New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

When protecting and managing digital identities, orchestration and automation are critical

New York Tech Editorial Team by New York Tech Editorial Team
January 20, 2022
in Cybersecurity
0
When protecting and managing digital identities, orchestration and automation are critical
Share on FacebookShare on Twitter

In this interview with Help Net Security, David Mahdi, CSO of Sectigo, talks about the importance of digital identity management, the issues organizations have with digital identities and what they can do to overcome them.

digital identity management

The rapid shift to hybrid work has left many organizations susceptible to cybercrime which leveraged identities to gain access. What was it that organizations did wrong?

In the rapid shift to hybrid many organizations did what they could to support their workforce. Legacy secure access and security were simply not enough. Unfortunately, bad actors leveraged this delicate situation, to their advantage. They knew, with simple reconnaissance that they could compromise many enterprises by targeting weak identities. Specifically, usernames and passwords, either alone, or in some cases bolstered with weak multi-factor authentication (such as SMS, which is no longer considered a strong option for MFA).

Organizations responded by introducing alternative methods for authentication, such as mobile push. This is a good move, but still only covers one piece of the puzzle, that is human identities. In reality, users leverage devices, such as laptops, tablets, and mobile phones to access the organizations’ applications and ultimately data.

This requires a completely different approach than what was practiced in the past. The approach needed is often called “zero trust.” Zero trust is a great concept, but it is only the first step in the journey to secure digital identities. What is needed at the foundation is identity-first security. Identity first security is a new concept, introduced by Gartner in 2021. It focuses on the notion that any entity, be a device, software, machine, or human requires digital identity.

With the explosion of digital and hybrid work styles, the amount of machine and human identities has increased dramatically. And it will continue to do so. As these entities connect to our networks, the chance that one of these identities can be compromised by bad actors increases. The first principle here would be to ensure that all human and machines are rooted in strong, non-reputable digital identities. The proven approach in the market today is with digital certificates, which leverage PKI. In fact, some of the best authentication mechanisms leverage digital certificates at their core. With more identities in an ecosystem, more certificates are needed to verify them to hold together the safety of the enterprise.

Although certificates offer the strongest possible safety net for identity-first security, they are notoriously hard to manage. Constantly expiring and requiring renewal, many unprepared organizations are still managing this vital utility with outdated manual means that are prone to human error. If a certificate inventory is managed ineffectively, it becomes highly vulnerable to outages, and security breaches.

What can organizations do to leverage and optimize identity-first security?

The challenge for businesses is to find a solution that can accurately manage this rapidly growing number of human and machine identities. It is no longer sustainable to simply buy more point-products to manage yet another security problem. In this case, when leveraging digital certificates as a baseline for human and machine identities, digital certificates must be provisioned to users and devices, and ultimately, orchestrated and automated.

Manual methods of managing certificates that businesses rely on are not only redundant but also potentially dangerous.

Organizations need to look towards end-to-end, cloud-based, automated, and orchestrated Certificate Lifecycle Management (CLM) solutions to give complete visibility and lifecycle control over any certificate in their environment. This will help them reduce risk and control operational costs. Furthermore, it will also allow them to enable new use cases that will drive further secure business enablement. Even in the most complex enterprise environments, certificate automation offers speed, flexibility, and scale. Full visibility into all digital certificates means that even the largest enterprises can have a centralized view of digital identities and security processes.

If certificate management is smartly orchestrated and automated, it can track things such as expiration dates, notify IT professionals when they’re approaching, and replace them without any manual labour from already overstretched IT teams.

What do organizations have to look out for when managing digital identities, for humans and machines?

First and foremost, orchestration and automation are critical. Limiting manual oversight will vastly reduce the chances of an expired certificate causing a breach or cyberattack. In addition to this, a cybersecurity strategy that invests in employee education is essential. For instance, Business Email Compromise (BEC) attacks are also notoriously difficult to prevent due to sophisticated social engineering techniques.

Businesses must invest time in educating their employees to spot and avoid the latest attack vectors. Implementing secure S/MIME email certificates is another essential step to decrease the chances of BEC and other email-based attacks. However, this should be done in concert with other identity-first principles such as strong authentication (for both humans and machines) as well as access management.

Is there a one-size-fits-all identity-first and digital identity management solution?

Unfortunately, there is no one-size-fits-all identity-first and digital identity management solution, as each enterprise requires different levels and methods of ensuring security, depending on their use cases, compliance, and relative risk profiles. However, all businesses must focus on certificate management as a means to protect all identities for humans and machines. Furthermore, as every single business relies upon email as a fundamental form of communication, any solution must excel in email certificate deployment, discovery, and renewal. As such, integration with common enterprise applications, and various other security solutions is needed to support an enterprise-wide notion of zero trust and identity-first security.

What improvements or developments could we expect when it comes to identity-first security and digital identity management?

While automation alleviates some human and machine identity management challenges, as they increasingly become rooted in digital certificates, the complexity of certificate management doesn’t end there. Most Certificate Authorities (CAs) that issue certificates tend to be reluctant to work together, meaning even the most sophisticated CLM solutions on the market cannot oversee the multitude of different CA-issued certificates in an organization. We will see further development of platforms that are certificate agnostic. Being ‘certificate agnostic’ means that a solution allows businesses to manage every certificate and digital identity in their organizations, no matter what CA it came from.

Furthermore, we will continue to see advances toward quantum-resistant certificates, as quantum computing inches closer to becoming a reality. Many academics and government-funded organizations are working hard to develop cryptographic algorithms that can resist quantum computing power in an attempt to avoid the ‘quantum apocalypse’ (the notion of “crypto-agility”). This is because current RSA and ECC algorithms used in our modern PKI infrastructure are unfortunately no match for this new computing paradigm.

Credit: Source link

Previous Post

Canon’s EOS R5C is a 2-in-1 stills and cinema camera

Next Post

The evolution of security analytics

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Shifting security further left: DevSecOps becoming SecDevOps

The evolution of security analytics

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025
Magnus Almqvist, new CEO of Exberry

Exberry Appoints Magnus Almqvist as CEO to Drive Next Phase of Strategic Growth

March 5, 2025
Expert Family Law Firms in New York: Your Essential Guide to Legal Help

Expert Family Law Firms in New York: Your Essential Guide to Legal Help

March 3, 2025

Recommended

Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media