The plague of identity-related incidents continues to cause suffering across the cybersecurity industry, corroborated by Identity Defined Security Alliance’s (IDSA) report, 2023 Trends in Security Digital Identities, which revealed that 90% of organizations experienced at least one identity-related breach in the past year, a year-over-year increase of 6% (in 2022, 84% of organizations reported an identity-related breach).
While cybersecurity experts and leaders have made successive investments into technologies that focus on protecting digital identities, they must recognize that the significance of a secure, continuous flow of information-sharing processes is directly proportional to the number of digital identities an organization handles. In other words, the higher the number of digital identities, the more businesses are likely to suffer from identity-related incidents.
At the same time, businesses are grappling with the task of prioritizing the protection of numerous digital identities while also managing the smooth exchange of identity information between systems. This exchange needs to be seamless and efficient, ensuring adherence to policies and meeting audit and privacy compliance standards. Additionally, the emergence of AI, powered by pre-trained models and the use of cloud-based computing and open-source resources, further complicates the decision-making process for businesses.
Numerous leaders in identity and access management (IAM) and cybersecurity have observed this ongoing challenge related to the proliferation of identity and security tools. This not only poses difficulties in addressing functional gaps but also contributes significantly to security vulnerabilities. According to the IDSA report, 52% of respondents attributed the rise in identities to the increased adoption of cloud applications. This surpasses the impact of remote work (50%) and the introduction of additional mobile devices (44%), underscoring the required emphasis on identity-centric concepts.
Looking ahead, the convergence of evolving AI technologies, cloud-based systems, and the persistent expansion of digital identities presents a multifaceted challenge for businesses navigating identity and security landscapes. Adapting to this dynamic landscape will demand innovative solutions and compliant, identity-centric strategies.
Decentralized identity: start saying “goodbye” to centralized strategies
The issues revolving around the security of identities are multifold. A variety of attacks such as certificate fraud, fake credentials, lengthy verification processes and identity breaches are a few examples of how identities spread out across a multitude of applications or systems can be attacked and exploited.
Decentralized identity, also known as Self-Sovereign Identity (SSI), is a form of identity management that enables individuals to independently manage their digital identity without reliance on a particular service provider. To grasp the significance of decentralized identity, it’s crucial to delve into its building blocks: blockchain, verifiable credentials (VCs), and decentralized identifiers (DIDs). These elements play pivotal roles in shaping the landscape of decentralized identity.
- Blockchain serves as a super-secure, decentralized database shared among devices in a network—a virtual fortress that makes it challenging for any unauthorized alterations or compromises.
- Verifiable Credentials (VCs) function as digital counterparts to essential credentials, be they physical or digital. These are akin to a digital ID, securely encoded and ready to be presented to organizations seeking verification.
- Decentralized Identifiers (DIDs) act as personal digital nametags, created and cryptographically verified by the individual. It’s a way of asserting ownership over these identifiers and saying, “Yes, this is me.”
Understanding these elements, there are also a few factors fueling this trend toward SSI. While centralized identity may sound tempting from an administrative perspective, it can prove to be a nightmare for security and risk management leaders, especially with the recent surge in identity-related attacks. Imagine the following scenario.
Picture a kingdom overseeing two areas: one with numerous lakes (Area A) and the other with a single, large and expansive lake (Area B). These areas symbolize the identity landscape, housing critical data like usernames, passwords, and social security numbers. Now, imagine an invader targeting this identity environment.
The strategic choice is clear – Area B, a single lake rich in valuable identity-related data, becomes the primary target, fueling immediate and subsequent attacks. This scenario mirrors the cybersecurity landscape, where threat actors prefer targeting centralized systems (like Area B) over decentralized ones (like Area A).
The rationale behind this strategy lies in the inherent characteristics of decentralized systems, which introduce obstacles and complexities that impede unauthorized access. On the other hand, centralized systems, resembling the alluring large lake, naturally draw the attention of threat actors due to their concentrated and extensive reservoirs of information. With the growing incidences of identity-based attacks, it’s no surprise that the decentralized identity market is expected to reach USD $632.7M by 2032.
Regulatory bodies have also recognized the vitality of identity decentralization. The European Union (EU) has rolled out the regulation eIDAS 2.0, which is the expanded version of the UK and EU framework for Electronic Identification, Authentication and Trust Services (eIDAS). The new version expands its scope to encompass current technologies and services such as mobile identities, federated identity schemes, digital wallets and more. Decentralized digital wallets reduce the risk of credential tracking, unauthorized access and compromise by a considerable amount.
For an effective decentralized identity strategy, digital wallets are key in empowering users to store their digital identities securely with an emphasis on encryption.
