Deloitte Reveals Eight Qualities of a Good Digital Identity Management Program
Growing consumer expectations, the breakdown of traditional “walls” and emerging technologies have given rise to a digital identity crisis. More than ever before, identity management is at the center of cybersecurity, regulatory compliance and consumer trust, and many organizations are struggling to define digital identity both internally for the enterprise and externally for consumers.
“In a digital economy, identity is a point of trust, perimeter of security and an index of customer satisfaction,” said David Mapgaonkar, principal, Deloitte & Touche LLP, and cyber technology, media and telecom sector leader. “Organizations should think about challenges related to both consumer and enterprise identity management to understand what they can do to create better outcomes. But it’s not easy — it requires managing relationships with many stakeholders and alignment on technology and funding.”
Read More: Looker Achieves AWS Retail Competency Status And Amazon Redshift Ready Designation
Deloitte shares top emerging trends and challenges shaping the evolution and management of digital identity:
- Rising global data privacy regulations pose compliance challenges: Identity, data privacy and regulatory compliance are increasingly overlapping. Cybersecurity leaders and executives are burdened with developing a more comprehensive view of their consumers to comply with legal and audit-related mandates such as the EU’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and the recommendations of the National Institute of Standards and Technology Cybersecurity Framework. This means that technology, cybersecurity, legal and business leaders are all stakeholders in effective identity management, each with their own challenges and ambitions related to user experience, system availability, resilience, risk management and consumer engagement.
- Digital identity lags on investment and priority: Cybersecurity teams must deal with legacy information technology (IT) environments and a resistance to migrate to cloud-first architectures. In the survey, 35.4% of poll respondents recognized upgrading legacy systems as a challenge to organizations employing identity programs. Nearly 18% of poll respondents selected lack of funding and sponsorship as a challenge. Either way, many organizations haven’t built modern systems that are API-based, orchestrated and enable easy integration with apps. And, investment into new systems and structures can be significant. Without an organization wide understanding of the identity imperative, sponsorship at an executive level can be hard to attain. Deloitte & Touche LLP’s 2019 Future of Cyber Survey found that 95% of C-suite level executives commit 20% or less of their security budgets to support identity solutions.
- Companies are reluctant to outsource identity management: Many cybersecurity leaders are concerned about integration, flexibility and access to specialized support with outsourcing their identity management to third parties. But third-party managed services, either on-premise or in the cloud, can offer the latest skills and capabilities, increase automation and future-proof identity systems. For example, 14.4% of poll respondents selected lack of talent and a skills deficit as a challenge for identity. With a cyber talent gap only growing, identity-as-a-service (IDaaS) may be a viable option for many organizations to empower innovation efforts and drive digital transformation.
- Responsibility and ownership are often distributed among multiple executives, teams (marketing, sales, cybersecurity, etc.) and IT systems, making coordination of large-scale projects challenging. The poll shows that 14.4% of respondents selected lack of executive prioritization and alignment as a challenge to impair identity from impacting digital transformation. Digital identity projects tend to take time and that can be a challenge for cyber organizations that may need to show immediate progress and broader return on investment. Many stakeholders increase complexity and timelines, and these critical programs are not getting implemented fast or well enough.
Read More: Relay Network Completes $30M Growth Capital Investment From LLR Partners
“An integrated digital identity program will provide organizations operational efficiencies and improve user experiences by powering digital transformation. In addition to the fact that regardless of what business you are in, we all need to know that what we share is protected, what we access is secure, and who we allow into our systems are supposed to be there,” said Mike Wyatt, principal, Deloitte & Touche LLP and cyber identity solutions leader. “An integrated approach can help prevent a future digital identity crisis from surfacing by building consumer trust and enabling both privacy and security.”
Digital identity is both a use case for blockchain and an enabler that allows each of the other assets for blockchain integration to exist. Other top use cases for digital identity, for example in government, include land and corporate registrations, voting, supply chain traceability and taxation.
Read More: ThousandEyes Names Former Zscaler, VMware, Citrix Sales Leader Matt Piercy As VP Of EMEA Sales