Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Protecting identity should be your resolution next year

by The Gurus
December 21, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

Cyber security has been a huge topic of discussion throughout 2016. With plenty of high-level (and often very public) threats, attacks and hacks, it is showing no sign of a slow down over the next 12 months.
With companies looking to protect their valuable data and identity, SailPoint takes a look at the year ahead and predicts what we can expect to see and hear more of terms of identity in 2017:

  • The domino effect – Poor password hygiene will continue to help hackers leverage identities from one organisation to the next
  • Identity analytics – Organisations must have insight into human behaviours in 2017 to help detect anomalies
  • Cyber-attack fatigue – Domestic attacks on the government and critical infrastructure will increase with devastating effects
  • GDPR wake-up call – Businesses must begin to align their processes in the coming year in order not to get caught out
  • The cybersecurity brain drain – The security market must overcome its significant talent shortage in two ways

The domino effect
Kevin Cunningham, president and founder, SailPoint
“2016 has been the year of poor password hygiene, with people continuing to use the same password across a myriad of personal and professional applications. The result of this is that seemingly unrelated corporate accounts are put at risk. It’s a domino effect – hackers are going on to leverage identities from one organisation to the next, charting their way across the corporate landscape unchecked. This is a new phenomenon, but one we’re likely to see more of in 2017. It’s also an indication of how patient these guys are. They take their time and work the chain to get to the info they’re ultimately after. They’re willing to work for it; with the average time for organisations to detect a threat embedded in the network more than 200 days in the round, it gives them a wide window to do serious damage.” 
Identity analytics
Kevin Cunningham, president and founder, SailPoint
“Identity analytics will become increasingly more important in 2017, giving organisations an understanding and insight into human behaviours related to identity access and anomaly detection. Understanding and predicting human behaviour is the next frontier of identity access management (IAM). This will manifest itself in enabling the organisation to query who has requested what and how that is different from other users. Additionally, how a certain application is being used compared to how other users are engaging with it. From a governance standpoint, if someone is not using an application, does that mean that entitlement goes away or do they simply not know that this application could help them do their jobs better? These are the kind of insights organisations will benefit from in the year to come with increased visibility into user behaviour.”
Cyber-attack fatigue (government, critical infrastructure, DNS and the cloud)
Darran Rolls, CTO, SailPoint
“Cyber-attacks are going to continue and increase in scale, but we’re seeing a greater acceptance of the fact that an attack will happen, leading to an increased level of fatigue. As a result, in 2017 we’re going to see an increase in domestic attacks on the government, as well as on critical infrastructure – that includes the grid and nuclear power plants. I like to call this the ‘internet of insecure things’, because as we’ve seen, these industries use devices that are completely vulnerable, ripe for attack. 
“We’ll see additional attacks on domain name systems (DNS), like the recent hit on Dyn which caused a massive outage on the US west coast, taking down several major websites that are used on a daily basis. The next attack will be even more significant than what we’ve already seen, down to our reliance on centralised systems and the sheer vulnerability of DNS. 
“There’s also a good chance we’ll see a major cloud provider admitting to a background worm that’s been there forever. We think of the underlying infrastructure providers as safe havens, but they’re not. There are likely major flaws in systems we’ve all assumed are secure, similar to the Heartbleed vulnerability. While for some, the frequency of data breaches can create a state of fatigue and acceptance, organisations must resist the temptation to sit on their hands. Identity must be at the core of cybersecurity. That means taking responsibility for knowing what data is being accessed, by who and at any given time.” 
GDPR wake-up call
Darran Rolls, CTO, SailPoint
“When people begin to truly understand the implications of what GDPR means for businesses today, it’s going to result in a lot more disclosure in general. While no-one will be penalised until 2018, businesses must begin to align their processes in the coming year in order not to get caught out. For example, if you lose your laptop, which contains a list of customers on its hard drive, and it’s not encrypted, your company will have to declare that publicly to avoid a hefty fine. The GDPR ‘wake-up call’ will likely see companies scrambling to get organised in 2017.” 
The cybersecurity brain drain
Mark McClain, CEO and founder, SailPoint
“The security market is experiencing a significant talent shortage – exacerbated by the continuing evolution of the industry. There aren’t enough experts out there and those that exist are sometimes in danger of becoming obsolete if they’re not constantly reinventing themselves, or staying abreast of the tools and threats of the day. 
“In 2017 the industry will respond to this in two ways: firstly, there will be lots of education and training to retrofit general IT staff into many of these roles, due to the increasing importance of security within the general IT landscape. Secondly, vendors will continue to look for ways to leverage the new wave of automation and artificial intelligence. As the complexity and volume of security-related issues increases, companies will expect vendors to help them ‘separate the signal from the noise’, so they can focus their efforts on the areas of greatest risk and impact.”

ShareTweet
Previous Post

This Free App Can Protect You From Ransomware

Next Post

Modern account security is finally on its way

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol