Home / Companies / Veza / Blog / May 2025

May 2025 Summaries

12 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
The 2025 Data Breach Investigations Report (DBIR) highlights the growing threat of credential abuse as the primary battleground in cybersecurity. Infostealer malware is fueling this surge, with 23 million compromised devices and 2.1 billion passwords leaked in 2024 alone. The report shows that infostealers are being used to steal credentials, which are then sold on the black market or used laterally post-intrusion. This has significant implications for security teams, who need to detect compromised credentials in real-time, monitor access across SaaS and cloud services, enforce least privilege, and integrate access insights into incident response and risk scoring. The report emphasizes that identity is now the new perimeter, and attackers are no longer breaking in but logging in. As a result, security teams must take identity seriously and arm themselves with insight, strategy, and execution to protect against this growing threat.
May 30, 2025 884 words in the original blog post.
Saviynt is an identity governance and cloud security platform designed to help enterprises manage and secure identities, applications, and data. The global average cost of a data breach in 2024 reached $4.88 million, a 10% increase over last year, highlighting the need for robust identity security solutions like Saviynt. However, users have reported complex implementation processes, performance issues, poor customer support, and high costs associated with Saviynt. In contrast, Veza offers comprehensive access governance capabilities, real-time monitoring, and Zero Trust security principles, making it a more agile and effective solution for modern organizations in hybrid and multi-cloud environments. Other alternatives like SailPoint and Oracle Identity Governance also have their strengths and weaknesses, but Veza's ability to quickly integrate into existing cloud architectures and its focus on comprehensive access governance capabilities make it an attractive choice for enterprises looking for a robust identity security solution.
May 29, 2025 2,755 words in the original blog post.
Veza's 2025.5 product update introduces a comprehensive set of enhancements focused on strengthening access governance, lifecycle management, and non-human identity (NHI) security to improve organizational security and streamline operations. Key updates include enhanced access review operations with new alerting options and usability improvements for reviewers, an enterprise-grade lifecycle management system with new provisioning targets and flexible automation options, and expanded integration coverage supporting Atlassian provisioning and Zip platform integration. The update also introduces improved administrative controls with full Separation of Duties (SoD) exporting capabilities and enhanced notification management, as well as new features for access reviews, lifecycle management, and access requests to enhance efficiency and security. Additionally, access intelligence is bolstered by the introduction of SOC 1 and SOX model dashboards for compliance monitoring, Veza Actions for Jira and Slack, and improved integration capabilities with platforms like Snowflake, Windows Server, and Google Cloud. The update also emphasizes consumer-grade product design with new design updates and enhanced first-time user onboarding notifications.
May 29, 2025 2,860 words in the original blog post.
Identity and Access Management (IAM) is crucial in today's security landscape, with 80% of organizations experiencing identity-related incidents in the last year. IAM tools can help mitigate risks, but traditional solutions have limitations that create blindspots, such as non-human identities and outdated group names. To address these challenges, organizations need to implement more intelligent solutions that offer better visibility into access management and provide a comprehensive view of permissions across systems. This requires understanding the differences between identity management and access management, how IAM works, cloud vs on-premise deployment models, and the limitations of traditional IAM solutions. Modern solutions like Veza can help simplify IAM, automate provisioning and deprovisioning processes, improve visibility into effective permissions, and provide a unified view of access across systems. By moving beyond traditional IAM tools and adopting more advanced solutions, organizations can address emerging identity security challenges and ensure their organization's future.
May 27, 2025 3,556 words in the original blog post.
Volt Typhoon is a state-sponsored advanced persistent threat (APT) group attributed to China that has been targeting critical infrastructure in the US and globally since at least 2021. Their tactics prioritize stealth over speed, exploiting zero-day vulnerabilities, leveraging valid credentials, and using "living-off-the-land" techniques like PowerShell and WMI to avoid detection. To combat these threats, security teams need deep, continuous visibility into access across human and non-human identities and the ability to act on that insight in real time. An identity threat detection approach built on access intelligence is key to identifying and disrupting campaigns like Volt Typhoon. Platforms like Veza provide this capability by mapping who can do what across fragmented environments, helping CISOs reduce risk without slowing operations. Veza helps defend against Volt Typhoon by detecting abuse of legitimate credentials and living-off-the-land binaries, eliminating overprivileged access to limit lateral movement, continuously monitoring to disrupt long-term persistence, securing non-human identities, and unifying identity governance across fragmented infrastructure. Proactive identity security isn't optional, it's essential in an era defined by identity-centric threats, and Veza helps security teams unify visibility, disrupt persistence, and respond decisively to threats before they become breaches.
May 23, 2025 904 words in the original blog post.
Machine identities are digital credentials that allow non-human entities such as servers, applications, APIs, and IoT devices to authenticate and communicate securely. As the number of machine identities grows, so do the risks associated with mismanaged certificates, weak authentication controls, and unauthorized access. Machine identity security is crucial to prevent unauthorized access, credential theft, supply chain attacks, compliance violations, service disruptions, and financial penalties. Organizations must implement automation tools, identify "rogue" machine identities, protect certificate authorities from being compromised, conduct machine identity audits, and enforce least privilege access to secure their machine identities. The future of managing machine identities requires advanced technology that can analyze permissions and activity for all non-human identities, including machine identities, and provide a unified platform for protection both for human and non-human identities.
May 20, 2025 3,277 words in the original blog post.
