Most of the breaches that occur within organisations are avoidable through simple and intermediate controls.
So said Patrick Hunter, Quest Software's identity and access management team lead for EMEA, during an identity and access management seminar, in Woodmead, yesterday.
According to Hunter, it is possible to detect and prevent 96% of the contraventions that businesses suffer.
He revealed that most of the challenges businesses face relate to lax security systems, complexity of passwords, and failure to comply with certain practices.
“In regards to security, almost all organisations are at the risk of both internal and external threats. However, there is increased risk of internal threats,” he pointed out.
Hunter also noted that companies suffer breaches as a result of having “orphaned accounts”, which he defined as accounts belonging to users who have since left the organisation.
“The other problem why systems are also breached is because, often, there are too many people within organisations that have to access privileged accounts,” he said.
Hunter also revealed that while most organisations make their password policies complex in order to avoid breaches, the practice can, in fact, have the opposite result.
“Complexity of a password only makes it difficult to guess, but not to crack,” he said, adding that, on average, a typical enterprise end-user has six enterprise-issued passwords.
Having passwords that are too complex can also lead to anomalous activities going unnoticed, Hunter explained. “Managing complex user access rights is also resource-intensive.”
According to Hunter, compliance is another issue that leaves organisations exposed to breaches.
“A recent study has shown that 48% of the organisations surveyed rated the odds of experiencing a compliance risk within the next 18 months as high or very high.”
He explained that this was because, over the years, the number of regulations has continued to grow, leading to more administrative tasks.
“Businesses also find compliance difficult mostly because the process of proving compliance is usually labour intensive, while reviewing activity logs only during audits is often too late to detect the breaches.”
To curtail breaches, Hunter pointed out that organisations should enforce access governance into their systems. “They must improve visibility into who has access to business-critical information.”
He added that businesses must centrally manage privileged accounts and provide granular control of administrator access. “Identity administration is also a critical aspect. Businesses should simplify the environment and user experience with centralised account management.
“It is also vital to audit what users are doing with the access they have been granted,” he concluded.

