{"id":2277,"date":"2018-01-24T14:57:52","date_gmt":"2018-01-24T18:57:52","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=2277"},"modified":"2018-01-24T15:05:58","modified_gmt":"2018-01-24T19:05:58","slug":"numbers-security-conveince-iam","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/","title":{"rendered":"By the Numbers: Security or Convenience in Identity Management?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2278\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg\" alt=\"security or convenience by the numbers identity management\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod-540x270.jpg 540w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod-162x81.jpg 162w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">It\u2019s a question that haunts so many cybersecurity professionals across enterprises of all sizes when deploying an <a href=\"https:\/\/solutionsreview.com\/identity-management\/top-7-iam-vendors-watch-2018\/\" target=\"_blank\" rel=\"noopener\">Identity Management solution<\/a>: do you emphasize security or convenience?<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">This question may appear simple on the surface. After all, shouldn\u2019t security always come first when it comes to Identity Management? If enterprise credentials fall into the wrong hands, then your data may end up for sale on the black market or broadcasted for the all the world to see. The financial and legal headaches from the resulting fines, consultations, and reputation damage in the wake of a data breach is enough to make cybersecurity professionals and executive alike wary of making anything easier for hackers. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><br \/>Widget not in any sidebars<br \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Credentials are already a lucrative target for the digital criminal: <\/span><\/p>\n<p style=\"text-align: justify\"><b>81%<\/b><span style=\"font-weight: 400\"> of confirmed data breaches in 2017 were due to weak, reused, or stolen passwords, according to a study by LastPass. <\/span><\/p>\n<p style=\"text-align: justify\"><b>63%<\/b><span style=\"font-weight: 400\"> of confirmed data breaches involved weak stolen or default passwords, according to a separate study by Verizon.<\/span><\/p>\n<p style=\"text-align: justify\"><b>19% (nearly \u2155)<\/b><span style=\"font-weight: 400\"> of enterprise professionals use poor quality passwords or shared passwords, according to a study by Preempt.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Adding onto these appropriate fears is that the idea that making an identity management solution too convenient plays into the hands of rogue or ex-employees with ill intent. The latest statistics justify those fears: \u00a0\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><b>60%<\/b><span style=\"font-weight: 400\"> of all attacks conducted by insiders, according to IBM. <\/span><\/p>\n<p style=\"text-align: justify\"><b>75%<\/b><span style=\"font-weight: 400\"> of these attacks were conducted with malicious intent, according to those same findings.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Furthermore, any retailer or enterprise with a customer-facing aspect also need to consider their enterprise\u2019s identity management solution as part of their efforts to secure public trust. In addition to quality products and services, security is an increasing customer demand: <\/span><\/p>\n<p style=\"text-align: justify\"><b>67% <\/b><span style=\"font-weight: 400\">of consumers are concerned about their online identities while shopping or banking, according to a survey by BetaNews. <\/span><\/p>\n<p style=\"text-align: justify\"><b>51%<\/b><span style=\"font-weight: 400\"> of consumers in that same survey said that news of data breaches changed the way they conducted their business online.<\/span><\/p>\n<p style=\"text-align: justify\"><b>50%<\/b><span style=\"font-weight: 400\"> would be okay with providing even more authentication factors when verifying their identities online, according to Crossmatch. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">It seems so straightforward, but very little is in identity management or in cybersecurity as a whole is so simple. The problem is that users even in the most prestigious enterprises will pick the most convenient option, even if it compromises the security of their credentials and their business. Perhaps this is not surprising; humans gravitate to a state of maximum efficiency naturally, and corporate culture does reward speed. Combined with password fatigue, perhaps the results are not so surprising: <\/span><\/p>\n<p style=\"text-align: justify\"><b>36 minutes<\/b><span style=\"font-weight: 400\">\u2014the time per month the average employee types in their credentials, according to LastPass.<\/span><\/p>\n<p style=\"text-align: justify\"><b>154 times a month<\/b><span style=\"font-weight: 400\">\u2014the number of times an employee must type in their credentials, according to the same findings. <\/span><\/p>\n<p style=\"text-align: justify\"><b>39% <\/b><span style=\"font-weight: 400\">of users find it challenging to keep up with all the passwords for all their online accounts according to Pew Research. <\/span><\/p>\n<p style=\"text-align: justify\"><b>20% to 30%<\/b><span style=\"font-weight: 400\"> of help desk tickets concern lost or forgotten passwords, according to Gartner. <\/span><\/p>\n<p style=\"text-align: justify\"><b>91%<\/b><span style=\"font-weight: 400\">\u2014the percentage of users who know the dangers of reused passwords, according to Pew Research. <\/span><\/p>\n<p style=\"text-align: justify\"><b>61%<\/b><span style=\"font-weight: 400\">\u2014the number of users who do so anyway, also according to Pew. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">A takeaway from all these findings is that even with the most comprehensive identity management solution, your employees and third-party users may still constitute the weakest link in your security. Not necessarily from malice either, but from human laziness. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The implied ideal is a solution that balances security and convenience. Part of the recent buzz around <a href=\"https:\/\/solutionsreview.com\/identity-management\/biometrics-iams-future\/\" target=\"_blank\" rel=\"noopener\">biometrics<\/a> as a replacement for passwords stems from the solution being seen as the bridge between the two values. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">According to a Keeper Security survey, <\/span><b>66%<\/b><span style=\"font-weight: 400\"> of respondents believe biometrics are a strong tool that are both secure and convenient. <\/span><b>38.9%<\/b><span style=\"font-weight: 400\"> of respondents think biometrics are more secure than passwords. <\/span><b>70% <\/b><span style=\"font-weight: 400\">of respondents find biometrics easier than passwords, according to a Visa survey. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The problem is that biometrics may not be as secure as the public perception of them has leads many to believe. After all, if biometric data is compromised users can\u2019t simply change them for the future: <\/span><\/p>\n<p style=\"text-align: justify\"><b>46%<\/b><span style=\"font-weight: 400\"> of respondents felt biometrics are more secure than passwords or PINS, according to AYTM Market Research. <\/span><\/p>\n<p style=\"text-align: justify\"><b>1.2 billion people<\/b><span style=\"font-weight: 400\">\u2014the number of people left vulnerable in a hack on India\u2019s Aadhaar biometric database. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The lesson from all this is that, if you are considering an <a href=\"https:\/\/solutionsreview.com\/identity-management\/idaas-vendors-to-watch-2018\/\" target=\"_blank\" rel=\"noopener\">identity management<\/a>, <a href=\"https:\/\/solutionsreview.com\/identity-management\/privileged-identity-vendors-to-watch-2018\/\" target=\"_blank\" rel=\"noopener\">privileged access management<\/a>, or biometric solution, you need to weigh the security benefits with how easy it will be for your employees to adapt to the solution. Training them in the solution\u2019s policies and nuances will be as necessary as selecting the solution in the first place. Additionally, it is essential to evaluate your employees\u2019 security practices and enforce password best practices across your enterprise. \u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The alternative may be letting your employees relax themselves into a data breach.<\/span><\/p>\n<p style=\"text-align: justify\"><br \/>Widget not in any sidebars<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s a question that haunts so many cybersecurity professionals across enterprises of all sizes when deploying an Identity Management solution: do you emphasize security or convenience? This question may appear simple on the surface. After all, shouldn\u2019t security always come first when it comes to Identity Management? If enterprise credentials fall into the wrong hands, [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":2278,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,1],"tags":[499,237,356,16,112,70,124,91],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>By the Numbers: Security or Conveince in Identity Management?<\/title>\n<meta name=\"description\" content=\"Should you emphasize security or convenience in your identity management security solution? The numbers don&#039;t lie...but may surprise you!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/\",\"name\":\"By the Numbers: Security or Conveince in Identity Management?\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg\",\"datePublished\":\"2018-01-24T18:57:52+00:00\",\"dateModified\":\"2018-01-24T19:05:58+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"Should you emphasize security or convenience in your identity management security solution? The numbers don't lie...but may surprise you!\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg\",\"width\":800,\"height\":400,\"caption\":\"security or convenience by the numbers identity management\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"By the Numbers: Security or Convenience in Identity Management?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"By the Numbers: Security or Conveince in Identity Management?","description":"Should you emphasize security or convenience in your identity management security solution? The numbers don't lie...but may surprise you!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/","url":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/","name":"By the Numbers: Security or Conveince in Identity Management?","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg","datePublished":"2018-01-24T18:57:52+00:00","dateModified":"2018-01-24T19:05:58+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"Should you emphasize security or convenience in your identity management security solution? The numbers don't lie...but may surprise you!","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/01\/By-the-numbers-IAM-Mod.jpg","width":800,"height":400,"caption":"security or convenience by the numbers identity management"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/numbers-security-conveince-iam\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"By the Numbers: Security or Convenience in Identity Management?"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/2277"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=2277"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/2277\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/2278"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=2277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=2277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=2277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}