Home / Companies / P0 Security / Blog / June 2025

June 2025 Summaries

4 posts from P0 Security

Filter
Month: Year:
Post Summaries Back to Blog
Lalit Choda, founder of the NHI Management Group, recently hosted discussions on non-human identities (NHIs) highlighting the security challenges they present. Participants, including the author and Kirby Fitch from SailPoint, discussed the industry's inconsistency in NHI terminology and the urgent need for standardized governance. The panel underscored the importance of distinguishing between credentials and identities, noting that most organizations struggle to understand who or what can access specific resources, leading to reactive and fragmented governance. Insights from Vincenzo Iozzo and Michael Silva illustrated real-world threats, including a significant increase in credential-based attacks and a demonstration of exploiting NHIs through stolen AWS credentials. The discussions emphasized the necessity of comprehensive identity security involving posture, governance, and orchestration to mitigate risks associated with both human and non-human identities.
Jun 23, 2025 435 words in the original blog post.
In a recent panel discussion hosted by Lalit Choda at Identiverse, the urgent issue of managing non-human identities (NHIs) in cybersecurity was explored, highlighting the industry's inconsistency in terminology and governance. Experts emphasized the need for clearer distinctions between credentials and identities, as well as a standardized framework for access management across different systems like AWS, Azure, and GCP. The panelists, including Kirby Fitch, discussed the challenges organizations face in answering fundamental questions about access control, often resulting in fragmented and reactive governance efforts. Vincenzo Iozzo and Michael Silva provided real-world examples of how NHIs are exploited, noting a significant increase in credential-based attacks and demonstrating how attackers use leaked credentials to move undetected across cloud services. The discussion underscored the necessity for identity security measures that extend beyond visibility, advocating for comprehensive governance and short-lived, least-privileged access policies.
Jun 23, 2025 458 words in the original blog post.
Developed by security experts for CISOs, this guide addresses the complexities of modern cloud identity management, highlighting the challenges posed by ephemeral workloads and AI agents in today's cloud environments. It emphasizes that there is no single maturity phase but rather a spectrum of fragmented controls and evolving risks. The guide presents a 6-phase cloud identity maturity model designed to help organizations assess their current position on the identity maturity curve and plan their next steps. It provides real-world patterns and potential pitfalls to avoid, aiming to assist teams in benchmarking, prioritizing, and communicating their access strategies effectively, without any commercial pitches or vendor influences.
Jun 09, 2025 153 words in the original blog post.
P0 Security's Lunch-and-Learn series offers a concise 15-minute virtual session designed to enhance access governance and identity security for organizations by providing practical strategies for managing both human and machine identities. Participants will learn to implement just-in-time access for sensitive resources such as S3 and Kubernetes using developer-friendly tools like Slack and Teams, and automate access reviews and lifecycle management through integrations with Slack, JIRA, and Terraform. Tailored for security engineers and team leaders, the session includes actionable steps to improve security practices, and attendees will receive a DoorDash gift card for lunch. Held monthly on the third Thursday, the event aims to equip security professionals with the knowledge to streamline identity management in production environments.
Jun 09, 2025 261 words in the original blog post.