April 2025 Summaries
14 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
Identity is eating security as digital transformation accelerates, making every identity, human or not, a potential entry point for threat actors. The modern enterprise's reliance on data has shifted the focus from network perimeter security to identity-based protection. However, most organizations struggle to answer basic access questions due to fragmented ownership and accountability across silos. Non-human identities, such as service accounts, bots, APIs, and cloud functions, pose significant risks, while legacy IAM tools are ill-equipped to handle the hybrid, multi-cloud environment. Over-permissioning and tooling that doesn't match today's threat landscape exacerbate the issue, feeding a problem that legacy tools are failing to address. To counter this, organizations must regain control by establishing unified identity governance, gaining real-time visibility into access, automating remediation and access certifications, and applying least privilege and context-based access controls.
Apr 30, 2025
1,024 words in the original blog post.
Veza’s 2025.4 release delivers powerful enhancements across access governance, non-human identity (NHI) security, compliance reporting, and platform extensibility to help organizations reduce risk, improve audit readiness, and simplify identity operations at scale. The update includes features such as faster access decisions, tighter lifecycle policy control, improved audit readiness, NHI risk reduction, stronger access visibility and monitoring, enterprise integration coverage, streamlined user management, and more. Specific capability enhancements include entitlement synchronization, access lifecycle management, access reviews, non-human identity security, separation of duties, access monitoring, and Veza platform updates such as SCIM user provisioning and OpenID Connect. The update also includes new dashboards for key risk indicators, enhanced risks UI, policy draft mode, lookup table export, ASCII transformer for identity attributes, and automatic profile type selection.
Apr 29, 2025
3,044 words in the original blog post.
Veza has raised $108 million in Series D funding led by New Enterprise Associates to accelerate its growth and research and development, focusing on identity security innovation areas such as NHI Security, AI Governance, and Agentic AI Security. The company aims to revolutionize identity security by addressing the growing complexity of cloud infrastructure, SaaS sprawl, and non-human identities through its novel approach known as the Veza Access Graph. With this new funding, Veza plans to expand its products to address emerging initiatives in IGA, PAM, IAM, SaaS Security, NHI Security, AI Governance, Agentic AI Security, and more, while building partnerships to accelerate identity transformation and protect organizations' most valuable assets: their data and identities.
Apr 28, 2025
681 words in the original blog post.
The traditional identity and access management models used by organizations to manage third-party relationships are failing, as they were designed for a more static environment. The modern business landscape is characterized by complex, fast-moving relationships, digital transformation, and data supply chains, which have exponentially increased the number and diversity of third-party touchpoints. As a result, most organizations over-provision access to vendors, contractors, and partners, creating unnecessary risks such as license waste, identity sprawl, security complexity, and integration overhead. To break this cycle, modern third-party identity security requires comprehensive visibility, real-time intelligence, automated governance, least privilege by default, lifecycle management, and smart service integration. Organizations need solutions that unify visibility, context, and automation to protect sensitive data while maintaining compliance and operational efficiency. Ultimately, treating third-party access as a core security imperative is essential to creating a culture of identity-first thinking and ensuring the security perimeter remains strong.
Apr 25, 2025
1,375 words in the original blog post.
Veza's Over Provisioned Access Score (OPAS) is a modern approach to quantify over-provisioned access and help security teams take actionable, data-driven steps to reduce risk. OPAS scores represent the percentage of access granted to an identity that has not been used recently, providing real-time insights into over-provisioning. By combining OPAS with Veza's Activity Monitoring, security teams gain near-real-time visibility into privilege usage, enabling them to identify and remove excessive permissions, streamline compliance efforts, and enforce least privilege with precision. The solution helps organizations eliminate standing privileges for inactive users and service accounts, reduce excessive access across cloud, SaaS, and on-prem platforms, and shrink the attack surface without disrupting legitimate workflows. OPAS also streamlines access reviews by displaying OPAS scores alongside entitlements, ensuring that permissions are revoked based on usage, not assumptions. By quantifying privilege risks and enabling proactive access reductions, organizations can finally take control of their attack surface and implement the principle of least privilege, significantly reducing risk without disrupting business operations.
