A look at the evolving definition of privilege from an Identity Security context, from the early days of productivity-led IAM to modern ITDR.
A look at the evolving definition of privilege from an Identity Security context, from the early days of productivity-led IAM to modern ITDR.
The speaker discusses the evolving definition and role of privilege in identity security, highlighting its history and current relevance. He explains that privilege, traditionally seen as a special right or advantage, is being redefined in the context of identity security due to changes brought about by cyber threats and technological advancements. The speaker outlines the evolution of identity security from simple, productivity-focused solutions in the 1990s to the complex, security-driven approaches of today. He categorizes this evolution into several stages, from the initial focus on user ID and password management to the current emphasis on real-time threat detection and response. The speaker stresses the need for a new approach that includes managing not just human identities but also non-human identities—such as API keys and scripts—that hold privileges within networks. These non-human identities present significant security risks due to their often-poor management and high-standing privileges. The speaker argues for convergence in identity security platforms, advocating for comprehensive management and governance of all identity types, with a focus on risk-based rather than compliance-driven security measures. He calls for organizations to adopt a model that embraces zero-standing privilege policies and lifecycle management, with particular attention to encryption, rotation, and secure vaulting of secrets. The talk concludes with a reminder that compliance should be viewed as a baseline, not the goal, for security standards, and a call to action for companies to address the security of non-human identities.
Thanks Warwick, and I hope, I was in microphone problems at the back so I hope it's coming through, it sounds like it's fine. So I thought it would be interesting for us to examine the definition of privilege, right, and how that's changed through the evolution of identity security. So I work for an organization called Arcon.
I've previously had go-to-market leadership positions at Novell and NetIQ and SailPoint and Savient, and now I'm at Arcon, who are, if you're not familiar, are best known as an overall leader in the PAM space for Privileged Access Management, but we're also the first to market with a converged identity solution, and I'll talk about how we believe the worlds of identity security are converging through the presentation. So my slides are up.
So the agenda, I want to talk about the definition of privilege, or more accurately, the definition of privileged resources and access, from three different perspectives. So from, because they are quite different, so the kind of definition of privilege, the dictionary definition of privilege, us as identity security professionals, what our kind of definition of privilege and privileged identity is, and then a different perspective which hopefully will expose the kind of delta in our understanding and how it needs to move.
I'll then talk about how that's relevant to identity security since probably the late 1990s up until the kind of identity security solutions in the modern era. So we'll talk about the different types of identity after that, the kind of explosion of both human and non-human identity types, and on from that, the types of privileged resources that are generally attached and owned or accessed by those identity types, and then we'll draw some conclusions.
If we've got some time, I think maybe we'll do some Q&A if you've got interest, but I would warn you I'm not the world's most technical person before you ask me a very technical question. So let's start. So what is the definition of privilege? So the dictionary definition says it's a special right, advantage or immunity, granted or available only to a particular personal group. So that's the kind of what most people think of as a privilege, something above standard level.
And this, and I'll talk about this in the slides in a moment, and this is kind of very similar to when the world was simpler, right? So in the first kind of era of identity security, before we had lots and lots and lots of breach and cyber attack, we tended to think of privilege as someone that had different types of permissions. They had create, read, write type permissions. They were a domain admin or a local administrator or an application admin, and it was pretty clear-cut about what was normal and what wasn't.
So that was kind of easy back in 1995 about who's privileged and who's not, right? Bear that in mind and remember that for later. And then we talk about it from all of us, probably most of the room are identity security professionals, and so our understanding is like I've just mentioned really, it comes from does that person have a privileged role or some type of privilege within the organisation?
And I think we're encumbered a little bit, particularly the older members, myself included, by the history of identity security because we still think of those old definitions of what constitutes privilege, and that is actually dangerous in today's world when we need to think of privilege differently. And that brings me on to a different perspective altogether, the perspective of the person we're trying to fight against, the cyber attacker, right? Their definition, and by the way, I've written this before, so you can disagree with it or its opinion.
It's not a definition that I've downloaded or anything, or there's no AI in my presentation. But my view is this is the definition of a cyber attacker, right? A privilege is, or something valuable in the organisation which should be protected by privilege, is anything that can be disrupted for fun sometimes, ransom sold, often for financial reward. That's what cyber attackers are looking for. There's a reason that the most common type of breach attempt in every enterprise these days is credential-based attack, right?
So these cyber attackers are not looking for credentials that give access to standard. They want privileged credentials. They want to get hold of privileged credentials any way they can. But whereas we used to think of privileged users as domain admins with write and create permissions that could really change something, the definition of value to these guys up here might be just a read permission on a data file that they can put on the dark web and sell that creates credentials, right?
So my point there is the old view of the difference between privileged and not is very different 15 years ago than it is today, right? So we need to start thinking differently about what a privileged resource is and what privileged access is, right? So here we go. I know it's a pretty busy slide. We'll talk about the evolution. I've talked about some of this already, but I put them into life cycles, really. I've been around in this industry since identity 1.0 just about, so I've kind of lived through this.
Again, I've given my own opinions on these. But 1.0 is when the world was pretty simple. There was very little breach going on. We kind of invented solutions based on productivity needs. We had lots of people. We were giving them access to applications. They required some type of user ID and password, and a productive way to do that efficiently on the first day of their employment was to give them kind of JML, joiners, movers, leavers activity, but it was all really driven out of a need for more productivity, more cost-saving, right?
And then we go to 2.0, and they were generally, we started to see certain types of cyber attack, and so, therefore, we were seeing some compliance that was coming into various fields, particularly in financial services and healthcare where real protection was necessary, and maybe some central and local government. Now, the problem as we used to talk about it back then is compliance was a pretty low standard, actually. Compliance was not, for some organisations, maybe not, but compliance is not an aspirational standard.
Now, I've known many companies throughout the years that have been compliant but not secure, and actually, I've known many companies that were very secure but, ironically, were non-compliant with some of the standards that were in their vertical or their industry. So, the issue is that compliance needs to be a standard that can be achievable by a small or medium enterprise business, right?
So it's certainly not an aspirational standard of security, and that's what we've seen, and often you'll see professionals say that the compliance standard is way behind where you need to be to be secure as an organisation. Then we get to 3.0, and we tend to be very security-focused by this point back in 2015.
You know, we're all starting to do things in kind of real-time or near real-time. We're starting to present information on a risk basis, or maybe some UEBA was included in terms of analysing the behaviour of certain types of usage. We're doing some clever things in line in a preventative fashion, things like SODs to ensure we've not got toxic combinations of access that were really risky for organisations. So we've got to a point where the human identities in this era, in my opinion, were pretty well managed, right?
We were analysing different human identity types, workforce, collaborators, third parties, vendors, you know, and giving them certain types of access and collaboration to be able to do their jobs, again, more efficiently but with security. Then we get to 4.0, and that's kind of where we are now. And this is where I think we need some radical change, actually, and some of you agree, some of you might disagree, and it kind of, actually, my view on convergence, because there's a lot of different views on convergence, right?
I believe, because the platforms are now capable, and they have the kind of elastic capability to be able to deliver entitlement-level operations in real-time, you have the ability now to move to kind of an ITDR model, right?
Something that works in real-time, it's got a lot of in-line processing, a lot of in-line analysis based on analytics and behavioural stuff, and you can prevent the incorrect behaviour, or you can report, or you can alert, or you can generally kick off activity in the joiners, movers, leavers life cycle, or the appropriate alerting to be able to, in real-time, visualise something that's going wrong in an application or an endpoint with a human identity, right? That's where we kind of are now. Identity threat detection and response, right? Often in real-time.
So, here's the problem. What we focused on, what a lot of us, not exclusively, but what lots of us have focused on are those human identity types. We all have an opinion, or lots of us have an opinion that the most common type of breach is looking for human credentials with privilege, and so we need to be cautious and careful about how we deliver privilege to humans, right? Absolutely. We should implement things like least privilege. We are living in a world now where you can almost get to a model where privilege is only where necessary, or any kind of step-up is only where necessary.
It doesn't need to be there inherently in things like roles, right, or groups, or permissions. It can be delivered when it's needed, and when it's not needed after that, it can be deprovisioned away again, right? There are ways to deliver that on the human basis. Unfortunately, there's been very little focus, or relatively little focus, on non-human identities, right?
And what we are seeing, credential-based attack obviously forms the largest threat vector to the average enterprise is what they're most concerned about, some type of attack that includes credentials to get hold of privileged resources and information and data. Within these non-human identities, and you can look at the standards of people that are kind of in close agreement with some of the things we feel, people like the NHI group downstairs, Lalit Chodha's group, is an interesting kind of study that's very similar to look at.
