ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Xage Delivers Industry-first Multi-layer Identity and Access Management to Block Attacks on Critical Infrastructure

PALO ALTO, Calif., April 20, 2023 (GLOBE NEWSWIRE) -- Xage Security, the zero trust real-world cybersecurity company, today announced its new, industry-first Multi-layer Identity and Access Management solution to bring defense-in-depth to every asset in every layer of operational technology (OT) and industrial control system (ICS) environments. This innovation pairs with Xage’s existing multi-layer multi-factor authentication to protect critical infrastructure, including the ability to stop attackers from compromising critical assets, even if the attackers have stolen privileged login credentials.

Today there’s an escalating siege of credential-based attacks on real-world infrastructure. Nearly every headline-making attack of the past two decades, from Target to Equifax to the Colonial Pipeline ransomware, has involved stolen or compromised credentials. In parallel, government directives from the likes of TSA, CISA and NIST have led critical infrastructure organizations not only to prioritize cybersecurity but specifically to seek out an “identity-first defense-in-depth strategy.” Ideally, this type of strategy leverages the latest in identity and access management (IAM) advancements for zero trust with granular access control over a complex and interconnected OT-IT-Cloud architecture. 

“In operational environments where OT systems are increasingly interconnected with IT systems and the Cloud, it is imperative to strengthen defense-in-depth security measures to protect critical infrastructure,” said Jonathon Gordon, directing analyst at Takepoint Research.  "Simply put, Xage enables the deployment of a new line of defense to secure OT-IT convergence. With its Multi-layer Access Management solution, Xage markedly reduces risks due to a key attack vector, that of stolen credentials, designed to improve user experience without compromising cybersecurity, and supports OT-IT-Cloud interconnectivity securely for digital transformation initiatives.”

Operations teams struggle to evolve past their legacy perimeter-based approaches to access management. This causes users to be bogged down with multiple static credentials across OT and IT environments, makes the whole environment vulnerable when attackers get inside the perimeter, and can leave administrators unable to implement modern security features such as multi-factor authentication (MFA). Xage alleviates these traditional hurdles of executing an identity-based defense-in-depth strategy.

Xage Multi-layer Identity and Access Management addresses these challenges in an innovative way. The solution enables organizations to eliminate attacks on their critical infrastructure by delivering defense-in-depth security for their environments, while orchestrating protection across multiple identity providers, Microsoft AD instances, network security levels, and locations. By controlling, at a granular level, the access that each individual has, organizations are able to block credential-based attacks at earlier stages to limit damage and keep mission-critical services running. 

“Large operational enterprises design systems for high availability and resiliency, yet they face the challenge of cyber hardening complex IT, demilitarized zone (DMZ) and OT environment layers that are increasingly coming under adversarial attack,” said Duncan Greatwood, CEO of Xage Security. “Add to that the federal regulations and guidance from TSA, CISA and NIST,  and the urgency is clear for our Multi-Layer Identity and Access Management to deliver unified cybersecurity mesh protection for disjointed OT/IT/Cloud environments. Organizations have the ability to realize zero trust with granular control, no matter how complex or layered their existing equipment and architectures.”

Critical infrastructure operators, for example, can use Xage Multi-layer Identity and Access Management to create separate identities (e.g. login credentials) at each layer and site with different admins to ensure that compromise of corporate IT credentials doesn’t result in compromise within OT. This also assures that compromise of one site does not lead to compromise of all sites (or even other assets at the same site). In addition, operations teams can reduce complexity in the access management flow for their personnel and improve user experience, as well as block attacks by taking advantage of the following unique capabilities offered by the new Xage solution:

  • Orchestrate multiple Identity Providers (IdPs) and AD domains with different security zones or network layers, with an ability to configure different IdPs with different authentication protocols such as LDAP, SAML, and ADFS.
  • Restrict asset visibility for all users until after they authenticate: Only allow local and remote users to see the assets and systems for a site or zone after they successfully authenticate against that site level AD and pass the site-level MFA challenge.
  • Enable local users to authenticate with the local site level AD even if that site loses network connectivity.
  • Enable local and remote users to use passwordless, hardware-based, and biometric MFA through multiple hops that may be mapped to different identity providers.

Check out the Xage Multi-layer Identity and Access Management blog post here for more details on these features. To learn more about how the Xage Fabric can secure and transform critical infrastructure organizations, visit Xage.com. 

About Xage Security
Xage is the first and only zero trust real-world security company. Xage’s solutions and services accelerate and simplify the way enterprises secure, manage and transform digital operations across OT, IT, and cloud. Xage products include Identity & Access Management (IAM), remote access, and dynamic data security, all powered by the Xage Fabric. Xage also offers Cybersecurity Services, which deliver expert design, implementation, and support services to accelerate the adoption of proactive cyber-defense and underpin secure digital transformation. 

Xage PR Contact
xage-security@inkhouse.com 


Primary Logo

Recent Quotes

View More
Symbol Price Change (%)
AMZN  235.09
+1.21 (0.52%)
AAPL  285.50
+2.39 (0.85%)
AMD  217.25
-2.51 (-1.14%)
BAC  53.16
-0.09 (-0.16%)
GOOG  314.89
-0.23 (-0.07%)
META  643.54
+2.67 (0.42%)
MSFT  491.20
+4.46 (0.92%)
NVDA  181.46
+1.54 (0.85%)
ORCL  203.04
+2.10 (1.05%)
TSLA  423.81
-6.33 (-1.47%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.