By shifting our focus to secrets security and adopting a comprehensive approach that includes robust detection, automated remediation, and integration with identity systems, organizations can significantly reduce their attack surface and bolster their overall security posture. Secrets security begins with monitoring a wide range of assets at scale, from source code repositories to messaging systems and cloud storage. Integrating with identity and access management (IAM), privileged access management (PAM) systems, and Secrets Managers provides a more comprehensive view of NHIs footprint and activity. GitGuardian's partnership with CyberArk Conjur, the leader in secrets management and identity security, is an industry first. This partnership brings end-to-end secrets security to the market, unlocking new use cases such as automated public exposure detection, secrets management policy enforcement, and automated rotation following a leak. This is not an isolated story: 80% of organizations have experienced identity-related security breaches, and the 2024 edition of the DBIR ranked "Identity or Credential compromise" as the number one vector for cyberattacks. Accompanying Fortune 500 customers in this process for the past 7 years is what made GitGuardian the industry leader in secrets security. Organizations must adopt a proactive and comprehensive approach to NHI security, starting with secrets security. Unified incident management, custom remediation guidelines, and detailed incident information allow organizations to tackle the threat of secrets sprawl at scale. It's not surprising that mismanaged identities— of which secrets sprawl is a symptom—are now the root cause of most security incidents affecting businesses worldwide. In January 2024, Cloudflare internal Atlassian systems were breached because tokens and service accounts— in other words, NHIs— were previously compromised at Okta, a leading identity platform. The time to act is now—the question is, are you ready to take control of your secrets security? Start today with GitGuardian.
This Cyber News was published on thehackernews.com. Publication date: Thu, 03 Oct 2024 16:13:06 +0000