July 2025 Summaries
15 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
Identity security has evolved beyond simple user provisioning and deprovisioning to encompass governance at scale, access enforcement across diverse systems, and comprehensive identity visibility. Veza addresses these challenges with over 300 permission-aware integrations and tools for custom integration development, promoting least privilege enforcement through detailed privilege models. Key to this approach is the Open Authorization API (OAA), which enables organizations to integrate any system into Veza’s access graph, facilitating real-time identity security posture management (ISPM) and supporting Gartner's Identity Visibility and Intelligence Platform (IVIP) model. Veza's flexible, extensive integrations empower IT and security teams to manage complex identity environments effectively, offering solutions for rapid app onboarding and detailed access intelligence without vendor dependency. This extensibility ensures that legacy and bespoke systems can be integrated smoothly, thereby enhancing operational compliance and security posture across various industries.
Jul 31, 2025
1,096 words in the original blog post.
In July 2025, Mandiant's threat intelligence team detailed how the cyber group UNC3944, also known as Scattered Spider, executed a sophisticated breach of VMware vSphere environments by exploiting identity processes rather than software vulnerabilities. The attackers used social engineering techniques, such as vishing, to gain initial access to Active Directory (AD), escalating privileges rapidly by leveraging internal knowledge systems and AI tools. They then moved laterally within the virtual infrastructure, tampering with virtual machines and enabling remote access while maintaining a low profile to evade detection. The breach strategy emphasized identity as the primary target, highlighting the critical need for organizations to strengthen their identity security controls. This includes implementing stringent verification processes, enforcing multi-factor authentication, and maintaining robust monitoring and visibility to protect against identity-based attacks. The report underscores the importance of treating identity management as a fundamental component of security strategy, as traditional defenses focused solely on malware are insufficient to counter such sophisticated threats.
Jul 30, 2025
1,921 words in the original blog post.
The 2025 Gartner Hype Cycle for Digital Identity highlights emerging categories like Identity Visibility and Intelligence Platforms (IVIP) and AI for Access Administration, which address the persistent challenges in identity governance by offering enhanced visibility and intelligence for managing access across various systems. Veza, recognized as a Sample Vendor in these categories, has been pioneering solutions for these issues long before their formal recognition by leveraging a patented architecture to provide a cohesive view of access permissions and risks. Traditional identity tools like IGA, PAM, and IDPs are deemed insufficient for answering modern security questions such as "Who has access to what?" and "Why is it granted?" The introduction of IVIP and AI for Access Administration aims to fill this gap by correlating access data and automating governance processes, thus enabling organizations to visualize, understand, and confidently manage access controls across their technology stack without overhauling existing systems.
Jul 29, 2025
1,066 words in the original blog post.
Sam’s post highlights the promise and potential risks associated with the “ChatGPT Agent” in the new agentic era, emphasizing challenges such as unpredictable actions and data leakage. Veza addresses these concerns by providing a platform that ensures deep visibility and control over AI agents' permissions, applying the principle of least privilege to mitigate risks. It maps all identities and permissions, offering precise answers to security teams and transforming permissions into simple terms to preemptively manage access. Veza also enhances incident response by instantly revealing an agent's access in case of a compromise, thus containing potential damage swiftly. Additionally, Veza's platform adapts to the evolving landscape of AI technology through intelligent access analysis and natural language queries, serving as a proactive security co-pilot. This solution effectively bridges the gap between AI innovation and secure governance, enabling organizations to confidently integrate advanced AI agents like “ChatGPT Agent” by replacing uncertainty with robust visibility and control mechanisms.
Jul 29, 2025
788 words in the original blog post.
In a recent episode of the Identity Radicals podcast, Matt Hart, Chief Security Officer at PTC, discusses the evolving cybersecurity landscape, emphasizing the shift from network-centric defenses to identity-focused security strategies. Hart, with extensive IT leadership experience, highlights how traditional security measures like firewalls and VPNs have become obsolete, replaced by identity as the new control plane in a cloud and AI-driven world. He explains the importance of a zero-trust model, where access is constantly validated and not based on proximity, likening it to hotel access governed by keycards. The transition to an identity-first model presents challenges, including managing third-party and non-human identities, which can lead to security risks if not properly governed. Hart also notes the complexity added by AI, which requires robust observability and auditability to ensure accountability in systems that may operate autonomously. He acknowledges the difficulties posed by legacy systems, where outdated permissions complicate identity management, urging a strategic approach to identity hygiene. While Hart admits there are no easy solutions to the identity risks posed by AI, he underscores the importance of centering identity in security strategies to build a more resilient digital future.
Jul 28, 2025
629 words in the original blog post.
The text explores the evolution of digital trust, illustrating how advancements in technology have transformed societal norms and behaviors, such as how people now comfortably ride in vehicles with strangers through apps like Uber and share personal health data via devices like Fitbit. It emphasizes the role of robust trust architectures, which use identity verification, encryption, and transparent data policies to build confidence that overcomes traditional safety and privacy concerns. This shift from traditional security to trust architecture requires a focus on transparency, accountability, and empowering users, enabling digital transformations across industries. The text argues that successful organizations must prioritize trust as a business imperative, enabling innovation, resilience, and value creation through what is termed the "Trust Dividend." As technology continues to advance, especially with emerging fields like AI and IoT, the importance of trust architecture in overcoming behavioral resistance and enabling new possibilities becomes even more critical.
Jul 25, 2025
1,853 words in the original blog post.
User access reviews (UARs) are increasingly vital in identity security as threats become more sophisticated, necessitating better verification of access for both human and non-human identities. As organizations face growing regulatory pressures from frameworks like GDPR, SOX, and HIPAA, UARs help protect critical systems and reduce lateral movement risks. Managing these reviews is complex due to cloud sprawl and non-human identities, but selecting the right UAR software can automate oversight, reduce manual tasks, and bolster security. Modern UAR tools minimize unauthorized access, enhance compliance, and mitigate risks by automating processes and providing comprehensive visibility across identities. The guide discusses essential features of UAR tools, such as automation balance, separation of duties enforcement, and robust audit trails. It evaluates several top platforms, including Veza, SailPoint, SecurEnds, ConductorOne, Zilla Security, Zluri, and Lumos, highlighting their capabilities in managing access governance and compliance across diverse environments. The piece emphasizes the need for intelligent, risk-aware governance tools that offer centralized visibility and real-time insights, with Veza exemplifying this approach through its Access Graph technology.
Jul 24, 2025
2,494 words in the original blog post.
Access control compliance is a critical challenge for organizations, as increasing cyberattacks and stringent regulations like GDPR, HIPAA, and PCI-DSS demand robust identity management systems to secure sensitive data. Traditional identity management tools often fall short in managing granular permissions, tracking user role changes, and identifying non-human identities such as service accounts or APIs. Effective access control involves a combination of authentication, authorization, and identity governance practices like role-based access control (RBAC), user provisioning, and periodic access reviews, which are essential for information security, data integrity, and regulatory compliance. Modern solutions like Veza provide real-time visibility into permissions across various systems, automating access reviews, monitoring user activities, and ensuring compliance with frameworks such as SOX, PCI-DSS, SOC 2, ISO 27001, HIPAA, and GDPR. By employing a Zero Trust policy, maintaining the principle of least privilege, and ensuring consistent provisioning and deprovisioning, organizations can mitigate risks, reduce the likelihood of data breaches, and maintain trust with customers and partners.
Jul 22, 2025
4,734 words in the original blog post.
The concept of an Identity Visibility and Intelligence Platform (IVIP) is gaining traction as a crucial framework for modern identity and access management, addressing the limitations of traditional IAM tools. Unlike conventional IAM systems that operate in silos, IVIPs provide a unified, real-time view of identity access data across diverse environments including SaaS, cloud, and on-premises systems. This platform translates disparate permission models into a common language, maps identities to their system roles, and surfaces access anomalies, thereby enhancing security governance and zero trust initiatives. As machine identities now vastly outnumber human identities, IVIPs help manage permissions intelligently, reducing attack surfaces and providing actionable insights needed for compliance and audit readiness. While traditional IAM tools remain essential for provisioning and authentication, IVIPs augment them by offering context and clarity, ensuring organizations understand and govern access effectively and prevent security breaches.
Jul 17, 2025
1,667 words in the original blog post.
Identity Security Posture Management (ISPM) is an emerging approach that addresses the expanding identity attack surface due to the proliferation of cloud services, remote workforces, and machine identities, which traditional identity management systems struggle to secure. ISPM provides continuous oversight, risk scoring, and automated enforcement across both human and non-human identities, offering organizations a proactive framework to manage identity risks effectively. Unlike legacy tools, ISPM ensures real-time visibility and control, which is crucial in preventing breaches caused by over-permissioned users and compromised credentials. Veza, a leader in the ISPM space, enhances this approach by offering comprehensive identity visibility, continuous risk assessment, and policy-based remediation, helping organizations streamline compliance, reduce risk, and improve operational efficiency. The GigaOm ISPM Radar report recognizes ISPM as a distinct category and highlights Veza's leadership in providing solutions that align with the demands of modern security environments.
Jul 16, 2025
1,937 words in the original blog post.
