Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Is Identity Governance and Administration (IGA)? A Complete Guide

Disconnected identity systems create the access risk, audit friction, and IT overhead that identity governance and administration (IGA) is built to close. The 2026 Verizon Data Breach Investigations Report found credential abuse in 39% of breaches. IGA combines policy, certification, and compliance evidence with automated provisioning, deprovisioning, and access requests to keep access aligned with business needs and reduce that risk.

How to reduce DLP false positives

DLP false positives bury real incidents under benign alerts and push teams to switch off the controls they bought. Most of that noise is configuration. Classify sensitive data before enforcement, pair content matches with identity and destination context, phase policies from simulation to blocking, and read override reasons as a tuning signal. Track the trend per policy, and you can show an auditor what the controls do.

A guide to API key management

Unmanaged, long-lived keys weaken visibility, audit readiness, operational continuity, and cyber resilience, making API key management critical across non-human identities. An effective program maintains inventory and ownership, enforces least privilege and secure storage, and automates rotation, monitoring, and revocation across each key's lifecycle.

Copilot broke your insider threat detection, and MITRE wrote the proof

MITRE ATT&CK's detection analytic for adversaries mining SharePoint describes bulk access to files and metadata in a short window by privileged or rarely used accounts. That is also a description of Microsoft 365 Copilot answering a question. The technique hasn't changed, but the baseline has, and the exposure now happens with no vulnerability, no compromised credential, and no malicious intent anywhere in the chain.

Uncovering indirect attack paths to virtualized domain controllers in Azure

Within Netwrix Security Research, we were helping a customer with an Entra ID assessment and knew they'd already done AD tiering on-prem. We also knew they had domain controllers virtualized in Azure, but it was hard to tell which Windows Server was actually a DC. We figured out that Azure Run Command lets you run commands as SYSTEM, so we used that to do reconnaissance and identify the DCs.

AI Governance in healthcare: Compliance and security

AI governance in healthcare has become a question boards and auditors ask directly. They want to know which AI tools reach protected health information, who's accountable for each one, and what evidence shows the controls are holding. Most health systems have a written policy and no way to produce those three answers on request, which is precisely what an auditor tests. Healthcare organizations adopted AI faster than they built the governance to account for it.

Endpoint Protector picks up 8 G2 badges for Fall 2026

Netwrix Endpoint Protector earned 8 G2 badges in the Fall 2026 reports, including Leader recognition in Data Loss Prevention (DLP) and Data Security, plus Regional Leader and High Performer badges across multiple regions. Endpoint Protector holds a 4.5 out of 5 rating from more than 160 G2 reviews, driven by feedback on fast support, quick implementation, and consistent policy enforcement. Buyers evaluating DLP tools have to take a lot on faith.

Top 9 Netwrix Auditor reports for NIS2 compliance audits

NIS2 changes what "good enough" security looks like for a huge slice of the European economy. If your organization operates in energy, transport, finance, health, digital infrastructure, or any of the other sectors the directive designates as critical infrastructure, you can no longer choose whether to formalize your cybersecurity risk management. Instead, you have to decide how fast you can prove it.

The Linux AI blind spot: 7 exfiltration points your DLP can't see

Shadow AI now contributes to one in five data breaches, and Linux endpoints, where most developers work, largely lack DLP enforcement. That means engineers can upload code to AI tools, copy files to USB or Bluetooth devices, sync data to personal cloud storage, and move files through network shares undetected. HIPAA, PCI DSS, GDPR, and CMMC hold organizations accountable regardless of this coverage gap. Netwrix Endpoint Protector extends content-aware inspection and device control to Linux.

Device inventory is not privileged account discovery

A device inventory tells you where the machines are, while a privilege inventory tells you where an attacker can go. An endpoint record can show that a machine exists, who owns it, and whether a management agent has checked in. It does not show who can administer that machine. That distinction matters because an attacker doesn't need a complete asset inventory. A valid privileged path to one useful endpoint may be enough.