{"id":21968,"date":"2018-10-03T11:15:52","date_gmt":"2018-10-03T10:15:52","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=21968"},"modified":"2018-10-03T15:04:19","modified_gmt":"2018-10-03T14:04:19","slug":"beyondtrust-expert-on-privilege-security-for-the-new-perimeter","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2018\/10\/03\/beyondtrust-expert-on-privilege-security-for-the-new-perimeter\/","title":{"rendered":"BeyondTrust expert on privilege security for the new perimeter"},"content":{"rendered":"<p><em style=\"font-weight: bold\">Morey Haber, Chief Technology Officer, BeyondTrust,\u00a0<\/em><em><b>explains why a comprehensive approach to privileged access management (PAM) \u2013 which encompasses not just the full community of credentialed users but also the many technologies and systems that they can access \u2013 is the only way for organisations\u00a0to protect their critical assets in the ever-expanding IT perimeter.<\/b><\/em><\/p>\n<p>For all of information technology\u2019s benefits, most organisations are well acquainted with the by-product of rapid IT advances and expansion <strong>\u2013\u00a0<\/strong>increased cybersecurity risk. Indeed, growing cybersecurity concerns correlate directly with your organisation&#8217;s expanding digital universe and the number of people given some level of authority to operate within it.<\/p>\n<p>A swiftly expanding digital perimeter <strong>\u2013\u00a0<\/strong>both physical and logical <strong>\u2013\u00a0<\/strong>inevitably makes organisations more vulnerable to the so-called cyberattack chain, regardless of how far the perimeter has extended. The attack process starts with a successful perimeter breach or insider malfeasance, followed by the theft of &#8216;privileged&#8217; user credentials through either poor privilege security management or exploitation of a vulnerability. With privileged user IDs and passwords in hand, an attacker can then move laterally throughout an organisation, seeking its most valuable digital resources.<\/p>\n<p>As the IT perimeter continues to evolve, threats and risks become increasingly difficult for IT and security teams to manage as they try to connect the dots between privileged accounts, vulnerabilities, exploits and successful data and system breaches. This barrier is a big reason why compromised privileged credentials are such a dominant source of\u00a0successful attacks, accounting for 80% of all cyberbreaches,\u00a0Forrester Research estimates.<\/p>\n<p>Not all of these breaches involve cyberthieves or other outsiders stealing and then exploiting privileged credentials. In many cases, privileged users cause problems on their own, usually inadvertently through poor security practices but sometimes malevolently. Whether intentional or accidental, privilege-related breaches can bring devastating consequences.<\/p>\n<p>Regardless of the perpetrators and their intentions, it\u2019s clear that organisations generally haven\u2019t done enough to understand and manage their privileged accounts. That\u2019s a big problem because the need for privileged account access <strong>\u2013\u00a0<\/strong>and\u00a0management <strong>\u2013\u00a0<\/strong>will only become more pressing as IT and communications environments continue to expand beyond traditional firewalls.<\/p>\n<p><strong>The expanding IT perimeter<\/strong><\/p>\n<p>The days of computer users sitting only within the four walls of a secure and digitally isolated building are a distant memory. The adoption of mobile devices and cloud computing dramatically expanded the digital footprint of companies. The more recent emergence of Internet of Things (IoT) devices is accelerating this expansion and the spread of new processes and technologies, from DevOps to Artificial Intelligence, is adding ever more complexity across the digital landscape.<\/p>\n<p>This emergence of next-generation technologies (NGTs) makes it hard for IT and security teams to keep up. According to our\u00a0<a href=\"https:\/\/www.beyondtrust.com\/resources\/white-paper\/2018-implications-using-privileged-access-management-enable-next-generation-technology-survey\/\"><em>2018 study\u00a0of NGT trends and issues<\/em><\/a>, 78% of the participating IT professionals said security was a challenge associated with NGT adoption. A total of 20% said they had experienced five or more breaches related to NGTs over the prior 24 months, resulting in data loss, IT outages or compliance alerts. What was more revealing was that the cause of 85% of all NGT-related breaches involved privileged access <strong>\u2013\u00a0<\/strong>either authorised users unintentionally or intentionally doing inappropriate things or outsiders gaining privileged access to steal credentials.<\/p>\n<p>Further complicating matters, an organisation&#8217;s connected community now extends well beyond employees to include vendors, contractors, cloud services providers and others who have various levels of authority to access digital resources.