The traditional role-based access control (RBAC) model is no longer sufficient to secure modern enterprises, as the way we work has fundamentally changed and many organizations are still trying to apply an outdated approach to security. Roles remain valuable as foundational controls in specific scenarios, but they don't provide enough scaffolding for access in today's dynamic environment. Modern identity security requires understanding the full picture of effective permissions, including what access someone actually has, whether they're using it, and how that access creates risks. Technology has evolved to provide comprehensive visibility and analytics-driven insights, enabling organizations to make data-informed decisions about what access should stay and what shouldn't. Security leaders must challenge status quo thinking about access control and evolve towards a more fluid, analytics-driven approach to identity security.
May 16, 2025 966 words in the original blog post.
Conifer Retail, a mid-sized omni-channel retailer, faced a critical inflection point after failing its PCI DSS 4.0 audit, exposing weaknesses in its identity and access management (IAM) program. The company's security and compliance teams aligned on a north star to modernize their IAM program and adopted Veza's Access platform, which provided unified visibility into identities, automated reviews, entitlement mapping, and audit-ready evidence. By implementing a proactive identity-first governance model, Conifer Retail was able to achieve significant reductions in shared credentials, MFA enforcement, over-privileged accounts, and documentation trail for PCI DSS 4.0 compliance, positioning itself for the evolving landscape of compliance and security.
May 15, 2025 1,154 words in the original blog post.
Role mining is a technique used to analyze how access is used across systems in order to detect patterns, eliminate unnecessary permissions, and enforce the principle of least privilege at scale. It helps security teams regain control, reduce risk, and stay ahead of evolving compliance demands. Role mining can reveal how people use access across systems and define roles that match real-world job functions, enabling organizations to streamline access management, reduce risk, and support the principle of least privilege. The future of role mining is being shaped by the rapid adoption of artificial intelligence (AI) and machine learning (ML), which are helping organizations automate the detection of over-permissioned users and recommend role adjustments based on evolving business needs and real-time data. AI-driven tools can identify redundant permissions, eliminate unnecessary access, and ensure that the principle of least privilege is always maintained. By leveraging real-time data and automation, platforms like Veza ensure that role mining remains dynamic, helping organizations optimize their access governance while maintaining compliance and security. Role mining offers organizations measurable improvements in their identity security posture, including enhanced security, improved efficiency, regulatory compliance, cost savings, and continuous visibility. The future of identity security is moving toward more adaptive and intelligent governance models that evolve in real-time, requiring solutions that go beyond static policy enforcement, incorporating behavioural context, near real-time access verification, and AI-driven insights. Organizations are now looking for identity security frameworks that can respond in real-time to emerging threats and evolving business needs, integrating zero-trust principles and contextual access management to provide more granular control over who can access what, when, and why.
May 14, 2025 1,300 words in the original blog post.
Many non-human identities are present in modern enterprise environments, powering essential digital processes and handling tasks such as automated data transfers and cloud service operations. However, managing these invisible workforces is becoming increasingly necessary for securing modern IT environments, with only 15% of companies feeling highly confident in their ability to prevent NHI attacks. Non-human identities can be categorized into different types, including API Keys, Service Accounts, Service Principals, Tokens, and Certificates, each serving a specific purpose in automated workflows, system processes, or application connections. These identities are created for machines, applications, or devices to facilitate smooth enterprise operations, but they also introduce unique security risks due to their lack of direct oversight, interactive authentication, and static credentials that can be exploited by attackers. As reliance on automation and integration grows, managing non-human identities is becoming a critical aspect of securing modern IT environments, requiring organizations to develop best practices for non-human identity management, including building a complete inventory, assigning ownership, right-sizing access, establishing lifecycles, integrating into identity security frameworks, and strengthening their non-human identity management.
May 13, 2025 3,087 words in the original blog post.
The Cloud Security Alliance's latest State of SaaS Security Report highlights the challenges organizations face in securing their rapidly expanding SaaS environments. Despite increasing investments in SaaS security, significant gaps remain in how organizations approach this challenge, particularly in managing identity and access. The report reveals that traditional approaches to identity and access management are no longer effective in today's complex multi-everything world, where sensitive data is scattered across various platforms, environments, and non-human identities. To address these challenges, a fundamentally different approach to identity security is needed, one that spans all platforms and environments, treats human and non-human identities with equal rigor, provides real-time visibility into access relationships, enables automated enforcement of least privilege, and understands the context of access relationships. The report serves as a wake-up call for organizations to modernize their approach to identity security and adopt more effective solutions to regain control and confidence in their security posture.
May 06, 2025 824 words in the original blog post.
Just-in-time (JIT) access is a powerful concept that grants users access only when needed, reducing standing privilege and its associated costs, security risks, and compliance issues. Traditional access models grant durable permissions to resources, leading to users amassing significant and ever-increasing amounts of standing privilege over time. This can result in users having drastically more privilege than they need to perform their job on a day-to-day basis, increasing the risk of lateral movement in case of a security breach and making it difficult for organizations to maintain large amounts of standing privilege. JIT access mitigates these issues by requiring users to request access to applications, privileged entitlements, or resources when needed, with approval workflows and automation ensuring that access is granted only temporarily. This approach minimizes the attack surface on users, reduces the risk of lateral movement, and provides significant cost savings through optimized software licensing and improved compliance with regulations. The Veza Access Platform facilitates the deployment of JIT access by providing a comprehensive product to manage and orchestrate access requests, with customizable policies, approval workflows, automated provisioning and revocation, and logging capabilities that provide a detailed audit trail.
May 05, 2025 3,441 words in the original blog post.