Talk to us Risks to Watch

Why is the Education Sector being Increasingly Targeted by Cyber Criminals?

The Context:

When we talk about data security, we think about financial institutions, banks, government organizations, telecoms, or maybe healthcare companies. Seldom do we think about the education sector. In recent years, the education industry has faced an uphill battle in protecting and securing data day in and day out.

According to Forbes, data theft and data misuse have increased by more than 50% in the education sector since 2022. The digital identities and personal information of students and teachers are targeted by cybercriminals. The education industry is the latest treasure trove for personal information.

The entire education sector has shifted to virtual mode after the global pandemic hit the world. Even in the post-pandemic age, the trend of “virtual classes” has become an option for both students and teachers. To learn the alphabet, solve mathematical problems, know historical facts, and teach chemical formulas, both students and teachers are counting on smartphones, tablets, laptops, and desktops instead of green boards or whiteboards.

Not just in virtual classes, but also for the administrative procedures in schools, colleges, and universities like new admissions, preparing academic calendars, examinations, or even report cards, have gone digital for convenience and safety.

Hence, the question has started to linger: Are digital records and personal identifiable information safe and secure in schools, colleges or universities?

Some Recent IT Incidents:

Year        IncidentWho did it?
2021Cyber attack on third-party service Atlassian by gaining unauthorized access through a known vulnerability at a US-based universityUniversity was preparing to update a new version of Atlassian software when the culprits took advantage of the access vulnerabilities of the transition phase
2020Ransomware attack costs around $1.14 million in two US-based universitiesOrganized cyber criminal group gained unauthorized access to the sensitive university data and threatened to expose the data if ransom is not paid as per demand 
2021An Australia-based university admits data breach of 5000 individuals including, staff, students and external third-partiesOrganized cyber criminal group
2022One million students’ data from a India-based university has been stolen and offered for sale on the dark web – the data includes students’ information, registration numbers, students’ email Ids (including passwords) and more.A dark web hacking forum

Each and every incident  above shows how organized cyber criminal groups, unknown hackers, or even insiders are responsible for data breaches. 

Why are Educational Institutions Challenged with Security Vulnerabilities?

The regulatory IT compliance standards are applicable to each and every industry across the globe. The education industry is also one of them. Compliance with the regulatory standards is for the benefits of the educational organization and its goodwill. 

Now, the question is, do educational institutions follow the norms, rules, and regulations of standard compliance policies? How do they ensure that every personal and sensitive student’s data in their system is secured and encrypted?

What is lacking in most universities or any institute is a dedicated IT security team who can continuously manage and monitor the data that is generated and accumulated in the systems regularly.

Modern schools and colleges have exclusive applications from which students can check every detail of their academic calendar, regular assignments, academic records and other important announcements. Moreover, these applications are also accessed by the parents of students who can pay their school/college fees online through the app. 

As a result, the applications have hundreds or maybe thousands of digital identities of the students’ details, parents’ details, payment details, contact details, and more. This accumulated huge size of personal information and dynamic data necessitates a dedicated IT security team. There is an urgent need to have a dedicated team to keep check on network intrusions, and practice robust identity governance and management to secure critical information, SaaS applications and users’ data. 

How can Educational Institutions overcome Security Vulnerabilities?

In this digital age, everything boils down to managing data and securing passwords. It is highly imperative for students and their guardians to ensure that they protect their passwords by changing them regularly. At times, there are instances of reminders from the application that state “your password is more than 60 days old”. It is always advisable to take such notifications seriously and keep on changing and rotating the passwords at regular intervals. 

On the other hand, school, college, or university authorities need to have a comprehensive mechanism to continuously monitor the logins and what activities are happening in the system or application during login hours. It will help them to quickly detect any kind of anomalous action happening in the network and take necessary action regarding the same.

Educational institutions must have foolproof security mechanisms for their applications, database servers, and network devices. Every day, hundreds of users use their authorized identities to access critical applications. Sometimes, with the help of privileged identities, organizations access confidential information about universities. Educational institutions need to authorize, authenticate, and monitor every session’s access to target devices and applications.

