Connect with us

Tech Features

Provisioning and Deprovisioning – A Guide to Stronger Identity and Access Management

Published

on

Access Management

By: Christopher Hills, Chief Security Strategist, BeyondTrust

Across the Middle East, CIOs and CISOs huddle together to determine ways of making their organizations more secure so that digitalization can align with the vision of business leaders. No enterprise can afford to shut itself off from the digital economy. Whether it operates locally, regionally or globally, a business must build trust. And to do that, it must master the art of identity management. Therefore, it must understand the importance of provisioning and deprovisioning.

Provisioning is the name we give to the granting of privileges. This is a more granular process than onboarding, in which a new user account is created. Each user may have privileges granted at any time. And we should remember that not all users are humans — employees, contractors, customers, and so on. Privileges may be assigned to service accounts, machinery, and other resources. The purpose of provisioning is to maintain access while accounting for security and compliance standards.

To meet modern security standards, however, deprovisioning is just as important. Again, this does not just occur during offboarding. Privileges can be revoked all the time. Not because of a loss of trust in the person or asset that held them, but because it is best practice. Effective provisioning and deprovisioning is the foundation of a robust identity-centric security solution.

Covering the bases

Both are important. Overprovisioning can lead to a junior employee or overlooked service having unnecessary privileges, and under-deprovisioning can lead to a range of invisible issues such as unmonitored or orphaned accounts, or stale privileges. Special care must also be taken when adding or removing accounts to user groups — which carry with them a predetermined set of privileges —because these actions amount to provisioning and deprovisioning.

Any active account is a potential entry point, so it should come as no surprise that security best practice lies in minimizing the number of accounts and the access privileges they hold. If an account is no longer needed — an employee has resigned, a project has come to an end, or a range of other scenarios — then it should be disabled, deleted, or its rights downsized. Threat actors rely on organizations not following this simple practice.

Tools and tricks

Robust IAM will also include just-in-time (JIT) provisioning, which goes hand in hand with PoLP. When deprovisioning occurs, the timely revocation of access also occurs. Regularly reviewing and adjusting access rights is best practice because it prevents unnecessary permissions being exploited by malicious parties inside or outside the organization. All unused accounts should be placed in a disabled state and removed from all relevant security groups until such time as they can be reviewed and, if appropriate, deleted.

Identity and access management cannot be effective without the right tools to simplify provisioning and deprovisioning. This is because looking after the end-to-end lifecycle of identities, privileges, and entitlements is a complex task that has grown even more complex since the region’s mass migration to hybrid and multi-cloud environments. Identity management tools can streamline the creation, maintenance, and deletion of human and non-human accounts. Governance management tools enforce policies that limit access based on the assigned privileges. Lifecycle management tools are useful for ensuring (from onboarding to offboarding) that privileges always fit the role of an account owner. Privileged access management (PAM) enforces PoLP and provides a useful integration hub for other tools so that IT and security teams have single-pane control over everything that may impact identity security.

In a modern setting, provisioning and deprovisioning tools must offer automation and user behavior analytics, which means they must incorporate some flavor of AI or machine learning. To be consistent with the implementation of PoLP and other governance policies, variants of AI are necessary to minimize human error. Granting and revoking access rights in a company of even moderate size is a constant process that responds to changes in personnel and circumstances. While some of these situations may be subject to planning, others, such as real-time behavioral anomalies, are not. Threats can arise at a moment’s notice and only AI offers a practical option for timely response.

Be strong

Having established provisioning and deprovisioning as the keys to strong IAM, enterprises will find they can implement more effective lifecycle management of identities, privileges, and entitlements. As with any new measure, ongoing reviews will uncover any additional requirements, and adjustments can be made to cover new regulations, new assets, or new business models. As the identity landscape fluctuates, so should provisioning and deprovisioning strategies.

Define roles clearly. If an account owner does not need access to a resource, do not grant it (PoLP); and if they do, wherever possible, grant access only for as long as it is required (JIT). Disable and delete accounts where appropriate and monitor access across the entire ecosystem as often as is practical — quarterly or annually.

