State of Enterprise Secure Access Report Highlights Operational Deficiencies as Organizations Grapple with Hybrid IT Complexities and Zero Trust Controls
Summary
The survey of large enterprises in the US, UK and DACH uncovers business risk and impact resulting in a pivot towards extending Zero Trust capabilities to enable productivity and stem exposures to multi-cloud resources, applications and sensitive data. According to the report, the shift in how organizations deliver Hybrid IT services to enable digital transformation must also take into consideration empowering a mobile workforce, supporting consumer and IoT devices in the workplace and meeting data privacy compliance obligations – all make for a challenging environment to ensure, monitor and audit access security. The survey revealed the top access threat mitigation deficiencies: When survey participants were asked what they perceive as their largest operational gaps for access security, the majority identified hybrid IT application availability; user, device and mobile discovery and exposures; weak device configuration compliance; and inconsistent or incomplete enforcement. It encompasses proving identity, device and security state before and during a transaction; applying a least privilege access closest to the entities, applications and data; and extending intelligence to allow policies to adapt to changing requirements and conditions. 91% of enterprises plan to increase secure access expenditure over the next 18 months; 30% anticipate an increase spend between 15% to 25% 44% of enterprises use data center in conjunction with public cloud, 30% in conjunction with private cloud, and 26% utilize all three delivery environments 46% of large enterprises prefer data center and private cloud; primarily preferred by financial services and U.K.-based companies 49% or more cited significant access incidents due to malware, unauthorized and vulnerable endpoint use and mobile and web app exposures - healthcare organizations experienced greater mobile and web app exposures 81% expressed gaps in hybrid IT application availability - financial services experienced the most business impact related to application availability 78% indicated need for greater visibility of users, endpoints and mobile devices; more evident in large enterprises and those in the DACH region 42% will focus on refining privileged user or service account-based access – a top priority in financial services and manufacturing 56% stated a project or pilot of Software Defined Perimeter technology over the next 18 months Over 38% of respondents outsource secure access capabilities to Managed Security Service Providers (MSSPs) with additional MSSP usage to grow 10% by 2021 The independent research for the report, which offers key insights into the current access security landscape and the maturity of defenses, was conducted by IDG Connect.