[00:00:00] [music]
[00:00:04] Welcome back to another episode of Tech
[00:00:06] Unhinged, where tech gets human. I’m
[00:00:07] your host, Ravia Jave, and joining me
[00:00:09] today is DJ David Mariamano, um, field
[00:00:12] CTO for North America at Zeliant, where
[00:00:15] he helps Fortune 500 companies build
[00:00:17] identity and access management
[00:00:18] strategies. DJ brings over 20 years of
[00:00:21] hands-on experience implementing
[00:00:22] identity security across financial
[00:00:24] services, healthcare, energy, and
[00:00:26] manufacturing. DJ is also a contributor
[00:00:28] to industry research groups that shape
[00:00:31] global identity security standards. DJ,
[00:00:33] welcome to the show.
[00:00:34] >> Yeah, thanks for having me. It’s good to
[00:00:35] be here.
[00:00:36] >> Well, uh, for setting the stage off for
[00:00:38] our topic in hand today, which is Agent
[00:00:40] AI in the enterprise. TJ, you’ve spent
[00:00:42] over 20 years in the identity trenches,
[00:00:46] building IG, implementing PAM,
[00:00:48] privileged access management, working
[00:00:50] with Fortune 500s. Now you’re finishing
[00:00:52] a book on aentic AI. What made you pivot
[00:00:55] from identity governance to writing
[00:00:58] about AI? What’s the problem that you’re
[00:01:01] trying to solve? There’s a couple
[00:01:02] problems for sure that I think need
[00:01:04] addressed in the industry and and one of
[00:01:06] the reasons why I’m I’m writing the book
[00:01:08] in particular is if I look at my past
[00:01:11] experience and looking at the governance
[00:01:13] controls that we put over humans
[00:01:15] carbon-based life forms that exist in
[00:01:17] all white all walks of life in in the
[00:01:20] industries that uh we serve is those
[00:01:23] core principles of you know validating
[00:01:26] who could do what why they’re doing it
[00:01:28] is it appropriate those are core
[00:01:30] principles that need adapt apted into
[00:01:32] this, you know, new world and new age of
[00:01:34] AI. And one of the reasons why I’m
[00:01:37] writing the book is to try to reshape
[00:01:39] those principles in ways that could be
[00:01:41] easily digested and easily acted upon
[00:01:44] for the enterprise to manage uh agentic
[00:01:46] AI in particular. And one of the I think
[00:01:48] that one of the key differentiators that
[00:01:51] I I want to try to get across and it
[00:01:53] seems like the industry is is also
[00:01:55] leaning into is that when we look at a
[00:01:57] Gentic AI in particular, it really we
[00:02:00] need to start looking at them as an
[00:02:01] identity as a digital governed worker,
[00:02:04] not as like a traditional service
[00:02:06] account for example. There’s this
[00:02:08] demarcation between different types of
[00:02:10] non-human identities. And and the
[00:02:12] easiest way that I I kind of put the two
[00:02:15] sides of that up is on one side, which
[00:02:18] non-human identities have existed for
[00:02:19] quite some time. It’s not a new concept,
[00:02:21] but on one side, we have identities or
[00:02:24] or non-human accounts that we tell what
[00:02:26] to do like a service account or an RPA
[00:02:30] bot or maybe even a workflow. We’re
[00:02:32] scripting. We’re we’re deciding the
[00:02:34] permissions. We’re deciding the actions
[00:02:36] and we’re telling it to do a thing to
[00:02:38] provide an output. On the other side
[00:02:40] though, in this new world of AI and
[00:02:42] Agentic, we’re not necessarily telling
[00:02:44] it to do, we’re requesting it to do
[00:02:46] something. And because we’re requesting
[00:02:48] it to do something, it’s determining how
[00:02:50] to do the output. Just like a person,
[00:02:52] right? We hire a person onto a job and
[00:02:55] to a role and we trust that they’re
[00:02:57] going to fulfill that role. We don’t
[00:02:58] tell them how to do the job. We request
[00:03:01] them to do the job. We hire them to do
[00:03:03] the job and they kind of determine the
[00:03:04] right way to to work and flow to give us
[00:03:07] that output. Um I’m sure through the
[00:03:08] conversation we’ll get a lot deeper than
[00:03:10] that but but at its core it’s really
[00:03:12] defining how to look at these things and
[00:03:15] that’s kind of why I entitled the book
[00:03:17] you know you know it’s kind of I could
[00:03:19] almost summarize it like HR for AI but
[00:03:21] it’s a you know aentic AI you know why
[00:03:24] it’s kind of the new insider threat
[00:03:26] thinking of it as a human almost but not
[00:03:28] quite again it’s not a carbon based life
[00:03:30] form but those basic controls over the
[00:03:32] last 20 years we’ve developed need
[00:03:34] adapted I wouldn’t say replaced or
[00:03:36] changed but they need adapted and
[00:03:38] evolved per se for this new era.
[00:03:40] >> No absolutely and you know how you
[00:03:42] phrase it as the HR for the AI you know
[00:03:45] I am excited to dive further into that
[00:03:47] you know into our conversation. David in
[00:03:49] one of your articles about the striker
[00:03:51] cyber attack you wrote that identity is
[00:03:54] now operational infrastructure but with
[00:03:56] agentic AI entering enterprises in 2026
[00:03:59] are we facing a fundamentally different
[00:04:01] kind of identity crisis and what has
[00:04:03] changed? Yeah, that’s actually a really
[00:04:05] good question and uh in particular the
[00:04:07] part about if we’re facing a new crisis
[00:04:10] and I would probably argue the answer is
[00:04:12] yes and no into that and the reason why
[00:04:15] that is is the way that we’re looking at
[00:04:18] identity and and we’re looking at kind
[00:04:21] of the threshold that threshold being
[00:04:23] almost lowered you know for that
[00:04:25] boundary of entry because of AI we’re
[00:04:27] looking at more of an expedited more
[00:04:30] effective more realtime faster
[00:04:34] you know, attacker, a bad actor. And
[00:04:35] that bad actor may not be a human. It,
[00:04:38] you know, actually may be, you know, an
[00:04:40] agentic AI agent or maybe it’s an army
[00:04:43] of those agents backended by a human.
[00:04:46] And the reason I say yes and no is that
[00:04:48] they’re still kind of going down the
[00:04:50] same attack pattern. You know, they’re
[00:04:52] potentially going down, you know, trying
[00:04:54] to spoof and fish and, you know, steal
[00:04:57] credentials. At the end of the day, when
[00:04:59] we look at the world of privileged
[00:05:01] access, you know, that’s what ultimately
[00:05:03] the bad actor is after is access. Access
[00:05:05] to data. Data is the golden, you know,
[00:05:08] goose that they’re trying to capture.
[00:05:09] And they’re going to do so with access.
[00:05:11] They’re going to do so with privilege.
[00:05:12] So, it’s the same things that we’ve been
[00:05:15] fighting for years, just at a much
[00:05:18] larger scale, faster scale, more
[00:05:20] immediate scale. Now on the other side
[00:05:23] of that coin is there are new ways that
[00:05:27] we’re still trying to or bad actors are
[00:05:29] still coming after the same things right
[00:05:31] there’s you know an injection of an
[00:05:33] agent almost like putting in an impostor
[00:05:36] into your environment right it’s an
[00:05:38] interesting world and we can kind of go
[00:05:39] down those paths but that that spectrum
[00:05:42] of attack vectors and if you look at
[00:05:44] like the MITER attack framework and all
[00:05:46] of that it’s not that that stuff isn’t
[00:05:48] is is old news and you set it aside
[00:05:50] really It’s the same thing that we’re
[00:05:53] trying to defend against. It’s just now
[00:05:54] the attacker’s been empowered, enriched
[00:05:57] with more effective, you know, toolkit.
[00:06:00] And that toolkit, you know, good or bad,
[00:06:02] has lowered that boundary of entry. And
[00:06:04] what I mean by that is is these bad
[00:06:06] actors aren’t necessarily the top
[00:06:08] skilled people anymore. They can use AI
[00:06:10] to upskill, you know, their their attack
[00:06:13] and upskill their effectiveness. This
[00:06:15] super basic example of just fishing
[00:06:17] campaigns, right? We used to educate our
[00:06:19] workforce of looking for mistakes and if
[00:06:21] something’s misspelled or check the you
[00:06:23] know URL and still do those things.
[00:06:26] However, AI is is allowing the the bad
[00:06:29] actor to just get that much more
[00:06:31] realistic. And then you can’t you know
[00:06:32] we can bring deep fakes and and AI video
[00:06:35] and voice you know fraud and all that
[00:06:37] stuff into the mix now. It’s just so
[00:06:39] much more convincing is and us as humans
[00:06:42] we’re we’re gullible by nature. You know
[00:06:44] it’s interesting when you say that
[00:06:45] because you know my next question is
[00:06:47] about um you know one of the things that
[00:06:49] you mentioned about you know 1:10 ratio
[00:06:52] one human to 10 machine identities right
[00:06:55] but we see David that AI agents aren’t
[00:06:57] just service accounts or API keys um
[00:06:59] they make decisions they act
[00:07:01] autonomously they behave differently how
[00:07:02] does an AI agent fundamentally differ
[00:07:04] from the machine identities we have been
[00:07:07] managing for the years
[00:07:08] >> one thing I want to comment on uh before
[00:07:11] diving into that question is if you were
[00:07:13] to go back you know a year from now you
[00:07:16] know and saying that machine identities
[00:07:19] uh in particular non-human identities
[00:07:21] outnumbered you know 1 to 10 right then
[00:07:23] then a few months later then all the
[00:07:25] reports were like 1 to 50 and then that
[00:07:27] now it’s like 1 to 100 and and that
[00:07:29] ratio keeps growing and I kind of taking
[00:07:31] the stance and the belief that the ratio
[00:07:34] itself is not necessarily the the issue
[00:07:37] or the or the talking point it’s we know
[00:07:39] that that ratio is an is out there we
[00:07:42] know that there’s some sort a
[00:07:43] multiplier. Non-human identities will be
[00:07:45] a multiplier to the workforce. It that’s
[00:07:48] just now common knowledge at this point.
