BeyondTrust’s annual Privileged Access Threat Report highlights that greater privileged access visibility and improved integrations are vital to tackling the modern threat landscape
BeyondTrust has released the 2019 Privileged Access Threat Report.
In its fourth edition, the global survey explores the visibility, control, and management that IT organisations in the U.S., APAC, Europe and the Middle East have over employees, contractors, and third-party vendors with privileged access to their IT networks.
According to the report, 64% of businesses globally believe they’ve likely had either a direct or indirect breach due to misused or abused employee access in the last 12 months, and 62% believe they’ve had a breach due to compromised vendor access.
“Both internal employees and third-party vendors need privileged access to be able to do their jobs effectively, but need this access granted in a way that doesn’t compromise security or impede productivity,” commented Morey Haber, CTO & CISO of BeyondTrust. “In the face of growing threats, there has never been a greater need to implement organisation-wide strategies and solutions to manage and control privileged access in a way that fits the needs of the user.”
Globally, the businesses surveyed reported an average of 182 vendors logging in to their systems every week. In UK organisations, 46% say they have more than 100 vendors logging in regularly, highlighting the sheer scope of risk exposure, with 83% admitting they trust third party vendors accessing their networks, a slight increase to last year’s report. Trust in employee privileged access was cited at 87% however, a decrease of trust from last year which was 91%.
With GDPR coming into effect last year, it’s unsurprising that last year’s report found that compliance was one of the biggest drivers of cybersecurity strategies, however this year’s survey has found that high profile security breaches is the leading driver. Almost half (43%) say that high profile security breaches not related to themselves is having a significant effect on the way they’re governing employee access, with GDPR compliancy taking a backseat as third most important (41%), and 42% citing concern of unintended data loss from unsecured data devices as driving their policies of employee network access.
The report further delves into the threats posed by emerging technologies. The risks associated with the Internet of Things (IoT) posed a big concern for the professionals surveyed. Despite this, a majority (80%) are confident they know how many IoT devices are accessing their systems, and 81% are confident they know how many individual logins can be attributed to these devices. At the same time, 41% of security decision makers perceive at least a moderate risk from Bring Your Own Device (BYOD) policies.
The report did show that some organisations are managing these risks with a Privileged Access Management (PAM) solution. From the research, these same organisations experience less severe security breaches and have better visibility and control than those who use manual solutions or no solution at all.
“As the vendor ecosystem grows, the threat landscape evolves and users should be granted specific role-based privileges. Organisations need to accept that the way to mitigate risks is by managing privileged accounts through integrated technology and automated processes that not only save time, but also provide visibility across the environment,” Haber added. “By implementing cybersecurity policies and solutions that also speed business efficiency, versus putting roadblocks in users’ way, organisations can begin to seriously tackle the privileged access problem.”