Following the guidance laid out here will strengthen your identity security posture. The modern threat actor is always on the lookout for gaps in your defenses. Unfortunately, these often take the shape of overprovisioned identities or abandoned accounts that have not been adequately addressed. The good news is that by applying the steps above, you can shore up defenses and protect the enterprise from the worst of the threats beyond its walls.  

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech Features

THE MIDDLE EAST’S DIGITAL FAULT LINES: A RESILIENCY BLUEPRINT FOR CIOS AND CTOS

Published

on

Ahmad Shakora, Group Vice President- META, Cloudera

We are now in an era where digital connectivity underpins many areas such as commerce, security, governance, and social life.

In the Middle East, with ever-changing external factors, access to data has transitioned into a critical asset, with organisations and nations increasingly focused on protecting a vast array of information.

 For businesses operating in this region, traditional efficiency-focused IT strategies are no longer sufficient. Robust business continuity and disaster recovery must take center stage.

The expanding risk matrix

The current operating environment highlights several areas of vulnerability for global digital infrastructure, demonstrating that risks can be either planned or entirely unexpected:

  • Government interventions can result in significant, sudden internet restrictions. Additionally, physical data center infrastructure is susceptible to multiple external factors. Severe and unpredictable environmental events, including extreme heat and unexpected flooding, can place a strain on the physical and cooling infrastructure of centralized data centers, forcing facilities offline
  • Unexpected impact on physical infrastructure can arise, causing noticeable latency
  • Total reliance on centralized third-party platforms amplifies operational risks. These can stem from planned events, such as routine maintenance and vendor migrations, or unplanned events, such as global software updates that inadvertently lead to widespread, cascading outages

In response to these varied and potentially compounding threats, the Gulf Cooperation Council is shifting from efficiency-first cloud adoption to resilience-first planning. Nations are accelerating investments in localized data centers, sovereign cloud environments, and multi-channel data access architectures that can withstand both cyberattacks and physical military threats.

In the UAE, the sovereign cloud market is projected to grow at a compound annual rate of 23% through 2033, signalling a sustained commitment to securing critical data and reducing exposure to fragile global dependencies.

When resilience becomes the backbone of survival

These external forces elevate Business Continuity and Disaster Recovery from a regulatory checkbox to a fundamental requirement for corporate survival. For CIOs and CTOs operating in the Middle East, ensuring operational resilience requires highly specific architectural choices.

Tech leaders who view infrastructure through a purely technical lens may be vulnerable. Data infrastructure must function as a strategic fortress. Resilience must supersede efficiency as the primary design goal. To continue operating amidst disruptions, tech leaders should look for the following differentiators when building their enterprise data infrastructure:

1. Cloud power, local control: do not put all the eggs in the public cloud basket. Organizations need a setup that works the same way whether it is in a giant data center or a small server at a remote branch. By running mini-clouds locally, enterprises keep the speed and control without being at the mercy of a service provider’s outage. Infrastructure must allow organizations to run data and AI workloads anywhere, converging the best of public cloud with on-premises deployments, including secure air-gapped environments.

2. Maintain internal control over enterprise AI: if there are disruptions to internet access or travel is restricted, AI shouldn’t stop working. Sovereign Private AI, by design, brings the thinking power to where the data actually sits. This keeps sensitive data secure and ensures automated systems stay online even if the rest of the world goes offline.

3. Diversify technology partners: tech leaders should implement an Open Data Lakehouse architecture that unifies 100% of the organization’s data to avoid vendor lock-in and catastrophic single points of failure. A critical design principle to look for is the strict separation of compute and storage. By utilizing highly scalable, S3-compatible object storage independently from computing power, enterprises can leverage robust data replication and erasure coding to ensure high durability, guaranteeing that all backup data remains safely within sovereign boundaries.

