{"id":35019,"date":"2019-03-28T08:28:44","date_gmt":"2019-03-28T08:28:44","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=35019"},"modified":"2023-10-02T10:59:29","modified_gmt":"2023-10-02T09:59:29","slug":"protecting-your-enterprise-with-privileged-access-management","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/03\/28\/protecting-your-enterprise-with-privileged-access-management\/","title":{"rendered":"Protecting your enterprise with Privileged Access Management"},"content":{"rendered":"<p><em><strong>With traditional perimeter security tools unable to cope with advanced cyberattacks, John Hathaway, Regional Vice President &#8211; Middle East and India at BeyondTrust, tells Intelligent CIO about the benefits of Privileged Access Management (PAM). He says: \u201cModern PAM technology can ensure that only authorised individuals have access to your powerful privileged accounts and only in a fully audited manner.\u201d\u00a0<\/strong><\/em><\/p>\n<p>In today\u2019s world cyberattacks have become ubiquitous. Consider the famous words of former Cisco CEO John Chambers: \u201cThere are two types of companies: Those that have been hacked, and those who don&#8217;t know they have been hacked.\u201d<\/p>\n<p>So, if it\u2019s inevitable that intruders will get in, the question you should ask is: How will I protect my organisation after hackers breach our network perimeter?<\/p>\n<p><strong>The privileged account attack vector<\/strong><\/p>\n<p>First, consider what usually happens during a cyberattack. Obviously, hackers get inside your network. And they do it with social engineering, phishing emails, malicious insiders, zero-days, or a host of other tactics.<\/p>\n<p>Most of these attacks can quite easily defeat traditional perimeter security tools like antivirus or firewalls that are defending against yesterday\u2019s threats. Once they\u2019re inside, the intruders look for ways to expand their access. To do that, they install remote access kits, routers and key loggers.<\/p>\n<p>During this phase of an attack, hackers seek SSH keys, passwords, certificates, Kerberos tickets, and hashes of domain administrators. Their goal is to extract the credentials that will let them escalate their access, gain lateral movement throughout the network and anonymously steal data at will. \u00a0In our automated world, this entire \u2018land and expand\u2019 process can be conducted surprisingly quickly.<\/p>\n<p>But usually the attackers will take their time. They\u2019ll quietly monitor and record activity on your systems and then use the information they gather to expand their control of your environment. According to research from Ponemon, hackers lurk on the network for an average of 206 days before being discovered. That\u2019s a lot of time for a malicious entity to anonymously prowl your network.<\/p>\n<p>The key factor in this process is privileged access. With access to an unsecured privileged account, an attacker can view and extract sensitive data, change system configuration settings, and run programs on almost any IT asset in an organisation \u2013 on premises or in the cloud.<\/p>\n<p>In large enterprises there are so many privileged accounts, that organisations often can\u2019t keep track of where all their privileged accounts reside or who can access them. Unfortunately, though, almost every one of these powerful privileged accounts represents an attack vector that can be exploited by an insider threat or an external hacker. And it only takes one breached privileged account to snowball into a disaster.<\/p>\n<figure id=\"attachment_35027\" aria-describedby=\"caption-attachment-35027\" style=\"width: 1000px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-35027\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2019\/03\/BeyondTrust-John_Hathaway-1000.png\" alt=\"\" width=\"1000\" height=\"1000\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2019\/03\/BeyondTrust-John_Hathaway-1000.png 1000w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2019\/03\/BeyondTrust-John_Hathaway-1000-150x150.png 150w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2019\/03\/BeyondTrust-John_Hathaway-1000-300x300.png 300w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2019\/03\/BeyondTrust-John_Hathaway-1000-768x768.png 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><figcaption id=\"caption-attachment-35027\" class=\"wp-caption-text\"><em><strong>John Hathaway, Regional Vice President &#8211; Middle East and India at BeyondTrust<\/strong><\/em><\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p><strong>Privileged identities are often overlooked<\/strong><\/p>\n<p>When I describe this situation to people, it\u2019s usually at this point where they tell me they have an Identity and Access Management (IAM) tool to handle the problem. No, actually you don\u2019t, I respond. Here\u2019s why: \u00a0IAM products deal primarily with user accounts associated with personal logins. Organisations use IAM solutions to provision and de-provision users.<\/p>\n<p>However, privileged identities aren\u2019t managed by standard IAM systems. Unlike user identities, privileged identities aren\u2019t typically provisioned. Instead, they appear on the network whenever physical and virtual IT assets get\u00a0deployed or\u00a0changed. As a result, it\u2019s necessary to discover and track privileged identities with software that\u2019s separate from conventional IAM. That\u2019s where Privileged Access Management (PAM) comes in.