April 2022 Summaries
8 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
Veza is a new company launching a data security platform that aims to make it easy for organizations to understand, manage, and control who can access their sensitive data in the cloud. The platform addresses the growing challenges of digital transformation and cyber crime by providing a single source of truth for authorization across various applications, data systems, and cloud services. Veza's solution includes real-time search capabilities, violation detection, and recommendations to help organizations maintain an ideal state of permissions. The company aims to empower security and data leaders with technology that enables them to build trust and unlock the value of their data.
Apr 27, 2022
1,361 words in the original blog post.
The text discusses the challenges and strategies for integrating authorization systems in various applications and platforms. It highlights that while authentication standards like SAML 2.0 and OpenID Connect are widely adopted, authorization standards are still in their infancy due to the complexity of varying actions and objects involved. This makes it difficult to build standardized integrations across different systems.
The author suggests focusing on the most important systems containing critical data such as customer or employee information. Veza's integration strategy involves building native integrations for larger, more complex systems with high demand and using Open Authorization API (OAA) for simpler ones or custom apps. OAA allows customers to build their own connectors, making it faster, free, and easy to integrate with the Veza platform.
The text emphasizes the importance of openness in enterprise products and encourages customers to experiment and discover the power of visualizing and managing authorization across any system. It also mentions a growing community that taps into customer's brilliance for solving complex problems together.
Apr 26, 2022
1,365 words in the original blog post.
Organizations are transitioning to zero trust security architectures to protect against breaches resulting from stolen or misused credentials. A key prerequisite for creating a zero trust architecture is a holistic approach to privileged access management (PAM). Many high-profile breaches have been made possible because privileged accounts were compromised or misused, making PAM solutions crucial. The market for PAM technology is expected to grow significantly in the coming years. To strengthen security across enterprises, experts recommend taking an architecture approach to privileged access management and implementing least privilege access throughout organizations. Veza's data security platform helps manage, understand, and control least privilege access to data, reducing the risk of credential misuse and data breaches.
Apr 25, 2022
1,111 words in the original blog post.
The text discusses the increasing exploitation of excess permissions in critical systems by threat actors as a leverage point for cyberattacks. It highlights how organizations moving to public clouds often enable a liberal approach to access rights, leading to unnecessary shadow privileges that can be easily exploited by attackers. The article also explains why cloud over-permissioning happens and the challenges faced in gaining visibility into effective permissions across multiple cloud providers. Finally, it introduces Veza as a solution to discover, understand, and normalize permissions, helping organizations uncover and remediate the sprawl of effective permissions and reduce their attack surface.
Apr 25, 2022
1,413 words in the original blog post.
The challenge of managing the complexity of AWS is growing rapidly as organizations increasingly turn to it for their public cloud needs. A 2020 Gartner report states that half of all cloud security failures stem from poor management of identities, access, and privilege, a number expected to rise to 75% by 2023. AWS IAM provides a solution to this problem by offering strong identity management for AWS users. It uses concepts like users, groups, roles, and policies to help enterprises determine who has what privileges over which resources. AWS IAM also improves reliability and performance across AWS solutions, and helps organizations remain compliant with regulatory compliance mandates such as HIPAA, PCI DSS, and emerging data privacy laws. However, for many enterprises, AWS IAM may not be sufficient on its own due to inherent complexity and other limitations. Veza can help by adding a dedicated, cloud-first data security layer that integrates fully with cloud-native infrastructure permissions systems like AWS IAM, allowing organizations to more easily understand and manage all the identities in their public cloud while keeping their data safe and their enterprise in compliance.
Apr 22, 2022
1,679 words in the original blog post.
Organizations are increasingly recognizing the value of their data and aiming to increase utilization and sharing across cloud platforms. However, traditional infrastructure-centric security solutions do not adequately secure multi-cloud data, leading to increased friction, security breaches, and compliance issues. To leverage data without compromising security, teams need to adopt a zero trust approach and make data authorization a fundamental pillar of their overall security strategy. This involves aligning the security approach with business priorities, evolving from siloed solutions to comprehensive data security platforms, and prioritizing data sharing initiatives. Many companies are already investing in modern cloud data architectures, which have shown significant improvements in business performance. However, challenges remain for organizations focusing on infrastructure-centric security when accelerating data sharing efforts. Veza offers a solution by reinventing data security for the multi-cloud era with a comprehensive data security platform built on the power of authorization, enabling organizations to confidently enable cloud-data-sharing while reducing the risk of breaches and compliance nightmares.
Apr 22, 2022
1,047 words in the original blog post.
Authorization is a growing challenge for enterprises as they shift towards complex multi-cloud ecosystems. It involves making informed, centralized decisions about who should take action on what enterprise resources. Strong security without easy accessibility adds friction, cost, and inefficiency to business operations, while easy accessibility without strong security leads to compliance nightmares and data breaches. Authorization is sometimes confused with authentication but differs as it provides authenticated identities with specific permissions to access, share or interact with enterprise resources. Organizations should shift their focus to authorization due to the rise of strong authorization limiting damage from cyberattacks, tightening data privacy laws and compliance mandates, building consumer trust, and supporting Zero Trust security models. Strong authorization can be fine-tuned to supply least privilege access without restraining productivity. Companies need new tools for strong authorization to provide always-on data access while keeping the enterprise safe from data leaks and security breaches.
Apr 07, 2022
1,357 words in the original blog post.
The text discusses the importance of data security in organizations and how modern approaches to data management have evolved. It emphasizes the significance of understanding authorization and managing it effectively, as well as connecting both people identities and machine identities for better visibility and control over data access. Compliance is also highlighted as a necessary process that should improve security rather than just being a formality. The text further stresses the need for practical solutions rooted in customer needs and avoiding new potential points of failure in customer infrastructure. It concludes by advocating for open extensibility over closed ecosystems, and determination to solve problems with optimism.
Apr 06, 2022
737 words in the original blog post.