Talk to us Risks to Watch

Securing High-Velocity Cloud Workloads with ARCON’s Digital Vault

Overview: Secrets Management

Cloud-dominated architectures are ubiquitous as more organizations are seeking to reap benefits from cloud-based technologies. Agility and flexibility are the critical elements offered by cloud-based technologies even as they offer developers the ability to run applications and tools quickly and dynamically, necessary to keep up with the pace of market requirements. 

And in this pursuit of agility, dynamism and flexibility, organizations are creating large numbers of non-human identities that interact with high velocity cloud workloads such as DevOps pipelines, virtual machines, scripts, applications, containers, RPA tools to conduct day-to-day automated IT tasks. 

But when organizations have high-velocity cloud workloads, spread sometimes in multi-cloud environments, and both human (console level access for DevOps users) and non-human identities get into action, at this point, it is extremely crucial  to protect the passwords, API keys, SSH keys, certificates or OAuth tokens etc. to ensure that there is secure access to high-velocity cloud workloads. Secrets management enables cloud security teams to securely manage the cloud workload. 

Just like human identities and their interaction with critical systems need to be brokered for secure access, secrets management is vital component for ensuring secure access to dynamic cloud workloads. Secrets management allows developers to securely rotate vault credentials such as passwords, keys, and tokens with strict access controls is known as secrets management.

What are the Challenges in Secrets Management

  • Sprawling of Secrets: With the proliferation of multi-cloud services and microservices, there are hundreds of secrets that the developers use for accessing critical systems, cloud-native applications, or virtual machines. If these secrets are left unrevoked, the organization is left open to catastrophes.
  • Fragmented Control of Secrets: In some organizations, different teams manage their secrets separately. Such decentralized platform can lead to security loopholes, some might abide by the policies, some might not. This bears risks of non-compliance as well.
  • Cloud Services: While opting for different cloud service models such as AWS (Amazon Web Services), Microsoft Azure or GCP (Google Cloud Platform), organizations work with many virtual machines that require their own secrets. Some are default secrets while some are organization-made. There could be vulnerabilities of default secrets and if those are overlooked, there could be unprecedented incidents. 

Automate Secrets Management with ARCON Digital Vault 

ARCON is focused on developing cloud-native applications so that organizations cloud-first journey is successful. ARCON Digital Vault is a centralized engine that provides the capability to generate, vault, and randomize credentials for non-human identities and broker trust between two non-human identities, along with ensuring authorization and policy enforcement for the same. The powerful engine can support dynamic functions like secrets management for RPA, bots, etc. to control and mitigate the threat vector arising from large-scale process automation.

ARCON Digital Vault: Key Points  

  • Leverages native application attributes and role-based access controls to authenticate applications and containers
  • Manages credentials/tokens used by applications, container platforms, automation tools, and other non-human identities 
  • Manages and securely pass credentials to validated containers and clusters as and when required
  • Secures credentials, certificates, APIs, tokens, secrets in digital vaults and protects and monitors both non-human and human identities with CI/CD consoles 
  • Implements role-based access control policy to authenticate cloud applications and containers
  • Controls both human and non-human access during continuous integrations (CI) and continuous deployments (CD)

Conclusion

Secrets management is not only critical for the security of passwords, keys, tokens, or certificates, but also systematic management of IT operations and resources. With this systematic approach, organizations can prevent unauthorized/ unknown access, credential misuse and subsequent catastrophic incidents on cloud environments.

ARCON – Cyber Insurance

Considering the amount of data containing confidential or sensitive information that businesses store digitally, cyber liability insurance becomes more and more important every day. This kind of insurance is necessary not only for protecting businesses from data breaches but also for remaining compliant with all relevant legal and industry-specific regulations. From global standards set by regulatory bodies like the European Union to mandates in US federal law, ARCON products can help your business meet the compliance requirements set by a variety of regulatory entities. Implementing the proper technology, such as ARCON’s solutions, can reduce insurance premiums, and some companies may not even insure your cyber security without proper protection in place.

Cyber risks businesses face

Businesses face a variety of cyber risks every day, including network failures, malware infections, cyber extortion demands, ransomware, and data breaches. Digital identities are the most common attack vector, but many businesses are unaware of just how vulnerable their many unique digital identities are. Some cyber insurance companies have even mandated Privileged Access Management (PAM) technology to obtain cyber insurance.