Besides, it is always necessary:

  • To have a secure gateway for accessing critical IT services of the organization
  • To secure, vault and encrypt passwords especially those for the privileged accounts 
  • To do comprehensive audit trails– capability enabling the security team to log daily changes executed in a secure and reliable way for administrative task

Conclusion:

Universities and educational institutions are an attractive target for compromised actors such as organized cyber criminal groups, malicious insiders and suspicious third parties. As personal information sells on the web nowadays, this commercialization incentivises them to steal sensitive information. Therefore, it is important to have adequate IT security measures in place to safeguard personal information. 

Why Are Cyber Insurance Companies Demanding PAM Solutions?

The Context:

In our earlier blogs, we have discussed how and why cyber insurance has become such a relevant part of overall corporate planning. Organizations with definite pre-set goals for their cyber security policy and posture are opting for cyber insurance without any second thought. 

And it is interesting to note the growing importance of privileged access management in the backdrop of the growing cyber insurance market. Cyber insurance companies want organizations to comply with mandates such as PCI DSS, HIPAA, ISO 27001, SOX. 

Globally, cyber insurance companies are keeping a requirement for organizations to implement Privileged Access Management (PAM). Cyber insurance companies are making PAM solutions a mandatory safeguard as a condition of their cyber insurance coverage. 

The rapidly growing size of business-sensitive data due to the increased pace of digitalization and increased threats to that data from insiders and third-parties are prime reasons behind cyber insurance companies’ demand to meet the compliance standards. 

Implementing these mandates enables organizations to build a robust compliance framework. Privileged Access Management also assists IT security risk management teams in meeting most security mandates such as password rotation, rule and role-based access, data encryption, session management, and so on.

Notably, in the latest report: “2022 Critical Capabilities for Privileged Access Management“, Gartner has predicted that by 2025, 75% of global organizations will mandate the usage of Just-In-Time (JIT) privilege access management. In this report, Gartner has also emphasized that regulatory frameworks and cyber insurance providers are demanding comprehensive PAM tools to stay compliant. 

Why Privileged Access Management?

Privileged Access Management (PAM) solutions have long been at the top of IT risk management teams for securing dynamic and complex IT environments. Whether the IT infrastructure is on-premises or on IaaS, PaaS platforms and/or data is processed on SaaS applications—the significance of PAM has increased as it closes the breach vector.

A full-blown PAM solution such as ARCON | PAM offers adequate features and functionalities to secure organizations’ data, digital identities, secrets, credentials, APIs, and other forms of sensitive data. However, in this article we have discussed three basic reasons why PAM has become an indispensable solution for overall security.

Mitigating Insider and Third-party Threats: Malicious insiders and suspicious third-party users are the major reasons behind the increase in data breaches worldwide. Many insiders, especially users with elevated rights to applications, databases, and other forms of sensitive information, are typically aware of what and where the critical data is generated and stored. 

Recently, the threats have increased due to the proliferance of hybrid work conditions, and in the case of insider attacks, it takes a lot of time to realize and identify that a data breach has occurred. According to Forbes, 49% of organizations agreed that it takes an average of one week to identify insider attacks, which worsens the situation. 

Just-In-Time (JIT) Privilege: A robust Privileged Access Management (PAM) solution ensures deployment of the ‘Least Privilege’ principle and reinforces the Just-In-Time (JIT) privilege approach. Due to the rapid increase in the number of privileged accounts and privileged identities in the current IT context, the risk surface has increased significantly. 

IT administrators manage and monitor a few privileged identities that access critical systems, network devices, databases, and other applications. The security risks coming from privileged access misuse have multiplied given that SaaS applications have proliferated significantly. There is fast adoption of other cloud services such as DevOps engineering, virtualization, and containerization.

The Just-in-Time (JIT) approach assists IT administrators in mitigating application misuse by reducing unnecessary 24×7 access to them. The JIT approach is nothing but a stepping-stone to ensure that the risks of data breach incidents are mitigated while practicing the principle of least privilege. 

