Anyhow, I'm Matt Berzinski. I'm here. I'm the field CTO for Ping Identity, responsible for all of EMEA. I know I have this really weird American accent, but I have been living here for seven and a half years now. And I'm really here. I'm happy to talk to you guys about some of the other things that are impacting the market today, right? Because we've talked a lot about AI, but there's other things out there to do. So I want to talk to you about bridging the trust gap and how you deliver trust for all identities.
And just some of those things that you need to think about when we're talking about the human side of identity. Remember back in the day when we all focused on how do you identify humans and not AI? We need to think about this again. 86% of companies experienced an identity attack last year.
Identity, human identity, is becoming the attack vector. This is what we need to continue to remind ourselves. Another interesting stat brought out by the FBI in America. Over 300 American companies last year hired North Korean spies. Unknowingly hired North Korean operatives. The interesting thing was they weren't there to exfiltrate data or steal anything or do anything nefarious. They were actually just there to make money to fund some of their other programs, some of their hacking programs, some of their rocket programs. But 300 companies hired people that they didn't really want to hire.
And another analyst, I won't say the name, has basically said by 2028, one in four applications will be fake. So these are AI generated applications, humans, bots pretending to be humans. That'll be fake to try to get in and infiltrate organizations.
As I said, identity is becoming the new attack surface. Actually, I would say it has always been the new attack surface, but we're seeing it exploited more and more. And it's really, again, still on the human side. This clicker.
Anyhow, but the trust landscape is evolving. Like, what's going on here?
Well, we have decentralized access. People are accessing things from all different places. SAS applications, clouds, different things along those lines. You have constant and evolving threats.
You know, anybody now can take a cloud agent or a chat GPT agent and launch a massive breach. We had one person alone in Mexico who exfiltrated 25 million records in an hour. Just one person doing that with a cloud agent. So having AI out there for the attackers is bringing on a whole new set of evolving threats. Non-human identities, of course. We're talking about AI. We're talking about non-human identities in a scale that we've never seen before.
Like, the low estimates say it'll be 80 to 1 non-human identities ratio. Non-humans to one identity. I've seen other people say there'll be 300 non-human identities to every one human identity. So the scale is astronomical.
But yet, all of our employees and all of our customers demand a simple, frictionless experience. So we have to still deliver that. So what's happening is you have all these different things out there. And the criminals and the fraudsters, what they're doing is they're attacking what I like to call the trust gaps. And the interesting thing is when you think about fraudsters and you think about what they do, they're kind of like water. And what do I mean by that? When you think about a water, it runs downhill and it takes the path of least resistance to find its way to wherever it wants to go.
And hackers are doing the same thing. If you've secured your front door with MFA and all these great things that we tell you to do that we've talked about as an industry forever, they find another way in. Maybe it's the side door, maybe it's the back door. And so we have to make sure that we're thinking about all the different attack vectors and how we make these secure. And so this comment here from Donald Rumsfeld really sums up where we are today in the identity and the cybersecurity space. Donald Rumsfeld was a brilliant war tactician and strategist.
And what he basically said is there's threats that we know about that we have a solution for. There's threats that we know about that we don't have a solution for. And then there's things that are coming that we don't even know and don't know how to have a solution for it. And so what it really does is it kind of turns into this graph of secure the known but prepare for the unknown. And what we kind of look at is on the left hand side, those are the threats that we know that we've adopted solutions for.
But what's in the middle are threats that we have that we haven't solved yet, but there is technology available to solve. Then you have the disruption on the right hand side. Really interesting. I put MFA in there as something everybody's adopted, but we know that's not true. We know there's people out there still running just passwords. But then when you look at the Delta, there's all this technology to help you solve those known problems that we haven't deployed yet. But I'm not up here saying just go throw a whole bunch of tech to solve these problems.
We need to sit down and think with every organization and every individual company, what is going to give them the most bang for their buck? What's going to give them the most additional security of these things to close that Delta so that we can prepare for the disruption that's coming?
You know, an identity for AI and AI is definitely going to be a disruption. So this is what I talk about with that trust gap.
And, you know, the classic trust gap scenario is scattered spider. Right.
I mean, we heard about this a lot last year. Anybody in the room drive a Jaguar Land Rover? Anybody? No. Is that because you wanted to buy one last fall, but you couldn't because they didn't make cars for seven weeks? Like and I joke.
I mean, it's a funny joke. But think about what happened with Jaguar Land Rover. Right. They were losing 50 million pounds a day that they could not produce cars and they could not produce cars for seven weeks. I'm not really good at math, but seven times seven times 50 million is a huge number of revenue loss. Right. So that's a huge impact to Jaguar Land Rover, JLR. And we always talk about, hey, you get breached.
It's, you know, reputational damage. Well, that's real dollars. But it got worse than that. It extended out to their supply chain because they weren't making cars. So they weren't buying supplies. They weren't buying the parts from their supply chain. And then all of a sudden, all these suppliers said, we're going to have to lay off tens of thousands of employees, which the UK government said, whoa, hold on, hold on.
Hey, I don't want that many employees going on the dole to collect unemployment. I don't have the money to support that. And you're going to slow down the economy. So the UK government backed a multi-billion pound loan to bail JLR out so they could pay their suppliers, so they could keep their employees employed so that when they could turn back on the factories, they had cars. So this one attack, the scattered spider attack, actually caused a national financial crisis in the UK alone that involved government intervention. So that's how dangerous these attacks can be.
But why does attacking the help desk work? Like, why does it work?
Well, the answer is in the name, right? It's the help desk. They're there to help you. They're there to get you back online as fast as possible. They're rated, their KPIs is how many tickets do you close and how quickly do you close them, especially the outsourced ones. So this is why it works, because these are people who don't know the culture, don't know what's going on. Scattered spider goes out, uses AI to do enough social engineering and scraping things together to be feasible, feasibly be that person. And then the help desk person just resets the password.
I was talking to a CISO at an airport once and we were having a whole conversation about this. And he just said in passing at the end of it, at the end of the meeting as we were walking out, he goes, maybe if they called it the security desk, we wouldn't have such a big problem. Right. And I looked at him.
He goes, well, for me to get access to go out to where the planes are, I have to go to the security desk to get a badge. And I can tell you they are anything but helpful. They carry guns. Right. So maybe that would work. But if I asked an AI agent what they would say, the solution is just get rid of the help desk because agents are easy. They're lazy. So you have a problem at the help desk. Just get rid of it. But we can't do that. Right. We can't do that. Help desk are essential to our business. They're essential to running our organizations. So this brings up another trust gap.
Can you identify every user in your organization? And what about your partners? Right. These are these are issues that we need to still think about. Like the world is talking about AI, but we still haven't solved this problem for all of our end users, all of our partners, everybody that's in your identity directory. So where do we need to do? We need to get from implicit trust, which we have today. How many people think we do a really good job at implicit trust of authenticating and knowing who's there on the other end of the device? How many people here use password managers on their phone?
Great. That's amazing. So you've just taken your security to having your phone in a six digit pin. That's really all you got. Because right now what we do with implicit trust is we say this device is owned by this user. And if they authenticate from that device, I'm pretty sure it's that person. But if you drop your phone and your pin is your birthday and I know your birthday, I can be you. I can go to your bank account and I can log in. But it's good because we all look at our phones. People are doing it right now.
You know, no offense, but we all look at our phones all the time. So we're pretty aware when we lose our phone. So it's a good security thing. But what we need to do is we need to get to explicit trust where we can jump out of that phone, reach out and touch that person and say, I know this is the person who's trying to do access, trying to get into my bank account, trying to get into my work, trying to do anything online. We need to touch that person. We need to move away from the device. We need to know explicitly that you are the right person before we go and do anything.
And this is what we call verified trust. And what this does is this brings together three key elements in security. Identity security, which we've all been doing for a very, very long time. We've added identity fraud capabilities in there to determine does this look like it's coming from a legitimate source? Is it originating right? But we've also added identity assurance.
