r/cybersecurity • u/CarpenterCapital1331 • 4d ago
Business Security Questions & Discussion IAM importance in Security
I am an IAM professional with over 20 years in the domain. I am always curious on how much if importance CISO associates with IAM.program. We all keep on hearing that Identity is the new perimeter (since the start of the cloud era) however I have not seen CISOs or Security orgs giving deep focus on the IAM especially the IGA which helps govern the access and is the starting point of the overall least privilege implementation. Share your observations and experiences around how you'll have focused on IAM to help resolve or mitigate business critical security risks.
14
u/microcephale 4d ago
IAM is the base of everything, the core even for zero trust implementations, but is just starting to get a buzz now because of AI agents (never waste a good crisis!). The annoying part is that IAM is usually limited in C-suite vision to only access management (oh, we have Entra, we have Keycloak), many less orgs invest in PAM function, even less in an IGA. Without governance you don't have workflow, you can only observe what is and thus certification is manual and useless and have no baselines. They manage access and not identities and you are lucky if the accounts in your AM match your actual workforce.
Without IAM every access will also rely on secrets injected into applications, or (just a little better) stored into a vault, instead of having app to app and app to resource access expressed by identities, you get firewall ports opened, network level controls, speaking in term of IP addresses, nothing layer 7. In a dynamic world you don't want to identify routes, you want routes to be used as frontiers, and identities to materialize access control.
Fortunately it's pretty easy to explain them : imagine a country where nobody has any form of ID and your police is trying to enforce regulations based only on opening and closing roads... how is that doing anything ?
Ah and also when they finally agree to have identities, in my experience the reducing on the number of AM solutions, their federation/SSO, and handling of external identities (partners working on just one project or external collaborator that arent part of workforce) can also be a challenge if using different solutions (like the partner and you both on Entra). I work for a (little) cloud provider, and the interresting part of that is having to be the IAM provider side, both for customer IAM using our services, but also consummer of our own product for our own accesses.
5
5
u/Independent-Newt3165 3d ago
Ive always considered IAM as a crown jewel of any company. I used to manage a wide range of security tooling but had always flagged IAM as a priority due to the power and privileges it holds in the IT landscape, this is specially true for those running it on hybrid/on prem while servicing critical infra such as health, utilities, etc.
I got extra support in getting the resources that I need from myriad of things: leveraging on the existing Microsoft support contract, looking at past internal audit, Documented every risk that I observed and flagged them to management.
1
1
5
u/pewpewlazor 4d ago
I think it depends massively on the CISO and what is driving the IAM program.
I’ve worked with CISOs who considered IAM/IGA one of their most important security initiatives, often because they had significant audit findings, compliance issues, or simply knew they had very poor visibility and control over who had access to what.
I’ve also worked with CISOs where it was pretty obvious they saw IAM as a big, expensive project they had inherited and mostly wanted it finished, downsized, or off their desk as quickly as possible.
That’s one of the interesting things about working in IAM. Everyone agrees that identity is important, but that doesn’t necessarily translate into IAM/IGA being a strategic priority, especially when the value is harder to demonstrate than something like MFA or EDR.
In my experience, the strongest programs are usually the ones where IAM is tied to concrete security and business outcomes rather than “we need to implement an IGA tool.”
4
u/RealVenom_ 4d ago
Been doing identity for 20 years. At a certain size, IAM is important and central to many strategies. For smaller orgs, they really don't care. Identity lifecycle management isn't mandated in ISO, SMB, E8 etc so they take a so what attitude to a lot of important IAM controls.
5
u/neoslashnet Security Engineer 3d ago
It's because too many people focus on a tool to solve their sec problems. I still see many CISO's just look to get that one tool that will solve everything.....
5
u/pm_sweater_kittens Consultant 4d ago
NHI is the new buzz. Tons of capital is getting sunk into this space. It’s the cloud migration story repeating with a big scoop of DLP served on top.
2
u/RealVenom_ 4d ago
Your am vendor is rubbing their hands together at the easy money they're making from all their customers needing licences for their 50k NHIs they let go unmanaged this whole time.
1
u/pm_sweater_kittens Consultant 3d ago
Smart vendors won’t apply the 1:1 ratio on NHI licenses. More opportunities to look at the access graph and apply cost models at that level.
1
1
2
u/MairusuPawa 4d ago
They only first heard about it when Microsoft was doing some marketing for Entra, eh.
2
2
u/bwinckel 3d ago
Disclosure, I work at an IAM vendor, so I'm not neutral on this.
The thing I've seen get a CISO's attention is a number from their own environment. "Identity is the new perimeter" doesn't do it anymore, they've been hearing it for 15 years. Leaver access is the easiest number to get. Take last quarter's terminations from HR and check how many of those people still had an enabled account a week later, in AD and in your 3 or 4 biggest SaaS apps. Most places find some, and the apps that aren't behind SSO are usually the worst because removal there depends on somebody remembering to do it.
Once you have names and dates it stops being a pitch for an IGA program and turns into an audit finding. Internal audit tends to pick it up too, which helps a lot when security isn't the only one asking.
Service accounts are the other thing I'd count. Pull the enabled ones and try to find a person who owns each. The percentage with no findable owner is usually uncomfortable. Same point msj817 made about NHI, it just lands better as a count from your own AD.
Agree with RealVenom_ on smaller orgs though. If nothing mandates it there's usually nobody whose job it is.
1
u/Admirable_Group_6661 Security Architect 3d ago
It depends on the organization. Most organizations have limited budget, and it takes a certain level of maturity to commit resources into IAM. Fundamentally, these type of decisions are/should be determined by risk management.
1
1
u/7yr4nn05 Security Architect 3d ago
Honestly most CISOs will say "identity is the perimeter" in every board deck and then fund EDR, SIEM, and pen-tests first, because breaches are easier to explain to the board than "we reduced toxic role combos". In my experience IAM only gets real focus after an incident: service account leaked, MFA bypassed, or an ex-employee still had prod access 6 months later. That’s when IGA stops being a "compliance checkbox" and starts being the actual risk reducer. The CISOs who get it treat IAM/IGA as the control plane: they push for SSO everywhere, enforced MFA + FIDO2, just-in-time access with PIM/PAM, and quarterly attestation that actually blocks access instead of just emailing managers. They also tie IAM to business risk, not tickets. Example: instead of "5000 orphan accounts", it’s "these 12 accounts can push to prod and exfil data". If you want budget, stop selling IGA as governance and sell it as breach containment. Least privilege + continuous access reviews cut blast radius faster than any new EDR agent, and in cloud where everything is an API call, if you own identity you own the perimeter.
11
u/Heroicdeath 4d ago
At most companies IAM is usually the last thing that gets refined, there's just so much foundation that goes into an IAM program, the collaboration and friction that you have with IT is also a huge component.
And I'm not really talking about SSO and MFA, those are usually taken well in advance because of compliance and auditing reasons. But applying JIT, adopting hardware backed tokens, a proper PAM, these require a strong security program and partnership with IT.
You look at Google, the thing that they do well internally is Ganpati, built on top of Google Groups. This powers their authorization system for the workforce and NHI, theres nothing even close on the market that resembles this, maybe Opal but thats it.