Talk to us Risks to Watch

KuppingerCole Leadership Compass for Privileged Access Management

Yet another feather in the cap!

ARCON has been named an “Overall Leader” in the 2022 KuppingerCole Leadership Compass for Privileged Access Management report, written by Paul Fisher, lead analyst of KuppingerCole Analysts AG.

The phenomenal run for ARCON as a business organization that focuses on protecting digital identities and vaults (for securing secrets) continues, as earlier in 2022, ARCON was named a “Leader” in the Gartner Magic Quadrant for Privileged Access Management.

For the second year in a row, ARCON has been named an “Overall Leader” in the Kuppingercole Leadership Compass. This recognition is a reiteration of the fact that ARCON is a global leader in the Privileged Access Management (PAM) space. More information on the Leadership Compass report can be found here.

In the latest edition of KuppingerCole’s Leadership Compass for Privileged Access Management, the analyst evaluated 25 privileged access management vendors to prepare a comparative analysis and the leadership compass. While ARCON climbed the ladder in the “Overall Leader” compass, we have also been recognized as an: 

The Leadership Compass report provides a deep-dive analysis of the privileged access management market. The research has a set of criteria to evaluate the vendors based on their product and technology capabilities, including their market presence. This Overall Leadership provides a combined view of the vendors’ ratings for their products, market presence, and innovation road map. ARCON performed superbly in all the parameters.

Today, a Privileged Access Management (PAM) solution has become an absolute must for large enterprises, mid-size companies, and small scale organizations. In addition to ensuring data security, a PAM solution helps organizations comply with regulatory requirements. For this research report, based on the customer-centric feedback and product research, KuppingerCole Analysts AG considered the classic PAM capabilities and extended PAM capabilities to evaluate the vendors. More can be read here: 

A big shout-out to the ARCON team and its broader ecosystem. ARCON’s vision is to create a stack of products for global enterprises to provide a robust access control framework. These products can work not only for devices but also across systems and applications. Our goal is to constantly innovate and add new features and functionalities that can address emerging access control use cases. Our achievement as an “Overall Leader” in the KuppingerCole Leadership Compass for 2022 confirms that we are on the right path.

The Journey of ARCON: Upwards and Onwards

ARCON ends the year 2022 on a high note

ARCON believes in consistency, and consistency is the key ingredient to success. This is exactly what happened in 2022, another eventful year, when ARCON continued to make rapid progress on its global expansion plans, win the customers’ accolades, and win their trust even as our flagship product, ARCON | Privileged Access Management managed to outperform the competition by a long way in terms of product capabilities and functionality.

While the last year was punctuated by global recognitions and awards all through the year, one of the best things that happened was the emergence of our new solution, the Converged Identity Platform. We believe that Converged Identity Management will be the next big thing in the IAM space, as security and risk management professionals are increasingly looking to implement a centralized platform to manage, control, and govern all kinds of digital identities (human and non-human) with standardized policy enforcement. Earlier in 2022, ARCON successfully implemented its SaaS-delivered Converged Identity Management platform for a large manufacturing company.

Here are some of the high points for ARCON as an organization:

July 2022

ARCON was named a “Leader” in the 2022 Gartner Magic Quadrant for Privileged Access Management report. For the second time in a row, Gartner named ARCON a “Leader” for its ability to execute and completeness of vision. This report showcases ARCON’s credibility and completeness as a brand, product, and ascertains how comprehensive ARCON’s Privileged Access Management solution is as per demands in the cyber security market.

Being a “Leader” in the Gartner Magic Quadrant is an unbiased and credible recognition that is admired and acknowledged by IT security professionals across the globe.

July 2022

While deploying privileged access management is one thing, the ability to address numerous use cases seamlessly is the most important part for IT security professionals. A mature PAM should provide support for critical use cases such as Privilege Elevation and Delegation Management, Cloud Infrastructure and Entitlement Management, Secrets Management among many others.

Gartner, in one its widely read reports, the Critical Capabilities for Privileged Access Management rated ARCON | PAM the highest in all 5 use cases that were evaluated by its analyst team. In product and service for PASM, Windows PEDM, UNIX/ Linux and MacOS PEDM, Secrets Management and CIEM, ARCON scored the highest in all with 4.03, 3.70, 4.0, 4.80, and 3.60 (out of 5) respectively.

