Reduction in the attack surface is the main benefit. We have not worked with it much yet, but so far, it has been good. It can be improved a bit more in the future, but so far, we have just scratched the surface with Entro Security.
Entro Security has helped develop a better culture among developers. They are willing and starting to use something called Vault to store credentials, and they even do it without us telling them. In the past, they used to post everything like in ClearText, whereas now, they are voluntarily migrating the information to Vault. I am pretty sure it is because Entro Security is also annoying them. Every time there is a finding, we ping them via Slack. The ping comes from Entro itself. They do not want to be bothered by messages. They do not want to be seen as a bad employee, so they are using it on their own.
It is not hard for us to establish behavioral baselines for non-human identities (NHI) in Entro Security.
It is important that Entro Security’s detection and mitigation of NHI threats is done in real-time. It is becoming a worldwide issue, not only in our company. So many companies are trying to solve this issue where developers are posting credentials in plain text. It is of very high priority. It is not critical, but it is highly important.
Entro Security has improved visibility, revealing the extent of our credential issues, where strong credentials like admin accounts were found in plaintext in numerous projects. We have more visibility and control. We got to know that the issue was much bigger than we thought. We thought that only one out of ten projects would have some kind of password, but we found more than five to seven projects having plain text credentials. The credentials stored were of strong accounts. They had put admin account information in plain text. We did not think it would be this severe. We thought that, at worst, they would be some maintainer credentials, but they were using full admin credentials in their code and had put them just in plain text.
Entro Security has helped improve our organization’s security posture.
Entro Security has decreased our exposure to risk. It reduces exposure from the inside, not from the outside.