4. One view, no silos: managing fragmented data across a region during a crisis can be chaotic. CIOs need a Unified Data Fabric that breaks down silos and provides a single view of all organizational data with centralized, end-to-end security and governance across complex hybrid environments. Coupled with this, infrastructure must support Data in Motion: the ability to seamlessly move and process real-time data from any source to any destination. If a subsea cable is damaged or a data center goes offline, this capability ensures business-critical decisions can still be made seamlessly as traffic reroutes.

5. Visibility & isolation: Operational survival requires extreme visibility. A resilient infrastructure must feature granular observability across the full IT stack for proactive health monitoring, incident response, and data-flow policy enforcement. By using containers to isolate different tasks, enterprises can ensure that if one part of the business encounters technical issues, the risk is contained, protecting critical operations.

The future of business in the Middle East belongs to leaders who treat their infrastructure as a sovereign fortress.

True resilience requires moving past simple cloud adoption to build localized, hyper-resilient architectures that remain fully functional when global networks fail. CIOs and CTOs must now prioritize digital autonomy by anchoring their most critical operations in hardened, local environments that can withstand physical and international uncertainties. By designing for total isolation, leaders can ensure their organization remains operational and secure regardless of regional instability. The ultimate competitive advantage is the ability to maintain power and connectivity.

Continue Reading

Tech Features

FIVE WAYS B2B MEDTECH MARKETPLACES ARE RESHAPING HEALTHCARE BUSINESS

Published

on

Healthcare and wellness businesses across the GCC are growing in a market that is becoming more digital, specialised, and commercially active. The GCC healthcare market is projected to grow from $121.9 billion in 2025 to $170.5 billion by 2030, according to Research and Markets, creating stronger demand for trusted platforms that connect buyers, sellers, service providers, and investors. Yet many businesses still rely on personal networks, fragmented supplier searches, and informal channels when selling equipment, finding operational support, or exploring business transactions.

MedSahra, the first B2B MedTech ecosystem platform focused on healthcare and wellness trade across the GCC, outlines five facts that show how marketplaces can bring more structure to this evolving sector.

Verified businesses build trust

Healthcare transactions often involve high-value assets and licensed businesses, which makes trust essential from the first interaction. A B2B marketplace becomes stronger when sellers and buyers are verified before they engage with others. This can include requesting documentation that confirms a company is legally registered and operational. For buyers, this reduces uncertainty. For sellers, it creates a more credible environment where serious business conversations can begin with greater confidence.

Private listings support business sales

Selling a healthcare or wellness business is often sensitive because owners may not want staff, competitors or the wider market to know they are exploring a transaction. In many cases, owners are left to rely on word-of-mouth or private referrals because there is no clear, specialised marketplace for these opportunities. Public listings can create unnecessary concern among employees, patients, and competitors before a deal is even serious. Private listings can make this process more practical by allowing sellers to present opportunities discreetly, while helping buyers discover small private clinics to large hospitals in different sectors, including general, dental, dermatology, cosmetology, pediatric and others areas, with existing infrastructure, equipment, and customer bases.

Equipment access becomes more efficient

Medical equipment is a major investment, yet many owners struggle to sell pre-owned devices through the usual channels. In some cases, distributors may only buy back equipment when the owner is purchasing a new device, which leaves clinic owners with limited options when they simply want to sell. A dedicated marketplace creates a clearer route for listing and discovering all types of medical and wellness equipment, whether new or pre-owned, across healthcare and wellness categories, including  dental, diagnostic, general medical, cosmetology and others. This is increasingly relevant as the UAE medical devices market is projected to grow from $3.18 billion in 2025 to $4.71 billion by 2032, according to Fortune Business Insights. Marketplaces can also help users find providers for repair, calibration, upgrades and spare parts.

Support services become easier to find

Running a clinic or wellness business requires more than medical expertise, and finding reliable service providers can be a constant operational challenge. Owners often depend on search engines, personal recommendations, or scattered supplier contacts when they need support for digital marketing, accounting, logistics, customs, software development, printing, pest control, equipment repair, calibration, hardware upgrades, or software upgrades. A B2B marketplace can make supplier discovery more structured by bringing relevant service providers into one professional ecosystem where businesses can compare options and start conversations more efficiently.

