A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Manage HR Advisory Board.



Willie Clemons is the Director of Identity and Access Management at EBSCO Industries. As a seasoned information systems executive with over 31 years of experience in critical business requirements, identifying deficiencies and potential opportunities, database security monitoring, and access management, he brings a wealth of qualities required for his role.
As the Director of Identity and Access Management, could you describe your key responsibilities at EBSCO Industries?
I have been working with EBSCO for five years now. I primarily focus on workforce identity lifecycle management as part of my role. Additionally, I supervise my team in managing and securing the access of employees throughout the organization, which involves tasks such as creating and managing accounts, privileged access management, and enforcing identity-related policies.
Please shed some light on some of the challenges prevailing in the industry.
The fear of ransomware is a universal concern in today's security landscape. It is often disheartening to hear about companies being compromised through phishing attacks. I believe that the strength of an organization lies in its weakest links, such as human users. Whether it's an ordinary employee with limited privileges or a highly skilled systems administrator who clicks on the wrong link, it can inadvertently give access to unauthorized individuals. To avoid such data breaches, we prioritize protecting our users and resources at EBSCO Industries while giving them the necessary access to perform their work efficiently.
“I believe that the strength of an organization lies in its weakest links, such as human users. Whether it's an ordinary employee with limited privileges or a highly skilled systems administrator who clicks on the wrong link, it can inadvertently give access to unauthorized individuals.”
How do you effectively manage user identities at EBSCO Industries?
When it comes to cybersecurity, we need to adopt a zero-trust mentality and prioritize the delegation of access and proper management of privileged accounts. Additionally, we must emphasize educating employees through a learning management system to ensure regular awareness training. Newsletters or emails can be used to remind employees not to comply with any unauthorized or suspicious requests. At the end of the day, everything comes down to human involvement and the best practices that an organization adopts to enhance cybersecurity.
Is there a recent security initiative that you have been working on lately?
We dedicate significant time to addressing business email compromise and implementing safeguards against external threats. Implementing a new policy, in this instance, may not yield the intended result, as most employees do not read or follow them. Our learning management systems are aligned with the organizational objectives and reflect only what is most important, which helps employees focus on the key takeaways. We also consistently analyze various aspects of identity management to ensure our practices meet expectations. This proactive approach enables us to address significant changes, such as promptly removing departed employees from the database and restricting their access. By conducting regular analysis and making necessary adjustments, we strive to maintain a robust and secure system that aligns with the best practices in identity management.
In light of your experience, what will be your advice to fellow peers in the industry?
In a world where technology is evolving steadfastly, preserving one's identity is crucial. Any tarnish or ruin brought upon your identity will stay with you forever. The same goes for organizations; mistakes that compromise your system can devalue your business.