Home / Companies / Veza / Blog / December 2025

December 2025 Summaries

6 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
Zero Trust is an operating model focused on securing access by continuously verifying identity, device posture, policy, and permissions, emphasizing principles such as verify explicitly, use least privilege, and assume breach. Unlike being a product, Zero Trust is a strategic framework that incorporates various implementation layers like identity controls, Zero Trust Network Access (ZTNA), Security Service Edge (SSE), privileged access management, and governance, all of which are evaluated using standards like NIST SP 800-207 and CISA's Zero Trust Maturity Model. While many providers claim Zero Trust capabilities, they usually specialize in specific layers, and the future success of these providers will depend on their ability to integrate seamlessly and adapt to complex enterprise environments. Effective Zero Trust implementation requires a combination of identity verification, device posture management, application-level access control, and governance, ensuring that policy decisions, enforcement, and evidence remain consistent. The ecosystem includes a variety of tools and providers focusing on different aspects, such as identity-first programs, application access, and privileged access management, with the ultimate goal of reducing standing privileges, minimizing lateral movement, and enhancing audit evidence.
Dec 30, 2025 2,555 words in the original blog post.
Over the past year, cybersecurity has seen a significant shift, with identity now being the primary risk surface rather than just a layer in the defense-in-depth model, as revealed in the 2026 State of Identity & Access (SOIA) Report. The report highlights that today's most disruptive breaches often originate from identity weaknesses such as dormant accounts, orphaned logins, and machine identities without owners, rather than traditional malware or vulnerabilities. Despite investments in identity and access management (IAM) technologies, identity risks are accelerating due to structural issues, as identity creation outpaces governance processes, leading to permission sprawl and identity debt beyond the capacity of traditional IAM programs. A notable trend is the rise of non-human identities, such as service accounts and AI agents, which are becoming the industry's largest attack surface due to their concentrated power and lack of governance. The report also emphasizes the challenge of entitlement sprawl, where organizations struggle to manage complex and abundant permissions, creating opportunities for attackers. Additionally, unresolved risks such as human offboarding, MFA gaps, and orphaned accounts remain significant vulnerabilities. The SOIA Report underscores that identity risk is now a critical business health indicator, affecting regulatory exposure, operational resilience, AI governance, and cyber insurance, marking the transition to an "Authorization Era" where identity security requires continuous visibility into permissions as a business-wide initiative.
Dec 23, 2025 1,011 words in the original blog post.
As identity management becomes more complex with the rise of non-human identities, enterprises are grappling with challenges beyond the traditional frameworks of Identity and Access Management (IAM) and Privileged Access Management (PAM). The proliferation of machine identities across cloud, SaaS, and AI services has led to a need for specialized solutions, prompting analysts like Frost & Sullivan, GigaOm, and Gartner to focus on non-human identity security and identity security posture management (ISPM). Veza has emerged as a leader in these areas by leveraging its access graph architecture, which provides a comprehensive view of who or what can take actions on systems and data. This architecture supports continuous evaluation and governance of identities, ensuring that both human and non-human identity risks are managed effectively. Veza's platform integrates with existing systems to provide enhanced visibility, governance, and actionable insights, helping organizations address identity as a primary attack surface and implement effective security strategies without overhauling their existing infrastructure.
Dec 16, 2025 2,713 words in the original blog post.
The text discusses the challenges and importance of applying Identity Security Posture Management (ISPM) to AI agents as they rapidly evolve from simple tools to complex, interconnected systems. It highlights that while AI agents can enhance business operations, they also introduce identity risks such as overpermissioning and fragmented inventories due to their fast-paced evolution. The Model Context Protocol (MCP) is identified as a solution to integrate AI systems efficiently, though it also amplifies existing identity risks. The text emphasizes that AI agent security should not be treated as a new category but rather as an extension of ISPM principles to manage non-human identities effectively. Veza is mentioned as a tool that provides governance across AI models, infrastructure, and applications, helping ensure that AI systems remain trustworthy. The document further argues that securing AI agents is essential for scaling AI capabilities safely without compromising identity risk, compliance posture, and customer trust. It encourages organizations to extend ISPM-grade identity discipline to AI agents to prevent unmanaged expansion and suggests steps for implementing AI agent security effectively.
Dec 09, 2025 1,192 words in the original blog post.
Veza's latest product update introduces several new features and enhancements aimed at improving identity management and security automation. Key updates include customizable outlier detection for access reviews, expanded enterprise integrations with databases like MySQL, Oracle, PostgreSQL, and AWS RDS, and improved lifecycle management workflows that allow for safer testing and gradual rollouts. The update also enhances non-human identity security through new integrations with Okta and AWS, providing better visibility into authorization servers and IAM role relationships. Additional improvements in access visibility and query building are designed to facilitate faster and more reliable security investigations. These updates are intended to support security teams in automating identity lifecycle operations and reducing compliance burdens while increasing the efficiency and effectiveness of access management.
Dec 09, 2025 2,058 words in the original blog post.
ServiceNow's acquisition of Veza marks a significant development in the identity security sector, aiming to enhance the security of identities—both human and machine—across modern enterprises. Founded on the belief that identity would become a crucial aspect of security, Veza has pioneered an innovative Access Graph, designed to manage permissions across diverse systems, making the concept of "least privilege" an operational reality. This acquisition is timely as identity has emerged as the primary vector for security breaches, driven by the complex landscape of human and non-human identities, including AI agents. By integrating with ServiceNow, Veza's identity security platform will enhance ServiceNow's capabilities, providing comprehensive identity security within its existing architecture, thus positioning ServiceNow as a leader in enterprise trust and productivity. This partnership is rooted in a shared mission and cultural alignment, promising to reshape how enterprises manage identity risks and secure their operations in an AI-driven era.
Dec 02, 2025 1,112 words in the original blog post.