Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What SPIFFE Answers for Workload Identity and What It Doesn't

On workload identity, a spec the industry has already started building around, and what the next layer looks like. I don't have a better answer than SPIFFE (Secure Production Identity Framework for Everyone) for workload identity, and that's where I want to start, because what follows is going to sound like I do.

How Persona supports age verification and privacy online

Addressing these potentially competing priorities is difficult with today’s technology, and it's an active area of work for government agencies and private organizations alike. But we think there’s a potential path forward if regulations and organizations limit what you have to share, who you have to share data with, and how your data can be used.

Persona is one of the first verification vendors to accept California's mobile driver's license

During identity verification, organizations typically have to decide between increasing security controls and improving user conversion. Tighter checks mean more abandonment, and smoother flows mean more risk. Most verification flow design is an exercise in finding the right tradeoff. Mobile driver's licenses (mDLs) are different. Because an mDL is cryptographically signed by the issuing DMV and presented directly from a user's device, it's both faster to verify and harder to fake.

Stop Talking Tech to the Boardroom. Start Talking ROI.

The corporate firewall is dead. With cloud, remote work, and state-sponsored attacks reshaping the threat landscape, identity is now the security perimeter, and boards are paying attention to the price tag. One Identity CEO, Praerit Garg, shows CISOs how to ditch the technical jargon and make the case for identity security in the only language the boardroom understands: money, risk, and ROI.

Our comments to NIST: AI agent security starts with human identity verification

AI agents have developed advanced capabilities faster than most would have imagined. In enterprise contexts, workforces are delegating more and more tasks to them. While the promise of increased productivity is enticing, the shift from deterministic automated tools to agentic autonomous systems introduces security risks that most enterprises haven’t prepared for.

Introducing Persona's Workday Recruiting integration for candidate verification

Imagine spending weeks moving a strong job candidate through a rigorous interview process. The hiring manager is excited for their new hire and collaborates with multiple teams to prepare for a smooth onboarding. But on day one, a completely different person shows up for the job. For too many companies, scenarios like this have become disturbingly common. Besides introducing serious security risks, fake job candidates waste valuable talent team resources.

8 ways I use Graph to uncover fraud rings

As a fraud analyst at Persona, I have to balance working on fraud escalations for specific customers and keeping an eye on cross-customer (and cross-industry and cross-region) fraud trends. The work naturally overlaps, as one escalation can turn into a trend as fraud rings move on to new targets. And, getting ahead of large trends helps us stop escalations. I have a lot of tools at my disposal, but I want to discuss Graph, Persona’s real-time link analysis product.

What Is Third-Party Risk Management (TPRM)?

Your security team has hardened your perimeter. You have MFA enforced, endpoint detection running, and your crown-jewel systems are locked down tight. Then a vendor you onboarded two years ago, a mid-size SaaS tool your procurement team signed off on, gets breached. They had access to your customer data. Now it is your problem. This is the third-party risk problem in one paragraph. And it is why TPRM has moved from a compliance checkbox to a board-level conversation.

CrowdStrike Named a Leader in Identity Threat Detection and Response

Two recent industry reports validate CrowdStrike’s leadership in the identity threat detection and response (ITDR) market: Identity is the front line of modern cyberattacks. Today’s adversaries log in and use legitimate identities to move laterally, escalate privileges, and operate inside legitimate sessions as trusted users.