Behavioural Analytics: End-user behavioural analytics has become a critical requirement for IT administrators in the age of Zero Trust and remote work environments. This threat detection technology learns every user’s behaviour based on their historic records like login history, login time, IP address, etc., and predicts risks on that basis. A PAM solution such as ARCON | PAM offers an AI and ML based threat detection capability that helps organizations detect, predict, and display anomalies in their logged systems. 

Conclusion:

Today, cyber insurance is no longer an option; it is mandatory. The continuous adoption of advanced technologies for seamless IT operations has made organizations vulnerable to complex IT threats. This has resulted in an increased demand for cyber insurance. However, to avoid organizations paying high premiums, cyber insurance organizations are demanding reliable and robust Privileged Access Management (PAM) as part of regulatory requirements and insurance coverage. 

Zero Trust: Is it a Marketing Gimmick?

Hype, Overhype and Misconceptions

Time and again, the world of marketing has witnessed several “buzzwords” being used vehemently to capture the attention of the audience. On different occasions and in different contexts, humans have elevated marketable terms into buzzwords to leverage the hype in the market.

The IT industry is not untouched by the buzzwords and the hype that are created from those catch-phrases. Over the years, terms such as AI and ML have been extensively used for something which is the result of automation. 

In the same vein, “Zero Trust” is arguably one of those cliches that have been exploited and overused in the cyber security space. When Zero Trust started to become mainstream about four years ago, we saw literally every organization with its “Zero Trust solution” and every event organizer create a psychological hammering on the customers with this term. Numerous thought leadership webinars, roundtables, and panel discussions have been done around this, but the core value of this concept is somehow submerged under this overhype. On most occasions, people have missed the central idea of this concept. There are so many misconceptions. 

Moreover, much to our surprise, we have recently come across many IT professionals and organizers who went on saying that Zero Trust is a thing of the past– so marketers should focus on some “new” catch-phrases.

 So, that brings us to debate whether “Zero Trust” is really just a marketing buzzword. Or, is it more than that?

Zero Trust: Understanding the Framework 

First and foremost, Zero Trust is a security framework and not a compliance mandate such as PCI DSS, ISO 27001 and SOX. This framework is based on the principle that all trusted IT entitlements in the ecosystem must be verified for trust at every level of access. Whether it is the network, user, device or data, each and every access to all IT infra components must be attested to a set of verification layers along with context-based authentication.

Why is Zero Trust so Important in Today’s IT Context?

The Zero Trust extended framework, which resonates with Gartner’s Continuous Adaptive Risk and Trust Assessment approach (CARTA) is a radical shift from a perimeter-centric security or network security to combined data- security and network-security centric approach.This model challenges the conventional security approach because the latter is tilted in favor of perimeter (network) security and assumes that there is no threat inside the inner realm of IT kingdom. 

That thinking is wrong. If that’s the case then why are we witnessing so many data breach incidents? The Zero Trust extended model and CARTA never assumes “trust” but it continuously assesses “trust” using risk-based assessments available from information gathered.

Moreover, the modern-day enterprise IT ecosystem is highly distributed. End users access databases, applications, APIs, IaaS and PaaS resources from remote, third-party, and MSP environments. These emerging technologies and access use cases have necessitated implementation of a Unified Data Security and Access policy to protect IT resources. 

The framework essentially requires constructing micro-perimeters and micro-segmentations for governing scattered digital identities including the entitlements so that access to every critical IT resource is secure, controlled, and documented. 

The basic Zero Trust foundation therefore requires comprehensive understanding of the IT infrastructure. To successfully implement it, IT risks management must ensure that security analytics and orchestrated Zero Trust architecture offers greater security and visibility. There is nothing such as the ‘Zero Trust solution’, but a robust solution can help to build the Zero Trust architecture. 

Building  Zero Trust Privileged Access Security with ARCON | PAM 

In 2109, ARCON was one of the first Privileged Access Management vendors to explain how comprehensive security can be ensured in the Privileged Access environment by implementing the Zero Trust model. 

Having a comprehensive knowledge of emerging use cases arising from day-to-day IT operations, ARCON has architected the best-in-class solution to support the enterprise Zero Trust journey and the much evolved CARTA framework. 

Here are the four enablers, on the basis of which ARCON | PAM supports the Zero Trust framework: 

Enabler 1: Establishing Trust: ARCON | PAM has high maturity when it comes to verifying the “Trust”, as one can configure various tests to be performed before the “Trust” can be established. The solution allows for the establishment of trust not only in identity but also in various access management elements such as MFA, Adaptive Authentication, and device and location verification, all while continuously monitoring and assessing the same using risk-based assessment methodologies. 

Enabler 2: Enforcing Access Control: If one were to apply the CARTA principles, then the expectation is to ensure that while one is accessing the systems, there is constant monitoring of whether what is done is right. This is echoed by the ARCON Predict | Protect | Prevent Model. If Knight Analytics is configured, it provides constant monitoring of who, when, and what is being accessed as well as what activities are executed on the systems.

Enabler 3: Micro Segmentation of Network: ARCON | PAM provides network overlays, network encryption, software-defined perimeter (SDP), and host-based agents to achieve network segmentation and micro-segmentation. 

Enabler 4: Robust Detection & Response: ARCON | PAM offers robust threat detection capabilities in the form of session monitoring with textual context and commands executed on various systems. The detection capabilities have been further improved with the AI/ML leveraged Knight Analytics tool, which provides predictive capabilities and identifies anomalies or threats at an early stage. 

Conclusion:

There are many misconceptions about Zero Trust, but if the model is properly designed, the framework can aid in the establishment of a solid foundation for network, device, user, and data security.

Webinar: The Importance of Endpoint Privilege Management – ARCON and KuppingerCole Analysts Ag.

After a very successful webinar on the role of IAM in Multi-cloud Environments, ARCON and KuppingerCole Analysts AG. came together again to co-host a webinar on yet another burning topic in information security: endpoint security.

On July 28th, 2022, Paul Fisher, Senior Analyst, KuppingerCole Analysts AG, and Anil Bhandari, Thought Leader and Chief Mentor, ARCON, appeared live to discuss the benefits of the Endpoint Privilege Management (EPM) solution.

In the first half of the webinar, Paul Fisher took the stage as he explained why modern regulatory compliance requirements and IT infrastructure setups demand the deployment of an EPM solution to secure data, devices, and critical-applications from potential abuse or misuse.

Initially, Paul discussed the generic IT aspects that enterprises “should have” to ensure business continuity, and later on, he highlighted the concerns about endpoint security. 

Here are the key points highlighted by Paul.

  • Agility – Organizations always look for IT agility to build a strong foundation of secured IT infrastructure. And secured endpoints are the keys to ensure that the right data asset is accessed by the right person at the right time for the right reason. 
  • Rapid Rollout – It is essential for organizations to accomplish the designated task with the designated user within the designated time. To make sure that it happens on time, proper and rapid rollout is the key.
  • Productivity – Productivity is the ultimate goal of any organization. What level of automation an organization has incorporated into their IT operational infrastructure, what kind of proactive end-users are there in the IT ecosystem and what extent of stringency is followed through the policies – all these help in the productivity of the end-users.
  • Cost Reduction – If digital transformation is not cost-effective, then organizations refrain from going for transformation or sometimes delay it to arrange an adequate budget. Hence, cost is another crucial component of the IT security infrastructure.
  • Infrastructure – There is a proverb, “Infrastructure creates the form of a city.” The same applies to an organization as well. A proper infrastructure not just means a good number of people, a good number of systems and machines but also a comprehensive policy for the people for the right execution at the right time for the right reason. 
  • Control over end-users – Inadequate control over the end-users is the biggest reason for cyber incidents in organizations. Controlling end-users does not mean that they should be allocated well-defined roles and responsibilities, but also means monitoring them continuously to keep track of who is doing what, where, when and for which reason.
  • Deployment – Deployment of access management solutions and endpoint security solutions help organizations to stay secure from emerging insider and third-party threats.

