{"id":634139,"date":"2023-04-22T09:56:02","date_gmt":"2023-04-22T14:56:02","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/04\/22\/how-veza-helps-companies-map-data-access-and-stop-insider-threats\/"},"modified":"2023-04-22T09:56:02","modified_gmt":"2023-04-22T14:56:02","slug":"how-veza-helps-companies-map-data-access-and-stop-insider-threats","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/04\/22\/how-veza-helps-companies-map-data-access-and-stop-insider-threats\/","title":{"rendered":"How Veza helps companies map data access and stop insider threats"},"content":{"rendered":"<div>\n<section>\n<p><time title=\"2023-04-21T19:07:00+00:00\" datetime=\"2023-04-21T19:07:00+00:00\">April 21, 2023 12:07 PM<\/time>\n\t\t\t<\/p>\n<\/section>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"500\" src=\"https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/VB_security-breach-padlock_2_1200x800.jpg?fit=750%2C500&#038;strip=all\" alt=\"Red padlock on a background of electronic circuitry, representing security breach\"><\/p>\n<div>\n<p><em>Image Credit: Created using Bing Image Creator with DALL-E.<\/em><\/p>\n<\/div><\/div>\n<\/p><\/div>\n<div id=\"primary\" role=\"main\">\n<article id=\"post-2871249\">\n<div>\n<div id=\"boilerplate_2682874\">\n<p><em>Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success<\/em>. <em><a href=\"https:\/\/avolio.swapcard.com\/Transform2023\/registrations\/Start?utm_source=vb&#038;utm_medium=boiler&#038;utm_content=landingpage&#038;utm_campaign=T23_BoilerPlates\">Learn More<\/a><\/em><\/p>\n<hr>\n<\/div>\n<p>Last week, a U.S. federal government employee and Air National Guardsman named Jack Texeira was alleged to have exploited his Top Secret clearance and <a href=\"https:\/\/www.cbsnews.com\/news\/pentagon-leaked-documents-details-takeaways-jack-teixera\/\" target=\"_blank\" rel=\"noreferrer noopener\">leaked<\/a> dozens of internal Pentagon documents to a Discord server, including sensitive information related to the Russia-Ukraine war.\u00a0<\/p>\n<p>The breach is a classic example of a malicious insider attack, where a privileged user decides to exfiltrate valuable information. It also highlights that organizations need to act under the assumption that any employee or contractor can decide to leak data assets at any time.<\/p>\n<p>In fact, research shows that insider threats are incredibly common. <a href=\"https:\/\/www.cyberhaven.com\/blog\/2022-insider-risk-report\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cyberhaven<\/a> found that nearly one in 10 employees (9.4%) will exfiltrate data over a six-month period, with customer data (44.6% of incidents) and source code (13.8%) being the most common assets leaked.<\/p>\n<p>\u201cPrivileged users often maintain an overabundance of standing access to critical systems and sensitive data, which, if excessive or unnecessary, can expose organizations to data leaks,\u201d said Geoff Cairns, Forrester principal analyst. For this reason, \u201cidentity management is critical to preventing identity sprawl and enforcing the principle of least privilege.\u201d<\/p>\n<p><html><body><\/p>\n<div id=\"boilerplate_2803147\">\n<h3>Event<\/h3>\n<div>\n<p><span>Transform 2023<\/span><\/p>\n<div id=\"gm0a52976\">\n<p>Join us in San Francisco on July 11-12, where top executives will share how they have integrated and optimized AI investments for success and avoided common pitfalls.<\/p>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/avolio.swapcard.com\/Transform2023\/registrations\/Start?utm_source=vb&#038;utm_medium=incontent&#038;utm_content=landingpage&#038;utm_campaign=T23_incontent\"><br \/>\n                Register Now            <\/a>\n                        <\/p>\n<\/div>\n<p><\/body><\/p>\n<p>However, for <a href=\"https:\/\/www.accel.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Accel<\/a>-backed data security startup <a href=\"https:\/\/www.veza.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Veza<\/a>, security teams need to go well beyond identity management to mitigate the risks caused by malicious insiders; they need granular visibility into human and machine identities throughout the enterprise and what data these identities have access to.