October 2022

As GEC (Global Enterprise Event) Media Group celebrated their tenth anniversary, they organized a grand awards ceremony to celebrate the reigning champions in the IT security industry in the MEA region. ARCON has been awarded “Top Vendor – Enterprise Security” by GEC Awards. It is one of the prestigious and popular awards in the MEA region that is acknowledged by industry leaders and IT security professionals. The respected jury scrutinizes every bit of progress and innovation in the IT security space and makes sure that only the right vendors are honored and recognized. ARCON is proud to be the deserving one!

December 2022

For the third year in a row, ARCON was named the Customers’ Choice.

The 2022 Gartner Peer Insights Voice of the Customer” for Privileged Access Managementadded another feather in the cap of ARCON by conferring the “Customers’ Choice” badge, which is given to those vendors who meet or exceed both the market average overall rating and the market average user interest and adoption. This recognition reemphasized the fact that ARCON is a customer-centric company.

 In the report, ARCON also had an average of 88% of customers who were willing to recommend it. And while we continue to expand in the North American market and win large enterprise PAM projects across the industry verticals  and across the world, we have also been recognized as a Customers’ Choice for midsize enterprises. Industry-wise, ARCON was named “customers’ choice” for the finance industry as well, and region-wise, ARCON was named “customers’ choice” for the Asia-Pacific region, which we believe is a terrific achievement.

January 2023

ARCON has been named an “Overall Leader” in the 2022 KuppingerCole Leadership Compass for Privileged Access Management report, written by lead analyst Paul Fisher. For the second year in a row, ARCON has been recognized as the “Overall Leader” in the KuppingerCole Leadership Compass. (although the report came out in January 2023, the entire evaluation process and other formalities happened in 2022)

In the latest edition of KuppingerCole’s Leadership Compass for Privileged Access Management, the analyst evaluated 25 privileged access management vendors to prepare a comparative analysis and the leadership compass. The vendors are evaluated based on their product and technology capabilities, including their market presence. After a deep-dive analysis of privileged access management market trends, KuppingerCole not only named ARCON an “Overall Leader”, but also an “Innovation Leader”, a “Product Leader”, and a “Market Leader”. This recognition is a reiteration of the fact that ARCON is a global leader in the Privileged Access Management (PAM) space.

Conclusion

We have just stepped into 2023 and we are very much apprehensive about making 2023 another colorful feather in our crown. Our well-planned and strategic road map is the key behind our success and we will continue the legacy in the coming days. Stay tuned and we will be back with our new achievements in our upcoming blogs.

How to Secure New IT boundaries amid the Adoption of Hybrid Data Centers and Multi-cloud Environments?

Overview

“Change is inevitable” and “Evolution is never-ending”! 

This adage particularly holds true for IT infrastructure and operations. Indeed, in an extremely vast IT setup, new IT boundaries (and new IT challenges) are emerging as organizations model their data center architecture in hybrid (partially on-prem data centers, partly in the cloud) or multi-cloud environments for operational efficiencies.  

Why new IT challenges emerging? The reason being that increasing adoption of multi-cloud and hybridization of IT infrastructure is changing the IT security landscape. From an access control perspective, data breach, insider threats and third-party attacks threats are inevitable as end users have a growing number of access paths to confidential information. 

This emerging IT challenge paves the way for steadfast digital security wherein managing a vast number of digital identities for end users and administrators demands a careful implementation of broader Access Management (AM) framework. 

Access Management (Converged Identity Management) initiative includes Privileged Access Management (PAM), SSO, MFA, Identity and Access Management (IAM), and Identity Governance and Administration (IGA) while Cloud Infrastructure and Entitlement Management (CIEM) capabilities provides risk assessment and threat prediction capabilities in multi-cloud environments.

An effective, carefully crafted, and mature Access Management and CIEM framework not only provides role- and time-based secure access to the target systems and applications but also ensures real-time alerts on perceived threats. Furthermore, from a compliance perspective, a robust IAM and CIEM framework ensures user governance.

In this blog, ARCON has highlighted two time-tested reasons why Access Management and CIEM will spearhead the most sought-after IT security initiatives in the coming days. 

Secure confidential information and highly sensitive data in remodeled data center environments.  

  1. Adoption of Multi-cloud Platforms

In one of its reports, “Projecting the Global Value of Cloud,” Mckinsey says that large enterprises aspire to have roughly 60% of their environments in the cloud by 2025. Indeed, nowadays, almost three out of four businesses adopt multi-cloud platforms. It helps enterprises meet the requirements arising from daily IT operational and infrastructure use cases through various cloud platforms such as AWS, Azure, and Google Cloud.

Hundreds of human and non-human (digital) identities accessing cloud resources, consoles, and workloads for day-to-day use cases, on the other hand, have exposed enterprises to the risk of a data breach. 

The challenges:

  • Each cloud console has it own set of access management mechanisms 
  • Managing the growing number of complex and dynamic cloud infrastructure entitlements 
  • Difficulty in having complete control and visibility of over-privileged users  
  • Detecting potential threats from anomalous identities 
  • Enforcing access control regulations across multi-cloud environments

ARCON’s CIEM platform addresses administrative challenges spread across cloud platforms. The solution provides the ability to manage the cloud infrastructure through a unified engine. It ensures the monitoring, controlling, and managing of cloud entitlements spanning multiple cloud platforms. 

ARCON Cloud Governance Platform for CIEM ensures: 

  1.  Role-based restricted access to the target systems / applications. 
  1. AI-based automated anomaly detection capability that helps cloud security teams associate a risk score with each entity based on their activity on the cloud platform. It provides the administrator with an overview of the riskiness required to take appropriate action to remediate it using an AI-based recommendation model associated with each entity. 
  1. Controlling over-entitlements (Provision/DeProvision policies,groups) by following the ‘Least Privilege’ principle.

     2. Hybridization of IT infrastructure

The year 2022 can be considered the first year of post-pandemic age. And the world has seen rapid growth in cloud computing to scale IT operations last year. Not just to manage day-to-day administration, there are too many business applications across the IT environment that boost the demand for and importance of cloud technologies. As a result, the proliferation of cloud technologies is now unstoppable.

However, there are organizations that are unprepared (or sometimes reluctant) for this transition. Unlimited security worries, a fear of mismanagement in handling advanced technologies, and sometimes cost are the reasons behind the same. As a result, they end up adopting a hybrid work culture where both on-cloud and on-premises infrastructure, including legacy applications, coexist. 

Challenges in hybrid environments: 

  • Controlling the end-users in a centralized manner
  • Managing all kinds of identities – standard, privileged, and non-human
  • Monitoring and managing the privileged users seamlessly
  • Reducing the number of logins (SSO)
  • Additional layers of validating end users (MFA)
  • Meet compliance requirements- Least privilege principle (identity governance)

ARCON’s Converged Identity platform enables seamless integration of both on-prem and on-cloud IT resources through one unified access control framework. 

Through  a converged identity management platform, IT security and risk management teams

can ensure: 

  1. Analytics and Reporting 
  2. Provisioning and deprovisioning of identity for life cycle management 
  3. Access request
  4. Workflow matrix management 
  5. Identity authentication with MFA 
  6. SSO for seamless user experience 
  7. Authorization of end users 
  8. Identity administration and governance 

Moreover, ARCON provides:

  • A broad set of connectors that eases the integration of IT resources with different applications in a hybrid environment.
  • Flexibility with tailor-made gateways that cater to both on-prem and multi-cloud environments

The role of IGA in today’s IT environment

If we consider the changing threat patterns in the Identity Access Management landscape, strong identity governance has become extremely essential to building a comprehensive IT security infrastructure. Today, the threat surface created by the ever-increasing number of digital identities, is quite large. Every identity, especially a privileged identity, in the IT infrastructure needs to be treated as a perimeter in itself. If not governed, the anomalous behaviour associated with every access goes unnoticed, and analysis of the threat possibilities is also not done. With this, the lifecycle of every identity remains improper, which bears security and compliance risks.

The threats magnify when a large number of human and non-human identities exist without any well-defined role in a distributed IT environment. Critical access management criteria such as fine-grained access, just-in-time privilege access, or rule-based access are extremely important to establish a viable risk assessment practice. It aids in the development of the desired identity lifecycle management. 

