Data Security, Software Security, Web Security Tools

Imperva® and Fortanix Partner to Protect Confidential Customer Data

Businesswire | April 18, 2023 | Read time : 05:00 min

Imperva® and Fortanix Partner to Protect Confidential Customer Data

Imperva, Inc., (@Imperva) the cybersecurity leader that protects critical applications, APIs, and data, anywhere at scale, and Fortanix, Inc. (@Fortanix), the Data Security company powered by Confidential Computing, announce that they have signed a partnership agreement, and have each joined the other’s strategic partner program.

This partnership brings together two of the most innovative and trusted cybersecurity companies focused on multicloud data protection. The joint offerings from Imperva and Fortanix will provide the ability to manage the entire data security workflow for customers ensuring data privacy and compliance.

Imperva now offers Fortanix Data Security Manager (DSM), a highly scalable data security platform that delivers unified cryptographic and privacy services such as encryption, tokenization, dynamic data masking (DDM), secrets management, and enterprise key management. The solution works across multiple cloud service providers (CSPs) and provides an “easy button” to secure over 100 services. Fortanix DSM is simple to deploy and is offered in two editions — on-premises and a cloud-based SaaS solution — providing data security controls with both backed by FIPS 140-2 Level 3 certification.

"We’re thrilled to partner with Imperva and take a best-in-class solution to the market together,” says Anand Kashyap, CEO of Fortanix. “With Imperva’s data discovery and classification capabilities and the Fortanix Data Security Manager SaaS and multicloud offering, customers have an end-to-end solution for securing workloads across the entire Data Lifecycle. This solution will help customers accelerate their data journey to the cloud while meeting the highest level of compliance.”

Imperva Data Security Fabric (DSF) is a robust and scalable hybrid, multicloud platform for data discovery and classification, activity monitoring, access controls, security analytics, threat detection, and compliance reporting. Imperva DSF provides protection for unstructured, semi-, and structured data — both on-premises and in the cloud.

Organizations continue to seek the most efficient and effective data security solutions to address multiple use cases such as sensitive data protection, insider threat detection, and data risk management. They must also meet compliance and privacy requirements while operating diverse ecosystems at scale and consolidating legacy tools, all without impacting the speed and agility of the application development team to achieve the highest level of ROI.

With the combined strength of Imperva DSF and Fortanix DSM, this data security partnership will benefit organizations that find their traditional controls are no longer sufficient as they move data workloads and applications to the cloud. These data security solutions address data security and privacy regulations such as GDPR, CCPA, PCI DSS, and HIPAA by employing methods to help protect and control data confidentiality, data integrity, and data access across the hybrid multicloud environment.

“With the unprecedented explosion of data over recent decades and every day, unknown sensitive data might be anywhere — potentially exposed, and unsecured. But with this new partnership between Imperva and Fortanix, companies can now discover, classify, and secure their data using encryption and tokenization wherever it resides,” says Dan Neault, SVP and GM of Data Security at Imperva. “Using the intelligence and flexibility of Imperva DSF combined with the power of the Fortanix DSM, finding sensitive data and taking the right steps to secure it is now easier than ever.”

Additionally, Imperva is now able to provide customers with Fortanix DSM via the Imperva End-User License Agreement (EULA) providing streamlined procurement via a single vendor for sales, implementation, training, support, and services.

Building a complete cybersecurity technology ecosystem dedicated to data security and compliance

The Imperva Technology Alliance Program (TAP) enables technology companies, security vendors, and cloud service providers to co-market, sell, and integrate their products and platforms with the award-winning Imperva cybersecurity portfolio to create solutions that deliver added value for customers and generate revenue growth for TAP partners.

Imperva DSF continues to deliver more value to customers through these alliances. Additionally, Fortanix also supports the Imperva Web Application Firewall (WAF) by being able to store WAF encryption keys.

Meet with us at RSA Conference

Join Imperva and Fortanix at RSA Conference 2023 on April 24-27 in San Francisco, CA. Imperva will be exhibiting at booth #5180, North Hall, and Fortanix will be exhibiting at booth #449, South Hall. There will be representatives from both companies at both booths throughout the conference including;

  • Terry Ray, SVP, Data Security GTM and Field CTO at Imperva, will be speaking at the Fortanix booth at 3:00 pm on Tuesday, April 25: “Why organizations need monitoring AND encryption for data security, not monitoring OR encryption​.”
  • Sumanth Kakaraparthi, VP of Data Security Product Management at Imperva, will be speaking at the Fortanix booth at 3:00 pm on Wednesday, April 26: “You can’t protect your sensitive data unless you know where it is and what it is.”

Additional Information

  • Learn more about the Imperva Data Security Fabric (DSF)
  • Learn more about the Fortanix Data Security Manager (DSM)
  • Learn about Imperva joining the Fortanix Partner program here
  • Learn about Fortanix joining the Imperva Technology Alliance Partner program here
  • Check out the Imperva Blog for the latest products and solutions news and threat intelligence from Imperva Research Labs

About Imperva

Imperva is the cybersecurity leader that helps organizations protect critical applications, APIs, and data, anywhere, at scale, and with the highest ROI. With an integrated approach combining edge, application security, and data security, Imperva protects companies through all stages of their digital journey. Imperva Research Labs and our global intelligence community enable Imperva to stay ahead of the threat landscape and seamlessly integrate the latest security, privacy, and compliance expertise into our solutions.

About Fortanix

Fortanix secures data, wherever it is. The company’s data-first approach to security powered by Confidential Computing complements traditional infrastructure-centric solutions and allows businesses of all sizes to modernize their data security posture on-premises, in the cloud, or everywhere in between. Rated highly by customers, and with 100-plus tech integrations, the company’s award-winning flagship Data Security Manager (DSM) platform delivers a unified approach to the data security and privacy lifecycle while reducing risk and increasing compliance. Fortanix customers include global banks and financial services institutions, technology companies, retailers, government agencies, healthcare institutions as well as cloud service providers.

Spotlight

How prepared was your organization for the pandemic of 2020? If your answer is “not very,” you are not alone. Few could have predicted the circumstances that sped up the work from home (WFH) movement and catapulted remote access to the forefront for many organizations. Prior, there was a steady trend by some to support geographi

Spotlight

How prepared was your organization for the pandemic of 2020? If your answer is “not very,” you are not alone. Few could have predicted the circumstances that sped up the work from home (WFH) movement and catapulted remote access to the forefront for many organizations. Prior, there was a steady trend by some to support geographi

Related News

Platform Security, Software Security, API Security

Cequence Strengthens API Protection Platform with Game-Changing Generative AI and No-Code Security Automation

Businesswire | June 28, 2023

Cequence Security, the leader in API Protection, today announced new updates to the Unified API Protection (UAP) platform that strengthen customers’ ability to discover, manage risk and protect APIs. With the latest capabilities, organizations can rapidly deploy API Security Testing with built-in generative AI automation, protect users from online fraud and operationalize security findings with low-code/no-code workflows. “We are always exploring ways to further automate and improve our UAP solution and help our customers consolidate the tools required to stay ahead of the threat actors,” said Ameya Talwalkar, founder and CEO. “The updates to our platform continue to set us apart from other point solution vendors in the API security space as we are providing our customers with the only integrated best-of-suite approach to discover, comply, test and protect their APIs.” “Today, we are also excited to share we are the first API security vendor to take advantage of the game-changing Generative AI and no-code security automation within our UAP solution to better protect users from online fraud and simplify security findings,” continued Talwalkar. Enhance API Security Testing with Generative AI With the enormous potential of generative AI tools like ChatGPT and Google Bard, Cequence is one of the first cybersecurity companies and the first API Protection company to leverage its power to protect data and users from bad actors. Cequence has added several new capabilities to API Security Testing, including Test Plan generation using a new feature called Intelligent Mode that helps automate the generation of API Security Test Plans using plain English, extending the low-code/no-code approach to test case generation. Cequence UAP's Intelligent Mode automatically associates the appropriate APIs with the right test cases, given the functionality of that API. This not only drastically reduces the time needed to create a test plan to minutes, as compared to months with other solutions, it also ensures consistent experience across a customer's entire applications and environments. Several other enhancements include detailed insights and remediation workflows into test failures. The test catalog now has test cases for the latest OWASP API Top 10 2023. Cequence also empowers InfoSec teams to run API tests outside of CI/CD pipelines, and instead, point attack test suites directly against staging or even production servers. New Fraud Prevention Capabilities To enable organizations to protect their APIs from online fraud, Cequence has introduced the Fraud Prevention module in API Spartan. The new module enables organizations to protect their end-customers from online fraud and instantly take action, including blocking transactions and generating enterprise-grade notifications to relevant teams. Protecting applications and users against online fraud complements the existing capabilities of Cequence to detect and block business logic abuse, account takeover (ATO) attempts, common OWASP API Top 10 security risks and automated malicious traffic. Operationalize API Protection with Low-Code/No-Code Security Automation Cequence has introduced out-of-the-box integrations with over 300 third-party apps, including ServiceNow, PagerDuty, JIRA and Slack. Using off-the-shelf connections to these apps, security analysts can ensure security risks or threats are routed promptly to their business teams for remediation. Security analysts can use a low-code/no-code approach within Cequence to implement the equivalent of an API Security Orchestration and Response (SOAR) workflow, wiring together multiple third-party connections to achieve their desired outcomes. Using this approach, analysts can operationalize workflows that promptly remediate critical API security risks, such as the discovery of shadow APIs that have access to sensitive data and new security risks of weak authentication or non-conformance to OpenAPI specifications in newly built pre-production CI/CD pipelines. Enhanced Visibility of External Facing APIs with API Spyder New enhancements to API Spyder enable customers to easily identify APIs that are externally accessible, but not entirely protected by Cloud Security Posture Management (CSPM) infrastructure. Additionally, this approach offers a seamless complement to API Sentinel's deep insights into runtime API inventory and compliance checking using the OWASP API Security Top 10 and other custom risk categories. With the latest Unified API Protection platform updates, organizations can now protect their users from online fraud, operationalize security findings with low-code/no-code API SOAR-like workflows and rapidly deploy API Security Testing with built-in Generative AI automation. These capabilities continue to set Cequence apart from other point API security, bot management, anti-fraud and WAF vendors by having the industry’s first and only Unified API Protection platform that covers the entire API lifecycle. With UAP, customers can discover with API Spyder, comply with API Sentinel and protect with API Spartan. About Cequence Security Cequence Security, the pioneer of Unified API Protection, is the only solution that unifies API discovery, inventory, compliance, dynamic testing with real-time detection and native mitigation to defend against fraud, business logic attacks, exploits and unintended data leakage. Cequence Security secures more than 6 billion API transactions a day and protects more than 2 billion user accounts across our Fortune 500 customers. Learn more at www.cequence.ai.

