<img src="https://ws.zoominfo.com/pixel/6169bf9791429100154fc0a2" width="1" height="1" style="display: none;">
Curious about how StrongDM works? 🤔 Learn more here!
Search
Close icon
Search bar icon

When Old-School Isn't Cool: Sluggish and Untenable Access

StrongDM manages and audits access to infrastructure.
  • Role-based, attribute-based, & just-in-time access to infrastructure
  • Connect any person or service to any infrastructure, anywhere
  • Logging like you've never seen

In DevOps environments, fast and steady wins the race. So when developers struggle to gain timely access to the systems they need, it’s clear that something isn’t working. And these challenges extend beyond DevOps to include users in both technical (e.g. data science, engineering) and non-technical roles (e.g. HR, finance). Old-school access policies make it harder for users of all types to connect to the databases and other infrastructure they require to do their jobs. 

Waiting For Access

Stop me if you’ve heard this one. Q: How many requests does it take to gain access to critical systems? A: Far too many.*

The combination of legacy approaches, cloud services, and rapidly-growing businesses that contribute to modern computing environments is making it harder and harder to grant users the access they need when they need it. In fact, in our recent survey, 88% of respondents said two or more employees are involved in approving and granting an access request. More than one in five organizations require four or more people to be involved.

And, no surprise–jumping through all those hoops takes time. At 50% of organizations, the average access request takes hours, days, or weeks to fulfill. If one of the main tenets of DevOps is agility, then it’s clear these workflows are fundamentally broken.

Those Workarounds Aren’t Working

Broken workflows motivate admins and users to find access workarounds such as over- and underprovisioning, password sharing, and using static credentials. And while unsanctioned attempts to sidestep old-school security measures may ease bottlenecks and speed up production, they often lead to real-world consequences.  

This article is quite eye-opening. It presents a typical day at a hospital, with healthcare professionals sharing logins, taping passwords to their devices, and even requiring “the most junior person on a medical team … to keep pressing the space bar on everyone’s keyboard to prevent [session] timeouts.” But you can’t fault the users. Although their behaviors can put patients at serious risk, so do the outdated protocols the doctors and nurses are trying to circumvent.

Outside of the healthcare industry, problems are just as prevalent. In our recent survey, 42% percent of DevOps professionals report the use of shared SSH keys, and 65% manage infrastructure access with team or shared logins.

Old Methods Don’t Scale and Are Non-compliant

Sluggish access is more than an inconvenience. The workarounds people take to ease friction can lead to security gaps and compliance problems, plus a lot of pain for users and admins alike. 

Spreadsheets and sticky notes may work well enough in the early days of an organization, but these methods certainly don’t scale. And they make implementing new security initiatives, such as Zero Trust, nearly impossible.

Furthermore, stopgap measures such as credential sharing make evidence gathering for compliance extremely difficult, as nobody really knows who has access or who was in your systems at any given time. Keeping a trail of who-did-what-when is essential to modern access control. Failing to do so may explicitly violate regulatory requirements, and even when they don’t, observability is just good security hygiene.

Want to learn more about how your peers are managing access to their infrastructure? Check out the full report, 2022: The Year of Access. Then schedule a free demo of StrongDM to see how you can upgrade your access management today.


About the Author

, Contributing Writer and Illustrator, has a passion for helping people bring their ideas to life through web and book illustration, writing, and animation. In recent years, her work has focused on researching the context and differentiation of technical products and relaying that understanding through appealing and vibrant language and images. She holds a B.A. in Philosophy from the University of California, Berkeley. To contact Maile, visit her on LinkedIn.

StrongDM logo
💙 this post?
Then get all that StrongDM goodness, right in your inbox.

You May Also Like

HIPAA Multi-Factor Authentication (MFA) Requirements
HIPAA Multi-Factor Authentication (MFA) Requirements in 2025
The HIPAA Multi-Factor Authentication (MFA) requirement is a security measure that requires users to verify their identity using at least two different factors—such as something they know (a password), something they have (a smartphone or token), or something they are (a fingerprint)—to access systems containing electronic Protected Health Information (ePHI). This additional layer of security is designed to protect sensitive healthcare data from unauthorized access, even if one credential is compromised, and helps organizations comply with the HIPAA Security Rule.
There Will Be Breaches: A Blueprint for Smarter Access
There Will Be Breaches: A 2025 Blueprint for Smarter Access
I’ll spare you the “I drink your milkshake” tropes, but we all face a sobering reality: there will be breaches in 2025. Breaches aren’t a question of “if” anymore—they’re a question of “when” and “how bad.” It’s a foregone conclusion, like taxes or the 37th season of Grey’s Anatomy. But here’s the good news: knowing the inevitability of breaches gives us the perfect opportunity to prepare, if we have the will – and strategy – oh, and tools – to do it. And no, I’m not talking about the “build a bunker and buy 1,000 cans of beans” kind of preparation. I’m talking about a smarter, modern approach to managing access.
13 StrongDM Use Cases with Real Customer Case Studies
13 StrongDM Use Cases with Real Customer Case Studies
Managing access to critical infrastructure is a challenge for many organizations. Legacy tools often struggle to keep up, creating inefficiencies, security gaps, and frustration. StrongDM offers a modern solution that simplifies access management, strengthens security, and improves workflows. In this post, we’ll explore 13 real-world examples of how StrongDM helps teams solve access challenges and achieve their goals.
What Is Network Level Authentication (NLA)? (How It Works)
What Is Network Level Authentication (NLA)? (How It Works)
Network Level Authentication (NLA) is a security feature of Microsoft’s Remote Desktop Protocol (RDP) that requires users to authenticate before establishing a remote session. By enforcing this pre-authentication step, NLA reduces the risk of unauthorized access, conserves server resources, and protects against attacks like credential interception and denial of service. While effective in securing RDP sessions, NLA is limited to a single protocol, lacks flexibility, and can add complexity in diverse, modern IT environments that rely on multiple systems and protocols.
How to Automate Continuous Compliance in AWS with StrongDM
How to Automate Continuous Compliance in AWS with StrongDM
Enterprises seek ways to effectively address the needs of dynamic, always-evolving cloud infrastructures, and StrongDM has developed a platform that is designed with built-in capabilities to support continuous compliance in AWS environments.