<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/identity-and-access-management-iam" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Identity-and-access-management-iam ]]></title>
                <link>https://www.itpro.com/tag/identity-and-access-management</link>
        <description><![CDATA[ All the latest identity-and-access-management-iam content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 17 Jul 2026 08:13:20 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ AI agents could make living off the land attacks ‘much more dangerous’, says CrowdStrike Field CTO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/compromised-ai-agents-could-make-living-off-the-land-attacks-much-more-dangerous-says-crowdstrike-field-cto</link>
                                                                            <description>
                            <![CDATA[ Living off the land attacks are evolving rapidly as threat actors target agents with deep access to enterprise networks and sensitive data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iPBrXtxhoCgpJm7A7cdhb7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KnKTf5Bo5sPb7EpyetdbVn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 08:13:20 +0000</pubDate>                                                                                                                                <updated>Fri, 17 Jul 2026 15:18:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KnKTf5Bo5sPb7EpyetdbVn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image symbolizing living off the land attacks showing a faint skull symbol blending into computer source code.]]></media:description>                                                            <media:text><![CDATA[Concept image symbolizing living off the land attacks showing a faint skull symbol blending into computer source code.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image symbolizing living off the land attacks showing a faint skull symbol blending into computer source code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KnKTf5Bo5sPb7EpyetdbVn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-attacks/how-to-protect-your-business-from-living-off-the-land-attacks">Living off the land (LOTL) attacks</a> are a worst-case scenario for enterprises globally, with hackers lurking in networks, extracting sensitive data, and biding their time before wreaking havoc.</p><p>These attacks rely on <a href="https://www.itpro.com/security/cyber-attacks/cloudflare-warns-state-backed-hackers-are-weaponizing-legitimate-enterprise-ecosystems-as-living-off-the-land-attacks-surge">weaponizing the legitimate software and tools</a> used by enterprises, and they're by no means a new trend.</p><p><a href="https://www.bitdefender.com/en-us/business/campaign/2026-cybersecurity-assessment" target="_blank"><u>Research from Bitdefender</u></a>, for example, found 84% of major cyber attacks leverage these techniques, and security teams globally have developed an array of detection capabilities aimed at combatting the threat. </p><p>But the dangers posed by these methods could escalate with the <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-the-age-of-agentic-ai">arrival of AI agents</a>, according to Zeki Turedi, CrowdStrike's Field CTO for Europe. Speaking to <em>ITPro, </em>Turedi said the deep access given to agents across enterprise IT estates represents a huge threat if even just one were to be compromised or manipulated.</p><p>“Organizations are giving them [agents] full access. They're giving them full capabilities. They will have the full privilege of the human user,” he told <em>ITPro</em>. </p><p>Turedi pointed to previous LOTL techniques that involved compromising tools like PowerShell. While this gave users access to valuable data, the risk with agents is drastically higher given how they operate, and, crucially, where they can go within networks. </p><p>“They also have further reach across an enterprise,” he said. There’s only so much PowerShell can touch or manipulate or modify, but an agent theoretically can touch every single part of that organization's technology ecosystem and architecture.”</p><p>“This is where it makes it so much more dangerous.”</p><h2 id="living-off-the-land-attacks-are-evolving">Living off the land attacks are evolving</h2><p>Findings from CrowdStrike’s 2026 <a href="https://www.crowdstrike.com/en-us/global-threat-report/" target="_blank"><u><em>Global Threat Report</em></u></a> show these risks aren’t just theoretical, they’re now a reality, and the same logic with traditional LOTL attacks is being applied to agents. </p><p>Indeed, the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm has observed threat actors exploiting legitimate <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> at dozens of organizations globally. In these cases, AI systems such as chatbots and assistant were abused to <a href="https://www.itpro.com/security/crowdstrike-says-ai-is-officially-supercharging-cyber-attacks-average-breakout-times-hit-just-29-minutes-in-2025-65-percent-faster-than-in-2024-and-some-attacks-take-just-seconds">generate malicious commands</a> and steal sensitive data. </p><p>The goal here is often focused on credential theft for <a href="https://www.itpro.com/security/cyber-attacks/368116/cyber-criminals-are-spending-longer-inside-business-networks">initial access brokers</a>, attacks later down the line, and even cryptocurrency theft. All typical hallmarks of financially motivated cyber criminals. </p><p>LOTL attacks have also become a go-to method for highly sophisticated, state-sponsored threat actors. As <a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach"><em>ITPro </em>reported last year</a>, the infamous <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-norway-cyber-espionage-warning">Salt Typhoon</a> threat group laid low in compromised US National Guard networks for nearly a year, accessing sensitive military and law enforcement data. </p><p>It’s here where risks are even higher as government departments and public sector organizations begin exploring the use of agents. A recent <a href="https://www.mckinsey.com/industries/public-sector/our-insights/rewiring-public-sector">study from McKinsey</a>, for example, found agentic AI is emerging as a key focus area for public sector organizations in the US. </p><h2 id="keeping-up-with-hype-cycles">Keeping up with hype cycles</h2><p>Turedi told <em>ITPro </em>the focus on agents isn’t surprising given that threat actors will “follow the technology landscape that their victims are looking to invest in”. </p><p>“We've seen this time and time again. So previously, we saw as cloud got adopted, funnily enough, adversaries became very capable in cloud,” he noted. </p><p>“When organizations started to be more focused and store sensitive data in <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>applications, SaaS tools, guess what? We saw adversaries go after the SaaS applications.”</p><p>Turedi added that the pace of change within the generative and agentic AI space, combined with rapid adoption efforts, could create additional challenges moving forward. </p><p>Enterprises across a range of industries are diving headlong into the hype cycle, and threat actors are keen to capitalize on the confusion and lack of risk awareness with the technology. </p><p>“This is just a brand new technology landscape that organisations are investing in,” he commented. “And of course, the adversary is very, very aware that for multiple reasons this is a great opportunity.”</p><p>“There’s a lot of confusion,” Turedi added. “There’s a lot of lack of knowledge and expertise in this space.”</p><h2 id="an-identity-conundrum">An identity conundrum</h2><p>According to Turedi, a key concern surrounding ‘living of the AI land’ attacks, as CrowdStrike dubs them, is that many organizations lack the visibility or governance capabilities to adequately monitor what’s going on with these bots. </p><p>This has become a recurring talking point since the advent of agents. <a href="https://www.itpro.com/security/enterprises-are-adopting-agents-faster-than-they-can-secure-and-govern-them-experts-warn-its-a-disaster-waiting-to-happen"><u>Research from Ping Identity</u></a> in March this year specifically highlighted IT architecture visibility as a key concern for enterprises rolling out agents. </p><p>The sheer volume of agents is jarring for security teams, the study noted, but things are exacerbated by sub-agents, essentially creating chains of untraceable bots – an ideal target for stealthy threat actors. </p><p>Identity is another area of concern, Turedi noted, albeit one within a broader range of overlapping considerations for security teams. He noted that efforts to improve processes on this front are falling flat. </p><p>Many organizations are working with infrastructure or tools that were struggling to manage human identities in the first place. Adding agents into the mix further compounds the problem. </p><p>“The problem we see is that a lot of organizations are only starting to think about things like identity security or <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">IAM (identity and access management)</a> hygiene,” he said. “These are typically infrastructures and architectures that were not designed for modern human identity usage, never mind for the AI identity usage.”</p><p>With living off the land attacks, the whole advantage for the attacker is that they’re blending into IT environments. They’re using your tools and software and thrive on the confusion. With agents, Turedi said this adds further complexity in terms of identifying what actions are legitimate and potentially nefarious. </p><p>“It's actually quite difficult to figure out if it's AI usage on an identity layer,” he said. “Can you truly say that that's a human accessing the network versus that's an AI agent accessing the network on behalf of a human?”</p><p>A recent survey from the Cloud Security Alliance (CSA) raised similar concerns with regard to agent identity. More than two-thirds (68%) of respondents said they <a href="https://www.itpro.com/technology/artificial-intelligence/workers-cant-identify-work-produced-by-ai-agents-business-risks"><u>couldn’t accurately identify agent activity compared to human activity</u></a>. </p><p>Turedi said it’s crucial to have “data from multiple different domains” when it comes to monitoring agent activity, taking into account applications, endpoints, and broader network traffic and “marrying them together” for a clearer picture. </p><p>“You need to be looking at the identity layer, you need to be looking at the endpoint, you need to be looking at the application layer,” he said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effect ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/microsoft-entra-id-passkey-default-authentication-dealine-september-2026</link>
                                                                            <description>
                            <![CDATA[ The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kChEktaF69uzSFMWgbZ6bT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 10:39:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft’s Entra ID platform will now operate solely with passkeys as it looks to shift away from SMS and voice-based authentication practices. </p><p>The changes to the identity management platform, set to come into effect on 1 September 2026, will see passkeys established as the “default authentication experience” for users. </p><p>Microsoft urged customers to move to passkeys or alternative phishing-resistant methods before the changeover. </p><p>“As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multi-factor authentication, they’ll be prompted to register a passkey,” the company explained in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank"><u>blog post</u></a>. </p><p>There is a grace period, however, with voice and SMS-based authentication still being possible until 1 February 2027. After that deadline, Microsoft will retire telecom delivery for both authentication methods and no longer offer SMS and voice as a “native Microsoft Entra capability.”</p><p>For those organizations that still require SMS or voice-based authentication, there is the option to do so via the Microsoft Security Store, where administrators can find approved telecom partners to facilitate this need.</p><p>This may incur additional costs, however, with Microsoft warning: "Customers will be responsible for any associated telecom-related costs charged by the telecom partners."</p><h2 id="why-is-microsoft-moving-to-passkeys">Why is Microsoft moving to passkeys?</h2><p>According to Microsoft, the shift to passkeys is in response to  growing concerns over credential theft, <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, and <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attacks. </p><p>AI, the company added, has also prompted a rethink of identity security and a move away from “phishable methods” such as voice and SMS-based authentication. </p><p>“Authentication methods that use SMS or voice rely on shared secrets or channels that attackers increasingly intercept, phish, or manipulate,” Microsoft explained. </p><p>“The case for moving beyond SMS and voice is no longer just that attackers intercept or socially engineer these methods. The threat environment has changed in speed, scale, and sophistication.”</p><p>Microsoft said its Threat Intelligence division has observed a marked rise in AI-enabled phishing campaigns in recent months, with these methods reaching click-through rates as high as 54%. </p><p>That’s a stark contrast compared to the 12% click-through rates typically observed in traditional campaigns, highlighting the potency of this new wave of attacks. </p><p>Other tactics employed by threat actors, such as <a href="https://www.itpro.com/security/cyber-attacks/cisa-urges-organizations-to-adopt-passwordless-security-in-lapsusdollar-report">SIM swapping</a> and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA bypass techniques</a>, have also become “more accessible and repeatable”, Microsoft noted. </p><p>As <a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026"><u><em>ITPro </em></u><u>reported earlier this year</u></a>, AI-generated phishing campaigns have become a recurring concern for cybersecurity leaders. </p><p>Research from Kaseya suggested that AI phishing “became the baseline” for threat actors in 2025: 83% of phishing emails used AI in some capacity, while 40% of <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> attacks also fared similarly. </p><h2 id="why-passkeys">Why passkeys?</h2><p><a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>Passkeys</u></a> are touted as a more reliable and secure method of authentication, as they tie credentials to a specific device, such as a smartphone or laptop. This removes the need for interceptable codes. </p><p>Indeed, Microsoft noted that because they use public-key cryptography rather than “shared secrets”, this makes them phishing-resistant by design. </p><p>“They also provide a faster, simpler sign-in experience for users,” the company noted. </p><p>Microsoft isn’t alone in advising the shift to passkeys. Earlier this year, the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> urged enterprises and consumers alike to <a href="https://www.itpro.com/security/the-ncsc-says-its-time-to-switch-to-passkeys"><u>adopt passkeys to provide “stronger resilience” and ease-of-use</u></a>. </p><p>“We strongly advise all organizations to implement passkeys wherever possible to enhance security, provide users with faster, frictionless logins and to save significant costs on SMS authentication," NCSC CTO Ollie Whitehouse said at the time.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Barracuda strengthens identity security capabilities with Evo Security acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/barracuda-strengthens-identity-security-capabilities-with-evo-security-acquisition</link>
                                                                            <description>
                            <![CDATA[ The deal expands BarracudaONE with new identity and access management capabilities tailored to the needs of MSPs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8mFBbDbRaGXbqBZWvyS8dD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zMGVGzLkXVKouNxp3mejej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 14:27:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zMGVGzLkXVKouNxp3mejej-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Barracuda Networks pictured on a sign at the 12th hole prior to the start of the Barracuda Championship at Tahoe Mountain Club&#039;s Old Greenwood course.]]></media:description>                                                            <media:text><![CDATA[Logo of Barracuda Networks pictured on a sign at the 12th hole prior to the start of the Barracuda Championship at Tahoe Mountain Club&#039;s Old Greenwood course.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Barracuda Networks pictured on a sign at the 12th hole prior to the start of the Barracuda Championship at Tahoe Mountain Club&#039;s Old Greenwood course.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zMGVGzLkXVKouNxp3mejej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/business-strategy/barracuda-targets-channel-growth-with-partner-program-revamp">Barracuda Networks</a> has announced the acquisition of <a href="https://www.itpro.com/security/data-protection/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity and access management (IAM)</a> specialist Evo Security, in a move that will bring expanded capabilities to its BarracudaONE platform.</p><p>Founded in 2018, Texas-based Evo Security provides a platform that combines IAM capabilities with privileged access management (PAM) technology into a single, multi-tenant platform tailored to the needs of MSPs.</p><p>The acquisition will see the firm’s technology integrated into BarracudaONE, creating a unified offering that brings together access management, identity protection, and identity threat detection and response.</p><p>According to Barracuda, the expansion will provide partners with a single platform for delivering identity resilience while helping customers simplify identity security by reducing the need to manage multiple point solutions.</p><p>In an announcement, Barracuda CEO Rohit Ghai said combining Evo Security's technology with BarracudaONE will help customers stay ahead of identity-centric attacks as AI continues to reshape the threat landscape.</p><p>“In the agentic AI era, protecting both human and non-human identities is imperative for delivering cyber resilience,” he explained. “Existing enterprise identity solutions are complex, costly and fail to meet the needs of MSPs that must scale to securely manage millions of identities across thousands of customer environments.</p><p>“We are thrilled to combine Evo Security’s partner-first innovation with our vision of BarracudaONE and offer a complete, intelligent, easy, and open platform that closes this gap.”</p><p>According to the vendor, Evo Security’s integration into the BarracudaONE platform will provide partners with a unified identity security architecture that spans privileged access management, access control, identity protection, and identity threat detection and response.</p><p><a href="https://www.itpro.com/security/msps-grow-wary-over-supply-chain-security-threats">MSPs </a>will be able to manage customer identities from a single multi-tenant environment while enforcing authentication, access policies, identity protection, and identity threat detection.</p><h2 id="barracuda-builds-on-resilience-goals">Barracuda builds on resilience goals</h2><p>The acquisition also builds on Barracuda’s wider cyber resilience platform, which already includes solutions that cover email security, data protection, network security, cloud security, and managed extended detection and response (MXDR).</p><p>For customers, Barracuda said the expanded offering will deliver integrated identity security that is designed to be easier to deploy and manage than traditional enterprise identity platforms, while allowing organizations to retain their existing security infrastructure rather than replacing it.</p><p>Alongside the technology integration, Evo Security’s team has joined Barracuda as part of the acquisition and the vendor said it will continue to support Evo’s existing MSP customers as the platform continues to expand.</p><p>Commenting on the acquisition, Evo Security founder and CEO Michael Roth said joining Barracuda will enable the business to expand its identity-first approach to a wider global partner base.</p><p>“We built Evo Security to solve the identity challenges MSPs face every day,” he explained. “Joining Barracuda gives us the scale, reach and resources to accelerate that mission globally.</p><p>“Our identity‑first approach was designed from day one for MSP operations, and now, together with BarracudaONE, we can bring modern identity security, privileged access management and automation to far more partners and the customers they protect.”</p><p>Financial terms of the acquisition were not disclosed.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SaaS has a big identity problem ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/saas-has-a-big-identity-problem</link>