Cyber liability insurance can include identity protection, but there are more steps businesses can take to protect the digital identities of their employees and devices. ARCON’s solutions create a digital fence around your core digital infrastructure to protect these digital identities and secure your digital assets. The cost of cyber insurance can be significantly reduced if they have ARCON’s technology deployed. We can also provide extensive insight into your data so you know what you have, what is important, where it lives, and when it moves. This ensures you’re always protecting the most contextually important pieces of information and can follow its trail should it ever move.

These threats businesses face become more complex and sophisticated by the day, making it not a question of if your organization will be threatened or suffer a breach but when. This fact highlights the need for cyber security insurance that protects against these evolving threats. Combined with cyber liability insurance, a comprehensive plan and secure identity management solutions from ARCON allows businesses of any size and in any industry to mitigate cyber risk and achieve security compliance. In addition to increasing security, these measures can also increase productivity.

Protect your business with ARCON solutions

While it’s true that larger corporations face more risk and have more areas of vulnerability, cyber insurance for small businesses – even mom and pop shops – is still important. ARCON understands the complexity of cyber threats facing businesses small and large, and we have the solutions that help ensure data and other important business assets are protected.

Request a demo today to see our privileged access management solutions in action!

Implementing Identity-first Security is Foundational for Robust Cybersecurity Framework

Why Identity-first security?

The sheer pace at which digital identities are being created to manage an increasing amount of computing resources both on-premises and in the cloud environments- make identity-first security of paramount importance. Several catastrophic IT incidents happen when the security fabric for distributed digital identities lack identity-centric controls. 

While organizations deploy IAM and IGA controls to secure identity, the conventional (IAM, IGA) methods are inadequate as they provide only static control. On the other hand, the essence of identity-first security is continuous monitoring and context-wise controls- the first step towards successfully implementing the zero-trust strategy. 

The context that necessitates implementation of identity-first security

  1. Remote workforce: Since the onset of “Work-From-Anywhere” (WFA) norm in the post-pandemic era, the number of remote users is increasing. The remote users’ access to numerous services means that identities have control over both business assets and critical information and in many cases, access to infrastructure assets. So, in this scenario, perimeter-based security is of little importance as identities are dispersed across distributed environments. Every digital identity has become a perimeter which must be secured, controlled, and monitored, which conventional IAM and IGA control do not provide.
  1. Proliferation of SaaS applications: SaaS-delivered applications are gaining popularity worldwide due to their scalability, flexibility, cost-effectiveness, simplicity of deployments and convenience of usage. Applications across different functional areas are increasingly deployed by organizations of all shapes and sizes. Therin lies a problem from identity security perspective. On most occasions, it is the business team, HR teams, sales team, marketing team among many other functions that keep on adding SaaS applications, circumventing IAM teams. As a result, there are no role-based and policy-based controls. Many privileged level activities are carried out without the least privileged principle and other necessary identity-centric safeguards.
  1. Human and non-human identity sprawls across multi-cloud environments: A rapid adoption of multi-cloud platforms among global enterprises has resulted in emerging IAM use cases that require relook at how cloud privileges and cloud infrastructure entitlements are managed. Today, more than 70% of organizations adopt multi-cloud platforms to meet the IT operational requirements and infrastructure use cases through various cloud platforms such as AWS, Azure and GCP (Google Cloud Platform) among many others. It is not just the human identities that need to be protected but also machine identities/non-human identities for cloud workloads such as scripts, containers, VMs, CI/CD tools, RPA tools require continuous monitoring and governance. 
  1. Limitations in conventional IAM approaches: The modern-day IAM use cases are dynamic and require variable controls to navigate through high-velocity workloads. Conventional IAM tools, although providing role-based access control (RBAC) and attributes-based access control (ABAC), were never designed to address decentralized and dynamic use cases. In other words, conventional IAM tools offer only static access control and governance that increases identity-based threats. Likewise, conventional IAM methods provide preventive security measures such as MFA, fine-grained access control, and session monitoring. On the other hand, to enhance the identity-first security framework security pros require non-static- continuous monitoring and context-based authentication of digital identities as well as centralized engine to manage identities. 

How to design an identity-first security posture? 

