HomeMalware & ThreatsOkta Acquires Permiso to Enhance ITDR Capabilities Beyond Native Identity Logs

Okta Acquires Permiso to Enhance ITDR Capabilities Beyond Native Identity Logs

Published on

spot_img

Okta Set to Acquire Permiso Security to Enhance Identity Protection Capabilities

In a significant move to broaden its identity security offerings, Okta, the San Francisco-based giant in identity management, has announced its plans to acquire Silicon Valley startup Permiso Security. This acquisition is anticipated to greatly enhance Okta’s visibility across diverse enterprise identity ecosystems, enabling customers to detect security threats more effectively regardless of where their identities are located. Ely Kahn, the Chief Product Officer of Okta, emphasized that this step aims to provide a comprehensive view of identity threats, a necessity given the expansive use of multiple platforms like AWS and Azure alongside Okta’s own services.

The need for such integration has become increasingly apparent as numerous organizations leverage various identity infrastructures. Kahn further elaborated that until now, Okta’s Identity Threat Protection product primarily relied on its own telemetry data. The acquisition of Permiso is seen as a pivotal step in extending these identity threat detection capabilities beyond Okta’s native logs.

Permiso Security, established in 2020 by industry veterans Jason Martin and Paul Nguyen, has garnered attention for its innovative approach to identity security. The startup has raised $28.5 million in funding, with an impressive $18.5 million raised during its most recent Series A round, led by Altimeter Capital. Both Martin and Nguyen bring a wealth of experience from their previous roles at FireEye, where they played crucial roles in engineering and product strategy within the realm of global security.

One of the standout features of Permiso is its ability to not only detect isolated security threats but also to evaluate the complex interactions between various identity components within an organization. Okta already provides tools for Identity Security Posture Management, which identifies issues like dormant accounts and excessive permissions. However, where Permiso excels is in its capacity to recognize suspicious behaviors that may indicate compromised accounts. Kahn provided a compelling example: a dormant account exhibiting anomalous login activity can signal potential incidents, making such insights crucial for prioritizing security responses.

Okta’s evaluation of various acquisition candidates highlighted Permiso’s extensive identity telemetry as a key differentiator. The startup provides over 2,500 risk signals spanning more than 70 identity platforms, enabling Okta to significantly broaden the range of identities it can monitor. This expanded visibility allows Okta to integrate data from existing infrastructure, moving beyond merely first-party information to create a more holistic approach to identity threat detection.

Additionally, as artificial intelligence becomes more integrated into cloud environments, the need for oversight increases. Kahn mentioned that Permiso’s capabilities extend to the discovery and monitoring of AI agents, identifying anomalies that may signify compromises. This preemptive approach differs from traditional methods, as it assesses whether the operational commands fed to AI agents contain malicious intent rather than merely reacting to executed threats.

As a result of the acquisition, Okta aims to lessen its reliance on external partners for identity risk information. Currently, Okta can utilize its own threat detection mechanisms to trigger various security measures, such as blocking access or requiring additional authentication. By acquiring Permiso, Okta is looking to enhance its self-sufficiency in generating risk signals across multiple platforms, including Microsoft Entra and Google Cloud.

Identity providers like Okta inherently possess advantages over standalone security vendors. They are positioned at the forefront of the authentication process, enabling them to assess risks even before an individual logs in. This approach allows for immediate response measures to be implemented during the sign-in process while also providing continuous monitoring of user behavior post-authentication.

Kahn articulated the significance of this acquisition, stating that it offers Okta a unique opportunity to combine Identity Threat Detection and Response (ITDR) with Identity Security Posture Management (ISPM). This combination facilitates risk assessment before authentication, ongoing behavior monitoring post-login, and comprehensive action throughout the identity life cycle.

While Kahn refrained from disclosing specific financial targets, he indicated that Okta measures the success of its acquisitions based on customer adoption rates and long-term revenue growth. He also noted that the acquisition of Permiso is unlikely to be the last, hinting at further efforts to bolster Okta’s unified identity platform in the future.

Essentially, Kahn concluded by reiterating that the ultimate goal is to enhance customer safety through improved security offerings—a metric that can be gauged by the number of new customers opting for these services. The acquisition of Permiso Security, therefore, marks a significant step forward for Okta as it endeavors to reinforce its reputation as a leader in identity security while addressing the evolving demands of the digital threat landscape.

Source link

Latest articles

New Warnings of Russian Operatives Targeting Emails of US Nuclear Scientists and Defense Contractors

Russian Hackers Target U.S. Nuclear and Defense Sectors in Cyber-Espionage Campaign In a concerning development...

Chinese Hacker Utilizes DeepSeek AI to Coordinate Vulnerability Exploits

A Chinese threat actor has strategically exploited large language models (LLMs) offered by both...

Max-severity Exchange Server Vulnerability Actively Exploited by Kremlin Hackers

Russian Hackers Exploit Outlook Vulnerabilities to Compromise Security In a concerning development regarding cybersecurity, researchers...

Anthropic and OpenAI AI Sandbox Failures Highlight Testing Risks

Human Errors Allow Frontier AI Models to Escape Testing Sandboxes Recent admissions from leading artificial...

More like this

New Warnings of Russian Operatives Targeting Emails of US Nuclear Scientists and Defense Contractors

Russian Hackers Target U.S. Nuclear and Defense Sectors in Cyber-Espionage Campaign In a concerning development...

Chinese Hacker Utilizes DeepSeek AI to Coordinate Vulnerability Exploits

A Chinese threat actor has strategically exploited large language models (LLMs) offered by both...

Max-severity Exchange Server Vulnerability Actively Exploited by Kremlin Hackers

Russian Hackers Exploit Outlook Vulnerabilities to Compromise Security In a concerning development regarding cybersecurity, researchers...