[00:07:50] Also, we have to take into consideration
[00:07:52] different verticals and different sizes
[00:07:54] of organizations. That ratio is probably
[00:07:56] going to be different. So, if I go in
[00:07:58] and say it’s definitely 100 to one and
[00:08:01] then another organization, it still may
[00:08:02] be 1 to 10. I mean, and I get that, you
[00:08:05] know, if you look at the the latest
[00:08:06] report from like PaloAlto and them, they
[00:08:08] I think it’s around 199 to1. And that’s
[00:08:11] probably a good average, but again, the
[00:08:13] value of knowing that isn’t, I think, as
[00:08:15] potent as it used to be because it’s
[00:08:17] such a moving target. It the the value
[00:08:19] is knowing it’s a multiplayer. It’s
[00:08:21] you’re going to have more. The number of
[00:08:23] how many more is is not necessarily the
[00:08:26] issue. It’s the controls and the
[00:08:27] mechanisms and the methodology and being
[00:08:29] able to look at that inventory and have
[00:08:32] that inventory and tie it back to
[00:08:33] ownership. We need to kind of move past
[00:08:35] the scary fact there’s more. We know
[00:08:37] there’s more. Let’s get into the next
[00:08:39] level. But as far as the the the
[00:08:41] question directly when we talk about,
[00:08:43] you know, non-human identities and like
[00:08:45] like I said kind of earlier in this
[00:08:46] session here that non-human identities
[00:08:48] have been around for a while. We’ve been
[00:08:49] using service accounts. we’ve been
[00:08:51] using, you know, writing scripts that
[00:08:52] are using different types of keys and
[00:08:55] sessions and these general concepts and
[00:08:57] uh and populations of of accounts aren’t
[00:09:00] necessarily a new thing. It’s now a new
[00:09:02] classification that has emerged when we
[00:09:04] look at these. And although we look at
[00:09:07] machine identities and we look at
[00:09:08] nonhumans and we want to kind of wrap
[00:09:10] this big bubble around it, the reality
[00:09:12] is is if you if you look at the
[00:09:14] traditional type of service account or
[00:09:16] or the type of nonhuman that is again
[00:09:20] leveraged in a process that we’ve
[00:09:22] designed that we’ve built that we’ve
[00:09:25] instructed is we’re sitting there and
[00:09:27] we’re saying let me go request this
[00:09:29] account that has access to X. This
[00:09:31] account’s going to live in all
[00:09:32] perpetuity and more than likely be
[00:09:34] static. Although the secret should not
[00:09:36] be static. There should be privilege
[00:09:38] management controls around it. But in
[00:09:40] most organizations, it’s static still.
[00:09:42] That’s going to be an account that we
[00:09:43] have told it exactly what to do and we
[00:09:46] expect it to do it in a certain way and
[00:09:49] we expect the outcome that we’ve
[00:09:51] designed. The other category around
[00:09:53] Agentic and AI is we don’t really tell
[00:09:56] it how to do what it’s going to do,
[00:09:58] right? we’re going to go to the and
[00:10:00] we’re going to give it a a role. We’re
[00:10:02] going to give it a purpose. We’re going
[00:10:04] to ask it to do something. We’re going
[00:10:05] to request it to do something. And then
[00:10:07] the agent itself, the AI model, is going
[00:10:10] to try to serve back what it thinks
[00:10:12] we’re asking for. And it’s it’s going to
[00:10:15] determine how to do that. It’s going to
[00:10:17] go out to the data that it has
[00:10:19] available. It’s going to go out and look
[00:10:20] at what it can obtain. And don’t, you
[00:10:23] know, be deceived at any level, right?
[00:10:25] It’s not going to go specifically after
[00:10:27] what you’re asking. It’s going to
[00:10:28] consume everything it can consume to try
[00:10:31] to give you back the output that you it
[00:10:33] thinks that you’re wanting and it’s and
[00:10:35] it’s going to heir on the side of
[00:10:37] positivity and and try to please you.
[00:10:39] It’s going to try to give you what you
[00:10:41] want over and over and over. And that’s
[00:10:44] a behavior that is native to a lot of
[00:10:47] these agents. And I think it’s something
[00:10:49] that can be easily exploited if we don’t
[00:10:51] have proper controls. One of those big
[00:10:52] differences other than that
[00:10:54] categorization is the fact that we now
[00:10:57] have something that is operating in the
[00:10:59] environment when we speak of that agent
[00:11:01] side where we don’t really have the
[00:11:03] insights into how it’s reasoning and
[00:11:06] thinking right and it can hallucinate
[00:11:08] and make things up and serve it to us
[00:11:09] and make us believe that that is
[00:11:11] correct. So we need to not only have
[00:11:13] proper controls around permissions and
[00:11:16] data and and look at it like an insider
[00:11:18] like an insider thread if it’s not quite
[00:11:20] you know controlled but it still makes
[00:11:22] mistakes just like humans make mistakes.
[00:11:24] The difference is humans are typically
[00:11:26] going to believe the mistakes the AI is
[00:11:28] making because we’re not taking the time
[00:11:30] to validate its output but all along
[00:11:32] while it’s thinking while it’s reasoning
[00:11:34] we don’t really know what and why it’s
[00:11:36] doing what it’s doing. So we need to
[00:11:38] have proper visibility on that. We need
[00:11:40] to understand the intent. And that’s the
[00:11:42] difference, right? When we built a
[00:11:44] script on the left hand side, when we
[00:11:46] told it what to do, we knew why it was
[00:11:49] doing it cuz we told it to do it that
[00:11:51] way. We don’t necessarily know the
[00:11:52] intent in which it did something. We
[00:11:54] know the output of what it done, but why
[00:11:56] the intent? We’re not scrutinizing the
[00:11:58] intent. And that’s one of the things
[00:12:00] that’s missing in or organizations
[00:12:02] today, right? We’re overlooking that. So
[00:12:04] this categorization of the two camps is
[00:12:07] to my mind pretty easy to tell, right?
[00:12:09] You tell it to do something on the left
[00:12:11] hand side, you request it to do
[00:12:12] something on the right. And ultimately,
[00:12:14] if you kind of think of it like you’re
[00:12:16] hiring somebody, you’re going to write a
[00:12:17] job description. And in that job
[00:12:19] description, you’re going to have roles
[00:12:20] and responsibilities. It’s kind of the
[00:12:22] same way with an agent, right? If you
[00:12:24] could sit down and say this finance
[00:12:26] agent or this, you know, engineering
[00:12:28] agent or this developer agent, whatever
[00:12:30] the case may be, if you were to write a
[00:12:32] job description as if you were hiring
[00:12:34] someone to do what you think that
[00:12:35] agent’s going to be used for, you kind
[00:12:37] of start to see the boundaries in which
[00:12:38] it could work. Now, it in itself isn’t a
[00:12:41] control mechanism, don’t get me wrong,
[00:12:43] but it at least opens up the mindset and
[00:12:45] the conversation as to where those
[00:12:47] boundaries and those control mechanisms
[00:12:48] should be. That’s an entirely different
[00:12:50] conversation than hey I need a service
[00:12:52] account and I needed to have access to
[00:12:54] this server or I needed to have access
[00:12:56] to this and I’m going to run a scheduled
[00:12:57] task. Completely different ballgame.
[00:12:59] >> Here’s one scenario that I’m going to
[00:13:01] coin you know which is probably keeping
[00:13:02] the CIOS up at night. An AI agent
[00:13:05] anonymously provisions access to
[00:13:07] production database because it learned
[00:13:09] that’s what helps the team move faster.
[00:13:12] Something goes wrong data gets exposed.
[00:13:14] Now who’s accountable there? the
[00:13:16] developer who deployed the agent, the
[00:13:19] person who gave it the initial access,
[00:13:21] the EI itself. How do we begin to answer
[00:13:23] this question?
[00:13:24] >> Yeah. No, it’s a it’s definitely a
[00:13:26] question that I think deserves some
[00:13:28] thought and some discussion in most
[00:13:29] organizations. And I and I don’t quite
[00:13:31] hear the depth of conversation when I go
[00:13:34] into organizations to the level it needs
[00:13:36] to be. And and I’ll take it back one
[00:13:38] step is I know a lot of CIOS, CISOs,
[00:13:40] leaders are still struggling with where
[00:13:43] are the agents? How many agents do I
[00:13:45] have and what are they doing and and you
[00:13:47] know who commissioned them? Let’s just
[00:13:49] use that term for now until we move
[00:13:51] further into the question. Now once we
[00:13:53] can solve that, once we start to get a a
[00:13:55] picture of our AI estate, right? What’s
[00:13:57] there? Who’s there? What is it doing?