                                                                            <description>
                            <![CDATA[ With more guest access than licensed users, firms are being compromised through the trusted identities and collaboration tools they rely on every day ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">32VEKkRqiqTcyAqgozrPUZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 11:40:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:description>                                                            <media:text><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:text>
                                <media:title type="plain"><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Unmanaged <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>guest accounts are creating massive security liabilities for small and mid-sized businesses, new research has shown.</p><p>According to Kaseya’s 2026 <a href="https://www.kaseya.com/resource/saas-application-security-insights-2026/" target="_blank"><u><em>SaaS Security Report</em></u></a>, 69% of SaaS accounts have more guest access than licensed users, with persistent third-party access and externally shared data leaving small and mid-sized businesses open to attack.</p><p><a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">Gaps in multi-factor authentication (MFA)</a>, OAuth sprawl, and external file sharing are widening the SMB attack surface, the study noted. Indeed, threat actors are now abandoning perimeter attacks in favor of softer targets like identities, OAuth integrations, and collaboration workflows. </p><p>This, Kaseya noted, leaves a trust gap most small and mid-sized businesses can't even see, let alone close.</p><p>“Today’s AI-emboldened threat actors see one interconnected attack environment, whereas most organizations defend their infrastructure in pieces,” said Jim Lippie, chief product officer at Kaseya. </p><p>“The most resilient organizations will be those that embrace continuous monitoring, identity governance ,and automated response as foundational requirements.”</p><h2 id="ai-scramble-has-caused-oauth-chaos">AI scramble has caused OAuth chaos</h2><p>The rush to adopt AI has led to a sprawl of third-party OAuth integrations that use persistent tokens instead of credentials, and that risks granting attackers permanent data access even after password resets. </p><p>As a result, non-human service principal logins now account for one-fifth of critical security alerts. </p><p>At the same time, attackers are using AI-driven automation to instantly locate and exploit dormant guest accounts, moving faster than manual defenses can respond.</p><p>Legacy controls like geolocation blocks are also failing to help, as attackers route traffic through trusted cloud hosts and <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPNs</a>. </p><p>Outside North America, Kaseya found nearly half (44%) of unauthorized logins originated from trusted infrastructure and outsourced hubs.</p><p>India accounts for 14%, the Philippines 10%, Germany 7%, the UK 7% and the Netherlands 6%. </p><h2 id="hackers-are-exploit-saas-identity-gaps">Hackers are exploit SaaS identity gaps</h2><p>Once inside, attackers are able to exploit massive identity gaps, with 56% of accounts lacking active MFA and only 27% of SMBs enforcing it across the organization.</p><p>Meanwhile, researchers found data leakage is through the roof in productivity environments. In Microsoft 365, 45% of all shared files were sent outside the organization.</p><p>Companies are also failing to keep up with severe alerts. Last year, while 98.9% of security events monitored by SaaS Alerts were classified as low severity, organizations still faced more than 278 million medium- and critical-severity alerts requiring investigation.</p><p>Kaseya recommends transitioning from rigid perimeter defenses to active, identity-first governance frameworks. </p><p>"Bridging the modern trust gap requires businesses to move away from static event tracking and instead prioritize automated behavioral monitoring that can flag anomalous activity inside trusted accounts," the company said. </p><p>"By aggressively consolidating security stacks, enforcing organization-wide MFA and continuously auditing machine identities and external sharing permissions, SMBs can eliminate critical visibility silos and systematically neutralize attacker persistence before a breach occurs."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Most organizations are losing ground’: Identity security risks are skyrocketing, and enterprises can’t keep up ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/most-organizations-are-losing-ground-identity-security-risks-are-skyrocketing-and-enterprises-cant-keep-up</link>
                                                                            <description>
                            <![CDATA[ Most organizations are being hit at least once a year, and experts warn incidents are accelerating ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TxJUXxWW6vbESWvmeM2cV9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 May 2026 12:05:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprises have experienced a sharp increase in the number of identity-related breaches over the last year, according to two new studies. </p><p>According to new <a href="https://www.sophos.com/en-us/resources/report/the-state-of-identity-security-2026" target="_blank"><u>research from Sophos</u></a>, 71% of organizations suffered at least one identity-related breach across 2025, with organizations reporting an average of three separate incidents and 5% reporting six or more. </p><p>The main consequences of an identity-related breach are data theft (49%), ransomware (48%), and financial theft (47%), the study found. Indeed, two-thirds of ransomware attacks were carried out this way, with serious financial consequences. </p><p>Sophos noted that the mean recovery costs associated with ransomware attacks reached $1.64 million, with a median of $750,000. Nearly three-quarters (73%) of those affected faced costs of $250,000 or more.</p><p>“Identity has become the primary attack surface in modern <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>, and this data shows most organizations are losing ground,” said Ross McKerchar, chief information security officer at Sophos. </p><p>“The non-human identity problem is particularly urgent. AI agents are being granted privileges faster than security teams can track them, and organizations that fail to get ahead of this will find it an increasingly costly gap to close.”</p><h2 id="enterprises-have-a-visibility-problem">Enterprises have a visibility problem</h2><p>Visibility is a critical weakness, according to Sophos, with only a quarter of organizations continually monitoring for unusual login attempts, and more than half checking every three months or less. </p><p>Detection, meanwhile, is equally poor. Around 14% of breached organizations were unable to detect and stop their most significant identity attack before damage was done.</p><p>A key factor for many identity breach victims lay in compliance, according to the Sophos study. Among those that found compliance requirements challenging, 82.4% had suffered a breach – a full 14 percentage points higher than those with less difficulty with compliance.</p><h2 id="uk-firms-grappling-with-identity-security">UK firms grappling with identity security</h2><p>In the UK specifically, enterprises are contending with similar challenges. According to Palo Alto Networks' <a href="https://www.paloaltonetworks.com/idira/identity-security-landscape-report" target="_blank"><u><em>Identity Security Landscape Report 2026</em></u></a>, machine identities now outnumber humans 100 to one, creating serious identity security risks. </p><p>82% of organizations expect to see the number of machine identities rise over the next 12 months, the study noted, and 90% expect to see a sharp increase in AI identities.</p><p>More than one-third (34%) of AI agents and 37% of <a href="https://www.itpro.com/security/how-machine-identities-changing-cyber-defense">machine identities</a> have access to their organization’s data, which may include sensitive information such as financial records or high value systems. </p><p><a href="https://www.itpro.com/cloud/cloud-computing/what-palo-alto-networks-usd10bn-deal-with-google-cloud-means-for-customers">Palo Alto Networks</a> noted that only 51% of UK organizations are using behavioral monitoring for their autonomous AI agents.</p><p>Identity security has become a key focus – and pain point – for many enterprises since the advent of agentic AI. With agents given deep access to sensitive data sources, risks are amplified and the potential for data leakage is now a leading concern for IT and security leaders alike. </p><h2 id="fragmented-tools-create-blind-spots">Fragmented tools create blind spots</h2><p>Fragmented identity security systems and tools are also causing problems with regard to visibility, according to eight-in-ten UK firms. Respondents to Palo Alto Networks’ survey said disparate tools are impacting or delaying their ability to detect and respond to identity-related threats. </p><p>As a result, 83% of UK organizations have experienced an identity-related breach, while 74% have fallen victim to at least three in the last 12 months. </p><p>“The explosion of machine identities represents a fundamental shift in the enterprise attack surface. With AI-driven identities projected to continue accelerating in the next year, organizations are facing a reality where identity complexity is rapidly outpacing traditional security controls," said Rich Turner, Palo Alto Networks' senior vice president EMEA.</p><p>"The fact that 83% of organisations have suffered an identity-related breach in the UK - and 91% in EMEA more broadly - proves that as AI agents gain more access to sensitive data, security leaders must move beyond manual processes. To close the gap, organizations must embrace end-to-end automation and unified governance. Otherwise, the risks of expanding AI and machine identities will only continue to intensify.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Enterprises are adopting agents faster than they can secure and govern them – experts warn it’s a disaster waiting to happen ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprises-are-adopting-agents-faster-than-they-can-secure-and-govern-them-experts-warn-its-a-disaster-waiting-to-happen</link>
                                                                            <description>
                            <![CDATA[ Identity systems developed for human interaction fail to cope with the new demands ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZNS99FFXfZRPCT59whwfcf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PbaraXgyBf5cecgbD4TJLU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Apr 2026 11:22:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PbaraXgyBf5cecgbD4TJLU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration showing an AI agent side profile, depicted as a blue robot, with seven human faces in varying earthy metallic tones shown to the right.]]></media:description>                                                            <media:text><![CDATA[An illustration showing an AI agent side profile, depicted as a blue robot, with seven human faces in varying earthy metallic tones shown to the right.]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration showing an AI agent side profile, depicted as a blue robot, with seven human faces in varying earthy metallic tones shown to the right.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PbaraXgyBf5cecgbD4TJLU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The use of <a href="https://www.itpro.com/business/microsoft-expects-1-3-billion-ai-agents-to-be-in-operation-by-2028-heres-how-it-plans-to-get-them-working-together">AI agents</a> is spiralling out of control, as they're rushed into deployment more quickly than organizations can govern them.</p><p>According to new <a href="https://www.pingidentity.com/en/lp/4380-ai-agents-trusted-digital-workers.html" target="_blank"><u>research</u></a> from Ping Identity, identity systems originally designed for human interaction are now being pushed to operate continuously. </p><p>The firm warned this is placing huge strain on existing models while creating gaps in governance, visibility, and accountability at the point when decisions are executed.</p><p>"Enterprises are deploying autonomous AI faster than they can govern it,” warned Andre Durand, CEO and founder of Ping Identity. “Identity remains foundational, but in an agentic environment it must operate continuously. Control must be enforced at the moment an action occurs.”</p><p>Researchers noted that agents are creating a new class of identity risk in environments where they operate autonomously across enterprise systems. </p><p>By combining individually legitimate permissions in unintended ways, they can generate actions that bypass controls and that can't be fully traced or governed. </p><p>Some of the biggest challenges include a lack of visibility when it comes to delegation, along with sub-agent spawning, where agent chains become untraceable and break auditability. </p><p>Meanwhile, AI agents are bypassing human decision-makers in ways that aren't planned for in OAuth and OIDC models. </p><p>Other issues include context leakage across systems where there's no continuous re-evaluation of authorization, and new questions around permission inheritance, liability, and enforcement in agent-to-agent interactions.</p><h2 id="iam-strategies-need-overhauled">IAM strategies need overhauled</h2><p>Despite these risks, most <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity and access management (IAM)</a> approaches remain centered on human users and static access decisions, leaving organizations unprepared to govern autonomous systems.</p><p>“These trends reflect a broader shift in identity requirements,” said Martin Kuppinger, founder of KuppingerCole Analysts, which carried out the research. </p><p>“As autonomous agents become more prevalent, organizations will need to extend identity and authorization models to maintain control, accountability, and trust across increasingly dynamic environments.”</p><p>According to IBM’s <a href="https://www.ibm.com/reports/data-breach"><u>2025 Cost of a Data Breach</u></a> report, 13% of organizations have experienced AI-related security breaches, and 97% lack adequate access controls for AI systems.</p><p>The Ping Identity report echoes recent <a href="https://www.itpro.com/security/agent-identity-governance-cant-keeping-up-with-adoption-rates-and-its-creating-a-security-nightmare"><u>research</u></a> from SANS, which found that non‑human and <a href="https://www.itpro.com/security/agentic-ai-poses-major-challenge-for-security-professionals-says-palo-alto-networks-emea-ciso">AI identities</a> are multiplying faster than organizations can secure them. </p><p>More than three-quarters of organizations said they were seeing growth in the use of <a href="https://www.itpro.com/security/non-human-identities-are-we-sleepwalking-into-a-security-crisis"><u>non‑human identities (NHIs)</u></a> such as service accounts, API keys, automation bots, and workload identities - but that governance was failing to keep pace.</p><p>Of the three-quarters already using AI agents that require credentials, 5% of security leaders told the SANS researchers that they didn’t even know whether agentic AI was running in their environment or not.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Agent identity governance can't keep up with adoption rates – and it’s creating a security nightmare ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/agent-identity-governance-cant-keeping-up-with-adoption-rates-and-its-creating-a-security-nightmare</link>
                                                                            <description>
                            <![CDATA[ Enterprises are leaving high-privilege keys unchanged for months or years at a time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N82g7W3zaCU9k6GTFjUXbE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Apr 2026 11:37:17 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jul 2026 13:51:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Non‑human and AI identities are multiplying faster than organizations can secure them, new research warns, and giving AI systems real decision-making power is leaving them wide open to security risks. </p><p>More than three-quarters (76%) of organizations surveyed for the <a href="https://74n5c4m7.r.eu-west-1.awstrack.me/L0/https:%2F%2Fwww.sans.org%2Fwhite-papers%2F2026-state-of-identity-threats-defenses-survey-how-identity-became-new-security-perimeter/1/0102019d71116ab9-0e2e4dae-6da1-4aab-9fe6-4860e401928c-000000/cgcoun6YNpr6z75oux0W_OPocgU=473"><u>2026 </u><u><em>SANS Identity Threats & Defences Survey</em></u></a> reported growth in the use of non‑human identities (NHIs) such as service accounts, API keys, automation bots, and workload identities.</p><p>The number of identities has quietly doubled or tripled – not because firms have more employees, but because machine‑to‑machine processes now underpin core business operations.</p><p>Governance practices have failed to keep pace, however. Indeed, among the three-quarters of organizations that are already using AI agents that require credentials, 5% of security leaders don’t even know if agentic AI is running in their environment or not.</p><p>While credential rotation remains a basic defence against long-term compromise, 92% of organizations are failing to carry it out on a 90-day cycle, creating a “forever access” problem.</p><p>Meanwhile, 15% admit they don’t even know their machine credential rotation rate, and 59% rotate fewer than half of their NHI credentials quarterly.</p><p>The reason for this is often fear that changing machine credentials can break service accounts and lead to downtime, according to SANS. </p><p>This, the firm said, encourages teams to prioritize system availability over credential hygiene – leaving high-privilege keys unchanged for months or years.</p><h2 id="structural-identity-problems-are-growing">Structural identity problems are growing</h2><p>There's also a structural problem, according to SANS. Many organizations still rely on human‑centric processes, such as manual access reviews, ticket‑based provisioning, and periodic rotation. </p><p>Crucially, these processes don’t scale to environments with large volumes of continuously authenticating machine identities across cloud, <a href="https://www.itpro.com/software/development/ai-isnt-killing-devops-youre-just-using-it-wrong">DevOps</a>, and <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>systems. </p><p>While controls such as secrets vaults, automated rotation, and scoped least‑privilege access are increasingly being used, they need to be scaled to match the growth of NHIs.</p><h2 id="agentic-ai-identities-are-a-big-problem">Agentic AI identities are a big problem</h2><p>Agentic AI is creating a perilous situation for security teams, SANS warned. Nearly three-quarters (74%) of organizations are deploying AI systems that require credentials and access permissions to operate autonomously, often interacting directly with critical infrastructure and data.</p><p>Unlike traditional NHIs, which follow fixed logic, agents interpret instructions and can take unpredictable, non-deterministic actions. This effectively grants them privileged access across environments, with the potential to escalate errors or hallucinate actions.</p><p>Despite this though, no single safeguard – approvals, sandboxing, or audit trails – is used by more than 40% of organizations.</p><p>“Organizations are giving AI systems real decision‑making power faster than they’re building the governance to control it. We’ve already seen what happens when non‑human identities scale without guardrails, and agentic AI is moving even faster,” said Richard Greene, certified instructor at SANS Institute.</p><p>"The early signs of governance are encouraging – nearly four in ten organizations have now use human in-the-loop approvals for AI agent actions – but the real challenge is staying ahead of these systems as they shift from pilots to core operations."</p><p>Organizations are at least starting to cotton on to the threat, with <a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why"><u>recent research</u></a> from Okta revealing that 85% now view Identity and Access Management (IAM) as important to their security posture, up from 79% last year. </p><p>More than three-quarters (78%) of respondents said that controlling access and permissions for NHIs was their main security concern.</p><p>According to Cisco's 2026 <a href="https://www.itpro.com/security/privacy/ai-is-forcing-a-fundamental-shift-in-data-privacy-and-governance"><u><em>Data and Privacy Benchmark Study</em></u></a>, virtually all organizations are expanding privacy programs and governance frameworks, with AI the main reason for 90%. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Palo Alto Networks CEO hails ‘the end of identity silos’ as firm closes CyberArk acquisition  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/palo-alto-networks-ceo-hails-the-end-of-identity-silos-as-firm-closes-cyberark-acquisition</link>
