Security Leaders on Privileged Access Management: ‘We Can Do Better’

Information Security Media Group

New Survey Reveals Shortfalls in How Enterprises Protect Identities

In a survey conducted during the fall of 2015 by ISMG and sponsored by Hitachi ID Systems, more than 90 percent of security leaders say they are concerned about external and/or internal attackers gaining unauthorized access and compromising corporate networks.

Subtitled “How Well is Your Organization Protecting its Real Crown Jewels – Identities?” this study reviews how organizations are best managing privileged identities, as well as the true business impact of intrusions due to compromising external/internal privileged access.

More than 130 respondents from organizations across global regions and industry sectors have responded:

 

  • 47 percent believe that former employees, contractors or vendors are still familiar with their organization’s password change processes on shared accounts;
  • Only 42 percent have deployed a multi-factor authentication technology for high-risk or highly privileged users;
  • Only 40 percent have deployed automation to control access to shared, privileged accounts.

Idan Shoham, CTO of Hitachi ID Systems, says the message from survey respondents re: privileged access management is “We need to do better.”

“People stated that despite the fact they are doing OK compared to other organizations, they still are not satisfied with current processes referring to strong authentication, deactivating access, and access control automation,” Shoham says. “The survey clearly indicates that most enterprises need to significantly improve privileged access controls.”

Survey results are available in a webinar presentation [http://hitachi-id.com/cgi-bin/emaildoc?document=Web873-HitachiID.pptx ], as well as a PDF report [ http://hitachi-id.com/cgi-bin/emaildoc?document=ISMG-Hitachi-Privileged-Access-Management-120115.pdf ], both of which feature the full responses and expert analysis by Idan Shoham of Hitachi ID Systems.

 

About Hitachi ID Systems:

Hitachi ID Systems delivers access governance and identity administration solutions to organizations globally. Hitachi ID solutions are used by Fortune 500 companies to secure access to systems in the enterprise and in the cloud. To learn more about Hitachi ID Systems, visit http://Hitachi-ID.com/

About ISMG:

Information Security Media Group publishes InfoRiskToday, DataBreachToday, BankInfoSecurity, CUInfoSecurity, HealthcareInfoSecurity, GovInfoSecurity and CareersInfoSecurity. These digital media sites offer news, views, research and education on the top industry, security, regulatory and technology challenges facing information security leaders worldwide. Each site is guided by an advisory board of renowned thought-leaders from business, government and education.

ISMG’s suite of educational webinars offers hands-on training by knowledgeable practitioners and is available to individual and corporate subscribers.

ISMG’s custom research, including the Healthcare Information Security Today and Faces of Fraud surveys, as well as the new FireEye-sponsored 2015 Breach Impact Study, is routinely featured at leading industry events, such as RSA Conference and Infosecurity Europe. The company also offers exclusive events, which currently include the Fraud Summit series, Data Breach Prevention Summits, custom roundtables and roadshows.

Our Press Releases

Nullcon Anchors 16th Edition of Goa Conference Around AI Exploit Research and Discovery

Nullcon Goa 2026 Brings Real-Time AI Vulnerability Discovery to the Conference Floor, Benchmarked Against the OWASP LLM Top 10 Risk Framework Princeton, NJ – Nullcon, Asia’s leading hacker-first cybersecurity conference, returns for its 16th edition from February 28 to March 1 at BITS Pilani, Goa Campus, convening researchers, practitioners and security leaders to confront the […]

Nullcon 2026 Launches ‘Day Zero’ Forum, Connecting Exploit Research to C-Suite Strategy

C-suite and Policymakers Converge at Nullcon 2026 as Demand for Hands-on Trainings Increases Amid AI-Driven Risk Debates Princeton, NJ – Nullcon, Asia’s largest and longest-running hacking and cybersecurity conference and training, returns for its 16th edition with the debut of “Day Zero,” a new executive forum designed to connect exploit research and C-suite strategy and […]

Nullcon 2026 Introduces ‘Day Zero’ to Bridge Cybersecurity Research and Boardroom Cyber Strategy

Senior Government Officials, Enterprise CISOs and National Cyber Leaders to Convene at Nullcon Goa 2026’s Inaugural Leadership Forum Princeton, NJ – Nullcon, Asia’s largest hacking and cybersecurity conference, is expanding its 16th edition with the launch of Day Zero, an invite-only leadership forum scheduled for Feb. 27 at BITS Pilani, Goa Campus, ahead of the […]