Home / Companies / Veza / Blog / May 2023

May 2023 Summaries

7 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
In this monthly customer email, Veza introduces powerful new Identity Analytics with user analysis, group analysis, and role analysis capabilities to help IAM teams understand complex RBAC permissions. Additionally, new policy analysis for separation of duties requirements is introduced, allowing security teams to compare the results of multiple complex queries and link identities directly to their permissions to sensitive data. Furthermore, Salesforce posture and misconfigurations insights are provided, along with updates on Veza's integrations with NetSuite, AWS EKS, Workato, OneLogin, Azure AD, and Active Directory. Custom dashboards for tracking trends in access security and privileged access are also highlighted. Finally, upcoming events at Identiverse, AWS re:Inforce, and Snowflake Summit are mentioned, along with a featured webinar on safely deprovisioning access when employees depart.
May 31, 2023 966 words in the original blog post.
The text discusses a journey through the history of hacks and data breaches, focusing on server-side request forgery (SSRF) attacks on AWS, specifically the Capital One hack in 2019. It highlights that while attackers' tools and strategies evolve, Least Privilege is an effective defense strategy.
May 31, 2023 85 words in the original blog post.
The principle of least privilege is crucial in the security world as it limits the damage that can be caused by compromised identities and reduces the scope for catastrophic error or intentional sabotage. However, achieving least privilege is challenging due to scale, complexity, visibility issues, and productivity concerns. Manual access reviews are often ineffective at reducing excess privileges, highlighting the need for better tools and processes. Veza is an authorization platform that enables organizations to achieve least privilege by providing granular permission visibility, continuous monitoring, and intelligent access reviews with automation capabilities.
May 25, 2023 3,042 words in the original blog post.
The migration to the cloud and adoption of Software as a Service (SaaS) has become prevalent over the last couple of decades, with organizations maintaining an average of 125 different SaaS apps. While this offers benefits such as remote work capabilities and easy scaling, it also introduces new security challenges. Veza can help manage these risks by tracking permissions across all SaaS applications, monitoring for changes in access, and addressing excess privileges, best practice violations, and misconfigurations promptly.
May 25, 2023 201 words in the original blog post.
Ransomware attacks are on the rise and becoming more complex, causing significant damage to organizations in terms of budget, cycles, and brand reputation. These attacks involve malware locking users out of their files and demanding payment for access. The most prevalent types of ransomware include encryptors, screen lockers, and scareware. Ransomware-as-a-Service (RaaS) campaigns make it easy for cybercriminals to launch attacks without specialized expertise. To prevent ransomware attacks, organizations should focus on education, data backups, maintaining strong cybersecurity posture, vulnerability management, and implementing least privilege access.
May 19, 2023 2,167 words in the original blog post.
Veza has released several product features and enhancements in April 2023, including a Salesforce Misconfigurations report offering insights into common identity risks. Users can now set "Critical" or "Warning" risk levels for saved queries, with results appearing on the Insights > Risks page. The Access Risks Summary section is added to the Veza landing page, and users can manage exceptions for risks. Authorization Graph and Query Builder now highlight risks by default. Saved Query enhancements include new filters and redesigned sections. Integrations have been updated with a new NetSuite connector, GitHub Enterprise integration (Early Access), and automatic mapping of Azure AD Users to Snowflake Local User accounts. Veza Access Workflows features include tags in certification results (Early Access), single-action Approve and Sign Off (Early Access), Saved Filters (API Preview), and Notification Templates (API Preview).
May 12, 2023 758 words in the original blog post.
The rapid adoption of Software as a Service (SaaS) applications across enterprises has led to significant security risks that often go unnoticed by security teams. Despite these risks, the benefits of SaaS are substantial enough for organizations to continue adopting it. To ensure safe usage of SaaS applications, an identity-first approach focusing on authorization is crucial. Key vulnerabilities in SaaS environments include weak passwords, shadow IT, provisioning challenges, insider threats, misconfigurations, and lift & shift vulnerabilities. Automating SaaS access governance can help organizations manage these risks effectively by ensuring the right people have access to the right applications at the right time. Implementing a Zero Trust architecture is essential for maintaining robust security posture management in SaaS environments. Veza's Authorization Graph provides comprehensive visibility into identity-to-data relationships, enabling intelligent access reviews and threat detection across all platforms within an organization.
May 03, 2023 1,718 words in the original blog post.