< ciso
brief />
Tag Banner

All news with #iam tag

228 articles · page 8 of 12

Active Directory Password Resets Surge in Hybrid Work

🔒 Hybrid work has driven a sharp rise in Active Directory password resets as cached credentials, inconsistent network connectivity, and stricter rotation policies cause more account lockouts. IT helpdesks supporting distributed employees are inundated with routine tickets that drain resources and reduce productivity. Forrester estimates a $70 cost per reset, and Specops data shows an average organization handles 923 resets annually. Implementing self‑service password reset solutions like Specops uReset can reduce wait times and restore access quickly.
read more →

73% of CISOs Now Prefer AI-Enabled Security Solutions

🛡️Foundry’s Security Priorities Study finds 73% of security decision-makers are now more likely to consider a security solution that uses artificial intelligence, up from 59% a year earlier. CISOs plan to deploy AI for malware and threat detection, anomaly detection, real-time risk prediction, IAM, DLP, automation of responses, and improved visibility. Respondents cited faster detection of unknown threats, accelerated response times, and lower analyst workload. Experts caution against vendor hype, data-quality issues, hallucinations, and governance gaps, and recommend building AI-ready security data platforms.
read more →

Misconfigured Demo Environments Become Cloud Backdoors

🔒 New research from Pentera Labs shows that internal testing, demo, and training applications left in default or misconfigured states are being used as entry points into enterprise cloud environments. The team found popular vulnerable apps such as Hackazon, DVWA, and OWASP Juice Shop exposed on major cloud platforms and sometimes tied to overly permissive IAM roles. Attackers have leveraged these exposures to deploy crypto miners, webshells, and persistence mechanisms; Pentera recommends inventorying assets, enforcing least privilege, isolating labs from production, and expiring temporary test environments.
read more →

SageMaker Unified Studio Adds Cross-Region and IAM Access

🔁 Amazon SageMaker Unified Studio now supports cross-Region subscriptions and IAM role-based subscriptions, enabling teams to subscribe to AWS Glue and Amazon Redshift tables and views published in different AWS Regions. Cross-Region support helps break down data silos and removes the need for manual replication. IAM role-based subscriptions let users request access without creating a SageMaker project, simplifying governance. These APIs are available via the SageMaker console, Amazon DataZone API, SDK, and AWS CLI.
read more →

Make Identity Threat Detection Your 2026 Security Focus

🔐 Identity-focused attacks are now the dominant threat, and organizations must pair prevention with deep visibility. Identity Threat Detection & Response (ITDR) provides centralized logging, behavioral analytics, and alerts that reveal suspicious logins, anomalous account activity, and insider risk. tenfold combines Identity Governance and Event Auditing in one platform with lifecycle automation, access reviews, and centralized investigation tools. Book a personalized demo to evaluate capabilities and deployment speed.
read more →

Hidden Risks of Orphan Accounts in Enterprise Identity

🔒 Orphan accounts — abandoned human, service, and AI‑agent identities — create persistent, unseen access across applications, platforms, assets, and cloud consoles. These dormant accounts often evade traditional IAM and IGA tools due to integration gaps, unclear ownership, and proliferation of non‑human identities. Continuous identity audit using application telemetry and a unified audit trail can detect, flag, and automatically remediate or decommission orphaned accounts. Orchid positions its Identity Audit as connective evidence to inform IAM decisions.
read more →

Why Security's Future Depends on Identity, Not Perimeter

🔒 Modern security must treat identity as the perimeter rather than the network. As remote work and cloud adoption dissolved traditional edges, attackers increasingly target credentials — a trend underscored by reports from Verizon, Microsoft and Okta — making identity the primary attack surface. Organizations must adopt Zero Trust identity controls such as MFA, SSO, RBAC, PAM, device trust and continuous, adaptive monitoring, and treat identity lifecycle and privilege management as core infrastructure.
read more →

From Arts Degree to Cybersecurity: Rona Spiegel's Path

🔐 Rona Michele Spiegel transitioned from an arts and multimedia background into cybersecurity by blending early human-computer interface work with formal study and hands-on industry experience. She helped establish a user experience practice at Deloitte, worked in technology governance at Cisco, earned a Master of Information and Cybersecurity, and later focused on cloud controls at Wells Fargo before joining Autodesk to lead security and trust for mergers and acquisitions. Spiegel emphasizes careful risk assessment in M&A—especially when absorbing small, resource-constrained companies—while navigating AI-driven complexity, addressing hiring and entry-level gaps, and preventing burnout through inclusive leadership and mentoring.
read more →

CISOs' Top Cybersecurity Priorities and AI Focus for 2026

🔐 In 2026 CISOs are balancing core security tasks with urgent AI-related challenges. Strengthening data protection, securing cloud and enterprise AI deployments, and improving identity and access management rank high. Leaders are preparing for AI-enabled attacks, rolling out AI to accelerate security operations, and addressing shadow AI and third-party risks to bolster resilience and supply-chain security.
read more →

Jamie Norton on securing government and finance systems

🔐 Jamie Norton, CISO at ASIC and vice chair of ISACA, describes persistent cyber challenges across government and financial sectors. He points to legacy systems, weak foundational hygiene, and the need to align people, process and technology while warning that rapid advances in AI will change roles and tooling. Norton emphasizes executive accountability, mentorship, training and a mission-driven culture to retain talent, and champions the mantra Do the basics brilliantly.
read more →

