Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Problem with privileged users should be reversed to show benefits

by The Gurus
June 19, 2014
in Editor's News
Share on FacebookShare on Twitter

The problem with privileged user access is caused by “super” user accounts that are generally shared by IT staff members to perform their job.
 
Speaking at the Identity Management conference in London, Jitender Arora, information and security risk executive in the financial services industry, said that users often need access to do their job and this means full access for individual accounts. However, this problem is compounded by number of orphan and dormant accounts left in the environment due to lack of effective account management processes.
 
He claimed that users often need privileged access to production IT assets to do their job on daily basis, and applications also need privileged accounts on systems to run as service or connect to other systems or databases for machine to machine communication. But the problem is that the number of privileged accounts on systems have grown significantly, posing the challenge of effective management of “Keys to the Kingdom”.
 
“Every IT asset needs at least one privileged account to run and every application installed on that IT asset also need at least one privileged account to run as service,” he said. “Any typical global organisation would have approximately 20,000+ IT assets, which means 40,000+ accounts minimum. Now, there are human users who manage these environments and they also need access to these IT assets. If you add up the numbers it becomes a monster figure”.
 
He said that it is easy to give super-user access to every person who manages IT assets as it is simple that way, but it gets really complicated and difficult to implement if you want to give individual restricted access based on least privilege and segregation of duties principle.
 
Arora admitted organisations are finding it difficult to keep track of who is coming in, who is moving and who is leaving the organization, and modify access accordingly but said that the best action is not to change the access controls on systems too much because of movement in user space.
 
“The number of accounts are up and down, and when someone leaves you have potential of orphan and dormant accounts. The knowledge of passwords for such orphan and dormant privileged accounts adds on to this problem and complicates the issue.” he said.
 
He said that everybody joining the organisation is given a laptop or desktop with standard set of controls i.e. data leakage controls, proxy controls, email encryption and laptop encryption and these controls are fit for purpose for day to day work conducted by all users e.g. checking emails, attending meetings, creating documents etc., however, a subset of the user population needs to have privileged access to IT systems that are running business applications that earn money for the organisation.
 
“These standard controls are not adequate for such privileged access while accessing production systems,” he said.
 
“You need a flexible mechanism to elevate controls (based on risk) when a user needs to logon to the production system in the privileged capacity. These controls can be adapted based on the level of risk by creating a fine balance between convenience and security. It’s very difficult to control how and when users access production systems unless we take the knowledge of credentials away. The future of privileged access management is providing access on need to use basis with different level of controls based on risk associated with the type of access.”
 
Asked why privileged user access is still a problem in 2014, Arora said: “A lot of the problems a
re in that we need to make too many changes to the production systems due to movement of users in the IT organisation. We don’t need to be making so many changes just because someone joins, moves or leave the IT support organisation.
 
“We need standard set of privileged accounts with granular access on production systems that are well controlled and managed, and a mechanism to provide access to these accounts to privileged users on need to use basis. If we can achieve this, we have a better chance of managing ‘Keys to the Kingdom’.”
 
Hans Zandbelt, senior technical architect at the CTO office at Ping Identity, said that rather than see it as an ongoing problem, we should look at reversing the situation to realise how privileged user access can be seen as a benefit for the company.
 
In another presentation, David Higgins, professional services manager for UK and Ireland at Cyber Ark, said: “According to Mandiant, 100 per cent of breaches involved stolen credentials and they were typically privileged that allow you to do whatever you want to do. When it is privileged, it is access to more information and Edward Snowden accessed the agent roster, and privilege that he had was something they needed to focus on when a user gets access and when it is used.
 
“Everyone has got a good grasp on the end-user, but not on privileged accounts and what was created for a project may not be properly documented. Understand what out there and when passwords changed, they may be ten years old, but if you understand the scope you can understand what to remove and manage.”

Tags: IAMIdentity
ShareTweet
Previous Post

Hacker puts hosting service code spaces out of business

Next Post

Maze prison records were unwittingly sold at an auction

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol