Banking CIO Outlook
show-menu

Venafi: Machine Identity Protection for Banking

Jeff Hudson, CEO, VenafiJeff Hudson, CEO
The dynamics of the financial industry have changed drastically over the last decade; every financial services firm has steadily increased their reliance on technology. As a result, securing the ever-increasing number of SSL/TLS banking certificates and their corresponding keys required to keep communication between these new technologies secure has become a tedious, error prone task. However, when keys and certificates are poorly managed they dramatically increase security risks for banks. This is because certificates and keys serve as machine identities, similar to the way usernames and passwords serve as human identities. They are critically important in keeping the enterprise secure, because they establish which machines are safe to connect and communicate with and which are not.

To put this into perspective, Jeff Hudson, CEO of Venafi, highlights that every year banks end up spending billions to eradicate phishing attacks and other fraudulent activities, but these efforts are focused almost exclusively on human identities. At the same time, most financial institutions remain very vulnerable to attacks that target machine identities. “The problem lingers, because banks are still early in their understanding of the security loopholes associated with machine identities,” says Hudson. Just as consumers can have poor password hygiene, system administrators can apply weak security practices to machine identities, such as copying or sharing private keys. Machine identity protection is needed to enforce machine identity protection policies to ensure automated machine-to-machine connections and communications remain secure.

With its proprietary Venafi platform, the firm enables banks to authenticate and communicate securely across multiple machine identity types, including SSL/ TLS keys and certificates, SSH keys, and mobile, WiFi, and VPN certificates. The Venafi Platform provides detailed visibility as well as comprehensive machine identity intelligence to help banking organizations detect key weaknesses, prevent misuse and policy violations, and automate incident response. For example, banks can identify the keys and certificates that do not comply with bank policies for key length, hashing algorithm, validity periods, and other attributes, and can then automatically replace them with new, secure, and compliant ones. Venafi enables banks to oversee machine identity risks and consistently enforce stringent security policies.

Venafi also automates the entire key and certificate life cycle to enable customers to reduce management and administration time, as well as automating workflows and policies that govern keys and certificates.

Venafi makes it possible for banks to keep up with the rapidly increasing number of machine identities by providing full automation of keys and certificates across the entire machine identity life cycle


“Today, many of our clients are managing millions of machine identities. So, everything has to be automated to detect and deter weak or compromised machine identities,” mentions Hudson.

When a security event does occur, Venafi helps banks respond in real time. “Automation makes it possible for our clients to replace specific certificates very quickly or remediate thousands of certificates within just hours when a new machine identity weakness or threat is identified.”

The firm also provides an extensive technology partner ecosystem. Out-of-the-box integrations enable banks to integrate comprehensive machine identity intelligence with a wide range of systems. Venafi also created a set of APIs that can be used by its customers and partners to develop and customize interfaces to legacy and proprietary technologies quickly and effectively.

The firm has over 30 machine-identity-protection-related patents and spent over 200 million hours over the last decade developing robust security for keys and certificates. Hudson cites two examples of how Venafi has worked hard to partner with its extensive list of banking customers. In the first instance, after realizing they had no system to track certificates and their private keys, a major bank collaborated with Venafi to protect these important security assets. “We installed our machine identity platform that enabled the bank to gain control over their encrypted keys and deliver audit-ready evidence of these efforts. As a result, they got rid of audit findings.”

In the second case, Venafi assisted another bank that was using DevOps processes and workflows while they were moving applications to the cloud. “We helped them to set up machine identity protection that was fully automated from end-to-end, giving them comprehensive visibility and policy control while not slowing down DevOps innovation and delivery.”

Having worked with leading banks and government firms across the globe, the firm takes pride in partnering with some of the most security conscious financial institutions in the world. The Venafi Platform protects machine identities in four of the top five banks in each of the following countries: U.S., U.K., Australian and South Africa. In the days ahead, as the banking industry increasingly relies on Fintech, Venafi envisions itself as the only viable partner to protect the identities of these machines. Hudson concludes, “Our business is machine identity protection, and we are relentlessly focused on delivering the best technology and being the best partners.”
Share this Article:
Top 10 Security Solution Companies - 2018

Venafi

Company
Venafi

Management
Jeff Hudson, CEO

Description

Brings machine identity protection to secure the cryptographic keys and digital certificates used by every business and government

Venafi News

Venafi Introduces Control Plane for Machine Identity Management

SALT LAKE CITY-Venafi®, the inventor and leading provider of machine identity management, today unveiled the Venafi Control Plane for Machine Identities. The Venafi Control Plane unifies machine identity management across all identity types: in data centers, cloud, hybrid environments and at the edge. The Venafi Control Plane enables customers to accelerate digital transformation, increase development speed, reduce security risk and eliminate business disruptions.

“Venafi partners with the largest, most complex organizations in the world, and our solutions secure the vast majority of the digital infrastructure that runs our modern world,” said Jeff Hudson, CEO of Venafi. “These partnerships have given us a deep understanding of the complexity created by digital transformation and the shift to hybrid and cloud native architectures. Today, a typical global organization has hundreds of thousands of machines – which include applications, APIs, containers and microservices, in addition to physical devices -- spread across a wide variety of environments. Each one of these machines requires an identity. At Venafi, we know how costly and slow it is to build identity-based, zero trust architectures in these complicated, rapidly changing environments. The Venafi Control Plane for Machine Identities is unmatched in reducing complexity and increasing the speed of development, while at the same time increasing security for machine identities which are the foundation of trust in our modern world.”

There are two actors on every network: people and machines. People rely on usernames, passwords and two-factor authentication to gain access to data and services. Machines also need identities for the same reasons. Rapid adoption of cloud infrastructures requires a greater number and variety of machine identities, many of which change rapidly because they are ephemeral. For example, some cloud native environments require huge volumes of certificates (one of many different types of machine identities) with near zero latency. Organizations spend millions of dollars managing human identities but are just realizing the criticality of security and protecting machine identities.

The Venafi Control Plane is the only control plane for machine identity management designed to deliver observability, consistency, reliability and freedom of choice across clouds, hybrid environments, data centers and the edge.

The Venafi Control Plane delivers core capabilities directly and distributes or delegates them within reusable patterns and policy controls. Together these capabilities support cradle-to-grave machine identity lifecycle orchestration, authentication, authorization and governance providing customers with immediate value, including:

• Elimination of outages on customer-facing infrastructure, which saves an average $9.3 million of revenue per hour for financial services firms

• Dramatic reduction in the risk of data breaches that cost, on average, $5.97 million per breach

• Improvement of machine identity management efficiency, increasing productivity by as much as 98%

To ensure these capabilities are available in even the most demanding edge and cloud native environments, Venafi is also announcing early access to a new Venafi Control Plane service: Fast Issuance. Fast Issuance is an ultra low-latency service for issuing machine identities at speed with zero dependencies. The Fast Issuance service enables local issuance for entities or services that require machine identities to be delivered at scale with near-to-zero latency. Fast Issuance can be used in any environment: cloud native, data center, hybrid or edge.

Venafi has also published the Modern Machine Identity Management Reference Architecture. The Reference Architecture incorporates zero trust best practices for architecting machine identity management in data center, cloud and edge architectures. The reference architecture is based on extensive experience partnering with global organizations designing complex hybrid and cloud native production environments.

“As companies come to grips with the increasing number of workloads they are running in the cloud, they realize that inefficiencies are slowing down teams and creating new security risks that are just waiting to be exploited,” said Kevin Bocek, Vice President of Threat Intelligence and Security Strategy at Venafi. “Success in the cloud is now a function of design and architecture, especially when board members want specific information about zero trust strategies. Without the right architecture, the headaches, costs and incidents connected with the cloud are sure to grow. The Control Plane for Machine Identity Management is the first and only solution that gives platform and security teams the power to collaborate on repeatable design patterns and blueprints. From cloud native to mainframe, the Venafi Control Plane provides measurable consistency, observability and reliability. This new approach makes it possible for developers to build using the tools, clouds and languages they love, while security and platform teams have confidence and frictionless operations.”

Venafi Secures Workload Identities Across Cloud Native Environments With New SPIFFE Support for Venafi Firefly

New Capability Enables Security Teams to Ensure Governance and Reduce Risk, While Empowering Platform Teams to Accelerate Development

PARIS -(KubeCon + CloudNativeCon Europe 2024) — Venafi, the inventor of machine identity management, introduced SPIFFE (Secure Production Identity Framework For Everyone) support for Venafi Firefly, Venafi’s industry-first lightweight workload identity issuer uniquely designed to support modern, highly distributed cloud native workloads. As workload identity plays an increasingly fundamental role in cloud native architectures, today’s modern applications require an automated way to scale and secure heterogeneous workloads that are short-lived. By leveraging SPIFFE’s open source framework of identity standards, Venafi Firefly customers can now easily secure and govern workload identities across complex, dynamic development environments such as Kubernetes without slowing down innovation.

“There’s an urgent need to ensure workload identities are governed and consistent across many teams and applications in a modern business. Security teams want to know how and why workloads are being authenticated without getting in the way of business-changing apps.”

“The cloud native tsunami is making workload identity the focus for both security teams and adversaries. Knowing what workload is allowed to authenticate is only getting harder with more clouds, more clusters and more microservices,” said Kevin Bocek, chief innovation officer at Venafi. “There’s an urgent need to ensure workload identities are governed and consistent across many teams and applications in a modern business. Security teams want to know how and why workloads are being authenticated without getting in the way of business-changing apps.”

Unlike secrets managers and legacy PKIs that can’t support modern, decentralized approaches, Venafi Firefly with SPIFFE can easily and reliably mutually authenticate workloads across dynamic, multi-cloud environments using short-lived, verifiable identities managed by the Venafi Control Plane. As a result, security and platform teams can effectively secure workload identities across all environments while significantly reducing operational complexity and costs.

“Venafi Firefly goes beyond conventional workload identity management. It bridges the gap between security compliance and platform team efficiency by providing a unified, automated approach to seamlessly authenticate workloads in modern, cloud native environments,” said Shivajee Samdarshi, chief product officer at Venafi. “It automatically issues each workload with its own identity and creates an enterprise-wide trust root system to secure and authenticate workloads across any infrastructure. With SPIFFE support now added, platform teams can use Venafi Firefly to consume SPIFFE-compatible identities and seamlessly authenticate workloads for improved workload identity governance and trust.”

Venafi Firefly’s new SPIFFE capability offers security teams:

• Enhanced Governance and Security Compliance – Firefly with SPIFFE allows security teams to adopt a recognized industry standard for workload identity and security. This improves governance and security compliance for authenticating workload identities in highly scalable, cloud native environments.

• Secret-Less Authentication – Using Venafi Firefly, security teams can establish verifiable and ephemeral workload identities, underpinning a zero-trust architecture that eliminates the need for persistent, long-term secrets in certificates. Venafi Firefly automatically rotates and renews SPIFFE identities, which significantly mitigates the risks associated with secrets compromise or leakage.

Additionally, it offers platform teams:

• Advanced Automation for Workloads Across Multi-Cloud Operations – Venafi Firefly’s support for SPIFFE delivers a unified workload identity system, which helps platform teams remove the complexity and challenges of managing different workload identity systems from different cloud providers. This enables platform teams to simplify their operations and scale highly efficient, secure development environments across any public cloud, on-premise or hybrid setup.

• Simplified Service Mesh Operation With Automatic Mutual TLS (mTLS) – Using Venafi Firefly to authenticate SPIFFE identities enables simplified authentication and attestation of workloads. This creates secure trust domains using mTLS within Istio service meshes. Venafi Firefly scales trust domains by seamlessly enforcing identity and trust for workloads across multiple public cloud infrastructures and service mesh environments.

Venafi Introduces 90-Day TLS Readiness Solution to Accelerate Compliance With Shrinking Certificate Lifecycle Requirements

Helps organizations achieve the process simplification and automation necessary to meet the needs of new TLS lifecycle standards and post-quantum cryptography

SALT LAKE CITY --Ahead of RSA Conference 2024, Venafi, the inventor of machine identity management, today launched its new 90-Day TLS Readiness Solution to help organizations comply with Google's proposed 90-day TLS certificate standard, improving security posture while reducing the risk of certificate-related interruptions.

“Venafi’s 90-Day TLS Readiness Solution goes beyond the limited focus on certificate discovery and visibility that we see in the market today”

According to a Venafi study, 83% of organizations have been hit by certificate-related outages in the past 12 months, and 57% of organizations have experienced security incidents involving compromised TLS certificates. Shortening certificate lifespans will help businesses reduce the risk of compromise.

"Google’s proposal in the CA/Browser Forum to reduce TLS certificate lifespans to 90 days is an important step toward increasing the web's responsiveness to emerging threats and technological advances, including quantum computing. This significantly decreases the risks associated with key compromises by reducing the value of a key to the attacker,” explained Ryan Hurst, former head of product at Google. “Moreover, embracing automation not only enhances security but also mitigates the risk of outages, allowing organizations to reduce operational toil and free resources to work on more impactful tasks while supporting a more agile and trustworthy Web PKI."

“Transitioning to the 90-day TLS certificate standard isn't just about deploying technology—it's a comprehensive organizational shift,” said Ryan Douglas, cybersecurity architect at FactSet. “Venafi has been a crucial partner in equipping us for this change, not only by automating our certificate lifecycle management with TLS Protect but also by partnering with us to build a robust, cross-team foundation that prevents outages and ensures continuous compliance with the new standard. With Venafi’s support, we are starting to prepare early for 90-Day TLS certificates to ensure our entire organization is set up for success during this transition.”

Venafi helps organizations implement an effective certificate management process at both the technical and organizational level. Powered by Venafi’s Control Plane for Machine Identities, the Venafi 90-Day TLS Readiness Solution leverages Venafi’s TLS Protect to proactively identify and map TLS certificates into a comprehensive certificate inventory and renewal schedule for an organization. By delivering full visibility and control over TLS certificates—coupled with Venafi’s expert guidance to review policies, align processes, and design advanced automation workflows—this solution helps reduce the time and risk associated with automating the entire lifecycle process. Additional details on the new solution, including a full features list, can be found at https://venafi.com/blog/technology-alone-won-t-prepare-you-for-shorter-certificate-lifespans.

“Venafi’s 90-Day TLS Readiness Solution goes beyond the limited focus on certificate discovery and visibility that we see in the market today,” said Shivajee Samdarshi, chief product officer at Venafi. “Our solution combines cutting-edge automation technologies with strategic planning and support to help organizations simplify and navigate what is an overly complex process, enabling them to reduce outages, strengthen their overall security posture and ensure the agility required for initiatives like post-quantum cryptography.”