Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 9 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Identity Security: The New Perimeter for Cloud Security Companies Using CNAPP

By: Josh Breaker-Rolfe, cyber content specialist at Bora

by Guru Writer
August 4, 2025
in Insight
Public Cloud
Share on FacebookShare on Twitter

In a cloud-native world, your network is no longer your perimeter; identity is.  

Every user, workload and service account is an entry point. And every entry point has permissions. The problem? Most of those permissions are excessive, unnecessary or never revoked.  

In fact, according to Tenable research, more than 90% of cloud identities use less than 5% of their permissions. That’s not just an inefficiency, it’s a risk. And, as organisations scale across AWS, Azure, and GCP, it gets harder to see who can access what, where and why.  

What Makes Identity Security So Difficult in the Cloud? 

Cloud infrastructure is fast, flexible, and dynamic. Access decisions, however, often stay static. Teams copy IAM roles between environments, forget to clean up credentials and create service accounts that live forever.  

This leads to three key problems: 

  • Too many permissions: Identities are overprivileged by default 
  • Not enough visibility: It’s hard to know who has access to what, especially across multiple clouds 
  • No lifecycle control: Access is rarely tied to business need or time limits 

The result? Identities become a pathway for attackers to move laterally, escalate privileges and access critical data. And this isn’t just hypothetical: according to the Verizon 2025 Data Breach Investigations Report, stolen credentials are involved in 22% of breaches.  

How Does CIEM Help Secure Identity in the Cloud? 

Cloud infrastructure entitlement management (CIEM) is a purpose-built solution for taming identity sprawl. Where traditional IAM tools stop at assigning roles, CIEM goes further:  

  • Discovering all identities, including human, service, federated and machine 
  • Analysing effective permissions across accounts, environments and clouds 
  • Highlighting unused or risky entitlements 
  • Prioritising remediation based on exposure and behaviour 
  • Supporting least privilege at scale 

CIEM works by continuously scanning your cloud accounts, analysing policy relationships and detecting anomalies; like a service account with read/write access to sensitive workloads that hasn’t been used in 30 days.  

In short, CIEM replaces guesswork with visibility. It helps teams enforce least privilege without slowing development or creating constant manual work.  

What Role Does Just-in-Time Access Play in Identity Security?  

However, even with CIEM in place, static permissions are still a risk. This is where just-in-time access (JIT) comes in.  

JIT access means granting permissions only when needed, for defined time, and revoking them automatically afterward. Think of it like temporary keys for specific jobs.  

For example:  

  • A developer needs admin access to troubleshoot a production bug 
  • They request elevated permissions through a workflow 
  • Access is granted for a one-hour window and revoked automatically 

This mode reduces standing privileges, which in turn limits the damage attackers can do if they compromise an account. It also improves governance by making every access decision time-bound, auditable and tied to context.  

JIT is especially useful in environments with high compliance requirements, external vendors, or large DevOps teams moving quickly between roles.  

 

Why Do CIEM and JIT Need a CNAPP to be Effective? 

CIEM and JIT are essential tools for managing cloud identity risk, but they only fulfil their full potential as part of a Cloud Native Application Protection Platform (CNAPP).  

Why? Because access risk isn’t always obvious in isolation. 

A dormant service account with admin privileges might seem low priority, until you discover that it can access: 

  • A misconfigured virtual machine exposed to the internet 
  • A workload with no runtime protection 
  • A storage bucket containing sensitive customer data  

Individually, each issue might seem manageable. But together, they form a high-impact attack path. In the 2023 Okta support system breach, for example, attackers compromised a service account with excessive permissions and used it to access customer files. The breach wasn’t about weak identity controls, it was the combination of overprivileged access and exposure to a vulnerable system.  

CNAPPs are built to detect exactly these types of interconnected risks.  

Where CIEM shows you who has access to what, and JIT limits when and for how long, a CNAPP layers in:  

  • CSPM to identify exposed or misconfigured assets 
  • CWPP to uncover vulnerable workloads 
  • DSPM/AI-SPM to flag sensitive data or model access 
  • IaC scanning to catch problems before they’re deployed 

By correlating identity data with everything else in the cloud environment, CNAPP helps teams prioritise what matters most and act accordingly. In other words, CIEM and JIT give you control over identity, but CNAPP gives you the context to use that control wisely.  

 

What’s the Takeaway for Security Professionals? 

If you’re managing cloud environments, identity is no longer just the IAM team’s problem; it’s a critical part of your security posture.  

  • CIEM gives you visibility into who has access to what, across every cloud account. 
  • JIT puts time-bound control around that access, minimising standing privilege. 
  • CNAPP ties it all together, combining identity with context from workload, data and configuration risk help you act on the alerts that matter most.  

By taking this identity-first approach within a CNAPP framework, security teams can achieve: 

  • A smaller, more manageable attack surface through leas privilege enforcement 
  • Faster, smarter remediation of risky permissions 
  • Continuous monitoring with less manual overhead 
  • Stronger alignment with compliance and zero trust initiatives 

In cloud environments, identity is the front door. The question every organisation needs to be on top of isn’t just ‘Who has the keys?’; it’s how long they need them and, crucially, what else they might unlock.  

ShareTweet
Previous Post

One Week of the Online Safety Act: Cyber Experts Weigh In

Next Post

Surge in zero-day exploits identified in Forescout’s latest threat report

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol