Platform Security, Software Security, Cloud Security

AppOmni Launches Identity Fabric for Secure SaaS Data Access

AppOmni Launches Identity Fabric for Secure SaaS Data Access

AppOmni, the leader in SaaS security, today announced SaaS Identity Fabric, an identity-centric solution that provides a comprehensive and consistent approach to securing end-user access to SaaS across the SaaS ecosystem. This enhanced capability includes end-user discovery, permissions analysis for identity governance, and end-user activity monitoring, combined with our advanced identity threat detection and response (ITDR) across enterprise SaaS applications. AppOmni’s SaaS Identity Fabric provides actionable user-centric insights with guided steps for remediation that can be accessed in the AppOmni console or integrated into an organization’s preferred security tool, such as a SIEM or SOAR solution.

Until recently, security and IT teams lacked the SaaS-specific security tooling to understand the risk created at the intersection of user over permissioning, posture misconfigurations, identity exposure, and malicious end-user activity. With the typical enterprise organization commanding a SaaS estate of hundreds of applications, pinpointing a specific end-user’s activity and risk across relevant SaaS apps presents a significant challenge to already overwhelmed security and risk teams.

Powered by the industry’s largest SaaS-activity data scope, which processes and analyzes over one billion events daily, the SaaS Identity Fabric empowers AppOmni customers to detect latent SaaS identity security risks, as well as identity-focused SaaS attacks that continue to dominate headlines and put organizations’ data, finances, and reputation at risk.

Without these SaaS events data logs and AppOmni’s unique identity-centric security approach, SaaS-specific end-user activity remains a blind spot for most enterprises, representing significant unmitigated cyber risk.

At a more granular level, the AppOmni SaaS Identity Fabric initiative enables a new level of identity cyber risk and threat detection capability and ability for security and risk teams to proactively manage the SaaS attack surface through the following capabilities:

  • Providing consistent and context-aware identity security governance across all SaaS apps, including custom, in-house apps
  • Identification of end-users with excessive identity access and permission entitlements or over-permissioning that introduce excessive cyber risk across all SaaS applications
  • Analysis and reporting of end-user permissions and roles that provide excessive permission scopes
  • Role-Based Access Control (RBAC) based on least privilege principles
  • End-User data access model analysis to help security and identity governance teams assess who can access specific data in complex SaaS data models
  • Comprehensive end-user activity monitoring and identity threat detection and response (ITDR) across all SaaS environments to identify compromised accounts, insider threat, and advanced threat actors, and guided risk and threat remediation
  • Out-of-the-box integration with SIEM, SOAR, and security data lakes to enable SaaS activity correlation with broader cyber threat data

The AppOmni SaaS Identity Fabric initiative removes this time-consuming, manual work, and is the first vendor in the SaaS security posture management (SSPM) marketplace to provide such insights. For example, a SOC team member may be alerted that an employee downloaded an unusually large number of files from a code repository. The security team can review the end-user’s activity over days, months, or even years across the code repository in conjunction with the end-user’s other active and inactive SaaS accounts. It can also identify other SaaS applications where the user may pose risk. This level of end-user activity insight and forensic capability is also becoming increasingly important from a regulatory compliance reporting standpoint.

Armed with this information and context, AppOmni customers can make smarter decisions, faster and mitigate cyber risk and significantly reduce the blast radius of a compromised end-user, promptly, with actionable security insights that enable guided remediation.

“As organizations move their sensitive and valuable data into SaaS applications, they have a more pronounced need for strong cloud data protection,” wrote Andras Cser, Vice President, Principal Analyst at Forrester, in The SaaS Security Posture Management Landscape, Q2 2023. “Excessive human and machine user identities’ access allows hackers to steal data easily from SaaS applications.”

"The SaaS Identity Fabric initiative is the next phase to further extend the AppOmni platform,” said Harold Byun, chief product officer at AppOmni. “Our solution already delivers best-in-class security for SaaS platforms, SaaS-to-SaaS connectivity, identification of critical misconfigurations and SaaS data leakage. The AppOmni SaaS Identity Fabric adds to this by providing an end-user-centric tie-in to help customers answer the question 'who did what, when' in each SaaS app, across the SaaS estate. Providing that level of visibility is paramount to securing these SaaS applications in today’s threat landscape.”

