April 2024 Summaries
10 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
The text discusses the increasing need for advanced Identity Security solutions in today's rapidly evolving digital landscape. It highlights that traditional IAM systems are struggling to keep up with the complexities of modern hybrid, multi-cloud environments and emphasizes the importance of shifting towards a new mindset focused on protecting sensitive data. The article suggests embracing identity security with intelligent access, which is grounded in three key principles: comprehensive visibility, continuous monitoring and adaptation, and scalable and flexible control. It concludes by urging the industry to prioritize identity security and collaborate to develop standards and innovative solutions that enable organizations to secure their identities, permissions, and data effectively.
Apr 24, 2024
1,043 words in the original blog post.
Non-human identities (NHIs) are digital credentials and permissions of automated actors like computers and devices, which help them talk to each other. NHI management is crucial in modern business systems as companies rely more on machines for communication or scenarios where non-human identities outnumber humans. Examples of NHIs include devices, software-defined infrastructure (SDI), DevOps tools, service accounts, system accounts, and application accounts. Managing NHIs ensures that every device or software has its own identity, like a digital fingerprint, which it uses to communicate and interact securely with others. Understanding the differences between human identities and non-human identities is essential for effective management of these digital credentials. Non-human identity management helps businesses meet regulatory compliance standards, maintain efficiency in data and digital projects, and keep their digital operations running properly.
Apr 19, 2024
2,272 words in the original blog post.
In March'24, Veza released a monthly product update with new features, usability enhancements, and integrations across its products. Key updates include Select All Permissions option in Access Intelligence & Visibility, Activity Monitoring for AWS, enhanced Access Reviews, and new integrations such as Delinia Secret Server, Aspera, Anaplan, Oracle EPM, Hashicorp Vault, Dropbox, Databricks (Unity Catalog), and Appian. Additionally, several existing integrations have been improved, including Active Directory, AWS, Box, Concur, Coupa, Egnyte, Jenkins, Microsoft Azure, Salesforce, Snowflake, and Workday. The Veza Platform has also received enhancements such as Single Sign-On Configuration, SSO Event Logs, Team Integration Scope, and Webhook and Email Domain Filtering. Furthermore, Lifecycle Management now supports Microsoft Entra ID, Workday, and Snowflake as provisioning targets.
Apr 19, 2024
903 words in the original blog post.
2024 is being called the "Year of Identity" in cybersecurity, with 80% of breaches being identity-related. Organizations are focusing on improving their identity security efforts and reevaluating legacy tools. Veza is building a modern Identity Security Platform to address multiple business initiatives such as cloud migration, supply chain resilience, and digital transformation. The company also emphasizes non-human identity management, which involves assigning, securing, and overseeing the digital credentials and permissions of automated actors within IT environments. Veza has recently integrated with HashiCorp to provide end-to-end insight on human and machine identities accessing secrets in HashiCorp Vault.
Apr 18, 2024
598 words in the original blog post.
In a recent Identity Security Spotlight, Veza's Chief Security & Trust Officer Mike Towers and Chief Strategist Rich Dandliker discussed the CISA investigation into Microsoft. The key takeaway from their conversation is that many organizations heavily rely on Microsoft for security, with it being considered "the kingdom" in some cases. This highlights the importance of implementing defense-in-depth principles to ensure comprehensive protection against potential threats. To learn more about the investigation and its implications, check out the full discussion.
Apr 16, 2024
87 words in the original blog post.
Veza has released updates to its Access Intelligence, Access Reviews, and Lifecycle Management products. Key improvements include usability enhancements in Access Reviews, faster time-to-value with new dashboards for tailored insights into Snowflake and Salesforce authorization in Access Intelligence, enhanced ability to review past event logs and pending provisioning actions in Lifecycle Management, and added support for creating team-scoped API keys for programmatic access by non-root team members. Additionally, the company has introduced new integrations and hardened existing ones to support a growing range of customer environments and use cases.
Apr 15, 2024
689 words in the original blog post.
HashiCorp Vault is a leading solution for secret and key management in enterprises. Veza has integrated with HashiCorp Vault to enhance Privilege Access Management (PAM) and Non-Human Identity Management (NHI). This integration provides comprehensive visibility into identities accessing secrets, operational insights, non-human identity management, and access reviews. The benefits include effective secrets entitlement management, simplified Vault licensing visibility, improved identity security posture, and streamlined compliance processes. Overall, the integration of Veza with HashiCorp Vault enhances an organization's security framework and operational efficiency.
Apr 12, 2024
386 words in the original blog post.
Veza is a tool that helps organizations manage access control across their applications and databases, both on-premise and in the cloud. It works with CrowdStrike Falcon® Identity Protection to identify high-risk users and assess which apps and objects are impacted by them. Veza also tracks permissions created outside of IGA tools to prevent deactivated users from accessing sensitive data. The platform helps ensure users have the least permissive roles, monitors enterprise systems for privilege elevation, and brings governance to SaaS apps. Additionally, it automates intelligent access review processes, allowing organizations to run user access reviews on demand or triggered by risk classification.
Apr 12, 2024
217 words in the original blog post.
Snowflake is a cloud-based data platform that has revolutionized data storage, management, and analysis. As companies increasingly adopt this technology, managing access control and security becomes paramount. Veza provides a comprehensive guide on navigating Snowflake's roles, security, access control, and privileged access management. Key challenges include understanding access across the entire data estate, managing external data sharing, and ensuring compliance with various regulations. Veza offers solutions to these challenges by providing clear visualization of user permissions, automating access reviews and certifications, and maintaining least privilege access principles.
Apr 12, 2024
1,971 words in the original blog post.
FBI Special Agent Donovan McKendrick discussed the current cyber threat landscape and strategies businesses can use to mitigate risks in a live event. Ransomware has become a major form of cybercrime, with ransomware groups evolving their tactics and operating as sophisticated businesses. Healthcare is particularly susceptible to cyberattacks due to the sensitive nature of patient data. To combat ransomware, organizations should prioritize cybersecurity measures such as regular backups, endpoint security, employee training, and a zero-trust security model. Collaboration between organizations and government authorities is crucial in addressing cyber threats effectively, with reporting incidents to sites like IC3.gov facilitating investigations and threat intelligence aggregation. Top cyber threats for 2024 include ransomware, financial fraud, and supply chain attacks. AI is playing an increasingly prominent role in both offense and defense of cybersecurity. The "Five C's" framework can be used to build a comprehensive security posture: connectivity, collection, configuration, compliance, and culture.
Apr 10, 2024
918 words in the original blog post.