[00:13:59] What’s its intent? we can start to put
[00:14:01] together a a hierarchy of control and
[00:14:04] accountability and that all hinders on
[00:14:07] observability, right? We still have to
[00:14:09] be able to see it. We have to know what
[00:14:11] it’s doing and we have to justify it. As
[00:14:13] far as the accountable party, this is
[00:14:15] where it’s again different from the old
[00:14:18] world, right? I requested a service
[00:14:20] account. I’m going to build something
[00:14:21] and me as the the developer, the writer,
[00:14:23] the scriptor is probably going to be
[00:14:24] responsible for that service account. if
[00:14:26] I do something wrong with it, I’m
[00:14:28] probably the accountable party. However,
[00:14:31] in the AI world, the enentic world, we
[00:14:34] have to look at it in a little bit
[00:14:36] different of an angle. And this kind of
[00:14:37] goes back to some of the stuff I put in
[00:14:39] my book as well, which is think of these
[00:14:41] as a digital governed worker, not as a
[00:14:44] service account. And just like a
[00:14:46] governed worker, just like a worker, a
[00:14:48] cobburn based life form, they have a
[00:14:49] manager, they have a reporting
[00:14:51] structure. And and we have to look at
[00:14:53] what the job that it’s doing and who’s
[00:14:56] going to be accountable for the output
[00:14:57] of that job. And you know, take f let’s
[00:15:00] just do a crude example with finance,
[00:15:01] right? In the human world, you have
[00:15:03] maybe a a finance director, maybe some
[00:15:05] finance managers that report to that
[00:15:07] director and then you maybe let’s just
[00:15:08] say accountant for keeping the
[00:15:10] conversation simple underneath those
[00:15:12] managers and they all have their
[00:15:13] separate things and books and all that
[00:15:15] that they’re accountable for. Well,
[00:15:17] let’s start pulling in agents and and AI
[00:15:19] into that to automate and do some of
[00:15:21] this more autonomously. We’re probably
[00:15:23] going to have layers of agents, right?
[00:15:26] We’re going to have those actionable
[00:15:28] workers that are going to report to more
[00:15:30] of a manager style agent or an overseer
[00:15:32] agent. Now, whether we have another
[00:15:34] layer beyond that still up for
[00:15:36] discussion and and structure depending
[00:15:38] on the use cases, but ultimately what
[00:15:40] we’re saying is at that worker level, we
[00:15:43] need some sort of oversight. in that
[00:15:44] oversight is more than likely going to
[00:15:46] be yet another agent. And at the
[00:15:48] accountable level from a human side,
[00:15:50] because they should still be in the
[00:15:51] loop, it’s not necessarily the one who
[00:15:53] commissioned and built the agent. It’s
[00:15:55] the one who’s asking and requesting a
[00:15:58] job to be done of the agent. So, it’s a
[00:16:00] little bit of a different world, right?
[00:16:02] Perfect utopian setting. You know, only
[00:16:05] finance agents would be doing work for
[00:16:07] the finance team and therefore you have
[00:16:10] an accountable manager or accountable
[00:16:12] party tied to that. Going way back to
[00:16:14] earlier in the conversation, we talked
[00:16:16] about some of the principles over the
[00:16:18] last 20 years and we look at like
[00:16:19] something like IGA or identity
[00:16:20] governance administration, right? We
[00:16:22] need those types of structures and
[00:16:24] capabilities with you know entitlement
[00:16:26] management at astation control and tying
[00:16:29] it back to a manager or or an operator
[00:16:32] in in that sense not an owner of a
[00:16:34] service account but an actual reporting
[00:16:36] manager or reporting party over this
[00:16:40] particular agent. So again, there
[00:16:42] there’s probably not even enough time in
[00:16:44] this call to really break down that
[00:16:46] structure and how to do this and and how
[00:16:49] to stay on top of it because there are
[00:16:51] ways to do so. But it becomes a very
[00:16:53] large conversation of what ifs. Well,
[00:16:55] what if this and what if that and what
[00:16:56] if this. And when those whatifs come up,
[00:16:58] that lets me know immediately we’re
[00:17:00] probably working in the wrong framework
[00:17:01] for that organization. Not that everyone
[00:17:03] needs to understand and be on board, but
[00:17:05] when we look at the right framework for
[00:17:07] that particular organization, the the
[00:17:09] whatifs start to kind of disappear
[00:17:11] because we’re putting the correct
[00:17:12] boundaries around it, right? We need
[00:17:14] those boundaries. We need those
[00:17:16] controls. Again, finance agents working
[00:17:18] for the finance team. You wouldn’t hire
[00:17:20] someone, a human, to go into the finance
[00:17:23] team and then expect them to get onto
[00:17:25] servers and deploy and patch, right?
[00:17:27] It’s a different role. It’s a different
[00:17:29] job. So don’t expect your agents to be
[00:17:31] able to cross that way, right? Put them
[00:17:33] in the right teams in the right
[00:17:34] categories.
[00:17:35] >> David, in context of privileged access
[00:17:37] management, if we look at it
[00:17:39] holistically, are we being forced to
[00:17:41] choose between security principles and
[00:17:43] AI functionality or is there a middle
[00:17:45] path that doesn’t compromise either?
[00:17:48] >> Yes to all the above. [laughter]
[00:17:50] So most organizations are at different
[00:17:52] levels of maturity and I would probably
[00:17:55] argue the fact that no organization is
[00:17:58] really actually mature in this space
[00:18:00] right we’re all maturing but there are
[00:18:02] different levels of maturity so if we go
[00:18:04] back just ah just just a year AI was
[00:18:07] around but the adoption seemed to be
[00:18:09] just like lightning speed it was all
[00:18:11] about efficiencies it’s all about
[00:18:13] gaining you know the the the edge over
[00:18:16] your competitor it’s all about how do we
[00:18:17] use AI how do we do this what are we
[00:18:20] with AI. It it was very businessoriented
[00:18:22] and driven and the explosion and
[00:18:25] adoption of AI has frankly outpaced the
[00:18:28] control of AI, the AI control and the AI
[00:18:30] structure. What’s happening now is we’re
[00:18:32] starting to catch up a little bit and
[00:18:34] we’re starting to see frameworks
[00:18:36] released. We’re starting to see ideas of
[00:18:38] control and governance manipulation and
[00:18:41] all this stuff starting to come into
[00:18:42] play in particular around, you know,
[00:18:44] privileged access. Now all these things
[00:18:46] are catching up and what they’re doing
[00:18:48] is going back to those older principles
[00:18:50] that are you know tried and true if you
[00:18:52] follow them appropriately and adop
[00:18:53] adopting them and evolving them for this
[00:18:55] world. problem is, you know, that’s what
[00:18:57] they’re doing is they’re catching up,
[00:18:59] right? We we’re in this little bit of a
[00:19:00] paradigm where a lot of organizations, a
[00:19:02] lot of businesses are saying, don’t
[00:19:05] disrupt like our operations. Don’t don’t
[00:19:07] disrupt our our path forward. Like don’t
[00:19:10] slow us down, basically. But security is
[00:19:13] saying, I need to slow you down because
[00:19:15] we’ve gotten too big or we’ve gone too
[00:19:17] many directions and we need to put these
[00:19:18] controls in. So, we need to work
[00:19:20] backwards. Well, there is a middle
[00:19:21] ground there, right? that and in that
[00:19:23] middle ground, it really starts with
[00:19:25] observability and it starts with the
[00:19:27] awareness of what’s going on because I
[00:19:29] would argue most businesses as they’re
[00:19:31] using and adopting AI on the business
[00:19:33] side, they don’t really understand maybe
[00:19:35] the fact that what their request is or
[00:19:37] that application they brought in has,
[00:19:39] you know, x amount of agents along with
[00:19:41] it or it’s got x amount of access. They
[00:19:43] probably don’t understand on the back
[00:19:44] end and more more than likely they
[00:19:45] probably don’t need to understand on the
[00:19:47] back end how big of an issue that is
[00:19:48] other than the fact it’s an issue but
[00:19:51] we’re going to start pulling that back
[00:19:52] while we allow you to keep doing what
[00:19:54] you’re doing. And you only can do that
[00:19:55] with observability to understand what it
[00:19:58] is that they’re doing and then start
[00:19:59] questioning the intent. So it’s a big
[00:20:01] project, big effort becomes a massive
[00:20:03] program. It’s I’m not trying to
[00:20:05] understate the fact it’s a lot of work
[00:20:07] but it’s something that we have to kind
[00:20:08] of step into but we have to step into
[00:20:10] very fast. We have to try to catch up. I
[00:20:13] don’t think we’ll ever actually get
[00:20:14] caught up. I think it will still
[00:20:16] slightly outpace and and my my evidence
[00:20:19] for that is if you just go back to the
[00:20:20] basic, you know, world of just PAM and
[00:20:23] IGA and, you know, in that realm and
[00:20:26] what we’ve been doing with humans, I
[00:20:27] still haven’t encountered a large
[00:20:29] organization that has those controls
[00:20:31] across everything. It’s always a limited
[00:20:33] scope, right? You might have a in place.
[00:20:35] It’s not 100% of your applications
[00:20:37] you’ve got this control on. It’s
[00:20:39] probably a smaller subset. there’s
[00:20:40] probably applications you still don’t
[00:20:42] even know exist in your environment even
[00:20:44] though you think you have a good
[00:20:45] inventory. On the same side with
[00:20:46] privilege access controls, you may think
[00:20:48] you have all your quote unquote
[00:20:50] privileged accounts or or or u you know
[00:20:52] high critical accounts managed by by
[00:20:55] Pam, but there’s probably plenty out
[00:20:57] there you’re not aware of. But again,
[00:20:58] adoption of that still hasn’t been
[00:21:00] caught up with where it needs to be. So
[00:21:02] I don’t have any disbelief that on the
[00:21:04] AI world or the AI side of it that all
[00:21:06] of a sudden we’re going to get caught up
[00:21:07] and get ahead of that when it comes to
[00:21:09] control. We’re still struggling to get
[00:21:11] ahead of it for humans and no
[00:21:13] organization I’ve ever worked with has
[00:21:15] been completely ahead of it in all
[00:21:17] aspects in scope areas of the
[00:21:19] organization sure but on an
[00:21:20] enterprisewide end to end 100% yeah it
[00:21:24] still just doesn’t happen. I think it’s
[00:21:25] a little bit of an uphill battle, but
[00:21:27] ultimately it comes down to, and I think
[00:21:29] this is the biggest problem in
[00:21:30] organizations, lack of skills,
[00:21:32] understanding, resources, and people.
[00:21:34] We’re saying that this whole AI wave is
[00:21:36] going to eliminate, you know, jobs and
[00:21:39] be efficient and do all of this. And in
[00:21:40] some aspects, that is true, but on the
[00:21:42] security and the control side, we we we
[00:21:45] don’t have the right skills and enough
[00:21:46] people to stay on top of what we’re
[00:21:48] staying on top of and stay on top of all
[00:21:50] of this. There will be an inflection
[00:21:52] point of that that changes um from a
[00:21:54] resourcing perspective and an efficiency
[00:21:56] perspective the more we let AI manage
[00:21:58] and control AI with some sort of human
[00:22:00] oversight but we’re not quite there yet.
[00:22:02] >> Delving into you know the ownership
[00:22:04] model and you’ve spoken about it in you
[00:22:06] know some of your podcasts as well that
[00:22:08] how every identity needs someone
[00:22:10] accountable and that is a human on the
[00:22:11] hook and that is you know this this has
[00:22:13] been uh one of the hot debates in in the
[00:22:16] tech these days too. So David, what does
[00:22:19] that ownership model actually look like
[00:22:21] for AI agents? Is it like application
[00:22:24] owners in the identity and governance
[00:22:26] administration or do we just completely
[00:22:29] um you know have a new governance
[00:22:31] structure? Walk us through what probably
[00:22:33] good looks like.
[00:22:34] >> Yeah, I I think it’s a it’s a bit of a
[00:22:36] mixed model. If we talk about what good
[00:22:37] looks like, right, let’s set aside the
[00:22:40] fact that nobody’s actually there and
[00:22:42] there’s multiple, you know, competing
[00:22:44] models and structures. Just set all that
[00:22:45] aside. In a in a perfect world, we look
[00:22:47] at these AI agents. Again, it’s going to
[00:22:49] be a mixed model. And AI agents that are
[00:22:52] designed and and hired on to do a
[00:22:55] particular set of jobs. Those need to be
[00:22:58] in a more traditional governance
[00:23:00] structure where they report to a human,
[00:23:03] right? We’re going to do addestation and
[00:23:05] governance controls just like we do a
[00:23:06] human. And in order to do that, we need
[00:23:08] to have it report to some sort of
[00:23:11] manager or governing body that it
[00:23:12] understands what that agent is doing
[00:23:14] from a job perspective, the types of
[00:23:17] things that are being requested of it.
[00:23:18] So just like humans report to that
[00:23:20] manager, that agent reports to a manager
[00:23:23] per se, and we have that add astation,
[00:23:25] that governance control. There’s a
[00:23:27] little bit of a nuance there, which is
[00:23:28] if we put the right boundaries around
[00:23:30] that agent, then we’re not necessarily
[00:23:32] saying do an add astation of every
[00:23:34] single agent because you may have one
[00:23:36] agent, you may have a thousand agents
[00:23:38] doing the same thing. But if they’re all
[00:23:40] copies of each other doing the same
[00:23:42] thing, as long as we have that template
[00:23:44] and control around them all, you’re
[00:23:46] doing an addestation of that template
[00:23:47] and that control. On the other side,
[00:23:49] when it comes to application owners, the
[00:23:52] way that we look at application owners
[00:23:53] today, those that are kind of closer to
[00:23:55] the application or to the data or or you
[00:23:58] know, all the above, when we get into
[00:23:59] more of the crown jewels conversation,
[00:24:02] kind of the the important critical
[00:24:04] things in the organization, I think it
[00:24:06] has to be more than just a quote unquote
[00:24:08] manager, right? It has to be some sort
[00:24:10] of security oversight or security
[00:24:13] accountability as well as an application
[00:24:16] owner accountability. Right? Now the
[00:24:18] person over the application isn’t always
[00:24:20] the one who understands what the user is
[00:24:22] doing with that application. Therefore,
[00:24:24] that’s why we still kind of need need
[00:24:26] the manager per se in there, but the
[00:24:27] person over the application should know
[00:24:30] how they’re allowing the agents to
[00:24:32] interact with that application and that
[00:24:34] data or you know so they’re they need to
[00:24:36] be involved. But then there’s the
[00:24:37] security level that security aspect and
[00:24:39] accountability right so there’s kind of
[00:24:41] a triaged approach to these kind of more
[00:24:43] crowd jewels critical things and that
[00:24:45] and that level we need proper DLP you
[00:24:48] know data loss protection we need to see
[00:24:50] the intent of the agent maybe why it is
[00:24:52] doing the thing it’s doing you know do
[00:24:54] basic insider threat you know checking
[00:24:56] you know make sure it’s not taking large
[00:24:58] chunks of data and sending it off to a
[00:25:00] third party for a thing or this you know
[00:25:02] we need these types of controls so it’s
[00:25:04] not as simple as hey this agent has the
[00:25:07] access to do X. Do you approve, manager?
[00:25:10] Yes, I approve. And then you move past
[00:25:12] it. Some agents will probably live in
[00:25:14] that world if they have the right
[00:25:15] control. But again, your crown jewels,
[00:25:18] your critical systems need more scrutiny
[00:25:20] because it’s not the fact that the agent
[00:25:22] has the access to do it. It’s why is the
[00:25:25] agent doing what it’s doing with the
[00:25:27] access that it has because it’s again
[00:25:29] being requested to do a job and it’s
[00:25:31] just going to try to fulfill that job.
[00:25:33] So we need to look at that whole action
[00:25:35] path, right? Why the request came in.
[00:25:38] What was the intent? All right, the
[00:25:39] agent tried to fulfill it. What was the
[00:25:41] intent of it going after what it was
[00:25:42] going after? Why did it do it this way
[00:25:45] and not that way? What was the intent of
[00:25:46] that? Then the output. What did we do
[00:25:48] with the output? What was was the output
[00:25:51] valid? Was it handed off to a third
[00:25:53] party when it should not have been? Was
[00:25:54] it given to the right party? Um how do
[00:25:56] we validate that it’s DJ sitting at the
[00:25:59] machine who’s asking it to do it?
[00:26:01] because maybe the agent has access to do
[00:26:03] X but DJ doesn’t have the access to see
[00:26:05] the output of X or should not have the
[00:26:07] privilege of doing so which get brings
[00:26:09] just one comment I I I want to make uh
[00:26:11] before we move on we mentioned a couple
[00:26:13] times now about privilege privilege
[00:26:15] access control I have this conversation
[00:26:17] quite a bit in organizations is we’re we
[00:26:19] we are past a point in this industry
[00:26:21] where there is a delineation between a
[00:26:24] normal user and a privileged user all
[00:26:26] users human and non-human are privileged
[00:26:28] they have access to do something within
[00:26:30] the organization Now they have different
[00:26:32] levels of privilege for sure. However,
[00:26:34] we cannot live in a world any longer
[00:26:37] where we say there are just standard
[00:26:39] users and then there are privileged
[00:26:41] users. Everyone in the organization has
[00:26:43] access to do something on company
[00:26:46] property, company assets with company
[00:26:48] data, company communications at some
[00:26:51] level. We need to deem them all as
[00:26:53] privilege and put the right controls in
[00:26:56] place. Again, different levels of
[00:26:57] privilege, but still when we go to the
[00:26:59] mindset of those are just standard
[00:27:01] users. And again, this goes for Agentic
[00:27:03] as well. Those are just standard agents
[00:27:05] or they’re just doing job X and that’s
[00:27:07] not important. We we’re giving ourselves
[00:27:09] a little bit of false security by saying
[00:27:11] nothing bad could happen over there. The
[00:27:13] reality is a lot of bad could happen
[00:27:14] over there. Now, they still want to get
[00:27:16] to the other side of the fence, but
[00:27:17] they’re going to start and typically on
[00:27:19] that side of quote unquote a
[00:27:21] non-privileged user. So, I just wanted
[00:27:22] to put that comment out there. As we
[00:27:24] move into this new era, we have to step
[00:27:26] back and say human and non-human, end to
[00:27:28] end, everyone is privileged, we need the
[00:27:30] proper controls in place end to end, not
[00:27:33] just in one category.
