Okta Acquires Permiso to Extend Identity Threat Detection Beyond Native Logs
What Happened — Okta announced the acquisition of Permiso Security, a startup that provides identity telemetry across more than 70 platforms, to broaden Okta’s Identity Threat Detection and Response (ITDR) beyond its own logs. The deal adds over 2,500 risk signals and enables detection of multi‑platform credential abuse and anomalous activity.
Why It Matters for Compliance & Audit Readiness —
- Expands coverage for SOC 2 CC6 (Security) by feeding third‑party identity data into continuous monitoring, creating auditable evidence of threat detection across the entire identity estate.
- Supports the “Identity Management” control family (CC5) by correlating dormant privileged accounts with suspicious logins, helping demonstrate effective access‑control policies.
- Provides a single source of truth for control mapping, simplifying evidence collection for auditors and reducing gaps in the “Logical Access” controls.
Who Is Affected — SaaS identity providers, enterprises using hybrid cloud directories (Azure AD, Okta, GCP, AWS), and any organization subject to SOC 2 or similar frameworks.
Recommended Actions —
- Map Permiso’s risk signals to your SOC 2 CC5‑CC6 controls and update your continuous‑monitoring policy.
- Integrate third‑party identity logs into your SIEM/EDR to create a defensible audit trail.
- Validate that alerts generated from cross‑platform telemetry are documented and reviewed per your incident‑response playbooks. Source: DataBreachToday
Technical Notes — Permiso aggregates telemetry from 70+ identity platforms, delivering 2,500+ risk signals such as dormant privileged accounts, anomalous login locations, and permission‑escalation patterns. No new CVEs or vulnerabilities are disclosed. Source: DataBreachToday