Furthermore, Paul Fisher presented an analytical view of how the number of endpoints is increasing rapidly in organizations across the globe. In order to achieve higher levels of productivity, most organizations end up increasing the number of identities as well as functional departments to manage the IT workloads. As a result, the number of endpoints keeps on increasing as well. He also discussed several reasons of Endpoint Security misuse which includes:

  • End-users knowingly/ unknowingly downloading/ accessing malicious/ unknown applications
  • Malefactors accessing secret servers and sensitive databases
  • Lack of visibility in the endpoint activities
  • End-users having too much privileged/ elevated access
  • End-users sharing business and personal information on a single device

Regarding this, Paul also highlighted the importance of following the Least Privilege principle. ARCON’s EPM solution offers Just-In-Time (JIT) privilege access to the critical applications, which ensures that there are no standing privileges that could end up with unauthorized access.

Following Zero Trust architecture at the same time is extremely important in this context because an excessive number of endpoints poses challenges to administrators in terms of whom to grant access to for what and when. The Zero Trust model allows access to the system/ application but only with a seamless assessment of the level of risk involved in the activities.

Key Takeaways from Paul’s session:

  • Continuous assessment of EPM goals
  • Empowering users with ‘low friction’ rather than just assessing and securing them from IT threats – it could even enhance productivity and profitability
  • Defining end-user outcome is highly important
  • Extensive research on Privileged Access Management (PAM) solution in the market as it has direct/ indirect impact/ correlation with Endpoint management

Anil Bhandari in the second half of the webinar explained the role of the ARCON | Endpoint Privilege Management (EPM) solution in reinforcing endpoint security and how it uses User Behavior Analysis (UBA) and Data Leakage Prevention (DLP) features, including Data Intellect, to build a contextual security layer in enterprises. 

Looking a little back during the pandemic, every end-user in an organization worked from home, learned from home, and earned from home. In order to strengthen IT security, many organizations ended up making access management policies highly stringent. As a result, it became a high-friction access model, and productivity suffered a lot.

  • Considering the access management scenario, organizations started to invest in laptops with authorized access licenses – it resulted in slow access with bad user experience. Even Just-In-Time (JIT) access requests take forever.
  • Endpoints are the largest attack surfaces in modern IT environments.
  • Monitors access activities on the endpoints
  • Helps end-users to follow IT security policies even when they are outside the network
  • Application Blacklisting and Whitelisting
  • Privacy Control on files
  • File Monitoring (FIM capabilities)
  • Data Intellect (capabilities of classifying and protecting data based on AI/ ML mechanism)
  • Continuously assesses and analyzes user behaviour to find any anomalies
  • Makes a strong barrier between end-users and IT assets
  • Data backup, recovery and protection against ransomware
  • Continuing his discussion, Anil Bhandari said that current IT infrastructure is broadly divided into on-prem and cloud infrastructure. No doubt, the necessity to protect the endpoints is applicable to both. From security perspective, organizations concentrate on IT security in five different angles:
  • Endpoint Protection
  • Multi-factor Authentication (MFA)
  • Control the admin privileges
  • Control installations, applications & data
  • Device hardening

ARCON believes in securing IT infrastructure with an outcome-based model. Today, most of the applications are cloud-based, the profiles are dynamic in nature, the attack surface is huge, and there are multiple login and logout areas in the entire network. On top of that, remote security is again a demand because more than 80% of global organizations are now following a hybrid work model. Just-in-Time access, in this regard, is the best solution to ensure seamless security.

So what should we do?

According to ARCON, the best bet to establish next-gen protection is the ease of IT operations and support by securing the endpoint privilege passwords. At the same time, continuous automated analysis of every user behaviour helps in the crucial decision of whom to allow access to what, when and why. With EPM solution, organizations can:

  • Authenticate end-users everywhere and anywhere while accessing critical systems
  • Establish Zero trust framework with continuous assessment of end-point access
  • Notify any kind of deviation from the device pattern at any point of time

The intention here is not to restrict the user from doing whatever he/she wants, but to give liberty to the end-users with a low-friction model where end-users can do whatever they want, whenever they want. This eventually enhances productivity and fast performance. 