[00:27:35] >> And now if we talk about you know a few
[00:27:37] concise steps for enterprises in
[00:27:39] particular, if an IT director is perhaps
[00:27:41] listening right now, their CEO just
[00:27:43] announced we are going AI first, which
[00:27:45] you will hear all of the companies these
[00:27:47] days doing and suddenly there are AI
[00:27:49] agents being piloted in three different
[00:27:51] departments. what are the first three
[00:27:53] things they should do from an identity
[00:27:55] and access perspective? So the first
[00:27:58] three things I’m going to start with
[00:27:59] maybe like a little bit of foundational
[00:28:01] maybe a step zero thing. And this isn’t
[00:28:03] necessarily a step. It’s more of a
[00:28:05] public service announcement which is
[00:28:07] there is no there is no vendor out there
[00:28:10] that’s going to solve this problem for
[00:28:12] you. Not end to end. There’s no magic
[00:28:13] bullet. There’s not one one particular
[00:28:16] product or one vendor that’s just going
[00:28:17] to be able to drop in and fix
[00:28:19] everything. Right? So, if you’re just
[00:28:21] starting and you’re going about saying,
[00:28:22] “I’ve got this problem or I need to be
[00:28:24] able to put something in and you’re
[00:28:26] going to go out and look at tools first
[00:28:28] and vendors first.” I think you’re
[00:28:30] starting in the wrong place. I think
[00:28:31] what you need to start with is
[00:28:33] understanding your estate, understanding
[00:28:35] what’s there, understanding the vision
[00:28:37] of the organization as to where it’s
[00:28:38] going to try to head with AI and then
[00:28:40] creating your strategy, your vision,
[00:28:43] your mission statement as to how you’re
[00:28:44] going to align or secure or change that
[00:28:49] whatever that is, right? We need to
[00:28:51] start there, that step zero. And I I
[00:28:53] work a lot with with leaders uh in the
[00:28:55] organization where I come in and you
[00:28:57] know we’ll do like an kind of an
[00:28:59] advisory view a strategic session where
[00:29:01] we kind of help them with that. Here’s
[00:29:03] the right way to think about it for your
[00:29:05] organization. Here’s the right stepping
[00:29:07] stones for your strategy. But eventually
[00:29:09] we do get to that conversation, right?
[00:29:11] We’re going to need technology to be
[00:29:13] able to solve the issue. But the
[00:29:14] technology, the tool is not the
[00:29:16] solution. It is a tool to allow us to
[00:29:19] provide a solution. So that’s kind of my
[00:29:21] step zero, right? Like understand that.
[00:29:24] Then we get into step one. Step one is
[00:29:26] truly to understand and and be able to
[00:29:30] look at your environment, understand
[00:29:32] your estate, understand exactly where
[00:29:35] all these agents are. So step one is
[00:29:37] understand the size of the problem. And
[00:29:40] and that sounds very negative when I say
[00:29:42] problem, but but ultimately that’s what
[00:29:44] we’re trying to solve. It’s a series of
[00:29:46] challenges and it’s a series of of
[00:29:48] issues um that we need to align to. Now,
[00:29:50] once we understand that, as we move into
[00:29:52] step two, when we move into step two,
[00:29:54] it’s really about that prioritization,
[00:29:56] right? Working with the business,
[00:29:58] creating proper organizational control
[00:30:00] because again, you don’t want to slow
[00:30:02] them down or give them the perception
[00:30:04] you’re going to slow them down by
[00:30:05] putting in controls. And in this
[00:30:07] prioritization step, this is when we
[00:30:09] want to align with some sort of
[00:30:11] framework or a combination of frameworks
[00:30:13] that are best for your industry or best
[00:30:15] for what your goals and objectives are.
[00:30:17] Um, just like my comment about the
[00:30:18] tools, there’s a lot of good information
[00:30:20] across multiple different frameworks
[00:30:22] that are starting to appear, but that
[00:30:24] doesn’t mean that’s 100% the fit for
[00:30:27] your organization. A lot of these
[00:30:28] frameworks go after the same outcomes uh
[00:30:30] or similar outcomes. So let’s let’s
[00:30:32] align a best fit, you know, series of
[00:30:34] guidelines for you, but still the notion
[00:30:36] is the same. There’s different ways to
[00:30:38] kind of get there and figure out what’s
[00:30:40] going to work with your culture, your
[00:30:42] environment. Then in step three and and
[00:30:44] again there’s way more than three steps,
[00:30:46] but in step three, like we’re just
[00:30:48] talking getting started, right? This is
[00:30:50] when we can kind of have that technology
[00:30:52] discussion, right? We understand the
[00:30:53] size, the estate, the scope of the
[00:30:56] problem. We’ve prioritized, we’ve
[00:30:58] aligned with a framework. Now, let’s go
[00:31:00] to the to the market. Now, let’s go to
[00:31:02] the industry and say, “All right, to put
[00:31:04] this into practice. What technology is
[00:31:07] out there that aligns best with what I
[00:31:09] need to accomplish.” See, if you were to
[00:31:11] start with the tool, you would have
[00:31:12] skipped those steps or at least not gone
[00:31:14] to the depth you need in those previous
[00:31:16] steps. And sometimes that tool you’re
[00:31:17] bringing in doesn’t quite align and you
[00:31:19] now are forced to reshape. And sometimes
[00:31:21] that reshaping is what causes your
[00:31:24] program or your project to stall and get
[00:31:26] stuck in a rut because you didn’t quite
[00:31:28] you’re not using the right tool for the
[00:31:29] right problem. And ultimately, you know,
[00:31:32] now that you’re having that discussion,
[00:31:33] it’s probably not going to be one tool.
[00:31:35] You’re probably going to need a tool for
[00:31:37] the data side of this issue. Maybe a
[00:31:39] tool for the governance side of this
[00:31:40] issue. Maybe you need a tool for the
[00:31:42] privilege side of this issue. And it
[00:31:43] sounds daunting because you’re like,
[00:31:46] more tools, more tools, more tools. But
[00:31:48] the reality is is most large
[00:31:49] organizations probably have tools in the
[00:31:52] environment that have solutions now or
[00:31:54] add-ons or features that can be adapted.
[00:31:57] So let’s let’s investigate that. And I
[00:31:59] work a lot of times with organizations
[00:32:00] that once we have that estate, that
[00:32:02] scope, prioritization, the framework
[00:32:04] laid out of what we need. And and that
[00:32:05] sounds like a huge task and it is it is
[00:32:07] a big task, don’t get me wrong, but it’s
[00:32:09] not something that typically takes a
[00:32:10] year. You know, we’re talking, you know,
[00:32:12] a pretty short duration to get us to the
[00:32:14] point we can start te talking
[00:32:15] technology. But let’s align with a
[00:32:17] series of technologies. Look at what you
[00:32:19] have. Maybe you have an IG and a PAM
[00:32:21] tool that just needs adapted to this
[00:32:24] world. Maybe you don’t have anything and
[00:32:25] you are looking at a net new tool. But
[00:32:27] again, it needs to be the right fit for
[00:32:29] the right problem, the right series of
[00:32:31] prioritizations, the right framework.
[00:32:33] And if you can align all of that, your
[00:32:35] rate of success is going to be quite a
[00:32:37] bit larger. Because I’ve seen both sides
[00:32:39] of this fence. I’ve gone in where they
[00:32:40] started and said, “I bought the tool.
[00:32:42] Let’s make it happen.” And the rate of
[00:32:43] success is is typically pretty low. Or
[00:32:45] they resize the scope to make the tool
[00:32:47] and the project successful, but they’ve
[00:32:49] left so much out to make that happen.
[00:32:51] And the flip side is, you know, if you
[00:32:53] get the right, you know, the best fit
[00:32:55] solution for what you’re trying to go
[00:32:56] after in the best program. The last
[00:32:58] little bit I’ll say on that is we’re
[00:33:00] kind of entering a realm where because
[00:33:02] of the what I mentioned earlier with
[00:33:04] kind of the lack of skills and
[00:33:06] resources. And I think this is a bit of
[00:33:08] a timing problem because of how fast AI
[00:33:10] is moving and people are trying to learn
[00:33:12] and adapt. The workforce hasn’t
[00:33:14] completely upskilled to the level I
[00:33:16] think we need. But obviously
[00:33:18] organizations aren’t to the maturity
[00:33:19] level where I think that’s needed at
[00:33:21] this moment, but it’s growing. That
[00:33:22] inflection point is growing is don’t
[00:33:24] don’t be a poise as to using some kind
[00:33:27] of managed service at least for a time
[00:33:29] being right there. there are experts out
[00:33:31] there that can help you and maybe you do
[00:33:33] need to kind of source that for a bit to
[00:33:35] not just the strategy but you can you
[00:33:37] know once you get that plan and you want
[00:33:39] to execute it you know don’t hold back
[00:33:41] and say I’m ready to go but I don’t have
[00:33:43] the right people let me wait and hire
[00:33:45] the people that could take weeks months
[00:33:47] years to get the right people move as
[00:33:49] fast as you can do your due diligence
[00:33:51] vet whoever you’re going to use for sure
[00:33:53] but maybe maybe source it for a while
[00:33:55] there’s nothing wrong with bringing it
[00:33:57] back in house later when the timing is
[00:33:58] right but I I just want put that out
[00:34:00] there because I think some organizations
[00:34:01] are afraid of managed services and
[00:34:03] sourcing this. Don’t go to managed
[00:34:05] services if you’re just looking to do
[00:34:06] ticket counting, right? Opening a ticket
[00:34:08] and closing a support in this world. You
[00:34:10] need more than that. You need a
[00:34:12] strategic managed service and there’s a
[00:34:14] big difference. So, I just wanted to put
[00:34:15] that out there cuz if you’re in the
[00:34:16] starting point, these are all things to
[00:34:18] consider.
