LogMeIn study finds 92% of businesses experiencing significant identity challenges

LastPass by LogMeIn has announced the results of a new study conducted by Vanson Bourne to offer businesses insights into the state of identity and access management (IAM) and actionable steps to improve their IAM programme. The study, entitled ‘The Guide to Modern Identity’, surveyed 700 global IT and security professionals at organisations ranging from 250 to 2,999 employees and found 92% are experiencing at least one challenge when it comes to identity management, with 47% citing ease of use with security as the biggest challenge.

Data from the report reveals IT professionals overwhelmingly (82%) agree that poor identity practices have exposed their business to risks, citing incorrect access controls (41%), loss of employee data (36%) and loss of customer data (33%) as the biggest consequences. Despite this, many have not implemented an adequate identity management solution.

Additional key findings include the following:

Passwords continue to cause frustration and risk
IT teams continue to spend valuable time and resources dealing with tickets for password-related problems. On average, IT security teams spend four hours per week on password management-related issues alone and receive 96 password-related requests per month. Given the ongoing resource drain that passwords pose to organisations, almost all (95%) of IT security professionals surveyed report that their organisation should place more emphasis on the importance of strong password behaviour. 

Single Sign-On serves a crucial role – but leaves critical gaps in isolation
Given the risks and resource drain associated with passwords, Single Sign-On (SSO) solutions offer the benefits of eliminating passwords for IT-supported apps and simplifying the login process for employees accessing key apps in the cloud and behind the firewall. However, many apps are not integrated into an SSO solution – whether because they don’t support SSO, they’re not high enough priority for IT to configure SSO or IT doesn’t even know they’re being used. LastPass by LogMeIn’s research shows 80% of IT professionals agree that relying on SSO alone isn’t enough, as it still leaves a variety of cloud apps and privileged accounts unsecured. 

Upgrading identity capabilities now a top priority 
98% of IT professionals surveyed see room for improvement in the general security behaviour of their employees (creating strong passwords, ensuring secure sharing and collaboration). Due to competing priorities, IT teams are struggling to address their security needs. When asked about next year’s IT security objectives, 65% agree that upgrading their IAM capabilities is a priority. When asked for ideal features in an identity solution, respondents noted multi-factor authentication (MFA) (55%), integration with current infrastructure (52%), a built-in password generator (44%), support for both legacy and cloud apps (44%) and an integrated system for managing, monitoring and setting policies (44%).

Strengthening user authentication with MFA “critical”
Among the key priorities for improving identity capabilities, 59% of IT professionals agree that strengthening user authentication with MFA technology is critical. IT security professionals from organisations that have invested in or plan to invest in MFA see the most likely benefits as greater organisational security (60%), fewer instances of incorrect access to confidential information (48%) and decreased risk of credential/password theft (47%). Additionally, 36% of respondents see implementing biometric MFA as a priority.

Balancing ease of use and security is a challenge when implementing an identity solution
Given that security is a high priority for most businesses, it’s no surprise that many are investing in identity solutions. Less than 1% of IT professionals believe that managing user access is unimportant to the overall security of the organisation. Unfortunately, 92% of organisations also say they’re experiencing at least one challenge when it comes to identity management. The average organisation struggles with three identity-related challenges: 47% of respondents said balancing ease of use with increased security was a hurdle, 40% cite the general security of their solutions and 37% are facing demands from employees for a solution that’s easy to use.

“When used individually, enterprise password management, SSO and MFA all bring unique security and productivity benefits to a business,” said John Bennett, general manager of the IAM Business Unit at LogMeIn. “However, when brought together under one solution, businesses have complete security and visibility into every user and access point in their organisation. This is something we found almost all (93%) of the surveyed IT professionals agreed with. With more limited resources, it’s particularly important for SMEs to look for all-in-one solutions that combine the key components and maximise their investment in identity technology.”

About the Author
Brian Sims BA (Hons) Hon FSyI, Editor, Risk UK (Pro-Activ Publications) Beginning his career in professional journalism at The Builder Group in March 1992, Brian was appointed Editor of Security Management Today in November 2000 having spent eight years in engineering journalism across two titles: Building Services Journal and Light & Lighting. In 2005, Brian received the BSIA Chairman’s Award for Promoting The Security Industry and, a year later, the Skills for Security Special Award for an Outstanding Contribution to the Security Business Sector. In 2008, Brian was The Security Institute’s nomination for the Association of Security Consultants’ highly prestigious Imbert Prize and, in 2013, was a nominated finalist for the Institute's George van Schalkwyk Award. An Honorary Fellow of The Security Institute, Brian serves as a Judge for the BSIA’s Security Personnel of the Year Awards and the Securitas Good Customer Award. Between 2008 and 2014, Brian pioneered the use of digital media across the security sector, including webinars and Audio Shows. Brian’s actively involved in 50-plus security groups on LinkedIn and hosts the popular Risk UK Twitter site. Brian is a frequent speaker on the conference circuit. He has organised and chaired conference programmes for both IFSEC International and ASIS International and has been published in the national media. Brian was appointed Editor of Risk UK at Pro-Activ Publications in July 2014 and as Editor of The Paper (Pro-Activ Publications' dedicated business newspaper for security professionals) in September 2015. Brian was appointed Editor of Risk Xtra at Pro-Activ Publications in May 2018.

Related Posts