a specific task are revoked immediately after the task is accomplished. That’s how “always-on” privileged rights are avoided and security is restored round the clock.
  • A detailed session log in video and text format offers a seamless vigilance over the user activities and any kind of deviation from the baseline activities is intimated immediately to the super admin.
  • A robust Password Control rotates and randomizes passwords frequently for all devices and for all IDs. This engine creates a centralized secure repository of passwords for multiple systems so that no password can be duplicated under any circumstance. Privilege password vaulting assists the IT administrators to adopt a robust privileged access management practice.
  • ARCON offers an outcome-based model where a secured virtual access is offered for on-prem, in-cloud and hybrid data centers. This feature has moved a step ahead with the on-going demand for remote access scenarios where the day-to-day IT operations in multiple levels are happening remotely. ARCON | PAM creates a security shield there as well.
  • ARCON envisages comprehensive security under one roof with all the three solutions and protects the organizations from targeted attacks and zero-day threats.

The geography of Africa and APAC has always been promising and lucrative in terms of business opportunity. The global pandemic has changed the entire scenario of IT security. The demand for IT security has created a new realm in the world of digital transformation. Most of the organizations emphasize the awareness of modern IT security and thus, the importance of Privileged Access Management (PAM) is rising rapidly. ARCON received overwhelming responses from both the sessions and it is looking forward to participate in the next phase.

ARCON is a leading enterprise risk control solutions provider, specializing in risk-predictive technologies. ARCON | User Behaviour Analytics enables to monitor end-user activities in real time. ARCON | Privileged Access Management reinforces access control and mitigates data breach threats. ARCON | Secure Compliance Management is a vulnerability assessment tool.