Best Practices To Combat Identity-Related Cyberattacks
- By Kumaravel Ramakrishnan, ManageEngine
- February 16, 2025

Across the Asia-Pacific (APAC) region, businesses face a growing challenge: protecting digital identities when employees, contractors, and customers access critical data globally. With hybrid work, cloud services, and mobile apps becoming the norm, securing access has never been more critical, and traditional data security methods are no longer sufficient.
IDC forecasts that security spending in Asia Pacific excluding Japan (APeJ) will grow at a five-year compound annual growth rate (CAGR) of 12.8%, reaching USD52 billion by 2027.
The ever-changing technological landscape has increased operational efficiency, but this benefit comes with challenges. Of these challenges, identity-related cyberattacks are considered the most damaging, as they jeopardize cybersecurity posture and can lead to total business disruption. This propels organizations to adopt emerging tools and technologies to remain secure and function effectively.
What is an identity-related cyberattack?
As the name suggests, identity-related cyberattacks target and invade the identities within an organization. These identities — both human (users) and non-human (devices, applications) — are crucial to an organization's operations. When compromised, they significantly impact the organization's security posture and overall productivity.
Modern technologies have increased the sophistication and targeted nature of cyberattacks, making them harder to detect. From AI-generated phishing and social engineering to credential theft, these attacks are more dangerous than ever. However, these same technologies also empower organizations to strengthen their defenses and fortify their identity security framework.
The need for identity security
In the vast digital landscape, identity security has become mandatory to proactively monitor threats, protect against cyberattacks, and adhere to regulatory standards. ManageEngine's 2024 Identity Security Report highlights the need for identity security, with 79% of Singaporean respondents stating they could benefit from adopting identity security tools to protect themselves from potential threats.

Identity security is both a technical and business imperative, enabling safe digital transformation and determining an organization's resilience. Professionals, from executives to specialists, emphasize embracing the latest advancements, such as AI, to have complete visibility to safeguard assets and ensure maximum productivity.
Identity security tools
Modern organizations are compelled to elevate their cybersecurity strategy by deploying the right identity security tools. The same survey found that 57% of Singaporean respondents strongly believe that embracing AI advancements will strengthen their defenses against sophisticated cyberattacks. Adopting these advanced technologies will ensure that every digital interaction within an organization is monitored and authorized to prevent external threats, insider attacks, and accidental misuse.
Starting with simple password managers, identity security has evolved to include tools and processes like single sign-on (SSO) and multi-factor authentication (MFA). But the crowded market for identity security tools can contribute to tool sprawl. While tool sprawl can provide comprehensive security, it can also create challenges. These include integration difficulties, hampered interoperability, a siloed approach, and potentially wider security gaps. Therefore, the right tools are needed to enhance innovation without compromising security.
Never trust, always verify
Organizations should implement Zero Trust (ZT) solutions to improve their cybersecurity posture in today's rapidly changing threat landscape. The Zero Trust principle of "never trust, always verify" ensures that all access requests are verified, regardless of origin.
ManageEngine's report shows that less than 25% of respondents have implemented zero-standing privileges (ZSP), despite over 60% focusing on identities within their Zero Trust strategies. In Singapore, 24% of organizations lack a ZT-focused identity security strategy. Among those striving for ZSP, 69% cite the absence of processes, workflows, and tools as the primary challenge.
Technological and operational gaps hinder ZSP implementation across all regions, highlighting the need for comprehensive solutions.
Staying ahead of the game
An effective identity security strategy requires the integration of technology, processes, and, crucially, people. In an environment with numerous attack vectors and sophisticated cyberattacks, these elements must work together to mitigate threats. This integrated approach ensures that the strategic vision of identity security is realized into practice.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/Iaremenko
Kumaravel Ramakrishnan, ManageEngine
Kumaravel Ramakrishnan is the technology director at ManageEngine. He has over fifteen years of experience in the IT industry. During his 13+ years at ManageEngine, the IT management division of Zoho Corporation, Kumaravel has participated in service desk implementations and consulting worldwide. In his present role, Kumaravel leads all marketing initiatives for ManageEngine’s IT Service Management and Privileged Access Management suites. He is a regular speaker at ManageEngine conferences and industry events.