In today’s digital landscape, identity and access management (IAM) is a critical part of enterprise security strategy. IT leaders need to rethink their internal processes to minimize the IT security risks and attack surface of their organizations. This is becoming increasingly complex as companies’ IT environments evolve.
Important findings
- Companies need to consider both human and non-human access controls.
- Regular checks of access permissions are essential to detect and manage privileges.
- Automation of processes such as account setup and deactivation can reduce human error.
- Phishing-resistant MFA techniques should be implemented instead of traditional methods.
- A strong security-conscious corporate culture is crucial for IAM governance.
The Complexity of IAM
IT leaders face the challenge of determining which employees and roles need access to which systems. This also includes non-human identities that gain access to IT resources. Varun Prasad, vice president of the ISACA San Francisco Chapter, emphasizes that companies often overlook or hastily handle key access management processes, which can lead to security risks.
Automation and Efficiency
To minimize human error, Prasad recommends automating key processes such as account setup and deactivation. An interface between the central IAM system and the human resources management system can automate the offboarding processes and ensure that access rights are regularly checked.
Phishing-resistant MFA
Given the increasing threats posed by cyberattacks, it is important to implement phishing-resistant MFA techniques. These techniques, such as WebAuthn and PKI-based authentication, eliminate the human factor and provide a more secure way to access systems.
The Role of Artificial Intelligence
According to Forrester, generative AI can help organizations identify new identity threats in different applications. Some IAM tools automatically generate identity and access policies to ward off threats. This also allows non-technical users to create simpler queries and reports.
Security-conscious corporate culture
Alongside technology, it is crucial to establish a strong security culture within the company. Companies should follow the principle of least privilege, track all identities and review permissions regularly. A well-managed IAM environment is the foundation of a strong cyber security strategy.
Proactive threat detection
IT security leaders should use their security operations to proactively detect and respond to threats. Developing capabilities to detect and analyze signs of potential compromises is critical to minimize the impact of successful phishing campaigns.
Conclusion
IAM is an essential part of defence against cyberattacks. Companies must consider both technological and human factors to develop an effective security strategy. By encouraging a security-conscious culture and implementing advanced technologies, organisations can significantly improve their security posture.
Sources
- IAM within the framework of defence in depth | Computer Weekly, Computer Weekly.



