A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Manage HR Advisory Board.



Could you talk about your current role and responsibilities, and how has your career trajectory been to reach this position?
I have been working in information systems for over 30 years now, with a strong focus on identity and access management in the last decade. Throughout my career, I have worked closely with HR departments to ensure that employee accounts are provisioned correctly and that there is a single source of truth for employee data. However, I have also noticed that contractors are often left out of this process, which can lead to complications.
As the director of identity and access management at EBSCO Industries, a privately held conglomerate in Birmingham, Alabama, I oversee the lifecycle management of workforce environments for all our lines of business. These include insurance, real estate, sporting goods, hydraulics, electrical supplies, digital media, and libraries. While my team focuses on managing the internal workforce, we don’t handle any customer-facing operations.
My experience in information systems and identity and access management has taught me the importance of having a single source of truth for employee data, as well as the need to account for contractors in this process. I am committed to ensuring that our workforce environments are managed efficiently and effectively to support the various businesses within EBSCO Industries.
What are some of the prevailing challenges you see within the industry?
I have observed that challenges related to identity and access management are consistent across businesses, regardless of their size or industry. It’s essential to ensure that individuals have access only to what they need, which involves creating accounts with the least privilege and revoking access when they leave the company. However, maintaining consistency in these practices can be a challenge for many organizations.
“By centralizing the management of risks, you can prioritize and rank them, which allows you to take action on the most significant threats.”
Smaller businesses may not have a formal HR system, which can make it difficult to track employee data, especially if they have regional or global offices. Even larger companies may struggle to keep up with when people start or leave the company or if a new hire doesn’t show up. In such cases, IT departments may not be notified of inactive accounts, leading to potential security concerns. These issues can go unnoticed without proper auditing, and it is a common problem for smaller companies. However, larger companies may have to go through extensive audits and checks to stay on top of their user population.
At EBSCO Industries, one of the significant challenges we face is not having a centralized location for contractors. Each business unit handles contractors differently, making it challenging to keep track of who should have access and who should not. Ensuring accurate employee data across multiple businesses can also be difficult, especially when it comes to cost centers. This is critical for us at EBSCO since we base a lot of our licensing on headcount. Incorrect or missing cost center information can lead to issues with invoicing, which can be frustrating for both our company and our clients.
What are the technological advancements adopted by organizations to combat these challenges?
Many solutions are available for identity and access management, especially in the HR space. ADP and Workday are two commonly used platforms, and some businesses also use SAP. However, the problem is not always the lack of options, but rather the age and maintenance of the solution being used.
For instance, cloud-based solutions with robust APIs and functionality are typically more modern and easier to integrate with newer applications. But when a company invests in an HR solution and customizes it without keeping it up to date, there can be issues when trying to integrate with newer lifecycle management solutions like SailPoint. These older HR systems may not have the necessary hooks and may require additional workarounds to communicate with other applications.
It’s important to maintain and upgrade your applications not just for security and patching but also for functionality. Many businesses make the mistake of buying an application and trying to fit their existing processes into it instead of standardizing their processes to take advantage of the application’s capabilities. This can lead to rigidity and a delay in upgrading, making it difficult to take advantage of new features or technologies down the line.
That said, there are other identity and access management solutions available, such as SailPoint, Opta, and Active Roles. The solution choice may depend on your environment, with many companies still relying heavily on an active directory for network accounts and single sign-on, even as more applications move to the cloud.
Where do you envision the technology moving forward, and how will it impact the industry?
Identity and access management have finally gained the attention they deserve in the past few years. In the past, security was reactive, and companies would only put measures in place after a breach had occurred. But breaches usually happen because attackers exploit weak identity and access management practices. It has taken years for people to understand this, but now user behavior monitoring, least privilege, and zero trust have become more prevalent in the industry. Credentials are what matters, not the person’s identity. When attackers get into a network, they’re looking for root access or domain admin access, which allows them to capture what they want.
I think this issue will remain at the forefront of security concerns. There will be an increase in the number of identity and access management products available in the market. However, implementing an accurate role-based access control across many organizations is still a challenge. It’s not a simple task to implement this, because many companies use old mainframe solutions. These systems use old code somewhere in the process, which makes it challenging to integrate them with newer solutions. These older systems lack the APIs and features that newer solutions have, such as Workday, which is built from the ground up to be a cloud-based solution.
To keep everything secure, companies need to keep their systems patched and up to date. But most companies still have old servers and applications that they use, which makes it difficult to modernize their systems fully. As much as we want to make things modern, if the company’s applications are not up to date, they will still have gaps that affect automated provisioning and de-provisioning.
Is there a specific piece of advice that you would like to share with other industry leaders looking to venture into the same field?
Building a solid relationship with your HR teams is crucial in managing identity and access risks within an organization. This is especially true for larger organizations, where managing user data across different departments and offices can be a daunting task. In my experience, having a dedicated governance, risk, and compliance (GRC) team can be an ally in addressing these challenges. By centralizing the management of risks, you can prioritize and rank them, which allows you to take action on the most significant threats.
One of the common challenges is managing access for contractors. It’s crucial to have a process in place to track their access and revoke it when necessary. Often, compromised accounts are those of contractors, and it’s vital to ensure they only have access to what they need. Building a strong relationship with HR can help you stay informed about when contractors are hired or when they leave the organization so that you can manage their access accordingly.