Where does digital security end and tangible, or physical, security begin? In today’s cybersecurity ecosystem, I’d argue that it’s all just security. In fact, if you are handling these domains in discrete silos, your cyber resilience is already taking a hit.

If your identity and access management (IAM) and physical security initiatives are not working as one, your organization may be suffering from unnecessary grief — and increasing risk.

When Physical and Digital Security Became One

Pinpointing exactly when these two previously discrete functions became one is up for discussion, and some may not even agree that they have become one at all. Regardless, it will be hard to envision them as discrete issues for much longer, particularly as the industry pushes the digital transformation envelope.

At the most basic level, IAM is a username/password credentialing system that gives one layer of authentication. Best practices say to have some second or multifactor authentication (MFA) procedure as part of the process. But this is a more basic question: Even if you’re using MFA, ask yourself, with today’s deceptions, has an identity truly been authenticated?

Not exactly, because in the scenario described, we are only authenticating credentials, not identity. Similar to physical identity and access management (PIAM), which unifies your physical and IT security systems, there is something called dynamic identity management, a next-gen solution gaining some support from major industry players that makes an effort to address the identity issue.

To best explain dynamic identity management, think of a mishmash of facial recognition, internet of things (IoT) sensors and monitors, and risk profiling. You walk into your workplace, a facial recognition system verifies your identity and, based on the risk profile assigned to you, you are allowed access to certain areas, both physical and digital, of the enterprise’s assets.

This certainly sounds like a combined solution that addresses both IAM issues and physical security challenges. From a security perspective, this approach looks fantastic.

But it’s also a brewing privacy nightmare.

Where Security Meets Privacy at the Workplace

Employers and employees generally expect some oversight and monitoring of behavior to occur in the workplace. But when the combination of identity and access management and physical security turns into a form of continuous monitoring that captures what time you get up from your desk and which bathroom in the office you’re using, it’s only a matter of time before privacy is violated.

Furthermore, if the security restrictions become too strict, you end up impacting workflow. Can you imagine what hospital operations would look like in the ER if a doctor or nurse were slowed down due to some IoT sensor failing?

With all the new technological innovations happening right now, it’s a short hop, skip and jump from robust security to behavior control in the workplace — something that, paradoxically, can kill the innovation of organizations. Building out your combined solution will always go back to your risk tolerance. The IBM Institute for Business Value (IBV)’s executive report, “Digital Transformation: Creating New Business Models Where Digital Meets Physical,” captures the essence of this security challenge: “The challenge for business is how fast and how far to go on the path to digital transformation.”

Put differently, before an enterprise makes a decision about which digital transformation path it will take, it should have a relatively good sense of what its security posture should look like post-transformation. Not defining the expected end state can create a huge blind spot that will not only impact security posture, but will also impact business operations as a whole. What’s more, you need to ensure your transformation is trusted by your users, otherwise you’re increasing the likelihood of legal challenges and ethical dilemmas coming toward your enterprise.

Don’t Be Afraid of Low Tech

For the reasons outlined above, there’s a case to be made for some more “archaic” solutions. These include sound human intelligence, situational awareness, and good old-fashioned holistic assessments and education campaigns. For all the gadgetry you integrate into your enterprise, at least in 2019, there is no replacing the gut instinct and human innovation. After all, it is human innovation — albeit sometimes with technical assistance — that circumvents security measures.

The “human touch” needs to be a critical part of identity and access management and physical security systems. The human is where these two issues meet, and trying to move all human security interaction to something more passive will ultimately raise your risk profile, not lower it.

Which is better positioned to see if something is amiss: an IoT sensor, or an employee who knows Johnny shouldn’t be in that part of the building? These are the small vulnerabilities we need to be sensitive to, because for all the wonder and benefit that things like artificial intelligence bring to cybersecurity, we still want to ensure that we are using this great technology as a tool and not a crutch.

Looking further into the future, as you consider which digital transformation strategy will best meet your security needs, remember that there is a technological wildcard waiting to play in the big leagues: quantum computing. Quantum computing has the capability to obliterate credentialing systems as we know them today. We’re not dealing with apples-to-oranges comparisons here — it’s more like apples to locomotives. When quantum computing takes hold, we will not be talking about digital transformation anymore, but instead, quantum transformation.

Key Digital Transformation Takeaways

Because there is so much going on in this space today, it’s worth summarizing some key takeaways.

First, identity and access management and physical security tasks need to be dealt with as one joint task, not two separate ones. Treating them as separate may be a sign that your teams are not aligned internally.

Second, next-gen identity and access management systems, such as those that integrate biometrics and IoT sensors, have incredible potential, but also come with intangible concerns, such as privacy issues. These issues need to be addressed concurrently as part of any digital transformation effort.

Third, before any digital transformation undertaking, make sure you know what the end state is supposed to look like. Not only might you be building more risk and fragility into your system than you bargained for, but new technologies on the horizon may completely alter the expected return on your investment.

Lastly, don’t overlook the human component when facing the digital/physical security challenge. Humans are the glue that connect these two realms — and a critical part of successful digital transformation.

More from Identity & Access

CISA, NSA Issue New IAM Best Practice Guidelines

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently released a new 31-page document outlining best practices for identity and access management (IAM) administrators. As the industry increasingly moves towards cloud and hybrid computing environments, managing the complexities of digital identities can be challenging. Nonetheless, the importance of IAM cannot be overstated in today's world, where data security is more critical than ever. Meanwhile, IAM itself can be a source of vulnerability if not implemented…

4 min read

The Importance of Accessible and Inclusive Cybersecurity

4 min read - As the digital world continues to dominate our personal and work lives, it’s no surprise that cybersecurity has become critical for individuals and organizations. But society is racing toward “digital by default”, which can be a hardship for individuals unable to access digital services. People depend on these digital services for essential online services, including financial, housing, welfare, healthcare and educational services. Inclusive security ensures that such services are as widely accessible as possible and provides digital protections to users…

4 min read

What’s Going On With LastPass, and is it Safe to Use?

4 min read - When it comes to password managers, LastPass has been one of the most prominent players in the market. Since 2008, the company has focused on providing secure and convenient solutions to consumers and businesses. Or so it seemed. LastPass has been in the news recently for all the wrong reasons, with multiple reports of data breaches resulting from failed security measures. To make matters worse, many have viewed LastPass's response to these incidents as less than adequate. The company seemed…

4 min read

Cybersecurity in the Next-Generation Space Age, Pt. 3: Securing the New Space

8 min read - View Part 1, Introduction to New Space, and Part 2, Cybersecurity Threats in New Space, in this series. As we see in the previous article of this series discussing the cybersecurity threats in the New Space, space technology is advancing at an unprecedented rate — with new technologies being launched into orbit at an increasingly rapid pace. The need to ensure the security and safety of these technologies has never been more pressing. So, let’s discover a range of measures…

8 min read