LastPass working through ‘systemic’ security overhaul (2024)

At LastPass, a security overhaul is underway in a monthslong effort to win back customer trust after the password manager was hit by a cyberattack in August 2022 that unraveled into one of the most notorious intrusions last year.

“We invested across platforms, infrastructure and systems — we believe all of which will mean a more modern and secure customer,” LastPass CEO Karim Toubba said via email.

“This has been a multiyear and multimillion-dollar investment. We’re still looking for ways to continue to invest and we’re not done,” Toubba said.

This “systemic change,” as Toubba describes it, is critical for customers’ security and the company’s future outlook.

With some security improvements complete and others still underway, a clear crisis of confidence among some of LastPass’ customers lingers. The scars of the comprehensive breach that exposed a cloud-based backup of all customer vault data remain.

“LastPass has seen about a 9% increase in customer churn since the end of Q4 2022,” Toubba said.

Toubba declined to say how many businesses currently use LastPass, but in a June interview he told Cybersecurity Dive the company had about 115,000 business customers after the customer renewal rate took a hit of about 8% in the first quarter of 2023.

“We’re now seeing evidence that our customer churn rates are improving and we anticipate being back to pre-security incident numbers in early 2024,” Toubba said.

The company’s cybersecurity makeover, a plan it first shared in March,touches a large swath of the alphabet soup of security tool acronyms.

A cloud security posture management (CSPM) layer was added to all cloud infrastructure and the company switched to an endpoint detection and response (EDR) system it deemed more effective.

The company also invested in a secure access service edge (SASE) deployment and improved logs and alerts in its security orchestration, automation and response (SOAR) platform, LastPass said last week in an update.

“We didn’t just address the issues that were the cause of the breach, we literally looked at everything and made investments across the board,” Toubba said.

It’s unclear how enterprise customers will respond to these initiatives.

The true impact of these changes depends on how LastPass’ infrastructure is architected, according to Allie Mellen, principal analyst at Forrester.

“However, the security updates overall are positive authentication and access improvements, software bill of materials initiatives, new cloud security investments, and data protection updates are efforts every company should invest in,” Mellen said via email.

“Ultimately, these updates are technical, and will be meaningful to security practitioners and LastPass partners, but are likely to have little effect with consumers beyond awareness that LastPass has made broad security enhancements,” Mellen said.

Other security improvements, according to LastPass, include:

  • A move to a new source code management system.
  • A new policy, still rolling out, that will eventually require all customers to use longer and more complicated master passwords.
  • A hardening of key component rotations for Okta and Microsoft Azure AD.
  • Improved recovery options for one-time passwords.
  • An initial deployment of FIDO2 hardware security keys.
  • A reset of security information and event management (SIEM) Splunk tokens and a new SIEM integration deployed in mid September that stores access tokens in encrypted form.
  • Code-safety initiatives for SBOM and elevated compliance with supply chain levels for software artifacts.

LastPass did not disclose the vendors it uses or the configuration of its security architecture.

LastPass working through ‘systemic’ security overhaul (2024)
Top Articles
What is OSI Model | 7 Layers Explained | Imperva
4 Ways to Make a Down Payment on a House When You Don't Have Much Saved
Toa Guide Osrs
Encore Atlanta Cheer Competition
Hallowed Sepulchre Instances & More
King Fields Mortuary
Skip The Games Norfolk Virginia
Strange World Showtimes Near Amc Braintree 10
Epaper Pudari
Urban Dictionary Fov
Obituary | Shawn Alexander | Russell Funeral Home, Inc.
Indiana Immediate Care.webpay.md
Koop hier ‘verloren pakketten’, een nieuwe Italiaanse zaak en dit wil je ook even weten - indebuurt Utrecht
Troy Athens Cheer Weebly
Breakroom Bw
Elizabethtown Mesothelioma Legal Question
180 Best Persuasive Essay Topics Ideas For Students in 2024
065106619
How do I get into solitude sewers Restoring Order? - Gamers Wiki
Att.com/Myatt.
Certain Red Dye Nyt Crossword
Craigslist Alo
Access a Shared Resource | Computing for Arts + Sciences
Wku Lpn To Rn
Uno Fall 2023 Calendar
Nurofen 400mg Tabletten (24 stuks) | De Online Drogist
Guide to Cost-Benefit Analysis of Investment Projects Economic appraisal tool for Cohesion Policy 2014-2020
Mark Ronchetti Daughters
Opsahl Kostel Funeral Home & Crematory Yankton
Kattis-Solutions
Regis Sectional Havertys
Can You Buy Pedialyte On Food Stamps
Sam's Club Gas Prices Florence Sc
Thelemagick Library - The New Comment to Liber AL vel Legis
Energy Management and Control System Expert (f/m/d) for Battery Storage Systems | StudySmarter - Talents
ACTUALIZACIÓN #8.1.0 DE BATTLEFIELD 2042
Chase Bank Zip Code
Grand Valley State University Library Hours
Walmart Careers Stocker
Mcoc Black Panther
Who uses the Fandom Wiki anymore?
6463896344
Jeep Forum Cj
Heat Wave and Summer Temperature Data for Oklahoma City, Oklahoma
Msatlantathickdream
Jigidi Jigsaw Puzzles Free
Raley Scrubs - Midtown
Rise Meadville Reviews
Acellus Grading Scale
Latest Posts
Article information

Author: Pres. Carey Rath

Last Updated:

Views: 6276

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Pres. Carey Rath

Birthday: 1997-03-06

Address: 14955 Ledner Trail, East Rodrickfort, NE 85127-8369

Phone: +18682428114917

Job: National Technology Representative

Hobby: Sand art, Drama, Web surfing, Cycling, Brazilian jiu-jitsu, Leather crafting, Creative writing

Introduction: My name is Pres. Carey Rath, I am a faithful, funny, vast, joyous, lively, brave, glamorous person who loves writing and wants to share my knowledge and understanding with you.