Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Identity security is undergoing a transformation
Global Security

Identity security is undergoing a transformation

AdminBy AdminOctober 23, 2024No Comments5 Mins Read
Permiso
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 23, 2024Hacker newsIdentity Security / Data Protection

permission

Identity security is front and center in all of the recent breaches, including Microsoft, Okta, Cloudflare, and Snowflake, to name a few. Organizations are beginning to realize that changes are needed in how we approach identity security from both a strategic and technological perspective.

Identity security is about more than just providing access

The traditional view that identity security is primarily concerned with granting and denying access for applications and services, often piecemeal, is no longer sufficient. This view was reflected as a broad theme in Permiso Security Identity Status Report (2024)which finds that despite growing confidence in the ability to identify security risks, nearly half of organizations (45%) are still “concerned” or “very concerned” that their current tools are capable of detecting and protecting against identity security attacks data.

Identity security

The survey, commissioned this summer by Permiso, surveyed more than 500 IT security and risk professionals who directly oversee or influence security and risk decision-making. The findings show that despite increased investment, maturity and confidence in controls to mitigate cyber risks, organizations remain concerned in the face of growing identity threats.

Key ideas include:

  • SaaS is seen as the riskiest environment.
  • 93% of organizations said they can inventory credentials across all environments and track keys, tokens, certificates, and any modifications made to any environment.
  • 85% can determine “who does what” through fragmented authentication boundaries.
  • 45% are still “concerned” or “very concerned” that their current tools are capable of detecting and protecting against identity security attacks.
  • 45% suffered an identity security incident in the past year, with phishing attacks the top threat vector.

Can you spot the crooks?

While 86% of organizations said they can identify their most risky identity (human and non-human), nearly half (45%) suffered an identity security incident in the past year, with phishing attacks the top threat vector – showing that social engineering-based attacks continue to be a pervasive threat to organizations.

When it came to the consequences for those who were breached, sensitive data, which included personally identifiable information (PII) and intellectual property (IP), topped the list for 54% of those who were breached. 46% of organizations said threat actors have also escalated privileges and harassed their supply chains (45%) from both their suppliers and customers.

Identity security

Human identities remain an easy target

Another interesting finding is that human identities are seen as the most risky, with employees at the top of the list. Contrary to much of the hype in the market, non-human entities (API keys, OAuth tokens, service accounts) are considered less risky than their human counterparts.

Identity security

Identity security is closed

It is unclear whether organizations understand the responsibility of identity security in a hybrid and multi-cloud reality. While most organizations use an average of 2.5 public clouds, the IT team (56%) was identified as primarily responsible for ensuring identity security for the organization across multiple environments. This may reflect an identity that is still considered limited to granting and revoking access. According to Jason Martin, co-CEO and co-founder of Permiso, this finding can be explained by the fact that “Identity security has traditionally been the domain of shared responsibility of IT custodians, which includes access provisioning and identity security. Only a minority organizations, we view the security department as the primary stakeholder for ensuring the security of personal data.”

Identity security

Security budgets also appear fragmented, with SaaS (87%) and IaaS (81%) environments accounting for the bulk of security spending compared to all environments (46%). In terms of tools, it appears that the IaaS tier (66 %) has focused on a combination of proprietary cloud-based security tools such as AWS GuardDuty and CNAPP solutions.

​​​​​​While most organizations appear to be “risk aware” of the cyber threats they face, it is clear that we have some way to go to be able to detect and respond to identity threats as they occur. In fact, the ability to detect and prevent credential breaches, account hijacking, and insider threats were cited as top concerns for organizations.

Towards Universal Identity Security

It is up to all of us, vendors, organizations and the wider security community to do what is needed in terms of people, processes and technology to ensure the new reality of human and non-human identity as the leading threat vector. In this regard, we need to reframe identity security from simply granting or denying access to applications and services to seeing it as a strategic business enabler.

Permiso Security was created to solve this problem, making unified identity security for all identities in all environments a reality.

You can access the full report here: https://hero.permiso.io/state-of-identity-security-survey-report-2024

Learn more about how Permiso can help bring this strategy to your organization.

Did you find this article interesting? This article is from one of our respected partners. Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.