Identity data engineering will empower tomorrow’s IAM
Within IAM, identity data engineering is a crucial aspect governing the design, implementation, and maintenance of IAM technologies to adhere to auditory and privacy compliance mandates. The driving force behind it is the right use of automation in every conceivable area.
Cybersecurity experts, managers and IAM technical professionals are responsible for enabling IAM data engineers to implement and optimize incorporated IAM services aligned with progressive technologies and regulations. They are also responsible for ensuring best data engineering practices are followed with a special focus on identity and access intelligence (IAI) paired with generative AI (GenAI).
Given that IAI is strongly reliant on identity data engineering, cybersecurity heads and IAM technical professionals will need to ascertain and enforce identity data engineering tactics and strategies, as well as advance IAI using GenAI.
In the quest for effective IAM, organizations often find themselves facing clear objectives but grappling with the challenge of finding efficient pathways to achieve them. Gartner’s 2024 Planning Guide for Identity and Access Management offers valuable insights into navigating this terrain, breaking down the journey into a comprehensible life cycle for managing identity data systems.
Here’s a simplified roadmap, inspired by Gartner’s guidance:
- Identify use cases: Think of it like developing a product – consider the quality, availability, interoperability, and reproducibility of identity data in various scenarios.
- Determine data needs: Tailor your data requisites based on IAM capabilities, such as adaptive access, policy information points, access modeling, and certification requirements.
- Architect data solutions: Develop a feasible data engineering architecture using skills like distributed system architectures, relational/non-relational databases, and effective data modeling and analysis.
- Build data pipelines: Leverage identity data catalogs and incorporate newer data sources, such as Human Capital Management (HCM) systems and external contractors.
Orchestrate data management: Implement continuous data and code testing practices to manage data, configuration, and infrastructure changes seamlessly. - Establish visibility: Swiftly identify and rectify issues by establishing clear visibility into identity and access data, ensuring the integrity and accuracy of information.
Pairing these recommendations with the power of generative AI can unlock remarkable outcomes. It’s akin to having IAM copilots or integrated queries guiding the way, understanding the nuances of IAI use cases.
In this journey, the development of an IAI architecture takes center stage. Picture it as a dynamic duo – the IAM GenAI model and IAM GenAI orchestration working hand in hand. This innovative approach will reshape the landscape of IAM, making it not just a necessity but a strategic advantage for organizations navigating the complexities of digital security.
Revolutionize IAM with analytics and generative AI
In the realm of AI within identity and access management, a crucial realization is that, despite the myriad implications of AI-driven IAM, AI is far from achieving perfection as of today.
That being said, organizations should begin preparations for the democratization of AI as organizations seek to embrace the technology. For instance, Gartner says that more than 80% of enterprises will have used GenAI APIs or deployed GenAI-enabled applications by 2026.
GenAI is set to make a leap in leveraging IAI for overall security, affecting the following IAM pillars:
- Authentication and authorization
- Governance and administration
- Auditing and compliance
Integrating GenAI with these IAM pillars is set to revolutionize how we perceive information intelligence. On the bright side, it offers a range of advantages, from continuous user authentication to analyzing behavioral biometrics. Gartner’s predictions indicate that by 2026, organizations actively prioritizing AI transparency, trust, and security in their operations will witness a substantial 50% improvement in the adoption rates, achievement of business objectives, and user acceptance of their AI models.
In the meantime, however, there are significant concerns. These include worries about privacy and compliance, along with challenges in building “trust” in identities. The lack of trust arises from limited visibility into GenAI mechanisms, data sources, and potential biases, causing reservations in implementing AI-generated outputs.
Gartner’s 2023 Hype Cycle for Generative AI suggests that the current landscape of AI risk management lacks consistency, making organizations susceptible to negative outcomes such as project failures and security breaches.
Arun Chandrasekaran, a VP analyst at Gartner stated that, “Inaccurate, unethical or unintended AI outcomes, process errors and interference from malicious actors can result in security failures, financial and reputational loss or liability, and social harm,” implying the need for AI frameworks that prioritize responsible AI delivery.
As we step into 2024, the IAM landscape continues to evolve, bringing both challenges and opportunities for organizational leaders. Decentralized identity, identity data engineering, and the integration of analytics and generative AI stand as pivotal pillars that will shape the success of IAM strategies in the coming year. Embracing these trends is a necessity for businesses striving to fortify their security postures, and will play a defining role in the strategic security blueprints of enterprises that will propel them toward a future of powerful IAM frameworks, enabling them to thrive in an ever-expanding digital world.

