March 2025 Summaries
8 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
The text discusses the evolving landscape of Artificial Intelligence (AI) and its growing autonomy, referred to as "Agentic AI." This shift introduces new challenges in controlling what data an AI agent can access, how it uses that data, and ensuring its identity or credentials are secure. To address these concerns, Model Context Protocol (MCP), an open standard, has emerged as a unifying framework for AI integrations with data sources and tools. MCP standardizes how AI assistants discover resources, read or write data, and call "tools" on remote systems, enabling enterprises to unify data sources under a single interface that is AI-aware. However, this autonomy also raises security risks such as "permissions creep," identity masquerading, invisible overprivileged access, and cross-system entitlements. To mitigate these risks, organizations need to adopt a robust identity governance approach, recognizing every AI agent as its own distinct identity subject to scrutiny, and leveraging platforms like Veza's Access Graph to gain a holistic view of these new identities and their interactions with data. By embracing MCP and Veza's Access Graph, enterprises can harness the productivity of Agentic AI while ensuring data security and control.
Mar 31, 2025
1,690 words in the original blog post.
The latest Veza product update includes significant enhancements across various product areas. NHI Security has improved credential rotation visibility, platform navigation, and NHI detection for security teams managing service accounts, access credentials, and other machine identities. Access Intelligence has received improvements to governance controls, analytical capabilities, and overall usability. The updates also include changes in the Separation of Duties (SoD) feature, such as multiple manager assignment, bulk assignment capability, and terminology update. Additionally, there are enhancements to Lifecycle Management, including a new Dashboard page, granular control for access management, and expanded integration support. Other notable updates include improvements to Access Requests, Veza Access Reviews, Integrations, and the Veza Platform.
Mar 26, 2025
2,235 words in the original blog post.
The rapidly spreading OAuth-based attack on GitHub repositories is a growing threat, where attackers trick users into granting excessive permissions to malicious apps, compromising sensitive information and altering code. This type of attack exploits the trust placed in security notifications, leveraging fake security alerts to hijack user accounts and repositories. OAuth integrations simplify authentication but also come with risks when not properly managed, as most security teams lack visibility into which third-party apps have access to their repositories and what level of control they have. Veza is a solution that offers complete visibility into OAuth permissions, continuous monitoring for unusual behavior, enforcing least privilege, automated auditing and compliance, and protection against supply chain attacks, helping developers and security teams secure their GitHub repositories and prevent malicious OAuth-based attacks.
Mar 25, 2025
979 words in the original blog post.
The Gartner Identity and Access Management (IAM) Summit in London focused on the importance of understanding one's identity graph, a map of human and machine identities across an organization. This includes employees, external partners, service accounts, and sensitive secrets like keys and certificates. The summit highlighted the need for visibility and observability to avoid breakdowns caused by hackers, and outlined three main steps: discovering identities, calculating risk scores, and discovering resources, entitlements, and policies. By achieving this understanding, organizations can reduce attack surfaces, prevent privilege creep, simplify compliance, and create a safer and more secure environment.
Mar 25, 2025
424 words in the original blog post.
The European Union's Digital Operational Resilience Act (DORA) is a significant shift in how financial organizations approach Information and Communication Technology (ICT) security and operational resilience. DORA establishes a comprehensive framework for risk management, incident reporting, resilience testing, and third-party oversight, which applies to EU financial organizations but has similar frameworks emerging worldwide. Modern identity security platforms can provide the capabilities needed to meet DORA's requirements while strengthening overall security posture. The act mandates four key pillars of compliance: ICT risk management and governance, incident reporting and classification, digital operational resilience testing, and third-party risk management and oversight. Identity security is at the core of operational resilience and effective ICT risk management, involving ensuring authorized individuals access sensitive systems and data, preventing unauthorized access that could lead to security breaches. Modern identity platforms like Veza approach DORA compliance through several key capabilities, including Access Intelligence, Risk Management Through Continuous Monitoring, Automated Governance in Practice, and Third-Party Risk Management. Implementing identity security for DORA compliance requires a strategic approach that balances immediate compliance needs with long-term operational resilience goals, involving discovery and assessment, phased implementation, integration and automation, and measuring success and maintaining compliance. The future of DORA compliance lies in selecting the right identity security platform that provides visibility, automated governance, and sophisticated risk management capabilities, while helping organizations manage access risks, improve operational efficiency, and maintain strong security measures beyond compliance.
Mar 24, 2025
1,254 words in the original blog post.
The blog post explores the challenges faced by two security professionals, Alicia and Mark, in managing access controls and audits within SharePoint environments. Both use tools for their respective organizations, with Veza providing real-time insights and automated remediation capabilities, while Legacy IGA focusing on detailed compliance reporting and structured policy enforcement. The authors highlight the benefits of using a tool that offers immediate visibility and rapid response to security breaches, such as Veza, particularly in fast-moving incidents where every minute counts. In contrast, Legacy IGA's strengths lie in its ability to provide comprehensive audit reports and rigorous compliance checks, which may be more suitable for organizations prioritizing these aspects over real-time insights and automation. Ultimately, the choice between Veza and Legacy IGA depends on an organization's specific security needs, risk tolerance, and operational tempo.
Mar 11, 2025
1,177 words in the original blog post.
In today's fast-paced digital world, organizations rely heavily on SharePoint for collaboration and document management. However, with great functionality comes significant security challenges. Two security professionals, Alicia and Mark, confront and resolve SharePoint access control and audit issues using Veza and Legacy IGA, respectively. They face common challenges protecting SharePoint from internal misconfigurations and external threats while ensuring seamless operations. Through real-time, cross-platform views, automated remediation features, and unified interfaces, Veza empowers security teams to counteract potential breaches in real time, ideal for fast-moving incidents where every minute counts. In contrast, Legacy IGA excels in detailed compliance reporting and structured policy enforcement but lacks immediacy and automation. Ultimately, the choice between these tools depends on an organization's specific security needs, risk tolerance, and operational tempo.
Mar 11, 2025
1,177 words in the original blog post.
Veza simplifies SOX compliance by providing automated access controls, real-time Segregation of Duties monitoring, and audit-ready reporting. Despite two decades since the Sarbanes-Oxley Act was enacted, companies continue to struggle with IT-related failures and SoD issues, which account for a significant share of Material Weaknesses. The main culprits behind these challenges are growing scale and complexity in business processes and technology, evolving audit standards, and manual processes that can't keep up. Veza helps organizations manage controls at scale, reduce manual effort and costs with automation, and maintain SOX compliance while cutting down audit preparation time.
Mar 07, 2025
1,366 words in the original blog post.