Insights & Data

Why Unified Identity and Endpoint Security Matters More for African Organisations

Why Unified Identity and Endpoint Security Matters More for African Organisations
Share

Cyber attackers increasingly use valid credentials to enter systems, making malicious activity look like ordinary work. That shift exposes the limits of security programmes that monitor devices and identities separately.

CrowdStrike argues that unifying both layers can improve visibility, response time and operating efficiency.

For African organisations with lean teams, the governance case is as important as the technology.

Credentials Have Become the New Perimeter

The familiar image of a cyberattack begins with malicious software landing on a laptop. The more difficult threat may begin with a valid username and password.

  • Once an attacker looks like an authorised employee, conventional endpoint controls can struggle to distinguish an intrusion from normal activity.

That problem stretches from office computers to cloud workloads, remote access tools and identity stores.

  • It is especially important for African banks, telecommunications companies, public agencies and fast-growing digital businesses, where service disruption or stolen customer data can quickly become a governance, regulatory and public-trust issue.

CrowdStrike eBook on identity and endpoint security sets out five reasons for combining the two disciplines:

  • Protection against Active Directory attacks.
  • Faster response.
  • Stronger defence against advanced threats.
  • Lower costs.
  • Better operational efficiency.

Its central argument is straightforward.

  • Security teams need one view of who is acting, which device is involved and what the account is trying to reach.

Stolen Access Can Defeat Traditional Defences

The supplied report says 90% of organisations depend on Microsoft Active Directory.

  • It also cites research indicating that half of organisations had experienced a recent Active Directory attack and that 40% of those attacks succeeded.

These figures come from sources published in 2020 and 2021, so they should be read as evidence of a persistent exposure rather than a current global census.

Speed raises the stakes.

  • CrowdStrike's 2023 Threat Hunting Report put average adversary breakout time, the period before an intruder begins moving laterally, at 79 minutes.
  • The eBook also reported that more than two-thirds of attacks were malware-free.

An analyst waiting for a malicious file may therefore miss an attacker who is using legitimate credentials and standard administrative functions.

The governance implication is clear.

  • Identity cannot remain only an access-management function, while endpoint security sits elsewhere in the technology department.

Boards and executives need assurance that account behaviour, device activity and cloud access can be correlated quickly enough to stop a breach before it spreads.

Five Reasons Integration Reduces Security Exposure

The first benefit is fuller visibility around Active Directory and other identity systems.

  • A compromised account can move through an organisation without deploying obvious malware.
  • Joining identity signals to endpoint telemetry helps investigators see the account, device and destination as one attack path.

The second benefit is time.

  • The eBook says organisations using a combined platform can respond to threats up to 85% faster and avoid about 5,000 investigation hours each year.

The third is coverage against techniques that use trusted tools.

  • The report describes attackers using Azure Run Commands and PowerShell to place remote-management software on cloud virtual machines, activity that may appear legitimate when each signal is viewed alone.

The experience cited for Land O'Lakes shows what integration can look like in day-to-day operations.

  • The company reported that investigations and responses to identity-related anomalies became 92% faster, manual identity-hygiene audits required 90% less time, vulnerability prioritisation fell by 85%, and accounts with excessive permissions declined by 80%.

Those results came from one customer case, but the measures are useful because they connect technical changes to work that executives can understand and verify.

There is also a control-design advantage.

  • One sensor and a shared data layer can support policies at both the account and device level.
  • A high-risk login from an unmanaged endpoint, for example, can trigger stronger authentication, restricted access or automated containment.

The decision is stronger when it draws on several signals instead of a password event or device alert in isolation.

Consolidation Can Lower Cost and Friction

The fourth and fifth reasons concern the economics of defence.

  • The eBook says many organisations operate more than 45 security tools. Each additional product can bring another contract, update cycle, data format, support channel and integration task.
  • For a small security team, these demands consume the same staff time needed for threat hunting and remediation.

CrowdStrike estimates that combining endpoint and identity protection can save up to $2 million over three years, cut compliance and support costs by 75%, and improve operational efficiency by 84%.

Those figures draw on more than 100 projected and realised business-value assessments completed between 2018 and December 2022.

  • Outcomes vary by customer, which makes a local baseline essential before any procurement decision.

The most useful lesson is more than a single vendor.

  • Consolidation creates value when it removes duplicate coverage, shortens investigations and improves control.
  • It creates risk when an organisation replaces several imperfect tools with one poorly configured platform, accepts vendor lock-in without safeguards or assumes that technology can compensate for weak identity governance.

African Organisations Need A Unified Response

Security leaders should begin with an exposure map.

  • It should identify privileged accounts, dormant identities, service accounts, remote-access routes, unmanaged devices and cloud workloads.
  • That map can show where identity and endpoint data are disconnected and which gaps create the greatest operational risk.

The next step is a controlled consolidation assessment.

  • Organisations can compare licences, renewal dates, incident-response time, analyst hours, false positives and audit effort before selecting a platform.
  • Procurement teams should test data portability, integration with existing systems, local support, incident escalation and recovery arrangements.

Boards should receive measures that show reduced risk, not simply a lower tool count.

Basic controls still matter:

  • Multifactor authentication, least-privilege access, rapid removal of stale accounts, protected backups, regular tabletop exercises and clear responsibility for identity incidents.

A unified platform can help teams enforce these controls, but management must retain accountability.

  • Cyber resilience becomes credible when technical integration is matched by oversight, evidence and repeated testing.

Performance reporting should include median detection and containment time, the number of privileged and dormant accounts, multifactor authentication coverage, unresolved high-risk identity findings, control exceptions, and lessons from exercises.

Reporting the trend over time gives directors a clearer view than a single compliance score. It also helps management identify whether a lower security bill reflects genuine simplification or a dangerous reduction in capability.

Path Forward – Building Resilience Around Identity and Devices

African organisations should connect identity and endpoint monitoring around their highest-risk accounts and systems, then measure whether detection and response actually improve.

Tool reduction should follow verified control coverage, not precede it.

The objective is a defensible security model: fewer blind spots, faster containment, clearer accountability and reliable evidence for boards, regulators and customers.

That strengthens governance and protects the digital services communities and economies increasingly depend on.

More Insights & Data

Start typing to search...