2024 Trends in Identity Security with IDSA’s Jeff Reich
Jeff Reich, executive director of the Identity Defined Security Alliance, discusses the IDSA’s “2024 Trends in Identity Security report,” which analyzes data on the identity security programs of large companies. The research revealed that: 90% of companies reported an identity-related incident in the last year (same as 2023) and 84% of identity stakeholders reported direct business impacts, an increase from 68% in 2023.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Textron tv.
I am really pleased to have my friend Jeff Wright back here on on Textron TV today. For those of you who don't know Jeff, he is the executive director of the Identity Defined Security Alliance, the IDSA. Uh, Jeff's gonna tell you a little bit about the IDSA and their mission, and then we're gonna talk about their latest, uh, report, which is the, uh, 2024 trends in identity security report.
But first, let's welcome 'em. Jeff, it's great to see you. Looking great.
I hope all is well. Thank you, Alan. I'll, everything's great and it's great to see you as well, and it's wonderful to be back.
Thank you for inviting me. My pleasure. So, Jeff, you weren't always, you are a board, the IEC Executive Director of the IDSA and I, I know you before, you know, the IDSA.
Um, but for those of, uh, my, of our audience out here who are not familiar with you, with you and the IDSA, why don't you give us a little bit of your background and then a little bit of the IDSA and its mission? I'm happy to, thanks. Now, I wasn't born the executive, but I was born to be the executive.
Her flack is fair enough. Fair enough. Um, I have, you know, my background is in science and physics, um, at, at school.
And then, um, I, I did a, a bit of work with law enforcement associated there, and then really got into, went back to school and got into computers. So, without doing the whole resume, I've spent the past 45 plus years working on computer security, information security, data security, cybersecurity, and all the names that have come in between. I've, I, I'd like to think I've outlasted all of them so far.
Mm-Hmm. Um, I've started a security program at Arco Oil and Gas Company. I started a security program at Dell, at Rackspace.
Mm-Hmm. A few financial services companies. So I've always had the opportunity to build, I have been fortunate to build a, a good operations, um, and focused on security.
And over time I discovered that security, although there's security controls, there's gates, there's firewalls as everything else, security really boils down to who or what is doing what to what. And that really is a definition of identity. If you don't know who or what you're dealing with, should you be allowing any activity to occur, chances are fair enough.
Right, fair enough. So when the op, that is the truth. When the opportunity came to, to lead the nonprofit, um, IDSA, whose mission it is, 'cause you asked for that as well, is to, uh, it's a nonprofit.
So we provide education and re and, um, research information for people. We do have some, uh, we have paid members, certainly, and there are some benefits that come with, uh, a paid membership. But the overwhelming majority of what we do is free information and education for the general public or anyone that wants to know about or work in identity and security to really raise the level of awareness for identity, identity, security, and security.
Fair enough. Very cool. And of course, you know, identity this, say your grandpa's identity, right.
But when we used to think about identity, we would think of a person's identity. Mm-Hmm. Him, her, they, but it was, it was a identity was, uh, was attached to personhood, if you will.
It was carbon based. Yes. Carbon based.
That's a great way of putting it. Today, of course, identity has expanded. The, the who, who has identities or what has identities maybe is a better term.
Um, machines have identities, devices have identities, instances have identities. Containers have identities. Everything has a unique identity so that we can uniquely identify who or what it is and whether and how we want to interact with it.
And so the whole identity and access management, you know, as it relates to security, has become the, I think what network security was prior to the cloud. Identity security is to the cloud. Yeah.
I, I would offer that core is there, you know, um, you and I have been around long enough to see evolutions and, you know, the, the perimeter of security used to be the data center. In fact, at one point it was the computer, then it became a data center, and then it expanded to the network. And then that grew the land, the Yes.
The, the perimeter, whether it was Nobel or IBM, you know, whatever proprietary land there was. Right. And then that security perimeter grew to the internet, and that essentially becomes the universe.
And now the focus is, is it shrinking down to, is the perimeter of what you're doing, dealing with a given identity at a given time, right. In a given place. Yeah, absolutely.
Because that seems to be the consistent, I, I don't wanna use the word choke point, but the consistent ES point where we can have some control. Right. You can't, you can't do it based on device anymore.
You can't, as you said, you can't do it based upon what that we're all on the big network. Um, it, it is identity. And so it's an important thing.
And of course, this is recognized by industry. The IDSA has a tremendous roster of corporate members, many of the biggest vendors in the, uh, in the identity defined security space, a part of it, as well as end user organizations. Mm-Hmm.
Right. And, um, go ahead. Yeah, no, we, we enjoy working with 'em.
We're always looking for more as well, because I think the more people we have in this party, the more fun it's gonna be. And, um, you know, getting pretty quickly to the report that you talked about as much, it's a, it's a report on trends, you know, how have things been changing? This report in many ways astonished me this year because, um, yeah.
Let me give you just one example. We don't necessarily have to dive in, but I'm gonna give you one example. Last year, and I'm looking over here at my notes just because I'm old.
My memory isn't that good last year. You memory both 68%. Uh, we, we, by the way, we, we get the information for our research, uh, report, but, um, through a research agency, uh, dimensional research, and that adds a level of abstraction.
So we don't know, all we know is that each organization has at least a thousand employees. And, and there's a couple other criteria which are in the report. We list what it is.
But beyond that, we don't know who's answering it. You know, what the, you know, is there a political, uh, twist to it? Whatever we know nothing.
All we get is the data, which is how pure research should be. Last year, 68% of the respondents said that, um, identity related incidents directly related their business to their business. So that, that was a negative impact.
Right? Yeah. This year, that's 84%.
Wow. And if 84% are reporting, that means over 90% are actually having it. Yeah.
I mean, that's beyond critical mass, right? Yes. 70, 75% is like, you're a critical mass.
Well, you're at 90%. That's virtually every art. Yep.
And, and that's how I feel. And that's, and these aren't simply people saying, yes, we had an incident. These are people saying we had had an incident that had an adverse impact on our business.
Yep. Now we, so here we are. That perimeter that we just talked about, it's pretty porous.
Yeah. It really is. Geez.
Um, you know, you think about these things and it's like, wow, what else was it? You know what, let's back up. 'cause we dove right into the kind of the, the big one that got your attention.
Give me some demographics around the report, if you don't mind. Like how many people responded where, who are they? That kind of thing.
And then maybe, you know, we did this one that was most sort of eye catching for you, but maybe two or three other highlights from the report. Sure. No, and, and you know, I'll give you highlights until you tell me to stop, because okay, we've been there this year, but, um, the, the size of, I'm giving you some demographics, company size, I'll start with that.
We had about a third, uh, we had 521 organizations respond. Alright? And about a third of them, or a thousand to 5,000 employees, uh, these are split almost evenly not on purpose, it just worked out the way how they responded.
A third is 5,000 to 10,000, and a little more than a third actually. Um, they have the largest share slightly is more than 10,000 employees. And Charles.
Yeah. Yeah. These are not simply mom and pop shops that say, oh, we had a problem.
Mm-Hmm. So even with these large organizations, 84% are saying something happened. And we all know this, all we have to do, and regardless of when you're watching this, to whoever's watching this, take a look.
Do a search for a data breach this week, and you will see a significant hit no matter when you do it, unfortunately. And I will offer at least 84% of them, if not more, were related to an identity compromise somewhere. So, um, that's, that's a size job level for people responding about 20% were executives, about half were team managers, and about 30% were individual contributors.
So once again, a nice even distribution. Nice. Yeah, nice, nice distribution.
And it's interesting to see how A CEO responds differently. We do have cross tabs with all the breakdown of, of that. And by the way, our members get access to all that cross tab information.
Um, the, it's, it's still interesting to see that, and we've talked about this before, Alan. I know the gap between CEOs and CISOs, although is maybe shortening a bit, that gap is still there. It's still pretty much a chasm that CEOs think, yes, I've invested money, so I think I'm covered.
And CISOs are saying either we invested money in the wrong place or we're not investing enough. And this is not a new story, although the two need to be smashed together because there isn't an endless amount of funds that can go into protecting this. And, and it's simply throwing money at it isn't gonna help it.
Cecils also need to recognize in some cases that simply getting a shiny new toy isn't gonna fix a problem. So, uh, both of those are there. So, um, across the, uh, industries, uh, about, um, and this is a, a good even distribution and under 20%, and we don't have any one industry represented by more than 20% is technology and software, financial services, insurance comes in next, healthcare comes in next.
By the way, those are the two biggies, especially healthcare right now with ransomware and how that's working. Sure. Government, telecom, manufacturing, other technology.
Then it drops down really into single digits of services. Some retail and a few others that are there as well. Food and beverage is actually represented in their, so, uh, when you take a look at the demographics that were there, we have, I'm very pleased with, um, dimensional research and how they find a cohort that gives us that good peanut butter spread across, across the world.
I mean, in many ways it's kind of the usual suspects know what the biggest verticals are, you know, because those are, you know, the heavy regulated industries, Jeff, are obviously the ones where you see security and compliance having, you know, such representation so that that's, uh, you know, I think somewhat expected or that's the way you want it to be anyway. If you do one of these kinds of things and you're getting bud and beverage as your leading vertical, you gotta ask yourself, something's, something's wrong there. Right?
Or am I really getting an accurate representation? Yeah. So I like the distribution we have.
Um, excellent. You know, something else that we do. And, and because it's a trend report in many cases, we focus on, you know, what happened in the past year or the past two years.
So something I led, I wrote the report this year, and something I led with on this was, um, the past three years, 20, 22, 23, and 24, we asked the question, how do you characterize the importance of your program effectively managing and securing digital identities? In other words, how well do you think you're doing Mm-Hmm. And once again, there's been a gap because organizations feel they're doing it pretty well, and then they talk about the breach they had.
And, and I'm still trying to wrap my head around that, you know? Yeah, I'm sure. Yeah.
You, you either do well and or you have a breach and, you know, it's not binary, but the gap shouldn't be that big. But there has been improvement, and I think we are doing better in that. Um, 90, uh, let's see, um, in 2022, about 60% or so thought they were doing pretty well or optimized.
This year, that's gone up to 73%. And I do think there has been an improvement. So it's good to see that.
Absolutely. Well, I, you know, so here, here's, I'm always conflicted about this, Jeff. I think the good news is, is you know what?
We are making progress. We are making strides and, and being more security aware, security conscious, and we aren't putting in new tools, policies, process people to, to, um, make the situation better, to raise the level. However, like you said, on any given week, do it.
You google search for security breaches and you are overwhelmed by the amount of, of breaches we have. And so it's very easy to look at that and say, oh my God, this is like shoveling sand against the tide. We, we're not making any progress.
We're going backwards, but we're really not. I mean, the goodness is, we're not, it, it's just the enormity of the problem and the sophistication of the, of the enemy, if you will, of our foes here. It can seem that way.
Right. But we are, you know, your thoughts. Yeah, no, we are, we are improving.
And in fact, I'll draw an analogy to driving a car. In general, Americans are safe drivers in general. The problem is, just like with the question I just asked, if you ask any individual driver, are you a safe driver?
The answer is going to be yes. Mm-Hmm. But sometimes if you look at their record, they say, well, you've had, you know, four moving violations in the past year, two accidents last year.
Maybe you're not as safe a driver. No. If you think you are, yeah.
But, and, and there read that. Um, and, and if you look at numbers, you can talk up, you can see here's how many people were killed on US highways. I know in, in our state, and I'm not sure if every state does this, you know, we have the signs that say, you know, how many deaths there were in the highway pa last year, use your seatbelt and keep that number low.
Um, and I'm not saying any death is acceptable, that could be prevented, certainly, but those numbers aren't as overwhelming. You know, they aren't, they aren't dropping the population of the country. No.
You know, now this is like a covid epidemic pandemic kind of blip or something. Unfortunately, my state, we don't like to give out numbers. So we, we don't have anything like that, Jeff.
Um, but no, I mean, I, I think it's important for people, especially, you know, what, even our fellow security brethren and, and women and, you know, coworkers, it could be depressing sometimes because it feel, you know, when we don't get, when an attack is not successful, when nothing happens, no one comes over and says, Hey, great job. Nothing happened this week. Right.
When something happens though, you know, it hits the fan, and, and it, it, you know, it, it can, it can be depressing and discouraging at times. But you gotta remember, at the end of the day, we're, we're ever vigilant, you know, we are, and we are improving. You know, there's some other, um, uh, uh, I'll give you another example then don't wanna come back to another analogy.
One of the questions that's new this year is, uh, deals with identity sprawl. Mm-Hmm. And if you don't know what identity sprawl is, just think about every account you have for work, for email, maybe for your HR system, for your payroll system or accounting, um, for your bank, for your, um, personal email.
I've already just listed seven without even going through a list. So just so you know, and, and it's ridiculous. I have 900, no one should have that many, including me.
However, people are closer to 900 than they are to one than they think. Sure. So, so that's identity sprawl.
And the problem with that is every additional account that you have increases your, um, um, risk surface your tax exposure. Sure. Yep.
So the good news is that 93% of organization surveyed said they're, they're taking steps to manage ident sprawl because they see it's out of hand. So we are doing a lot of the right things relatively early on. This is still a relatively new problem.
Um, and, and to get back to, you know, our, our fellow security compatriots, this can be a very, um, emotionally draining and mentally draining position. I've been doing this a long time. I have had close friends that I've worked with that we've lost Yeah.
As a direct result of, you know, how they did or didn't manage the stress in, in, in this industry. And, and we could do a whole session on that, unfortunately. But, uh, yes, very unfortunately.
Um, but we need to recognize, as important as it is, it is still just your job. It, you know, you wanna be able to go home or, or, or go out of your office if you're working from home every evening, you know, enjoy time with your family, um, have fun activities and not have to worry about this. And every time I, I deal with a CISO or A CSO that says, I don't know if I can handle this, it's nonstop.
I can never turn it off. My first pushback is it one of two things. Either you may not be managing this correctly, or two, you may need to find another place to do this.
Um, and so to your point about we are doing better, I think we are, and it can be very stressful, and I don't think we do enough other than, you know, a session at RSA, you know, once a year if someone says, Hey, here's why mental health is important in this field, to me that has to be a daily exercise. Absolutely. You know, there was a time, especially in the DevOps movement, Jeff, where Gene Kim was really highlighting burnout.
And he had, I forget her name actually, her and her husband are the two most, like foremost authorities on workplace burnout. And they, they come out of universities out of California and they were instrumental in having the, uh, the ocean folks recognize burnout as a valid medical condition. And, um, you know, quite frankly, it's not just security.
It's a lot of it. It's the constant cycle of, you know, stand and deliver, stand and deliver, stand and deliver. We're always on def con level five.
We're always, you know, uh, on a short timeframe, short budgets, high pressure, and, and people, you know, if you want to do this and stick around, you gotta learn to that. You know, we talk about work-life balance, and people stop. I don't know how we got onto to this anyway, Jeff, but work-life balance is important.
And, and, and people need to learn that if they wanna, you know, stick around and be successful, otherwise you will, you'll burn out and it'll lead you up alive. Yeah. Because yeah, you could read this report as, oh, look at all these incidents.
I don't know how I'm gonna be able to handle it. Or you could look at this report to say, here's all these incidents. Here are the ones that we manage.
Well, we just need to start doing that to a few more what you can and respond to the rest. Keep one foot in front of the other and keep moving forward, my friend. Yep.
Hey, we're about outta time for people who want to, uh, maybe download and get better, you know, deeper dive in on this report. Where can they go, Jeff? org, where you can just, Mm-Hmm.
Or you can just do a search on our name and you'll actually see a rotating banner that says, you know, here's a 2024 report. Or you can just go to resources and see the, the white paper report there. You can download it.
There's an infographic on it as well. Uh, we invite you to either submit questions, talk about either what you want to do to support it or, or become a member should you want to. All of all of that's on the table.
We'd love to engage with anyone that wants to look at this, use this report. We encourage everyone that when you write articles or do anything else or, or have a webinar, take data from the report. All we ask is that you cite us, but, but please use it.
It's there so that the public will know more about these trends on that, on digital identity security. I love it. Jeff, thank you so much for coming on.
It's always a pleasure to see you, my friend. You're looking great. Whatever you're doing, keep doing it and we'll, we'll see you soon, Alan.
Thank you very much. All righty. Jeff Re, executive director, the Identity Defined Security Alliance.
We'll be back here on Techstrong TV in just a moment.