Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Hacking Away: It’s Time To Look At Your Foundation
Articles

Hacking Away: It’s Time To Look At Your Foundation

ISBuzz TeamBy ISBuzz TeamMarch 17, 20144 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Hacking_Away
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The security world has endured one scandal after another since Edward Snowden’s leaks hit the news. Recently, investigators revealed that Snowden used an NSA employee’s personal credentials to log into the system. It’s truly amazing how one unsuspecting employee’s mistake led to such a chain of events. The employee resigned in January, taking responsibility for his actions and it’s likely that others who may have been involved will follow. However, the one question no one seems to be asking is – should we put so much power in the hands of users, or are there other security measures we need to take?

I think that all this talk about educating end users is nonsense – organizations need to also take responsibility and realize that they need to protect users, rather than expecting users to protect themselves.

Up the ante on your identity

Many companies are asking themselves, “Is there really anything we can do to stop hackers?” We all know that hackers are constantly looking for the newest approach to cracking systems and stealing information. The truth is that many companies are still using legacy identity technology, the bare bones approach to dealing with today’s modern day cybercriminal. Considering the damage a highly publicized breach has on a firm’s brand and reputation, the lack of initiative is indeed surprising. In particular, there are a few security options that companies continuously overlook, including federation.

Federation is a simple approach to granting access to users without exposing their profiles and personal information – an approach that could have helped prevent the Target breach, where hackers got user information through the company’s partner. The way this works is easy – you form a trusted relationship with your partner, the partner application accepts a token and then the user is authenticated anonymously. With federation, there is no reason why companies need to share user information with their partners – a huge step forward in protecting end-users.

But, federation is not the only answer. Yes, with federation, the data you share with partners is protected, but that is only one step. Organizations must also make sure that their own security system is strong enough to keep hackers out. As mentioned, most companies are still relying on their legacy systems. They have a mentality that “it won’t happen to us,” and they don’t take the time to invest resources in a solution built for today’s modern Web. As hackers advance their cyber-skills, many companies are like lame ducks, just sitting and waiting to see if their system is the next to get attacked.

Step away from legacy

While companies sit back with a false sense of security, their business is evolving and how they engage with employees, partners and customers is fundamentally changing. To cope with the change in landscape, companies need to ensure that their identity management is adaptable and tailored to meet ubiquitous access and Internet scale – something that legacy security solutions, including identity, are not built to handle.

In the world of hackers and security breaches, it is very important for companies to arm themselves with the most up to date technologies and processes. Legacy identity management software is far behind the times and puts the end-users at risk. This has real implications for the company, as we’ve seen with Target. With the number of hacks on the rise, it’s time for companies to re-evaluate their foundation – identity – and make sure that it’s ready to deal with the onslaught of threats.

Daniel Raskin

Daniel Raskin | www.forgerock.com | @raskindp

Bio: Daniel is currently VP of marketing at ForgeRock and has more than 15 years of experience building brands and driving product leadership. Prior to joining ForgeRock, he served as chief identity strategist at Sun Microsystems. Daniel has also held leadership positions at McGraw-Hill, NComputing, Barnes & Noble and Agari. He holds a master’s degree in international management from Thunderbird School of Global Management and a master’s degree in publishing from Pace University.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}