
Your background spans network security, identity and access management, cloud security, and enterprise infrastructure. How has working across all of those areas shaped the way you think about identity as a core security control rather than simply an administrative function?
Working with network security, identity and access management, cloud security, and enterprise infrastructure solutions has allowed me to recognize the importance of the concept of identity in relation to the security field.
The traditional approach to security focuses on the perimeter of an organization’s network. In other words, security is built around the idea of the network being insecure. However, if the organization uses Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), cloud platforms, and works with remote employees, then the security approach needs to be changed.
An employee’s credentials may no longer be sufficient or safe. Therefore, the security team needs to have an understanding of everyone and everything that can access a system. Even though the idea of IAM, Least-privilege model, Multi-Factor Authentication, Privileged Access Management, and security in the cloud may seem like an identity and access management, it is a part of security solutions that are vital for an enterprise. If implemented correctly, the identity concept can become the ultimate security tool for an enterprise, network security, cloud security, and IAM.
As organizations distribute infrastructure across AWS, Azure, GCP, SaaS platforms, and on-premises systems, why has identity increasingly become the new security perimeter?
As enterprises proliferate their AWS, Azure, GCP, SaaS applications, and on-premises solutions, the attack surface explodes. My experience tells me that the old-school perimeter security approach is no longer relevant. The problem is that users, applications, APIs, service accounts, and AI agents increasingly demand access to data and services and are often distributed across multiple clouds and on-premises. Identity is the new security perimeter because it grants or denies access to resources and data. It is also where the majority of attacks originate. Enterprises should enforce the least-privilege model, multifactor authentication, privileged access management, and continuous monitoring to secure their identities and critical data.
Attackers have pivoted and are targeting IAM accounts, expansive access permissions, and other weaknesses in the authorization and authentication processes. The Zero Trust architecture is the new normal, and every organization must take cybersecurity a step further. Enterprises must rethink their strategy and operational philosophy regarding identity governance and compliance by ensuring that every login is authenticated and authorized before granting system access. I strongly believe that the security perimeter and continuous verification of identities will play an even more significant role in the future. Enterprises should invest in IAM technologies to ensure all users and AI agents have the least privilege to access resources. By leveraging Zero Trust security models, organizations can harden their systems and lessen the risks of attacks, breaches, and compromises of their critical assets. Identity is the new security perimeter because it is where enterprises can demonstrate compliance and security posture, thus protecting data and systems.
Managing access across multiple environments can become extremely complex. What are some of the biggest challenges organizations face when trying to enforce consistent identity and access policies across cloud and on-premises systems?
One of the main challenges many businesses encounter is the absence of standardized identity and access management across one’s cloud services, software-as-a-service (SaaS) applications, and enterprise systems. If these elements are not supported consistently throughout an organization’s network and infrastructure, it becomes exponentially harder to establish and maintain records of one’s employees’ activities and entitlements. In addition, workers may acquire significantly more access than necessary, organizational assets such as service accounts may not be retired faster, and privileged users’ authority may become challenging to document and examine.
Another issue that may arise is the need to integrate legacy infrastructure with modern identity platforms while still supporting one’s business needs. In addition, businesses may face challenges associated with the inability to enforce heterogeneous compliance rules, the inadequacy of one’s tools to govern and document permissions, and the incapability to rapidly respond to revoked credentials or changing roles within the company.
From my perspective, the central problem to be solved in this case is a company’s need to establish an identity governance platform. This will allow one to formalize one’s records of employees’ activities and entitlements, thereby resolving the issues of excessive permissions, long-retained service accounts, and hard-to-track privileged access. To do this, businesses should consider implementing the principles of least privilege, single sign-on, multifactor authentication, and role-based access control. The processes that take place will need to be automated, but organizations also must guarantee that administrative responsibilities are regularly audited and acted upon.
You have hands-on experience with platforms including SailPoint, CyberArk, Okta, and Microsoft Entra ID. How do these technologies address different parts of the identity security problem, and why is it important for enterprises to think about IAM and privileged access management as part of a broader security architecture?
Based on my experience with SailPoint, CyberArk, Okta, and Microsoft Entra ID, I can notice that products address different use cases and layers of security. For instance, SailPoint’s products are focused on identity governance and administration, including automated provisioning, access reviews, remediation, and compliance reporting. On the other hand, CyberArk’s products are designed to address privileged access management use cases, such as privileged account security, privileged workspace, and privileged session monitoring. Okta’s products focus on the identity and access side of the architecture and provide single sign-on and multifactor authentication solutions. Microsoft Entra ID offers products related to authentication and authorization and conditional access in Microsoft ecosystems.
