In today’s world of access, companies must increase their Identity and Access Management (IAM) maturity to effectively reduce the likelihood of a data breach. A recently commissioned study conducted by Forrester Consulting found that two-thirds of organisations have been breached five times in the past two years. It’s clear that traditional approaches are not working, and companies need to completely rethink their security approach. Companies must employ IAM approaches as well as use integrated IAM technology platforms to reduce security risk in today’s boundaryless hybrid enterprise.
The Forrester study found that organisations without a mature IAM approach experience two times more breaches and $5 million more in costs than those with a mature IAM approach. The study examined four levels of IAM maturity, and found a direct correlation between a mature IAM approach and reduced security risk, improved productivity, increased privileged activity management and greatly reduced financial loss.
Below are a few best practices for enterprises to improve IAM maturity and reduce security risk:
1. Consolidate Identities
According to Verison, 80 percent of breaches are due to compromised credentials. It’s critical to develop a holistic view of all users and strengthen and enforce password policy, or eliminate passwords, where possible.
2. Enable Single-Sign-On (SSO)
SSO to enterprise and cloud apps, combined with automated cloud application provisioning and self-service password resets, cuts helpdesk time and cost, and improves user efficiency.
3. Implement Multi-Factor Authentication (MFA)
MFA, including third parties and the VPN that adapts to user behaviour, is widely acknowledged as one of the most effective measures to prevent threat actors from gaining access to the network and navigating to target systems.
4. Audit Third-Party Risk
Outsourced IT and third party vendors are a preferred route for hackers to access corporate networks. Conduct audits and assessments to evaluate the security and privacy practices of third parties.
5. Enforce Least-Privilege Access
Role-based-access, least-privilege and just-in-time privilege approval approaches protect high value accounts, while reducing the likelihood of data loss from malicious insiders.
6. Govern Privileged Sessions
Logging and monitoring of all privileged user commands makes compliance reporting a trivial matter and enables forensic investigation to conduct root cause analysis.
7. Protect The Inside Network
Network segmentation, isolation of highly sensitive data and encryption of data at rest and in motion provide strong protection from malicious insiders and persistent hackers once inside the firewall.
A breach can wipe out company value as seen with Yahoo!’s acquisition price devaluation of $350 million and with Chipotle’s loss of $400 million in shareholder value after their breaches were announced. The stakes for properly securing access to corporate resources and handling security incidents couldn’t be higher. In fact, a recent Ponemon research study found that stock prices fall an average of five percent, customer churn can increase as much as seven percent and brand reputation is tarnished after a data breach is disclosed. In order to avoid financial and reputational ruin, organisations must rethink their traditional endpoint and firewall security approach and add identity security into their arsenal against cyberattacks.