\u00a0\u00a0<\/p>\n<h2 id=\"h-unveiling-the-identity-to-data-relationship\"><strong>Unveiling the identity-to-data relationship\u00a0<\/strong><\/h2>\n<figure><img loading=\"lazy\" data-lazy-fallback=\"1\" decoding=\"async\" width=\"1782\" height=\"834\" alt   data-recalc-dims=\"1\" srcset=\"https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=1782&#038;strip=all 1782w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=300&#038;strip=all 300w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=768&#038;strip=all 768w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=800&#038;strip=all 800w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=1536&#038;strip=all 1536w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=400&#038;strip=all 400w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=750&#038;strip=all 750w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=578&#038;strip=all 578w, https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?w=930&#038;strip=all 930w\" src=\"https:\/\/venturebeat.com\/wp-content\/uploads\/2023\/04\/Veza-Authorization-Graph.png?resize=1782%2C834&#038;is-pending-load=1#038;strip=all\" data-old-srcset=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\"><figcaption>A screenshot of the Veza identity graph <\/figcaption><\/figure>\n<p>Traditional <a href=\"https:\/\/venturebeat.com\/security\/what-thoma-bravos-latest-acquisition-reveals-about-identity-management\/\">identity management<\/a> is about establishing a process for authenticating users before they can access assets. While this approach is essential to enterprise security, it\u2019s not always clear what data an individual has access to, particularly when the average user has <a href=\"https:\/\/www.cyberark.com\/press\/cyberark-report-massive-growth-of-digital-identities-is-driving-rise-in-cybersecurity-debt\/\" target=\"_blank\" rel=\"noreferrer noopener\">over 30 digital identities<\/a>.\u00a0<\/p>\n<p>\u201cWe call it the identity iceberg,\u201d said Tarun Thakur, CEO of Veza, in an exclusive interview with VentureBeat. \u201cThis observation that we have had since we founded the company is really the problem statement of who has access to what and what can they do? Organizations don\u2019t have an answer to that question.\u201d\u00a0<\/p>\n<p>\u00a0With modern enterprises maintaining an <a href=\"https:\/\/www.businesswire.com\/news\/home\/20210915005244\/en\/Less-than-Half-of-Company-SaaS-Applications-Are-Regularly-Used-by-Employees\" target=\"_blank\" rel=\"noreferrer noopener\">average<\/a> of 254 applications, it\u2019s difficult to achieve granular visibility into the actual data assets a given identity or account can access.\u00a0<\/p>\n<p>\u201cUsing Nike as an example,\u201d Thakur began, \u201cwe can see [for example a user named] Gillian belongs to Nike, and our username Gillian or <span \n                data-original-string='hw8C8KckiwQMc81J2Fdm6g==7f4n5f0U\/aSNTzJoX2P12pM+7fqzxvYq9FndtlYqf77X78='\n                class='apbct-email-encoder'\n                title='This contact has been encoded by Anti-Spam by CleanTalk. Click to decode. To finish the decoding make sure that JavaScript is enabled in your browser.'>Gi<span class=\"apbct-blur\">*****<\/span>@<span class=\"apbct-blur\">**<\/span>ke.com<\/span>. But what can Gillian do? What can she read? What can she delete? What can she update?\u201d<\/p>\n<p>Veza\u2019s answer to the challenge of data visibility was to create an <a href=\"https:\/\/venturebeat.com\/ai\/artificial-intelligence-ai-vs-machine-learning-ml-key-comparisons\/\">AI\/ML<\/a> model engine to ingest role-based access control (RBAC) metadata from hundreds of apps to build an identity threat graph.\u00a0<\/p>\n<p>The graph highlights the identity-to-data relationship, showing human users each identity, what assets they can access and what actions they can perform (e.g. whether they have read or write permissions). Once this information is discovered, security teams can control authorization and app permissions from a single location and reduce their organizations\u2019 exposure to malicious insiders. \u00a0<\/p>\n<p>This approach is different from traditional identity management tools like <a href=\"https:\/\/www.sailpoint.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Sailpoint<\/a> and <a href=\"https:\/\/www.okta.