Before wrapping up the webinar, Anil Bhandari highlighted the exclusive demands of next-gen IT security and how ARCON | EPM is adding value to the trends:

  • Analyzing user behaviour with with AI/ ML-based algorithms
  • Real-time session monitoring for every access even while working remotely
  • Vault the privilege passwords of the device
  • User authentication with continuous assessment of ‘trust’ (Zero Trust)
  • Comprehensive report of endpoint access, device type and facial recognition
  • User identity-based third layer of defense
  • Elevation of an user based on requirement and ease of operations
  • Monitoring IT threats in a real-time (when, where & how)

Conclusion

As the webinar came to an end, both Paul and Anil discussed the poll question, “What are the concerns about endpoint security?” 40% of the respondents were of the opinion that cyber attackers access servers and databases taking advantage of vulnerabilities in endpoint security.

Emerging Trends and Expectations in the Access Management Space

Doing by learning and learning by doing—it is not just an adage, but also a time-tested approach that leads to innovation, agility, and experimentation. That’s the work culture we at ARCON have espoused over the years. As a result, whatever we build or innovate, we continue to push the boundaries by embracing a doing by learning and learning by doing culture to achieve the best results.

Participation at global conferences and events is surely one way to learn, observe, and understand new things, trends, and expectations.

Indeed, as the world is coming towards normalcy post-pandemic, event organizers are gradually shunning their virtual modes for physical modes. We have passed more than the halfway mark for the 2022 calendar year. And ARCON has traveled across the world to comprehend the expectations of global IT professionals.

Face-to-face meetings and discussions with the audience has helped us to learn about the latest Access Management use cases and expectations. 

A Glimpse of Some of the Major Global Summits attended by ARCON Thus Far in 2022

  1. Gartner Security & Risk Management Summit, Maryland, US
  2. Gartner Security & Risk Management Summit, London, UK
  3. Gartner Security & Risk Management Summit, Sydney, Australia 
  4. Blackhat Asia 2022, Singapore
  5. European Identity & Cloud Conference 2022, Berlin
  6. PhilSec Hybrid event, Manila
  7. Vietnam Security Summit, Hanoi
  8. Cyber Security & Threat Intelligence Summit, Kuala Lumpur
  9. CYSEC 2022, Doha
  10. GISEC 2022, Dubai 

The strategic business development team opined that business has taken a welcome turn after industry leaders started to come out of the cocoon of virtual meetings and resumed face-to-face business meetings. At events, the advantage is that the professional bonding between the participants and visitors strengthens. Moreover, new business prospects are brightened with hand-to-hand understanding of mechanisms and live demos of the product functionalities. It even clarifies and answers queries on the spot that arise in between the discussions.

Key Takeaways from Meetings and Discussions with Global IT Professionals 

Speaking about the trends, it is highly evident that IT security pros are still keeping pandemic experiences in mind while discussing and searching for scalable and integrable solutions to reinforce their Access Management use cases. 

Most organizations have started to embrace hybrid work environments in order to ensure flexibility for employees. Against this backdrop, IT security leaders are looking for a security framework that not only enhances the user experience but also mitigates the looming threats arising from a growing IT setup. Here are some of the most discussed IT security trends that we came across. 

Zero Trust Architecture: Zero Trust is now mainstream as user authorization and authentication at every layer of access is critical to protect digital identities, devices and business information. As perimeters are no longer confined to on-prem data centres, IT security leaders are looking to build micro-perimeters and micro-segmentation of digital identities to ensure that trusted entitlements are never compromised by using continuous and contextual authentication of end users.

Identity-centric Security: As hybrid work models have been widely accepted, organizations are facing the challenge of managing hundreds, or maybe thousands, of user identities in the enterprise network. As a result, there have been queries about how to control, monitor, and secure user identities (including privileged identities) seamlessly. Organizations are not just looking to manage the lifecycle of a high number of identities but also want to govern them and predict risks arising from suspicious users. What the security leaders are looking for is a robust platform designed to detect identity-related threats and respond in a timely manner.

