Home / Companies / Veza / Blog / December 2023

December 2023 Summaries

6 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
The migration of data and infrastructure to the cloud has increased the scale, scope, and complexity of identity security. However, traditional tools for identity security and governance have not evolved significantly from the on-prem era, leaving security teams struggling to manage risky permissions that can empower attackers when identities are compromised. This article discusses policy-violating permissions, which violate aspects of a company's data or security policies and may threaten compliance with regulatory frameworks. Examples include segregation of duties violations, sovereignty violations, and misconfigured identities. Companies found not to be complying with frameworks like Sarbanes-Oxley (SOX) face penalties from enforcing agencies, loss of business, reputational damage, and increased scrutiny from regulators. Policy-violating permissions often go unnoticed due to a lack of visibility into the true permissions identities have, vague or inaccurate group/role names, incomplete metadata, and siloed data. Veza's Authorization Graph can help enforce segregation of duties by linking any identity to its granular permissions across SaaS apps, cloud infrastructure, and custom apps. It also provides comprehensive identity and resource metadata and highlights missing key metadata like location or department.
Dec 21, 2023 1,026 words in the original blog post.
Veza has coined a new term, Intelligent Access, which leverages automation and next-gen IGA to ensure organizations can confidently answer who can take what action on what data. This approach covers all systems, identities, and permissions, providing a complete picture of access within an organization. Intelligent Access is "intelligent" because it automates decision-making, enabling continuous monitoring of access, and automatically finds and fixes dormant accounts, segregation of duties violations, and local admin accounts that were not approved. The goal of privilege management is to make sure all subjects are known, objects are known, policies are defined, and the reality corresponds to policy intent. Veza's Access Control Platform enables identity governance, monitoring privilege, investigating identity threats, automating access reviews, and bringing access governance to enterprise resources like SaaS apps, data systems, cloud services, infrastructure services, and custom apps.
Dec 20, 2023 876 words in the original blog post.
Veza is an Access Control Platform that focuses on enabling identity governance for organizations. The company aims to help businesses secure access to their data by making the principle of least privilege achievable at scale. They believe that understanding "who can take what action on what data" is crucial, and this information lies within identities and associated permissions to data everywhere (SaaS apps, databases, cloud services, etc.). Veza's platform helps companies monitor privilege, investigate identity threats, automate access reviews, and bring access governance to various enterprise resources.
Dec 20, 2023 1,402 words in the original blog post.
The migration of data and infrastructure to the cloud has increased the scale, scope, and complexity of identity security. However, tools for identity security and governance have not fundamentally changed from the on-prem era, leaving security teams struggling to keep up with rising identity-based attacks. Excessive permissions are a major issue in this context, as they result from inaccurate or overly broad permission grants that allow identities to perform actions which were never necessary. This can increase the risk of sensitive data being compromised without accomplishing anything useful for the identity that holds them. To tackle excessive permissions, organizations need to improve visibility into effective permissions and develop business intelligence and metrics to help spot excessive privilege. Automated continuous monitoring of permissions across the stack is also crucial in addressing this issue. Veza's Authorization Graph can connect any identity with its actual permissions to any resource, helping IT and IAM teams validate access decisions and identify employees or machine identities with a high blast radius for prioritizing risk mitigation efforts.
Dec 16, 2023 1,243 words in the original blog post.
Identity security is crucial for ensuring that users have appropriate access to apps and databases. In today's globalized work environment, managing multiple digital identities, authorization for each identity, and securing enterprise data pose significant challenges. To address these issues, enterprises use tools like Identity Providers (IdP) and Single Sign-On (SSO). However, weak identity security persists due to "Shadow IT" and overpermissioning. Effective identity security requires implementing least privilege access controls and visualizing who can do what with which data.
Dec 08, 2023 1,125 words in the original blog post.
In a podcast episode, Rachel Wilson discussed the importance of layered security strategies, not relying solely on multi-factor authentication, assuming breaches will occur and preparing for them, rigorous control and monitoring of user authorization, and embracing automation and developing cybersecurity talent. Key points include implementing robust defenses, efficient detection mechanisms, continuous access evaluations, AI-driven anomaly detection, real-time monitoring, incident response plans, employee training, and fostering a culture of continuous learning in cybersecurity.
Dec 01, 2023 438 words in the original blog post.