[00:34:18] >> No, absolutely. I think that was that
[00:34:20] was very thorough and thank you for
[00:34:22] this, you know, great insight. Um,
[00:34:24] moving on to, you know, an interesting
[00:34:26] twist here. You’ve talked about AI
[00:34:28] potentially helping with identity
[00:34:29] hygiene, analyzing access patterns,
[00:34:32] detecting anomalies. Could AI agents
[00:34:34] actually be a part of the solution to
[00:34:36] managing other AI agents or does that
[00:34:39] create some kind of recursive nightmare?
[00:34:41] >> I mentioned a couple times through this
[00:34:42] conversation, you know, about maybe an
[00:34:44] agent reporting to an agent and that is
[00:34:46] the world I think we’re going to we’re
[00:34:48] starting to head down and and will exist
[00:34:50] and we will be managing for some time.
[00:34:52] Agents will report and manage other
[00:34:54] agents. agents will watch other agents.
[00:34:56] There still needs to be a human on the
[00:34:57] hook or human in the loop at some level
[00:34:59] in that, you know, chain of custody or
[00:35:02] authority chain, right? However, that
[00:35:04] will that will happen. That that is
[00:35:06] happening and starting to happen. Now,
[00:35:08] it could potentially be a nightmare if
[00:35:10] we don’t have the right series of
[00:35:12] controls and frameworks around this. You
[00:35:13] know, we don’t want to have a manager
[00:35:16] agent spinning up and spending a 100
[00:35:18] agents, right? just because it needs to
[00:35:20] be a an intent and purpose-driven action
[00:35:23] with some sort of human in the loop to
[00:35:25] say here’s the threshold of what’s okay,
[00:35:27] right? If you need to spin up and spin
[00:35:29] down maybe something more ephemeral
[00:35:30] because a lot of tasks and you got a lot
[00:35:33] of work for a period of time and spin it
[00:35:34] back down. Sure, here’s the threshold.
[00:35:36] Allow that to happen. Bring it back. But
[00:35:38] if you don’t have those proper controls
[00:35:40] in place, you know, you could wind up
[00:35:42] with a a nightmare of an army of agents
[00:35:45] that you’re trying to get your hands
[00:35:46] around. And what would be very scary in
[00:35:49] my mind or concerning is uh if you look
[00:35:52] at what happens has happened with
[00:35:54] service accounts for example right some
[00:35:56] service accounts have been in
[00:35:57] environments for decades and we need to
[00:35:59] manage them we need to put them under
[00:36:00] privilege control or we need to do this
[00:36:02] but everyone’s afraid to change the
[00:36:04] password or maybe disable it if they
[00:36:06] don’t know if it’s being used because it
[00:36:08] could break something because we just
[00:36:09] don’t know. And if we get into that a
[00:36:12] decade from now I’m I’m sure we’re going
[00:36:14] to evolve into a whole another problem
[00:36:16] by then. Let’s just assume that over
[00:36:18] time, you know, we run into the same
[00:36:20] problem where we’ve got these 20,000
[00:36:23] agents in our environment cuz we let it
[00:36:25] go crazy. Are we going to be comfortable
[00:36:26] with pulling that back? Do do we put the
[00:36:29] if we didn’t put the right controls in
[00:36:30] place to control that? We probably
[00:36:32] didn’t put the right controls in place
[00:36:33] to see what these things are even doing.
[00:36:35] Are we going to break operations? Are we
[00:36:37] going to break the business by trying to
[00:36:38] pull that back? Like, we just don’t
[00:36:40] know. I mean, if you don’t have the
[00:36:42] right controls in place, you know, to
[00:36:43] have stopped that, you probably don’t
[00:36:45] have the right controls in place to have
[00:36:47] the answers to what are these things
[00:36:49] actually doing. So, there’s a little bit
[00:36:51] of concern there that I have that I’m
[00:36:52] going to walk into an organization one
[00:36:54] day and they’re like, you know, we got
[00:36:55] an army of agents and we don’t know what
[00:36:57] they’re doing. It’s like, well, that’s
[00:36:59] the bigger problem, right? So, so yeah,
[00:37:01] the number isn’t necessarily the scary
[00:37:04] part. It’s the number of agents that you
[00:37:06] don’t know what are doing is the scary
[00:37:08] part. Well, you know, for for the sake
[00:37:10] of this question and if we have an
[00:37:11] outlook here and if you’re getting
[00:37:13] speculative, let’s say it’s 2031 and you
[00:37:16] are actually walking into a large
[00:37:18] enterprise as a consultant, what does
[00:37:21] identity management look like in a world
[00:37:23] where AI agents outnumber, you know,
[00:37:25] your formula of 1 to 10 to 100 to one?
[00:37:29] So I think if if we’re asking what what
[00:37:31] it looks like realistically, I think
[00:37:34] it’s going to be kind of that mid-grade
[00:37:36] of maturity like we see with humans,
[00:37:38] right? We’re going to probably have good
[00:37:42] control around the most critical thing
[00:37:44] and we’re going to probably have
[00:37:46] hopefully a insider threat adoption
[00:37:49] program, you know, for these agents.
[00:37:52] We’re doing actual insider threat
[00:37:54] controls for the agents. We got proper
[00:37:56] governance. They’re tagged with an
[00:37:57] owner. we’re doing at a station, all the
[00:37:59] above, right? On our critical stuff.
[00:38:01] However, on the other side of the fence
[00:38:04] on things that we probably haven’t
[00:38:05] deemed critical, we’re going to have a
[00:38:07] mixed bag. We’re going to have agents
[00:38:09] out there that we really don’t watch. We
[00:38:11] don’t monitor appropriately. I’m sure
[00:38:13] we’ll get logs and put them in a sim,
[00:38:14] but again, that’s more noise and we’ll
[00:38:16] probably have agents there to sift
[00:38:18] through the noise. So, it’s kind of this
[00:38:19] like cycle of agent to an agent problem.
[00:38:22] However, we’ll have a a PAM solution or
[00:38:25] an evolved version of a PAM solution and
[00:38:27] an evolved version of an IGA solution um
[00:38:30] in there to to help us manage this
[00:38:32] population. And the depth of management
[00:38:34] and control again is going to be a mixed
[00:38:36] bag of maturity. We’re going to have at
[00:38:38] a station that makes sense in some
[00:38:41] regards and other regards not so much.
[00:38:43] We’re going to have those agents that
[00:38:45] were just simply asking who owns this
[00:38:47] thing because we never tagged it
[00:38:48] appropriately. We’re going to have these
[00:38:49] like problems, but we’re going to at
[00:38:51] least see maturity, I think, over what’s
[00:38:54] critical. And the what’s critical, I
[00:38:56] think organizations are trying to answer
[00:38:58] now, but if we look ahead a few years,
[00:39:00] they’re going to scope down to that. Do
[00:39:02] I think that’s the right thing to do is
[00:39:04] a different question because agents can
[00:39:06] allude to the critical based on the
[00:39:08] non-critical. If I got access to so much
[00:39:10] data and so many files, I guarantee you
[00:39:13] no organization has tagged everything
[00:39:14] appropriately as to what’s a critical
[00:39:16] file, what’s a critical bit of data,
[00:39:18] what’s sensitive, what’s not, probably
[00:39:19] have done a good job, but I I doubt
[00:39:21] they’ve gotten everything. These agents
[00:39:23] will be out there reading everything and
[00:39:25] learning everything they can if you
[00:39:27] allow them. Again, putting the right
[00:39:28] framework and control around that is is
[00:39:31] important. But going ahead to another 5
[00:39:34] years, 6 years from now, that’s the
[00:39:36] problems that are going to exist. And I
[00:39:38] think we need to have the right controls
[00:39:40] in place to structure the framework in
[00:39:43] which these agents live. Just like we
[00:39:45] have HR rules and policies that try to
[00:39:47] put control and rigor around humans, we
[00:39:49] need something very similar for these
[00:39:51] agents and these non-humans. So I would
[00:39:53] love to say it’s going to be a utopian
[00:39:55] view that we’re going to have this all
[00:39:56] under control, but the reality is is
[00:39:58] agents are going to be managing agents
[00:40:00] and controlling agents. Humans will be
[00:40:02] on the loop. There’ll be different
[00:40:03] levels of maturity and just like we see
[00:40:05] today, there’s going to be silos, right?
