THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, September 15, 2025
FREMONT, CA: Understanding who, what and why people are on a network without a perimeter is essential to ensuring security. Implementing zero-trust architecture, which entails constantly confirming authorised users and giving them the fewest privileges when they access sensitive resources, requires a robust IAM policy. Even authorised users need to re-authenticate when switching between network segments, though IAM can be automated with tools like single sign-on and authentication mechanisms.
According to CRA Business Intelligence’s survey, progress remains slow while many organisations are taking steps towards zero-trust security. About 35 percent were familiar with the zero-trust concept and had even put it into practice. One-quarter of those who did not implement zero trust reported a lack of financing as a significant barrier, and another quarter mentioned a lack of management support. This highlights a considerable gap causing business enterprises to embrace technology slowly, even in the face of federal obligations.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
When the shift to remote work was a challenge for many firms at the pandemic’s onset, the perimeter security model, which relied on location-based access, became outdated. As a result of this change, an identity-driven security paradigm was adopted, enabling authenticated people or devices to access networks from any location. Organisations were driven to strict monitoring and limit user and device activity when the perimeter was removed, which led to the development of the zero-trust approach.
A firm IAM policy is essential for a zero-trust architecture because it guarantees that the active directory domain controller knows every device's identity and the access it needs. Given that breaches frequently result from credentials that have been stolen or brute-forced, weak or inadequately implemented IAMs are insufficient. Seventy-three percent of the most common attack methods use stolen or poorly maintained credentials, while most breaches require compromised credentials. Strong IAM policies and zero-trust designs are designed to prevent attackers from moving laterally, posing as genuine users, after gaining network access. With an IAM policy in place, even insider threats could be reduced.
Implementing an IAM policy correctly seems complicated because network managers need to identify all identities, machine and human—that require network access. Specific access privileges must be catalogued for every user, frequently resulting in excessively high levels of trust. The idea that access should be restricted to the bare minimum of privileges may compel IT managers to limit high-level executives' access, which can be challenging to implement. The adoption of zero trust is slowed by managerial support and financial constraints. Development is being hampered by a lack of knowledge about its components and how to use them.
Eighty-six percent of diverse technology, healthcare and manufacturing firms that effectively applied the zero-trust paradigm were frequently motivated by regulatory mandates or worries about intricate supply chains. Among these companies, 66 percent stated that lowering the risks associated with remote workers significantly influenced their decision to implement zero trust.
More in News