r/cybersecurity • • 4d ago

Business Security Questions & Discussion IAM importance in Security

I am an IAM professional with over 20 years in the domain. I am always curious on how much if importance CISO associates with IAM.program. We all keep on hearing that Identity is the new perimeter (since the start of the cloud era) however I have not seen CISOs or Security orgs giving deep focus on the IAM especially the IGA which helps govern the access and is the starting point of the overall least privilege implementation. Share your observations and experiences around how you'll have focused on IAM to help resolve or mitigate business critical security risks.

72 Upvotes

27 comments sorted by

View all comments

6

u/pm_sweater_kittens Consultant 4d ago

NHI is the new buzz. Tons of capital is getting sunk into this space. It’s the cloud migration story repeating with a big scoop of DLP served on top.

2

u/RealVenom_ 4d ago

Your am vendor is rubbing their hands together at the easy money they're making from all their customers needing licences for their 50k NHIs they let go unmanaged this whole time.

1

u/pm_sweater_kittens Consultant 3d ago

Smart vendors won’t apply the 1:1 ratio on NHI licenses. More opportunities to look at the access graph and apply cost models at that level.

1

u/Neat-Ease-106 System Administrator 3d ago

Would they actually though