The proliferation of cloud applications and use of a disparate range of devices within businesses has led to 64% of IT leaders admitting that their security teams are considering implementing consumer-grade access to cloud services for employees.
How has your organization’s security policies around access management been influenced by breaches of consumer services?
Pressure mounting to make authentication stronger
Surveying more than 1,000 IT decision makers globally, Gemalto’s 2018 Identity and Access Management Index revealed that 54% believe that the authentication methods they implement in their businesses are not as good compared to those found on popular sites including Amazon and Facebook.
With a growing number of cloud apps in use, more employees working remotely and pressure mounting to make authentication stronger while ensuring ease of use, IT decision makers are keen to ‘consumerize’ the login process. In fact, 70% of IT professionals believe that authentication methods applied in the consumer world can be applied to secure access to enterprise resources.
Despite this, 92% of IT leaders express concern about employees reusing personal credentials for work. This comes as 61% admit that they are still not implementing two-factor authentication to allow access to their network, potentially leaving themselves vulnerable to cyber criminals.
New approaches to cloud access
At the same time, there seems to be increasing recognition that new approaches to cloud access can contribute to alleviating these issues. 62% of respondents believe that cloud access management tools can help simplify the login process for users, while 72% stated that a strong consideration for implementing a cloud access solution is the desire to reduce the threat of large scale breaches.
The fact that 61% of respondents also stated that inefficient cloud identity management would be a key factor in adopting a cloud access management solution, shows that scalability and management overheads are also of high concern to IT professionals.
“These findings clearly show that IT managers are struggling to balance the need for a simple and easy login experience with security,” said Francois Lasnier, SVP Identity and Access Management at Gemalto. “While there is a need to make things easier for employees, there is a fine line to be walked. IT and business line managers would do best to figure out the risks and sensitivities associated with the various applications used in their organizations and then use access management policies to manage risk and apply the appropriate authentication method. In this way, they can ensure a convenient login experience for their users, while still maintaining access security.”
Why do you feel that cloud applications are a target for cyber-attacks?, asked to respondents who think that cloud applications (SaaS, PaaS, IaaS) are a target for cyber- attack
Secure access to applications
With the growth in remote working, the cloud and secure access to applications have become important for organizations. As a result, almost all (94%) respondents believe that cloud access management is integral to adopting cloud applications. In fact, nine in 10 also feel that ineffective cloud access management can lead to issues for their company, such as security (52%), IT staff’s time being used less efficiently (39%) and increased operational overheads and IT costs (38%).
Despite this focus on protecting cloud applications, just three of the 27 used on average by organizations are protected with two-factor authentication.
“The rapid increase of cloud apps has brought organizations lots of benefits, but also caused a high degree of fragmentation in their ability to manage access security across numerous cloud and on-premises applications,” continued Lasnier. Without effective access management tools in place, this is liable to lead to higher risk of breach, a lack of visibility into access events, regulatory oversite – and hamper organizations’ ability to scale in the cloud.”