NewsMacroIdentity as the Digital Foundation of Enterprise Security

Identity as the Digital Foundation of Enterprise Security

Author: Bworldonline·

Key Takeaways

  • Approximately 30% of cyberattacks exploit credentials, leading security leaders to call for strategies that go well beyond traditional passwords and multi-factor authentication.
  • Threat actors increasingly target people through social engineering because manipulating individuals is often easier and more effective than defeating sophisticated technical defenses.
  • Zero Trust implementation is a gradual process that requires sustained investment, careful planning, and active participation from all organizational stakeholders rather than relying solely on technology.
  • Executive sponsorship is essential for consistent identity governance, yet many organizations delay security investments until they suffer an actual breach or financial loss.
  • Organizations should adopt a secure-by-design approach by defining IAM requirements before deploying new technologies and treating systems that lack enterprise identity integration as failing to meet business requirements.
Identity as the Digital Foundation of Enterprise Security

By Mhicole A. Moral, Special Features and Content Writer

As organizations accelerate their digital operations, identity has emerged as a defining priority in enterprise cybersecurity. Increasingly, companies depend on identity and access management (IAM) to govern who can reach critical information, when that access is approved, and how it is continuously monitored. The shift has been amplified by widespread cloud adoption and the proliferation of software-as-a-service applications, which have dramatically expanded the number of user accounts and access paths that security teams must manage.

During the third panel discussion at the BusinessWorld Cybersecurity Summit — titled "Identity and Access Management in the Enterprise" — technology executives examined why stronger identity and access systems have become indispensable for modern organizations.

Beyond Passwords and Multi-Factor Authentication

Catherine Anne Paleracio, Chief Information Security Officer (CISO) at Tonik, noted that the identity landscape has evolved in tandem with the expanding accessibility of digital services. While organizations once leaned on conventional authentication methods, the current threat environment demands that security teams think well beyond usernames, passwords, and multi-factor authentication.

"About 30% of attacks are credential-based," Ms. Paleracio said. "This calls for organizations to act according to the landscape that we're in right now, and it triggers us to think about a different strategy on how we're usually approaching IAM."

Jan Martin Encina, director of information security at Maya Philippines, Inc., underscored that identity and access management has long been a core concern for security and audit professionals, since controlling access is the bedrock of protecting enterprise resources.

Although access management can seem routine, Encina stressed that organizations should build robust practices to unlock benefits that extend well beyond reducing cyber risk.

"If an organization is able to get their IAM right, it serves as a very important value driver for that organization," he noted. "You're able to make your process a lot more efficient, and really be able to engage your employees."

This business impact helps explain why adversaries often target identities before attempting more technically sophisticated exploits.

"Access is like the first choice of our adversaries, simply because it's so basic that everyone has it," Mr. Encina said. "Before a threat actor attempts any sort of complicated, sophisticated exploit, they will try to gain access first. If you can get that password from that administrator, from that finance manager who can transfer funds, from someone who can escalate your privileges, there's nothing technical about that. It's all social engineering."

The Remote Endpoint Challenge

Mark Anthony P. Almodovar, Risk Services — Cybersecurity and Privacy executive director at PwC Philippines, pointed out that organizations have had to shift from concentrating security within corporate offices to protecting thousands of remote endpoints.

During the COVID-19 pandemic, for example, many companies sent employees home with desktop computers so operations could continue, dramatically expanding the number of environments security teams needed to defend.

"The endpoint is actually tied up to an individual," Mr. Almodovar explained. "So it's really hard as well to protect it. We still rely on the trust basis."

He noted that organizations generally assume the person logging into a corporate account is the authorized employee, but verifying that assumption across thousands of users each day remains a formidable challenge.

People: The Weakest Link

Advances in enterprise security have also reshaped attacker behavior. As organizations fortified technical defenses through better technologies and broader security awareness, threat actors pivoted toward targeting people and credentials.

"The weakest thing sometimes in the chain is not the process, it's not the technology, but it's really the people," Mr. Encina explained. "Even if you have the most sophisticated security systems, if your admins are giving out their passwords, then just forget your multimillion-dollar investment in security."

Mr. Almodovar echoed that view, stating that access control remains the most fundamental information security control because attackers find it easier to manipulate individuals than to defeat technology.