<\/p>\n<p>Privileged identities are separate from user identities. They\u2019re different technologies. Industry analysts write about them in separate reports. Software vendors usually specialise in one or the other. At a fundamental level, the idea of a regular user and a privileged user are different.<\/p>\n<p>If user identities are the keys that employees carry to open the front door of the office, privileged identities are the keys used by the security guards to get into every door in the office building.<\/p>\n<p>User identities are tied to a particular person. All the things in the IT infrastructure connected to that particular person are traced to his or her digital identity.<\/p>\n<p>Privileged identities, on the other hand, are not mapped to a single person. They\u2019re used by many people. And sometimes they\u2019re not even used by people, like the privileged identities created to run service accounts. So, PAM must account for the fact that the people using a privileged identity may be different at any given time. Therefore, it\u2019s essential to have a way to track who has privileged access and control what they are doing with that access.<\/p>\n<p><strong>Automating cybersecurity with Privileged Access Management <\/strong><\/p>\n<p>Now, let\u2019s bring this back to the question posed at the start of this article. If it\u2019s inevitable that intruders will get in, how will I protect my organisation after hackers breach our network perimeter?<\/p>\n<p>Traditional perimeter security tools can\u2019t cope with advanced cyberattacks or carefully crafted social engineering exploits. Once the intruders penetrate the perimeter, conventional IAM solutions don\u2019t defend the powerful privileged identities that attackers need to accomplish their nefarious plans.<\/p>\n<p>But PAM technology does. With a PAM solution you can automatically discover all the privileged accounts throughout your cross-platform network. Just one vulnerable account can open your entire network up to compromise.<\/p>\n<p>Manually finding and tracking all the privileged accounts in large enterprise environments is virtually impossible. And if you can\u2019t find your privileged accounts, you can\u2019t secure them. But just because you may not know where all your privileged accounts reside, doesn\u2019t mean the bad guys can\u2019t locate them \u2013 and exploit them. So, finding your privileged accounts is step one.<\/p>\n<p>Securing them is step two. That involves generating unique and cryptographically complex credentials for each account \u2013 and continuously updating them. Manual password change processes can\u2019t keep up with the scale required in large organisations.<\/p>\n<p>But with automated PAM technology you can change these credentials as frequently as your policies require \u2013 even every couple of hours. That effectively negates advanced cyberattacks like zero days and keeps intruders from nesting in your environment. The reason being, even when an intruder steals one of your credentials, that stolen credential is time-limited and unique. So, it can\u2019t be leveraged to leapfrog between systems and anonymously extract data.<\/p>\n<p>Once an automated PAM solution finds your privileged accounts and then secures them, the next step is controlling access. Modern PAM technology can ensure that only authorised individuals have access to your powerful privileged accounts and only in a fully audited manner. There\u2019s no more mystery around who had access to what and when.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With traditional perimeter security tools unable to cope with advanced cyberattacks, John Hathaway, Regional Vice President &#8211; Middle East and India at BeyondTrust, tells Intelligent CIO about the benefits of Privileged Access Management (PAM). He says: \u201cModern PAM technology can ensure that only authorised individuals have access to your powerful privileged accounts and only in [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":35021,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,139,36,15963,93,3629,332,13,79],"tags":[1102,293,159,1812,1083,8456,562,5943,8457,2257,3518,6775],"class_list":["post-35019","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-industry-expert","category-intelligent-technology","category-kuwait","category-main-story-newsletter","category-newsletter","category-software","category-top-stories","category-used","tag-beyondtrust","tag-cisco","tag-cyberattacks","tag-india","tag-john-chambers","tag-john-hathaway","tag-middle-east","tag-pam","tag-pam-technology","tag-perimeter-security","tag-privileged-access-management","tag-privileged-accounts"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/35019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=35019"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/35019\/revisions"}],"predecessor-version":[{"id":35029,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/35019\/revisions\/35029"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/35021"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=35019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=35019"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=35019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}