ARCON’s Converged Identity Platform addresses the identity governance challenges in every access control use case.

  • It ensures that the right end-user has access to the right system at the right time for a right purpose.
  • It seamlessly validates each identity access and its activities as per the role and time of access.
  • It improves identity lifecycle management by segregating the roles and responsibilities of the identities as per the policies.
  • It modifies end-user details as per configuration and even deletes or revokes elevated rights if required.

Conclusion

A resilient AM and CIEM architecture is the need of the hour in the IT security space. In fact, it is going to drive critical managerial IT decisions in the coming days. A mature AM and CIEM model solution will aid in the creation of a robust digital ecosystem, whether it is cloud implementation, hybridization of work environments, or managing identity governance in a hybrid IT environment.

Protecting Non-human Identities for a Holistic Identity and Access Management Framework

Overview

“Automation” is the new-age mantra in information technology management. From large enterprises to mid-size organizations, IT infrastructure and operations teams are increasingly implementing process automations. The two major reasons behind the growing acceptance of process automation are higher IT efficiencies leading to better operational outcomes and a reduced number of man-hours spent on mundane IT tasks.

However, amid this increasing pace of automation, we are witnessing a massive explosion in the number of non-human identities that interact with systems to conduct IT tasks. Forrester expects that RPA products and services will reach $16 billion by 2023.

Now the question pops up: How safe are non-human identities? Can non-human identities be misused? Do organizations adopt enough IT security mechanisms to secure non-human identities? Because, just like human identities, non-human identities are vulnerable to bad actors as well.

And the threat vector that is created by the proliferation of non-human identities is very large, and any malicious kind of activity through a non-human identity might lead to an IT catastrophe.

For example, when the digital identities of non-human entities are misused and their credentials (user names, passwords, and certificates) are compromised due to weak access controls, attackers can misuse the data, cause IT downtime and/or disrupt services. Likewise, non-human entities with privileged-level access are at risk of insider and cyber-attacks due to the sensitive nature of information stored in digital accounts.

A Holistic Identity and Access Management Approach: Towards Identity Convergence

Organizations typically administer, control, and track human identities that access disparate applications, databases, servers, and OSes by deploying identity and access management solutions, including identity administration and governance and privileged access management solutions.

In a similar vein, controlling and administering non-human identities is equally important to building a holistic identity and access management framework. And we believe that, as the number of both human and non-human identities grows, future organizations will adopt a converged identity management platform to manage a large number of all forms of (human and non-human) identities seamlessly.

How ARCON Digital | PAM can address a growing number of non-human identity use cases and their security 

It is highly imperative for organizations to manage the lifecycle of non-human identities in their IT environments. It is critical to ensure that they have the necessary systems and processes in place to control and manage the non-human identities seamlessly.

For example, developers using agile methodologies such as DevOps or leveraging microservices for a faster build process, workloads being managed on cloud containers, VMs including RPA—there are an increasing number of use cases that interact with machines, scripts, applications, and IT infrastructure processes. So, from an IT security perspective, it is crucial to manage the credentials (passwords, SSH keys, certificates, and OAuth tokens).

ARCON | Digital PAM provide the capability to generate, vault, and randomize credentials for non-human identities and broker trust between two non-human identities, along with ensuring authorization and policy enforcement (Identity Governance) for the same.

To summarize, ARCON | Digital PAM:

1. Leverages native application attributes and role-based access controls to authenticate applications and containers

2. Manages credentials/tokens used by applications, container platforms, automation tools, and other non-human identities

3. Controls human and non-human access to CI/CD consoles

4. Manages and securely pass credentials to validated containers and clusters as and when required

5. Secures credentials, certificates, APIs, tokens, secrets in digital vaults and protects and monitors both non-human and human identities with super-user level access to cloud workloads

Conclusion

In a nutshell, strong Identity and Access Management practices are the best and only choice to secure non-human identities or machine identities with the same objective that are used for human identities. These identities are increasingly falling prey to abuse by malicious insiders and third-party users. And organizations that are adopting automation techniques are highly prone to these threats. Hence, in another couple of years, protecting machine identities could be the only choice for organizations to secure their critical business assets.