Home / Companies / Veza / Blog / March 2023

March 2023 Summaries

7 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
Zero Trust has become mainstream in security, emphasizing the need for authentication and authorization as pillars of security rather than relying on perimeter-based security models. The "front door" of access is crucial to Zero Trust, with identity being its lifeblood. Common identity tools like IGA and IAM are insufficient to solve the problems of authorization and achieve Zero Trust due to issues such as managing permissions with naming conventions, unique permission languages for each integrated system, narrow targets, unresolved identity errors, slow and expensive integrations, and lack of coverage for service accounts. To get to Zero Trust, a practical solution is needed that provides visibility into end-to-end permissions, meets compliance demands, automates least privilege work, and uses a graph database to manage relationships and paths connecting identities, actions, and resources. Veza's Authorization Graph addresses these challenges by showing the reality of permissions today, connecting to over 60 different systems, and enabling users to find and fix over-permissioning in their environment.
Mar 20, 2023 1,330 words in the original blog post.
Companies are struggling with implementing zero trust strategies due to challenges in managing employee identities and access permissions. The panelists, including Nicole Perlroth, Ted Schlein, and Tarun Thakur, discussed how the shift from traditional perimeter-based security models to cloud-based systems has made it difficult for organizations to control access to sensitive data. They also highlighted the importance of automating identity management and authorization processes using technologies like Veza's Authorization Graph. The panelists believe that addressing these challenges is crucial for improving cybersecurity in today's evolving digital landscape.
Mar 20, 2023 546 words in the original blog post.
Gertie the Goat, an experienced CISO and new member of Veza, shares her reasons for joining the company. She explains that as a security professional, she is often blamed for incidents out of her control due to factors such as employee errors or sophisticated attackers. Despite investing in various security measures like employee training, CSPM, and MFA, Gertie found it challenging to achieve least privilege access management. IGA tools also had limitations, leading her to search for a better solution. She discovered Veza, which offers an identity-first approach to security, allowing her to make progress on least privilege and secure data, SaaS apps, and source code. Gertie is joining the company to take this movement global and empower other CISOs with a new approach to identity-first security.
Mar 20, 2023 907 words in the original blog post.
The Gartner Identity & Access Management Summit is set to take place from March 20-22nd in Grapevine, Texas. Attendees can find Veza at booth #117 for product updates and demos. A presentation by David Tyburski of Wynn Resorts and Rich Dandliker of Veza will discuss managing access permissions for over 20,000 identities and hundreds of apps. Executive dinners are also being hosted during the conference, with spots still available at Old Hickory Steakhouse on March 20th.
Mar 20, 2023 257 words in the original blog post.
The text discusses the ideal practice of granting access to applications through group membership rather than direct assignment via an identity provider (IdP). It highlights that bypassing groups can complicate access governance, lead to unnecessary expenses on SaaS licenses, and increase security risks. However, implementing this best practice in a busy work environment is challenging. The text introduces Veza, a tool that simplifies the process of identifying direct app assignments in an IdP through a simple query. To explore more about Veza, scheduling a demo is suggested.
Mar 10, 2023 111 words in the original blog post.
Veza has released a series of product updates, including an enhanced Insights experience with customizable Authorization Risk Dashboard, private and public reports, improved report design, and Path Summaries for Google Cloud to provide visibility into how identities gain access to projects. Additionally, new integrations have been added for Bitbucket Server, Jira Server, Box, and ServiceNow. Tips on tracking user access to SaaS apps via Okta are also provided. Upcoming events include meetups in Chicago, SecureWorld East, Gartner IAM, and RSA. Veza has also announced the launch of its GitHub integration to prevent IP theft and enforce access policies on source repositories.
Mar 01, 2023 1,229 words in the original blog post.
GitHub is an increasingly important part of many organizations' IT infrastructure, hosting over 300 million repositories and used by 94 million software developers. However, the massive proliferation of source code on the platform has made it a more attractive target for cybercriminals. Risks include secrets exposure, attack path analysis, supply chain attacks, and Infrastructure-as-Code vulnerabilities. Challenges to securing source code in GitHub include complexity of access controls, private and public repositories in the same organization, and mingling of company and personal identities. Veza offers a solution by capturing identity and authorization metadata from various platforms, allowing users to track access permissions for all contributors and understand effective permissions.
Mar 01, 2023 1,294 words in the original blog post.