Apr 23, 2025
1,764 words in the original blog post.
In today's digital landscape, identity has evolved into a critical organization-wide priority for cybersecurity teams, requiring collaboration from multiple teams across the enterprise to solve access challenges and achieve least privilege. The "wild west" of access can only be tamed through a joint effort between Security operations (SecOps), application owners, data owners, cloud engineering teams, governance and audit teams. With 2024 seeing its first billion-dollar breach, organizations need to get a definitive handle on access to reduce risk, improve operational efficiency, and ensure compliance. Identity security encompasses the philosophies for securing all identities, human and non-human alike, during every phase of the access lifecycle, involving multiple departments with distinct but interconnected responsibilities. Security operations teams sit at the frontlines of incidents, charged with protecting sensitive assets and preventing permission sprawl, while app and data owners must continuously review and revoke outdated access rights to maintain least privilege. Governance and audit teams have traditionally applied vast resources to tedious access reviews, leaving them set up for failure without automation. Thriving towards the principle of least privilege is a team sport, and the benefits are felt across teams and the entire enterprise when identity security is placed at the forefront of an organization's key initiatives, including securing non-human identities (NHIs) that now outnumber human identities 17 to 1.
Apr 22, 2025
1,167 words in the original blog post.
The conversation around cybersecurity has shifted from prevention to resilience, as firewalls and antivirus software are no longer enough to protect against zero-day exploits. According to Nicole Perlroth, the focus is now on how to recover when attackers have already breached systems. The world of zero-day vulnerabilities has become increasingly complex, with governments hoarding these flaws for espionage, surveillance, and disruption purposes. China's cyber operations have evolved to be sophisticated, stealthy, and strategic, often using covert infiltration methods to target critical infrastructure. Enterprises are now the frontline of cybersecurity, with organizations expected to defend themselves against nation-state attacks, making identity and access management a mission-critical aspect of their cybersecurity posture.
Apr 21, 2025
496 words in the original blog post.
The text discusses the importance of access control and data security in compliance with the Cybersecurity Maturity Model Certification (CMMC) 2.0 requirements for contractors and subcontractors working with the US Department of Defense (DoD). CMMC 2.0 outlines a framework of cybersecurity maturity levels built on multiple security domains, including Access Control, Audit and Accountability, Configuration Management, and Security Assessment. The text highlights how modern access governance platforms, such as Veza, can support each domain by providing real-time visibility and control, enforcing least privilege and need-to-know principles, and detecting anomalies in access patterns. Veza's platform includes over 500 pre-built queries that detect privileged users, dormant permissions, policy violations, and misconfigurations, enhancing its effectiveness across all domains. The text also provides best practices for implementing CMMC compliance, including conducting a comprehensive discovery of systems containing Controlled Unclassified Information (CUI)/Federal Contract Information (FCI), mapping existing identity providers and access management tools, documenting current access control processes and policies, and establishing baseline security posture measurements.
Apr 18, 2025
1,426 words in the original blog post.
Agentic AI is transforming applications by enabling autonomous reasoning, planning, and action, but its adoption depends on organizational trust. Agentic AI systems consist of three essential layers: the model layer, where core intelligence is developed; the infra layer, which grounds the model's actions in real information; and the application layer, where models are orchestrated into intelligent behaviors. Each layer requires protection to ensure security and trust, particularly during deployment and live usage stages. Veza provides comprehensive protection across all layers and lifecycle stages, including model governance, infra layer governance, and application security, enabling enterprises to move faster and innovate more boldly with confidence.
Apr 14, 2025
842 words in the original blog post.
