Home / Companies / P0 Security / Blog / March 2024

March 2024 Summaries

2 posts from P0 Security

Filter
Month: Year:
Post Summaries Back to Blog
Divvy, a financial technology company offering a rent-to-own program, faced challenges with their legacy Privileged Access Management (PAM) solution in managing access to sensitive customer data stored on cloud-native platforms like Google Cloud Platform (GCP) and Snowflake. The legacy system was cumbersome, required a complex setup, and was not user-friendly for their developers who frequently faced difficulties with access requests and management. To address these issues, Divvy transitioned to the P0 solution, which streamlined access control by providing just-in-time access, seamless Slack integration for access requests, and automated on-call access through PagerDuty. This transition improved the developer experience by reducing the mean-time-to-resolution for access requests and enhancing security by offering visibility into over-provisioned access and unused keys, thereby reducing operational overhead and increasing efficiency and security in handling sensitive financial data.
Mar 01, 2024 639 words in the original blog post.
Divvy Homes, a financial technology company offering a rent-to-own program, improved its visibility and control over privileged access by adopting a modern cloud-native solution called P0. This transition was necessary due to challenges with the previous legacy Privileged Access Management (PAM) system, which was cumbersome to deploy and manage, particularly for cloud-native resources like Kubernetes and Snowflake. The old system also lacked effective control over cloud entitlements and created operational overhead due to its reliance on proxy deployment. P0 facilitated a smoother developer experience by simplifying access requests through Slack integration and automating on-call processes using PagerDuty, which significantly reduced the mean-time-to-resolution for access requests. The migration to P0 enhanced Divvy's security posture by providing insights into over-provisioned access and unused keys, thereby optimizing their journey towards SOC2 compliance and allowing the infrastructure team to focus more on revenue-driving initiatives.
Mar 01, 2024 668 words in the original blog post.