{"id":3743,"date":"2024-05-23T17:21:23","date_gmt":"2024-05-23T22:21:23","guid":{"rendered":"https:\/\/www.darkreading.com\/identity-access-management-security\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal"},"modified":"2024-05-23T17:21:23","modified_gmt":"2024-05-23T22:21:23","slug":"cyberark-goes-all-in-on-machine-identity-with-venafi-deal","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/23\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal\/","title":{"rendered":"CyberArk Goes All In on Machine Identity with Venafi Deal"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd2f93c4f90bee583\/65f0ab5fc348e4040aa89088\/ai-Mopic-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Identity-based attacks aren&#8217;t just limited to breached credentials of people with rights to sensitive information or privileged access to critical systems. Machine identities are increasingly being targeted in attacks, and organizations need to expand their defenses to include both user and machine identity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Identity security and access management company CyberArk&#8217;s announcement it is spending <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/cyberark-picks-up-machine-id-manager-venafi-for-1-54b\" rel=\"noopener\">$1.54 billion to acquire Venafi<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from private equity firm Thoma Bravo reflects the shift to protect machine identities. CyberArk over the past few years has added machine identity management capabilities via Secrets Manager and Secrets Hub to its privilege access management (PAM) platform and identity and access management (IAM) tools. Venafi specializes in machine identity management, and will allow CyberArk to expand its capabilities once the deal closes in the second half of 2024. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Analysts say CyberArk has zeroed in on machine identity security more aggressively than other established identity providers among the significant providers of IAM and PAM platforms. &#8220;Machine identities haven&#8217;t been an area of focus for [most IAM] vendors,&#8221; says TechVision Research CEO Gary Rowe.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Machine Identity Management Heats Up\">Machine Identity Management Heats Up<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Several security companies have already made this shift. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/thoma-bravo-practical-decision-merge-forgerock-into-ping-identity\" rel=\"noopener\">Ping Identity merged with ForgeRock<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> last fall. Providers of certificate lifecycle management platforms have also added machine identity security capabilities, including AppViewX, Keyfactor and HashiCorp, which IBM recently&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/markets\/deals\/ibm-buy-hashicorp-64-billion-deal-expand-cloud-software-2024-04-24\/\" rel=\"noopener\">agreed to acquire<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;for $6.4 billion.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Numerous smaller players and startups have also surfaced with machine identity offerings. For example, startup Token Security&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/token-security-launches-machine-centric-iam-platform\" rel=\"noopener\">launched<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;a machine centric IAM platform earlier this month on the heels of receiving $7 million in seed funding from TLV Partners, SNR, and angel investors.&nbsp;Also, in February 2024, Entro&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/entro-extends-machine-secrets-and-identities-protection-with-machine-identity-lifecycle-management\" rel=\"noopener\">extended<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;its machine secrets and identity protection with a machine identity lifecycle management offering.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Forrester principal analyst Geoff Cairns says other startups with machine identity management offerings include Aembit, Astrix and Natoma. &#8220;We&#8217;ve been seeing a growing number of machine identity management startups recently, while established PAM vendors have mainly been approaching machine identity management from a DevOps-secrets management standpoint,&#8221; Cairns says.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Secrets Hub With Certificate Lifecycle Management\">Secrets Hub With Certificate Lifecycle Management<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, that was the case for CyberArk, whose secrets management offerings protect, discover, secure, and manage the secrets machines use to access data, infrastructure and systems. Yet, that only covers some of the potential machine identities that organizations manage.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We&#8217;re focused there, but that&#8217;s only a sliver of the extensive and very long-tailed set of non-human identities,&#8221; Clarence Hinton, CyberArk&#8217;s chief strategy officer, tells Dark Reading. Hinton explains that adding Venafi will let CyberArk expand its ability to manage and protect other machine identity types with Venafi&#8217;s certificate lifecycle management platform.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;They have a massive, powerful certificate discovery engine that defines certificates throughout your estate,&#8221; he says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Specifically, Venafi&#8217;s platform encrypts and locks down the certificates and ensures that any outdated, obsolete, or unused ones&nbsp;are destroyed. Also, Venifi keeps the rest of the certificates up to date, which includes automatically renewing them before they expire, Hinton says. &#8220;If you don&#8217;t renew an inactive and needed certificate, obviously you will have downtime that can be tremendously expensive,&#8221; he emphasizes.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After the deal closes, CyberArk plans to integrate its secrets management offerings with Venafi&#8217;s control plane. In addition to certificate lifecycle management, the Venafi control plane offers cloud-based PKI, identity management of IoT nodes and cryptographic code signing. The Venafi control plane secures machine identity types by orchestrating cryptographic keys and digital certificates using machine-to-machine communications.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We will deliver an end-to-end machine identity security platform at enterprise scale,&#8221; CyberArk CEO Matt Cohen said during the investor call announcing the deal. &#8220;We are confident this acquisition will help us set a new standard for machine identity security.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"More Machine Identities Than Human\">More Machine Identities Than Human<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cohen emphasized the growth of machine identities in the past two to three years, noting that large organizations can have 40 machine identities for every human identity. &#8220;The threat landscape has increased at such a quick vector, where machine identities are&nbsp;actually&nbsp;a target in the attack landscape&#8211;actually&nbsp;a significant target and a cause of several of the most recent, most prominent breaches.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The number of machine identities&nbsp;is expected&nbsp;to accelerate as companies expand their digital transformation efforts replacing legacy software with microservices, and they deploy IoT-based applications, In the next 12 months, CyberArk is forecasting a 2.4x rise in machine identities, based on a survey of 2,400 security leaders polled for the company&#8217;s 2024 Identity Security Threat Landscape. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to the report released this week, 68% noted that up to half of all machine identities have access to sensitive data, compared with 64% claiming that half of the human identities have that access.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CyberArk&#8217;s acquisition of Venafi underscores the growth of machine identities and the challenges that will put on large organizations, which require resilient operations and agile environments for developers, according to Forrester&#8217;s Cairns. &#8220;Longer term,&#8221; Cairns says, &#8220;it should enable organizations to take a more cohesive approach to identity security\u2014across a diverse set of both human and machine use cases\u2014with a single platform.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Identity-based attacks aren&#8217;t just limited to breached credentials of people<\/p>\n","protected":false},"author":12,"featured_media":3744,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3743","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=2560%2C1491&ssl=1",2560,1491,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=300%2C175&ssl=1",300,175,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=640%2C373&ssl=1",640,373,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=640%2C373&ssl=1",640,373,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=1536%2C895&ssl=1",1536,895,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=2048%2C1193&ssl=1",2048,1193,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=1024%2C596&ssl=1",1024,596,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/cyberark-goes-all-in-on-machine-identity-with-venafi-deal-scaled.jpg?fit=2560%2C1491&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3743"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3744"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}