The basic requirements for construction of identity-first security posture are to adopt access control mechanisms that offers the following: 

  • Implementing continuous identity threat analytics and orchestration 
  • Ensuring regular certification and recertification of digital identities 
  • Establishing centralized control to control, manage and monitor all sorts of identities- converged identity approach 
  • Verifying the trust of an identity using context-based authentication 
  • Enforcing just-in-time access to systems 

How does ARCON enable organizations to build an identity-first security posture?

  • Adaptive authentication: In addition to supporting MFA, ARCON product suites such as Converged Identity platform and Privileged Access Management leverage adaptive authentication for building an identity-first security posture. Deny access until one can establish trust is what makes adaptive authentication a very secure way to access business critical applications. ARCON has a high level of maturity when it comes to assessing the trust as one can configure various tests to be performed before the trust can be established using adaptive authentication components such as IP address, Mac address, geo-location, secret key authentication and time factor. 
  • User behaviour analytics: Predicting risk stemming from digital identity is as important as administering it. User behaviour analytics enables security professionals to identify identities that deviate from baseline activities as mandated by management. ARCON provides powerful identity threat analytics engine- the Knight Analytics that leverages the neural and deep learning technologies to identify any sort of deviation and sends alert to highlight anomalies in near real-time basis. . 
  • Unified engine (Converged Identity approach) to manage various digital identities: Modern-day organizations find it increasingly difficult to manage various kinds of identities in today’s vast and distributed IT infrastructure. A unified engine to manage and govern all sorts of identities– human, non-human, shared, privileged identities-is an absolute must for mitigating administrative hassles and chaos resulting from fragmented and siloed IAM approach that erodes the importance of identity-first security approach. 
  • Just-in-time access: Identity-based threats intensify if there is no mechanism to ensure the right identity has the right to access the right systems at the right time. Just-in-time access approaches eliminate always-on/standing privileges and enforces the principle of least privilege. ARCON provides all industry-standard JIT approaches such as creation of on-demand privileged accounts, time-based privileged elevation, temporary elevation, ephemeral credentials (access tokens for cloud resources). 
  • Identity governance: Robust identity governance (IG) is getting increasingly important in complex IT environments and one of the critical components to build an identity-first security posture. A widely distributed IT environment includes users, assets, and services that have increased significantly, and these IT components are distributed in multiple cloud platforms and hybrid data center setups. ARCON Identity Governance module enables organizations to manage a complex range of access rights for users, user groups, services, assets, and asset groups – both on-prem and on-cloud. In both environments, ARCON Identity Governance works as a key towards managing the workflow, provisioning/deprovisioning identities, revoking rights and certificate management including recertification. 

Conclusion

The foundation of a robust cybersecurity framework is built by implementing an Identity-first security approach. To manage identity-centric controls in on-prem or on-cloud environments, organizations count on an Identity-first security approach, that ensures context-wise controls and continuous monitoring of the identities, especially for distributed digital identities.

5 Essentials to Implement ARCON | My Vault

The Context

The security and confidentiality of business information not just depends on who all have access to that information, but also – 

  • How do organizations store business-critical information?
  • Where do organizations store this information?
  • With whom are employees sharing the information?

There was a time when organizations used to manage a huge pile of hard copies consisting of confidential information in secret drawers or iron lockers. To maintain confidentiality, these drawers used to remain locked always with keys kept in some fixed places with the knowledge of very limited people. 

Nevertheless, amid the increased pace of digitalization, that’s not feasible anymore. Business data is generated in huge volumes and scattered across the functional teams that manage the data. 

Indeed, usage of physical data has dropped drastically, and digital data (usage of soft copies) has skyrocketed. However, there have been loopholes with the practice of maintaining confidentiality, and thus, data security and data privacy concerns have increased. IT incidents such as data breaches, cyber espionage and data abuse/ misuse are rampant because of lack of adequate attention towards information security.

Today, there is an enormous amount of critical data and business secrets generated every day and organizations require a secure repository to store all such information. To address a growing number of use cases that can compromise critical business information, ARCON has developed My Vault to protect important files, folders, drives, secrets, keys, certificates etc.  

Use Case 1: Shared Information

Let us think of a situation where any user shares some confidential information with some other user and the recipient reshares the information with someone else. In a large IT environment, where huge volumes (in TBs) of data are generated (or transferred) every day, it is never possible for the IT administrators and the risk management team to monitor which file is accessed and shared.

Users either share files/ folders through email attachments or by sharing drives of the folders. They allow permissions to view the files, download the files or sometimes even edit the files as per requirements. Situations worsen if the receivers share those files again with someone else in the organization or anyone outside the organization.

This way, within a span of few days, there could be a possibility that the information gets shared randomly among multiple people both internally and with third parties. Some could save it in their drives, some could save in the USBs, some could even take a print of it. Eventually, the information no longer remains “confidential”, and the data privacy is misused.

ARCON’s My Vault offers a centralized repository to store, access and share critical business secrets in a secure manner. The files where this information is stored remain encrypted and can be deleted easily after a preset time to avoid any unauthorized access. It also controls the end-users’ activities based on the pre-configured permissions even at a granular level. ARCON My Vault can give certain privileges with regards to download, share, transfer of files/folders or access permissions that minimizes risks of data misuse.

Use Case 2: Packages

It is not just always files/ folders that require sharing, but also business secrets, keys, certificates or even new build of software are shared internally with multiple users to sync with the new patches. The users face challenges in maintaining security during such transfers. Any file/ folder, secrets, certificates or keys once shared with anyone in the organization, could be downloaded unlimited times, which is again a risky affair. Even if it is done in a secure enterprise network, we can confirm that downloaded files bear more risks of misuse compared to that of “read-only” or “view-only” files.

With ARCON My Vault packages, users can upload the files/ folders, secrets, keys, certificates or patches on My Vault and share those in an encrypted format with the recipients. My Vault implements restrictions also in the number of downloads to all these shared data. E.g., if the recipient downloads the file once after receiving it, he or she won’t be allowed any further downloads in the near future, unless the sender re-shares it. In addition, with the help of My Vault packages, the sender can apply a rule where the recipient will be restricted from sharing the file with anyone else without the permission of the sender.

Use Case 3: Downtime ARCON Password Envelope Management (APEM) Tool

Robust data backup mechanism is a crucial component of data storage. It has been witnessed quite frequently among organizations that inspite of vaulting their business secrets in an encrypted manner, they lack any convenient mechanism to have a data backup. What could happen if there is any unprecedented incident (majorly downtime) with the vault or storage system? The organization could be at grave risk of losing their information assets. 

ARCON Password Envelope Management (APEM) is a robust data backup mechanism tool that does not allow any stored information to be misused even if ARCON My Vault stops working. While analyzing and sharing confidential data assets and business secrets with My Vault, organizations can opt for APEM tool. During unexpected scenarios when My Vault is not working, then also the IT administrator can ensure that every data in the storage remains encrypted. The administrator can select a certain number of users through whom all the files are emailed in their inboxes in an encrypted manner. For further assurance of data security, those data files can be decrypted only through APEM tool after permission from the IT administrator. This eventually keeps every file and folder safe till My Vault services resume.

Use Case 4: Reports

If IT administrators do not have any record of the amount of data flow happening in an enterprise network, it could be catastrophic because they won’t be able to track who has accessed what data at what time and for what purpose. It could be risky from audit perspective as well because most of the regulatory compliances demand adequate safeguards to monitor data.

ARCON My Vault’s automated reporting tool keeps track of all the vault operations date-wise, timewise and user-wise. It highlights each action in the form of reports whether it is access or sharing of confidential files/ folders, keys, certificates etc. done by individual users in the enterprise network.

Use Case 5: Secure Data Sharing in Different Domain

In different departments of business development, it is a widespread practice to share business brochures, proposals or other Confidentials with their clients, prospects, and partners. Occasionally, the email domain restricts file sharing with different domains for security reasons. At this point, even if we remove the restriction and share the file, we still cannot be assured whether the file shared will not be re-shared with any other third-party user or how many times it is going to be downloaded.

After implementing ARCON My Vault, organizations can ensure secure and restrictive file sharing even with different email domains. Once the file is shared from My Vault, the users can put restrictions on –

  • How many times can the receiver download the file?
  • For how many days can the receiver find the file in his email inbox?
  • Whether the receiver will be permitted to re-share the file with anyone else.

Hence, chances of data misuse/ abuse are minimized to a large extent.

Conclusion

ARCON| My Vault is an essential information security solution in modern enterprise use cases. It offers a centralized repository to protect, store and share confidential business information and secrets in a secure manner.