
Oren Ohayon Harel at PlainID outlines the key considerations when choosing a modern authorisation solution
As digitalisation continues to drive evolution across a wealth of business sectors and industries, a growing number of organisations are turning to Zero Trust models to bolster their data security.
Changing work practices, in part driven by global events of the last few years, have left more and more companies dealing with complex, highly distributed workforces. Consequently, the traditional ‘castle’ approach to cyber security of building strong walls to try and keep intruders out is becoming less and less effective.
Today, modern enterprises more closely resemble ‘corporate cities’ with data constantly flowing in and out via open trade routes. This is causing growing concern about how best to secure sensitive digital assets in such an environment.
For many, the answer lies in new security technology designed to do just that. Organisations from a wide range of sectors are starting to adopt innovative new security technologies to help manage accessibility of assets at a scale that addresses different data structures, user environments, and relationships between user identities and digital assets.
While Zero Trust was originally a concept centred on enterprise network security, the paradigm has shifted significantly over the past decade, to the point where it is now a relevant part of securing both data, API’s and microservices to bring full Zero Trust to the application level.
The Zero Trust security framework is based around the central principle of requiring all network users to be identified, authenticated, and continuously validated for security posture before being granted access to existing assets. It emphasises the need for security checks at every stage of a user’s journey, not just at the entry point.
Of course, overly stringent security measures can have an adverse effect, as evidenced by previous tools such as siloed identity and protection mechanisms, which have hindered growth and profitability opportunities in some cases. Consequently, many businesses are nervous that rigid security models will return the same outcome.
However, with the right tools and implementation, modern-day authorisation solutions can actually help increase productivity and boost growth.
To achieve this, businesses must ensure they choose the right security model for their unique situation and needs, not just blindly go with the first solution they come across.
Here are four of the key aspects to consider when seeking a suitable modern authorisation solution:
Living in a dynamic data-driven environment requires organisations to be more responsive. Authorisation enables parties to define and enforce who has access to digital assets and how users can interact with them. The use of traditional authorisation methods is often connected with applications, making it time-consuming to manage, upgrade, or re-configure access policies.
With externalised authorisation, users can externalise access control decisions decentralised from the application while drawing parameters and risk signals from multiple sources of information. Doing so provides a range of benefits, from improved agility and security to more streamlined processes and many more.
Authorisation has become a broader tool for supporting business decision-making and processes. It requires aligning business decisions with security requirements to establish engagement with technical and non-technical users.
With the creation of a decentralised workforce, organisations have an increased susceptibility to security breaches and user impersonation. However, centralised management of access policies provides security and business teams with visibility of how users access digital information.
Through these processes, known as policy-based access control, organisations are given much tighter control over sensitive information, especially where external third parties are concerned.
The use of distributed enforcement aims to extend access policies to better secure endpoints and accelerate business decisions for teams that rely on different sources for data projects.
As enterprises continue to scale, so do their systems and their complexity. Distributed enforcement of access enables enterprises to scale authorisation alongside the growth of their data, API’s and microservices as part of their technology stack and apply more effective controls to address data privacy and compliance.
Authorisation addresses the business and technology needs of the modern day without leaving legacy applications behind. Current tools such as ‘rip and replace’ have become less feasible for many enterprises.
Instead, organisations are turning to modern access control tools as they can be deployed in diverse and complex environments. This can include hybrid cloud, cloud-native and existing-on-premises infrastructure.
The ability to be deployed across various environments will impact how fast a product can respond to changes in requirements set and the quality of each change, ultimately satisfying the ever-changing security needs of businesses and their consumers.
With more and more organisations now resembling corporate cities instead of traditional castles when it comes to their technology infrastructure, the way in which they approach data protection needs to evolve accordingly.
Fortunately, there’s a plethora of innovative new security platforms and solutions out there to choose from. However, it’s crucial that businesses take the time to find the right solution for their individual needs in order to achieve the long-term data protection they require.
Oren Ohayon Harel is CEO at PlainID
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543