IAM challenges in hybrid and multi-cloud environments
The modern IT infrastructure of Ukrainian companies combines on-premises systems with public and private cloud services. This blurs traditional corporate network boundaries, rendering outdated security approaches insufficient. In such conditions, Identity and Access Management (IAM) becomes a central security element, as errors in this area open direct paths to infrastructure compromise.
The growing complexity of hybrid environments increases the attack surface, as integrating cloud IAM with on-premises systems requires careful planning to ensure consistent security policies 1. This creates risks of unauthorized access, data breaches, and human errors. Situations where a terminated employee retains access to corporate resources or cloud services due to a lack of centralized control are particularly vulnerable.
Attacks related to identity theft increased by 45% in 2023 2. This necessitates a modernized approach to IAM that can encompass both human and non-human identities, ensuring transparent and manageable access in contemporary digital environments.
Least privilege and Zero Trust: Foundations of an IAM strategy
In an environment with a blurred network perimeter, the Zero Trust concept is mandatory for protecting corporate data and systems. The Zero Trust principle: “never trust, always verify,” means no implicit trust is granted to any access by default, even if initiated from within the corporate network 3.
A Zero Trust architecture focuses on specific resources, building protection around them using micro-perimeters. Each critical resource is isolated and has its own access rules. With every attempt, the system verifies the user and their role, the device and its state, the location and time of the request, and behavioral context.
A key element of Zero Trust is the Principle of Least Privilege, which involves granting users the minimum access necessary to perform their job duties 4. This reduces potential damage in the event of an account compromise. Implementing this principle includes regular auditing of permissions, using Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC), and automating identity lifecycle management.
Machine identity management: An underestimated aspect of cybersecurity
In hybrid and multi-cloud environments, not only people but also applications, services, APIs, automation, and AI agents access systems and data. These non-human identities (API keys, certificates, tokens) are proliferating, making manual control difficult. Traditional IAM primarily focused on human accounts, leading to excessive privileges, outdated service accounts, and uncontrolled API keys 5.
Compromise of machine identities can become an entry point for attacks 5. Therefore, managing their lifecycle, including creation, rotation, monitoring, and revocation, is critically important. It is essential to centrally define access rules for all types of identities, apply context-based policies, and ensure auditing of every access request in accordance with Zero Trust principles.
Ukrainian regulatory requirements and IAM: Ensuring compliance
For Ukrainian businesses, compliance with national cybersecurity regulatory requirements is mandatory. Protecting critical infrastructure is a matter of national security according to the Law of Ukraine “On Critical Infrastructure” [6].
The State Service of Special Communications and Information Protection of Ukraine (SSSCIP) updates cybersecurity requirements, approving new standards based on international frameworks such as NIST CSF 2.0. The draft amendments to the Requirements for Cybersecurity of Critical Information Infrastructure Objects have been published on the official website [7]. These requirements include asset inventory, risk assessment, and system compliance. For example, NBU Resolution No. 143 establishes strict requirements for the non-banking financial sector regarding the organization of information security and cybersecurity measures [8]. The Ministry of Defense has also approved an Industry Security Profile, which defines unified minimum requirements for cybersecurity of information systems [9].
An effective IAM strategy must consider these specifics, ensuring user action logging, creation of role-based access models, and automated report generation for auditors. This helps adhere to standards and demonstrate compliance during inspections.
Architectural approaches to IAM in the hybrid cloud: Choosing the optimal solution
The choice of an architectural approach to IAM in a hybrid/multi-cloud environment depends on business needs, existing infrastructure, and strategic goals. Various models exist, each with its advantages and limitations.
| Approach | Pros | Cons | Comments |
|---|---|---|---|
| Centralized IAM solutions | Simplified administration, unified security policies [10]. | Complexity of integration with complex on-premises systems, which may require additional resources and time [11]. | Unify identity and access management through a single platform. |
| Hybrid IAM solutions | Retention of control over key processes, leveraging cloud benefits, single sign-on [12]. | Require careful planning and synchronization setup [13]. | Synchronize on-premises identities with cloud identities, providing Single Sign-On (SSO) and centralized access management. |
| Native cloud IAM solutions | Ideal for cloud workloads, high granularity of control [14]. | Require careful integration into the overall hybrid strategy, may be less flexible for on-premises resources [15]. | Platforms such as AWS IAM or GCP IAM offer deep integration with cloud services. |
| Third-party tools | Extended capabilities, integration flexibility [16]. | Selection requires evaluation of compatibility, functionality, and needs, potentially higher implementation and support costs [17]. | Offer extended capabilities and integration flexibility with various platforms. |
The optimal approach often involves combining these models, with an emphasis on identity federation to create a unified framework that ensures a consistent security approach across both environments.
Practical steps to implement an effective IAM strategy
Building an effective IAM strategy requires a structured approach and continuous effort. Here are the key steps:
- Develop a clear IAM strategy: Define how the organization will manage digital identities and control access to systems. The strategy should outline user onboarding, role changes, and offboarding processes, authentication methods, and necessary security measures [18].
- Implement the Principle of Least Privilege: Regularly review and audit IAM permissions to ensure users have only the access strictly necessary for their roles. Use automated tools to identify excessive permissions 4.
- Apply a Zero Trust architecture: Treat every access request as a potential threat, regardless of its origin. Implement Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) for all users and devices 3.
- Manage machine identities: Establish processes for managing the lifecycle of API keys, certificates, and tokens. Ensure their rotation, monitoring, and revocation to prevent compromise 5.
- Automate IAM processes: Automate access provisioning and de-provisioning, as well as access request approval processes. This increases efficiency, reduces risks, and ensures scalability [19].
- Continuous monitoring and auditing: Integrate IAM data into centralized logging and monitoring systems to detect anomalies in real-time, conduct regular access reviews, and simplify audit preparation [20].
- Staff training and change management: Provide employees with training on new IAM policies and procedures. An effective IAM strategy requires not only technology but also adherence to best practices [21].
Checklist for auditing current IAM policies for excessive privileges
| Assessment criterion | Current status (Yes/No/Partial) | Comments/Risks | Recommended actions |
|---|---|---|---|
| Is the Principle of Least Privilege implemented for all human identities? | Review and adjust permissions, use RBAC/ABAC. | ||
| Are there policies for managing machine identities (API keys, service accounts)? | Develop and implement lifecycle, rotation, and monitoring policies for machine identities. | ||
| Is regular auditing of granted privileges and their use conducted? | Implement automated tools for auditing and reporting. | ||
| Is Multi-Factor Authentication (MFA) used for all critical systems and privileged accounts? | Expand MFA use, especially for remote access. | ||
| Are on-premises and cloud IAM systems integrated for unified management? | Consider hybrid IAM solutions for centralized management. | ||
| Do current IAM policies comply with Ukrainian regulatory requirements (e.g., critical infrastructure protection, personal data)? | Conduct a legal audit and adapt policies. | ||
| Are Zero Trust principles (e.g., continuous verification, micro-segmentation) implemented in your IAM strategy? | Evaluate current architecture, implement micro-segmentation and contextual access control. | ||
| Are access provisioning/de-provisioning and role change processes automated? | Implement automation to increase efficiency and reduce errors. | ||
| Is there a centralized system for monitoring and alerting on anomalous identity activity? | Integrate IAM with SIEM systems for proactive threat detection. | ||
| Is the cost of implementing and supporting IAM solutions evaluated? | Conduct a TCO (Total Cost of Ownership) analysis for various IAM solutions. | ||
| Are operational complexity and impact on user experience evaluated? | Conduct internal surveys and assess productivity impact. |
Softline IT helps plan and implement cybersecurity solutions: from current state audit to an agreed-upon change plan.
Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.
