Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - IT Weaknesses – The Barrier To Enterprises Becoming Security-First
Articles

IT Weaknesses – The Barrier To Enterprises Becoming Security-First

ISBuzz TeamBy ISBuzz TeamApril 8, 2019Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Enterprises are increasingly recognising the benefits of embracing a cloud infrastructure to support on-premise networks, but often create complicated network environments in the process. Recent OneLogin research revealed that 94% of global CIOs are in agreement saying the corporate technology stack is becoming increasingly complex – with more apps (both cloud and on-prem), data, devices and transactions than previously known[1]. Running systems via the cloud offers efficiency and productivity to better support large distributed workforces, no matter where an employee is based. As a company evolves it can often outgrow its on-premise network. Consequently, IT strategies must be created to futureproof networks, as well as protect customer and employee data. 

The influx of new applications onto enterprise networks shows no sign of abating, threatening networking security posture. OneLogin research found that two-thirds of UK enterprises expected to deploy up to 100 new commercial SaaS and on-premise apps in the last year. This high frequency of large-scale app deployment to enterprise networks means it is critical that enterprises develop a security-first strategy to encourage healthy hybrid-network environments. Such strategies are imperative to calm chaotic networks overwhelmed by the constant on-boarding of applications. Just like spinning plates, it is only a matter of time until a chaotic and fragmented hybrid network wobbles and the entire enterprise network collapses. 

To ensure enterprises’ networks remain agile and secure, IT decision-makers and professionals should consider the following points to encourage a companywide security-first culture: 

1. Single source of truth 

Multiple directories mean multiple vulnerabilities. Whether directories are in the cloud, on-premise, or both, they need to be managed from one unified system that’s adaptable and scalable.   

2. Manage access for employees and end-users 

81% of hacking-related breaches involve stolen or weak credentials. Single sign-on (SSO) and multi-factor authentication (MFA) work together to strengthen credentials and protect data from unauthorised access – across all users’ devices and apps.   

3. Onboard and offboard efficiently and securely 

As enterprises continue to grow, HR and IT departments are tasked with getting new employees onboarded quickly, and offboarding ex-employees just as fast, if not faster, to stay secure. With large enterprises hosting 250+ employees, new staff need to be added every week and, likewise, staff also leave every week – placing a strain on HR and IT teams. To simplify processes, run them most efficiently and put security-first, enterprises should invest in automated processes and tools. An “instant kill switch” for deprovisioning and real-time directory synchronisation can dramatically reduce time spent on IT administrative tasks and greatly reduce the risk of ex-employees leaving with sensitive information that could be sold to competitors.   

4. Security versus usability – getting the balance right 

To encourage employees to follow security protocols and buy into a security-first culture, additional security processes must make the tools they use to do their jobs easier to use. Otherwise, employees will be reluctant to adopt them and will find a way to circumnavigate security protocols, essentially leaving the business they work for open to malicious cyber criminals. 

It can be all too easy for employees to sign-up to and download new applications on corporate and even personal devices they use to work. Some employees even pay for these applications out of their own pocket to circumvent going through tedious HR and IT protocols. 

To succeed in 2019, enterprises must find a balance between usability and security to become a security-first organisation, or face becoming security-last and at the mercy of cyber criminals. Not only will an organisation’s inability to prioritise security cost the company its sensitive data, but it will also incur regulatory fines for not complying with data privacy laws, such as the European General Data Protection Regulation (GDPR) or the US’ Data Privacy Shield. 

Google recently, and publicly, came under regulatory scrutiny by the French National Data Protection Commission (NCIL) following two breaches of GDPR compliance due to a lack of transparency around how to access data policies and Google’s lack of valid user consent regarding the personalisation of ads[3]. As a result, Google has received a fine of €50m, the largest fine since GDPR came into force. The impact beyond the fine is on Google’s reputation among consumers and Google users. 

With this in mind, a security-first strategy and posture must be reflected in an organisation’s vendor selection processes and positively influence the end-user experience every step of the way. If organisations fail to acknowledge the importance of a security-first culture throughout decision-making processes, they will risk circumvention and hefty regulatory fines, damaging their reputations.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}