Read More

Platform Security

Conceal Announces Strategic Partnership with Kompingo: Revolutionizing Web Security with the Next Generation of Protection

Business Wire | August 23, 2023

Conceal, renowned for its pioneering stance against web-based threats, today heralded its significant partnership with Kompingo, the UK's distinguished value-added distributor and managed security service provider. This collaboration signifies a major enhancement for Kompingo’s Managed Detection and Response (MDR) services, as it integrates Conceal’s patented zero-trust browser security into its offerings. "As the digital threat landscape rapidly evolves, strengthening our MDR and managed services capabilities remains paramount. Integrating Conceal’s browser security solution aligns perfectly with our ambition to offer our customers top-tier, holistic security solutions," commented Toby Caton, Director at Kompingo. “Conceal also allows us to offer the product as a stand-alone solution to our growing MSP partners and reseller base for them to enhance their offerings further, too.” Gordon Lawson, CEO of Conceal, further emphasized the partnership’s potential: "Kompingo's expertise in managed security services makes them an ideal partner. We’re confident that by infusing ConcealBrowse into their MDR offerings, we can provide users with unprecedented protection from web-centric threats." Together, Kompingo’s state-of-the-art Security Operations Centre and ConcealBrowse promise a robust defense against today’s sophisticated web threats. With Kompingo’s AI and machine learning-enhanced operations now complemented by Conceal's dynamic web content analysis, both organizations are poised to set a new benchmark in cybersecurity. About Conceal Conceal is at the forefront of defending against web-based attacks, using innovative technology to detect, prevent, and shield businesses and individual users from ever-evolving online threats. ConcealBrowse operates on the principle of proactive protection. Its AI-powered intelligence engine, ConcealSherpa, runs at machine speed with virtually zero latency to identify potentially harmful webpages autonomously, stopping cyber attacks that take advantage of weaponized links. For more information, visit https://conceal.io/. About Kompingo Situated at the crossroads of innovation and technology, Kompingo has etched its mark as a leading light in the IT security arena. Famed for its comprehensive managed services, Kompingo is dedicated to incubating IT security start-ups, nurturing technological advancements, and driving growth. Their plethora of services, spanning from co-managed and fully managed offerings to vCISO and penetration testing, makes them an indispensable ally in the cybersecurity domain. With a steadfast dedication to the Cyber Essentials Scheme and their top-notch Managed Detection and Response services, Kompingo remains a name synonymous with excellence.

