
Pic: Hemangini Tandel, Head of Identity and Access Management, Ramsay Health Care
There is an often-quoted phrase in cybersecurity that suggest security is like the brakes on a car, in that they enable an organisation to go faster because you know you can stop when you need to.
At the risk of stretching an already troubled analogy, if security is the brakes on the car, then identity and access management is the gearbox.
Throughout Clutch Events’ Melbourne Identity and Access Management Summit, one of the key challenges described by identity management professionals was that of over-provisioned access credentials, and the risk this creates when credentials are compromised.
When staff are given access to more systems than they need to perform their function, it can be akin to giving them a high-performance five-speed vehicle for tasks that amount to standard inner-city driving. This may not be a huge problem for them in the day-to-day, as they might rarely need to use that fifth gear.
But it is a huge problem when that car is stolen, and the attacker inherits access to systems that should never have been accessible through that identity in the first place.
The remedy often proposed is to restrict access, but this can have the opposite effect – perhaps likened to locking users into first gear and forcing them to ask permission every time they want to shift into second gear or higher.
This challenge is becoming even more acute as organisations adopt AI agents and other technologies that require privileged access to systems. The number of these so-called non-human identities (NHIs) is expanding rapidly within organisations. Organisations are no longer provisioning access only for people, but increasingly for identities that can act autonomously, at speed, and across multiple systems. Being able to effectively govern these NHIs is a challenge that few organisations have locked down.
The starting point for providing appropriate privileges for both human and non-human identities is visibility. As several speakers suggested, you can’t secure what you can’t see.
But it is important to remember that visibility works both ways. Having visibility of who has access to which systems, and how they are using that access, is one side of the equation. The other is visibility into how people actually work, and therefore what access they need to perform effectively.
In short, some people really do need a fast car and access to all five gears to perform effectively. Understanding who they are, and under what circumstances they need that level of access is critical for ensuring that identity does not become the choke point in operational performance.
But there is one other point to consider within all of this, which was well articulated by our final speaker, Ramsay Health Care Head of Identity and Access Management Hemangini Tandel, who said that when implementing an identity program, organisational change management matters.
Changing the gears that are available to workers is something that needs to be communicated, and its impact needs to be monitored and adjusted. Understanding the human reaction to change is another important aspect of identity and access management, as friction can be an important indicator of where identity controls are chafing against the needs of its users.







