Issues 2

Why licensing has become a cybersecurity issue

Stephen Foley, Managing Director of Micromail, a Presidio company, explores why software licensing has become a critical part of cyber resilience. He explains how the right licensing strategy can strengthen security, improve compliance, and unlock greater value from existing technology investments.

For most public sector organisations, software licensing sits firmly in the “administrative” column: a procurement exercise, a compliance checkbox, a line item to be renewed and forgotten. Security sits somewhere else entirely; with the CISO, the security team, the incident response plan. It is a natural enough division of labour. It is also increasingly out of date.

Over the past few years, the products organisations already own have quietly become one of the most consequential and most underused levers in their security posture. The tools are often already paid for. The problem is that very few organisations know it.

Security you have already paid for

Take Microsoft’s enterprise agreements, which underpin much of the public sector’s IT estate in Ireland. Depending on the licence tier an organisation holds, a significant portion of the Microsoft 365 and Azure security stack such as conditional access, multi-factor authentication, mobile device management, information protection, or advanced threat protection may already be included, or a small step away from an existing entitlement.

In practice, what we see time and again during licence reviews is public bodies running parallel procurement processes: buying third-party security tools for capabilities they are already licensed to use, simply because nobody has mapped the entitlement against the requirement. In a budget environment where security spend must be justified line by line, paying twice for the same protection is a problem worth solving.

This is the first, and often the most immediately actionable, place where licensing and security intersect: understanding what you already hold.

Identity is the new perimeter

The second is identity and access management, which is now arguably the primary battleground for cyber defence. Firewalls and network boundaries matter less than they used to, because attackers increasingly go after credentials, not infrastructure, as has been seen in some recent prominent cyber-attacks on public sector bodies.

Licence estates determine directly what identity controls an organisation can actually deploy; how it enforces multi-factor authentication, how it manages privileged access, how it governs guest and third-party access to shared systems. An organisation licensed at the wrong tier is not just missing convenience features; it may be missing the specific identity controls that would have stopped a real, common attack pattern. Getting the licensing model right is a security design decision, not just a finance one.

Compliance and audit readiness

The third strand is compliance. Public sector bodies operate under some of the most demanding audit and governance regimes anywhere in the economy, and licensing sits closer to that obligation than most people assume. An unclear picture of what is deployed, by whom, and under what entitlement is not just a commercial risk if an unexpected true-up lands, it is a governance gap.

Auditors, and increasingly cyber insurers, want accurate, current records of software assets and access rights. That record-keeping is, in effect, security hygiene: you cannot secure or govern an estate you cannot accurately describe. A well-managed licensing position gives an organisation a live, defensible inventory; the starting point for any credible incident response or risk assessment.

“Getting the licensing model right is a security design decision, not just a finance one.”

AI adds a new layer

The rapid rollout of Microsoft 365 Copilot and similar tools across the public sector has sharpened this picture rather than changed it. Copilot is only as well governed as the licensing and permissions structure underneath it: if data access controls and information protection policies are not correctly configured before it goes live, Copilot will simply surface whatever a user’s existing permissions allow including, potentially, records they should not see. That is not really an AI problem. It is a licensing and identity problem AI has made impossible to ignore.

There is a ‘shadow AI’ risk building alongside the familiar shadow IT one, too; staff turning to unsanctioned AI tools outside any governed environment, often without weighing up where their data ends up. The organisations best placed to adopt AI safely are the ones that already have their licensing and identity foundations in order, which is a reason to bring a licensing review forward, not delay it.

Licensing as a resilience discipline

Pull those threads together and a pattern emerges: licensing management and cyber resilience are no longer separate disciplines. An accurate, well governed licence estate gives an organisation visibility over its software footprint, control over who can access what, and assurance that security features are switched on rather than dormant in an agreement nobody has read closely. Licensing left to drift – mismatched tiers, unused entitlements, shadow deployments – creates exactly the blind spots that attackers, and auditors, tend to find first.

This is why we increasingly treat licensing reviews as a security and compliance exercise, not just a cost-optimisation one. Our conversations with clients are not just about whether they are paying for the right licences or services. They are about ensuring what they pay for matches their security needs, is configured to deliver the expected level of protection, and provides real value for money.

Getting full value from Microsoft security investments

For public sector bodies operating on Microsoft frameworks in particular, this is a genuine opportunity. Many organisations are sitting on unused or under configured security capability within agreements they have held for years. Realising that value does not necessarily require new spend; it requires a proper audit of entitlements against actual security requirements, and the expertise to configure and roll out what is already there.

That is a different conversation to the traditional licensing renewal, and it is one more public sector organisations should be having. As Micromail – part of Ergo and now Presidio following Ergo’s recent acquisition – works across the frameworks underpinning Irish public sector procurement, this is where we see the most value being left on the table: not in what organisations need to buy, but in what they already own and are not yet using.

The starting point is simple. Before any organisation adds another security tool to its stack, it is worth asking a more basic question: what does our existing licensing already give us; and are we actually using it?

E: Stephen.Foley@micromail.ie
W: www.micromail.com

Show More
Back to top button