Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Point solutions vs platforms in identity security: what teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Cybersecurity has stayed fragmented because specialist vendors keep solving narrow problems faster than large platforms can absorb them, especially in on-premises environments where Active Directory still leaves gaps in MFA, session control, and contextual access, according to IS Decisions. The lesson for identity teams is that platform consolidation does not erase control-plane complexity.

NHIMG editorial — based on content published by IS Decisions: Why a lot of cybersecurity is still a point solution rather than a platform

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.

Questions worth separating out

Q: What is the main identity security gap that point solutions still fill in enterprise environments?

A: Point solutions still fill the gap between authentication and full session governance.

Q: Why do cloud IAM platforms often fall short in on-premises identity governance?

A: Cloud IAM platforms are usually optimised for a single login flow and a central policy layer.

Q: What do security teams get wrong about MFA for non-human identities?

A: They often assume one access-control pattern can cover both humans and machines.

Practitioner guidance

  • Inventory identity control gaps beyond sign-in List where authentication, session control, and contextual enforcement are handled by different systems or by manual exception handling.
  • Separate cloud login governance from on-premises session governance Do not assume a central SSO layer covers post-authentication behaviour in legacy estates.
  • Review concurrent access and shared-session risk Check for identities that can open multiple simultaneous sessions or reuse access paths without detection.

What's in the full article

IS Decisions' full analysis covers the operational detail this post intentionally leaves for the source:

  • How UserLock addresses concurrent logins and session-level access enforcement in on-premises environments
  • The stepwise feature evolution from MFA and SSO into contextual controls for Active Directory estates
  • Why the vendor frames air-gapped and remote access as distinct control problems rather than a single IAM category
  • Practical examples of how small, specialist tools fit alongside larger cloud IAM platforms

👉 Read IS Decisions' analysis of why specialist identity controls still matter →

Point solutions vs platforms in identity security: what teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Specialist controls persist because the control problem is still fragmented. The article shows that cybersecurity consolidation has not removed the need for narrow tools that solve specific identity gaps. Authentication, session control, and contextual enforcement are different control problems, and enterprise estates still need separate answers for each. For identity teams, the practical conclusion is that platform breadth does not replace control precision.

A few things that frame the scale:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: When should organisations rely on specialist identity controls instead of one platform?

A: Organisations should rely on specialist controls when the environment includes legacy applications, air-gapped systems, or access paths that do not fit a standard cloud SSO model. In those cases, a single platform may centralise policy but still leave enforcement gaps that need targeted controls.

👉 Read our full editorial: Why point solutions still win in identity security for on-premises gaps



   
ReplyQuote
Share: