Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Enterprise security: Convenience shouldn’t be king

by The Gurus
March 4, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

The relentless pursuit of a seamless digital user experience is having serious consequences in the workplace.
 
The expectation for convenient access to corporate and consumer applications such as Gmail, Twitter or Dropbox is undermining the efforts of CSOs seeking to protect sensitive personal and commercial data from falling into the wrong hands.
 
For everyone working in IT security, if this trend becomes the “new normal” and your company’s users are accessing systems and data with feeble username and password (UNP) authentication, then you have a serious problem.
 
The main driver behind the trend for convenience has been a change in boardroom culture. Many start-up founders, business owners and CEOs aren’t ensuring that risk assessments are being carried out to ensure corporate data networks and consumer-facing platforms are secure and fit for purpose.
 
Unfortunately, whilst this new culture may make workers more productive and increase the number of customers businesses have online in the short-term, the recent data breach news stories should prove beyond any doubt that these new bad habits will catch up with businesses at some point.
 
What is the answer? Here are three top tips:
 
Define and enforce clear use policies – A sensible first step is to form a holistic view of company’s data, assess what is business-critical and develop a strict policy document that must be adhered to. Organisations can then define the access control parameters that work best for their business structure, keeping the gateways to certain information accessible only to those with the right permissions.
 
Take back control – As a next step, deliver authentication through a standalone platform which redirects users back to the corporate domain, ensuring the user’s credentials can be validated using a corporate authentication solution before access is granted.
 
Introduce some friction – The final piece of the puzzle? Introduce appropriate levels of security.
 
Enabling static, risk-based policies is a step in the right direction. These solutions can determine access requirements based on who is accessing which service.
 
Better still, there are intelligent adaptive solutions that can apply exactly the right level of visible security appropriate to the access being requested. This serves to remind the user of the security risks associated with their actions, whilst the level of convenience also plays an important part.
 
Also, in circumstances where highly sensitive and confidential content is being reviewed, or when access requests are being made from beyond the control of the fixed network perimeter, it is essential that the user should be challenged to re-verify their credentials before access is granted.
 
Equally however, under circumstances where lower value data is being accessed, or indeed when the user has already authenticated into a secure environment during the same “session”, then barriers to access can be confidently lifted to raise convenience levels for the user.
 
Ultimately though, business owners, CEOs, CMOs and employees must all accept that some level of authentication is necessary when dealing with corporate data.
 
Any pursuit of an entirely frictionless digital environment in the workplace is short-sighted, and will lead only to an increase in corporate data loss. Fortunately, with the introduction of small amounts of ‘friction’, all parties can ensure that security and convenience actually turn out to be good bedfellows.
 
 
Chris Russell is CTO of Swivel Secure

ShareTweet
Previous Post

Endpoint security – will the state of security give it its sexy back?

Next Post

SIEM – more than a reporting tool, and useful as a control method?

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol