password issue

A reflection on Identity Security, and my Cybersecurity Fellowship

At first glance, identity security can look like a password problem.

Make it longer, Add a number, Insert a symbol, Perhaps, as the image suggests, include an emoji, your pet’s name, and a little piece of your soul. ๐Ÿ˜„

But during my cybersecurity fellowship with International Justice Mission (IJM) under the Global Technology Solutions, I learned that the real challenge begins after a user successfully enters the password.

๐—ง๐—ต๐—ฒ ๐—บ๐—ผ๐—ฟ๐—ฒ ๐—ถ๐—บ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—ป๐˜ ๐—พ๐˜‚๐—ฒ๐˜€๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ฎ๐—ฟ๐—ฒ:

  โ€ข Who is this user?
  โ€ข What can they access?
  โ€ข Why were they granted that access?
  โ€ข Is the access still necessary?
  โ€ข What happens when their role changes, or they leave?

These questions took me deeper into ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ฎ๐—ป๐—ฑ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—บ๐—ฒ๐—ป๐˜, where identity is not simply a username stored in a directory. It is a security boundary that must be governed throughout its lifecycle.

I began looking at the complete identity journey.

When an employee joins an organization, access must be provisioned according to their role. When they transfer departments or assume new responsibilities, their permissions must change without allowing old access to accumulate. When they leave, access must be revoked promptly across applications, groups, administrative roles, and other connected systems.

This is the ๐—ท๐—ผ๐—ถ๐—ป๐—ฒ๐—ฟ-๐—บ๐—ผ๐˜ƒ๐—ฒ๐—ฟ-๐—น๐—ฒ๐—ฎ๐˜ƒ๐—ฒ๐—ฟ ๐—น๐—ถ๐—ณ๐—ฒ๐—ฐ๐˜†๐—ฐ๐—น๐—ฒ; and weaknesses at any stage can create orphaned accounts, excessive permissions, privilege creep, and opportunities for attackers.

That led to one of my biggest lessons:

๐—œ๐—”๐—  ๐—ด๐—ฟ๐—ฎ๐—ป๐˜๐˜€ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€, ๐—ฏ๐˜‚๐˜ ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—ฒ๐—ป๐˜€๐˜‚๐—ฟ๐—ฒ๐˜€ ๐˜๐—ต๐—ฎ๐˜ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฟ๐—ฒ๐—บ๐—ฎ๐—ถ๐—ป๐˜€ ๐—ฎ๐—ฝ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฟ๐—ถ๐—ฎ๐˜๐—ฒ.

Effective identity governance requires clear ownership, role-based access controls, segregation-of-duties policies, auditable approvals, entitlement visibility, and periodic access reviews. Access should not remain active indefinitely simply because it was approved at some point in the past.

๐—ง๐—ต๐—ฒ ๐—ฟ๐—ถ๐˜€๐—ธ ๐—ฏ๐—ฒ๐—ฐ๐—ผ๐—บ๐—ฒ๐˜€ ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐—ด๐—ฟ๐—ฒ๐—ฎ๐˜๐—ฒ๐—ฟ ๐˜„๐—ต๐—ฒ๐—ป ๐—ฝ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ๐—ฑ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐—ถ๐—ป๐˜ƒ๐—ผ๐—น๐˜ƒ๐—ฒ๐—ฑ.

Through studying ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ๐—ฑ ๐—œ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—บ๐—ฒ๐—ป๐˜, I saw why administrative access should not be permanently assigned. Privileges should be activated only when needed, limited to the required task, approved where appropriate, time-bound, and monitored.

This is the principle behind ๐—ท๐˜‚๐˜€๐˜-๐—ถ๐—ป-๐˜๐—ถ๐—บ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—ท๐˜‚๐˜€๐˜-๐—ฒ๐—ป๐—ผ๐˜‚๐—ด๐—ต ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€: provide only the privilege required, only for the period it is required.

๐—ญ๐—ฒ๐—ฟ๐—ผ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐—ฐ๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—ฎ๐—น๐—น ๐˜๐—ต๐—ฒ๐˜€๐—ฒ ๐—น๐—ฒ๐˜€๐˜€๐—ผ๐—ป๐˜€.

