Leveling the Playing Field: How SMBs Can Win at Identity Security

Dhivya Balasubramanian
Cybersecurity Manager
Amie Dsouza
Senior Manager - Security Products

Reviews

0
No votes yet
Automatic Summary

Leveling the Playing Field: Identity Security for Small and Medium Businesses

Welcome to our blog post where we delve into the essential topic of identity security specifically tailored for small and medium businesses (SMBs). In today’s rapidly evolving digital landscape, ensuring robust identity security is not just a luxury; it is a necessity for organizations of all sizes. Join us as we explore how SMBs can effectively protect themselves against identity-related threats while operating within budgetary constraints.

Understanding Identity Security

Identity security is the practice of managing and protecting user identities and their access to resources within an organization. At its core, it involves four main pillars:

  • Directory Services: This is the system of record where identities are created and maintained.
  • Identity Governance and Administration (IGA): Ensures the right access is granted, renewed, and removed.
  • Access Management: Governs how users authenticate and securely access applications.
  • Privileged Access Management (PAM): Adds an extra layer of protection for high-risk access.

As we look toward the future of identity security, we recognize significant shifts in identity types, including human identities, nonhuman identities (like service accounts), and increasingly, AI agents. Understanding these identity types is crucial as organizations seek to balance security, compliance, and user experience.

Challenges Faced by SMBs in Identity Security

Within the identity security landscape, SMBs face unique challenges:

  • Identity Sprawl: As organizations grow, managing and securing identities across various platforms becomes increasingly complex.
  • Lack of Resources: SMBs often operate with limited budgets and personnel, making it difficult to deploy comprehensive security tools.
  • Insufficient Visibility: Many organizations struggle with visibility into the identities that exist within their systems.

Practical Solutions for SMBs

While these challenges may seem daunting, there are several effective strategies that SMBs can implement to enhance their identity security without breaking the bank.

1. Focus on the Basics

Ensuring a solid foundation is key. Start by doing the following:

  1. Identity Discovery: Know what identities exist in your organization, including nonhuman identities.
  2. Inventory Management: Utilize tools that fit within your budget to manage and track all identities.
  3. Least Privilege Principle: Limit access based on necessity to reduce potential attack surfaces.

2. Consolidation of Tools

Instead of using multiple tools for different identity challenges, consider choosing platforms that address multiple needs. This approach simplifies management and reduces costs, making it easier for smaller teams to maintain effective security protocols.

3. Adopting Lightweight Frameworks

Instead of complex security frameworks, opt for lightweight versions that allow you to implement crucial security measures without overwhelming your resources. Consider frameworks like CSF Lite or ISO Essentials, which provide essential guidance without the extensive overhead.

4. Investing in Culture and Training

Technology alone does not secure an organization. Focus on cultivating a culture of security within your team:

  • Security Awareness Training: Educate employees about phishing, social engineering, and credential misuse.
  • Identity Hygiene: Teach teams how to manage and rotate credentials effectively.
  • Incident Response Preparedness: Conduct regular drills to prepare for potential incidents.

Key Takeaways

Effective cybersecurity does not rely solely on high spending; rather, it hinges on smart investments. Focus on:

  • Establishing visibility into your identity landscape.
  • Selecting appropriate tools that cater to your specific needs.
  • Fostering a well-trained workforce that understands the importance of security.

Next Steps for SMBs

If you’re looking to enhance your identity security practices:

  1. Assess your current identity landscape regularly.
  2. Identify quick wins that can help mitigate immediate risks.
  3. Gradually build your security program by employing lightweight frameworks and investing in training.

In conclusion, while the challenges SMBs face in identity


Video Transcription

Yes. Alright. Hey, everybody. I I'm not sure which time zones y'all are joining from, but over here, it's evening. So good evening.Y'all are here for the session on leveling the playing field, how small and medium businesses can win at identity security. I'm Divya Bala, and I get the privilege of working in cybersecurity, which is, you know, my passionate field. And I do that, everything I love, day in, day out as a cybersecurity manager at Southwest Airlines. I am here representing myself out of my passion for identity security to learn things that I have, you know, read through in many forums based on talking with practitioners, seeing, like, real real time issues and not representing that of my workplace. Over to you, Amy.

Hey. Thanks, Divya, and hi, everyone. This is Amy. I'm also, in a similar field like Divya. I've been in cybersecurity for almost a decade now. Ex expertise is in identity and access management and a few other, like, neighboring areas. And we are I'm really excited to be here today bringing this really interesting topic on how small and medium businesses can win at identity security because the landscape is constantly changing. Lots of new challenges we see every day, and not every organization has big budgets to buy each and every tool. So we are giving you some tips and tricks on how small and medium businesses can also play this game and level the playing field. Alright. Okay. This is the agenda. So we will cover the identity security landscape. What are the top challenges in this area?

A few options, for small and medium businesses on how you can go about facing these challenges. And in the end, we will wrap up with key takeaways and next steps. We also will be here if there are any questions. Okay. This is a poll for just to understand where you are at. You can either scan this QR code, which will take you directly to Slido, or you can go to slido.com and enter the PIN on the screen that is 8227001 and answer this question. And I'm going to do that now as well. So for folks who just joined, we are answering this question on Slido. Like, what is your biggest identity and access management challenge today? K. Seems to be changing a little bit.

Alright.

So, yeah, the biggest one from the the audience here seems to be identity sprawl, which is true. The traditional I'm used to manage roles and access for on prem solutions, and now we have cloud, we have AI, we have nonhuman identities. It's just that boundaries keep on exploding every time we have every time we're talking about this, like, there's a new challenge. K. Let's talk a little bit about the cybersecurity landscape. So I am at its core in the foundations of I am sort of remain the same no matter how much is changing. Right? Like, there are four main pillars, and we sort of are constantly building on top of that, layers and layers on top of that.

So your four main pillars of identity and access management are starting from the left, the directory services. Directly services is the system of record where identities are created and maintained across employees, contractors, systems, nonhuman identities, agents, all of that. Then we have IGA, your governance, identity governance, and administrative system. This ensures right access is granted, renewed, and removed during and this drives compliance certification and life cycle management of identities. Then we have access management, which governs how users authenticate and securely access applications. This leverages capabilities such as single sign on, multifactor authentication. You might have heard these terms. And lastly, we have privileged access management, which serve accent as extra layer for high risk access, sensitive information, databases, servers, protecting critical systems through monitoring, just in time access, and tighter controls.

So together, these principal pillars enable organization to balance security, compliance, and user experience, ensuring access is not just granted, but it's governed, monitored, and constantly optimized. Now as environments become more complex, like I mentioned, cloud, SaaS, automation, IAM becomes even more critical. It shifts from a control function to a more strategic enabler of business agility and risk reduction. When we look at identity security in 2026, the landscape has fundamentally changed. We have now three distinct identity types. Right? We have our human identities, that's our workforce. We have the nonhuman identities, which is your service accounts, APIs, machines, which is rapidly growing. Last I heard this number is one is to 40. For one human, there would be 40 nonhuman identities. And are we ready to, you know, manage that scale of identities?

And the third one category is what is increasing rapidly is AI agents. So autonomous systems making decisions, taking actions, often with delegated access. The key point is identity is no longer just about people now. It's about everything that can access your systems. The risk is not in one category, but the gaps and how we are how we are fixing the gaps between all of these different identities. Leading organizations are shifting to a holistic identity strategy, one that brings all three under one single governance to reduce risk, improve visibility, and enable innovation security.

So these human, nonhuman, and like Amy said, right, these nonhuman and agentic identities, these together form the complete identity fabric of your organization. And the thing about fabrics, like, you know, women know better than men, is only as strong as its weakest thread. So let's talk about where that fabric is actually beginning to tear. Alright. So identity is not just an attack surface anymore. It's become the attack surface. Not malware, not zero days, but just compromised credentials. What you see on the screen is actually a very small subset of well documented, publicly available breaches. Today, we're focus on the patterns that emerge from observing many such breaches rather than focus on the specific of just the incident itself. Let's start with human identities. Yeah? Every human identity breach shares one goal. Someone is trying to be you. So how do they become you? Well, I share two really well known ways.

First, they steal your credentials through phishing or info stealers, or they crack your account through brute force, password spraying, credential stuffing, etcetera. Well, even if you think you have, like, a really good password hygiene, you have MFA, there is still another way that an attacker can become you. They could install malware in your system, wait for you to complete your login and also your MFA challenge, and then steal your authenticated session cookie. It's not easy anymore. And sometimes, the human is just a starting point. They compromise you to then actively compromise these nonhuman identities that you have access to. And sometimes, there's no human in the chain at all. Sometimes developers leave an API key hard coded in a repo, a service account token in a misconfigured Docker image, an OAuth token in an archived code base.

But with all that, the attackers didn't even have to make an attempt to steal it. It was just left out in the open. And if you're thinking, okay. So what if they have my API keys or service account or OAuth token? What could they do with that? Well, having access to these NHIs is not the end state. It could be the beginning of your attack surface based on what level of permissions your NHIs have. Because according to the 2025 state of nonhuman identities report from Entra Security, it's found that 97 percentage of NHIs have excessive privileges, and just point zero one percentage of machine identities control 80 percentage of the cloud resources. And that's it with you for a moment. Yeah? And these human breaches that we talked about, you're probably very familiar with that story. Right? But maybe these nonhuman identity breaches is new to some of you. And if you're sitting there thinking, wait. We have identity and access management tools. We have governance processes.

Why can't we use those same systems for these NHIs and AI identities too? It's just an identity. Right? Well, that's a great question. And the honest answer is those systems were mostly built with humans in mind. They were never designed for the scale, the behavior, or the sprawl of nonhuman identities. And let me show you why. Like Amy mentioned earlier. Right? So traditionally, IAM is considered to be of, like, four pillars. It just start with directory services. In organizations of any size, small, medium, large, doesn't matter. To manage us, like, for humans, we will have a centralized directory, the birthplace of an identity, if you will, like our HR systems. For nonhuman identities, a central location is challenging because they're not born in a central place. It's born, like, everywhere, in your CICD pipelines, in your repos, everywhere.

The second pillar, IGA, the governance pillar, for people, we have something called a joiner lever mover I mean, joiner mover lever process. And that basically defines the access you get when you join, when you change teams, or when you leave the company. Right? And we also do periodic access reviews to keep it, like, honest. But will that process actually scale for these nonhuman identities? Now imagine I have, like, a team of 10 folks, and I review their access. Like, just to make sure the access is still accurate, I review them periodically. It's painful, but it's doable. But if I have to do periodic reviews for 500 nonhuman identities, then periodically, I need a double paycheck because it is a full time job. Right?

The third pillar, access management. That's been, like, you know, you if you're if you're in your organizations, you have single sign on. So when you log in to some UI, you do SSO, you do MFA on top of it. Now how can an NHI SSO or MFA? Well, for all I know, and one day in the future, it might, but it can't do that yet. Finally, privileged access management. Like Amy mentioned, it's for all the super users with superpowers. And, again, most of the PAM solutions are secret centric, and they're not identity centric. Well, I know that was really a lot to take in. Right? And especially if you are a part of a small team wearing multiple hats, it could be pretty scary. But here's the good news.

You don't have to solve the whole problem at once, but you just need to start. For small and medium businesses, they do not lose to attackers because they lack a million dollar security stack. They lose mostly because the basics is sometimes not done right. Some of the bridges that we just covered or we just looked in the slide before, they actually could have been prevented or at least severely limited using a few ways that we're about to cover. Let's begin by focusing on the basics. If you don't know what identities exist, you cannot govern them, period. So first, define your baseline. By now, I hope, like, all small and medium businesses, like, everyone has one form or the other besides Excel sheets to handle your human head count. If not, please fix that first. So once you have your humans accounted for, next is the harder and often more invisible problem, asset discovery of your nonhuman identities.

Good news is small and medium businesses have lesser identities sprawl compared to larger organizations. So start now before you grow bigger. Find all the places your API keys, your service accounts, your OAuth app tokens, wherever it is. Find it wherever it is used. But if finding all those pesky API keys are like finding Lego pieces in your carpet, well, you might have to look really hard or just take a power vacuum. Else, it's gonna hurt you one day when you least expect it. So once you're done with the discovery, next is inventory. There are so many tools out there for that. Find one that fits your budget. Next, map all the applications and systems that these NHIs have access to. Let's say, for example, like API key one two three, that can access your HR data.

Then you have this OAuth token, which gets grants permissions to your company's financials, and so on and so forth. Finally, classify them by sensitivity. You actually did that classification in two important moments. First, when you're deciding to grant access, you must know what's behind door number one. Second, the case of a breach, god forbid, it should not happen. But if it happens, you need to know the level to which you need to freak out. Let's say your NHI to a weather information got breached. It's sort of okay. Right? But if you're NHI to your company financials got breached, you better go DEFCON one. Alright. So assuming by the end of this, you now have, like, a very clean baseline, second, apply security. And what do you see in this section is basically all the buzzwords you hear everybody say. Right?

So if you were to pick one, please MFA your humans if you haven't already. That's nonnegotiable. Next, make sure that these IDs can only access what they need to. That concept is called least privilege, and sometimes it's actually easier said than done. And I would actually throw a word of caution here, especially to organizations that have highly sensitive information. If you're finding it hard to maintain least privilege for humans, then please think twice before you deploy agentic AI use cases in your organization. Because with agentic AI, along with you adding nice capabilities, you're also adding a new attack surface. Because AI doesn't just use identities. It creates, it multiplies, and it acts on it autonomously. So first, figure out a system to manage least privilege and then scale your use cases with AI. Finally, secrets.

Please do not permit developers to hard code secrets in code. There are secret managers management tools with free tiers, so no excuses there. The third, monitor and respond. What we saw so far puts you in a much stronger position and reduces your risk, but no security posture is airtight. So always be prepared, and that means setting up monitoring, alerting, and a response plan is not optional anymore. Well, if the first thing, the SIEM integration sounds like very fancy, expensive, and enterprise y, you and don't have one, don't worry about it. You can start with just the threat detection services that are available for a cost, of course, in most cloud providers. Turn it on and set up behavioral based alerting. For example, let's say, like, you know, you're spotting a login from a geolocation that you do not operate in. Right?

Or maybe there's an abnormal usage to certain sensitive services that we classified in step one. Let's set up an alert. And once the alert starts to flow, you have to create a response playbook. And, again, one more word of caution here. Just make sure you don't alert fatigue around the team. Right? Because that is as good as not having any alerts at all. Lastly, and the most least focused area in most organizations, life cycle management. The goal here is that no credential lives forever, and no identity exists without an owner. So periodically perform access reviews, clean up your orphaned accounts, enforce policies, and try to automate wherever you can. Just apply a simple rule. If an identity hasn't been used in ninety days and no one can tell you why it exists, then poof it goes.

The reason this slide is called focus on the basics is because basics are where SMBs can actually win. You do not have to try to out resource a nation state actor, but you can definitely try to be harder to hit than the next target. So do these things consistently, and you will close the attack vectors behind majority of the breaches that we discussed a little while ago. Okay. Let's

look at solution number two for small and medium businesses. The biggest challenge often for small and medium businesses isn't just security. It's also doing more with limited resources and teams. A common mistake is adapting separate tools for every need. One for MFA, another one for privilege access, another one for secret, another one for logging. This quickly becomes hard to manage, expensive, difficult to integrate, especially without a large cyber team. Instead, the smarter approach is consolidation. Choosing platforms that solve multiple identity problems in one place. It may not be perfect, but you can make it work for your organization. This means fewer systems to maintain, simpler audits, and faster onboarding.

So being extremely intentional on what tools you're using and picking so that, you know, you don't overdo it and don't overburden your team. As your business grows, having an API friendly and a scalable platform ensures that you can support your employees, systems, and even emerging AI use cases without constantly adding new tools. In short, this approach, which is it's much easier said than done because there are just so many tools out there in the market. It's very tempting to try and solve every problem with the tool. But having this approach at the back of your mind when you are looking for tools will will definitely help smaller teams to operate with enterprise grade security, but don't take on that complexity of having multiple tool multiple technologies. It comes with also upgrades, end of life, and other tech tech as well. It's not just about buying tools.

This is we put this together just to show you how many players are in the market, how many vendors are in the market for each of these different requirements in within your workforce identity, customer identity, and nonhuman and workload identities? There are so many different vendors, so many options out there. And it's very tempting to try and solve every problem with a different vendor, different tool, but look for options which give you a more integrated identity solution, identity platform rather than picking one from each and every area. Some more in the agentic AI space, if you wanna just get back one here. So there's a few more tools in the governance, NCP servers, and agentic identity agentic space. So, again, this this this space is just growing and exploding. So and we totally understand how what small and mid medium businesses must be going through. It's very confusing to pick the right tool.

But keeping the values in mind that we don't wanna make it too complex. We don't want to have too much dead dead. We don't have too many people, so let's get fewer tools. Keeping this in mind with every product decision you take will help you a long way. The third solution is using lightweight frameworks. Now one of the biggest misconception in cybersecurity is that you have to adapt extremely heavy and complex frameworks to be secure, and that's not true. Traditional frameworks like the NIST CSF, ISO 2,701 were very comprehensive, but they can take years to implement, and that is not practical for small organizations with leaner teams. The smarter approach is to right size the framework for your organization. Start with lightweight versions, such as the CSF lite or ISO essential.

These are designed to give you a strong security foundation without too much overheads. They will help you focus on what matters most without slowing your business down and having to buy multiple tools. The next part would be sort of to layer in focus and high impact price practices. And some of them are zero trust basics. Not the whole zero trust architecture, but there are zero trust basics that you can adapt. Role based access, which is the most basic form of identity and access management, and just in time access, which is extremely useful in these days because of the different type of identities. Just give them what they need and when they need it, and that's it. These controls deliver immediate risk reduction without requiring a massive transformation.

If you want to adapt a heavyweight framework, it's going to take a lot of time. It's going to take a lot of people, and most small and medium businesses do not have the time or the resources. So these frameworks are your options. And you don't need to do everything at once. You you can pick one framework or one concept, like least prevalent access, and run with it for a few months. Then you pick the next one. You can you can sort of layer it as well. Solution four for small and medium businesses is to invest in culture and training. Technology alone does not secure an organization, and this has been proved over and over. People and culture play an equally critical role. For small and mid sized organizations, especially investing in training and awareness, this is one of the most effective ways to reduce risk without adding new tools and head counts.

First, security awareness. Ensuring your employees can recognize simple stuff like phishing, social engineering, and credential misuse. This helps stops threats at the at the front door. I mean, e even now, 80% of the breaches are due to humans somewhere in the mix. Security awareness. Ensuring employees can recognize sorry. The next one is identity hygiene, teaching developers and operations teams how to manage credentials, rotate secrets, and apply least privilege. So just make it a discipline to keep your identity environment hygienic. Just the way the way you like to keep yourself and your house clean. So it's the same way. Others, you're constantly collecting tech debt, and you're making it insecure as well. Third is incident response, like readiness for an incident. Even simple table doc exercises can significantly improve response times and minimize impact when something does go wrong. And reduce burnout.

When everyone shares security responsibility, the burden doesn't fall only on the cybersecurity team. It's a shared responsibility. So cultivating that culture will help any organization, especially small and medium organization, a long way.

Yeah. Thanks, Amy. I mean, just to recap the key takeaways. Right? Like, very crisp information here. Effective cybersecurity isn't about spending more. It is about spending smart. Please don't turn turn your cybersecurity investments into, like, how I go on a Black Friday shopping. And if you go, like, oh, that air fryer is the lowest it's ever been in three years, I need that. Oh, no. You don't. You already have one sitting in your kitchen counter. You have to use that, or at least that's what my husband keeps telling me. So, no, the goal is not to have the most tools. It is to have the right ones. So with full visibility into your identity landscape, the right tools, light frameworks, and a well trained workforce, you will definitely make yourself a very hard target to hit.

And a few next steps for anyone who started so starting on the journey and mid journey doesn't matter. You can always stop and assess where you are. Assessing your environment every now and then with is is a is a great step. It's like taking inventory of all of your identities, human, nonhuman, emerging AI. Most organizations are surprised by by how many nonhuman identities already exist and how little visibility there is. Second, let's focus on those quick wins. You don't need a multiyear transformation to make progress. Start by addressing your biggest risk. Is it access sprawl? Is it weak authentication? Is it unmanaged service accounts? Look for those challenges that can which have a ready solution. You've just not got to it. Look at that as a quick win and go for it. And then build your program over time. Introduce life cycle controls.

Adopt lightweight frameworks and invest in training and security awareness within your This is how you sustainably scale security, not through a big bang implementation, but through steady maturity. Yep. And that's what we the Vienna I wanted to share with you all. If you'll have any questions on how we could help small and medium businesses get started or just generally help along their journey identity security journey, we'll be happy to answer any questions.

Yep. Thank you all so much for your time. Can feel free to connect with us on LinkedIn. Any questions you all have, we're both really happy to answer that. Again, thank you so much for your time today.

Do you wanna take that question, Divya?

Yeah. Sure. What signals indicate an SME has outgrown its current identity practices? When I I personally feel when you have, like, a resource burnout. Right? Because when you're not able to, like, understand, okay. Well, who has what access anymore? You really have to dig through, like, 10 different layers for you to even answer the question as to who can access what. That is when you'll have to, like, start revisiting, start rethinking what kind of tools you have. Right? Because, basically, even with AI and all of these things coming in, the biggest biggest concern is the authorization. Who can access what and when? Right? That's basic identity security. If you're not able to answer that within thirty seconds, then I guess it's time for you to start, revisiting your strategy completely. Amy, anything you wanna add to that?

Yeah. And other signals is, I would say, if you're constantly getting certain kind of incidents or monitoring alerts which require, you know, a solution. For example, password issues or people getting logged out. You you might need to see you might you might need to check you know, devices have changed these days. MFA, SSO, you know, every everything is sort of progressing in different ways. If your identity practices are a few years old, they may not be able to keep up with the different kind of devices, hybrid devices, Mac, you know, Windows, mobile devices. So identity practices need to be updated as the other environments infrastructure is growing as well. And cloud is another big one. Cloud and AI, if you're not addressing both these spaces depending on your landscape, then you haven't you you haven't yet even scratched the surface on how complex that that piece is.

So, yeah, I would say the next thing after traditional IAM is cloud and agenda.

Oh, good point, Amy. Good point. Alright. Cool. I think your full minutes over. Thank you all. Really nice seeing everyone of you here. Hope to connect with you all soon.