Identity is a critical aspect of how users get access to network, cloud and on-premises resources, it's also often the weakest link in cybersecurity.

Protecting and managing identity is the realm of identity governance technology, which is what Boston-based Zilla Security provides with its technology. The company got its start in 2019 and to date had largely focused on identity governance in the cloud and software as a service (SaaS) environments. Now the company is looking deeper into the enterprise, with the launch of its Zilla PO Box technology, bringing its technology on-premises to enable hybrid identity governance.

“The last 10 to 15 years have been about standardized identity providers and the next 10 to 15 years are going to be about identity security providers that can lock down access,” Deepak Taneja, CEO, co-founder, and president of Zilla Security, told SDxCentral. “You need to lock down access to make sure that you don't have data breaches, because if you think about it, most data breaches today are rooted in some sort of identity and access compromised, and that's the idea that Zilla is based on.”

How Zilla helps to enforce identity governance

In the identity space, many organizations are already using technologies like Microsoft Active Directory or Okta.

Taneja said that Zilla isn't aiming to replace those technologies, rather he sees his company's technology as being complementary in many respects. He said that Zilla is complementary to Microsoft Active Directory and Okta because those products focus on user authentication, single sign-on and directory services.

While Microsoft and Okta handle the basic user identity layer, Zilla operates at a higher level of the identity stack. It focuses on governing and securing the permissions and access that identities have after authentication. Zilla reads identity data from Active Directory and Okta, but also integrates directly with apps. It then applies comprehensive governance across an  organization's IT environment.

Taneja said that Zilla works by connecting into a company's entire enterprise identity and access infrastructure, including applications, systems, APIs and more. It maps out all of the permissions and access configurations across the organization's digital assets. Zilla then continuously monitors this identity landscape to enforce governance and security policies. It ensures people only have the exact access they need to do their jobs. Zilla also helps provision new access automatically based on defined rules.

Hybrid identity governance with Zilla PO Box

With the new Zilla PO Box the company is digging deeper into the enterprise market.

“What's happening now is as we go more and more into the large enterprise market and connect with hybrid enterprises, companies are saying we have a lot of cloud apps, but we also have a lot of on prem apps and we want you to integrate with those really quickly,” Taneja said.

PO Box aims to solve this challenge by providing a way for Zilla to quickly integrate with and govern on-premises applications alongside cloud apps from its main identity security platform. PO Box acts as an extension that runs on premises connected back to Zilla's main cloud-based service.

The Zilla PO Box runs as a container that customers deploy on-premises. It then uses standard protocols like LDAP and SQL to integrate and gather data from legacy on-premises systems. This allows Zilla to provide a single unified experience and governance policies across hybrid environments

Looking ahead, Taneja said Zilla sees big opportunities to transform identity security using artificial intelligence (AI) trained on the vast amounts of user access data the platform collects.

“There's a lot to be learned from the decisions that people are making today about who should have access to what,” he said. “That is what we're going to leverage to kind of transform the space with AI.”