enterprisesecuritymag

3 Challenging Aspects of Identity and Access Management

Enterprise Security Magazine | Monday, May 20, 2024

Another challenging aspect for IAM is that it is hard to convey how important the data is to the company. A breach will affect the company's reputation—there could be fines, and one could lose significant sums of money, intellectual property, and more in the event of a breach.

FREMONT, CA: Database and password occurrences are so common today that it takes a huge breach to make headlines. Coverage of these violations also highlights that the stolen credentials were a crucial part of the network's infiltration. While one knows that credential fraud is often at the center of these events, why is it so difficult to persuade the organizations, leaders, workers, and consumers to take Identity and Access Management (IAM)? Below are three reasons.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

1. IAM Is Hard to Explain

It is pretty easy to explain the description of a firewall. Although firewalls have their intricacies, they are much easier to explain to the organization, but they may still fail to protect the firm completely. Attackers can also break through the network, and when one is spending time patching the firewall, they can claim to be one of the employees with stolen credentials and walk straight through the front gate.

Another challenging aspect for IAM is that it is hard to convey how important the data is to the company. A breach will affect the company's reputation—there could be fines, and one could lose significant sums of money, intellectual property, and more in the event of a breach. But the violation goes beyond that. For example, government-issued information, such as the social security number, is considered highly confidential information and is related to the ability to buy large items, like a home, or seek new job opportunities. That is why there are government laws in place that enable businesses to manage personal information safely.

2. IAM Is Hard to Budget

It is not easy to request support for identity governance programs. If it is hard to explain IAM, and trying to budget for a solution that one cannot explain is a lot harder. It is also difficult to quantify the ROI of an identity governance solution because the usage of Identity Governance and Admin (IGA) systems differs between entities based on the total size and organizational needs. However, according to one research service, global security spending is projected to surpass 103 billion dollars from 2019.

3. IAM Is Hard to Ignore 

External threat actors have become significantly more advanced in their malicious activities targeting insiders—from deploying social engineering attacks such as phishing emails to searching through social media platforms and other data stores on the internet to gather information regarding corporate environments. These problems are not going anywhere and will only continue to rise in severity in the years to come. Attacks using stolen or corrupted user data will remain at the top of the attacker's playbook. Without effective identity governance policies, you won't be able to track, much less deter, these attacks. This feature is no longer a matter that needs to be overlooked or fixed with a larger and stronger firewall.

