Regulation vs. Reality: Permissions in the Supply Chain as a Critical Point of Vulnerability
Cybersecurity regulations are important—but they do not adequately protect companies from attacks involving stolen identities and login credentials. A commentary by Elmar Eperiesi-Beck, CEO of Bare.ID, explains why modern identity and access management is the key to preventing damage.
Notable incidents such as the attack on V-Bank—in which hackers gained access to systems through an IT service provider and caused a data breach—or the data leak at Lastpass, which was exploited through a vulnerability in a third-party provider, highlight a bitter truth: Even in highly regulated markets or in the field of IT security, digital identities and login credentials are the weakest link in the security chain.
Digital Supply Chains Expand the Attack Surface
The fact that attacks are carried out via third-party providers—which are presumably inadequately protected—illustrates how quickly the attack surface is growing and how little control many organizations have over their own digital identities and access. Regulation alone does not guarantee security when a lack of control over digital identities is the root of the problem. Two aspects are crucial here: prevention and damage control.
Prevention Through Modern Identity and Access Management
Prevention is achieved through modern identity and access management—for example, using an Identity and Access Management (IAM) system. This provides companies with transparency regarding which identities have which permissions and how those permissions are being used. The “least privilege” strategy is a proven approach for reducing attacks—including those originating through the software supply chain and third-party providers.
Such a system must support security mechanisms such as passkeys or multi-factor authentication in a way that makes them easy and convenient to use for both administrators and users. This requires a wide range of features and, above all, a high degree of flexibility in the solution—it must adapt to the company’s structure, not the other way around. A modern IAM platform based on open standards provides the necessary flexibility for this.
Damage Control in an Emergency
If an incident does occur, damage control is essential—especially if the vulnerability lies with an external business partner. In the event of an attack via the software supply chain, it is crucial how quickly an external service, access point, or user can be blocked—ideally automatically. Here, too, modern access management provides the key to immediately locking out intruders across all systems. This helps minimize or even prevent damage.
Technology Instead of Compliance Requirements
Companies and organizations don’t need more compliance requirements. Rather, they need proven technological solutions that protect identities—and thus access to systems—from the ground up. Attacks like the one on V-Bank show that the digital supply chain significantly expands the attack surface. Organizations must ensure identity security not only for their internal infrastructure but also beyond their own perimeter.
Bare.ID stands for digitally sovereign identity and access management based on open source (Keycloak)—developed for organizations that want to manage identities and access securely, independently, and in a future-proof manner. The platform combines powerful single sign-on, modern multi-factor authentication, identity lifecycle management, and centralized access management into a comprehensive IAM solution. Flexibly deployable as SaaS, hybrid, or on-premises, Bare.ID integrates seamlessly into complex IT landscapes.
Source: www.bare.id
This article originally appeared on m-q.ch - https://www.m-q.ch/de/regulierung-vs-realitaet-berechtigungen-in-der-lieferkette-als-kritisches-einfallstor/