It is essential to mention that individual products rarely offer complete protection and need to be incorporated into a broader security architecture with other solutions. For instance, SailPoint can indicate which access needs to be granted to users, and Entra ID or Okta will enforce authentication and permission policies, while CyberArk justifies if a user who needs to perform a privileged task has met the set criteria. Enterprises should view Privileged Access Management (PAM) and Identity and Access Management (IAM) solutions as complementary security layers and integrate them with other cybersecurity solutions, such as cloud security posture management, monitoring, and response, to enforce the least privilege and zero-trust access models. In this regard, the primary goal of enterprises’ IAM initiatives should be to ensure that the correct identities can get the right access to specific applications, data, and systems at the moment it is needed.
Modern enterprises have to secure not only employees and contractors, but also privileged accounts, service accounts, applications, and other machine identities. How does the growth of non-human identities change the way organizations need to approach access management and security?
Nowadays, the number of non-human identities exceeds the number of people in most companies, and these identities operate in a different way. For example, a service account does not change its role, go on vacation, or be subjected to multifactor authentication. Non-human identities often contain extensive access privileges that have gone unreviewed for a long time. These factors make it challenging to organize and normalize access management in enterprise IT environments because such accounts are typically not governed by the same rules as humans or legacy systems.
The first step to address this issue is to establish visibility because entities that are not visible to the security team cannot be effectively managed or controlled. Therefore, every machine identity should have a named owner, a documented purpose, and least privilege access. In addition, long-lived passwords and API keys need to be replaced with credentials that have a limited lifespan, and a secrets management system should be introduced to protect and store these credentials.
The next critical step is to rethink monitoring and detection rules since machine identities typically follow well-defined patterns, and therefore deviations can be quickly detected if the administrators know what to look for. The final stage is to establish procedures for the end-of-life support of applications because every software that is decommissioned should have its identities and access rights terminated.
Over-permissioned accounts and inconsistent access policies remain common problems in large organizations. What mistakes do you see enterprises make most often when implementing IAM, and what can security teams do to reduce unnecessary or persistent access?
The majority of IAM issues stem from practices involving static permissions that are issued based on a set of responsibilities. Organizations provide extensive permissions to get their work done, but rarely take those privileges away later. Accumulation of permissions leads to employees having full access to everything a company offers, which is especially common among long-term workers due to changes in their roles since the time their access was initially approved. Different PaaS, cloud storage, directories, SaaS applications also have distinct sets of permissions, which leads to the formation of gaps that are often unaddressed before incidents occur.
An additional issue that contributes to the problem is the practice of annual access reviews, during which managers approve hundreds of permissions they do not fully understand.
To mitigate these issues, it is recommended that organizations eliminate just-in-time elevation of privilege when possible. It is also advised to configure roles based on occupation rather than persons and set up review cycles based on time, but not later than every year. There is a need to establish a set of rules in regards to permissions that apply to all systems and remove any that have not been utilized within 90 days.
Your experience also includes compliance frameworks such as SOC 2 Type II, ISO 27001, HIPAA, and PCI-DSS. How can organizations avoid treating IAM as simply a compliance requirement and instead use identity governance, privileged access management, and zero-trust principles to improve their actual security posture?
Organizations can take IAM beyond a compliance initiative and make it a security control by incorporating identity as an element of security governance. While standards such as SOC 2 Type II, ISO 27001, HIPAA, and PCI-DSS can be used as a reference, IAM must be improved continuously to reflect the changing threat landscape. The three overlapping areas of IAM governance, privileged account management, and Zero Trust security architecture must be reinforced by converging on a common framework. A healthcare organization, for instance, can deploy IAM best practices by ensuring that user identities have the lowest possible privileges, restricting database access to persons within the IT department, and utilizing multifactor authentication at the administrative level while eliminating passwords. The compliance controls can be designed to enhance security by specifying that the system can automatically revoke access to data, systems, or applications by employees who lose their status, e.g., termination of employment, and ensure that every privileged account is subject to just-in-time provisioning, multifactor authentication, and rigorous auditing during operation.

Andres Abadia is a Marketing and Community Manager specliased in technology research. His always been interested in applied technology as ways to achieve higher ethical awareness. He has worked previously in Microsoft Colombia as independet researcher and writer. Andres finished his marketing master in Middlessex University, London, UK which has let him to focus in international markets, in technology development and ethical subjects. He currently writes for intelligenthq.com and aswell endeavours in community management for the Ztudium brands. Andres is highly motivated to keep transforming public’s opinion on the metaverse, technology application and ethical approach towards them.