Enterprises Struggle with IAM, Privilege and AI Access

🔐 New research from CyberArk finds enterprise users routinely bypass IAM controls to work faster, with 63% of security leaders reporting this behavior. Only 1% of organizations have fully implemented a modern just‑in‑time privileged access model, while 91% say at least half of privileged access remains always‑on. Shadow accounts and unmanaged secrets surface weekly in 54% of firms, and many lack clear AI access policies.
read more →

Eight Critical Areas CISOs Must Address in 2026 Today

🔒 As enterprises deploy AI agents, expand cloud use, and rely on complex global supply chains, CISOs must tighten identity and access controls, govern agent accounts, and apply phishing-resistant MFA. They should prioritize zero-trust architectures across IT and OT, enforce proactive cloud posture management and supplier risk monitoring, and integrate geopolitical and regulatory scenario planning. Failing to address chatbot privacy, misconfigured cloud services, human error, and escalating compliance (e.g., GDPR, DORA, HIPAA) risks operational disruption, financial penalties, and reputational harm.
read more →

Identity Dark Matter: Unseen Risks in Modern IAM Infra

🔍 Identity has fragmented across SaaS, on‑prem, IaaS, PaaS and unmanaged apps, creating an invisible mass of ungoverned accounts and non‑human identities the author calls identity dark matter. Traditional IAM and IGA address only the nearly managed half of this universe, while APIs, bots, service accounts and agent‑AI remain unobserved and ungoverned. Orchid Security recommends shifting from configuration‑based controls to Identity Observability: collect telemetry from every application, unify audit trails, and extend governance across managed, unmanaged, and agent‑AI identities to achieve measurable visibility and faster response.
read more →

Why Passwordless Deployments Fail in Complex Enterprises

🔒 Many enterprise CISOs continue to struggle to abandon passwords despite decades of effort and mounting security risks. RSA’s ID IQ Report 2026, based on a survey of 2,000 security professionals, finds that 90% of respondents report problems with passwordless deployments. Technical complexity across hybrid environments, legacy systems, OT/IoT devices, and inconsistent platform support creates gaps that often force organizations to retain insecure fallbacks. Experts recommend sequencing rollouts to secure privileged users first, using reverse proxies or VPN-enforced SSO for legacy apps, and ensuring end-to-end phishing-resistant enrollment and recovery.
read more →

Implementing NIS2 Without Creating Excessive Paperwork

🛡️ Companies facing NIS2 risk turning compliance into a voluminous paperwork exercise unless security is embedded in the technical stack from the outset. The piece argues that documentation alone does not equal protection and advocates for automating controls and evidence via infrastructure as code, CI/CD pipelines, and policy-as-code. Practical focus areas include IAM, vulnerability and supply-chain management, and monitoring and incident response, where automation both reduces burden and improves auditability.
read more →

NIST and CISA Draft Guidance to Protect Identity Tokens

🛡️ NIST and CISA released the initial draft of Interagency Report (IR) 8597, offering implementation guidance to protect identity tokens and assertions from forgery, theft, and misuse. The draft, open for public comment through January 30, 2026, targets federal agencies and cloud service providers. It reviews controls for IAM systems that rely on digitally signed tokens and calls on CSPs to adopt Secure by Design principles while prioritizing transparency, configurability, and interoperability. The report also urges agencies to understand CSP architectures and deployment models to align protections with their risk and threat environment.
read more →

Protecting Against Forgotten IT Assets and Risks Today

🔒 Organizations regularly leave servers, accounts, APIs, applications, and storage unmanaged or forgotten, creating high‑risk “IT zombies” that attackers exploit. The post outlines detection approaches — Automated Discovery and Reconciliation (AD&R), CMDB reconciliation, directory analysis, WAF/NGFW monitoring and SCA — and prescribes concrete responses for decommissioning, credential rotation, and data lifecycle control. Implementing IAM, SBOMs, DLP/CASB and automated test‑environment lifecycles reduces exposure and helps meet regulatory obligations.
read more →

AWS cost allocation using workforce user attributes

📊 AWS now supports cost allocation using workforce user attributes imported into IAM Identity Center. Customers can enable attributes such as cost center, division, organization, and department as cost allocation tags to automatically attribute per-user subscription and on-demand application fees to internal business units. Costs are visible in AWS Cost Explorer and AWS CUR 2.0 and the capability is generally available in all Regions except GovCloud (US) and China (Beijing and Ningxia).
read more →

2026 Cybersecurity Forecast: AI, Agentic Defense, IAM

🔒 The Cybersecurity Forecast for 2026 highlights how agentic security automation and widespread AI will reshape defenses, shifting SOCs from monitoring to automated action. It calls for building workforce AI fluency, evolving IAM to treat agents as managed identities, and deploying model-protection measures alongside tamper-proof backups. Boards will increasingly demand operational resilience, quantified exposure, and mature AI governance.
read more →

Simplifying Enterprise Cybersecurity Through Identity

🔐 Organizations face rising complexity as AI and sprawling systems make policy and compliance management touch every application. Deloitte has helped industrial and financial customers by linking named users to accounts, surfacing privileged and unvaulted accounts, and automating contact and remediation to reduce manual work. That improved SOC telemetry and cut time mapping incidents to MITRE ATT&CK. Meanwhile, apexanalytix uses Azure Active Directory and conditional access to detect risky sign-ins, impossible travel, and enforce geographic boundaries.
read more →