July 2024 Summaries
11 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
The modern enterprise security landscape necessitates a comprehensive approach to identity security that addresses both human and non-human identities. This shift is driven by the proliferation of applications and other workloads leveraging service accounts, service principles, and the like. There are five key drivers for this need: 1) NHIs often use accounts intended for humans, leading to challenges in understanding your environment or the extent of risk; 2) assigning human owners to NHIs is vital for effective governance and security; 3) humans are often "upstream" of NHIs, making it critical to understand and manage full chains of access from data to human user; 4) similarities in tools and processes for both types of identities can reduce complexity and ensure consistency across operations and security; and 5) streamlining the process of creating and using NHIs for engineers is essential to securing them. Embracing a unified strategy that recognizes the overlap and interdependencies between these types of identities is crucial for ensuring robust protection against evolving threats in an increasingly interconnected digital landscape.
Jul 30, 2024
965 words in the original blog post.
Veza has released new features and enhancements in its June 2024 update, focusing on improving user experience and security around non-human identities. Key updates include expanded support for machine access credentials, enhanced risk management, query builder functionality, and access review usability. New integrations have been added, such as SwiftConnect and Oracle Database on AWS RDS, while existing ones have seen improvements in data collection and attribute extraction. The Access Intelligence landing page has also been updated to provide a better overview of the platform's capabilities.
Jul 24, 2024
1,281 words in the original blog post.
Values play a crucial role in startups like Veza, acting as guiding principles that steer decisions and actions. Founded by Tarun Thakur, Maohua Lu, and Rob Whitcher in 2020, Veza has grown to over 150 employees while maintaining its core values under the acronym "MIGHT": Ownership Mindset, Act with Integrity, Guardians of Our Customers, Opinionated Humility, and Build Trust, Earn Trust. These principles help foster collaboration, innovation, and resilience within the company as it strives to build a generational platform addressing cyber security's biggest challenge – identity-based data protection.
Jul 22, 2024
593 words in the original blog post.
A recent threat intelligence report from Mandiant highlights the growing risk posed by the UNC3944 threat group, which targets SaaS applications to steal sensitive data and extort organizations. As companies increasingly rely on a complex web of SaaS applications and cloud services, managing access sprawl and protecting against identity-related security incidents has become a top priority. Modern identity security platforms, with broad visibility, intelligence, and unified view of entitlements across platforms, are a powerful tool in mitigating these threats and safeguarding enterprises. By providing comprehensive visibility and control over identities and permissions across an enterprise's entire multi-cloud ecosystem, modern identity security platforms empower security teams to discover and map all human and service identities, identify and remediate excessive, unused, and high-risk permissions, continuously monitor for suspicious access activity and permission changes in real-time, bridge the gap between decentralized, line-of-business-owned SaaS platforms and central security governance, and augment and integrate with existing identity and access management tools.
Jul 18, 2024
491 words in the original blog post.
At Black Hat USA 2024, Veza will showcase its modern approach to identity access management, addressing the limitations of traditional tools by revealing all entitlements for both human and non-human identities. The Access Platform reduces security risks and labor associated with access reviews and compliance audits. It covers a wide range of enterprise systems, including data systems like Snowflake and cloud infrastructure platforms such as AWS, GCP, and Azure. Attendees can visit Veza's booth for updates, case studies, demos, and a chance to win YETI coolers. They can also schedule meetings or attend the VIP Experience at the GuidePoint Black Hat Party. An exclusive discount is available using code VEZA on the Black Hat registration site.
Jul 17, 2024
177 words in the original blog post.
The text discusses the creation of the Veza Access Graph, a platform that integrates with all systems within an enterprise to create a rich dataset showing connections between identities, authorization metadata, and resources. It provides a solution for mapping custom applications' authorization models into Veza's Custom Application Template using Python SDK. The tutorial guides developers through the process of building an OAA connector to PagerDuty, emphasizing on defining custom properties, roles, permissions, users, groups, and resources. Finally, it explains how the graph can be used for access search, intelligence, monitoring, workflows, lifecycle management, and access requests.
Jul 11, 2024
2,160 words in the original blog post.
Software as a Service (SaaS) sprawl occurs when organizations uncontrollably adopt and use SaaS applications without proper IT oversight, leading to security and compliance risks. Common causes of SaaS sprawl include lack of centralized management, limited access control, extensive SaaS application options, no employee training, and onerous procurement processes. The impact of SaaS sprawl includes privilege sprawl, a larger attack surface, financial waste, problems with compliance, and operational inefficiencies. To mitigate SaaS sprawl, organizations should conduct regular audits, gain full visibility of permissions and access, centralize their SaaS applications, streamline procurement processes, train employees, understand SaaS features, and improve departmental communication.
Jul 11, 2024
2,189 words in the original blog post.
In the May 2024 Veza Product Update, several enhancements have been made to improve visibility into non-human identities (NHI), customizable dashboards on the home page, and advanced export to Snowflake. The product team has also improved programmatic user management, enabled access reviews from saved queries, and added new integrations for a wider range of SaaS applications. Key updates include built-in dashboards for dormant entities report, identity and privilege access insights, and SaaS security posture management (SSPM) dashboard. Additionally, the platform now supports Google Workspace and AWS Identity Center as provisioning targets.
Jul 08, 2024
1,422 words in the original blog post.
Authentication and authorization are two critical components of access control in modern businesses. Authentication verifies a user's identity before granting access to resources, while authorization determines the actions a verified user can perform within a system. Both processes play essential roles in maintaining security and privacy by ensuring that only authorized users with appropriate permissions can access sensitive information. Despite their similarities, authentication and authorization serve distinct purposes and occur at different stages of the access control process.
Jul 02, 2024
2,088 words in the original blog post.
In recent years, cloud data solutions like Snowflake have seen rapid adoption, but security and governance often lag behind. Many organizations still manage access to complex Snowflake implementations using traditional tools and processes from the on-prem era. This approach has limitations, leading to significant technical debt around identity security and access control in the Data Cloud. Access debt can manifest as high numbers of super-privileged users, bloated RBAC implementation, or deep role hierarchies that impact query performance. To address these issues, organizations should adopt best practices for managing access debt, such as flattening excessive hierarchies, defining and trimming super-roles and super-users, removing dormant users and unused roles, and establishing best practices for access requests. AI-based optimization capabilities can also help improve overall role structure in Snowflake.
Jul 02, 2024
1,706 words in the original blog post.
The Chief Security & Trust Officer at Veza discusses the challenges organizations face when implementing a zero-trust security strategy. These include managing permissions, proliferation of identities, and access across multiple platforms. Key aspects of identity security that need to be addressed for successful zero-trust implementation are real-time monitoring and control of privileged access, enforcing least privilege across various platforms, managing user entitlements in SaaS applications, securing access to data platforms, streamlining identity governance processes, and managing non-human identities. The role of identity security is crucial as it forms the foundation for granular access control and continuous monitoring. To navigate these complexities, organizations need strategic partnerships with providers offering unified views of all identities and permissions, continuous monitoring, intelligent access controls, automated remediation capabilities, support for a wide range of platforms, applications, and data repositories, and scalability to meet the needs of growing organizations.
Jul 01, 2024
559 words in the original blog post.