APAC CIOOutlook

Advertise

with us

  • Technologies
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • Digital Transformation
      • Internet of Things
      • Low Code No Code
      • MarTech
      • Mobile Application
      • Security
      • Software Testing
      • Wireless
  • Industries
      • E-Commerce
      • Education
      • Logistics
      • Retail
      • Supply Chain
      • Travel and Hospitality
  • Platforms
      • Microsoft
      • Salesforce
      • SAP
  • Solutions
      • Business Intelligence
      • Cognitive
      • Contact Center
      • CRM
      • Cyber Security
      • Data Center
      • Gamification
      • Procurement
      • Smart City
      • Workflow
  • Home
  • CXO Insights
  • CIO Views
  • Vendors
  • News
  • Conferences
  • Whitepapers
  • Newsletter
  • Awards
Apac
  • Artificial Intelligence

    Big Data

    Blockchain

    Cloud

    Digital Transformation

    Internet of Things

    Low Code No Code

    MarTech

    Mobile Application

    Security

    Software Testing

    Wireless

  • E-Commerce

    Education

    Logistics

    Retail

    Supply Chain

    Travel and Hospitality

  • Microsoft

    Salesforce

    SAP

  • Business Intelligence

    Cognitive

    Contact Center

    CRM

    Cyber Security

    Data Center

    Gamification

    Procurement

    Smart City

    Workflow

Menu
    • Cyber Security
    • Hotel Management
    • Workflow
    • E-Commerce
    • Business Intelligence
    • MORE
    #

    Apac CIOOutlook Weekly Brief

    ×

    Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

    Subscribe

    loading

    THANK YOU FOR SUBSCRIBING

    • Home
    • Cyber Security
    Editor's Pick (1 - 4 of 8)
    left
    IAM May Help Secure Data, But It Needs to be Protected as Well

    Marc Ashworth, Chief Information Security Officer, First Bank

    The Changing Landscape of Cyber Security

    Scott Brandt, CIO & Director of IT, Texas Office of the Secretary of State

    Cyber Security - Integrated enterprise approach required to address the multifaceted challenges

    Sumit Puri, CIO, Max Healthcare

    Leadership Framework for Building Elite Teams

    Douglas Duncan, CIO, Columbia Insurance Group

    Four Cybersecurity Weak Spots You Should Care About When Others Don't

    Marc Probst, CIO & VP, Intermountain Healthcare

    Enterprise Security And The Elusive

    Andre' Allen, CISO, City of Houston

    Secure Text Messaging in an Academic Medical Center - Experience and Lessons

    Kari Cassel, SVP & CIO, UF Health

    It's Time to Turn Security Inside Out

    Gilad Raz, CIO, Varonis

    right

    The Critical Future of Identity and Access Management

    Joseph Carson, Chief Security Scientist, Thycotic

    Tweet
    content-image

    Joseph Carson, Chief Security Scientist, Thycotic

    The traditional security pe­rimeter is proving that it is no longer an effective cyber security control and fast growing technologies like Cloud, Mobile, and Virtualization make the boundaries of an organiza­tion blurry. For many years, organi­zations have protected their valuable and sensitive information by building a fence around those assets and all the data that flowed in and out of that organization was either via a single internet access point or on physical devices. That meant that a traditional perimeter was an effective measure because the boundaries were known. As long as the internet access was controlled by the data that flowed through it, it was possible to protect, monitor, and control that data. Orga­nizations protected the internet access with firewalls, VPNs, access controls, IDS, IPS, SIEM, email gateways, and so forth, building multiple levels of security on the so-called perimeter. The non physical devices, systems management, and antivirus protected those systems and kept them updated with the latest security patches. This is a traditional security approach that has been used for almost 30 years, but in today’s world it is no longer effective alone.

    Technology has significant­ly changed the world. In the past 10 years, we have seen the physical boundaries of an organization almost completely disappear. This has been a result of mobility and connectivity with almost every person in an orga­nization becoming an internet access point. With the ability to simply con­nect their mobile devices together and enable a personal hotspot, the method to control the perimeter became much more difficult. At an average transfer speed of 50MB per second a person could transfer almost 600GB of data out of an organization within a day via a connection that is not being moni­tored or secured. This leaves us with the question-what is the size of your data vaults that contain sensitive data? This, in combination with Cloud and Virtualization, makes data today so much more transportable than ever be­fore with data moving at fast transfer rates and more cloud services allowing data to be processed and easily stored in the cloud. With these evolutions and technological advancements, the tradi­tional perimeter needs to also evolve.

    “In the vast majority of breaches, more than 62 percent of cyber incidents, stolen identities, credentials, and privileged accounts continue to be the

    prime target for hackers”

    If we look at all of the cyber breach reports the past year–we can see that it has been busy for cyber criminals, with public reports describing more than 500 data breaches and more than 500 million records exposed in 2015. This includes the disclosure of 21 mil­lion U.S. Office of Personnel Manage­ment records, 70 million medical re­cords at Anthem, and 37 million user details at Ashley Madison.