"For the most part, people are still the most vulnerable," he said. "At least, the technology is playing a good part in terms of enforcing people to use, to some extent, a more sophisticated authentication."

Ms. Paleracio added that phishing campaigns remain among the simplest yet most effective attack vectors because they prey on individuals who already hold valuable access. Attackers, she said, are likely to concentrate on administrators, vendors, and employees with access to critical information, since compromising a trusted account can open a direct path into systems without the need for complex technical exploits.

Zero Trust as a Gradual Journey

While identity has become the focal point of enterprise security, the panelists agreed that implementing Zero Trust is a gradual process that depends as much on governance and business alignment as on technology itself. The concept, formalized in the U.S. National Institute of Standards and Technology Special Publication 800-207, shifts security away from implicit trust based on network location toward continuous verification of every access request.

Ms. Paleracio described Zero Trust as a sound security concept, but cautioned that translating it into day-to-day operations requires sustained investment and careful planning. Organizations also differ significantly in their capacity to adopt the model, since scale directly affects complexity. A smaller enterprise, for instance, may introduce Zero Trust controls more quickly, while organizations with thousands of employees must manage a far larger web of users, systems, and access relationships.

"The challenge is basically defining what you really need and limiting it based on the business needs," Ms. Paleracio added. "At the end of the day, it will be everyone's role, everyone's responsibility to have cybersecurity in place. We need to make sure we become enablers while we're putting up the security controls."

Mr. Encina similarly emphasized that Zero Trust cannot succeed without the active participation of every stakeholder.

"Security is everybody's responsibility because Zero Trust can only be implemented if all of the stakeholders are actually doing it," he noted.

He warned that security controls become ineffective when employees circumvent them. Excessively restrictive policies can push users toward personal devices, unsanctioned artificial intelligence applications, or unauthorized technology — creating additional risks that organizations cannot monitor or control.

Rather than imposing controls after systems are already built, Mr. Encina advocated integrating security into the earliest stages of development through a secure-by-design approach. Organizations, he argued, should define identity and access management requirements before selecting or deploying new technologies. Systems that cannot integrate with enterprise identity platforms should be treated as failing to meet business requirements from the outset, rather than being accepted as security exceptions after deployment.

Executive Support and Governance

Executive backing is equally critical, according to Mr. Almodovar, because policies cannot succeed without genuine organizational commitment. He recalled discussions with organizations that sought to strengthen authentication policies in the face of resistance from senior executives who questioned the need for stronger controls after years without a security incident. That reluctance, he noted, frequently delays security investments until organizations actually suffer losses.

"Access control is the most basic and most fundamental control in information security," Mr. Almodovar said. "Most of the time, only when they experience it, when they are compromised, when they lose money, their accounts have been taken over, that's the time when they will start implementing it."

The panelists repeatedly returned to leadership and organizational culture as the decisive factors behind successful security programs. Because every employee holds some degree of access to systems, applications, and information, each individual contributes to the organization's overall security posture.

"Every single person in the organization has access. Every single person in the organization has a role to play in your systems," Mr. Encina said.

He stressed that effective identity and access management requires executive sponsorship because security programs simultaneously affect technology, business operations, and employee behavior. Without visible support from leadership, organizations frequently struggle to establish consistent identity governance across departments.

He also cautioned against treating compliance requirements as the sole measure of security.

"It's extremely dangerous to have people implement technology without having the right set of policies and governance," he explained. "But it's also ineffective to be all governance and not do anything about technology."

Mr. Almodovar reinforced that protecting organizations ultimately comes down to protecting people. Since many cybercriminals exploit individuals with limited cybersecurity awareness, leaders should launch programs for stronger controls that go well beyond passwords and one-time PINs. Even so, technology alone cannot offset poor security habits.

"Before implementing technology, the governance and management parts are still the first requirement," Mr. Almodovar said. "How can we secure something if we don't understand what we are trying to secure?"

He emphasized that organizations must first establish a clear understanding of their assets, approval processes, ownership responsibilities, and decision-making structures before automating identity management.

The panelists agreed unanimously that organizations must first comprehend their own risks, their likely adversaries, and the level of security awareness across their workforce — rather than assuming that regulatory compliance alone delivers adequate protection.