SOC 1 compliance is crucial for businesses providing outsourced financial services to ensure strong financial controls, trust with clients, and safeguard against reputational damage. SOC 1 reports validate a company's internal control processes, providing reasonable assurance to customers. However, maintaining SOC 1 compliance can be challenging due to increasing complexity in financial operations, global decentralization of business applications, and the need for continuous monitoring of access controls and change management. Common failures include weak logical security controls, lack of incident response plans, and deficient change management controls. Veza helps automate access governance, enforce separation of duties, and strengthen cyber incident response to maintain audit-ready controls, providing a quick start guide on implementing SOC 1 controls and enhancing SOC 1 compliance automation with its Access Graph, Access Governance, and Access Intelligence products. By implementing automated access governance and continuous monitoring, Veza can help organizations significantly reduce the burden of SOC 1 compliance and improve security posture.
Apr 10, 2025
2,160 words in the original blog post.
The rapid advancement of Large Language Models (LLMs) and Generative AI (GenAI) is ushering in a new era of technology, where AI systems are no longer just tools but active participants in enterprise workflows. This shift is driven by Agentic AI—AI systems that can function autonomously, make decisions, retrieve real-time data, and execute complex actions across the enterprise environment. The two primary flavors of AI agents expected to see in enterprises are Enterprise-Managed AI Agents and Employee-Managed AI Agents, each with its benefits and risks. These agents promise tremendous productivity gains but also introduce significant identity security challenges that organizations must address proactively. To manage these risks, a robust identity security framework is critical, and organizations must determine a strategy for the "security" of AI agents quickly, which expands to one about "trust." How much capability and access are provided depends on how much trust is placed in the agent. Ultimately, the future of enterprise AI is both exciting and complex, requiring organizations to acknowledge the tremendous pull to adopt this technology and develop strategies for managing its risks.
Apr 08, 2025
2,296 words in the original blog post.
The recent Treasury Department breach highlights the persistent risks organizations face with identity security and access governance, emphasizing the need for automated, continuous monitoring and granular, permission-level access management to prevent similar breaches. The breach was caused by misconfigurations and gaps in access controls, underscoring the importance of modern identity platforms that provide real-time visibility, automated risk detection, and dynamic governance processes. Organizations must adapt to an increasingly complex digital landscape by closing the gap between role-based access control and granular permission-level understanding, implementing continuous monitoring and automated anomaly detection, and enforcing just-in-time and expiring access policies.
Apr 04, 2025
1,101 words in the original blog post.
Veza's Access Graph provides a deep understanding of permissions and entitlements, enabling the creation of powerful Access Profiles that define collections of permissions and entitlements. These profiles can be tailored to specific needs, such as birthright access or user-requested just-in-time access, and are application-agnostic, mapping disparate entitlements across various systems and platforms. Veza's Access Profiles offer a scalable framework for defining access across applications and systems over the end-to-end user access lifecycle, with features like automation, delegated management, and governance to streamline access provisioning, deprovisioning, and compliance. By leveraging the Access Graph and Access Profiles, organizations can improve their security and compliance posture while gaining efficiencies through more consistent birthright and just-in-time provisioning.
Apr 03, 2025
1,054 words in the original blog post.
Veza has simplified the process of managing access reviews for custom and on-premises applications by providing a seamless integration with its Access Platform. Unlike commercial off-the-shelf (COTS) software, custom applications often lack standardized interfaces and processes for access management, leading to manual reviews that are both time-consuming and prone to errors. Veza's Open Authorization API (OAA) enables the integration of custom applications into the same streamlined review workflows as COTS applications, eliminating the need for complex configurations or expensive training. With OAA, organizations can reuse existing access review setups, reducing costs and accelerating implementation. By automating data ingestion and unifying access reviews across all applications, Veza simplifies compliance, streamlines operations, and reduces manual effort, ultimately saving time and resources across teams.
Apr 01, 2025
982 words in the original blog post.