We recently caught up with Scott Carlson, a thought leader and user expert of identity and access management-as-a-service (IDaaS), also known as cloud IAM. Based on the security leadership positions he has held at PayPal, Charles Schwab and Apollo, Carlson shared his experiences in adopting cloud for identity and access management (IAM).

Life Before IDaaS

Question: Let’s start from the beginning, Scott. What was your life and the lives of your peers like before IDaaS?

Carlson: The largest challenge during my career with traditional IAM solutions is that they required significant funding and very specific expertise in order to keep the infrastructure working, the software stable and then even more people to build roles, modify code and deploy related features. Almost every IAM solution has an authentication provider such as Active Directory or LDAP — software that provides a directory of roles. And everything lives on middleware to tie it all together.

Of course, there are a number of headaches associated with doing this all internally. First, you need very specific skills in the infrastructure all the way through the application stack. Also, the cycle of upgrades lags behind because you have to version-control every piece of the infrastructure to ensure that it is functioning across all dependencies.

Lastly, it’s expensive, and management loses focus a few years into the project because everyone is past the point of excitement about there being a new way to manage privileges. You’re simply into the work part of the cycle. I’ve seen very few interested in continuous investment to keep an on-premises IAM environment upgraded and stable.

Get My Cloud TCO Assessment Now

Life With Cloud IAM

Thanks for outlining specific headaches security professionals face without an IDaaS solution. Now, can you please share with us how cloud IAM makes those headaches go away?

For the vast majority of companies, there is no need to customize the environment to such a point where a whole IAM team is required to be within the organization. Additionally, with all the in-house and SaaS-type tools, which most companies use, building a network that allows access to those external things can be eliminated with enterprise cloud IAM solutions. This allows in-house experts to interact with the IAM solution in a way that drives business value out of your applications rather than babysitting infrastructure.

Since the costs of IDaaS are known ahead of time, you can plan on a consistent road map of features and upgrades against your business applications. Moreover, you can let the IDaaS vendor worry about the dependencies of the interworkings of the tool, meaning there will never be a huge uptick in cost to build out an entire infrastructure. Because you don’t have to buy, build and then deploy, cloud IAM allows for faster adoption of the methodologies and the technologies. You can just deploy.

Minimizing the Risks With Cloud IAM Adoption

Scott, before we wrap, can you share some advice to CISOs and other security executives who are considering IDaaS?

Security experts reside in most companies that provide IDaaS and other cloud-based IAM solutions. It’s accurate to say they are “better experts” than you and your company. Rely on these best-of-breed cloud IAM solutions and hold them accountable to providing world class security.

Often, your being able to do identity and access management partially right on site is far worse than relying on an expert who does it for a living, building a solution to the highest level required by any customer.

More from Cloud Security

Why security orchestration, automation and response (SOAR) is fundamental to a security platform

3 min read - Security teams today are facing increased challenges due to the remote and hybrid workforce expansion in the wake of COVID-19. Teams that were already struggling with too many tools and too much data are finding it even more difficult to collaborate and communicate as employees have moved to a virtual security operations center (SOC) model while addressing an increasing number of threats.  Disconnected teams accelerate the need for an open and connected platform approach to security . Adopting this type of…

Cloud security uncertainty: Do you know where your data is?

3 min read - How well are security leaders sleeping at night? According to a recent Gigamon report, it appears that many cyber professionals are restless and worried.In the report, 50% of IT and security leaders surveyed lack confidence in knowing where their most sensitive data is stored and how it’s secured. Meanwhile, another 56% of respondents say undiscovered blind spots being exploited is the leading concern making them restless.The report reveals the ongoing need for improved cloud and hybrid cloud security. Solutions to…

Cloud security evolution: Years of progress and challenges

7 min read - Over a decade since its advent, cloud computing continues to enable organizational agility through scalability, efficiency and resilience. As clients shift from early experiments to strategic workloads, persistent security gaps demand urgent attention even as providers expand infrastructure safeguards.The prevalence of cloud-native services has grown exponentially over the past decade, with cloud providers consistently introducing a multitude of new services at an impressive pace. Now, the contemporary cloud environment is not only larger but also more diverse. Unfortunately, that size…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today