[00:40:07] One department’s going to manage it
[00:40:08] better than another department. They’re
[00:40:10] not going to necessarily always talk to
[00:40:11] each other and security is going to be
[00:40:13] there trying to be the intermediary of
[00:40:15] what should happen and shouldn’t happen
[00:40:16] and there’ll be push back from business
[00:40:18] because all this exists today on the
[00:40:20] human side. I don’t see that changing on
[00:40:23] the non-human side. I just see it
[00:40:25] becoming a larger population and a
[00:40:28] larger vector that we need to consider
[00:40:31] and a faster moving vector. At that
[00:40:33] point, the velocity of of these issues
[00:40:35] will pop up quicker and quicker and
[00:40:36] we’re not going to be able to stay on
[00:40:38] top of it. But, you know, not it’s not
[00:40:40] all doom and gloom and it’s not all, you
[00:40:42] know, roses and sunshine. It’s it’s
[00:40:44] somewhere in the middle. And a lot of
[00:40:46] security folks too, they they like to
[00:40:47] push the narrative and rightfully so
[00:40:49] that reduce risk, reduce risk, reduce
[00:40:51] risk, right? But the reality is, if you
[00:40:54] look over time, we’re actually never
[00:40:56] reducing risk. What we’re doing is
[00:40:57] keeping the risk needle about the same.
[00:40:59] We’re fighting against the the push and
[00:41:01] the flood of the the risk needle moving
[00:41:03] really far to the right. Because as soon
[00:41:05] as you take that needle and you reduce
[00:41:07] risk by closing something or, you know,
[00:41:09] controlling something and you think the
[00:41:11] needle’s going like this, the overall
[00:41:12] needle is actually probably staying
[00:41:14] where it’s at because there’s another
[00:41:15] risk that’s right behind it, another
[00:41:17] risk that’s pushing it back over. So
[00:41:19] you’re it’s a constant battle to keep
[00:41:21] that needle kind of fluctuating in the
[00:41:23] realm of okay, in the realm of in the
[00:41:25] middle. There’s no organization that is
[00:41:27] probably completely to the right or
[00:41:29] completely to the left if they’re they
[00:41:31] have a good program. They’re probably
[00:41:32] stuck in the middle and that needle’s
[00:41:34] like fluctuating little by little almost
[00:41:36] like a like a hair tick. So what’s
[00:41:38] happening is, you know, you’re closing
[00:41:39] those risks and you want to give
[00:41:41] executives the idea that that needle’s
[00:41:43] going all the way down to the green. And
[00:41:44] maybe it is for that one little risk
[00:41:47] that you check the box on, but your
[00:41:48] overall risk isn’t actually moving. It’s
[00:41:51] probably staying the same. Your your job
[00:41:53] in security is to try to fight against
[00:41:55] that wave. And as you’re fighting
[00:41:56] against that wave, you’re closing stuff.
[00:41:58] It’s probably staying relatively
[00:42:00] straight. It’s probably staying right
[00:42:01] there. That’s not necessarily a bad
[00:42:03] thing because if you stop fighting, it
[00:42:05] would push to the right. That’s what
[00:42:07] you’re fighting against is keeping it
[00:42:08] from going to the right, not necessarily
[00:42:10] reducing it to the green. Obviously,
[00:42:12] there’s a little bit of philosophy
[00:42:14] behind the rationale for that and I
[00:42:16] would love a discussion on on just that
[00:42:18] particular topic and there’s evidence
[00:42:20] and and rationale for all of that.
[00:42:22] However, that’s what it boils down to,
[00:42:23] right? We’re going to be in this realm
[00:42:25] of fighting against the wave of risks
[00:42:28] and threats and we’re going to find that
[00:42:31] happy medium. I say happy probably more
[00:42:33] sarcastically but that that medium of
[00:42:36] where we’re tr trying trying to fight
[00:42:37] against the push to the right when it
[00:42:39] comes to to the risk and the threats
[00:42:42] >> and if you look at the regulation on the
[00:42:44] horizon now we are seeing you know
[00:42:45] there’s AI act in place potential US
[00:42:48] frameworks coming you know around AI
[00:42:51] from your work in highly regulated
[00:42:53] industries like healthcare and finance
[00:42:55] where do you think identity governance
[00:42:56] requirements for AI agents are headed
[00:42:59] one and should enterprises get ahead of
[00:43:01] regulation or is it just too early to
[00:43:03] tell what’s coming next?
[00:43:04] >> I don’t think organizations should wait
[00:43:06] on regulations, right? I do think
[00:43:08] regulations are are starting to to pop
[00:43:10] up and there are things happening. I
[00:43:12] think there was a like the AI act in the
[00:43:14] UK that that that passed. I think there
[00:43:17] was an executive order of things to do
[00:43:19] with the federal government when it came
[00:43:20] to things like postquantum and and its
[00:43:22] involvement with AI and all of that.
[00:43:24] There’s good guidelines. There’s good
[00:43:26] best practices out there. My first
[00:43:28] recommendation or or knee-jerk reaction
[00:43:30] is don’t don’t wait on those things. Do
[00:43:32] what you know is best practice. I mean,
[00:43:34] we kind of know that already for from
[00:43:36] the human side. Let’s figure out how we
[00:43:38] can adapt some of that. Now, when
[00:43:40] regulations do come down and they are
[00:43:42] coming down, treat those regulations and
[00:43:44] those and what you’re being told to do
[00:43:47] again just like we do with the human
[00:43:49] side. Hopefully, you do this as the
[00:43:51] starting point, right? Not the finish
[00:43:52] line. Just because you meet the
[00:43:54] requirement doesn’t mean stop. You need
[00:43:56] to go beyond that. What does beyond that
[00:43:58] look like? That’s that’s the question we
[00:44:00] need to ask ourselves and develop that
[00:44:03] strategy around. Right? It’s we got to
[00:44:05] meet the regulation. Sure. We got to
[00:44:06] check that box. Sure. But compliance and
[00:44:08] regulation doesn’t equal secure. Just
[00:44:10] because you’re compliant and just
[00:44:12] because you you follow regulations does
[00:44:14] not mean you are secure. It just means
[00:44:16] that you’re doing the best of your
[00:44:18] ability to do what is being asked of you
[00:44:20] to meet that bare minimum baseline. Now,
[00:44:22] is that better than not doing that?
[00:44:24] Absolutely. you’re probably, you know,
[00:44:26] more secure than if you didn’t. So, so
[00:44:28] don’t get me wrong there. But, however,
[00:44:30] you need to continually push uphill as
[00:44:33] much as you can. Uh, if you look at
[00:44:34] health care and and and the big issue
[00:44:37] with privacy, especially in the United
[00:44:38] States, when it comes to healthcare,
[00:44:40] letting these AI agents look at all your
[00:44:42] health care data is kind of an
[00:44:44] interesting thought, right? You know,
[00:44:46] we’re we’re seeing right now where
[00:44:48] they’re using them to analyze MRIs and
[00:44:51] look at images and and good things are
[00:44:53] coming out of that, right? where they’re
[00:44:55] helping diagnose and find things that
[00:44:56] maybe doctors missed. Good stuff. So,
[00:44:59] I’m not saying don’t do those things,
[00:45:01] but when we look at the controls and the
[00:45:03] regulations of, you know, what thou
[00:45:05] shall and shall do, shall not do with
[00:45:08] with AI in these realms, you know, you
[00:45:10] have to ask yourself, well, is that good
[00:45:12] enough? Is that is that the right thing?
[00:45:14] And if you’re not asking yourselves
[00:45:15] that, I think there might be simply a
[00:45:17] gap in your understanding of the
[00:45:19] effectiveness of compliance and
[00:45:21] regulations. Now, on the flip side, when
[00:45:24] we look at organizations that have a
[00:45:26] great I mean, just an impeccable,
[00:45:30] you know, they got they got GRC and
[00:45:32] they’re following things and they’re
[00:45:33] they’re checking the boxes, you know,
[00:45:35] they don’t they don’t ever have the
[00:45:36] regulator come down and slap them with
[00:45:38] any fines, you know, they’re always
[00:45:39] getting passing scores, you know, I do
[00:45:42] think that is awesome to see. I love to
[00:45:44] see that. But that does not mean that
[00:45:46] they’re not susceptible to a breach, to
[00:45:50] a risk, to an issue. those types of
[00:45:52] organizations I think where most of
[00:45:54] their issues are going to be because
[00:45:56] they do have so many uh proper controls
[00:45:59] typically because they don’t they don’t
[00:46:01] stop there. If you have an impeccable,
[00:46:03] you know, governance program, GRC
[00:46:05] program, risk program, you’re probably
[00:46:08] already thinking kind of beyond that
[00:46:10] into that next level because you’re
[00:46:11] trying to stay ahead of the regulator
[00:46:13] more than likely. But don’t
[00:46:15] underestimate the power of a mistake. A
[00:46:18] human can make a mistake, but an agent
[00:46:20] can make a mistake. They’re not perfect
[00:46:22] and they can hand data off. They can do
[00:46:24] things with your data. So, it comes back
[00:46:27] to those general basic observability,
[00:46:29] the intent of why it’s doing it, the
[00:46:31] reporting structure of who’s
[00:46:32] accountable. Let’s just make sure we’re
[00:46:34] we’re not losing that in the mix either
[00:46:37] because sometimes these regulations and
[00:46:39] compliance and controls move us in a
[00:46:41] direction where we kind of say those
[00:46:43] basics are we like to say the term
[00:46:46] foundational but then what that does in
[00:46:48] a lot of organizations means we kind of
[00:46:50] just let them stay static. We put them
[00:46:52] in and we get a checkbox and then we
[00:46:54] just let them stay static. We don’t
[00:46:55] evolve those foundational things because
[00:46:57] we’re trying to move to something more
[00:46:59] beyond that. So, so don’t lose the
[00:47:00] foundational capabilities and the
[00:47:02] evolution of those capabilities in your
[00:47:04] I guess desire to fulfill what the
[00:47:06] regulator is asking you to do.
[00:47:08] >> So, David, your book on aentic AI is
[00:47:09] coming out soon and you know um I’m
[00:47:12] super excited to be able to get access
[00:47:14] to it too. But without spoiling it,
[00:47:17] what’s the one insight or framework you
[00:47:19] are most excited for people to wrestle
[00:47:21] with?
[00:47:21] >> So, there’s a few things we cover in the
[00:47:23] book. I think the thing I’m most excited
[00:47:25] about in particular and and and I like
[00:47:28] to have what I call healthy
[00:47:29] confrontation sometimes is is good,
[00:47:31] right? I like it when people look at a
[00:47:33] framework or look at a structure or look
[00:47:35] at an idea and say that’s good but or
[00:47:37] you know this could be better with like
[00:47:39] we we learn from each other. We grow
[00:47:41] from each other. So there’s no intention
[00:47:43] and or no false belief that what I put
[00:47:45] in the book is going to be an answer for
[00:47:47] everybody or it’s probably a point in
[00:47:49] time where I’ll have to do revisions and
[00:47:51] keep up with the market more than
[00:47:52] likely. But if you look at the
[00:47:54] frameworks, if you look at the ideas and
[00:47:56] the concepts that are in there, it
[00:47:57] really comes down to this level of
[00:48:01] maturity and logical check gates of
[00:48:04] intent. That is the most important thing
[00:48:06] to me. It’s questioning and putting
[00:48:08] something in place as to why this task
[00:48:12] just happened. We’re moving past the era
[00:48:14] of just verifying who you are at loon.
[00:48:17] We get into this realm of agents. We
[00:48:19] need to verify not only who the
[00:48:21] individual is that initiated the
[00:48:23] request, who the agent is that’s doing
[00:48:25] the task, but why that particular task
[00:48:28] was performed. You know, if there are
[00:48:30] five tasks that could be performed to
[00:48:32] give you the same output, you better
[00:48:34] believe that the agent’s probably going
[00:48:36] to not do the same task each time to
[00:48:38] give you that output. It’s going to try
[00:48:39] to change it up because it can and
[00:48:41] because we can’t control how it produces
[00:48:43] the work. So with that being said,
[00:48:45] questioning the intent of every task and
[00:48:48] every action and creating a framework in
[00:48:50] which validation of that intent to the
[00:48:52] request is I think ultimately the most
[00:48:55] critical thing that we could think of
[00:48:57] and do. Now that’s covered in the book
[00:48:59] um in in a little more detail. You know,
[00:49:01] I don’t want to go into too much depth.
[00:49:03] If they anybody wants to to read through
[00:49:05] the book and you know push back on that,
[00:49:07] I’d be happy to have that discussion.
[00:49:09] But I think that’s the thing I’m the
[00:49:10] most excited about because it’s a
[00:49:11] different concept, right? We we look at
[00:49:13] users and the tasks and what they do
[00:49:16] today and we simply look at it in a very
[00:49:19] kind of black and white scenario, right?
[00:49:21] You should not have access to do that.
[00:49:22] So don’t do that. You know, when we say
[00:49:24] why did you do that, what we’re really
[00:49:26] saying is why did you have the access to
[00:49:28] do that? The difference with an agent is
[00:49:29] it probably rightfully so needed the
[00:49:32] access to do that request. That’s not
[00:49:34] the right question. The question is why
[00:49:36] did you do that task that way? Like why
[00:49:38] did that happen? because that’s where
[00:49:41] that impersonation, that’s where those
[00:49:43] tricks can kind of come into play from a
[00:49:45] bad actor. But also, that’s where the
[00:49:46] agent can make the most mistakes and
[00:49:48] hallucinate the the most is if it starts
[00:49:50] to think all of a sudden that, you know,
[00:49:53] you’re asking me something a little bit
[00:49:54] different, even though you ask me the
[00:49:56] same thing every week, I’m going to try
[00:49:57] it a different way and I can’t find the
[00:49:59] answer. So now, let me make up an
[00:50:00] answer. And, you know, you’re going to
[00:50:02] believe it because the last nine times
[00:50:03] you asked me, it was a solid good
[00:50:05] answer. But this one time, I’m going to
[00:50:07] hallucinate and give you a different
[00:50:08] answer that’s wrong. and you’re just
[00:50:10] going to falsely take it and probably
[00:50:11] have a bigger impact.
[00:50:12] >> For IT directors and CTOs who are just
[00:50:15] starting this AI identity transformation
[00:50:17] journey, what’s one harder lesson you
[00:50:19] wish you could go back and tell yourself
[00:50:22] or perhaps them?
[00:50:23] >> I think one of the hard lessons I had to
[00:50:25] learn is that there isn’t one there
[00:50:27] isn’t one fix for everybody, right? as a
[00:50:30] a field CTO uh here at Zalant and and as
[00:50:33] an adviser for many years and as a
[00:50:36] practitioner and a leader uh in in cyber
[00:50:39] for the last 20 years you know I
[00:50:42] initially started off with there’s one
[00:50:44] right way to do everything right um you
[00:50:46] know we want to protect you know
[00:50:48] credentials there’s only one way to
[00:50:49] protect credentials we want to do
[00:50:51] governance there’s only one way to do
[00:50:53] governance we want to the reality is is
[00:50:54] there isn’t right I I the best the best
[00:50:57] practices that are out there does not
[00:50:59] mean that they’re the best fit for your
[00:51:00] organization. That’s just plain and
[00:51:02] simple. There could be a reason why that
[00:51:05] is. It could be culturally. It could be
[00:51:07] on a technical level. It could be on a
[00:51:08] maturity scale. It’s an endless number
[00:51:11] of things. Those frameworks, those best
[00:51:14] practices are are good for reference and
[00:51:16] they’re good for directional setting.
[00:51:18] Look at the outcomes that it’s asking
[00:51:20] you, not not the process. What’s the
[00:51:22] outcome of that best practice? What’s
[00:51:24] the outcome of that framework? And if
[00:51:27] that outcome is uh something that we
[00:51:29] need that we want that we have to have
[00:51:32] that we should do then you know let’s
[00:51:35] look at multiple ways to get there and
[00:51:37] what’s going to be the best fit for us.
[00:51:39] Don’t just do a best practice the way
[00:51:41] that it’s lined up because it says it’s
[00:51:43] a best practice. Look at the outcome of
[00:51:45] that. What’s the purpose? And then ask
[00:51:47] yourself what’s the right way to do
[00:51:49] this. Is it is it taking bits and pieces
[00:51:51] of maybe NIST and bits of pieces of you
[00:51:54] know something from CISA? maybe bits and
[00:51:55] pieces of just your past experience and
[00:51:57] putting these things together. It’s
[00:51:59] always good to say we align with a
[00:52:01] framework or we align with a series of
[00:52:03] guidelines, but don’t make that the
[00:52:05] false impression that you’re doing it
[00:52:07] the way that they say to do it cuz that
[00:52:09] doesn’t mean it’s the right way for you.
[00:52:11] That was a hard lesson for me to learn
[00:52:13] and I see organizations and I see
[00:52:15] leaders going down that path all the
[00:52:16] time. Well, NIST says this, yeah, what’s
[00:52:18] the purpose and the outcome of saying
[00:52:20] that? Let’s strive for that. Let’s not
[00:52:23] necessarily try to shoehorn in a process
[00:52:25] that isn’t going to allow us to obtain
[00:52:27] that because it doesn’t work in our
[00:52:29] environment. We have to find what’s the
[00:52:30] best fit for our environment that gives
[00:52:32] us the valued outcome that we’re
[00:52:34] striving for. We have to justify the
[00:52:36] purpose of that outcome. And I guarantee
[00:52:38] you with that methodology, your rate of
[00:52:41] success will be much greater than trying
[00:52:43] to shoehorn in something that simply is
[00:52:45] like oil and water as far as a process
[00:52:47] to your environment. Doesn’t mean your
[00:52:49] environment shouldn’t evolve. There may
[00:52:50] be valid use cases where that best
[00:52:52] practice is laid out a certain way and
[00:52:54] you have to ask yourselves, should we
[00:52:56] change to be able to make this work.
[00:52:58] Sometimes the answer is yes. However, go
[00:53:00] through that exercise and ask yourself
[00:53:02] that before you just simply adopt it.
[00:53:04] >> Well, David, thank you so much. This has
[00:53:05] been a genuinely fascinating
[00:53:07] conversation.
[00:53:08] >> Yeah. Thank you.
[00:53:11] [music]