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Okta<\/a> because it\u2019s based on highlighting the relationship between identities and data access and defining controls, rather than hardening the identity perimeter against threat actors with single sign-on (SSO) or adaptive, risk-based authentication.<\/p>\n<h2 id=\"h-the-role-of-privileged-access-management\"><strong>The role of privileged access management\u00a0<\/strong><\/h2>\n<p>Mapping human and machine identities is just one step on the road toward enforcing <a href=\"https:\/\/venturebeat.com\/zero-trust-the-new-security-paradigm\/\">zero-trust<\/a> access at the data level, as organizations also need to implement access controls to minimize the risk of data leakage. This starts by implementing what Michael Kelley, senior director analyst at Gartner, calls \u201cthe principle of least privilege.\u201d<\/p>\n<p>The principle of least privilege means that \u201conly the right person has the right level of access, for the right reason, to the right resource, at the right time,\u201d Kelley said. Each employee only has access to the files and resources necessary to perform their function, nothing more.\u00a0<\/p>\n<p>Both Veza and identity-data mapping provide organizations with the ability to highlight privileges at the data level so there\u2019s no ambiguity or risk of granting users over-privileged access.\u00a0<\/p>\n<p>That being said, Kelley argues that organizations who want to mitigate account takeover need to go beyond implementing the principle of least privilege, arguing that \u201ccompanies must then mitigate the risk of privileged accounts through <a href=\"https:\/\/venturebeat.com\/security\/pam-sphere-funding\/\">PAM<\/a> [privileged access management] practices,\u201d Kelley said.\u00a0\u00a0<\/p>\n<p>In practice, that means discovering accounts with privilege, identifying persons or machines with access to the accounts, and then discovering the extent of access held by that account.\u00a0<\/p>\n<p>Once these high-value privileged accounts are identified, they can be locked inside a single vault with a PAM solution. This enables authorized users to log in to the account to access data assets, while the security team audits and monitors their activity to make sure no harmful activity, such as data exfiltration, takes place.\u00a0<\/p>\n<p>The decision whether to incorporate identity management, PAM, or identity-data mapping should be based on an organization\u2019s specific needs.<\/p>\n<p>For cloud-native organizations or those operating in a hybrid cloud environment, automated mapping is critical for getting visibility over human and machine identities that exist in a decentralized environment, as is implementing authorization controls at the data level.\u00a0<\/p>\n<p><strong>VentureBeat&#8217;s mission<\/strong> is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. <a href=\"https:\/\/info.venturebeat.com\/website-preference-center.html?utm_source=VBsite&#038;utm_medium=bottomBoilerplate\" data-type=\"URL\" data-id=\"https:\/\/info.venturebeat.com\/website-preference-center.html\">Discover our Briefings.<\/a><\/p>\n<p>\t\t\t\t<\/html><\/div>\n<\/p><\/div>\n<p><a href=\"https:\/\/venturebeat.com\/security\/how-veza-helps-companies-map-data-access-and-stop-insider-threats\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Tim Keary<\/p>\n","protected":false},"excerpt":{"rendered":"<p>April 21, 2023 12:07 PM Image Credit: Created using Bing Image Creator with DALL-E. Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More Last week, a U.S. federal government employee and Air National Guardsman named Jack Texeira was alleged to have<\/p>\n","protected":false},"author":1,"featured_media":634140,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[106,4043,46],"tags":[],"class_list":["post-634139","post","type-post","status-publish","format-standard","has-post-thumbnail","category-companies","category-helps","category-technology"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/634139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=634139"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/634139\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/634140"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=634139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=634139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=634139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}