<\/p>\n<p><strong>Adopting a privilege-centric approach<\/strong><\/p>\n<p>There\u2019s no turning back the clock when it comes to our expanding and increasingly complex digital footprint. It\u2019s time for organisations to get serious about placing their privileged accounts under tight control, regardless of their digital presence. To this end, a partial or piecemeal solution won\u2019t do. Organisations require a comprehensive approach to\u00a0privileged access management\u00a0(PAM) that encompasses not just the full community of credentialed users but also the many technologies and systems privileged access management\u00a0existing and emerging <strong>\u2013\u00a0<\/strong>that they can access.<\/p>\n<p>As with almost any other cybersecurity solution, the first step to a successful PAM deployment is to perform a comprehensive inventory of your organisation&#8217;s digital assets, processes, and <strong>\u2013\u00a0<\/strong>in this case <strong>\u2013\u00a0<\/strong>privileged accounts. Only after completing this initial discovery process can you perform a detailed risk analysis that identifies the most valuable or most sensitive data and systems, along with the most likely threats to their security.<\/p>\n<p>Another major element of a successful PAM strategy is controlling user and application access rights as securely as possible. Often that means rescinding existing privileged credentials if a user\u2019s or application\u2019s need to access sensitive resources should be limited. By enforcing\u00a0least privilege\u00a0and appropriate credential usage and providing the lowest level of actual privileges needed to perform a task, some PAM solutions can help control mushrooming numbers of privileged accounts.<\/p>\n<p>PAM solutions can also block access on the fly, by inspecting scripts; verifying commands; and, in some cases, performing dynamic vulnerability management. The goal is to reduce an asset\u2019s risk, whether targeted via a privileged attack vector or through a vulnerability and exploit combination. With 80% of attacks traced to privileged credentials, deploying a comprehensive PAM solution is among the most effective ways to greatly reduce the risk of cyber breaches, regardless of the attack vector.<\/p>\n<p>Lastly, organisations need to take a risk-based approach to planning,\u00a0prioritising and implementing PAM solutions. Organisations new to PAM may consider applying a PAM layer to their traditional business infrastructure and processes, or they may opt to prioritise deployment for the NGTs that pose the greatest risk. In either case, it\u2019s crucial to select a PAM solution that provides the flexibility and capability to not only address current challenges but also grow and mature in step with evolving business needs.<\/p>\n<p><strong>The answer \u2013 a sophisticated solution<\/strong><\/p>\n<p>To provide these and other advanced PAM functions, organisations should consider a fully integrated and comprehensive PAM platform that provides one set of interfaces for\u00a0password and session management,\u00a0privilege management,\u00a0vulnerability management. The solution should also be able to be deployed in any format: as software; as a virtual or physical appliance; or as a\u00a0cloud service\u00a0on\u00a0Amazon Web Services,\u00a0Microsoft Azure or\u00a0Google Cloud.<\/p>\n<p>By deploying multiple platform components as software or appliances, organisations can scale their solution to accommodate any environment by using a simple, role-based model for features, functions and secure architecture. Such an extensible-platform approach can provide best-of-breed capabilities to protect privileges across traditional, emerging and next-generation technologies.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Morey Haber, Chief Technology Officer, BeyondTrust,\u00a0explains why a comprehensive approach to privileged access management (PAM) \u2013 which encompasses not just the full community of credentialed users but also the many technologies and systems that they can access \u2013 is the only way for organisations\u00a0to protect their critical assets in the ever-expanding IT perimeter. For all [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":21972,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,399],"tags":[386,393,5772,6839,6840,388,6841,291,1259,307,155,547,6842,6843,6844,6845],"class_list":["post-21968","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-more-news","tag-artificial-intelligence","tag-beyondtrust","tag-chief-technology-officer","tag-credentials","tag-cyberbreaches","tag-cybersecurity","tag-cyberthieves","tag-devops","tag-firewalls","tag-forrester-research","tag-internet-of-things","tag-morey-haber","tag-ngts","tag-pam","tag-privilege","tag-privileged-accounts"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/21968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=21968"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/21968\/revisions"}],"predecessor-version":[{"id":21970,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/21968\/revisions\/21970"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/21972"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=21968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=21968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=21968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}