Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How IT Can Balance Security And Productivity
Articles

How IT Can Balance Security And Productivity

ISBuzz TeamBy ISBuzz TeamAugust 28, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Namecheap Email Hacked, Used To Send Phishing Emails To Metamask and DHL
Namecheap Email Hacked, Used To Send Phishing Emails To Metamask and DHL
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Security solutions have great potential to improve organizational efficiency, but also to hinder day-to-day operations, limit access to information and impede employee output. As tech investments grow across industries, productivity concerns can be neglected, or worse, completely ignored.

It’s easy to see how these “pitfalls of productivity” can become a reality. IT security is a top priority, and protecting data and networks requires significant resources and technology investments. Companies evaluate security solutions against a host of requirements, but at the end of the day, users need to be able to do their jobs. If not chosen with productivity in mind, a new technology may completely backfire, costing an organization both time and money.

It falls to IT to ensure that the organization is striking the right balance between productivity and security. Part of this is working directly with end-users to make the most of technology implementations, from accessibility factors to individual or group training needs. But it’s also important that productivity considerations be included in security decisions from the outset.

A good cybersecurity strategy should consider the people and processes it impacts as much as the protection it provides. Historically, security best practices have focused on restricting and blocking access to sensitive data and systems to reduce the threat of a breach. While good in theory, in practice this often impedes employees’ ability to do their jobs, resulting in lost productivity or even workarounds that undermine the security mandate.

No single technology or procedure can completely protect the entire organization. However, with the right combination of solutions, companies can achieve this duality of productivity and security. Technologies that allow for strong privileged access controls combined with solutions to manage the risk of shared credentials and privileged passwords are essential for success.

 Privileged access generally refers to IT administrators or third-parties who have elevated or admin-level access to systems. It’s not uncommon for privileged credentials to be shared and rarely changed because the insiders and vendors who hold them are considered trusted. However, one need look no further than many of the most recent cyber breaches to see the damage that can result from trusting people with too much information. In addition, privileged credentials are a common target for attackers because they’re seen as the “keys to the kingdom” within a larger network. Through phishing scams and other methods, hackers attempt to gain access to these accounts and from there use the credentials to wreak significant damage.

Eliminating or significantly restricting privileged access is not the answer. Employees and external partners alike need efficient access to conduct daily operations and keep the business running. Rather, companies should implement solutions that eliminate the threat vectors associated with privileged access but still enable these users to do their jobs.

When managed properly, privileged credentials can foster increased productivity while simultaneously addressing security concerns. For example, a privileged access management, or PAM, solution provides vendors with immediate access to the systems they need without requiring them to log into a VPN. This eliminates unfettered VPN access to the entire network, while also enabling the vendor to complete the job more efficiently.

With some PAM solutions, it’s possible to take productivity to the next level by implementing credential injection, which allows users to inject a privileged username and password directly from a password manager or vault into an end system. This significantly reduces the risks that commonly arise from shared privileged credentials. Instead of having to memorize or search through a long list of admin passwords, or use a password vault that impacts daily workflows, privileged users can connect to endpoints with just one click without ever seeing the credential or having it pass through their system.

Privileged access management is just one example of how companies can implement security solutions that also consider the productivity demands of their users—both internal and external. As new technology investments are evaluated, it’s critical that decision makers replicate this approach and seek input from the individuals who will be impacted by the implementation. Many people don’t like change, especially when it has the potential to threaten productivity. However, the right security strategy doesn’t have to impede activity or require an inconvenient workaround. In fact, if mindfully, security tools can enhance workflow, operations and revenue, and above all, ensure safety and set the organization up for future success.

[su_box title=”About Sam Elliott” style=”noise” box_color=”#336588″][short_info id=’101975′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}