    So why do we continue to see so many cyber breaches? If we look at why many of the cyber breaches in the past year have occurred, it comes down to three major factors that can be categorized into Human Factor, Identities and Credentials, and Vul­nerabilities. With the digital social society, we are sharing more infor­mation, ultimately causing ourselves to be much more exposed to social engineering and targeted spear phish­ing attacks with the ultimate goal to compromise our systems for financial fraud or steal our identities in order to access the company we are entrusted with protecting. When our identities are stolen, it provides the attacker with the ease of bypassing the tradi­tional security perimeter undetected and if that identity has access to priv­ilege accounts they can easily carry out malicious activity that can some­times go undetected for more than 200 days or until the malicious activity has already occurred.

    In the vast majority of breaches, more than 62 percent of cyber inci­dents, stolen identities, credentials, and privileged accounts continue to be the prime target for hackers because they unlock the access required to ex­ploit virtually any part of an organiza­tion’s network, including critical and sensitive data. Hacking privileged cre­dentials can mean the difference be­tween a simple perimeter breach and one that could lead to a cyber catastro­phe. Once attackers gain access, they can escalate their privileges and move through networks to identify and com­promise confidential information or use Ransomware to encrypt critical business data.

    In today’s world where organiza­tions can no longer rely on the tradi­tional security perimeter as the only cyber security measure, it is ultimately important that the new cyber security perimeter is with the Identity and Ac­cess of the employee. This is the new and next generation security perimeter that can be effective in a world where systems and data can be located any­where and be accessed at any¬time as long as the identity and access can be validated and trusted. We can see successful implementations where even countries like Estonia have tak­en an approach to enable citizens and the government to be able to interact seamlessly via digital identities which allow Estonian citizens to vote, bank, and file taxes from any location in the world. It also enables Estonia to in­troduce the world’s first E-Resident program. Organizations can take sim­ilar approaches by embracing Identity and Access Management as the way to protect their data and systems. This can be done by taking an approach at securing the digital identities, using multifactor authentication, securing privileged access and data, and con­tinuously checking the reputation and behaviour of those identities. This ul­timately moves the focus to the data and the system or person who needs access to it and not the so-called tradi­tional security perimeter.

    An effective policy and approach on Identity and Access Management can help a company accelerate new technology adoptions and at the same time help avoid becoming the next victim of cyber crime.

    Where can you start to get ahead? Here’s a list to get you in the right direction:

    1. Educate key stakeholders on Identity Access Management

    2. Discover Identities and Privileged Accounts

    3. Automate the management and se­curity of privileged accounts

    4. Adopt and implement policies

    5. Get better visibility of Identity and Privilege Account usage and compliance.

    Operating since 1996, Thycotic is an IT security company based in Adelaide, Australia which prevents cyber attacks by securing passwords, protecting endpoints, and controlling application access.

    tag

    Identity and Access Management

    cyber criminals

    Financial

    Infor

    Weekly Brief

    loading
    Top 10 Cyber Security Companies in APAC - 2024
    ON THE DECK

    Cyber Security 2024

    I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

    Read Also

    From Friction to Function: How Winc Turned Customer Feedback into Business Growth

    From Friction to Function: How Winc Turned Customer Feedback into Business Growth

    Cara Pring, Digital & Cx Director, Winc Australia
    Why Contact Centres are Becoming Strategic Hubs for Social Insight

    Why Contact Centres are Becoming Strategic Hubs for Social Insight

    Cindy Chaimowitz, GM Wholesale & Customer Service and Karen Smith, Head of Customer Service, Foodstuffs North Island
    Why Compliance Needs a Seat at the Strategy Table

    Why Compliance Needs a Seat at the Strategy Table

    David Koh, Head, Legal & Compliance (Singapore) and Operational Risk Management Country Lead, Perpetual Limited
    Streamlining Operations and Empowering Teams in Facilities Management

    Streamlining Operations and Empowering Teams in Facilities Management

    Shaye Rogers, Workflow Support Manager, Cushman & Wakefield
    Technocreativity: The Synergy Of Technology And Creativity

    Technocreativity: The Synergy Of Technology And Creativity

    Tran Nguyen Phi Long, Group Head Of Retail Marketing, Pnj Group
    Leading It And Digital Transformation At Ikea: Insights From An Industry Veteran

    Leading It And Digital Transformation At Ikea: Insights From An Industry Veteran

    Sigit Triwibowo, Head Of It And Digital, Chief Technology And Digital, Ikea
    Executive Leadership And Digital Transformation In The Global Fashion Industry

    Executive Leadership And Digital Transformation In The Global Fashion Industry

    Eiko Ando, E-Commerce And Digital Director, Pvh Corporation
    Digital Transformation in Fashion Retail - From Efficiency to Experience

    Digital Transformation in Fashion Retail - From Efficiency to Experience

    Le Van, CTO, YODY Fashion
    Loading...
    Copyright © 2025 APAC CIOOutlook. All rights reserved. Registration on or use of this site constitutes acceptance of our Terms of Use and Privacy and Anti Spam Policy 

    Home |  CXO Insights |   Whitepapers |   Subscribe |   Conferences |   Sitemaps |   About us |   Advertise with us |   Editorial Policy |   Feedback Policy |  

    follow on linkedinfollow on twitter follow on rss
    This content is copyright protected

    However, if you would like to share the information in this article, you may use the link below:

    https://cyber-security.apacciooutlook.com/cxoinsights/the-critical-future-of-identity-and-access-management-nwid-4159.html