sb-nz logo
Story image

Companies caught between crooks and compliance - Centrify

12 Jun 2018

Businesses in Australia and New Zealand are increasingly squeezed between defeating cyber-attacks and complying with surging volumes of government regulation, cybersecurity company Centrify says. Centrify is concerned that complying with the increasing amount of red tape required to retain personal information may hamper the ability of a business to protect that customer information successfully. Already this year, Australian companies have seen the implementation of national Notifiable Data Breach legislation and the mandating of GDPR regulations for businesses with a presence in Europe.

In addition, the Australian Prudential Regulation Authority (APRA) is currently developing a new proposed cybersecurity standard, CPS 234, planned to take force from July next year to further strengthen the Australian financial system.

In April this year, the New Zealand Government announced plans to refresh its three-year-old Cyber Security Strategy. Centrify APAC sales senior director Niall King says regulatory protection of information privacy is completely commendable.

“The challenge that faces companies is they have to defend against cyberattacks while also having to comply with multiple regulations from diverse jurisdictions,” he says. “In an ideal world, these two activities would be aligned, but the reality is that while companies must jump through bureaucratic hoops to demonstrate their regulatory compliance, the bad guys don’t follow rules, so they keep on innovating to find new ways to get illicit access to private data. “The bottom line is that if companies want to keep the crooks out and comply with government regulations, they need to rethink how they approach cybersecurity by putting identity protection at the centre of their defences.”

King says that in many cases, hackers did not try to break in through corporate defences.

“The fact is, they use the path of least resistance by deploying our own weak credentials against us,” he says. “Reports show that 81% of data breaches exploit weak, default or stolen passwords. That means four out of five breaches occur through a failure in identity protection. “Centrify advocates a model of Zero Trust Security which assumes that every user - whether inside or outside the network - is a potential threat, so we verify every user, validate their devices, and limit their access and privilege to what is required to do their jobs,” he says.

“Centrify also uses machine learning to identify risky user behaviour and apply conditional access without impacting user experience. King says, “Securing identity while still making it easy for employees and partners to do their jobs is the key to delivering cybersecurity and regulatory compliance.”

Story image
Netlinkz revenue surges 846% as secure enterprise cloud technology gains traction
Executive chairman James Tsiolis believes this growth is the start of something much bigger.More
Link image
Data is an organisation's most significant asset - here's how to protect it
Data resilience strategies are becoming more crucial as more value is ascribed to a company's data. If it's not stored securely and cost-effectively, expect problems.More
Story image
Just one click – that’s all it takes to let in cyber-crime
So how do organisations ensure that users are not compromised by simply doing their work?  The answer is surprisingly simple, writes Bufferzone Security business strategist for A/NZ Greg Wyman.More
Story image
Video: 10 Minute IT Jams - The benefits of converged cloud security
Today, Techday speaks to Forcepoint senior sales engineer and solutions architect Matthew Bant, who discusses the benefits of a converged cloud security model, and the pandemic's role in complicating the security stack in organisations around the world.More
Story image
Check Point acquires Odo Security to bolster remote security offering
The deal will integrate Odo’s remote access software with Check Point’s Inifinity architecture, bolstering the latter company’s remote security capabilities in a time where working and learning from home has become the norm, and looks to largely remain that way in the near future.More
Story image
CrowdStrike integrates with ServiceNow program to bolster incident response
As part of the move, users can now integrate device data from the CrowdStrike Falcon platform into their incident response process, allowing for the improvement of both the security and IT operation outcomes.More