Like, how do I do identity verification? How do I make sure the person who is trying to do that is the right person? And we all know about document verification and selfies and things along those lines. You need to add that to the beginning of a lot of your processes. Right. We definitely need to add that to the beginning of a lot of processes. So once I verify that person, then I can issue them a passkey or something along those lines. So there's no passwords to phish. And then they can go about their business. And we know that it's them.
And if they ever come to do anything with their profile or anything along those lines, I can go back and re-verify who they are. And so where does this work? I've been talking for a little bit. I got to ask you guys a question. How many people here liked COVID? I did. I love COVID. You know why I love COVID? I could interview anywhere in the world without pants on. It was amazing. Sit down in front of your laptop, interview, get a job. Don't even have to leave your bedroom. Right. It's amazing.
Actually, it's really true. We did a really great job in the industry of having business continuity, allowing employers to be able to continue to hire people and onboard people remotely so they could continue doing their job and continuing to output things. And it was amazing. Technology solved a lot of problems. The thing that we forgot is that no one had to go to an office to get onboarded. And I know when I visit all of my customers, 90 percent of them ask me for an ID when I walk into their building, to validate that I'm allowed to be there, that I'm the person that said they was coming.
Well, when you're not going to a building to interview and you're not going to a building to pick up your laptop and it's all being shipped to you, no one's checking anybody's ID. That's how we got 300 companies unknowingly hiring North Korean spies. And now that we have gone to this work from anywhere type of mentality, you're going to continue to have those capabilities. So what we need to do is when you have somebody coming on board, you need to be able to verify them. Take a selfie. Do a document check. Enroll that person.
Give them a credential that has their biometric in it or store it in a way that's privacy preserving. That's GDPR compliant. It's not PII in a database. So that every time they come back for the interview, every time when they show up or when the laptop gets shipped to them to start working, they have to verify that biometric that you verified against a known identity document. And that way you know that you have a verified candidate and a verified person. The other place that works is on the help desk. And this is where you get scattered spider, right?
You go through and you have that verification process in the middle. The other thing that's great about this is verified peer and we're working on a solution where you can type in the app.
Hey, did you just ask me to do something? And I can look at my app and verify that it's me with my face.
Yes, I did. Or no, I didn't. And we don't have to worry about being that poor guy in Hong Kong who was the only person on a Zoom call because three deep fakes of the CEO, the CEO and the CFO asked them to transfer 25 million dollars to some dodgy account. He could have verified that in a different channel. So verification methods have different strengths and they can vary on how you do it. We use devices today. You have context. Where are you coming from? Is this what you normally do? You can leverage data. What do we know about you? Ask you questions. And of course, biometrics.
And all of these can be used in conjunction with each other or the right tool for the right job at the right place. That's really what's important when we talk about security is having choices and options for people's preferences and for what's going on around them. But trust also requires relationship and context. Like I have to know, is somebody doing something on behalf of somebody at the right time? Right. The right time of the month in the right organization, the right time of the year, these things that we want to do.
Because, you know, people generally don't use 80 percent of their entitlements in a workforce. But maybe once a year they have to use one of those entitlements. But maybe that's in May and now somebody is trying to do that in December. Maybe that's a red flag. And that relationship in that context is really important.
So, couldn't get too far into a presentation without talking about AI. Have to do it. The help desk is transitioning to AI. So this brings up a question. My favorite question. Can you trust an AI agent as much as you trust humans? Who here trusts an AI agent more than a human? Who here trusts a human more than an AI agent? Okay.
See, it's really funny because when I asked that question six weeks ago, it was 50-50. Now it's everybody trusts human more than AI. So I think the industry has done a really good job of scaring us of what AI can do and how bad AI is. So I don't have to go through this slide of, hey, you can bribe one. You can trick it. You can do all these different things to make it do bad things. We all know it can. So we need to put enforcement around it. And so if you think about Scattered Spider and attacking the help desk as this next vector, now I'm going to put AI in there.
And we all just said we don't trust AI agents. We're in a world of hurt, aren't we?
Like, that's not going to be good. So when we're talking to organizations today, this is how they want to deploy their help desk assistants. Right. Here's my help desk assistant. And it's connected to all these things in the back end because it might need them. That's awesome, right? Right? No. Because this allows you to actually just have prompt injections come in and you can trick that agent into giving you information that you need with it not even knowing who you are. And that's a problem.
So the way we need to deploy help desk assistants, and you've got to love my great graphics work here, but you could have access to all these systems, but you don't. The agent doesn't. Why? Because it's not doing anything right now. It's just sitting there and it doesn't know who's talking to it. And somebody shows up and starts asking it for stuff and it doesn't know who who's doing it. So it doesn't get access to those systems. It just sits there. And this is what zero trust looks like in an agentic world. Right.
Now, what do you do? Well, the agent triggers a verified trust authentication. I go back to the human and I say, who are you? Are you really allowed to be here? And you do it in a way that I absolutely know who you are. Because to me, the scariest thing about AI agents is we're focused on securing AI agents. We're forgetting to secure the people. And if you give the wrong people the right access to the right agent, they can exfiltrate data in seconds, not hours, not days, seconds. So you have to know who that person is.
And once you absolutely know who that person is, you can give that agent just time access to do one thing for that person based on the intent that we just heard about. Change my password. Register a new device for me. Do whatever it is you came to do. But only access for that one thing. Just in time. Ethereal. One task access. So AI agents offer great opportunities, right? They definitely do. We all know that. Another one that you guys should be thinking about is it's estimated that the agentic commerce market is going to be five to seven trillion dollars by 2030. And that's an amazing number.
That's the third largest GDP in the world, if you think about it that way. But what that also means is that there's amazing opportunities for organizations to ride that agentic wave and make a lot of money. There's also amazing threats that if organizations don't understand how to work through the agentic channel, they will go the same way as those high street stores that didn't go to the web went. They will be gone. We will no longer see them. So we need to start preparing for that. But you know what? Enough about AI. This whole conference is about AI.
Let's go back to like identity and all that stuff. Five questions that you guys should think about that I'm going to leave you with.
OK, just think about these as you go throughout your day and as you go back to your organizations, things you should ask and do you have questions? Can identity and trust react at the speed of AI? How are we going to do that? How are we going to use agents to look at all that data, synthesize it out and deliver answers and keep up with what's going on? We see this already happening in socks, right? So think about that. Will the clicker work? There we go. What is the boundary between performance and safety with AI?
A lot of people have a lot of thoughts on that, but you have to give AI identities and you have to make sure you're delegating access and consent to that agent. That's really important.
OK, a lot of people talk about that. Come to our booth. Tell you more about that. The question I want you all to ask, this was the number one question that came out of the last time I gave this presentation at a different conference. What if the bad guys are already on the inside? Go ask your CISO that or if you're a CISO, go ask your team that. What are we going to do?
At Ping, we re-onboarded everybody. Only took 90 seconds to re-onboard people per person. Now that's after you find your passport, of course. But once you find your passport, it only takes 90 seconds to go through that. So think about that. Re-onboard people. Verify their identities. Make sure they're the right people. We had one company, a customer of ours, who went through this process and before that, they had eight people that before they even tried the process just sent in their resignation. So think about what if the bad guys are already on the inside?
How much can you trust with authentication alone? Authentication is not the end game for identity anymore. It used to be. We go through all these things. We authenticate you. We give you a token and we stepped out the door and we said, bye-bye. Go play with your token. You're safe. Now authentication is just part of that context to make that decision at transaction time, what we like to call runtime identity. How do you make sure that the authentication was done in a way that I can trust this transaction? The session hasn't been hijacked and everything's happening in the right way.
And then the last question, beyond the wallet, what could you do with digital credentials? Right? I remember this conference two years ago was all about digital credentials and wallets.
Last year, it was all about digital credentials and wallets and AI residing in digital credentials. This year, it's all about AI. But let's not forget there are these digital credentials. There are these wallets. We can leverage them to verify who humans are and we can leverage them to take your digital proven identity into the real world, into the physical world without connectivity to prove that you're allowed to do something, to authorize yourself to do something, whether it's a commercial driving license, whether it's operate machinery, whether it's get into a VIP area at a sporting match.
There's a lot of things we could do. And with that, this thing's been flashing at me for about three minutes, but I don't really care. Thank you very much, guys. Nice to talk to you.