Never give humans the keys to your kingdom, say Goldman Sachs security chiefs
Privileged access management is rarely done well and humans are usually the issue
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Top security chiefs at Goldman Sachs have condemned the practice of handing the responsibility of access management to humans. Instead, they pushed for more organisations to adopt an automated approach.
To demonstrate this, Barry McConnell, technology risk lead at Goldman Sachs & Co asked his audience at (ISC)2 Security Congress to raise their hands and then put them down when their organisation doesn't follow certain security protocols in regards to privileged access management (PAM).
In a room of roughly 100 security professionals, only five had their hands in the air, indicating they followed the best practices as set out by the Goldman Sachs chief.
"Humans really shouldn't be doing this stuff, if humans have root access, if humans have access to APIs... that's something that should only be done within very controlled parameters," said McConnell.
Processes such as assigning user privileges is another example of why automation is the way forward in this area, according to McConnell. He said because employees tend to leave their companies, reassigning user privileges is a common area of mistake which results in accounts having wrong owners after a few years.
Examples of processes in an organisation's environment which utilise privileged access include SAS, Salesforce, social media, root access accounts (Hyper Visor admin, database admin), active directory - all these are privileged.
Poor access management to an organisation's system environment has led to some of the biggest cyber disasters of the century. The Yahoo data breach wasn't just a blow to the affected customers, its access management failures led to the sizable chunk of money (best part of a billion) stripped from its Verizon acquisition.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
While there's no strict definition for PAM, there are certain defining characteristics about what it must do, if an organisation implements it.
PAM must have a registration process; knowing what systems have access to which accounts. You need to know what these accounts do and build up as much info about these accounts but don't give humans the responsible for these. "You'll end up having wrong owners after a few years if you assign privileges to humans manually," said McConnell.
In terms of credential storage, eliminating config files is a must. "It's the easiest way for us to breach your organisation," said McConnell.
Organisations should also randomise their root passwords and deploy an external and highly available vault, so attackers can't laterally move after breaching and then find access credentials.
Businesses should also implement ways of monitoring misuse of applications, looking at log files and finding IPs and systems that don't usually speak to each other.
It's important that a business' PAM program accounts for the diverse systems of a modern organisation, from cloud platforms to in-house developed apps, according to Deepak Sharma, information security officer at Goldman Sachs & CO. It must be resilient to network and system failures and also must not affect the current system environment or cause operational slowdown or cessation.
Implementing a PAM program is "highly intrusive", will require C-level backing and the requirement for "over communication", as McConnell puts it, cannot be overstated. Everyone in a given business should know that one is in place and why it's there to protect against the human causes of data breaches.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
AWS CEO Matt Garman isn’t convinced AI spells the end of the software industryNews Software stocks have taken a beating in recent weeks, but AWS CEO Matt Garman has joined Nvidia's Jensen Huang and Databricks CEO Ali Ghodsi in pouring cold water on the AI-fueled hysteria.
-
Deepfake business risks are growingIn-depth As the risk of being targeted by deepfakes increases, what should businesses be looking out for?
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities
-
Everything you need to know about Google and Apple’s emergency zero-day patchesNews A serious zero-day bug was spotted in Chrome systems that impacts Apple users too, forcing both companies to issue emergency patches
-
Security experts claim the CVE Program isn’t up to scratch anymore — inaccurate scores and lengthy delays mean the system needs updatedNews CVE data is vital in combating emerging threats, yet inaccurate ratings and lengthy wait times are placing enterprises at risk
-
IBM AIX users urged to patch immediately as researchers sound alarm on critical flawsNews Network administrators should patch the four IBM AIX flaws as soon as possible