Consulting adds structure to transactions

Complex business decisions often require specialist support, especially when buying equipment, selling a clinic, or preparing for a larger transaction. Consulting partners can support areas such as M&A, accounting, audit, legal guidance, equipment planning, and operational readiness. This advisory layer is becoming more important as healthcare providers adopt more connected technologies, with GCC connected medical devices and wearables projected to grow at a CAGR of around 20.19% between 2025 and 2030, according to MarkNtel Advisors. A marketplace that connects businesses with relevant experts can help transactions become more informed, secure, and commercially viable.

Continue Reading

Tech Features

OPPO Find N6 Signals the End of Foldable Trade-Offs

Published

on

For years, foldable smartphones have existed within a category shaped by compromise. Users typically had to choose between slim form factors and flagship-grade performance, with many foldables sacrificing battery life, imaging capabilities, or long-term usability in favour of portability and design.

OPPO’s new Find N6 appears designed to challenge that equation directly.

With the Find N6, OPPO is positioning foldables less as experimental devices and more as fully capable flagship smartphones that happen to fold. The device combines a slimmer profile with flagship imaging, next-generation processing, and the largest battery yet seen within the Find N series, signalling how rapidly the foldable segment itself is evolving.

A New Hasselblad Imaging System

At the centre of the device is OPPO’s new Hasselblad Master Camera System, led by a 200MP Hasselblad Ultra-Clear Main Camera alongside a 50MP periscope telephoto lens supporting 6x optical-quality zoom and up to 120x digital zoom.

The system also integrates a redesigned ultra-wide camera and OPPO’s True Color Camera sensor technology aimed at improving white balance and colour accuracy across different lighting conditions.

The Find N6 additionally inherits several imaging capabilities from OPPO’s Find X flagship lineup, including the LUMO Image Engine, Hasselblad Portrait Mode, Hasselblad Master Mode, and XPAN-style panoramic photography modes designed to emulate cinematic film aesthetics.

Bringing Flagship Video Features to Foldables

Video also forms a major part of the Find N6’s flagship positioning. All three rear cameras support 4K 60fps Dolby Vision recording, while the main 200MP sensor additionally supports 4K 120fps Dolby Vision capture for higher frame-rate workflows.

The inclusion of Log video support also pushes the device further toward professional and enthusiast creators looking for greater flexibility during post-production and colour grading workflows.

Powered by Snapdragon 8 Elite Gen 5

Performance is powered by Qualcomm’s Snapdragon 8 Elite Gen 5 Mobile Platform, featuring the third-generation Qualcomm Oryon CPU architecture.

According to OPPO, the platform delivers improvements in both performance and power efficiency, helping the foldable maintain smoother multitasking and sustained workloads without heavily compromising battery endurance.

The newer Adreno GPU architecture also introduces improvements across graphics performance, efficiency, and ray tracing capabilities, reinforcing the device’s flagship-level positioning beyond design alone.

Tackling the Foldable Battery Challenge

Battery life has historically remained one of the biggest limitations within foldable smartphones, largely due to internal space constraints.

OPPO addresses that challenge with a 6,000mAh Silicon-Carbon battery, representing the largest battery integrated into a Find N device to date while maintaining an ultra-slim 8.93mm folded profile.

The device also supports 80W SUPERVOOC wired charging and 50W AIRVOOC wireless charging, helping reduce downtime for users balancing heavy productivity, content creation, and entertainment workloads.

The Foldable Category Is Maturing

More broadly, the Find N6 reflects a wider transition happening across the foldable smartphone category itself.

Earlier generations of foldables were often viewed as engineering showcases that required users to compromise somewhere along the experience. Increasingly, however, newer foldables are attempting to position themselves as mainstream flagship devices capable of matching traditional smartphones across imaging, performance, endurance, and portability simultaneously.

With the Find N6, OPPO appears intent on pushing that transition further, presenting a foldable device focused not only on design innovation, but on delivering a more complete flagship experience without the compromises that once defined the category.

Continue Reading

Trending

Copyright © 2023 | The Integrator