We have credentials in plain form in things like API keys, and scripts, and some of the other types you see here, and they're relatively poorly managed, right? So, often we've got organisations that don't gather, discover, visualise, manage, and govern all of these types of secrets, and put them in vaults with rotation and strong encryption standards, and that is fast becoming well-known to the cyber-attacking community, and that is often seen as a better route of entry into large enterprise, right?
And, ironically, again, often the credentials stored in plain form sometimes in lines of code and scripts often contain pretty high privilege, and it's standing privilege to gain access into those applications, to write or carry out crud activity within those applications. So, what we now, what some of us now regard as an identity type, what we used to talk about is some of these would be kind of assets.
Now we think of them, certainly a lot of professionals that I talk to now think of them as identity types, right, because they are having the same kind of status in your network, they're containing credentials that allow access to other pieces of the network, and so they operate very much like an identity, so we are calling them non-human identities.
In terms of the resources that we're talking about, we're talking about the classic examples of the user accounts, entitlements, type hierarchy that we've always looked at in identity security, you know, user IDs, password, roles, groups, accounts, entitlements.
But then after that, there's some up here, some of you this will not be news to, right, some of them it might be patronising to some of you, because you're already far ahead of what I'm talking about anyway, but anything in 2025 that contains the ability to move to somewhere that is privileged in the organisation, let's put it that way, needs life cycle management, right, so it needs to be, it needs a concept of ownership, it needs a concept of governance in terms of encryption and rotation, and it needs to be on a least privileged model, right, so we talk about all these other types of secrets that require good vaulting policy, good kind of rotation policy, and so these are the kind of things that we believe should all be controllable and governable within a converged platform.
So, our view at Archon of convergence is to deliver a platform that looks at all types of identity, human and non-human, with privilege over the top whenever necessary, from the time they are created to the time they disappear, right, so the full life cycle across all of these types.
So, that's what we believe is both the recommended standard and in fact the necessary standard now with large enterprise, to leave these kind of uncovered parts of the network and get much stronger security techniques across them, particularly NHI, you know, I know lots of enterprises have still got lots of work to do in their human identity strategy, but relative to their non-human identity strategy, it's pretty well catered for, right, we would recommend organisations start to at least consider what their strategy is for NHI, for non-human identities.
So, in conclusion, so we believe that all identity types need management and governance, that credential-based attack will continue absolutely to be the most common form of breach whilst it is lucrative and achievable. Managing privileges calls for, there are different views of convergence and what it means, but in our view, convergence means a full life cycle platform for human and non-human assets.
There needs to be, as a minimum standard, encryption and rotation for all secrets, with appropriate vaulting, and organisations need to move away from batch-type governance, often driven by compliance actually, to more risk-based or event-based governance. The obvious example there is where we talk about certification and recertification and those kind of campaigns. In this day and age, really, compliance needs to catch up because you don't need to deliver that way, right, we can deliver things based on entitlement execution, risk, recertification and deliver least privilege.
Again, my kind of key takeaway, or one of them, is compliance is generally a minimum standard and falls far short of providing security. So, that, I believe, is everything. I've got 15 seconds, so it's timed. I don't know whether there is any burning question for anyone.
If not, feel free to come see us, come learn our story. Archon are a platinum sponsor here.
Obviously, we're an overall leader in the PAM space, and we are down at stand 11. So, feel free to spend time with my team to talk about some of the things I've mentioned. Thank you very much. APPLAUSE Thanks, Grant. I really like what you had to say about compliance and security. I don't think I've come across the situation where they've been secure but not compliant very often. It's more often than not the other way around.
But, you know, hey. So, in the light of what you've been saying this afternoon, I was just wondering whether you think traditional PAM models are still relevant, or do they need a fundamental rethink in 2025?
I mean, is that kind of... Well, I don't want to be negative about the competition.
Look, it's better than not having a PAM strategy, absolutely, right? But it's not about throwing a tool at the problem, right?
I mean, we are talking here about the policies of zero-standing privilege are not solved by a tool. They're solved by a policy within the organisation, right?
So, and then the tool can deliver against that. I think there are... I think we're seeing a strong move to the cloud. I think at the moment, if I just look at PAM, about 40% of that is in cloud deployment, which actually opens up capabilities because of the just general processing capability and elasticity of the cloud. But that's the growing part of it. I think that will make a difference, and lots of legacy tools don't have either a cloud solution or don't have the ability to deliver the same kind of parity of functionality in a cloud move.
So, yes, right? And we're seeing that this is borne out in the buying behaviour across the PAM industry.
Okay, great. Thanks very much, Grant Evans. Thank you.
See All Locations
See All Locations