More in News

DNS traffic security solutions are becoming an important part of cybersecurity strategies across Latin America as businesses depend more heavily on cloud applications, remote access and distributed digital services. Because domain name system traffic connects users to websites, applications and infrastructure, it can also become a path for malware, phishing, data theft and command-and-control activity. Organizations are therefore placing greater attention on monitoring and controlling DNS requests before harmful connections are established. The business value lies in reducing attack exposure, improving visibility and supporting faster response without adding excessive complexity to daily operations across increasingly connected enterprise environments at scale. DNS Security Moves Closer to the Point of Connection DNS has traditionally been treated as network infrastructure, but security teams now use it as a control point. Every domain connection creates a signal that can help identify suspicious activity before users or devices reach malicious destinations. For Latin American organizations, this matters because business networks are becoming more distributed. Employees may connect from offices, homes, mobile devices and branch locations, while applications run across several cloud environments. Traditional perimeter controls are less effective when users and services are spread across many locations. DNS-based security can apply policy earlier, regardless of where the request begins. Filtering is one of the main functions. Security systems can block access to domains associated with phishing, malware, ransomware or other known threats. This reduces the chance that an employee reaches a harmful destination. The same controls can also prevent compromised devices from communicating with external command-and-control infrastructure. Policy management is becoming more flexible. Organizations can create access rules for employees, contractors, departments or devices, restricting risky categories while preserving legitimate business use. The strength of DNS security depends on threat intelligence and timely updates. Malicious domains can appear and disappear quickly, so static blocklists are not enough. Providers are combining reputation data, behavioral analysis and automated detection to identify newly created or suspicious domains faster. For business leaders, the value is not only technical. Preventing harmful connections at the DNS layer can reduce incident response costs, limit downtime and strengthen defense across distributed environments. Visibility and Integration Strengthen Threat Response Visibility is another major benefit of DNS traffic security. DNS logs show which domains users and devices attempt to reach, giving security teams useful context. Unusual requests can indicate malware, unauthorized software or data exfiltration. Analytics is making this information more useful. Instead of reviewing large volumes of DNS records manually, security platforms can identify abnormal patterns, repeated failed requests, unusual domain generation or communication with newly observed destinations. These signals can help security teams focus on activity that deserves investigation. Integration is also becoming more important. DNS security platforms are increasingly connected with endpoint protection, firewalls, identity systems and security information platforms. When these tools share context, a suspicious domain request can be linked with the user, device and broader network activity. This improves the speed and quality of incident response. Cloud adoption is expanding the need for this integration. Many Latin American companies use a mix of local systems, software-as-a-service applications and public cloud infrastructure. Security controls need to work consistently across these environments. DNS-based protection can provide a common policy layer without requiring every application to be secured in the same way. Remote work adds another consideration. Devices outside the corporate network still need protection from harmful domains. Cloud-delivered DNS security can apply the same filtering and monitoring policies wherever users connect, helping maintain consistent protection. This makes deployment easier across regional offices and remote workforces. However, visibility must be managed carefully. DNS data can contain sensitive information about employee activity and internal systems. Access controls, retention policies and clear governance are necessary. Security teams need enough information to investigate threats without exposing more data than required. Cloud Delivery and Governance Shape Long-Term Value The market is moving toward DNS security models that are easier to deploy and manage. Businesses want strong controls without unnecessary latency, user frustration or administrative burden. Managed services are becoming more relevant for organizations with limited security staff. External specialists can configure policies, monitor threats and review alerts while internal teams focus on broader priorities. This can help mid-sized companies gain advanced protection without building a large security operations function. Compliance and audit requirements also influence adoption. DNS logs can support investigations by showing when a device attempted to connect with a suspicious domain and whether the request was blocked. Clear records help security teams explain how controls are functioning and demonstrate that policies are being applied consistently. Scalability is important as companies expand across countries or business units. A centralized DNS security platform can make it easier to apply common rules while allowing local adjustments where necessary. This supports growth without requiring separate tools for every location. Cost control also matters. Security budgets must cover many priorities, and DNS protection needs to fit within a wider architecture. Businesses are therefore looking for solutions that integrate well with existing systems and reduce duplicated controls. The strongest business case comes from prevention, visibility and operational simplicity. DNS traffic security does not replace endpoint, network or identity protection, but it strengthens them by stopping many threats earlier in the connection process. ...Read more
Digital transformation in Latin America is shifting the way organizations develop, deploy and defend their technology environment. Applications that connect with other internal systems, customer platforms, and external services are critical to businesses. With the increased reliance on these connections, security teams are tasked with not only securing the applications but also securing the interfaces through which data flows. Along with the rise in cloud environments and connected applications, organizations now have more points to monitor. Security teams thus are focusing more on identity controls, API visibility and consistent security policies. Meanwhile, businesses are eager to have technology teams provide new digital services without opening up unnecessary security vulnerabilities. The connection between cybersecurity and API administration is turning out to be significant as they both affect the security of application-to-application collaboration and the administration of access to delicate data. How Are APIs Changing Security Priorities across Latin America? APIs are now an essential component of digital operations, enabling different applications and services to communicate with each other. Each API can provide an additional entry point to business systems. Organizations are reacting by enhancing authentication and authorization methods and monitoring API traffic for any unusual activity. API discovery is also emerging as a viable security need. Teams can not defend interfaces that they do not know are there. Having an accurate inventory can give security professionals insight into which APIs are used to safeguard sensitive data and where more robust controls could be in order. Access privileges are also becoming more of a concern for organizations. Security teams can set policies that restrict access to connected systems, based on user identity, application requirements and the sensitivity of the information accessed. The controls can be tightened to minimize exposure without being a hindrance to efficient data exchange in applications. Why Are Integrated Security Practices Gaining More Attention? Securing applications is becoming more like securing the enterprise. API gateways, IDM platforms, and monitoring tools can all play a role in delivering more visibility into digital environments. The result of such integration is that organizations can detect unusual behavior and act in advance of an incident impacting critical services. AI is also impacting security operations by assisting teams in reviewing vast amounts of activity and determining patterns that may need to be investigated. These functions are not intended to take the place of security professionals, but instead, they can assist them to focus on what may seem like unusual or potentially harmful events. Data Security is still another aspect to contemplate. APIs frequently carry customer, financial or operational data from one system to another. When data flows from environment to environment, encryption and access control features can minimize exposure, as well as careful data handling. ...Read more
In today's hyper-connected work environment, where people have to work across offices, remote work, and shared facilities, organizations from all over Latin America are re-thinking how to manage access. Common access methods are based on site-specific hardware, making site administration complex when it comes to multiple site operations. The technology of clouds provides another option in which information and controls for security can be accessed via central platforms. The change is driven by changing security and convenience expectations. Organizations desire control over who enters a facility, but without having to cause undue delays for employees or visitors. Security teams also want more visibility into access activity to quickly address any occurrences that seem unusual. These can all be combined in a cloud-based access control system with access management, centralized monitoring and digital identity controls. How Are Cloud Systems Changing Access Management Across Latin America? Cloud access control provides a centralized approach for security personnel to control access to more than one facility. The access rights can be remotely changed by administrators without relying on local hardware or manual changes at each access point. It can help to streamline the administration tasks for businesses that have offices, warehouses, or other facilities in various locations. Mobile credentials are also transforming the way people gain entry to secure areas. Employees can access the building without needing to use physical access cards every time. Permits are to be issued and revoked faster, and the administrative burden of replacement cards is reduced. Integration is another important development. Access systems are able to integrate with visitor management software, identity management systems and other security technologies. A more comprehensive view of who has access to the system and why can be developed when systems share information. The additional visibility can assist in quicker responses if an employee transitions jobs or if they leave the company. Why Are Flexible Access Controls Becoming More Important? The changing nature of workplace flexibility is generating new workforce security challenges. Flexibility in the workplace is changing workforce security requirements. Staff can walk from office to office or work from home offices; contractors and visitors need temporary access. Organizations must have policies that can easily adapt to these changes without compromising security. Temporary permissions might be easier to manage in a cloud-based system. Security staff can grant access for a specific time frame and revoke access once the need has subsided. Automated notifications can also aid administrators in checking permissions that are still active after the expected duration. ...Read more
Video surveillance systems are technologies used to monitor, record, and observe activities across physical spaces to support safety and security. They use cameras placed in strategic locations to capture real-time or recorded footage, allowing organizations to keep track of people, movements, and events within a property. These systems help maintain awareness, deter unwanted activity, and provide visual records that can be reviewed when needed. Modern video surveillance systems go beyond simple recording by offering centralized management and smarter monitoring. Video recordings can be saved locally or retrieved remotely, facilitating the management of various locations through a unified interface. With added features like motion detection and analytics, these systems support more informed responses and better control over environments, making them a key component of today’s security infrastructure. What Advantages Do Video Surveillance Systems Offer? Video surveillance systems provide stronger security by maintaining continuous visual oversight of spaces and activities. Their presence alone can discourage unwanted behavior, while recorded footage offers clear evidence when incidents occur. This visual record supports faster investigations and helps organizations respond more effectively to safety concerns. Constant monitoring also improves situational awareness, allowing potential issues to be identified before they escalate. Another key advantage of video surveillance systems is improved operational control and efficiency. These systems allow organizations to monitor daily activities, ensure procedures are followed, and verify that resources are used appropriately across facilities. In this evolving security landscape, Keeper Security supports organizations with advanced cybersecurity and access management solutions that help protect sensitive systems and digital infrastructure. Remote access to live and recorded footage further enables centralized oversight across multiple locations, allowing managers to make faster decisions and maintain consistent operational visibility without requiring constant on-site supervision. Video surveillance systems also enhance safety and accountability for both people and property. They support faster emergency response by providing real-time information during critical situations. Over time, these systems can help reduce losses, lower security costs, and create safer environments for employees, customers, and visitors. Together, these benefits make video surveillance an essential tool for modern security and risk management. Brinker Narrative Intelligence provides advanced cyber intelligence and strategic analysis solutions that help organizations anticipate emerging threats, strengthen security planning, and improve risk awareness across digital environments. What is the Future Outlook for Video Surveillance Systems? The future of video surveillance systems is moving toward smarter and more connected solutions that do more than just record footage. Modern surveillance cameras are becoming smarter, using advanced intelligence to analyze activity, identify irregular actions, and notify security personnel instantly when something appears out of place. This shift from passive recording to active monitoring will help organizations respond faster and more accurately to potential threats. With better integration of analytics, video systems will also support broader insights, such as tracking crowd flow or spotting maintenance issues before they become problems. Moreover, trends like cloud storage and remote management are making surveillance more flexible and scalable. Organizations will be able to manage multiple sites from anywhere, access footage instantly, and scale their systems without heavy infrastructure investments. Privacy and data protection will also play a bigger role, with more robust encryption and access controls becoming standard. Altogether, these developments point to a future where video surveillance systems are more intelligent, responsive, and better equipped to support safety, operations, and insights across industries. ...Read more