There’s a phrase that’s repeated so much in identity and access management (IAM) circles, that it’s almost become a cliché. “Identity is the new perimeter”. While it’s definitely an overused mantra, that doesn’t make it any less true.
Identity (or more correctly identity security) should be the first step in any cybersecurity journey and the foundational factor upon which all other principles build.
To understand why, let’s examine what attackers are actually after. Without fail, bad actors are seeking access to something (in our case technology assets) that they can exploit either for financial gain, to create havoc, to inflict damage, or to prove a point. To execute their objectives, they must first gain access. And access is all about identity.
The concept of zero trust is a great guide to building an effective cybersecurity program. Gartner defines zero trust like this:
"In its simplest term, zero trust is a way to securely connect users to applications through the devices they use to do their jobs…. Adopting a strong zero trust strategy is key to modern information security programs…. A critical function of a zero-trust model is to ensure that a user or entity has the proper level of authentication. Access to different resources may require different strengths of authentication, depending on how sensitive an application is.”
Virtually every zero trust model places identity as the first, foundational pillar. Identity comes before devices and endpoints, networks, applications, data, visibility, and automation. If you get identity security “right” the rest will more easily fall into place.
Palo Alto Networks, in an analysis of NIST SP 800-27 states:
"Every access request is evaluated using identity as the core control, augmented by device posture and context, and enforced near the resource. Because most modern attacks exploit compromised identities, SP 800-207 emphasizes continuous validation of who or what is requesting access, not where the request originates."
To combat attackers, it is critical to ensure that only the right identities, have only the right access, to only the right resources, in only the right way, at only the right time, and within the right cybersecurity framework. Simply put, you must get identity security right. But what does that actually mean?
Following a few principles can dramatically bolster the strength and effectiveness of identity security.
Assign individual accountability to identities. Avoid shared credentials, standing permissions, and anonymous accounts.
Strengthen authentication beyond default username and password login. Implement technologies and practices that irrefutably validate that the person or identity logging in is who they actually say they are.
Strictly follow the principle of least privilege. When provisioning permissions ensure that every user or identity has exactly the permissions they need – nothing more nothing less. Avoid over-provisioning or granting standing permissions.
Get as granular as possible for authentication workflows, provisioning orchestrations, and access control policy enforcement. The more specific and task/job-optimized identity security workloads can be the smaller the risk and the narrower the window of bad actor opportunity.
Wherever possible implement orchestrations and automation to eliminate human error, delays, and shortcuts for all of the above.
Most organizations have these principles in place to some extent on some systems and some identities. However, it’s the systems and users that are not easily covered that present the greatest risk and are prime targets of attackers. Identity security is only effective when these principles can apply to all users and identities – including those that are more difficult to secure such as third parties, non-human, and agentic users. Similarly, some systems that are more difficult to enforce identity security rigor on remain risky. For example, many operational technology and critical infrastructure resources default to shared credentials, standing permissions, over-provisioned entitlements, and cannot natively support strong authentication options.
If identity security is the new permitter, you better make sure that the fence is high enough and strong enough to keep the bad guys out. And you better make sure that is goes all the way around your property, not stopping because the terrain is more difficult to fence in.
This can be accomplished but it may take a change of mindset and a willingness to break out of the status quo. When implementing or evolving an identity security program the key factors to consider should include:
Depth – what will provide the appropriate level of protection, functionality, and useability necessary for my entire environment, realistic budget, and in-place skillset?
Breadth – what will deliver equal coverage for all my systems, even those that traditionally have fallen outside of IT-led cybersecurity initiatives?
Scope – what will provide equal (uncompromising) identity security coverage and capabilities across all my relevant users including previously neglected non-human, agentic and third-party users?
Usability – what fits best with the way I need to operate and what provides the flexibility to deploy identity security and it use in the manner that makes the most sense for me, my enterprise, and my user bases?
Finding the perfect, optimized mix of depth, breadth, scope, and useability may seem daunting. But it is doable – and may be the most important cybersecurity decision you can make.