Cloud Security: A growing number of  organizations have migrated their IT infrastructure to cloud platforms. Many have even opted for hybrid clouds. As an obvious result, there is a growing demand for a solution that would enforce granular-level controls over all cloud users to ensure there is no overprivileged cloud identity. The other urgent need for organizations hosting data in multiple cloud environments is a centralized cloud engine to elevate privileges, enforce rule and role-based access to cloud resources, and provide timely remediation of anomalies.

Password-less Access Approach: Organizations are looking for a password-less approach in the access management area. IT administrators look for a “low-friction” and “high-security” model so that an uninterrupted IT process is ensured. 

Adopting ITDR Frameworks: The industry leaders continuously try to stay updated so that they can offer the best of the best IT security infrastructure to their organizations. However, vulnerabilities are unpredictable. Hence, to stay unaffected by any unprecedented incident, organizations are now looking for robust ITDR (Information Technology Disaster Recovery) mechanisms.

Conclusion

Identity and data security is at the heart of the digitization process for global organizations, and IT security pros are looking to adopt adequate security measures to strengthen their compliance frameworks along with frictionless user experience.

Webinar-Paul Fisher and Anil Bhandari on Multi-Cloud Governance: Key Takeaways

ARCON and KuppingerCole once again co-hosted a webinar to discuss some of the most important issues in the Information Security space. On July 12th, 2022,  Paul Fisher, Senior Analyst, KuppingerCole Analysts AG and Anil Bhandari, Thought Leader and Chief Mentor, ARCON turned their attention to the role of Identity and Access Management (IAM) in multi-cloud platforms. 

In this webinar, both speakers covered the major risks involved in managing data and workloads in multi-cloud platforms, trends, and discussed how IAM technologies can help to build resilient security posture in the multi-cloud environments. 

During the first half of the webinar, Paul Fisher highlighted how the identity and access management landscape in multi-cloud environments is changing radically. Below are the key takeaways from the first half of the session:

  • Enterprises look for a host of business benefits from cloud adoption. The major ones among them are rapid delivery, uninterrupted user experience, convenience, data management and overall IT security.
  • End-users and IT administrators find a multi-cloud environment extremely beneficial for remote working, multi-location access and collaboration among the workforce.
  • In the ever-expanding IT infrastructure, the number of digital identities, including human identities, machine identities and cloud identities has increased exponentially. Many of them are third-party identities that pose IT security risks if not monitored in real-time.
  • While sharing some statistics about cloud services, Paul said that 42% of organizations use three or more IaaS providers as different teams/ departments select different vendors for their required services.
  • Moreover, 69% of organizations use proprietary IaaS IAM tools, whereas 39% of organizations prefer in-house IAM platforms to manage the security of their IT infrastructure.
  • For a better understanding of the cloud atmosphere, Paul spoke about the containerization of identities. For business reasons, the risk assessment teams are now moving outside the CIO/ CISO zone of influence and creating their own solutions for business reasons—mostly flexibility of requirements.
  • While managing identities in the complex IT environments, organizations need to focus on the IT security policies, data management, overall access management of the critical applications, and cloud resources and securing the identities from unauthorized intrusions.
  • Another challenge in a multi-cloud environment is to achieve business agility and simultaneously meet compliance requirements – especially cloud compliance standards eg. FedRAMP, NIST.
  • As per demand, adding AI-ML algorithms to the solutions for cloud security has increased the level of complexity. Only a robust solution that manages and controls identity governance can satisfactorily address it.
  • The core IT infrastructure consists of the identities of the administrators, developers, end-users, third-party users and endpoints. The overall access of all these identities are controlled by the Privileged Access Management and Identity Access Management solutions. With the inclusion of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), and on-prem private clouds, the security demands for secret files, servers, containers, virtual machines, admin accounts and privileged accounts have been much higher. 
  • The upcoming IT security trends speak of decentralized solutions that are compatible with the future of identities. This happens in two ways, to be precise: user-centric methods and reusable methods. For user-centric methods, the user holds the identity data and delegates access rights to multiple users. On the other hand, reusable methods include authentication and authorization of a single identity for multiple brands.
  • While summarizing the entire discussion, Paul stressed the importance of decentralization and containerization of a network expansion that is inevitable. He also suggested that organizations need to accept IaaS infrastructure with automation that can address every possible workflow chore. 