Read More

Data Security, Platform Security, Software Security

Immuta Unveils Platform Updates to Simplify Data Security and Monitoring in Snowflake

Businesswire | June 30, 2023

Immuta, a data security leader, today announced at Snowflake’s annual user conference, Snowflake Summit 2023, the launch of its latest platform enhancements to deliver simplified data security and monitoring in Snowflake so that joint customers can unlock more value, reduce costs, and speed up innovation. These new features include strengthened data mesh support, enhanced security for AI workloads in Snowpark, and advanced Data Security Posture Management (DSPM). The partnership between Immuta and Snowflake continues to have strong momentum, fueled by the growing adoption of their solutions at organizations across industries, including JB Hunt, Roche, and Thomson Reuters. In the last year, Snowflake has awarded Immuta with competency recognitions in the Healthcare & Life Sciences and Financial Services sectors. Earlier this week at Snowflake Summit, Immuta was also presented with the prestigious Data Security Partner of the Year Award by Snowflake. "Immuta has been pivotal in mitigating risk and optimizing operational efficiencies, allowing us to support self-service analytics and distributed data stewardship. We are innovating more and worrying less about security," said Paul Rankin, Head of Data Management Platforms at Roche. “As data volumes and AI-initiatives expand in the cloud, and more data teams adopt data mesh architectures, so too does the attack and risk surface,” said Steve Touw, CTO, Immuta. “As we extend our leadership in the data security category, we continue to collaborate with Snowflake to ensure our joint users can access their data securely at scale and continuously monitor usage to ensure security and compliance.” Securely Deploy New Data Products With Data Mesh Data mesh architectures promote decentralized data ownership to facilitate data management and help data owners build scalable and secure data-as-a-service products. However, the decentralized nature of a data mesh makes consistent data access control and policy enforcement difficult for organizations to manage at scale. Data mesh relies on four key pillars – domain-centric ownership and architecture, data-as-a-product, self-service data platform, and federated computational governance. Immuta’s built-in support for federated governance enhances Snowflake’s data governance capabilities to include scoping permissions through logical domain separation. Immuta’s support for data-as-a-product allows for granular permissioning of roles within individual data domains, and helps data owners securely innovate, build and deploy new data products, while eliminating centralized IT bottlenecks and accelerating their data mesh vision. Enhanced Security for AI Workloads in Snowpark Organizations are leveraging AI and ML to build advanced data science solutions for fraud detection, sentiment analysis, next-best-offer, predictive maintenance, and more. These solutions access a variety of data with speed and organizations must ensure the data is protected and in compliance with usage requirements. By leveraging Immuta, organizations can now enforce access controls and maintain compliance to effectively safeguard their data and AI workloads accessed via Snowpark. Advanced Data Security Posture Management with Immuta Detect Data is more available and distributed than ever, however the likelihood of a data breach is also at an all time high. In response, Data Security Posture Management (DSPM) has emerged as a new category of solutions aimed at discovering and mapping data flows and repositories to address new cloud data security and privacy challenges. Immuta Detect, now available to Snowflake customers, provides timely insights into data access, user activity and data controls, enabling data security posture management and risk remediation with the Immuta Data Security Platform. Users can now view a continuous data security posture management dashboard that shows a concise overview of data access insights, increasing awareness of attack indicators and risk vectors so that security teams can take action to improve data security. In addition, Immuta’s new Dynamic Query Classification (DQC) automatically classifies queries according to content and sensitivity level to provide security teams with better insight into what sensitive data is being accessed from unanticipated data combinations that are breaching confidentiality and potentially being exfiltrated. “Customers rely on Snowflake to maximize the value of their data, and to do so they’re building new architectures like data mesh and supporting new use cases using AI. To accomplish these initiatives, the data must be secured and security teams must have visibility into how the data is used in order to ensure compliance,” said Tarik Dwiek, Head of Technology Alliances at Snowflake. “Immuta is a key data security partner, and we’re thrilled to work with them as they roll out these new capabilities to provide great customer experiences.” Learn more about Immuta and Snowflake’s partnership here. Be sure to check out the Snowflake Summit 2023 keynotes live or on-demand here and stay on top of the latest news and announcements from Snowflake on LinkedIn and Twitter. About Immuta Immuta enables organizations to unlock value from their cloud data by protecting it and providing secure access. The Immuta Data Security Platform provides sensitive data discovery, security and access control, data activity monitoring, and has deep integrations with the leading cloud data platforms. Immuta is now trusted by Fortune 500 companies and government agencies around the world to secure their data. Founded in 2015, Immuta is headquartered in Boston, MA.

Read More