Boomi Controls 3rd-Party NHI Access With Astrix

Danielle Guetta August 16, 2024

Navigating the risks of a cloud-connected ecosystem

Boomi, a leading integration and automation company, has been at the forefront of connecting systems securely for nearly 25 years. As a company that operates entirely in the cloud, with all corporate systems being SaaS-based, Boomi faces unique challenges in managing and securing the thousands of connections that drive their business.

The hidden threats in every connection

Like many in the industry, Boomi’s leadership took note of the increasing risks associated with non-human identities (NHIs) following high-profile incidents at companies like MGM, Okta, and Microsoft. Carl Siva, CISO of Boomi, recognized the potential dangers these connections posed: “It’s not just about who is managing these connections, but also the permissions and rights these third-party vendors have within our environment. The potential damage from a compromise is significant, especially when dealing with thousands of connections.”

Simplicity and speed in security

Faced with the need to manage and secure an ever-growing number of NHIs, Boomi turned to Astrix. The platform’s simplicity, risk scoring, and anomaly detection capabilities stood out immediately. “The tool had to be easy to use,” Carl noted. “The simplicity and the ability to quickly understand high-risk connections were key. The time to value was much faster than other software we’ve seen, and the support from Astrix was phenomenal.”

Rapid response in critical moments

Astrix proved its value during a critical moment when Boomi needed to assess the impact of a security event involving Snowflake. “What could have taken hours or days was compressed significantly with Astrix,” Carl explained. “We were able to quickly determine there were no indicators of compromise in our environment and start our incident process immediately. That kind of response time is crucial in mitigating risk.”

A comprehensive view and a trusted partner

For Carl and his team, Astrix has become more than just a tool; it feels like an extension of their security team. Boomi has integrated Astrix across multiple systems, including their corporate environment and SIEM, to gain a holistic view of their security landscape. “Astrix is a best-of-breed tool that delivers value quickly without a lot of heavy lifting. I’d absolutely recommend it.”

Learn more

CSA and Astrix Research: The State of Non-Human Identity Security

CSA and Astrix Research: The State of Non-Human Identity Security

Massive NHI attack: 230 Million cloud environments were compromised

Massive NHI attack: 230 Million cloud environments were compromised

App-Specific Passwords: Origins, Functionality, Security Risks and Mitigation

App-Specific Passwords: Origins, Functionality, Security Risks and Mitigation