In the latter half of the webinar, Anil Bhandari from ARCON discussed the challenges in administering and governing multiple user IDs in an ever-expanding multi-cloud world in the current context and explained how ARCON’s Cloud Governance platform can help to overcome those challenges.  Here are the highlights of the discussion:

  • The evolution of digital identities is not yet over. In fact, a lot more is about to come in the next five years.
  • There are four business models that are trending globally: outcome-based model, hyper-personalization, access vs ownership, and digitalization of businesses. All these models evolve around digital identities and the proactiveness of these identities.
  • Digital identities drive business models with growth, efficiency, and excellence that is directly involved in profit-making and revenue generation.
  • If we try to construct a digital identity, there are several parameters that are considered. Personal thoughts, likes, dislikes, professional details, online activities/ behaviour, which tools are used, where the information is stored/ saved etc. are taken into account.
  • Today, most of the enterprise data related to identities is likely to be stored in the cloud and organizations opt for outcome-based business models where cloud storage offers the best operational experience.
  • Along with digital identities, there is a great need for digital vaults today.
  • If we classify the types of digital identities, there are interactive identities and non-interactive identities. Interactive identities include human identities and machine identities (bots). Non-interactive identities include mobile devices, desktops, APIs, web servers, database servers, application servers and more.
  • Non-interactive identities might vary industry-wise. For the telecommunications sector, a phone number could be an identity, whereas for a government organization, a social security number is an identity.
  • While talking about the privacy of the data associated with the identities, Anil emphasized that without data privacy measures, the whole idea of creating identities might go haywire. Social security details, property documents, financial documents, photos, and personal information, including personal certificates, – all require the utmost privacy to ensure the security of the identities in the cloud.
  • In the case of identities in the cloud, along with data privacy, secure access management is the only way to protect the digital ecosystem with endless digital assets. SaaS enables easy access to cloud technology where identities are easy to track with a zero trust framework.
  • As per the global trends of 2022, there are a couple of security domains that talk about attacks on digital supply chains that are embedded with vulnerabilities, for which identity threat detection and response tools are necessary. To ensure the integrity of the digital supply chain, it is critical to reframe security practices to ensure a timely response to emerging threats.
  • ARCON in this aspect, offers a friction-less solution for the security of identities in multi-cloud environments. Available on virtual access platforms, this solution offers multi-factor authentication, single sign-on, and just-in-time privilege to build a strong visibility for a zero trust model across the IT ecosystem.
  • ARCON believes in three basic principles of cloud governance: discover, monitor and remediate.
  • ARCON ensures multi-cloud governance by incorporating the below aspects:
  1. Gain visibility across clouds
  2. Mitigate access risks across clouds
  3. Provision/ deprovision custom policies
  4. Monitor and govern entities
  5. Assess permissions with interactive graphs
  • ARCON Cloud Governance tool helps organizations with a single view dashboard consisting of all types of identities and their activity details at a given point of time. It also shows the risk assessment perimeter in a graphical format for user-friendliness.
  • This risk assessment graph also helps in understanding the trend from the details of what has been used and what has not. In the case of organizations with multiple offices 
  • in multiple locations, this analysis is extremely beneficial for the IT risk assessment teams.
  • Lastly, ARCON’s strategy of business offerings is already aligned with the global trends. It includes a comprehensive governance framework, cloud-native access control applications, robust endpoint security, AI/ ML empowered solutions and compliance with stringent IT standards. With these, ARCON also stacks up to the expectations of ITDR (Identity Threat Detection and Response) compatibility. 

Conclusion

As the curtain of the webinar drew down, Paul and Anil discussed the webinar-poll results. On the question, “What worries you most about access management for the cloud?”, 40% of the participants agreed with the answer “Not knowing who has access”. This proves that robust identity governance along with role and rule-based access management is the key to a secured cloud environment.