Cisco’s latest report revealed a discrepancy between companies' sense of confidence and their actual level of preparedness. Jeetu Patel, executive VP and GM of security and collaboration at Cisco, warned of this “overconfidence” and the growing identity security challenges cited by organizations in the survey.
The 2024 Cybersecurity Readiness Index is based on a double-blinded survey of more than 8,000 business and cybersecurity leaders across 30 global markets.
It found only 3% of surveyed respondents stated their organizations have the mature level of readiness needed to be resilient against modern cybersecurity risks, with two-thirds falling into the beginner or formative stages of readiness. However, 80% of the respondents still feel moderately to very confident in their ability to defend against a cyberattack with their current infrastructure.
“This disparity between confidence and readiness suggests that companies may have misplaced confidence in their ability to navigate the threat landscape and may not be properly assessing the true scale of the challenges they face,” Cisco wrote in the report.
Patel echoed that overconfidence and under-preparedness is “never a good combination.”
The report evaluated readiness across five pillars: identity intelligence, network resilience, machine trustworthiness, cloud reinforcement and artificial intelligence (AI) fortification, comprised of 31 corresponding solutions and capabilities.
The importance of identity intelligencePatel highlighted identity intelligence emerged as a crucial area. “It’s actually very akin to the way that people are seeing the importance of identity increase … some people call it the new perimeter.”
“The question that people shouldn't be asking is ‘Can you log in,’ but should you be allowed to log in based on not just your identity, but your behavior associated with that identity, and the behavior of all the other identities that are integrally related with that user identity?”
“So identity should go way beyond the user to machine and service identity and application identity as we move forward,” he told SDxCentral.
Gaps in identity intelligenceCompounding the identity challenge, a mass majority (85%) of surveyed organizations said their employees access corporate platforms from unmanaged devices, with 43% of those spending 20% of their time regularly logging in from unmanaged devices. Additionally, 29% stated their employees hop between at least six networks weekly, according to Cisco’s report.
In addition, the index showed more than 82% of the organizations are in the formative or beginning identity intelligence maturity stages. Only 13% qualify as progressive and 5% as mature. Meanwhile, 36% of respondents ranked identity protection as their top cybersecurity challenge, up from 24% in 2023. It's no surprise then that 99% have implemented some form of identity management solution.
The most widely deployed identity security solutions are identity behavior analytics tools (54%), followed by continuous risk-based access analytics (50%), cross-context identity analytics and recommendations (48%), and real-time risk-based analytics (46%). Passwordless authentication and cross-context identity posture assessment trailed at 31% and 37% deployment, respectively.
For companies yet to implement such solutions, around half (51%) plan to within 12-24 months, representing an increase in the sense of urgency around deploying multiple identity management systems since last year, when 69% had no deployment plans, Cisco noted.
“I'm actually very encouraged by people who recognize that identity is an issue and that behavior is a core part of it,” Patel said. “It's not just about logging in, it is about making sure that you're able to track behavior on a continued basis.”
Identity and AI are core parts of a security platformHowever, many security platforms still lack robust identity intelligence capabilities, Patel said. “I think the key aspect is: Are you coordinating and correlating datasets from the user, applications, data, machine service [and] identity? And then seeing the behavior patterns across all of those? I think that is where there's work to be done and we're not quite where we need to be at.”
Cisco introduced its new Identity Intelligence product last month, aiming to bridge the gap between authentication and access, as well as feed identity intelligence into its security services and suites.
Patel argues identity and AI are the core parts of the fabric of a security platform.
The index found, on average, 90% of the surveyed companies said they are at least partially using AI in their various solutions to verify and secure identity. “AI is helping organizations deploy these identity management systems in a pretty big way,” he said.
Cisco EVP offers 3 recommendations for identity securityTo address the growing identity challenges, Patel outlined three key recommendations:
- Ensuring visibility enables comprehensive protection. “You have to have visibility. Without visibility, you cannot have security. You can only protect what you see,” Patel said.
- Enhancing authentication processes prevents unauthorized access. “You've got to make sure that only the right people get in,” especially guarding against social engineering attacks, he said. “You have to make sure that identity point of view is not just at the point of time of authentication, but beyond authentication; that you assess behavior across a multitude of different identities and correlate both reactively and proactively to be able to tell what's going on.”
- Continuously assess behaviors across all related user, application, machine and service identities. “The industry has looked at identity so far as they've always looked at identity — at a point in time of authentication,” Patel said. “In fact, what we should be doing is saying 'I'm going to let you in based on the verification that I need to make sure that I feel good that you're a trusted source. And then I'm going to have you prove to me every minute of every day that you're in fact behaving like a trusted source.'”
Comments