October 2023 Summaries
7 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
Okta recently announced that unknown attackers had compromised their customer case management system, using stolen credentials to access HAR (HTTP archive) files shared with customers for troubleshooting single sign-on issues. The breach highlights the risks of relying on third-party providers and the importance of protecting sensitive data. Organizations can take steps to protect themselves by never sharing unsanitized HAR files, protecting all systems that touch customer data, including SaaS and customer support apps, and prioritizing identity security with an "assume breach" mentality. This includes implementing least privilege access controls to prevent catastrophic breaches. A solution like Veza's next-gen Identity and Access Governance (IGA) can help organizations achieve these goals by providing visibility into permissions, monitoring for excess privilege, and enabling intelligent access reviews.
Oct 27, 2023
950 words in the original blog post.
At Gartner's IT Symposium/Expo in Orlando, recurring themes included preparing for growth, AI implementation, ransomware acceleration, building an identity fabric, investing in security outcomes, and reducing the friction of security. CEOs are cautiously optimistic about the economy and prioritizing growth over cost management. With increased investment in cloud platforms, BI/data analytics, and application modernization, IT teams will see a larger attack surface. AI is becoming increasingly important, with 56% of CEOs citing it as a top-impact technology. Ransomware attacks are expected to increase due to the use of generative AI in phishing emails. An identity fabric is necessary for safeguarding IAM assets and reducing vulnerabilities. Investing in security outcomes involves focusing on measurable protection levels, while reducing friction can promote cyber judgment among employees.
Oct 27, 2023
2,019 words in the original blog post.
Okta recently reported that unknown attackers accessed their customer case management system using stolen credentials. The attackers were able to access HAR files containing sensitive data such as credentials, cookie IDs or session tokens. Okta claims about 1% of customers are potentially affected by the incident and has provided Indicators of Compromise for customers to check against their logs. This highlights the level of trust organizations place in third-party providers and the dangers that can result from compromised vendors. Three lessons to take away from this attack include: never share an unsanitized HAR file, protecting your production app isn't enough, and identity is the weakest link in security.
Oct 27, 2023
906 words in the original blog post.
The Gartner Symposium, taking place from October 15-19 in Orlando, is an event where security professionals and executives can network and learn from each other. Attendees are encouraged to visit booth #836 for product updates, customer stories, or a demo. Veza's Chief Strategist, Rich Dandliker, will speak about achieving least privilege on October 18 at the IT Xpo Future Directions Stage in Pacific Hall. An exclusive experience at Epcot is also available with cocktails, dinner, and fireworks, followed by walk-on access to Ratatouille. A discount code for registration is SYM33EDC.
Oct 25, 2023
219 words in the original blog post.
In this episode of Identity Radicals, we have an insightful conversation with David Tyburski, VP of Information Security and CISO at Wynn Resorts. With over 15 years in the industry, David shares his expertise on leveraging automation to manage user access throughout its lifecycle. He discusses the importance of identity management and access control in cybersecurity, emphasizing the significance of pre-authorization and continuous monitoring. Additionally, he highlights the benefits of automating security processes, which can alleviate audit teams' workload and allow them to focus on more pressing issues.
David also shares his experiences as a leader in advancing the security field, offering tips on networking, professional growth, and understanding the industry. He advocates for sharing knowledge within the cybersecurity community, stating that it is crucial for professionals to share processes, techniques, and other valuable information.
Identity Radicals is a podcast hosted by industry experts, featuring exclusive interviews with security executives. It covers critical topics in identity security and provides practical advice, real-world examples, and actionable solutions for both seasoned professionals and those looking to enhance their understanding of the subject. The podcast is brought to you by Veza, offering demos and free trials for interested parties.
Oct 20, 2023
389 words in the original blog post.
The text discusses the importance of identity security in today's digital landscape, highlighting that identity is considered the new perimeter for businesses and plays a critical role in their growth and cybersecurity. It explains how Veza, a world-class team, aims to advance the state of the cybersecurity industry by focusing on three GTM principles: "Why anything?", "Why Veza?", and "Why now?". The text delves into the increasing complexity of authorization in cloud-native systems, mass-market adoption of cloud-based authentication systems, and the need to secure non-human identities as well. It also emphasizes the importance of modernizing identity governance and adding monitoring to privilege access management. Furthermore, it introduces Next-Gen IGA by Veza, a game changer in identity security for the entire multi- and hybrid-cloud world.
Oct 10, 2023
1,321 words in the original blog post.
"Identity Radicals" is a podcast hosted by industry experts and featuring exclusive interviews with security executives. The show covers critical topics related to identity security for organizations both in the cloud and on-premises. In this episode, guest Rachel Wilson, head of Cyber Security at Morgan Stanley Wealth Management, discusses the growing concern of identity-based targeting and vulnerabilities in our interconnected world. She highlights that Multifactor Authentication (MFA) alone is insufficient for robust security and emphasizes the importance of monitoring employee behavior to identify abnormalities. The podcast also explores scaling security measures practically while maintaining risk management and compliance adherence, addressing security queries from boards, automation in cybersecurity defenses, and talent recruitment in the field.
Oct 05, 2023
378 words in the original blog post.