Study reveals benefits of next-gen access solutions to organisations

Study reveals benefits of next-gen access solutions to organisations

Respondents with zero trust models leveraging next-gen access reported reduced overall risk and lower security-related costs in the study commissioned by Centrify

Centrify, a leading provider of zero trust security through the power of next-gen access, has announced results of a commissioned study conducted by Forrester Consulting on behalf of Centrify, which finds that organisations powering zero trust security with next-gen access solutions reported twice the confidence to accelerate new business models and customer experiences.

The study of 311 IT decision-makers in North America and the UK found that 67% of all enterprise resources are exposed to access-related risk and that a zero trust security approach is the best strategy to control access to enterprise resources.

The study revealed that next-gen access is the engine that powers zero trust security, stating that, ‘NGA technologies enable the layers necessary for a successful zero trust strategy.’

Organisations using next-gen access solutions – including Identity-as-a-Service (IDaaS), Enterprise Mobility Management (EMM) and Privileged Access Management (PAM) – also reported topline benefits including being 66% more confident in adopting mobile work models, and 44% more confident in securing DevOps environments. Those same respondents reported bottom line benefits of mitigating overall risk by 37% and reducing security costs by 31%.

According to Forrester, 58% of global enterprises have experienced a breach in the past 12 months. According to the study, ‘security leaders are urgently scrambling to defend every entry point but traditional approaches to security, based on keeping out the ‘bad guys,’ while letting in the good guys, have proven ineffective.’

In response, many security leaders are turning to zero trust approaches that remove trust from the equation completely, shunning the traditional ‘trust but verify’ approach and replacing it with a ‘never trust, always verify’ mandate.

“The dissolving network perimeter is causing a complete rethink in how we approach security, taking into account a new enterprise reality defined by the cloud, mobility, and increasing demands for agility,” said Tom Kemp, CEO of Centrify. “This study reveals that two-thirds of enterprise resources are exposed to access-related risk, largely because organisations are approaching security in a way that no longer works and with solutions that are ineffective. Zero trust security, powered by next-gen access, reduces risk and costs, while ushering in a new era in customer experiences and business models.”

Zero trust is the best strategy to control access, the study states.

“Successful access control is a key pillar in Forrester’s zero trust model for securing today’s enterprises,” it says.

“A zero trust strategy, as the name implies, rests on security leaders not making any trust assumptions throughout their security architecture.”

To enforce user access, a Zero Trust strategy requires that an organisation’s security must have the capability to:

  • Verify the identity of every user through a combination of identity governance, single sign-on and multifactor authentication (MFA) to eliminate the risk of credential compromise
  • Validate every device with mobile device management to enforce secure policy, with local administrator privilege management to eliminate local admin compromise and with device identity management to ensure that only trusted devices are allowed to access resources
  • Limit access and privilege using privileged access management to ensure a user has just enough access and only the necessary privileges to perform their job during any given time
  • Continually learn and adapt using behaviour-based analytics and privileged access auditing/monitoring to automatically improve and personalize access policies

Centrify’s next-gen access delivers a unified, industry-recognised solution that uniquely converges IDaaS, EMM and PAM to address these four pillars of zero trust security. This seamless integration secures access across applications, endpoints and infrastructure for all users, without sacrificing best-of-breed features.

Browse our latest issue

Intelligent CIO Europe

View Magazine Archive