                                                                            <description>
                            <![CDATA[ Palo Alto Networks' CEO Nikesh Arora says the $25bn CyberArk acquisition heralds "the end of identity silos" for customers, enabling them to supercharge privileged access management. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VpygXZLuvxfPWzicco5jij</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/72jVoq5CrK9ccrov93oj8Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Feb 2026 11:56:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/72jVoq5CrK9ccrov93oj8Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nikesh Arora, chairman and CEO of Palo Alto Networks, pictured at the VivaTech trade show at the Parc des Expositions de la Porte de Versailles on June 11, 2025, in Paris]]></media:description>                                                            <media:text><![CDATA[Nikesh Arora, chairman and CEO of Palo Alto Networks, pictured at the VivaTech trade show at the Parc des Expositions de la Porte de Versailles on June 11, 2025, in Paris]]></media:text>
                                <media:title type="plain"><![CDATA[Nikesh Arora, chairman and CEO of Palo Alto Networks, pictured at the VivaTech trade show at the Parc des Expositions de la Porte de Versailles on June 11, 2025, in Paris]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/72jVoq5CrK9ccrov93oj8Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Palo Alto Networks has completed its <a href="https://www.itpro.com/business/acquisition/palo-alto-networks-has-been-on-a-mission-to-become-a-huge-platform-player-in-the-security-market-the-cyberark-acquisition-might-take-it-to-the-next-level">$25 billion acquisition of CyberArk</a>, aiming to fill the gaps in its current offerings by incorporating identity security. </p><p>According to Palo Alto Networks, the deal will enable it to secure every identity across the enterprise - human, machine, and agentic - by adding CyberArk's AI-powered Identity Security Platform to its portfolio.</p><p>The platform applies intelligent privilege controls to every identity, offering continuous threat prevention, detection and response across the identity lifecycle, with tools covering areas such as <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">privileged access management (PAM)</a>, secure <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a>, and <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>.</p><p><a href="https://www.itpro.com/security/non-human-identities-are-we-sleepwalking-into-a-security-crisis">Machine identities now outnumber human identities</a> by more than 80 to one, the company noted, while three-quarters of organizations say their human identities are governed by outdated and overly permissive privilege models. </p><p>Attackers are increasingly exploiting identity weaknesses, making credential abuse and excessive privilege among the dominant threat vectors today. Nearly 90% of organizations have already suffered an identity-centric breach, research shows. </p><p>However, Palo Alto Networks said companies using identity-driven security controls can speed up their breach response by up to 80% by preventing attackers from abusing credentials and excessive access.</p><p>"The emerging wave of AI agents will require us to secure every identity — human, machine, and agent. This is why we moved decisively by announcing our intent to acquire CyberArk last July and am excited to have product integration begin," said Nikesh Arora, chairman and CEO of Palo Alto Networks. </p><p>"For our customers, this means the end of 'identity silos.' They can now manage privileged access across their entire <a href="https://www.itpro.com/hybrid-cloud/29668/what-is-hybrid-cloud">hybrid cloud</a> environment from the same company they trust for <a href="https://www.itpro.com/security/369418/information-security-vs-cyber-security-vs-network-security">network security</a> and security operations — to ensure they are secure in the <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>era."</p><h2 id="cyberark-integration-beckons">CyberArk integration beckons</h2><p>CyberArk's Identity Security solutions will still be available as a standalone platform, but the two firms are working to integrate CyberArk's capabilities into the Palo Alto Networks security ecosystem. </p><p>There'll be no disruption for existing customers, the duo claimed.</p><p>"This is a win-win: our customers gain access to the world's most comprehensive security portfolio, and our employees join a global innovation engine," said Matt Cohen, CEO of CyberArk. "Together, we are creating the most robust combination of proven technologies to stop identity-driven breaches."</p><p>Under the terms of the agreement, CyberArk shareholders will receive $45.00 in cash and 2.2005 shares of Palo Alto Networks common stock for each CyberArk ordinary share.</p><p>Following the deal, Palo Alto Networks plans to pursue a secondary listing on the Tel Aviv Stock Exchange, adopting the "CYBR" ticker. It will continue to be listed on the NASDAQ Global Select Market, trading under the "PANW" ticker. </p><p>The closure of the CyberArk deal follows the completion last month of Palo Alto Networks’ <a href="https://www.itpro.com/business/acquisition/palo-alto-networks-to-acquire-chronosphere-in-usd3-35bn-deal">$3.35 billion acquisition of Chronosphere</a>, a cloud-native observability provider.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CrowdStrike targets identity security gains with $740 million SGNL acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/crowdstrike-targets-identity-security-gains-with-usd740-million-sgnl-acquisition</link>
                                                                            <description>
                            <![CDATA[ The acquisition will expand CrowdStrike’s Falcon platform with new privilege and access capabilities to bolster agentic identity security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TDezkruHSwaR4XaNHBo9wQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BET2P3rGVJCL4qP6rpRF7D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 Jan 2026 11:53:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BET2P3rGVJCL4qP6rpRF7D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Crowdstrike booth during the RSA Conference in San Francisco, California, US, on Wednesday, April 26, 2023.]]></media:description>                                                            <media:text><![CDATA[The Crowdstrike booth during the RSA Conference in San Francisco, California, US, on Wednesday, April 26, 2023.]]></media:text>
                                <media:title type="plain"><![CDATA[The Crowdstrike booth during the RSA Conference in San Francisco, California, US, on Wednesday, April 26, 2023.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BET2P3rGVJCL4qP6rpRF7D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>giant CrowdStrike has signed a definitive agreement to acquire SGNL, a California-based startup specializing in <a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why">identity security</a>.</p><p>The proposed acquisition has been pegged at around $740 million and is expected to close during CrowdStrike’s first quarter of FY2027, subject to customary closing conditions.</p><p>The move will see SGNL’s dynamic Continuous Identity privilege and access capabilities integrated into the vendor’s Falcon platform to enable access for human, non-human (NHI), and AI identities to be continuously granted and revoked based on real-time risk.</p><p>In an announcement, George Kurtz, CEO and co-founder of CrowdStrike, said the speed and access at which AI agents operate make them a privileged identity that must be protected.</p><p>“With SGNL, CrowdStrike will deliver continuous, real-time access control that eliminates the known and unknown gaps from legacy standing privileges,” he explained. </p><p>“We’re disrupting the premise of modern privilege and access – for every identity, human or machine. This is identity security built for the AI era.”</p><h2 id="enhanced-identity-security">Enhanced identity security</h2><p>CrowdStrike’s Falcon Next-Gen Identity Security offering is designed to secure the full hybrid identity lifecycle, unifying initial access prevention, <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">privileged access management (PAM)</a>, identity threat detection and response (ITDR), SaaS identity security, and agentic identity protection.</p><p>SGNL operates as the runtime access enforcement layer between modern identity providers and the SaaS and hyperscaler resources. By integrating the technology into Falcon, SGNL will leverage the platform’s real-time intelligence and risk signals to continuously evaluate identity, device, and behaviour to control access as conditions change.</p><p>CrowdStrike said the addition of SGNL will eliminate standing privileges for humans, NHIs, and AI agents, as well as enable access enforcement across all major identity systems – extending Falcon Next-Gen Identity Security’s Just In Time access across major cloud identity and SaaS systems such as AWS IAM and Okta.</p><p>Continuous access evaluation protocol (CAEP)-driven driven enforcement will also be integrated into Falcon Fusion SOAR, adding the ability to revoke access beyond the identity provider to bolster protection against misconfiguration-driven breaches.</p><p>Additionally, SGNL will help unify hybrid identity security across on-premises, SaaS, and cloud environments, the vendor added. </p><p>Commenting on the company’s acquisition. SGNL’s CEO and co-founder, Scott Kriz, said the company was founded with the aim of connecting access decisions with ‘business reality’.</p><p>“The world needs our technology to eradicate the significant risk that legacy standing privileges expose in today and tomorrow’s environments,” he commented. </p><p>“Joining CrowdStrike provides us with global scale natively through cybersecurity’s leading platform to transform enterprise security with Continuous Identity, furthering CrowdStrike’s mission of stopping breaches.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ In the age of all-in-one platforms, how can partners avoid becoming interchangeable? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/in-the-age-of-all-in-one-platforms-how-can-partners-avoid-becoming-interchangeable</link>
                                                                            <description>
                            <![CDATA[ Complacency is the real problem, rather than platformization... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XsVYPsGdQxm4AeVKj364eR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ha5D2d4V5pYoYqemueYv5X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jan 2026 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Wilson ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/NtAZJEoEKLGvoKfBM57u9a.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ha5D2d4V5pYoYqemueYv5X-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of a laptop with a padlock to suggest endpoint security]]></media:description>                                                            <media:text><![CDATA[Graphic of a laptop with a padlock to suggest endpoint security]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of a laptop with a padlock to suggest endpoint security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ha5D2d4V5pYoYqemueYv5X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Platformization is accelerating across the enterprise tech stack. Enterprises are increasingly consolidating around major vendors, attracted by the simplicity of an all-in-one enterprise security offering.</p><p>It’s common to find companies operating all-in-one platforms, with security tools bundled into a license that feels easy and predictable to use. Convenience becomes the deciding factor. Even when they don’t cover every requirement, buyers often question why they should look beyond what is included. </p><p>For partners, however, this shift carries a clear risk. If everyone sells the same all-in-one stack, differentiation disappears, and channel contribution risks being reduced to transactional resale rather than the strategic guidance that is key to offering real value. </p><p>The long-term danger is obvious: partners become interchangeable. And interchangeable partners don’t win high-value projects, trusted advisor status, or long-term customer loyalty.</p><h2 id="why-convenience-can-create-hidden-risks-for-customers">Why convenience can create hidden risks for customers</h2><p>The biggest misconception of platformization is the idea that a platform-native deployment automatically means full security coverage. Enterprises often assume that if a capability is included in their license, it must be fit for purpose. However, in practice, many single-vendor platforms often sacrifice depth for scale, leaving critical areas underprotected. Segmentation, defense against lateral movement, and east–west visibility are frequent blind spots. </p><p><a href="https://www.illumio.com/resource-center/global-cloud-detection-and-response-report-2025"><u>In our latest research</u></a>, 90% of security leaders reported experiencing an incident involving lateral movement in the last year, despite high confidence in existing security tools. These gaps are part of why breaches continue to escalate, even in environments with strong firewalls, identity controls, and cloud security tools in place.</p><p>Organizations rarely see the problem themselves because visibility inside the network is limited. As a result, they are buoyed by a false sense of security, unaware of any holes in their coverage.  The tools give just enough visibility to create confidence, but not enough depth to reveal the full picture. Identifying and filling these gaps is precisely where partners can demonstrate real value.</p><p>The partners who win in this era will be the ones who shift the conversation from asking “What’s included in your license?” to “What risk are you trying to reduce?" That change elevates partners from transactional resellers to strategic advisors who identify blind spots, design resilient architectures, and guide customers toward decisions that genuinely reduce risk.</p><h2 id="integration-is-the-new-differentiation">Integration is the new differentiation</h2><p>As platformization gathers pace, differentiation increasingly depends on a partner’s ability to integrate, not simply resell. Customers may feel that a single vendor provides most of what they need, but a single-vendor platform strategy does not cover every use case or deliver the depth required to address modern threats. </p><p>Best-of-breed solutions still matter, especially in areas where all-in-one platforms were never designed to lead. Segmentation, lateral movement detection, and deep east–west visibility often require specialist capabilities that complement the platform rather than compete with it.</p><p>Partners who understand how these specialist capabilities interact with platform-native tooling can create architectures that customers cannot assemble alone. They bring together components that work in concert, forming an ecosystem rather than a collection of siloed features. That integration is where real value emerges. It delivers the convenience customers want but enhances it with the depth and precision that such platforms cannot provide on their own.</p><h2 id="building-services-around-platform-gaps">Building services around platform gaps</h2><p>To stay relevant as platformization accelerates, partners need to lead with services and outcomes rather than tools. Customers increasingly want guidance on how to address specific challenges like zero trust implementation or ransomware resilience, not just recommendations on what's bundled in their existing licenses. </p><p>For example, partners can elevate their offering with assessments that reveal what's actually happening inside the network. Most organizations lack clear sight lines into internal traffic flows, making it impossible to identify risks or measure improvement. An assessment that exposes these blind spots immediately demonstrates the value the platform doesn't deliver.</p><p>These findings can be followed up with an expanded service offering to design more resilient architectures that close these gaps. Now, the channel is positioned to help customers understand how specialist tools complement their existing investments, rather than replace them. </p><p>This could include, for example, demonstrating how network segmentation works alongside cloud security posture management, or how identity threat detection integrates with their existing identity and access management (IAM) platform.</p><p>Building alliances with specialist vendors strengthens this approach and allows partners to offer solutions that complement platform-native capabilities. By combining convenience with depth, partners demonstrate expertise that one platform alone cannot deliver, creating lasting differentiation.</p><p>Platformization is not the problem. The real issue is the complacency that comes from assuming built-in security covers every requirement. Customers need the convenience of consolidated platforms, but they also need depth in the areas that platforms overlook. </p><p>Partners who deliver both, through expertise, integration, and services, will stand apart.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud security teams are in turmoil as attack surfaces expand at an alarming rate ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/cloud-security-teams-are-in-turmoil-as-attack-surfaces-expand-at-an-alarming-rate</link>
                                                                            <description>
                            <![CDATA[ Cloud security teams are scrambling to keep pace with expanding attack surfaces, new research from Palo Alto Networks shows, largely due to the rapid adoption of enterprise AI solutions. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xmJiif6isjjMgPzHVjNpxf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aFQH4uPtxoHfmM2w5QiHV5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 08:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aFQH4uPtxoHfmM2w5QiHV5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Private cloud concept image showing a cloud symbol on a server box, with digital interface and bright colors below. ]]></media:description>                                                            <media:text><![CDATA[Private cloud concept image showing a cloud symbol on a server box, with digital interface and bright colors below. ]]></media:text>
