MSSP, Generative AI, Attack surface management, Data Security, Identity, Decentralized identity and verifiable credentials, Phishing

Druva Solution Looks to Bring More Intelligence to Identity Protection

Glowing fingerprint on sleek glass screen under hacker-blue lighting, ultra-HD, dark gradient backdrop. Symbolic of digital access breach, perfect for cybersecurity visuals and tech articles.

The definition of 'identity' has evolved over the past decade. The highly distributed nature of modern IT and business, and the resultant rapid rise in non-human identities (NHIs), has made identities an attractive target for bad actors. This has simultaneously expanded the attack surface for enterprises and smaller businesses alike, evidenced in threat intelligence reports that highlight threat groups abusing identities through phishing attacks, account takeovers, stolen credentials, and other means – as the primary avenue for compromising organizations.

In its Global Incident Response Report 2026, Palo Alto Networks’ Unit 42 threat intelligence group highlighted that 65% of initial access was fueled by identity-based techniques, like social engineering and credential misuse, and that weaknesses in identity played a key role in almost 90% of the unit’s investigations.

The rise of NHIs – service accounts, API keys, bots, and application identities – tied to AI agents, automated processes, and applications, outnumber human users by as much as 80-t0-1 and only add to the challenge.

Evolving Identities

“Identity has evolved from a perimeter gatekeeper into a sprawling, decentralized ecosystem where non-human identities outnumber human users, creating a massive, fragmented attack surface,” Yogesh Badwe, chief security officer at Druva, told MSSP Alert. “Non-human identities also lack the security control and governance that human identities have. [The] increasing footprint of third-party integrations and rise in AI Agents is only increasing this problem.”

According to Badwe, “the core security implication is that identity is no longer static; attackers now exploit the silent expansion of permissions and service account relationships to move laterally and bypass traditional defenses.”

A steady stream of security vendors is rolling out tools for protecting identities. The Santa Clara, California-based company, which provides a fully managed SaaS solution, this week launched Druva Identity Resilience, providing a range of capabilities – from unified protection to cyber recovery to threat detection and response – in a single SaaS platform and going beyond simply detection and directory backup, according to Badwe.

How Identities Relate and Change

Druva’s Identity Resilience understands how disparate identities relate and change over time, and how their behavior aligns with their evolving environments, he said.

“That’s what makes an identity-aware approach important,” he said. “Organizations need that missing layer of intelligence that maps identity relationships and behavioral context within a single SaaS platform.”

With this information, IT teams and MSSPs can make clearer decisions when an incident occurs and restore identity to a trusted state, according to the company. The offering models identity not as a collection of static directory objects. It shows the connections between human identities and NHIs, privileges, activity, and data across myriad identity providers, executives said.

Needed Context

This brings context to identities and allows security teams to distinguish legitimate behaviors and anomalies that could signal a compromise. Druva’s Dru MetaGraph underpins the vendor’s tenant-specific cloud-based architecture, through which IT and security teams can correlate identity changes and drive recovery decisions.

“Standalone identity and security vendors operate in the live production layer,” Badwe said. “Their focus is on authentication, policy enforcement, and detecting suspicious activity in near real-time. But when a potential incident is detected, the challenge shifts and teams need to be able to reconstruct what changed over time, how permissions evolved, and whether the current identity state can still be trusted.”

It’s a time-consuming task that often requires pulling data from multiple systems to manually piece together timelines and relationships, but “because Druva maintains a historical identity state within a single platform, we can provide the context that helps organizations connect those dots quickly and recover to a verified clean state,” he said.

Putting the Pieces Back Together

Such tools can help MSSPs ensure organizations can more quickly reestablish trusted access after an attack, the CSO said.

“By reconstructing changes to permissions and relationships and assessing their impact, MSSPs can determine what remains trustworthy, accelerating recovery and keeping organizations within required RTOs [recovery time objectives],” Badwe said.

Druva Identity Resilience initially will support unified protection across Okta, Microsoft Active Directory, and Entra ID environments, with plans to add other capabilities for recovery and threat detection and response coming soon.

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds