{"id":5232,"date":"2021-02-03T16:22:53","date_gmt":"2021-02-03T20:22:53","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=5232"},"modified":"2021-02-03T16:22:53","modified_gmt":"2021-02-03T20:22:53","slug":"new-challenges-in-third-party-identity-security-what-you-need-to-know","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/","title":{"rendered":"New Challenges in Third-Party Identity Security: What You Need to Know"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-4549\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg\" alt=\"New Challenges in Third-Party Identity Security: What You Need to Know\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD-768x384.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD-540x270.jpg 540w, https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD-162x81.jpg 162w, https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">What are some new third-party identity security challenges your enterprise must face in the coming year? Why do these matter now more than ever?\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Recently, the SolarWinds hack &#8211; already one of the worst in history &#8211; took on a new dimension. In addition to hackers affiliated with the Russian government, it appears that hackers possibly associated with the Chinese government also exploited a vulnerability. This vulnerability exploit allowed this hacking group access to the US Department of Agriculture&#8217;s National Finance Center.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The incident reveals the perils inherent in working with third parties. A third-party refers to another business that maintains access to your network, often to fulfill critical tasks. These can involve cybersecurity, financial data, human resources, and more. Almost no business today can function without employing at least a few third parties in their work processes.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, third parties open new <a href=\"https:\/\/solutionsreview.com\/identity-management\/identity-governance-and-administration-buyers-guide\/\" target=\"_blank\" rel=\"noopener noreferrer\">cybersecurity<\/a> challenges for enterprises of all sizes. For example, one of the most famous breaches of the modern age, the Target Breach, involved a third party; in that incident, hackers exploited an HVAC company with Target network access to steal millions of credit cards.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So your business needs to recognize the importance of third-party identity security. But where can you begin?\u00a0<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n<h2 style=\"text-align: justify\"><b>Third-Party Identity Security: What You Need to Know<\/b><\/h2>\n<h3><b>1. What Third-Parties Does Your Business Work With?\u00a0<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Yes, it really can come down to something this simple. Katie Nickels, Director of Intelligence at <\/span><a href=\"https:\/\/redcanary.com\/?_bt=430759504958&amp;_bk=red%20canary&amp;_bm=e&amp;_bn=g&amp;gclid=CjwKCAiAsOmABhAwEiwAEBR0ZruhYv_el31ZUewmQS_2dfsoM6VWjvBdaCAZUWtuxRv1gEMSFhvUThoCOIoQAvD_BwE\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">Red Canary<\/span><\/a><span style=\"font-weight: 400\">, gave this statement to <\/span><a href=\"https:\/\/www.wired.com\/story\/solarwinds-hack-china-usda\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">Wired<\/span><\/a><span style=\"font-weight: 400\">: \u201cWhat we saw for the first week or two, even after the initial SolarWinds revelations, was some organizations just trying to figure out whether they even use SolarWinds products. So I think the shift has to be to knowing [their] dependencies and understanding how they should and shouldn\u2019t be interacting.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Do you have a complete understanding of all the third parties that operate on your network? Does your organization have a concrete, systematic process for onboarding and offboarding third parties? Are all business partners subject to third party identity security processes?\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">These aren\u2019t idle questions. You need a higher level of visibility than you might realize to best secure your IT environment.<\/span><\/p>\n<h3 style=\"text-align: justify\"><b style=\"font-size: 1em\">2. What Privileges Do Your Third Parties Possess?<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">The other major problem that faces enterprises is knowing what third parties can do on their network. While third parties may receive initial privileges, they could accumulate others over the course of your business interaction in an insidious example of access creep. This bloating of privileges makes those accounts prime targets for hackers, and indeed could cause unbelievable damage over the short and long term.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Therefore, you need to exercise the Principle of Least Privilege on your third parties. The question becomes how. <\/span><\/p>\n<h3 style=\"text-align: justify\"><strong>3. Identity Governance Can Help<\/strong><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Identity Governance and Administration (IGA) can help your business with its third-party identity security. First, it can identify the accounts currently operating in your IT environment, and help find any orphaned accounts that might linger out of view. Second, it can help revoke unnecessary privileges on accounts, enforcing the Principle of Least Privilege. In fact, it can also limit new privileges, assigning set time limits so that accounts can\u2019t bloat with access creep.\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">IGA might just be the solution you need for your third party identity security. Find out more in our <a href=\"https:\/\/solutionsreview.com\/identity-management\/identity-governance-and-administration-buyers-guide\/\" target=\"_blank\" rel=\"noopener noreferrer\">Identity Governance Buyer\u2019s Guide<\/a>.\u00a0\u00a0<\/span><\/p>\n<br \/>Widget not in any sidebars<br \/>\n","protected":false},"excerpt":{"rendered":"<p>What are some new third-party identity security challenges your enterprise must face in the coming year? Why do these matter now more than ever?\u00a0 Recently, the SolarWinds hack &#8211; already one of the worst in history &#8211; took on a new dimension. In addition to hackers affiliated with the Russian government, it appears that hackers [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":4549,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,1],"tags":[142,125,16,76,425,286,397,188],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>New Challenges in Third Party Identity Security: What You Need to Know<\/title>\n<meta name=\"description\" content=\"What are some new third-party identity security challenges your enterprise must face in the coming year? Why do these matter now more than ever?\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/\",\"name\":\"New Challenges in Third Party Identity Security: What You Need to Know\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg\",\"datePublished\":\"2021-02-03T20:22:53+00:00\",\"dateModified\":\"2021-02-03T20:22:53+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"What are some new third-party identity security challenges your enterprise must face in the coming year? Why do these matter now more than ever?\u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg\",\"width\":800,\"height\":400,\"caption\":\"Machine Identity: The New Challenge in Cybersecurity\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Challenges in Third-Party Identity Security: What You Need to Know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New Challenges in Third Party Identity Security: What You Need to Know","description":"What are some new third-party identity security challenges your enterprise must face in the coming year? Why do these matter now more than ever?\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/","url":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/","name":"New Challenges in Third Party Identity Security: What You Need to Know","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg","datePublished":"2021-02-03T20:22:53+00:00","dateModified":"2021-02-03T20:22:53+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"What are some new third-party identity security challenges your enterprise must face in the coming year? Why do these matter now more than ever?\u00a0","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/08\/2019-SIEM-CEO-MAIN-MOD.jpg","width":800,"height":400,"caption":"Machine Identity: The New Challenge in Cybersecurity"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/new-challenges-in-third-party-identity-security-what-you-need-to-know\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"New Challenges in Third-Party Identity Security: What You Need to Know"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/5232"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=5232"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/5232\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/4549"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=5232"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=5232"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=5232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}