Home / Companies / Veza / Blog / September 2025

September 2025 Summaries

8 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
Veza transforms identity security into an operational system by using its Access Graph to provide a comprehensive view of permissions across an organization's data landscape, enabling Security Operations Centers (SOCs) to effectively manage and secure access. The platform integrates with tools such as ITSM, SOAR, and IdP, allowing teams to quickly interrogate permissions using Access AI and the Veza Query Language (VQL), and to implement least-privilege models in line with Zero Trust principles. Veza addresses both human and non-human identity management, mitigating risks associated with over-privileged accounts through continuous monitoring and automated changes. This approach enhances the ability to contain breaches rapidly, ensuring that organizations can maintain an auditable and secure IT environment. The platform provides measurable metrics like Time to Know, Time to Contain, and Entitlement Reduction, which help track and improve identity security posture over time.
Sep 29, 2025 868 words in the original blog post.
Effectively managing access within Azure environments hinges on minimizing standing privilege, appropriately sizing role scopes, and treating non-human identities with the same rigor as human users. This field guide is tailored for mid-senior IT professionals in IAM, PAM, and IGA, offering actionable steps to mitigate risks without hindering productivity. Key strategies include eliminating standing privileges through time-bound elevations, right-sizing role scopes to prevent unintended power escalation, and managing non-human identities with explicit issuance and regular reviews. The guide emphasizes the importance of using built-in roles over custom ones, maintaining a registry for service principals, and conducting regular access reviews to ensure permissions are up-to-date and necessary. By implementing these practices, organizations can shrink their blast radius, streamline audits, and enhance security posture, ultimately allowing teams to focus more on innovation than incident response.
Sep 25, 2025 2,175 words in the original blog post.
In 2025, data governance tools are critical for managing the vast amounts of data organizations handle, with more than 64% managing at least one petabyte. These tools are essential not just for data storage but for establishing policies, ensuring accuracy, monitoring usage, and protecting sensitive data to mitigate inefficiency, compliance issues, and security risks. Effective data governance involves clear internal policies for data collection, storage, classification, usage, and disposal while ensuring compliance with regulations like GDPR, CCPA, and SOX. Modern governance tools offer features such as automated quality checks, access governance, and integration with identity security frameworks like Gartner's Identity Visibility and Intelligence Platform (IVIP), which emphasize monitoring and controlling entitlements. These tools are designed to support regulatory compliance, improve operational efficiency, mitigate risks, and enhance decision-making. When evaluating data governance tools, it's important to consider their core capabilities, features, usability, and pricing while ensuring they can manage non-human identities and integrate with existing systems. The adoption of these tools helps organizations bridge the gap between policy and real-world entitlements, ensuring sustainable governance programs and compliance with global regulations.
Sep 18, 2025 1,445 words in the original blog post.
Veza's latest product update, 2025.6, introduces a range of features aimed at enhancing identity security governance while reducing risk and operational costs. Key enhancements include automated access remediation validation and dynamic lifecycle controls that standardize secure provisioning, alongside deeper risk intelligence for identifying high-risk identities and resources. The update also expands non-human identity governance and integration support, such as with Snowflake and CrowdStrike, and introduces operational and UX upgrades like dashboard sharing and improved navigation. By automating compliance processes and streamlining identity management, Veza addresses the growing threat of excessive access and machine identities, helping organizations achieve stronger least privilege outcomes with less manual intervention. Additionally, new capabilities like dynamic access profiles, advanced transformer functionalities, and enhanced integration features further improve operational efficiency and compliance readiness.
Sep 18, 2025 3,276 words in the original blog post.
Veza has launched Access AI powered Query Analysis, a new feature in Access Intelligence designed to revolutionize how security teams interpret access risk indicators and findings. This tool uses AI to convert complex access risks, query results, and historical trends into clear, actionable insights, significantly reducing the time and effort required for manual investigations. By providing an immediate, coherent narrative, it allows security teams to quickly understand and act on critical issues, such as dormant admin accounts lacking multi-factor authentication, without extensive manual data correlation. This capability not only accelerates incident response times but also democratizes sophisticated security insights for a wider audience, ensures consistency in assessments, and allows security analysts to engage in more strategic tasks. Access AI thereby enhances the power and actionability of security insights within Veza by automating data interpretation and streamlining the remediation process.
Sep 16, 2025 629 words in the original blog post.
Veza and CrowdStrike have teamed up to address identity-related security risks, which are increasingly recognized as a primary attack vector in cybersecurity. By integrating Veza's capability to map identity access with CrowdStrike's behavioral detection, organizations can gain comprehensive visibility and automation in managing identity risk. This collaboration helps security teams swiftly assess potential threats by identifying what systems and data a compromised identity can access, thus enabling quicker decision-making and targeted action. As identity breaches often begin with misused credentials, the partnership provides a unified intelligence layer that connects identity, entitlements, behavior, and device health, moving response times from days to minutes. This approach not only enhances detection but also operationalizes continuous, context-rich assessment and risk-aware automation, exemplifying the principles of Identity Security Posture Management (ISPM) and Identity Visibility & Intelligence Platform (IVIP).
Sep 16, 2025 635 words in the original blog post.
Ransomware attacks are increasingly exploiting identity infrastructures, with 83% of such attacks involving compromised identities, according to Semperis, and 30% involving identity-based tactics reported by IBM's X-Force. As attackers target unmanaged identities and over-permissioned accounts, traditional endpoint detection tools fail to address these vulnerabilities. Identity Security Posture Management (ISPM) emerges as a crucial solution, offering visibility and control over identities to prevent ransomware by managing entitlements, detecting toxic combinations, and governing non-human identities. Veza exemplifies the practical application of ISPM by providing a comprehensive view of identity risks across SaaS, cloud, and infrastructure, ultimately shifting security teams from reactive to proactive measures. The focus on identity as an attack surface highlights the necessity of ISPM to mitigate ransomware risks and improve organizational security posture.
Sep 11, 2025 857 words in the original blog post.
Generative AI is increasingly integrated into critical enterprise workflows, raising significant governance and security concerns related to non-human identities, such as service accounts and automation bots, which often outnumber human users significantly. These unmanaged identities pose substantial risks, such as data breaches and compliance issues, due to over-permissioned roles and untracked access, which are underscored by warnings from organizations like CrowdStrike and Google Cloud. Enterprises struggle to manage this identity sprawl effectively, with challenges in proving compliance and applying the principle of least privilege (PoLP) to prevent unauthorized access to sensitive data or AI models. Modern identity governance tools, like Veza, aim to address these issues by providing visibility into who can perform specific actions within AI systems, automating access reviews, and ensuring audit-proof governance, thereby helping organizations maintain compliance with frameworks such as SOX, PCI DSS, NIST 800-53, and ISO 27001.
Sep 05, 2025 779 words in the original blog post.