                                <media:title type="plain"><![CDATA[Private cloud concept image showing a cloud symbol on a server box, with digital interface and bright colors below. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aFQH4uPtxoHfmM2w5QiHV5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/cloud/cloud-security/10-cloud-security-tips-every-it-leader-should-know">Cloud security</a> teams are scrambling to keep pace with expanding attack surfaces, new research shows, largely due to the rapid adoption of enterprise AI solutions. </p><p>In a <a href="https://www.paloaltonetworks.com/state-of-cloud-native-security" target="_blank"><u>survey</u></a> of more than 2,800 security executives and practitioners by Palo Alto Networks, 99% said they had experienced an attack against AI applications and services in the past year.</p><p>Meanwhile, the firm warned generative AI-assisted <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate">vibe coding</a> is in use by 99% of respondents - but is <a href="https://www.itpro.com/security/74-percent-of-companies-admit-insecure-code-caused-a-security-breach">generating insecure code</a> faster than security teams can review it. </p><p>Of the 52% of teams that ship code weekly, only 18% say they can keep up with fixing the vulnerabilities the technology creates.</p><p>“As organizations aggressively scale cloud investments to power AI initiatives, they are inadvertently opening the door to sophisticated new attack vectors," said Elad Koren, vice president of product management at the firm's Cortex security platform.</p><p>Notably, Palo Alto warned <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do">attacks are getting faster</a>, with breaches that took an average of 44 days in 2021 now taking as little as 25 minutes.</p><p>"The speed, scale, and sophistication we’ve observed over the past couple of years is incredible," said Haider Pasha, vice president and chief security officer, EMEA, at Palo Alto Networks. </p><p>Attackers are increasingly exploiting the foundational layers of the cloud, targeting API infrastructure, identity, and lateral network movement. API attacks, for example, are up by 41%, making them a primary entry point for sophisticated threats.</p><h2 id="the-top-challenges-for-cloud-security-teams">The top challenges for cloud security teams</h2><p>Meanwhile, 53% of respondents cited lenient <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity and access management (IAM) </a>practices as a top challenge, saying that insufficient access controls are now a leading vector for credential theft and data exfiltration.</p><p>These findings align closely with a recent study from Okta, which also highlighted growing concerns about identity security. </p><p><a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why"><u>An August survey</u></a> from the firm found 85% of security leaders now view IAM as a critical security focus, marking an increase on the year prior. </p><p>Elsewhere, long-running issues with <a href="https://www.itpro.com/security/cybersecurity-teams-are-wasting-time-money-and-effort-dealing-with-tool-sprawl-and-multi-vendor-ecosystems">tool sprawl</a> are adding insult to injury for cloud and security practitioners. Disparate tools are creating dangerous blind spots, the company noted, with respondents now managing an average of 17 cloud tools from an array of vendors. </p><p>The resulting fragmented data and context gaps are prompting 97% of respondents to prioritize consolidating their cloud security footprint.</p><h2 id="soc-teams-are-struggling">SOC teams are struggling</h2><p><a href="https://www.itpro.com/security/370276/soc-modernisation-and-and-the-role-of-xdr">Security operations center (SOC) staff</a> are also struggling amidst a surge in cloud-related attacks, Palo Alto found. A key factor here lies in disjointed workflows and isolated data sources between cloud and SOC teams, the study noted. </p><p>This lack of alignment is stalling remediation efforts, with nearly one-third (30%) of respondents revealing they take more than a full day to resolve an incident. </p><p>To cope, researchers said cloud and SOC teams must merge, with 89% of organizations believing cloud and application security must be fully integrated with the SOC to be effective.</p><p>"Our research confirms that traditional approaches to cloud security are inadequate, leaving security teams to fight machine-speed threats with fragmented tools and slow, manual fix cycles," said Koren. </p><p>"Teams need more than just dashboards highlighting risks they can never burn down; they must transform with an agentic-first platform that spans code to cloud to SOC to finally operate faster than the adversary.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Docusign boots Irish presence with €4.5 million Dublin investment  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/docusign-boots-irish-presence-with-eur4-5-million-dublin-investment</link>
                                                                            <description>
                            <![CDATA[ The electronic signature software company says the expansion of its R&D centre will strengthen its European AI and R&D capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TkipUxr8L9D8MUgPSA2SW6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nYTnSc9LsJFKbqT3jBfLr-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Dec 2025 08:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nYTnSc9LsJFKbqT3jBfLr-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand holding up a smartphone with Docusign logo and branding pictured on screen.]]></media:description>                                                            <media:text><![CDATA[Hand holding up a smartphone with Docusign logo and branding pictured on screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Hand holding up a smartphone with Docusign logo and branding pictured on screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nYTnSc9LsJFKbqT3jBfLr-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Docusign is expanding its AI Centre of Excellence in Dublin, saying it wants to accelerate local AI innovation and fuel growth across the EMEA region.</p><p>The €4.5 million (£3.9m) investment includes support from Ireland's Foreign Direct Investment Agency (IDA) - a non-commercial, semi-state body promoting foreign direct investment - and was welcomed by minister of enterprise, tourism, and employment, Peter Burke.</p><p> “I congratulate Docusign on ten successful years in Ireland and welcome their plans to expand their operations here,” he said.</p><p>Docusign said the move will strengthen its European R&D footprint, complementing its French R&D centre in Paris. As part of this expansion, the company said it also aims to increase its engineering team by 20%.</p><p>“Today’s announcement underscores our commitment to Ireland and the broader EMEA region,” said Allan Thygesen, CEO of Docusign. </p><p>“This significant investment in <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>supported by IDA is a testament to the incredible talent pool here and our unwavering focus on building intelligent agreement management solutions for our European customers. </p><p>“This is an opportunity to help Ireland realise its vision of boosting competitiveness and enabling a digitally empowered Europe through AI-led innovation.” </p><h2 id="docusign-eyes-talent-boosts">Docusign eyes talent boosts</h2><p>The company said the investment will help it keep pace with regulatory changes, with AI-powered innovation tailored for European regulatory environments, including advanced identity verification, contract analysis, and data privacy tools.</p><p>Similarly, the expansion will create new opportunities for Irish <a href="https://www.itpro.com/business/careers-and-training/how-leaders-can-uncover-hidden-tech-talent">tech talent</a>, supporting the country’s reputation as a leading destination for technology innovation through collaboration with the local and regional technology ecosystem.</p><p>“Docusign’s decision further establishes Ireland as a trusted European technology partner," said Michael Lohan, CEO of IDA Ireland. </p><p>"With a focus on AI that enhances trust, security and compliance, this investment will help drive <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> for businesses across Ireland and the wider region.” </p><p>Docusign was founded in 2003, with the electronic signature software company now having more than 1,000,000 paying customers and over a billion users worldwide.</p><p>Its <a href="https://www.itpro.com/business/business-strategy/docusign-doubles-down-on-iam-with-partner-program-evolution">IAM </a>platform has more than 350 prebuilt integrations with popular business apps, and its API enables embedding and connecting Docusign with customers’ websites, mobile apps, and custom workflows.</p><p>However, the investment follows a time of significant change for the company, with rounds of job cuts during 2023 and 2024, and pre-tax losses for the company's Irish arm increasing from €44.65 million to €127.5 million in the 12 months to the end of January 2023. </p><p>Revenues, meanwhile, dropped by 5% from €107 million to €102.6 million.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/business-strategy/proofpoint-targets-further-expansion-with-cork-investment-new-ai-innovation-center">Proofpoint targets further expansion with Cork investment, new AI innovation center</a></li><li><a href="https://www.itpro.com/infrastructure/data-centres/ireland-has-become-a-data-dumping-ground-for-big-tech">Ireland has become a “data dumping ground” for big tech</a></li><li><a href="https://www.itpro.com/business/business-strategy/uk-and-irish-businesses-severely-underestimating-the-cost-of-it-outages-with-millions-lost-per-hour">UK and Irish businesses "severely underestimating" the cost of IT outages</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft opens up Entra Agent ID preview with new AI features ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/microsoft-opens-up-entra-agent-id-preview-with-new-ai-features</link>
                                                                            <description>
                            <![CDATA[ Microsoft Entra Agent ID aims to help manage influx of AI agents using existing tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XyFFfuCnEbBDv42E2pU5GB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZumXBeY7CSrC287cDeWJWN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Nov 2025 16:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Nov 2025 20:02:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZumXBeY7CSrC287cDeWJWN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo and branding pictured at the company&#039;s vendor stall at Mobile World Congress (MWC) in Barcelona, Spain. ]]></media:description>                                                            <media:text><![CDATA[Microsoft logo and branding pictured at the company&#039;s vendor stall at Mobile World Congress (MWC) in Barcelona, Spain. ]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo and branding pictured at the company&#039;s vendor stall at Mobile World Congress (MWC) in Barcelona, Spain. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZumXBeY7CSrC287cDeWJWN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft says agentic AI has helped identity and network access teams spot more than 200% more missing baseline policies – so now it's widening the public preview of its Entra Agent ID to keep tabs on agents and other new risks to zero trust strategies. </p><p>Microsoft first unveiled a preview of Entra Agent ID in May, and Joy Chik, president of identity and network access at the tech giant, said it quickly became clear that few companies were aware how many agents were active in their environment. </p><p>"Before you can securely manage, protect, and govern this new type of identity, you need visibility," Chik said in a blogpost. </p><p>"Then you need the right controls, because agent sprawl can quickly lead to excessive permissions, orphaned accounts, and increased risk."</p><p>Chik cited a recent Microsoft study that found admins using its Conditional Access Optimization Agent in Microsoft Entra finished key tasks 43% faster and with 48% more accuracy. Alongside that, she reported a 204% improvement in spotting missing baseline policies.</p><h2 id="new-ai-tools-for-access">New AI tools for access</h2><p>Microsoft has now added new tools to its existing Entra solution, which manages identity and network access, to help manage and govern agents, secure access to AI resources for the workforce, and strengthen security via multi-layer access controls. </p><p>Chik added that the wider Microsoft Entra Suite is getting new <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>powered features. </p><p>"First, we’re expanding Microsoft Entra Internet Access to secure access to and usage of generative AI (GenAI) at the network level," she said. </p><p>"Our Secure Web Gateway (SWG) is now a Secure Web and AI Gateway. It allows you to secure, govern, and monitor access to any AI or agent from any provider, running on any platform."</p><h2 id="what-to-expect-with-entra-agent-id">What to expect with Entra Agent ID</h2><p>Entra Agent ID allows companies to use the same tools for workforce identification as it does for AI agents, Chik said. That includes maintaining an inventory of an agent fleet, regulating access to resources and data, and governing them via corporate policies. </p><p>"Lifecycle management and IT-defined guardrails, for both agents and the people who create and manage them, keep your agent fleet under control," she added.</p><p>The Public Preview of Entra Agent ID also now features AI-powered tools including prompt injection protection, network file filtering, and blocking unsanctioned access to <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-model-context-protocol-mcp">Model Context Protocols (MCP)</a>, which allow AI agents access. </p><p>Plus, Entra Agent ID now detects shadow AI, helping security teams spot unsanctioned AI tools and letting them monitor usage trends and block risky apps. </p><p>"With these controls, you can accelerate GenAI adoption while maintaining compliance and reducing risk, so employees can experiment with new AI tools safely," Chik added. </p><p>Beyond those tools, the public preview also includes user-centric access reviews, risk-based approval in entitlement management, threat intelligence and URL filtering, and guest access. </p><h2 id="safer-access-for-ai-agents">Safer access for AI agents</h2><p>Microsoft Entra Agent ID can also manage access to Microsoft Agent 365, the dashboard for AI agents unveiled at Microsoft's <em>Ignite </em>conference. </p><p>"It takes the same infrastructure that you trust to manage and secure your people and extends it to agents, equipping frontier organizations with leading Microsoft security, productivity, and collaboration solutions," Chik added. </p><p>The launch marks the latest in a string of product announcements at the tech giant’s annual conference in San Francisco, which naturally has had a sharp focus on <a href="https://www.itpro.com/technology/artificial-intelligence/the-tech-industry-is-becoming-swamped-with-agentic-ai-solutions-analysts-say-thats-a-serious-cause-for-concern">agentic AI</a>. </p><p>Microsoft introduced its own MCP Server for enterprise at the event. Entra can be used to manage access, with Agent ID handling authentication and least-privilege access controls. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-get-used-to-working-with-ai-powered-digital-colleagues">Microsoft: get used to working with AI-powered "digital colleagues"</a></li><li><a href="https://www.itpro.com/business/microsoft-expects-1-3-billion-ai-agents-to-be-in-operation-by-2028-heres-how-it-plans-to-get-them-working-together">Microsoft expects 1.3 billion AI agents to be in operation by 2028 – here’s how it plans to get them working together</a></li><li><a href="https://www.itpro.com/security/malware/microsoft-quietly-launched-an-ai-agent-that-can-reverse-engineer-and-detect-malware">Microsoft quietly launched an AI agent that can detect and reverse engineer malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts call for better 'offboarding' practices amid spate of insider attacks by outgoing staff ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-experts-weigh-in-on-offboarding-practices-after-former-intel-worker-stole-documents-before-changing-jobs</link>
                                                                            <description>
                            <![CDATA[ Enterprises should act swiftly to revoke rights and access, regardless of the manner of an employee’s departure. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">j728r8wZhF2Z6DzBncRUeU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D9hMCbGjYf4CodAQHnU9RR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Sep 2025 11:55:00 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Sep 2025 17:37:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D9hMCbGjYf4CodAQHnU9RR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Corporate espionage concept image showing laptop with storage boxes on screen while confidential files are pouring out.]]></media:description>                                                            <media:text><![CDATA[Corporate espionage concept image showing laptop with storage boxes on screen while confidential files are pouring out.]]></media:text>
                                <media:title type="plain"><![CDATA[Corporate espionage concept image showing laptop with storage boxes on screen while confidential files are pouring out.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D9hMCbGjYf4CodAQHnU9RR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Closer collaboration between security teams and HR professionals is needed to prevent outgoing workers from leaking sensitive company information, experts have told <em>ITPro</em>. </p><p>The warning over staff “offboarding” comes in the wake of several incidents where disgruntled employees have sabotaged their former employer or taken sensitive materials to a new job. </p><p>In July, a former Intel engineer who admitted taking trade secrets to a new role at Microsoft received two years’ probation and a fine of over $34,000 by an Oregon court.</p><div class="product"><a data-dimension112="177d76da-f9fa-482e-b518-cc5503c310f6" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="177d76da-f9fa-482e-b518-cc5503c310f6" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="177d76da-f9fa-482e-b518-cc5503c310f6" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Varun Gupta, who had served at the chip maker for over a decade, left in January 2020 but not before copying confidential files containing presentation decks and sensitive business data. </p><p><a href="https://www.oregonlive.com/business/2025/08/former-intel-engineer-sentenced-for-stealing-trade-secrets-for-microsoft.html" target="_blank"><u>Reports at the time</u></a> of Gupta’s sentencing show this included PowerPoint presentations outlining the company’s pricing strategies. </p><p>Speaking to <em>ITPro</em>, Josh Kirkwood, senior manager for CyberArk’s field technology office, said the incident once again highlights why offboarding has become a perilous process for enterprises. </p><p>“It’s all too common for departing employees to walk away with sensitive company information, whether intentionally or simply because access to systems and files isn’t revoked quickly enough,” he said. </p><p>“The offboarding process has long been a weak spot for many organizations. It’s clear that a shift is needed. Offboarding should not just be an afterthought,” Kirkwood added. </p><p>Damian Garcia, head of GRC consultancy at IT Governance, echoed Kirkwood’s comments, adding that incidents like these have become a recurring theme in recent years – especially amidst continued hybrid working practices. </p><p>“Just because someone is out of the building doesn’t mean they’re out of your systems. It doesn’t work like that anymore,” he told <em>ITPro</em>. </p><p>“As more businesses move to remote or hybrid setups, people have more ways to stay connected to systems they shouldn’t be anywhere near.”</p><p>Garcia warned that layoffs, internal tension, or even individuals feeling undervalued in their roles can “create situations where someone decides to act out”.</p><p>“Most employees won’t go down that path, but the small number who do can cause serious damage,” he said. </p><h2 id="unwanted-parting-gifts">Unwanted parting gifts</h2><p>There have been several recent examples of disgruntled employees – whether current or former – have caused havoc for businesses. </p><p>In June 2024, a former employee at Singaporean IT firm NCS was sentenced to two years and eight months in jail after he <a href="https://www.itpro.com/security/a-disgruntled-ex-employee-at-a-singaporean-it-firm-caused-carnage-after-deleting-over-180-servers"><u>deleted 180 virtual servers following his dismissal</u></a>. </p><p>More recently, a software developer was convicted after <a href="https://www.itpro.com/security/disgruntled-dev-malicious-code-insider-threat"><u>installing a “kill switch” in the corporate network of his employer</u></a>. </p><p>According to the US Department of Justice (DOJ), Davis Lu, formerly of power management firm Eaton Corp, conducted a long-running campaign of internal sabotage on the company’s networks, planting malicious code and targeting colleagues. </p><p>This incident severely disrupted Eaton Corp’s global IT systems, law enforcement said.</p><h2 id="what-can-be-done-to-prevent-disaster">What can be done to prevent disaster?</h2><p>Garcia told <em>ITPro</em> that enterprises need to act swiftly when employees are in the process of leaving, regardless of the manner of their departure. </p><p>“When someone leaves, especially on bad terms, there’s a short window where things can go very wrong,” he said. “That’s when you need to act fast: shut down access immediately, don’t leave it until after the weekend.”</p><p>This isn’t just a “box ticking exercise”, either, especially with technical staff such as system administrators or developers who have deep access to internal knowledge bases and critical files. Access rights should be revoked straight away, he added. </p><p>“If companies want to reduce the risk, communication between teams is non-negotiable,” Garcia added. “HR, IT, and security need to work together so that access is revoked immediately and consistently.”</p><p>Kirkwood added that this is where robust identity management processes are critical for businesses, enabling them to rapidly revoke rights and access.  </p><p>“The most effective way for enterprises to prevent adverse activity following an employee’s departure is by automating identity lifecycle management,” he said. </p><p>“That means ensuring access is automatically provisioned and deprovisioned according to instructions from HR systems.”</p><p>Shane Barney, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Keeper Security, noted that tools such as user and entity behaviour analytics (UEBA) can provide an “important additional layer of defence” by establishing baselines of “normal activity and flag anomalies that may signal malicious intent”. </p><p>“While UEBA can help organizations detect suspicious behaviour early, it’s most effective when used in tandem with identity-first controls such as <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a>, least-privilege access and <a href="https://www.itpro.com/business-strategy/risk-management/357883/leadership-compass-privileged-access-management">privileged access management (PAM)</a>,” Barney told <em>ITPro</em>. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/british-it-worker-jailed-for-revenge-attack-on-employer-that-caused-a-ripple-effect-of-disruption-for-colleagues-and-customers">British IT worker jailed for revenge attack on employer that caused a “ripple effect of disruption” for colleagues and customers</a></li><li><a href="https://www.itpro.com/security/ai-means-cyber-teams-are-rethinking-their-approach-to-insider-threats">AI means cyber teams are rethinking their approach to insider threats</a></li><li><a href="https://www.itpro.com/security/former-gchq-intern-risked-national-security-after-taking-home-top-secret-data">Former GCHQ intern risked national security after taking home top secret data</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Okta acquires Axiom Security to enhance privileged access management ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/okta-acquires-axiom-security-to-enhance-privileged-access-management</link>
                                                                            <description>
                            <![CDATA[ Axiom’s identity-centric PAM capabilities will be integrated into Okta’s Privilege Access platform over the coming months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a3PhFxcRpJ5ZM2VhSLyqxM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F7EKKYikUvVxifUDHSuWXV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Sep 2025 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F7EKKYikUvVxifUDHSuWXV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Okta logo and branding pictured on a smartphone screen placed on top of a laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Okta logo and branding pictured on a smartphone screen placed on top of a laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Okta logo and branding pictured on a smartphone screen placed on top of a laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F7EKKYikUvVxifUDHSuWXV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity security specialist Okta has announced it has signed a definitive agreement to acquire Israeli privileged access management (PAM) startup, Axiom Security.</p><p>The move will expand the Okta Privilege Access platform with Axiom’s PAM capabilities as the vendor looks to help customers further extend their security fabric.</p><p>Founded in 2021, Axiom Security provides a cloud-native, identity-centric PAM platform designed to assist organizations in eliminating standing privileges and secure access to critical infrastructure. The solution offers Just-In-Time (JIT) access, automated request and approval workflows, as well as user access reviews.</p><p>Terms of the deal were not disclosed but Okta said it expects the transaction to be completed in September, with Axiom’s capabilities to be integrated into its wider PAM offering “over the coming months.”</p><p>In an <a href="https://www.okta.com/newsroom/press-releases/okta-with-axiom-security--delivering-robust-privileged-access-fo/" target="_blank"><u>announcement</u></a>, Okta’s chief technology officer Abhi Sawant said the addition of Axiom will help solve more use cases through additional security controls and connectors to critical infrastructure resources such as databases and Kubernetes.</p><p>“Axiom’s technology will be integrated into Okta Privileged Access, expanding access controls to more sensitive resources that Okta customers can use to further strengthen their identity security fabric, so they can manage the types of privileged access across resources and use cases in their environment,” he explained.</p><h2 id="extended-identity-security">Extended identity security</h2><p>Post-integration, Okta Privileged Access will equip customers with a wider range of capabilities, including unified control through a single point of administration for privileged access across all privileged resources, whether on-premises or in the cloud. </p><p>Organizations will also be able to eliminate standing privileges and provide time-limited access thanks to Axiom’s Just-In-TIme (JIT) functionality. </p><p>By automating permissions for elevated access to environments such as <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a>, Snowflake, <a href="https://www.itpro.com/data-insights/data-management/358976/security-best-practices-for-postgresql">PostgreSQL</a>, and <a href="https://www.itpro.com/cloud/amazon-web-services-aws/358909/aws-introduces-fully-managed-fault-injection-simulator">Amazon EKS</a>, Okta said the addition will help reduce operational overhead and risks.</p><p>The integration also brings more connectors through <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>-based application connector builder capabilities, alongside secure access to <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes </a>and databases for least-privileged access and full traceability.</p><p>“As more enterprises bring AI into their workforces, privileged access controls are a key defense layer to properly mitigate AI-related risks,” Sawant added. </p><p>“This acquisition will help Okta customers extend their identity security fabric to more privileged accounts and resources, ensuring a single control plane for managing privileged access, whether on-prem or in the cloud.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/acquisition/advania-acquires-gompute-to-bolster-ai-and-hpc-capabilities">Advania acquires Gompute to bolster AI and HPC capabilities</a></li><li><a href="https://www.itpro.com/business/acquisition/cloud-software-group-snaps-up-data-management-provider-arctera">Cloud Software Group snaps up data management provider Arctera</a></li><li><a href="https://www.itpro.com/business/acquisition/workday-snaps-up-ai-powered-conversation-recruitment-platform-paradox">Workday snaps up AI-powered conversation recruitment platform</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber teams are struggling to keep up with a torrent of security alerts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-teams-are-struggling-to-keep-up-with-a-torrent-of-security-alerts</link>
                                                                            <description>
                            <![CDATA[ Fragmented identity security processes are creating blind spots, and the proliferation of tools doesn't help ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w67CHuohS7fZPgdYHH6NMg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MjQuGkdjCUFdoQkTyyZXsB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Aug 2025 07:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MjQuGkdjCUFdoQkTyyZXsB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person identity concept with fingerprint and code]]></media:description>                                                            <media:text><![CDATA[Person identity concept with fingerprint and code]]></media:text>
                                <media:title type="plain"><![CDATA[Person identity concept with fingerprint and code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MjQuGkdjCUFdoQkTyyZXsB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are taking 11 person-hours on average to investigate a single identity-related security alert, according to new research. </p><p>Analysis from <a href="https://goteleport.com/api/files/identity-security-at-a-crossroads-balancing-stability-agility-and-security/" target="_blank"><u>Enterprise Strategy Group</u></a> found security teams are facing significant challenges managing the volume of alerts, especially since the <a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">rise of agentic AI</a>. </p><p>In many organizations, meanwhile, its rapid adoption is outpacing organizational oversight and creating new attack vectors.  </p><p>Identity is already fragmented across cloud services, developer platforms, identity providers, and infrastructure resources such as databases, servers, Kubernetes and workloads. </p><p>All told, this fragmented ecosystem of platforms, tools, and solutions, is hampering response times and placing enterprises at huge risk, the report noted. </p><p>“When it only takes minutes for threat actors to move laterally across your infrastructure, 11 hours to investigate an identity-related incident simply isn’t good enough,” warned Ev Kontsevoy, CEO of Teleport, a sponsor of the research.</p><p>“As we move deeper into the age of <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, we must remember that AI dramatically lowers the cost of <a href="https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them">identity attacks</a>, and we must expect the frequency of them to increase. </p><p>"We must improve the trustworthiness of computing environments. We can only achieve this by eliminating anonymity and human error, and by unifying identity to simplify policy enforcement and enhance visibility of what each identity is doing.” </p><h2 id="credential-theft-is-surging">Credential theft is surging</h2><p>Things are made all the harder by the ease with which criminals can obtain valid static credentials such as passwords or API keys to impersonate identities. </p><p>According to the study, credential theft now accounts for one-in-five data breaches, with the number of compromised credentials having surged 160% in 2025 so far. </p><p>This fragmentation of identities is also reflected in the tools that enterprises use to manage them, with security teams using an average of 11 tools to trace identity-related security issues.</p><p>The reason is a complex mixture of cloud adoption, cyber insurance requirements and the need for separate tools for different environments, such as on-premises, cloud or SaaS, as well as customer security requirements, legacy tools, and industry compliance requirements.</p><p>“Few organizations understand the scale of the threat, let alone how quickly malicious actors can move laterally and disrupt systems," said Todd Thiemann, principal analyst at Enterprise Strategy Group. </p><p>"Each application expands a company’s security and compliance surface area, often faster than they can govern it, and few are easily integrated with identity tools."</p><p>"This leaves blind spots, orphaned accounts, inconsistent access privileges, and gaps in auditability, which significantly raises the risk of breaches and regulatory penalties," Thiemann added.</p><h2 id="identity-security-is-now-a-priority">Identity security is now a priority</h2><p>For most organizations, modernizing workforce identity security is a priority, with 91% saying it's a top-five concern.</p><p>As a result, budgets are growing year over year, with 87% of organizations reporting plans to increase their spending on workforce identity security, and more than one-third anticipating a significant rise.</p><p>According to Kontsevoy, the most efficient strategy lies in combining unified, cryptographic identity with just-in-time access. That’s how teams can more effectively minimize the attack surface.</p><p>“The blind spots created by complex IT aren’t just a danger to security. They’re bottlenecking the productivity of engineers and security professionals. They need a way to quickly answer vital questions," he said. </p><p>"Who accessed database X and with what permissions? Is this behavior unusual for the identity in question? What’s the full summary of what an identity did in a single session across platforms? To answer these questions, we need a different approach to cybersecurity, one that isn't based on secrets and siloed identities." </p><h2 id="shoring-up-defenses">Shoring up defenses</h2><p>The study from Enterprise Strategy Group comes amid a sharpened industry focus on identity security in recent months. </p><p>With businesses across a range of industries adopting agentic AI solutions, this poses serious challenges with regard to managing machine identities. </p><p>A <a href="https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why">recent study from Okta</a>, for example, found 85% of security leaders now view <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity and access management (IAM)</a> as a crucial part of their broader security posture, marking an increase compared to 79% in the year prior. </p><p>Similarly, 78% of respondents to the Okta survey said that controlling access and permissions for “non-human identities” now represents their main security concern, overtaking long-running focuses such as lifecycle management and network visibility. </p><p>Okta’s advice on this front centered largely around closer inter-departmental collaboration, urging enterprises to foster closer ties between AI project leaders with security practitioners. </p><p>In doing so, enterprises can still accelerate agentic AI projects, but mitigate future potential risks by accommodating security team concerns during the experimentation process.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">How to implement identity and access management effectively</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/enterprises-are-worried-about-agentic-ai-security-risks-gartner-says-the-answer-is-just-adding-more-ai-agents">Enterprises are worried about agentic AI security risks</a></li><li><a href="Identity management for beginners">Top identity management and security tips for beginners</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Identity security is more important than ever – here’s why  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/identity-security-is-more-important-than-ever-heres-why</link>
                                                                            <description>
                            <![CDATA[ 78% of enterprises told Okta that controlling access and permissions for non-human identities is now their main identity security concern. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tTgkbfeK27VQ3mQo7Csj6g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Aug 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Identity security concept image showing a fingerprint placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zY3UeEvLTfczgZYTQY6hh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are cottoning on to the importance of <a href="https://www.itpro.com/cloud/cloud-security/machine-identity-attacks-will-be-top-of-mind-for-security-leaders-in-2025">identity security</a> with the arrival of AI agents, new research shows. </p><p>According to a <a href="https://www.okta.com/en-gb/newsroom/articles/ai-at-work-2025--securing-the-ai-powered-workforce/" target="_blank"><u>survey</u></a> from Okta, 85% now view <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">Identity and Access Management (IAM)</a> as important to their security posture, up from 79% last year.</p><p>Managing AI agent identity is different from managing human user identities, Okta noted. </p><p>They lack accountability, have short, dynamic lifespans requiring rapid provisioning and de-provisioning, and rely on various non-human authentication methods like API tokens and cryptographic certificates.</p><p>Similarly, they need very specific and granular permissions for limited periods and can access privileged information, while often lacking traceable ownership and consistent logging, complicating post-breach audits and remediation.</p><p>As a result, 78% of survey respondents said that controlling access and permissions for non-human identities (NHIs) was their main NHI-related security concern, with 69% similarly worried about lifecycle management, 57% about poor visibility and 53% about remediating risky NHI accounts.</p><p> “I’m most concerned about AI systems having too much access without proper controls,” said one Australian C-level executive in healthcare and pharmaceuticals. </p><p>"If not carefully managed, they can expose sensitive data or be exploited for attacks. Strong oversight and access control are essential to keep AI secure.”</p><p>However, the study found only 10% of organizations have a well-developed strategy for managing NHIs. Fewer than a third (32%) said they always treat digital labor forces with the same degree of governance as human workforces, and only 36% currently have a centralized governance model for AI.</p><p>“We are missing a roadmap and are not aligned on how we as a group should implement AI. Some of the team are working as silos, so we do not yet have a cohesive approach to adopting AI.” said one retail VP in France.</p><h2 id="identity-security-needs-strict-guardrails">Identity security needs strict guardrails</h2><p>In terms of governance, Okta recommends involving AI project leaders, including data officers, data scientists, and line-of-business leaders.</p><p>Security, including visibility, access controls through the entire lifecycle and the ability to detect and respond to threats should be deeply embedded. </p><p>Enterprises are also advised to implement a secure-by-design approach, including user authentication, API access controls, asynchronous workflows, and authorization for <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-retrieval-augmented-generation-rag">Retrieval Augmented Generation (RAG)</a>. </p><p>"Treat your digital labor forces with the same degree of governance as human workforces,” Okta said.</p><p>“Just as contractors, consultants, vendors, partners, and other members of your extended workforce should be subject to the same strict IAM controls as your in-house workforce, so too should the NHIs operating within your IT environment."</p><p>The report comes as new <a href="https://www.silverfort.com/resources/identity-security-at-a-crossroads-esg-research/" target="_blank"><u>research</u></a> from Silverfort finds the use of NHIs is expected to grow by 29% over the next 12-to-18 months, with 87% of organizations planning to increase their spending on workforce identity security. </p><p>Two-thirds (67%) are either very concerned or concerned about the potential for damage relating to NHIs.</p><p>"The truth is, AI agents are not machines, nor are they human. They lie somewhere in between and therefore need to be treated as their own category of identity," said the firm.</p><p>"An AI agent security solution needs to address these concerns, so every <a href="https://www.itpro.com/technology/artificial-intelligence/ai-agent-announcements-are-a-dime-a-dozen-right-now-heres-what-oracle-thinks-its-doing-differently">AI agent</a> is tied to a human and has the proper policies in place to prevent (and detect) improper activity."  </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">How to implement identity and access management (IAM) effectively in your business</a></li><li><a href="https://www.itpro.com/cloud/cloud-security/machine-identity-attacks-will-be-top-of-mind-for-security-leaders-in-2025">Machine identity attacks will be top of mind for security leaders in 2025</a></li><li><a href="https://www.itpro.com/business/acquisition/palo-alto-networks-has-been-on-a-mission-to-become-a-huge-platform-player-in-the-security-market-the-cyberark-acquisition-might-take-it-to-the-next-level">Palo Alto Networks eyes identity security gains with huge CyberArk acquisition</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Okta and Palo Alto Networks are teaming up to ‘fight AI with AI’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/okta-and-palo-alto-networks-are-teaming-up-to-fight-ai-with-ai</link>
                                                                            <description>
                            <![CDATA[ The expanded partnership aims to help shore up identity security as attackers increasingly target user credentials ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">esBUyogwUbKbo3ZHGZPP4k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2WZnzTLX55czeRqpkNi363-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Jul 2025 11:32:26 +0000</pubDate>                                                                                                                                <updated>Fri, 18 Jul 2025 11:32:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2WZnzTLX55czeRqpkNi363-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LLM/AI jailbreaking concept image showing digitized human brain on mustard yellow background with pixelated parts of the brain flowing away.]]></media:description>                                                            <media:text><![CDATA[LLM/AI jailbreaking concept image showing digitized human brain on mustard yellow background with pixelated parts of the brain flowing away.]]></media:text>
                                <media:title type="plain"><![CDATA[LLM/AI jailbreaking concept image showing digitized human brain on mustard yellow background with pixelated parts of the brain flowing away.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2WZnzTLX55czeRqpkNi363-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Okta and Palo Alto Networks have announced an expanded partnership that aims to unify AI-driven security and deliver improved automated threat response.</p><p>The agreement sees the introduction of two new integrations, the first of which combines Okta Workforce Identity with Palo Alto Networks’ Prisma Access Browser to create a conditional access method that restricts access to SSO apps to the secure browser.</p><p>Identity Threat Protection with Okta AI is also being integrated with Palo Alto’s AI-powered Cortex SecOps platform, extending to Cortex XSIAM and Cortex XDR, to equip organizations with a unified view of identity risks across their entire attack surface.</p><p>As <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>continues to pose an increasing risk on user credentials, Stephen Lee, Okta’s VP of technology partnerships, said the integrations aim to help organizations incorporate identity into their infrastructure as part of a “fight AI with AI” approach.</p><p>"With Palo Alto Networks, Okta is proud to enhance the interoperability of our AI-powered platforms to prevent risks of <a href="https://www.itpro.com/business/business-strategy/engineering-firms-see-little-productivity-benefit-from-use-of-ai">siloed tools</a>, providing nearly 2000 joint customers with a comprehensive view of their security posture, context-aware access controls, and secure authentication to stay ahead of today’s threats," he explained.</p><h2 id="secure-access-threat-detection-gains">Secure access & threat detection gains</h2><p>By integrating Okta Workforce Identity with the Prisma Access Browser, enterprises can now implement an additional defense layer for web-based activity. </p><p>This, the duo explained, will enable employees to securely access corporate web applications and data through the browser regardless of whether a device is managed or non-managed.</p><p>Security teams will gain enhanced visibility and control over <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>and web application use, while users will benefit from a secure, consistent, and speedy browsing experience.</p><p>Additionally, the new integration between Okta and Palo Alto’s Cortex XSIAM and Cortex XDR offerings introduces additional authentication for risky access and user activity. </p><p>The combined capabilities tackle threats through automated responses such as revoking user access, ending active sessions, and quarantining of endpoints.</p><h2 id="fresh-commitments-to-security">Fresh commitments to security</h2><p>Okta and Palo Alto Networks said the new integrations reinforce their shared commitment to driving zero trust adoption while ensuring secure and seamless access for hybrid workforces. </p><p>Joint customers will benefit from a “clear, integrated path” to confidently secure operations while simultaneously reducing costs and complexity.</p><p>"Our deep integrations with Okta ensure that our solutions are engineered to work together, making it easier for our customers to achieve higher levels of security and user experience,” commented Pamela Cyr, Palo Alto Networks’ VP of technical partnerships.</p><p>“These new integrations, from securing application access with Prisma Access Browser to providing unified protection against identity threats through our Cortex platform, empower organizations with comprehensive, AI-driven defense."</p><h3 class="article-body__section" id="section-more-from-channelpro"><span>MORE FROM CHANNELPRO</span></h3><ul><li><a href="https://www.itpro.com/business/business-strategy/msps-are-burned-out-and-overworked-as-tool-sprawl-and-it-complexity-grows-but-theres-light-on-the-horizon">MSPs are burned out and overworked as tool sprawl and IT complexity grows</a></li><li><a href="https://www.itpro.com/hardware/brother-uk-revamps-inkjet-lineup-to-drive-partner-opportunities">Brother UK revamps inkjet lineup to drive partner opportunities</a></li><li><a href="https://www.itpro.com/business/effective-data-and-cleo-expand-partnership-to-drive-supply-chain-integration-capabilities">Effective Data and Cleo expand partnership to drive supply chain integration capabilities</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Docusign doubles down on IAM with partner program evolution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/docusign-doubles-down-on-iam-with-partner-program-evolution</link>
                                                                            <description>
                            <![CDATA[ The company's latest channel initiative introduces new specializations, tailored tracks, and go-to-market support for partners ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rv2C8yRF4A2SwSnqaypTfL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eCYwuTzFTNmdqJWhZ92hxN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Jun 2025 08:11:49 +0000</pubDate>                                                                                                                                <updated>Fri, 20 Jun 2025 17:55:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eCYwuTzFTNmdqJWhZ92hxN-1280-80.jpg">
                                                            <media:credit><![CDATA[Docusign]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Docusign building]]></media:description>                                                            <media:text><![CDATA[Docusign building]]></media:text>
                                <media:title type="plain"><![CDATA[Docusign building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eCYwuTzFTNmdqJWhZ92hxN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Docusign has unveiled the latest evolution of its UK partner program, which has been designed to help partners capture opportunities through its Intelligent Agreement Management (IAM) platform.</p><p>Powered by <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, Docusign&apos;s IAM platform underpins all of the company&apos;s solutions to help organizations create and manage agreements. Since its launch last June, more than 10,000 customers have adopted the platform and have gone on to process "tens of millions of agreements," the firm said.</p><p>With its revamped partner initiative, <a href="https://www.itpro.com/business-strategy/collaboration/363904/docusign-business-review">Docusign</a> is aiming to help partners better capture this burgeoning market opportunity through new specializations, tailored tracks, and advanced go-to-market support.</p><p>Docusign said the program recognizes the full spectrum of partner types – whether focused on eSignature, contract lifecycle management (CLM), or IAM – and offers support regardless of size and industry of the organizations they serve.</p><p>With the new framework, partners can work with the company through the new &apos;Sell&apos; specialization, which covers IAM Core, IAM for Sales, and IAM for customer experience (CX), or through &apos;Service and Sell&apos; for CLM.</p><p>Additionally, the program&apos;s three new tracks offer exclusive benefits designed to help guide partners along clear pathways.</p><p>The &apos;Build track extends the Docusign IAM platform with customer integrations designed to increase customer value, while the &apos;Sell&apos; track helps drive customer adoption of Docusign&apos;s IAM and CLM solutions in a "more strategic, consultive way," the firm said. The third track, &apos;Service&apos;, aids partners in the strategic deployment of the firm&apos;s solutions through product expertise.</p><p>Additionally, partners can also leverage Docusign University for comprehensive IAM training with new accreditations and certifications.</p><p>In an announcement, <a href="https://www.itpro.com/business-operations/business-management/358151/docusigns-new-service-leverages-text-messages-to-get">Docusign</a> said these changes reflect its commitment to positioning partners as trusted advisors, technical experts, and business growth accelerators for customers.</p><p>"This is more than a program refresh – it&apos;s an evolution that enables partners to play a bigger role in the customer journey," explained Bronwyn Hastings, Docusign&apos;s group vice president of partner development and alliances. "Partners are vital to capturing this massive IAM opportunity and we&apos;re focused on building a program that supports long-term customer success through partner expertise, trust, and services."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Global cybersecurity spending is set to rise 12% in 2025 – here are the industries ramping up investment ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/global-cybersecurity-spending-is-set-to-rise-12-percent-in-2025-here-are-the-industries-ramping-up-investment</link>
                                                                            <description>
                            <![CDATA[ Global cybersecurity spending is expected to surge this year, fueled by escalating state-sponsored threats and the rise of generative AI, according to new analysis from IDC. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f7V9ga3qP3c7fPJX84W965</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4hVyszSwmmNH7bSS2GMKGk-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Apr 2025 09:30:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4hVyszSwmmNH7bSS2GMKGk-1280-80.jpeg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Financial chart trending upwards ]]></media:description>                                                            <media:text><![CDATA[Financial chart trending upwards ]]></media:text>
                                <media:title type="plain"><![CDATA[Financial chart trending upwards ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4hVyszSwmmNH7bSS2GMKGk-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> spending is expected to surge this year, fueled by escalating state-sponsored threats and the rise of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a>, according to new analysis from IDC. </p><p>Statistics from the consultancy’s <a href="https://www.idc.com/getdoc.jsp?containerId=IDC_P33461&_gl=1*1gbbp2s*_up*MQ..*_ga*MTQ5OTQwOTQ5LjE3NDI1NDYwOTA.*_ga_541ENG1F9X*MTc0MjU0NjA4NC4xLjAuMTc0MjU0NjA4NC4wLjAuMA..*_ga_Y7CNRMFF6J*MTc0MjU0NjA4NS4xLjAuMTc0MjU0NjA4NS4wLjAuMA.."><u><em>Worldwide Security Spending Guide</em></u></a> show spending is expected to grow by 12.2% across the year and to hit $377 billion by 2028.</p><p>The bulk of this spending - 70% - will be in the US and Europe, the study found. But there's set to be an increase in every geographical region, in particular Latin America, Central and Eastern Europe, and the Middle East and Africa. </p><p>Eman Elshewy, senior research manager with IDC Data and Analytics, said rapid <a href="https://www.itpro.com/strategy/29899/three-reasons-why-digital-transformation-is-essential-for-business-growth">digital transformation</a> efforts and enthusiasm for emerging technology adoption have significantly pushed demand for security solutions - and this is expected to accelerate further.</p><p>"MEA is witnessing substantial investments from both government and enterprises to fight rising cyber threats, with strong awareness for the importance of <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">cybersecurity education</a> and training programs to fortify organizations against possible attacks."</p><h2 id="the-industries-spending-big-on-cybersecurity">The industries spending big on cybersecurity</h2><p>Banking, federal and central government, telecommunications, capital markets, and healthcare providers will be the biggest spenders this year. </p><p>Meanwhile, the fastest-growing sectors will be capital markets, media and entertainment and life sciences with an expected year-on-year growth rate of 19.4%, 17.1% and 16.9% respectively. </p><p>"The protection from cyber threats — now enhanced by <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>and GenAI — is becoming an increasingly strategic issue for organizations in all industries," said Stefano. </p><p>He cited in particular organizations managing critical infrastructure - for example, oil and gas or telecommunications - along with those developing critical assets such as aerospace, defense and life sciences, or those providing key services to clients and citizens such as banking or government.</p><p>“Although national and international regulations still play an important role in guiding organizations' security strategies — especially in regulated industries — more of them are realizing that having a proactive approach to security is crucial, not only as a short-term operational protection measure but also as a competitive advantage in the long term," he said.</p><p>While large and very large businesses account for most security spending across all regions, IDC small and medium-sized businesses will also continue to increase their investments in security throughout the forecast period.</p><p>More than half the cash will go on security software, with a 14.4% year-on-year growth rate. There's particular growth for <a href="https://www.itpro.com/cloud/cloud-security/surging-cnapp-investment-is-a-big-opportunity-for-the-channel">cloud native application protection platform (CNAPP)</a> solutions, for example. </p><p>Similarly, smaller enterprises are ramping up investment in <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity and access management (IAM)</a> software and security analytics software.</p><p>Security services will be the second fastest growing technology group in 2025, driven by the continuing expansion of managed security services, followed by security hardware, which IDC said will achieve single-digit but steady growth in 2025.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/cyber-attacks-against-uk-firms-dropped-by-10-percent-last-year-but-experts-say-dont-get-complacent">Cyber attacks against UK firms dropped by 10% last year, but experts say don't get complacent</a></li><li><a href="https://www.itpro.com/security/369523/how-to-reduce-cyber-security-costs-for-your-business">How to reduce cybersecurity costs for your business</a></li><li><a href="https://www.itpro.com/business/business-strategy/it-services-spending-is-set-to-surge-in-2025-as-cios-shift-to-ai-partner-solutions">IT services spending set to surge in 2025 as CIOs shift to AI partner solutions</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CyberArk eyes identity security gains with $175 million startup acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/cyberark-zilla-security-acquisition</link>
                                                                            <description>
                            <![CDATA[ CyberArk has announced the acquisition of identity governance and administration startup Zilla Security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6SeC7737dXALML4CXbsnYB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uyarqkD5tqTh8kLdb23rEN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Feb 2025 08:30:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Feb 2025 14:38:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uyarqkD5tqTh8kLdb23rEN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CyberArk logo and branding pictured on a smartphone screen placed on a desktop computer keyboard.]]></media:description>                                                            <media:text><![CDATA[CyberArk logo and branding pictured on a smartphone screen placed on a desktop computer keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[CyberArk logo and branding pictured on a smartphone screen placed on a desktop computer keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uyarqkD5tqTh8kLdb23rEN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/acquisition/cyberark-to-acquire-machine-identity-management-specialist-venafi-for-dollar154-billion">CyberArk</a> has announced the acquisition of identity governance and administration (IGA) startup Zilla Security for a fee of up to $175 million.</p><p>The move will expand CyberArk’s Identity Security Platform with Zilla’s AI-powered IGA capabilities, which are designed to equip organizations with scalable automation of identity compliance and provisioning across digital environments.</p><p>CyberArk said the aim is to create a “powerful, comprehensive <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity security</a> platform” capable of securing all identities - both human and machine - with the right level of privilege controls.</p><p>The agreement will see CyberArk pay $165 million in cash, rising by a further $10 million depending on the achievement of certain milestones, the company said.</p><p>In an announcement, CyberArk CEO Matt Cohen described modern IGA capabilities as “critical” for organizations as they navigate the “proliferation of privilege” in complex identity landscapes.</p><p>“By expanding the CyberArk Identity Security Platform with Zilla’s modern IGA capabilities, we will reshape identity governance with scalable automation that delivers compliance and helps maximize security for the modern enterprise,” he said. </p><p>“We’re delighted to welcome Zilla’s co-founders Deepak Taneja and Nitin Sonawane, along with their talented team, to CyberArk. Their experience and expertise in IGA are unparalleled and will be instrumental in helping us shape the future of modern IGA and identity security.”</p><h2 id="cyberark-targets-deeper-ai-integration">CyberArk targets deeper AI integration</h2><p>Leveraging <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>-powered role management, Zilla’s IGA platform automates identity compliance and provisioning processes to drive governance efficiencies and features integrations for both commonly-used and custom applications.</p><p>Now available as standalone offerings via CyberArk, the firm said customers will benefit from improved discovery and onboarding of all identities with context and risk mapping, alongside the ability to apply appropriate privilege controls across the board. </p><p>Users will also be able to take advantage of <a href="https://www.itpro.com/business-strategy/it-infrastructure/367875/best-it-infrastructure-management-services">automated lifecycle management</a>, policy, governance, and compliance.</p><p>Built primarily for <a href="https://www.itpro.com/cloud/cloud-computing/359904/on-premises-vs-cloud-which-is-better-for-your-business">on-premises environments</a>, legacy IGA solutions rely on manual processes, which typically result in slower, more time-consuming deployments. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZdYKofdJ3xJusKZZKEp4oa" name="Unlock Profitability with Cove Data Protection" caption="" alt="Unlock Profitability with Cove Data Protection" src="https://cdn.mos.cms.futurecdn.net/ZdYKofdJ3xJusKZZKEp4oa.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: N-Able)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/unlock-profitability-with-cove-data-protection"><em>An overview of the backup and disaster recovery landscape</em></a></p></div></div><p>In contrast, modern IGA offerings are purpose-built for the cloud, combining AI-powered business processes with out-of-the-box integrations for visibility across applications.</p><p>Zilla said customers experienced in implementing legacy IGA solutions reported that its capabilities can be deployed five times faster, complete access reviews 80% quicker, as well as facilitate a 60% reduction in service tickets.</p><p>“What worked 20 years ago clearly doesn’t work today,” explained Deepak Taneja, Zilla Zecurity’s CEO and co-founder. “Zilla represents a fundamental shift in how organizations can manage identity governance and administration. </p><p>“By harnessing the power of AI, we’ve automated IGA, making it simpler, faster, and more cost-effective. And now with CyberArk, we’ll be offering our breakthrough technology as part of the broader CyberArk Identity Security Platform, reaching many more customers on a global level.”</p><h3 class="article-body__section" id="section-more-from-channelpro"><span>MORE FROM CHANNELPRO</span></h3><ul><li><a href="https://www.itpro.com/business/digital-transformation/sharp-continues-european-it-services-push-with-latest-acquisition">Sharp continues European IT services push with latest acquisition</a></li><li><a href="https://www.itpro.com/business/acquisition/ibm-eyes-oracle-expertise-gains-with-latest-acquisition">IBM eyes Oracle expertise gains with latest acquisition</a></li><li><a href="https://www.itpro.com/business/acquisition/searchlight-cyber-snaps-up-assetnote-in-maiden-acquisition">Searchlight Cyber snaps up Assetnote in maiden acquisition</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ JumpCloud reveals nation-state hackers breached internal systems, following customer speculation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/jumpcloud-reveals-threat-actors-breached-internal-systems-following-customer-speculation</link>
                                                                            <description>
                            <![CDATA[ Suspicious activity was discovered in June, but a customer link took longer than a week to establish ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JQdnB7acESqQ8FQWCgNVCc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/urzkXUM92ynXRdk7bRPyje-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Jul 2023 10:23:05 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Jul 2023 12:07:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/urzkXUM92ynXRdk7bRPyje-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[JumpCloud: A CGI render of a glowing blue cloud, made of interconnected data points, hovering above a faint blue grid and surrounded by small padlocks. It is set against a black background.]]></media:description>                                                            <media:text><![CDATA[JumpCloud: A CGI render of a glowing blue cloud, made of interconnected data points, hovering above a faint blue grid and surrounded by small padlocks. It is set against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[JumpCloud: A CGI render of a glowing blue cloud, made of interconnected data points, hovering above a faint blue grid and surrounded by small padlocks. It is set against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/urzkXUM92ynXRdk7bRPyje-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity and access management firm JumpCloud has revealed its recent ‘security incident’ was an attack by a state-sponsored threat actor, which first accessed internal systems almost two weeks before customers were notified.</p><p>Affected customers are also believed to have been specifically targeted by the threat actor which JumpCloud said was “sophisticated… with advanced capabilities”.</p><p>The customers that were targeted during the attack have been receiving additional support from JumpCloud to shore up their cyber defenses.</p><p>JumpCloud stated that it has mitigated the vector used by the attacker, not revealing any further details related to it, and committed to sharing information related to the incident with industry partners and the US government.</p><p>It also released indicators of compromise (IoCs) for the attack, comprising malicious IPs and hashes, and urged firms to use the data for Endpoint Detection and Response (EDR).</p><p>“Our strongest line of defense is through information sharing and collaboration. That’s why it was important to us to share the details of this incident and help our partners to secure their own environments against this threat,” <a href="https://jumpcloud.com/blog/security-update-incident-details" target="_blank"><u>said</u></a> Bob Phan, CISO at JumpCloud. </p><p>“We will continue to enhance our own security measures to protect our customers from future threats and will work closely with our government and industry partners to share information related to this threat.”</p><h2 id="jumpcloud-x2019-s-security-incident-what-happened">JumpCloud’s security incident: What happened?</h2><p>On 5 July it was found that an attacker had accessed the commands framework for some JumpCloud customers via data injection.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dMvCeHeXAPfyZtAWyvaHzY" name="Busting nine myths about file-based threats_thumb.jfif.jpg" caption="" alt="Whitepaper cover with two colleagues at workstations with one wearing headphones and reading, and digital IT icons behind them" src="https://cdn.mos.cms.futurecdn.net/dMvCeHeXAPfyZtAWyvaHzY.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Busting nine myths about file-based threats</strong></p><p class="fancy-box__body-text"><em>Deciphering the assumptions and myths about file-based threats.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/busting-nine-myths-about-file-based-threats"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The discovery was made at 03:35 UTC, and at 23:11 UTC JumpCloud rotated all admin API keys. It notified customers that it had invalidated their API keys “out of an abundance of caution relating to an ongoing incident” without providing any further details.</p><p>The firm first discovered suspicious activity on an internal system on 27 June, which it linked <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>spear phishing</u></a> attack on 22 June, but JumpCloud stated that it saw no evidence of customer impact at that stage.</p><p>The company responded by rotating credentials, bringing in its <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>incident response</u></a> partner, contacting law enforcement, and securing infrastructure. It was through the resulting forensic investigation that the activity linked to customers was subsequently found.</p><p>"JumpCloud recently experienced a cyber security incident that impacted a small and specific set of our customers,” said a JumpCloud spokesperson at the time.</p><p>“Upon detecting the incident, we immediately took action based on our incident response plan to mitigate the threat, secure our network and perimeter, communicate with our customers, and engage law enforcement. </p><p>“As always, our entire JumpCloud team remains vigilant about new and emerging threats, and we are confident in our robust security controls and people. We continue to work with our customers and are committed to sharing information about this incident with government agencies and industry professionals. We appreciate our ongoing partnerships with all our customers."</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">@troyhunt this seems ominous from @JumpCloud pic.twitter.com/Pu0keIHqSK<a href="https://twitter.com/LeeFromNuZuland/status/1676739855454461952">July 5, 2023</a></p></blockquote><div class="see-more__filter"></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What are decentralized identities and are they viable for businesses? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/blockchain/what-are-decentralized-identities-and-are-they-viable-for-businesses</link>
                                                                            <description>
                            <![CDATA[ Decentralized identities aren’t new, but policies enabled through Web3 technologies make this methodology more realistic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7vq5jZ8bu9ZM4WDFhLBhpG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t3xNocTFupB3tscnaFE2Fe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jul 2023 08:13:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Blockchain]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t3xNocTFupB3tscnaFE2Fe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several digital avatars emerging from a digital fabric]]></media:description>                                                            <media:text><![CDATA[Several digital avatars emerging from a digital fabric]]></media:text>
                                <media:title type="plain"><![CDATA[Several digital avatars emerging from a digital fabric]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t3xNocTFupB3tscnaFE2Fe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Although organizations have considered decentralized identification for several years, it’s only recently become a viable solution for managing digital identities in a robust way. </p><p>There’s a spectrum of potential decentralized identification methodologies, ranging from self-sovereign identification – individuals control the information they use to prove who they are – to federated identity – linking an identity to multiple identity management systems. </p><p>At its core, decentralized identification is a potential mitigation strategy against the threat posed by a single central authority having access to personal data. Therefore, as organizations increasingly contend with privacy and security concerns, they’re increasingly exploring a decentralized alternative. </p><h2 id="what-are-the-flaws-with-centralized-identification">What are the flaws with centralized identification?</h2><p>By definition, identification data contain a vast amount of personal information, which could be foundational or functional. Foundational identities are those that have been assigned by a state, such as a birth certificate, passport, or identity card. Functional identity relates to the addition of other attributes, such as relationship status, employment status, and entitlement to various services.</p><div  class="fancy-box"><div class="fancy_box-title">What is identity management?</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yW2pt8cPC9eH6MpzHkbbY6" name="GettyImages-1387273760-min.jpg" caption="" alt="GettyImages-1387273760-cyber-eye" src="https://cdn.mos.cms.futurecdn.net/yW2pt8cPC9eH6MpzHkbbY6.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><em>The data that organizations create, collect and store is valuable, so protecting it from unauthorized access, either internally or externally, is essential. Identity management adds a layer of security by identifying individuals, and then authenticating and authorizing them to provide them with access to your company’s data systems.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">Read more</a></p></div></div><p>Uncontrolled access to functional identities can be particularly problematic, as it could potentially lead to inclusion or exclusion, or similar abuses. “When the allies left Afghanistan, a large <a href="https://www.itpro.com/cloud/367937/best-cloud-databases-in-2022">database</a> of Afghani citizens who had helped was unfortunately made available to the incoming government, which is very dangerous for those people,” explains professor Jon Crowcroft, researcher-at-large for the Turing Institute. “It explicitly attributes those people that had helped foreign governments.”</p><p>It’s worth noting a distributed system isn’t necessarily decentralized. In a distributed system, data is spread over various servers, but may be within a single, centralized, authority. A decentralized system is where multiple authorities and agencies manage the system collaboratively. Therefore, just because a system is distributed does not make it also decentralized. A classic example of a distributed but centralized system would be the NHS in the UK, where there’s a single body overseeing the different health trusts across the country.</p><p>Decentralized identification is a methodology dependent on the organizations involved having a shared approach to <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity management</u></a> and control. “It came out of Tim Berners Lee’s <a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3"><u>Web3</u></a> stuff.” adds Crowcroft. “I&apos;m not a big fan of <a href="https://www.itpro.com/security/28031/what-is-blockchain"><u>blockchain</u></a> and <a href="https://www.itpro.com/technology/blockchain/359266/what-are-nfts"><u>NFTs</u></a>, but agreeing on standard formats and protocols is really good. It&apos;s engineering detail, but it matters, as when people agree to those, then you can have a rapid deployment.”</p><p>With a decentralized model for identification, there’s no single agency with oversight – and access to – all of the personal data. There have already been instances where companies have been coerced by governments into handing over user data. “We&apos;ve seen this in the Snowden paper revelations when the US government would use secret courts to coerce companies that ran cloud services to reveal personal information,” says Crowcroft. </p><p>Having a decentralized model for an identification system means it’s much harder for third parties to access the information. Instead of there being a single agency to be coerced, bribed, or overcome, there are now several. Whilst it won’t prevent third parties from gaining access to the information entirely, it does make it that much harder.</p><h2 id="how-can-you-deploy-decentralized-identities-successfully">How can you deploy decentralized identities successfully?</h2><p>With the growing number of privatized government services, decentralized identification is becoming an increasingly viable methodology for preventing a single private organization from having oversight over a large identification system. Decentralized identification allows governments to deploy the identification model across multiple vendors. With the appropriate agreements in place, decentralized identification also allows cross-border information sharing between countries to be conducted in a transparent and controlled manner. </p><p>Although the decentralized identification model is inherently robust, it has a fundamental weakness in that there’s no single authority. For example, there’s no single point of contact for users who have lost or forgotten their passwords. It’s therefore incumbent upon users to have appropriate <a href="https://www.itpro.com/server-storage/backup/357713/how-good-is-your-backup-really"><u>backups</u></a> of their security keys, such as a one-time access code. </p><div  class="fancy-box"><div class="fancy_box-title">What are identity-based cyber attacks?</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fYUM6JWPRVgRkHVduyaHcB" name="hacker-identity-attack-GettyImages-1141229196.jpg" caption="" alt="The reflection of a hacker seen in a broken mirror to represent identity-based attacks" src="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><em>These attacks are an increasing weapon of choice the more we are increasingly reliant on identity-based authorization. Organizations are adding new layers of authentication, which, inevitably, hackers work to find ways through or around. In this cat-and-mouse game, identity-based attacks are on the rise, and organizations must implement several measures to defend themselves.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them">Read more</a></p></div></div><p>In order to be viable, too, there needs to be a stable internet infrastructure so the decentralized identification system can operate between multiple agencies. As such, it has typically been deployed in dense, technologically-educated regions.</p><p>In 2021, the Estonian government issued its digital identity card as a decentralized identification system. In this case, it was less concerned about coercive governments abusing data than malicious actors from hostile nation-states accessing it. Although the digital identification system has proven to be highly successful, Estonia is a small country with a population of almost 1.5 million people, approximately the same as the number of people who work for the NHS.</p><p>There also need to be redundancy measures in place for when internet connectivity is unreliable, such as in remote regions or when there is poor telecommunication infrastructure. This is akin to carrying a paper copy of an e-ticket for a train or concert in case a smartphone runs out of battery.</p><p>“If you were retiring to the Western Highlands, where internet access is patchy, you would still need to be able to prove ID,” says Crowcroft. “If the internet is down that day, you could show up with a credential that you had previously printed in case of an emergency – it’s like I always print my boarding pass because I’m paranoid about my phone breaking. That consideration should be there for things you depend on.”</p><p>Given the foundational nature of decentralized identification, it’s best used in projects that are just starting out. Also, given that a decentralized identification would be spread across multiple organizations, these systems are intended for managing large numbers of identities.</p><p>When identification management is decentralized, the risk of the data being misused is mitigated due to there no longer being a single point of authority to be attacked, bribed, or coerced. With the agreed formats and protocols established through Web3, decentralized identification could become an increasingly viable method for robustly managing identification systems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to manage a departing employee’s access to IT ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/identity-and-access-management-iam/354332/how-to-manage-a-departing-employees-access-to-it</link>
                                                                            <description>
                            <![CDATA[ We talk to experts in access rights, data removal and human resources to navigate this most tricky of passages ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h4shYdRYN5vXeqDJDUL4n7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ksUgVUWjRhA3DCdhagme8R-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Dec 2019 06:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 17 May 2024 15:06:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ nik@nikrawlinson.com (Nik Rawlinson) ]]></author>                    <dc:creator><![CDATA[ Nik Rawlinson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ &lt;p&gt;Nik Rawlinson is a journalist with over 20 years of experience writing for and editing some of the UK’s biggest technology magazines. He spent seven years as editor of MacUser magazine and has written for titles as diverse as Good Housekeeping, Men&#039;s Fitness, and PC Pro.&lt;/p&gt;
&lt;p&gt;Over the years Nik has written numerous reviews and guides for ITPro, particularly on Linux distros, Windows, and other operating systems. His expertise also includes best practices for cloud apps, communications systems, and migrating between software and services.&lt;/p&gt;
&lt;p&gt;Nik is also a prolific writer of books — both fact and fiction — almost all of which you can find on Amazon. In most cases, he produces not only the words and pictures but the layouts, too.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ksUgVUWjRhA3DCdhagme8R-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Access denied]]></media:description>                                                            <media:text><![CDATA[A laptop screen showing &amp;quot;access denied&amp;quot; text on a red background]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop screen showing &amp;quot;access denied&amp;quot; text on a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ksUgVUWjRhA3DCdhagme8R-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Jobs for life are a thing of the past. Staff turnover has never been higher, in part because it suits employers to structure contracts that way – but more often because there's a skills shortage. Staff are a valuable asset easily lured away by rivals.</p><p>And then what? Do you revoke their access, both physical and digital, to keep them away from your infrastructure and data, or should it be business as usual while they work out their notice? A decision like this can only be made if the organisation has a clear picture of what exactly the employee can access.</p><p>"You need a complete understanding of the company assets employees use from their first day," said Fredrik Forslund, one of the part founders of the Blancco Technology Group, whose eponymous product is used by businesses to safely wipe used kit for reuse or sale. "You need an asset management system that tracks the physical assets an employee's using, which can be simple to organise and incredibly helpful when reconciling assets following an employee's departure. Besides that, it's great to know all digital services used, which is easiest to achieve with single sign on. Simple tasks like changing passwords and logging out of online services is an important process that could protect your company from a potential data breach."</p><p>"An IT admin requires quick visibility into the scope of who has access to what within the organisation, including internal systems, cloud services and files," said Brandon Shopp, VP of product strategy for security, compliance, and tools at SolarWinds, whose access rights manager software helps IT managers understand what a departing staff member had access to, beyond simply their Active Directory account. "Doing this manually is a time-consuming exercise, so having a tool that audits and provides it to you is an important resource. Before the employee exits the organisation, IT admin should revoke access to any information they don't need to complete their final assignments. Having a product in place to help with this not only provides visibility, but also an audit of changes to your infrastructure to help understand who is making changes and what they are."</p><h3 class="article-body__section" id="section-why-where-and-when"><span>Why, where and when?</span></h3><p>It also depends on the circumstances under which the employee is leaving. Redundancy requires a period of consultation, during which restricting an employee's right to work – and access to resources – may leave an organisation open to legal repercussions. Should an employee voluntarily hand in their notice, however, the situation is somewhat different.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/33714/cyber-security-crisis-looms-as-72-of-professionals-consider-leaving-their-jobs" data-original-url="/security/33714/cyber-security-crisis-looms-as-72-of-professionals-consider-leaving-their-jobs">Cyber security crisis looms as 72% of professionals consider leaving their jobs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security" data-original-url="/cloud-security/34458/what-is-cloud-security">What is cloud security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/34560/trust-in-public-cloud-providers-security-is-increasing" data-original-url="/cloud-security/34560/trust-in-public-cloud-providers-security-is-increasing">Trust in public cloud providers’ security is increasing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy" data-original-url="/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">What is identity management and what role does it play in a security strategy?</a></p></div></div><p>"If the employee is leaving to go to a competitor, it's still the situation in most cases that once they've handed in their notice they'll probably be leaving that day, so won't continue to have access to the [company's] data – although that's a bit of an outdated concept, to be honest," Shaun Thomson, CEO of Sandler Training told us. "By the time someone puts their hand up and says they're leaving, if they want to take that data, they already have it. They'd be silly to wait until the day after they've handed in their notice."</p><p>Thomson says organisations should concern themselves with continuation of business at least as much as they think about the safety of their data and the hardware they have loaned an employee. Building multiple contact points for each client, effectively sharing internal data far and wide may, conversely, be the most effective solution.</p><h3 class="article-body__section" id="section-hardware-and-data-jurisdiction"><span>Hardware and data jurisdiction</span></h3><p>"Once the decision about letting someone go has been made, a collection date for assets should be set and when assets are collected, all data should be securely erased with an audit trail... before these assets are transferred to another user," Forslund said. "There should be zero risk for data leaks in between users in a situation like this."</p><p>Frequently, the distinction between corporate and personal hardware – and corporate and personal data – is blurred. BYOD can result in business-critical data residing on users' own devices, while personal emails may linger in a corporate inbox. Should employees be allowed to export their mailbox and take their contacts with them?</p><p>"Generally, no," said Forslund. "The personal emails must originate from some other service where access to emails should still exist and remain. If employees are allowed to export their inbox, all locally saved work emails will come along, which is not okay."</p><p>Shopp agrees. "Company email systems and the underlying data stored within belongs to the company, which makes it the company's discretion to allow the employee to extract any personal items such as contacts and emails before they leave."</p><p>It's therefore essential that guidelines for the acceptable use of email are written into staff members' contracts of employment, so that confusion – and conflict – can be avoided at the point of departure.</p><p>As Thomson points out, "when you employ people you're looking for certain things, which you're disdainful about when they leave. You expect them to come with contacts but don't want them to leave with any."</p><p>But contacts alone are less important than an established relationship once an organisation reaches a certain size.</p><p>"When we're working with our client companies, we apply an acid test: do your clients have a relationship with you or just one person in your company?" Thomson asked. "If it's the latter, when that individual moves the client is going to go wherever they go. As you grow – both your own company and a company you're dealing with externally – it's more about dealing organisation to organisation. We use Microsoft Dynamics as a CRM, but if our contact at Microsoft left that wouldn't change: we'd still be using Microsoft software. The bigger a company is, the less likelihood that the employee will be able to take business with them."</p><p>From a leadership point of view, then, and with succession planning in mind, only considering the risk to your data at the point an employee announces they're leaving is probably too late. Data can be used as an insurance by staff who feel their position to be under threat. By cultivating multiple touch points between your organisation and its clients, this policy will be less effective, and have a less detrimental effect in-house if it was ever deployed.</p><h3 class="article-body__section" id="section-you-39-re-fired"><span>You're fired!</span></h3><p>Special consideration needs to be given to staff leaving under a cloud, for whom you may wish to curtail access to mission-critical systems and sensitive data in short order.</p><p>In this case, SolarWinds' Security Event Manager "alerts you if someone is still trying to use an account once they've been locked out" said Shopp. "It gathers logs that can tell you why someone is trying to authenticate with the account that you've shut down. Is it an application that was installed while the person was still at the company, which you need to go in and shut down, or is somebody actually trying to do something that they shouldn't? Having visibility into that is something that every organisation should have."</p><p>As Thomson explained, though, each situation must be considered on its own merits. There's a wide choice of safeguards that companies can choose from, depending on their philosophy, size, and the kind of assets – both physical and data-based – they're dealing with. Key is understanding what staff have access to, and knowing what needs to be done as soon as it becomes clear their time with the business is drawing to a close. After all, the rate of staff turnover is unlikely to slow down any time soon, if ever.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is two-factor authentication? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29982/what-is-two-factor-authentication</link>
                                                                            <description>
                            <![CDATA[ Passwords aren't secure; it's time to add multi-factor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gQvfHS4mVm2Use6tZBEpjC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Wdn8Yytj7fHsU8qTd49YVh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Jun 2018 11:26:10 +0000</pubDate>                                                                                                                                <updated>Fri, 06 Sep 2024 15:27:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Nicholas Fearn ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Wdn8Yytj7fHsU8qTd49YVh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration of a laptop with a lock screen overlaid with a phone showing a tick symbol, to represent two-factor authentication (2FA) and multi-factor authentication (MFA). Decorative: the illustration is entirely rendered in black and white.]]></media:description>                                                            <media:text><![CDATA[An illustration of a laptop with a lock screen overlaid with a phone showing a tick symbol, to represent two-factor authentication (2FA) and multi-factor authentication (MFA). Decorative: the illustration is entirely rendered in black and white.]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration of a laptop with a lock screen overlaid with a phone showing a tick symbol, to represent two-factor authentication (2FA) and multi-factor authentication (MFA). Decorative: the illustration is entirely rendered in black and white.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Wdn8Yytj7fHsU8qTd49YVh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybercrime is arguably the biggest threat affecting modern businesses. Half of British companies have experienced a cybersecurity incident over the past year, with large (74%) and medium (70%) firms being the most affected. </p><p>That’s according to the<a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024/cyber-security-breaches-survey-2024#:~:text=Half%20of%20businesses%20(50%25),in%20annual%20income%20(66%25)." target="_blank"><u> 2024 Cyber Security Breaches Survey</u></a> from the UK Government, which also found that <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attacks, email and online impersonation, and malware are the biggest cybersecurity threats faced by UK firms.</p><p>Two-factor authentication (2FA) adds an extra barrier of entry for any third party attempting to access your account.</p><p>Requiring users to complete a second round of authentication after entering a password, whether by entering a code sent via text message or email or by using an authenticator app, adds a far more robust protective layer. While it may seem arduous to jump through these hoops, the benefits of having them in place are untold.</p><h2 class="article-body__section" id="section-what-is-the-difference-between-2fa-and-mfa"><span>What is the difference between 2FA and MFA?</span></h2><p>Two-factor authentication (2FA) is a form of multi-factor authentication (MFA) designed to add an additional layer of security to online accounts, services, and apps. It requires users to prove their identity using two forms of authentication, the first of which is a combination of a username and a password. </p><p><a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">Passwords are often stolen by hackers</a> and 2FA aims to solve this by forcing anyone attempting to access an online account or service to confirm their identity via a second form of authentication. </p><p>Common examples include one-time passwords, push notifications, <a href="https://www.itpro.com/security/29705/what-are-biometrics">biometrics</a>, physical security keys, or codes generated by authentication apps. The premise is that only users will know or have access to this information, preventing unauthorized parties from accessing their accounts using breaches or <a href="https://www.itpro.com/security/data-breaches/a-treasure-trove-for-adversaries-10-billion-stolen-passwords-have-been-shared-online-in-the-biggest-data-leak-of-all-time">leaked passwords</a>. </p><p>Although 2FA falls under the MFA umbrella, it wouldn’t be accurate to use the former to describe the latter. The main difference between the two is that while 2FA only uses two forms of authentication, MFA relies on two or more methods for verifying user identities.</p><p>For instance, a user with MFA set up on their account could be asked to first complete a one-time password request after logging in with their username and password, then an additional form of authentication like a fingerprint. Only after passing these stages would they be able to access their account. </p><h2 class="article-body__section" id="section-how-does-two-factor-authentication-work"><span>How does two-factor authentication work?</span></h2><p>Two-factor authentication invariably uses a second, independent device that functions as a buffer between the service and the login attempt.</p><p>Some services will supply their own keys, although this has become less common as companies have turned to developing their own smartphone apps or making use of SMS messages. Regardless of whether it's a number-generating key or a confirmation message, the idea is that only the owner of the device will have access to the key and the ability to authorize the login attempt.</p><p>The additional security check normally appears after the user has submitted their username and password. Once the system checks that the account exists, it will then ask the user to perform an additional action.</p><p>Two-factor authentication has become ubiquitous with most online services that involve sensitive data, whether it’s banking or financial services, e-commerce, or <a href="https://www.itpro.com/security/two-factor-authentication-2fa/357071/zoom-rolls-out-two-factor-authentication">business applications</a> – although many other companies are starting to offer 2FA to stand out from the competition.</p><p>How that additional layer appears can vary from service to service. For example, most banks now have their own security tokens for online banking, often in the form of random number generators and usually offered through a smartphone application, although some users may still be using a physical fob. Many online services have now forced users to set up 2FA as a minimum, <a href="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication">including Google</a> and <a href="https://www.itpro.com/security/two-factor-authentication-2fa/361731/meta-makes-2fa-mandatory-for-high-risk-users">Meta</a> though the latter only has this requirement for 'high risk' accounts.</p><p>Getting through a second layer of security can be the slowest part of signing into a service but it's an effective way of sifting out those trying to brute force their way into an account.</p><h2 class="article-body__section" id="section-what-are-the-benefits-of-2fa"><span>What are the benefits of 2FA?</span></h2><p>The biggest benefit of 2FA is preventing cyber criminals from breaching online accounts using passwords they've stolen or found in leaked databases on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>. But there are other reasons why you should use this security feature. </p><p>2FA can help tackle password fatigue, the feelings of tiredness associated with having to constantly remember and enter myriad passwords. It means you can choose an easy-to-remember password with the peace of mind that your account will be secured by a second authentication method.</p><p>Security leaders have less cause to worry about account breaches if they have a good 2FA policy in place, in the knowledge that cybercriminals have that extra barrier to entry. Adopting features like 2FA is also key to developing a <a href="https://www.itpro.com/security/encouraging-a-security-first-mindset">security-first mindset</a> — paramount as the <a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape">threat landscape worsens</a>. </p><p><a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches">Remote workers are still difficult for security teams</a><a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches"></a> to support, as their devices and corporate access need to be properly configured with 2FA or MFA, but this step is essential for protecting critical corporate accounts while supporting a <a href="https://www.itpro.com/business-strategy/flexible-working/370225/lessons-of-covid-19-shaping-the-future-of-hybrid-work">hybrid work model</a>. This is particularly critical for offices that take a <a href="https://www.itpro.com/business/business-strategy/the-top-4-byod-risks-businesses-face">bring your own device (BYOD)</a> approach, as home devices can be more vulnerable to password-stealing malware and therefore need the extra line of defense.</p><p>Using 2FA methods like passkeys and authenticator apps provides users with “better and more secure protection”, says ESET global cybersecurity advisor Jake Moore.</p><p>“When threats are multi-layered themselves, accounts need the strongest multi-layered protection to stay secure,” he tells <em>ITPro</em>.</p><p>But as well as protecting against password breaches, 2FA could also bring about a <a href="https://www.itpro.com/security/the-end-of-passwords-and-how-businesses-will-embrace-it">passwordless future</a>. Moore says this is possible thanks to “superior security options” that offer greater pxrotection against phishing and brute-force attacks than single passwords. He adds:  “Passkeys, for example, offer ease of use, security as well as convenience and are already being rolled out smoothly across multiple accounts.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 class="article-body__section" id="section-is-two-factor-authentication-safe"><span>Is two-factor authentication safe?</span></h2><p>Despite the benefits it offers, it's worth noting that <a href="https://www.itpro.com/security/cyber-attacks/354868/android-cerberus-malware-can-hack-google-authenticator">multi-factor authentication is not 100% secure</a>. Microsoft has warned businesses against using systems that rely on voice and SMS due to security concerns, warning that these methods use no <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> and are therefore ripe for interception by hackers. With private details to hand, hackers can launch <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank">social engineering</a> campaigns </p><p>For example, authentication via text message is vulnerable to interception and spoofing by hackers, particularly if they can hijack an account that supports a person's mobile number. Various account recovery processes for lost passwords can also be harnessed by hackers to work around two-factor authentication. </p><p>Sophisticated <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank">malware</a> that has infected computers and mobile devices <a href="https://www.itpro.com/security/tycoon-2fa-the-popular-phishing-kit-built-to-bypass-microsoft-and-gmail-2fa-security-protections-just-got-a-major-upgrade-and-its-now-even-harder-to-detect">can redirect authentication messages</a> and prompts to a device belonging to a hacker, rather than the legitimate account holder, thereby working within but also around two-factor authentication.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="G4z9HRkWymxjNBTJAFRrxj" name="BCDR buyers guide_listing.jpg" caption="" alt="BCDR buyer's guide for MSPs whitepaper from Datto" src="https://cdn.mos.cms.futurecdn.net/G4z9HRkWymxjNBTJAFRrxj.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Datto)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/359139/bcdr-buyers-guide-for-msps">Dispels misconceptions about BCDR solutions</a></p></div></div><p>The most secure methods of 2FA use dedicated hardware tokens, such as a <a href="https://www.itpro.com/cloud/cloud-security/354809/google-expands-usb-c-titan-security-keys-to-10-countries" target="_blank">Google Titan Security Key</a> or YubiKey, which are difficult for hackers to spoof unless they physically steal one. Google's offering, for example, uses cryptography to verify a user's identity and a separate URL to stop would-be attackers from accessing accounts even if they have the username and password. </p><p>Methods of 2FA reliant on codes sent via SMS are best avoided if you are running an enterprise with a treasure trove of data. This is because SMS is vulnerable to <a href="https://www.itpro.com/security/cyber-attacks/cisa-urges-organizations-to-adopt-passwordless-security-in-lapsusdollar-report">SIM swap attacks</a>, in which attackers transfer a victim's number to a SIM card in their possession to intercept their messages. If they pull this off on a user they know uses SMS-based 2FA, they could gain access to their account without any alarms going off.</p><p>While 2FA may not be quite the security silver bullet it was once expected to be, it's still an important area of security and access control to keep in mind when procuring and setting up services for your business or personal life, because the more hurdles you can put in the hackers' way, the less likely they are to target you.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>