See AppOmni in action by scheduling time to chat with our identity security and SSPM experts or reach out to info@appomni.com.

About AppOmni

AppOmni is the pioneer of SaaS security that is trusted by over 20% of the Fortune 100 and secure enterprises globally. AppOmni provides unprecedented identity security, data access visibility, management, and security of SaaS solutions, enabling organizations to secure mission-critical and sensitive data. AppOmni’s patented technology deeply scans APIs, security controls, and configuration settings to evaluate the current state of SaaS deployments and compare against best practices and business intent. With AppOmni, organizations can establish rules for data access, data sharing, and third-party applications that will be continuously and automatically validated. It also offers unmatched SaaS compliance reporting capabilities according to the industry’s leading compliance benchmarks. The company’s leadership team brings expertise and innovation from leading SaaS providers, high tech companies, and cybersecurity vendors. Backed by Cisco Investments, Salesforce Ventures, ServiceNow Ventures, Scale Venture Partners, and more, AppOmni was recently named as a Notable Vendor by Forrester and PURE CYBER 100 “Companies To Watch In 2023.” The company has been recognized as a Dark Reading Cybersecurity Vendor to Watch and a SINET16 Innovator.

Spotlight

Other News
Data Security

GuidePoint Security Announces Portfolio of Data Security Governance Services

GuidePoint Security | January 30, 2024

GuidePoint Security, a cybersecurity solutions leader enabling organizations to make smarter decisions and minimize risk, today announced the availability of its Data Security Governance services, which are designed to help customers address the challenges of unstructured data and data sprawl through a proven process and program to meet their unique needs. GuidePoint’s Data Security Governance services consist of policies, standards, and processes leveraging the newest technologies to meet organizations’ data governance goals in both on-prem and cloud environments. Once the right strategy is determined with the customer, GuidePoint Security consultants will review program requirements, assess current policies and controls, perform gap analysis, design and develop/enhance the program, recommend and implement supporting technologies, and create operational processes and metrics. “Whether an organization is just beginning to build their data security governance program or needs help assessing and improving an existing program, our team and service capabilities are built to meet them at their current maturity level,” said Scott Griswold, Practice Director - Security Governance Services, GuidePoint Security. “We work side by side with the customer to conduct the necessary data discovery in their environment and provide tailored recommendations for solutions and processes to ultimately build/improve upon the data security governance program.” GuidePoint’s Data Security Governance Services include: Sensitive Data Cataloging: For organizations just getting started in the process of protecting their sensitive data, GuidePoint offers Data Identification workshops to identify sensitive data types in the environment, including trade secrets, intellectual property, and sensitive business communications. Data Security Governance Program Assessment: For organizations with existing Data Security Governance or Data Protection programs, GuidePoint Security experts will assess the program to identify policy non-compliance, gaps in data protection requirements—whether legal, regulatory, contractual, or business—and program maturity levels. Data Security Governance Program Strategy Development: The GuidePoint team will work with an organization's key stakeholders to design a program strategy aligned with relevant requirements. The outputs of this effort include delivering ongoing sensitive data discovery, automated classification and labeling, the application of required sensitive data protections, restrictions on where sensitive data can be stored and sent, and data retention policy enforcement. Merger and Acquisition Data Identification: This offering provides the ability to identify sensitive data within an M&A target or recent acquisition (including locations, amounts, and access rights) and then perform penetration testing on the storage repositories where that sensitive data exists to determine the risk of data compromise. About GuidePoint Security GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions that minimize risk. Our experts act as your trusted advisor to understand your business and challenges, helping you through an evaluation of your cybersecurity posture and ecosystem to expose risks, optimize resources and implement best-fit solutions. GuidePoint’s unmatched expertise has enabled a third of Fortune 500 companies and more than half of the U.S. government cabinet-level agencies to improve their security posture and reduce risk. Learn more at www.guidepointsecurity.com.

Read More