2023 Trends in Identity Security Report – Jeff Reich, Identity Defined Security Alliance
Protecting digital identities has never been more crucial in the fight against ever-evolving and increasingly sophisticated cyberattacks. As cloud adoption, remote work, mobile device usage, and third-party relationships drive up the number of identities, more businesses are suffering identity-related incidents. The IDSA’s 2023 Trends in Identity Security report details the current state of identity security and its impact on the security challenges and outcomes of organizations. Jeff Reich, executive director of the IDSA, discusses the report’s key findings, including:
1) Managing and securing identities continues to be a top priority for businesses
2) Phishing attacks lead identity-related incidents
3) Over two-thirds of businesses experience direct business impacts as a result of an attack
4) Cyber insurance for identity-related incidents is increasingly common
Transcript
This is techstrong tv. Hey everyone, welcome back to techstrong tv. I'm happy to be joined once again by my friend Jeff Fry.
Jeff is the executive director of the Identity Defined Security Alliance. Id s a. He's fresh off atten, attending Iver out in Las Vegas, wearing a Hawaiian shirt on National Chocolate Ice Cream Day.
Who could ask for anything more? Hey, Jeff. Welcome.
Perfect. Thank you very much, Alan. It's great to be back.
Great to have you on course. Jeff. We just saw each other at R rsa.
Wow. It wasn't just rsa, I guess was what, about six weeks ago? Five weeks ago at least.
Oh, Yeah. It's been over a month. Well, a been look, five.
Yeah. Yeah. No, go Time goes every day.
It's another day, man. Um, so Jeff, and, and not just at rsa, we've had John on a few times now since you joined as the, the, uh, the I dsa. But for those of us in our audience who are not familiar with the mission of the Identity Defined Security Alliance and what you guys are doing, why don't you remind us quickly if you can, Happy to do so, and thanks for the opportunity.
I D S A has been around for around five years. It's a nonprofit member driven organization with a focus on raising the level of identity security and the security of identities throughout the world. And we do that focusing mainly on what our, our identity vendors gonna provide.
What can enterprises do with those tools, and ultimately, what can consumers do to protect their identity? Love it. Um, and as you mentioned, it's a volunteer and, and community driven organization.
Um, you, I mentioned at the top you would recently added IDRs, which is of course, a, uh, a conference dedicated to this whole issue of identity. Um, and, you know, identity continues, especially when we talk about cloud and cloud security. You know, identity is the, the key to the kingdom, if you will, in in more ways than one when, when it comes to cloud security and, and security in today's kind of connect from anywhere world.
Um, before we go further for people want to get more information on, on idsa, what's the website, Jeff? org. Excellent.
All right. My next, my next, uh, kinda area we wanna jump into is recently, well, I guess it was in time for IDRs. You guys, uh, had a new study come out, a new survey and study, come out, a new report.
You want to tell us about it? Maybe? I'd love to.
Uh, uh, it, I, it's been waiting inside me waiting to get out. Uh, yeah. Every, every year I D S A does, uh, research surveys with organizations that have a thousand more employees and have a senior identity and or security person.
And we ask a series of questions, many of which are repeat questions cuz we'd like to follow trends. We release that at iden diverse, which is what we've been doing every year now. And so it was just recently released, still still warm off the press, if not hot.
And some interesting trends came out of there. It, you know, some things that, uh, really struck me. org, you'll see a banner right at the top.
You can download this, this research survey. It's about 16 pages long, so it's not gonna take you days to read, but it's more than just a glance because there's some good information in there. A couple of things that that struck me, and we can get into any details you want, are that, you know, about 60% of security professionals feel they have their identity, um, secured their identity, secured correctly within their environment, both for their, uh, u internal users and their customers.
But more than 50%, um, indicated that they had an i, uh, a breach within the past year that had identity information associated with it. So I was trying to get my head around how do most of them feel that they're doing really well and most of them have had breaches. So that's my challenge this year is to figure out where are those, I think we need to find a way to get expectations in reality a little closer to each other.
So, you know, Jeff talking now with someone who's followed, uh, security surveys and stuff for 20 some odd years and, and you know, just, I, I think it was just this week, the ver the latest Verizon data breach report came out, which is kind of the granddaddy of, of, of security reports. Um, there's always that disconnect, right? But here's the thing, over time I've seen that pendulum swing.
There was a time where we didn't have as many, let's call it, known breaches because I think we've always had breaches fair enough. But we didn't have as many known breaches yet. Security people, you know, the glass was half full security people knew that the emperor had no clothes and that, um, you know, they, they were just, they were just the zebra in the herd waiting for, for the day when it was their turn to get eaten by the lion, right?
I mean, that, that was kind of the state of things. Then, you know, over the years I've seen that pendulum sort of swing where they say, look, we're throwing so much money at this and we outsource and we insource and we, we, we, we are PCI compliant and we're that compliant and, and we're, you know, name whatever your des your security thing is that year. And, and so I feel more confident that we have greater visibility and we're more secure than we were last year, five years ago, three years ago, whatever.
But yet at the same time, as, as this report brings out, we've seen the breaches, the number of breaches, the percentage of breaches go up. But if you talk to those same people and say, do you realize the hypocrisy here? They'll say, no, no, no hypocrisy.
We just do a better job of reporting breaches than we did in the past. So first of all, I'm an optimist and there is a lot of good news in the report too, but to, to dive into this point just a bit further, um, you maybe do have a better job. In fact, we are reporting breaches better than we ever have.
The other side of that is the down risk side of every breach is greater than it's ever been. No doubt. It is no longer you need a new credit card number than you move on it.
And now, now it's how many years is it gonna take you to recover from a true identity breach? And in some cases you're not gonna be able to fully recover for decades. No.
There's the stuff you're just not going to recover. But, you know, again, it it's this story of show me the money. Mm-hmm.
And, and for a lot of public entities, if you look at their share price, you know, from time of breach to, well, time of breach breach disclosure to let's say two, three years post breach, it's a blip. There's really, there's not that long term kind of hit that they took, even though, look, we've seen cases where, you know, CEOs were toppled the cause of it. Right.
Or, or regimes changing ethoses In, in some recent cases. Well see. Yeah.
But CISOs are disposable. Jeff, no, Trust me, I've been doing this long enough to know that I've been a C S O and that's Stanford Chief Scapegoat Officer. Yeah, absolutely.
You know, but elite, well, let's not even get into the going to jail thing over it, but, um, yes, that that is true. That is true. And, and so, you know, I, I wonder in your findings here, did you separate out like what CISOs think about their current state of security versus what other C levels think about their current state of security?
Uh, we didn't in this report because this is mainly targeted towards security and identity leaders. Okay. As opposed to let's just focus on business leaders business.
There is another survey waiting, I believe, for that very issue. And then there's a whole different reconciliation that has to occur that here's what the CSOs are saying and here's what the rest of the C-suite and the board think. Fair enough.
We, um, so sounds like we need to have you back on when those are done. Um, we just need To make this a regular thing. Well, you know, you always have an open invitation here, Jeff, but thank you.
Let, let's turn to the good news. You said there was plenty of good news. Oh Yeah, there's plenty of, I, I'd like to share the good news.
Good. And so will I, so you know it, as I said, it's 16 pages. There's a lot there, but lemme come up with a couple, couple of 'em.
I talked about 60% are positive about their capabilities for securing identities. More than half, 52%. Here's something that I think is actually good news saying that cloud applications are the main driver for driving up the number of identities that they have to manage.
You know, the, the downside of that part is every organization has more identities to manage. Now, it's no longer one per person now it's multiple per person, multiple, multiple per machine. How many per silicon?
So cloud applications are driving that. I think that's good news because the more we drive to the cloud, even though it's expanding the number of identities now, I believe we're going to reach a point where it ends up, uh, merging a lot of identities, which I feel will make it easier to manage. And, um, one, I'll put in one more bit of good news and then get your thoughts on this.
63% of the respondents think that they either already are or could benefit from using artificial intelligence or machine learning for managing those identities. And that's good news. I believe it's fantastic news.
I'm, I'm being sarcastic. You know what, Jeff, look, I live in a world right now where I can't take three steps without tripping over artificial intelligence. Mm-hmm.
We launched Techstrong, do AI to kinda put all the AI stuff there, but you know, I I, I got pitched four press releases this morning, three of them, the CEO says, you know, we're gonna be great because we're incorporating artificial intelligence into our vulnerability management, into our, uh, uh, threat intel into our, uh, development process. DevSecOps and I, I'm just, you know, we've been through hype cycles before Jeff. Mm-hmm.
Is it really gonna help that much or is it gonna be that soon? So first of all, I believe yes, but not across the board. I am not a put AI into everything and, and, and everyone can eat chocolate ice cream every day.
And world's wonderful. Right? That's not how it's gonna work.
However, when it comes to identity management, think about the tasks that are involved in that. When you get down to it, as long as you write your rules correctly, which is really the only real thought process of identity management. Everything is simply execution.
That's where a AI does play a good role. And I think we all benefit from using machine learning for that. Because you can take conditions and say, here are the conditions we have and here's what the rules say.
Is there going to be a variance from that? If not, let's just go with it. And if there is, we either determine a, a variance or escalate it as an issue.
To me, that's a perfect application for ai. Now, with all the other applications you talked about, there certainly can be a play, but I'm not certain most people are ready for that or that most ai um, engines are ready for that. I, I don't disagree there either.
I I also think though, you know, there there's a little, there's this generative AI kind of thing that we see with chat G P T, and it's cool and it's almost automagical and people are wowed by it. It's sexy. Yeah, It's sexy.
Great word. But then there's also the, the industrial side of this where, where's the rubber, meaning the road with real application specific improvements. So I'll give you, for example, I, I use an email program called Spark and, and they just incorporated AI now into their email program or email app where if I hit reply on an email and, and, and say ai, it basically, it kind of reads the email that the person sent me and makes up a response.
I could give it say yes, no maybe, or whatever. And, and it makes up a response which I can then edit or reprompt or whatever. Um, I've been playing with it only, it's only been out less than a week.
So I don't have a big, you know, data set. I'm not quite sure it's ready for primetime. You know, it's, go ahead.
No, no, I would agree with you. And, and anytime, especially if it's generative, there, there is so much, there are so many variables that need to go into it when you write a reply to the em to an email, unless you say agreed and hit center, hit enter rather. Um, there's so much that goes into it.
There's the history of the relationship that you have that an AI program won't Never know. Yeah. There is the emotion of this is such a hot issue, I can't wait for you to read this email that the AI won't know about.
So it is not ready for prime time in many applications like that except for, you know, basic ones. The reason I think it is for tasks like identity management and others are that we have for too long been riding by the seat of our pants to say, we need an identity to do this and give this person access to that. Right?
And it grows into an unmanageable mess that at some point an auditor comes in and says, you don't have good control of your access access management because everything is individual rather than neither rule-based or rule-based. Even those are starting to fade away. So we need to do that correctly anyways.
And to me, the option is you can pay someone not as much as they feel they need to get to do those mundane tasks that are gonna drive them insane. Or you can say, let's elevate that position to writing those rules and making sure those rules are f are followed and automating, even if you don't wanna call it ai, automating all of the mundane task that are predictable when a situation occurs. Fair.
Um, You're not gonna move me on that one. I'm with you on generative and email responses And No, I get it. No, I, and I don't disagree with you John.
Hey, I gotta move off AI though cuz I want to return back to the survey and, and the report. What else can we highlight for, we only have a minute or two left here, but I wanted to see if there's anything else we could tell our audience about it. So here, here's, here's something, here's some really good news.
61%, I'm gonna have to cite numbers cuz that's what a survey is, right? Right. Six 61% say that managing and security securing digital identities is either the top priority or at least in the top three priorities for their organization, not just their department.
That is great news. That means absolutely. Yeah.
Yeah. The importance of this is penetrating C levels penetrating the board, the CFOs get it. So 61% is, is more than the majority.
I I think it's fantastic news there. Um, okay, One more, 58% say they fully implemented multi-factor authentication for privileged user access. Now, once again, m FFA is not an answer to everything, just like AI isn't.
But for privileged users, how long have we been saying that's where the compromises occur? And if it's simply a password, especially if it's a repeated password or shared password or whatever stupid password thing we're doing this year, putting an MFA at the very least reduces at risk. You have, we are now at 58%, 49% have it fully implemented for all users.
So Wow. We are now moving towards people get it. And I love that.
That's amazing. I mean, look, I'm so, I'm a big, I'm a big believer in mfa. I even, not only my work stuff, but my own personal stuff, I, I I implemented its anytime I can.
So I I think that's great. You know, there was a lot of noise these last couple weeks about something called PAKEs, right. Google, you gonna support PAKEs.
I think Safari is gonna support it now too. So Chrome and Safari, you got a lot there. I and I think Microsoft's explorer as well.
Yes. Which is kind of chromium as well. But, um, you know, and what this is going to mean, they're saying, Hey, maybe cause a lot of people get up, they're not, they're not big fans of mfa.
It, it's a pain in the butt for a lot of people. I think it's a worthwhile pain in the butt. But, you know, anything we can do to move that along I think helps.
I, I, I agree. Now, m ffa, some people think it stands for more friction to access and that's why people Okay. That Yeah.
But I, I mean, look, you get a quick text and you're done for the most part. And, and you know, don't be silly. Um, I agree.
I also, I, I use, you know, um, a a u SB key, I won't name you coming up with a brand name. That actually makes it easier for me. I don't even need the, the text, I just push it button.
Right. You just push your button with it. And I, I have, I have one of those too.
The only problem is it's A U S B A and I have Max now that only use the u s BBC ones, but that's a whole nother story. Oh, You can get to, I have a u s BBC that also has NEARFIELD communications and so yeah, you, you can make it work. Yeah, You can make 'em all work.
Hey Jeff, we're ahead of time. I've got people in the waiting room for our next interview, but, um, just real quick for people want to get more information on this survey and more about future surveys and just more about the Identity Defined Security Alliance. Give us that URL one more time.
Okay. org. You can download the, the survey report.
We have webinars almost every week. I'll look into membership. Love to have you engage with us.
Jeff, my friend. It's great seeing you. You look great.
Promise me you're coming back on soon. Promise me you have me. We got a deal.
Thank you, Alan. You're done. All right.
All right. Check it out. org.
Check it out. This is Alan. We're gonna take a break here.
We'll be back in a moment on text TV.