Venafi study shows enterprises struggle to protect machine identities

Venafi study shows enterprises struggle to protect machine identities

A study carried out by Venafi has shown that 96% of IT security professionals believe machine identities are central to company security and viability, but few have capabilities to protect them

A study carried out by Venafi has shown that 96% of IT security professionals believe machine identities are central to company security and viability but few have capabilities to protect them.

 Venafi, the leading provider of machine identity protection, has announced the results of Securing the Enterprise With Machine Identity Protection, a June 2018 commissioned study conducted by Forrester Consulting on behalf of Venafi.

The study focused on enterprise machine identity protection challenges and included responses from 350 senior IT security professionals who are responsible for their organisations’ identity and access management from the US, UK, Germany, France and Australia.

Key findings from the study reveal that a total of 96% of companies believe that effective protection of machine and human identities are equally important to the long-term security and viability of their companies. However, 80% of respondents struggle with the delivery of important machine identity protection capabilities.

“It is shocking that so many companies don’t understand the importance of protecting their machine identities,” said Jeff Hudson, CEO of Venafi. “We spend billions of dollars protecting user names and passwords but almost nothing protecting the keys and certificates that machines use to identify and authenticate themselves. The number of machines on enterprise networks is skyrocketing and most organisations haven’t invested in the intelligence or automation necessary to protect these critical security assets. The bad guys know this, and they are targeting them because they are incredibly valuable assets across a wide range of cyberattacks.”

Additional findings from the study include:

  • Nearly half (47%) believe protecting machine identities and human identities will be equally important to their organisations over the next 12 to 24 months, while nearly as many (43%) think machine identity protection will be more important
  • A total of 70% admit they are tracking fewer than half of the most common types of machine identities found on their networks. When asked which specific machine identities they track:
    • Just 56% say cloud platform instance machine identities
    • Only 49% say mobile device machine identities
    • Only 49% say physical server machine identities
    • Only 29% say SSH keys
    • Only a quarter (25%) say machine identities of microservices and containers
  • A total of 61% say their biggest concern regarding poor machine identity protection management is internal data theft or loss

Managing user and machine identities and privileged access to business data and applications is an enormous undertaking that has serious security ramifications.

Traditionally, the focus for identity and access management (IAM) programs has been people-centric but recent increases in the number of machines on enterprise networks, shifts in technology and new computing capabilities have created a set of challenges that require increased focus on protecting machine identities.

From Securing the Enterprise With Machine Identity Protection, Forrester Consulting, June 2018: “Newer technologies, such as cloud and containerisation, have expanded the definition of machine to include a wide range of software that emulates physical machines.

“Furthermore, these technologies are spawning a tidal wave of new, rapidly changing machines on enterprise networks. To effectively manage and protect machine identities, organisations need: complete visibility of all machine identities across their networks; actionable intelligence about each machine identity; and the capabilities to effectively put that intelligence into action at machine speed and at scale.”

To read the complete study, visit venafi.com/forrester-whitepaper

 

 

Browse our latest issue

Intelligent CISO

View Magazine Archive