Managing access to Oracle environments, such as Oracle E-Business Suite, JD Edwards EnterpriseOne, Oracle Fusion Cloud ERP, and Oracle Databases, involves navigating both technical and organizational challenges due to complex access control models, fragmented systems, and cloud transformations. Organizations face difficulties maintaining visibility, enforcing consistent access control, and mitigating operational risks, particularly under compliance mandates like SOX, PCI-DSS, and GDPR. Modern access management solutions aim to address these challenges by offering centralized visibility into roles and permissions, enforcing least privilege, automating compliance workflows, and providing real-time monitoring and alerts. By integrating directly with Oracle applications, these solutions help organizations detect privilege escalation, orphaned accounts, and inappropriate access, enabling proactive risk mitigation. The integration of automated access reviews and compliance reporting further aids in maintaining audit readiness and reducing administrative burdens. Overall, these modern solutions strive to ensure that the right individuals have the appropriate access to resources, thereby enhancing security, compliance, and operational efficiency across diverse Oracle environments.
Jul 15, 2025
1,368 words in the original blog post.
In today's cloud-centric environment, the traditional network perimeter has dissolved, making identity the new frontline of cybersecurity. As cyber threats evolve, compromised identities, often through phishing, present significant risks by allowing attackers to infiltrate systems using legitimate credentials. Organizations, on average, use 1.75 identity platforms with a significant portion of identities unmanaged, increasing vulnerability. Conducting identity perimeter analysis is crucial to identifying exposure and strengthening security by mapping access paths, identifying privileged accounts, and implementing protections like multi-factor authentication (MFA). Visibility into identity access is essential, as it forms the new control plane for enforcing least privilege and responding to threats. Gartner's Identity-First Visibility and Intelligence Platforms (IVIPs) offer a framework to unify access visibility across fragmented systems. The analysis involves inventorying identities, understanding their access, analyzing privileged account exposure, and simulating lateral movement scenarios to mitigate risks. Real-world examples highlight how identity visibility and access intelligence can prevent breaches. The continuous cycle of visibility, validation, and enforcement is vital to staying ahead of attackers targeting identity as the main attack vector, emphasizing the need for robust identity security frameworks and practices.
Jul 10, 2025
2,308 words in the original blog post.
Organizations have been struggling with fragmented identity management due to the proliferation of various Identity and Access Management (IAM) tools, each handling different aspects of identity data without providing comprehensive visibility. Gartner has introduced the concept of Identity Visibility and Intelligence Platforms (IVIP) to address this gap by offering a centralized intelligence layer that gathers, categorizes, and visualizes identity data across multiple domains, thereby overcoming the limitations of traditional IAM systems. These platforms are crucial in the modern landscape where non-human identities are rapidly increasing, and AI initiatives create new identity webs, requiring real-time visibility to support Zero Trust frameworks and ensure security compliance. Veza exemplifies the IVIP model by unifying identity data, providing actionable insights into permissions and access risks, and enhancing existing IAM tools without replacing them, thereby transforming identity data from a compliance burden into a strategic asset.
Jul 08, 2025
1,244 words in the original blog post.
Accenture's State of Cybersecurity Resilience 2025 report reveals that only 10% of organizations are "Reinvention-Ready," possessing the strategy and capabilities to defend against AI-driven threats, while the majority still treat identity as a compliance issue rather than a cornerstone of security. Traditional Identity and Access Management (IAM) systems are inadequate for the AI era, as AI agents can access vast amounts of data rapidly and operate with composite identities, posing significant security risks. The report emphasizes the need for modern identity security, which includes real-time access intelligence, unified visibility across human and non-human identities, Zero Trust principles at AI's pace, and granular access controls throughout the AI data lifecycle. Organizations that succeed in AI adoption are those that view identity security not as a barrier but as an enabler, allowing for faster business operations and innovation while maintaining control. The gap between AI adoption and security presents an opportunity for organizations willing to modernize their identity security approach, as it can serve as both a defense mechanism and an accelerator for AI-powered innovation and business value.
Jul 03, 2025
1,202 words in the original blog post.
Third-party risk management (TPRM) is an essential practice for organizations to mitigate the risks posed by external vendors, contractors, and service providers who often require access to sensitive data and systems. As businesses increasingly rely on third-party services, these relationships can expand the organization's attack surface and introduce various risks, including cybersecurity threats, compliance issues, and reputational damage. Effective TPRM involves a structured approach to vendor selection, onboarding, continuous risk monitoring, and offboarding, ensuring that third-party access is securely managed and aligned with regulatory standards. It requires collaboration across various teams, such as IT, security, procurement, legal, and compliance, with a designated point of accountability to oversee the third-party risk strategy. Trends such as the use of AI and machine learning for risk assessment, continuous monitoring, and the integration of zero trust principles are shaping the future of TPRM. Tools like Veza provide access intelligence by visualizing permissions and enhancing secure access governance, helping organizations maintain a robust identity security posture.
Jul 01, 2025
3,219 words in the original blog post.