Zero Trust is not a single tool or a one-time project. It is a security model built on the principle of โ€œnever trust, always verify.โ€

๐—” ๐˜€๐˜‚๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€๐—ณ๐˜‚๐—น ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ป๐—ผ๐˜ ๐—ฎ๐˜‚๐˜๐—ผ๐—บ๐—ฎ๐˜๐—ถ๐—ฐ๐—ฎ๐—น๐—น๐˜† ๐—ฟ๐—ฒ๐˜€๐˜‚๐—น๐˜ ๐—ถ๐—ป ๐˜‚๐—ป๐—ฟ๐—ฒ๐˜€๐˜๐—ฟ๐—ถ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€. Every access decision should consider signals such as:

๐Ÿ”น Identity and assigned role
๐Ÿ”น Device health and compliance
๐Ÿ”น Sign-in location and behavior
๐Ÿ”น Authentication strength
๐Ÿ”น Sensitivity of the requested resource
๐Ÿ”น User and session risk
๐Ÿ”น Whether the access remains necessary

Another key takeaway is that identity security extends beyond employees.

Applications, APIs, service accounts, automation tools, and cloud workloads all have identities. Without proper ownership, credential rotation, lifecycle controls, least-privilege permissions, and monitoring, these non-human identities can become invisible pathways into critical systems.

๐—ช๐—ต๐—ฎ๐˜ ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐—บ๐˜† ๐—ฟ๐—ฒ๐—ฐ๐—ผ๐—บ๐—บ๐—ฒ๐—ป๐—ฑ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ฏ๐—ฒ ๐˜๐—ผ ๐˜๐—ต๐—ฒ ๐—ผ๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜‡๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐—ถ๐—บ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ป๐—ด ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†:

โœ… Establish an authoritative identity source of truth
โœ… Automate joiner-mover-leaver processes
โœ… Design roles around least privilege
โœ… Perform risk-based access reviews
โœ… Remove dormant, duplicate, and orphaned accounts
โœ… Replace standing privileges with time-bound access
โœ… Strengthen MFA and move toward phishing-resistant authentication
โœ… Govern service accounts and workload identities
โœ… Integrate identity telemetry with SIEM and incident response
โœ… Treat identity governance as a continuous programโ€”not an annual compliance exercise

My fellowship is reinforcing an important truth:

Cybersecurity is no longer only about protecting the network perimeter. In modern cloud and hybrid environments, ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ต๐—ฎ๐˜€ ๐—ฏ๐—ฒ๐—ฐ๐—ผ๐—บ๐—ฒ ๐˜๐—ต๐—ฒ ๐—ป๐—ฒ๐˜„ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฝ๐—ฒ๐—ฟ๐—ถ๐—บ๐—ฒ๐˜๐—ฒ๐—ฟ.

The goal is not to make passwords so complicated that users need a haiku to remember them.

๐—ง๐—ต๐—ฒ ๐—ด๐—ผ๐—ฎ๐—น ๐—ถ๐˜€ ๐˜๐—ผ ๐—ฏ๐˜‚๐—ถ๐—น๐—ฑ ๐—ฎ๐—ป ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐˜๐˜† ๐—ฒ๐—ฐ๐—ผ๐˜€๐˜†๐˜€๐˜๐—ฒ๐—บ ๐˜„๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฑ๐—ฒ๐—ฐ๐—ถ๐˜€๐—ถ๐—ผ๐—ป ๐—ถ๐˜€ ๐—ถ๐—ป๐˜๐—ฒ๐—ป๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น, ๐˜ƒ๐—ถ๐˜€๐—ถ๐—ฏ๐—น๐—ฒ, ๐˜ƒ๐—ฒ๐—ฟ๐—ถ๐—ณ๐—ถ๐—ฒ๐—ฑ, ๐—ฎ๐—ป๐—ฑ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—ฒ๐—ฑ.

What is the greatest identity-security challenge facing your organization: privilege creep, access reviews, lifecycle automation, or non-human identities?

Article: https://lnkd.in/p/g_PdkmMQ

#Cybersecurity #IAM #IdentitySecurity #IdentityGovernance #PIM #ZeroTrust #LeastPrivilege #PrivilegedAccessManagement #InformationSecurity #EntraID

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top