As digital innovation accelerates, many organizations are adopting new technologies simultaneously. As a result, each new application or tool becomes a new identity silo with unique password management requirements, such as complexity and frequency of rotation.
Requiring to repeatedly authenticate to these new systems and maintain (not to mention remember!) numerous complex passwords creates many frustrations for help desk professionals.
They are in charge of user provisioning and manage hundreds (if not thousands) of corporate accounts and the resulting and ongoing requests for password reset and account lockouts. Let’s use some industry estimates and simple calculations to quantify the massive password problem:
Based on this data, CyberArk estimates that for a company with 1,000 employees, $495,000 is spent each year fixing password issues. (11 helpdesk password requests per user, x $45 per request x 1,000 users). It is well known that defining strong passwords is complex for users, and those chosen often need to be more involved, common, reused or shared. Employees reuse passwords on an average of 16 corporate accounts. While relying on password managers to solve this challenge is tempting, it still needs to be a risk-free approach. Furthermore, password managers cannot manage who accesses which sensitive resources and for how long.
Attackers know that many organizations still rely on a single verification method, such as a single set of credentials, to secure access to various systems and tools, especially dangerous behaviour when used with single sign-on, which allows broad access to many systems and applications. Cybercriminals know that stealing or compromising a corporate identity’s credentials is enough to gain a foothold and escalate privileges to high-value assets. Today, 67% of all breaches are caused by credential theft (using stolen or weak passwords) and social attacks.
However, when IT teams implement stronger authentication methods in the name of security, workers often develop clever ways to circumvent them or avoid using company-approved systems and applications to stay productive. According to SysAid research, 84% of IT service management professionals believe that IT service management will continue to get more difficult over the next three years, and the reason is clear given their anvil position (maintaining all systems and data as secure as possible) and hammer (keep teams productive). A more robust approach is needed as identity-based threats continue to grow and passwords fail to serve their purpose adequately.
It’s no longer about blocking access to attackers but about making it difficult for them to move around the network without setting off alarms to make them easier to spot and stop. Behind the scenes, controls such as session isolation and tracking, elevation and delegation are built into identity and access management capabilities to increase accountability and compliance. This way, access can be monitored on an ongoing basis in a data center, hybrid, multi-cloud and SaaS environments, and risk-based controls can be applied to each identity to streamline user activities.
Also Read: Manage Passwords With KeePass, The Easiest Way To Do It
There is not an industrial sector or a company that is not being transformed today… Read More
Although its logistics capabilities have been known for some time, RFID technology is now ready… Read More
There is great expectation for the future reform of the ePrivacy directive, which concerns the… Read More
How Many Steps Does Market Research Involve? The best technique for doing statistical surveying is… Read More
On September 9 and 10, Silicon is organizing two days of web conferences to share… Read More
Today's unpredictable business world presents serious security breaches and data theft threats as constant risks;… Read More