July 6, 2016 By Patricia Diaz 2 min read

In the early 1900s, Henry Ford discovered and addressed the weakest link in auto manufacturing: the production process. By creating the assembly line, Ford not only made the Model T widely available and affordable, but he also precipitated a global revolution in manufacturing, reshaped commerce and mobilized the world.

If you think of the world’s greatest inventions, such as Ford’s assembly line, you will find they all successfully address the weakest link in their respective fields. But when it comes to avoiding a data breach and improving security, what is our weakest link? Unfortunately, the answer is people.

Our heavily reused “123456” passwords or our susceptibility to clicking on phishing emails is not the biggest problem. One of the most significant hurdles is our lag in adopting technologies that truly target identity and access management (IAM) threats.

The Proof Is in the Pudding

The Verizon “2016 Data Breach Investigations Report” found that 63 percent of confirmed data breaches involved leveraging weak, default or stolen passwords. You can interpret this finding in one of two ways: The first and most obvious way is that 63 percent of data breaches are due to careless users. In fact, the report stated that the common threats associated with attacks involving legitimate credentials were, among others, stolen credentials and social phishing.

Now, the other way to interpret the statistic is to consider that if something as simple as stealing a user’s credentials is enough to expose sensitive information, organizations are not sufficiently utilizing intelligent access management practices.

I agree with the latter reasoning. Henry Ford did not lay blame on his plant workers for being the weakest link in his manufacturing process. Instead, he developed the technology that enabled his employees to work eight times faster — and therefore cheaper — than they could before.

Similarly, we should not blame end users for being the weakest link in security. Instead, we should acknowledge that users are the victims of sophisticated, continuously evolving malware and tricky phishing scams. We should enforce appropriate policies that can control access beyond easily stolen usernames and passwords.

Authenticating Beyond the Username and Password to Prevent a Data Breach

Back in 2004, Bill Gates predicted the death of the password. But now, 12 years later, it seems like we are clicking on “forgot password” more than ever. Given the rise in major data breach reports in recent years — and the role that stolen credentials play in those incidents — it is clear that many current access technologies might have been appropriate 12 years ago, but not today.

It is more important than ever to authenticate beyond username and password. Enforcing risk-based access policies can dynamically step up authentication in high-risk situations.

Risk-based access operates under a set of policy rules that determine, based on a calculated risk score, whether an access request should be permitted, denied or challenged. Attributes that impact the risk score of a specific request can include IP reputation, the user’s behavioral patterns, device characteristics and more. For instance, a banking application could take into account both the amount of funds looking to be transferred by a user as well as the user’s physical location to determine if stronger authentication is needed or if the user should be denied authorization to perform the requested transaction altogether.

Risk-based access allows for organizations to create policies that control access dynamically, adapting to the ever-changing ways users are accessing and consuming information. There are enterprise-grade IAM solutions that secure access points and corporate networks through risk-based access capabilities.

More from Identity & Access

Taking the complexity out of identity solutions for hybrid environments

4 min read - For the past two decades, businesses have been making significant investments to consolidate their identity and access management (IAM) platforms and directories to manage user identities in one place. However, the hybrid nature of the cloud has led many to realize that this ultimate goal is a fantasy. Instead, businesses must learn how to consistently and effectively manage user identities across multiple IAM platforms and directories. As cloud migration and digital transformation accelerate at a dizzying pace, enterprises are left…

“Authorized” to break in: Adversaries use valid credentials to compromise cloud environments

4 min read - Overprivileged plaintext credentials left on display in 33% of X-Force adversary simulations Adversaries are constantly seeking to improve their productivity margins, but new data from IBM X-Force suggests they aren’t exclusively leaning on sophistication to do so. Simple yet reliable tactics that offer ease of use and often direct access to privileged environments are still heavily relied upon. Today X-Force released the 2023 Cloud Threat Landscape Report, detailing common trends and top threats observed against cloud environments over the past…

Artificial intelligence threats in identity management

4 min read - The 2023 Identity Security Threat Landscape Report from CyberArk identified some valuable insights. 2,300 security professionals surveyed responded with some sobering figures: 68% are concerned about insider threats from employee layoffs and churn 99% expect some type of identity compromise driven by financial cutbacks, geopolitical factors, cloud applications and hybrid work environments 74% are concerned about confidential data loss through employees, ex-employees and third-party vendors. Additionally, many feel digital identity proliferation is on the rise and the attack surface is…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today