Home / Companies / Veza / Blog / February 2024

February 2024 Summaries

6 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
Delinea, a Privileged Access Management (PAM) company, has recently acquired Fastpath, an Identity Governance and Administration (IGA) vendor. This acquisition marks Delinea's expansion into the identity space. Fastpath is known for its provisioning, access reviews, and segregation of duties monitoring, with a focus on financial apps like Coupa and NetSuite. The acquisition supports the belief that PAM alone is not enough to secure identity access, and it appears that Delinea is building a portfolio of companies to offer a consolidated approach to identity security.
Feb 26, 2024 337 words in the original blog post.
Access governance is a crucial strategy for securing digital spaces by controlling who can see and use company information and tools. It involves overseeing and regulating user rights and privileges across various IT resources, ensuring employees only have access to the information they need for their jobs. The process has become more complex due to factors like the move to the cloud, application sprawl, and the complexity of new access models. Access governance plays a vital role in reducing complexity, improving efficiency, boosting security, staying compliant, and minimizing risk. It differs from other types of access management like Identity Access Management (IAM) and Identity Governance and Administration (IGA). Key best practices for effective access governance include adopting an "assume breach" mentality, documenting access governance policies, applying the principle of least privilege, conducting user access reviews, and collecting access intelligence. Veza's Intelligent Access is a revolutionary solution that ensures access governance keeps up with business speed by automatically adjusting permissions according to security policies for all identities and systems.
Feb 23, 2024 2,220 words in the original blog post.
On January 12, 2024, state-sponsored hacking group Midnight Blizzard breached Microsoft's infrastructure, exploiting excessive permissions granted to a legacy OAuth application and revealing machine identities as the key vulnerability. Limited visibility into true permissions of identities and limitations of role/group-based management contributed to the attack remaining undetected for so long. Veza offers comprehensive visibility into access rights for all identities, detailed insights into specific permissions held by each identity, and risk prioritization based on granular permissions evaluation, helping organizations protect against similar threats.
Feb 21, 2024 341 words in the original blog post.
The landscape of user access reviews has become increasingly complex due to the rise in cloud-based services and SaaS applications, with the average enterprise juggling 364 SaaS applications and 1,295 cloud services. This complexity is further exacerbated by the introduction of service accounts and machine identities, which often possess poorly understood permissions and are poorly monitored. The increasing sophistication of cyber attacks also means there's a greater chance for threat actors to exploit vulnerabilities or find gaps in security coverage. User access reviews (UAR) are crucial for maintaining the integrity of an organization’s security posture, ensuring sensitive information remains protected, and upholding compliance with various regulatory standards. They can be used as part of a defense in depth strategy that provides an extra layer of security to catch any provisioning (or deprovisioning) mistakes along the way and stick to the principle of least privilege. Performing user access reviews are crucial for maintaining the integrity of your organization’s security posture, ensuring sensitive information remains protected, and upholding compliance with various regulatory standards. They can be used as part of a defense in depth strategy that provides an extra layer of security to catch any provisioning (or deprovisioning) mistakes along the way and stick to the principle of least privilege. The importance of user access reviews cannot be overstated in our rapidly evolving digital landscape. These reviews are not merely a procedural checkbox, but a cornerstone of an effective cybersecurity strategy. They protect sensitive data, help organizations comply with standards, laws, and regulations, prevent privilege creep, decrease access debt, and reduce insider threats. To navigate user access reviews effectively, organizations should determine what systems should be reviewed, how often user access should be reviewed, identify who should review access for each role, generate user access reports, perform the access assessment, remove access for those who don’t need it, and re-run the access list to ensure access was appropriately removed. Best practices for conducting user access reviews include documenting your access control & management policy, implementing the principle of least privilege, automating the user access review process, and providing education and training on user access best practices. Challenges associated with user access reviews include understanding user access reviews vs access reviews, manual or outdated review processes, complex permissions, and lack of context during the review process. Modernizing user access reviews with Intelligent Access can help organizations overcome these challenges by providing a holistic view of all user and non-human access rights, automating the review process, ensuring compliance with regulatory standards, and reducing the risk of unauthorized access and potential data breaches.
Feb 16, 2024 2,516 words in the original blog post.
Cisco has announced the launch of its new "Identity Intelligence" product, which is set to be featured in an upcoming episode of Identity Security Spotlight. In this discussion, Veza Co-Founder and CEO Tarun Thakur, along with CMO Jason Garoutte, will share their thoughts on Cisco's announcement and why it might seem reminiscent of something else.
Feb 08, 2024 41 words in the original blog post.
In a recent chat, Tarun Thakur and Rich Dandliker discussed Microsoft's recent breach by Russian hacker group Midnight Blizzard. The attack involved a password spray attack on Microsoft's test environment, which lacked MFA requirements. Attackers gained access to an Oauth application, created additional applications, and compromised Microsoft's corporate environment. Key takeaways include the importance of minimizing highly privileged permissions and improving visibility around permissions. To defend against similar threats, organizations should use tools that provide insight into identities and resources access, as well as monitor for privilege drift. Veza has developed an Access Control Platform to help businesses manage identity-based risks effectively.
Feb 07, 2024 340 words in the original blog post.