Featured Article

Address cybersecurity challenges before rolling out robotic process automation

Our new ‘digital coworkers’ have their own identities

Comment

Digital Image of two wireframed faces representing digital identity
Image Credits: Mina De La O (opens in a new window) / Getty Images

Alan Radford

Contributor

Alan Radford is regional CTO of One Identity and has a passion for helping organizations solve unique challenges in the identity and access management space.

Robotic process automation (RPA) is making a major impact across every industry. But many don’t know how common the technology is and may not realize that they are interacting with it regularly. RPA is a growing megatrend — by 2022, Gartner predicts that 90% of organizations globally will have adopted RPA and its received over $1.8 billion in investments in the past two years alone.

Due to the shift to remote work, companies across every industry have implemented some form of RPA to simplify their operations to deal with an influx of requests. For example, when major airlines were bombarded with cancellation requests at the onset of the pandemic, RPA became essential to their customer service strategy.

According to Forrester, one major airline had over 120,000 cancellations during the first few weeks of the pandemic. By utilizing RPA to handle the influx of cancellations, the airline was able to simplify its refund process and assist customers in a timely matter.

Delivering this type of streamlined cancellation process with such high demand would have been extremely challenging, if not impossible, without RPA technology.

The multitude of other RPA use cases that have popped up since COVID-19 have made it evident that RPA isn’t going away anytime soon. In fact, interest in the usage of RPA is at an unprecedented high. Gartner inquiries related to RPA increased over 1,000% during 2020 as companies continue to invest.

However, there’s one big issue that’s commonly overlooked when it comes to RPA — security. Like we’ve seen with other innovations, the security aspect of RPA isn’t implemented in the early stages of development — leaving organizations vulnerable to cybercriminals.

If the security vulnerabilities of RPA aren’t addressed quickly, there will be a string of significant RPA breaches in 2021. However, by realizing that these new “digital coworkers” have identities of their own, companies can secure RPA before they make the headlines as the latest major breach.

Understanding RPA’s digital identity

With RPA, digital workers are created to take over repetitive manual tasks that have been traditionally performed by humans. Their interaction directly with business applications mimics the way humans use credentials and privilege — ultimately giving the robot an identity of its own. An identity that is created and operates much faster than any human identity but doesn’t eat, sleep, take holidays, go on strike or even get paid.

In order to perform tasks, digital workers require access to a variety of networks, systems and applications. Yet, many organizations have overlooked that the type of access being granted to their digital workers is leaving their most valuable asset out in the open — privileged credentials. With 53% of all breaches being due to the misuse of privileged credentials, the unmonitored and unrestricted access of RPA makes it even more susceptible to a breach than its human counterparts.

As pandemic drags on, interest in automation surges

To avoid this risk, organizations should extend their identity governance and privilege access processes to manage their digital workers. Today there are lines of business that actually create employee records in order to mimic a real-world employee from a human resources perspective and “cheat” existing joiner, mover and leaver processes and existing security controls for management of accounts.

This approach prevents existing controls from mitigating risk, most notably around privilege creep, orphaned accounts, erroneous attributes lacking meaning or context, the exposure of passwords and secrets, and the lack of a defined path of ownership.

RPA creates identity challenges 

The first step in solving any problem is recognizing there is one. Realizing our new digital workers have identities is the first and most important step in securing the future of RPA.

When a company first learns about how the business can benefit from investment in RPA, even with a heightened awareness of the security risks, the potential return on investment from increased productivity means the investment will inevitably continue. With many security solutions unable to preserve the business benefits of the RPA investment, by being too costly to deploy and integrate, it can be hard to preserve the returned investment when the security auditors come knocking.

RPA solutions don’t currently focus on solving security challenges because they are focused on increasing productivity. As a result, third-party security solutions need to be integrated in order to provide the correct controls to mitigate risk. The easiest of these controls to apply is in the form of privilege access management (PAM).

With a PAM system that provides connectivity to RPA systems, enterprises can effectively secure, control and audit the credentials and privileges being used by the robots. By choosing a PAM solution that is easy to deploy and integrate, this can be achieved without compromising the return on investment recognized by the RPA program, without impacting productivity.

An international private security company saw the benefits of this approach firsthand following investment in an RPA solution. With over 160,000 employees worldwide, the addition of digital workers allowed the reallocation of time from existing employees to focus on higher-value tasks. Through the implementation of a PAM system that seamlessly integrated into its existing RPA solution, the company was able to automate the control of its digital workers’ privileged access.

Now, when its digital workers need privileged access, the robot can retrieve credentials from the PAM system automatically without any exposure to the bot owners or developers. This not only provides a full audit trail of which digital workers had access to what applications, but also provides individual accountability and proof that no one can obtain the password in a noncompliant manner.

Through this system they have been able to scale their digital workforce across 14 business units in only two years, giving 350,000 hours back to the business without compromising security.

The future of the digital workforce

Throughout 2021, security teams will begin to realize the unconsidered security challenges of RPA. The core of all their problems will point back to one common perimeter — identity.

How are the robots in your organization created? How are their accounts created, used and removed? Who controls the robots activity and how would you know if a bot was compromised? Do you know how many of the records in your HR system are, in fact, nonhuman resources?

With access to a multitude of systems within the network, RPA has identities just like you and me — so why not secure it in the same way.

Top VCs discuss how COVID-19 is impacting robotics

More TechCrunch

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version of AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

On Wednesday, Google launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India

Bluesky has launched a new product roadmap for the coming months. The decentralized social network said on Tuesday that it is planning to introduce direct messages, support for videos, improved…

Bluesky to add DMs, video support and in-app custom feed curation

Samsung Medison, a medical device unit of Samsung Electronics that specializes in developing diagnostic imaging devices, said on Wednesday it plans to acquire Sonio, a Paris-based startup that makes AI-powered software…

Samsung Medison to acquire French AI ultrasound startup Sonio for $92.7M