Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Cyber Story Of The Pandemic: Our Shared Security Debt
Articles

The Cyber Story Of The Pandemic: Our Shared Security Debt

David HigginsBy David HigginsJune 18, 2021Updated:January 18, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Organisations, industry observers and vendors have all talked a lot about the pace of change in recent months. We have seen how services provision has been transformed, how rapidly new apps are rolled out, how new workflows are developed, and new ways of serving our customers. Our sheer ability to adapt to changing conditions has been hugely impressive.

And yet this incredible advance will demand a payoff. In fact, it has already created a payoff, in the shape of an identity-related security debt that is big, getting bigger, and must be repaid…or called in.

The pivot to digital has been beneficial in many ways, but it’s forced us into a place where the nature of digital identity must be re-thought and re-imagined into something that is implemented within organisations as something much, much more than access; this cumbersome exercise whereby people and, latterly, Things (machines, apps, servers, devices), get the permissions needed to perform their roles or tasks.

To a degree, we’ve always recognised that certain of these people and things have access permissions that need special attention. The access rights of the CEO of a public company are such that they enable access to privileged information of all kinds. This privileged access is managed and secured in order to avoid, for instance, market-sensitive information becoming known prior to an earnings announcement.

But what if you can get this information by other means?  What if, for instance, an attacker makes the logical leap of faith that an executive’s pay at certain points in the year would reflect – in the shape of no bonus being awarded – the fact that targets have not been achieved, and the stock is thus likely to tank when this information is announced?

And so, the payroll’s administrator’s identity and access also becomes a problem, in that it has to be secured and managed in such a way that they and only they can access this privileged data. This is often a blind spot for many firms. They oftentimes only look at how to secure the obvious routes to critical assets; they are not taking into consideration the need to secure other things that can still be critical in the right circumstances.

Added to this, we have the issue of lifecycle mis-management. In the on-premises world, the result is referred to as ‘orphaned’ permissions and, in the cloud, as ‘excessive’ permissions. These permissions are pervasive and are created for instance when people join one function, then move over to another. The permissions of the old function are not retired. The situation is replicated with services that are no longer used. In each case, they can be used by attackers to access potentially sensitive data and assets, like forgotten (but perfectly useable) forest trails. Unmanaged access associated with various human and non-human identities abounds.

Over the last 15 months or so, in the rush to reposition – and in some cases simply survive – organisations have exacerbated the problems described above. We have heard of many instances where employees were told to run into the office before it closed, grab their laptop and work via whatever connection that they could access. Or they were thrown some money and told to buy their own equipment. Cloud services have been rolled out in order to perform the functions that on-premises infrastructure could no longer do.

All the above means new identities and new access rights have had to have been created. Not just a few per company, either. For an average-sized organisation, each new cloud service, each new collaboration tool, and each new customer-facing application means hundreds if not thousands of new sets of credentials. An attacker thinks of these as ‘potential’. Consider this: The Verizon 2021 Data Breach Investigations Report says that phishing (the act of obtaining information – often credentials – through deception) and the use of stolen credentials were the top two actions taken by attackers in the 5,258 breaches studied. And privilege abuse featured in at least 60% of breaches. In practice, this means permissions, identities and access being used to progress an attack.

Speed has trumped security. CISOs planning for a hybrid future are probably aware of the identity-related risk that has been created. And what is going to happen is what we always see with access and security; they are going to try and add-in security to all the access that has been created after the fact. In doing so, CISOs will run into the problem of trying to effect behavioural change. People who have got used to full admin access to systems, secured over a VPN with little in the way of MFA are going to try and push back. The act of imposing least privilege on remote endpoints will similarly create friction.

What been incurred, then, over a very short period of time, and at an unimaginable scale, is a vast identity-related security debt. How security professionals address this will define how vulnerable our data and assets will be at least over the course of the rest of 2021 and into 2022.

David Higgins

EMEA Technical Director

  • David Higgins
    Phishing Attacks: Five Things To Watch Out For
  • David Higgins
    Six Ways Of Safeguarding Employee Workstations
  • David Higgins
    The Top Trends Shaping The Future Of Access Management In 2021
  • David Higgins
    Can Bargain Hunting Put Your Company At Risk?

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}