Hi everyone, I'm Rob. So I'm Chief Identity Security Advisor at Silverfort. So I joined the team about 18 months ago. Previously, I was a practitioner. So I spent 10 years running IAM, leading IAM at Tesco in the UK, so a really large retailer, 400,000 people. And I think, so I looked after all the big three in terms of IAM, so IGA, PAM, Access Management, Privileged Access, probably the one that was most difficult for us. And really, that's what we're going to talk about today and how we can think about that a little bit of a different way.
So kind of just centering us in, not everyone knows Silverfort or what we're about. So we're an identity security platform. And the way I explain this is, you know, we talk about identity like it's a single thing for the enterprise. But the reality is it's not, right? So it's not a two-dimensional problem. It's really a three-dimensional problem.
So for me, and having done this for a number of years, really every big kind of enterprise transition in terms of how we run businesses through technology has been powered by identity and changes to identity that's made things more complex. So you think about remote work, you think about outsourcing, you think about kind of cloud, SaaS, now agentic.
Really, it's all enabled by changes to identity and how we put that together for the enterprise. So really now we're in a place where identity itself is very fragmented, but also so are our controls, right? So is our security, which from a practitioner perspective, very difficult place to be. And the key here is that when attackers, and personally, I've seen an identity-based attack in my company, when they use identity or look to exploit identity, they treat it as a single surface. They don't care if it's on-prem or cloud or IDP X or Y.
They just see it as something that they can leverage and exploit to move around your business. So really importantly, from a defender side, treating identity as a single surface is really what we're trying to do. And the way we think about that is two ways. So the first is, what's really important from an identity security perspective, is taking the vulnerable bits of that identity infrastructure and trying to level them up, trying to harden them for these modern threats through identity.
And the second is, how do we treat this as that three-dimensional problem, bring it all together, and try and build integrity and effectiveness in how we're securing identity? Because, you know, from my perspective, the way I see it is, you know, we've got plenty of tools out there and plenty of capabilities, but we don't always have effectiveness. So that's really what we're trying to do as a company. There's going to be a lot on this slide. I'm not going to go through it all.
But effectively, we're bringing together all of these different elements of on-premise, cloud, SaaS, even local accounts that you see at the bottom. So that three-dimensional problem. And we're dealing with kind of all different kinds of identities, human, non-human, agentic. We don't think you can really separate them and treat them as different problems with different tools. We've got a ton of kind of capabilities and modules in the middle.
But effectively, if I kind of raise it up a level, it's about really understanding what's going on in identity, contextualizing it, understanding your attack surface and what's going on. The really important part that we talk about is this runtime access protection. So that's the enforcement capability that we've got to really start to take control and set some rules around identity. So that's really what we're going to focus on today. And then downstream to that, it's really about detection and response. Right. How do we know about threats? How do we respond to those threats?
How do we limit harm for our business? So it's really about resilience when it comes down to it in a really broad sense. So privilege access, as I say, this is where we're going to focus today. So the important part here is really. If I click on, despite those changes in enterprise identity, despite that complexity, Active Directory still remains at the center for a lot of organizations. But how we protect that really hasn't changed. So now we've got a much more connected on premise Active Directory environment than ever before through identity.
But how we're dealing with controlling that risk really hasn't changed. And we've got a stat here from Mandian. 90% of incident response cases that they see involve Active Directory. Right. So I've seen this personally and it's well known attack chain for someone like Scattered Spider. Compromise credential, get into kind of your SaaS landscape and your corp landscape, get some credentials, try and get to AD as quickly as you can. Because they know about this vulnerability. They know how critical it is to business today.
And when we think about that and the controls we apply, we commonly jump from saying PAM and then thinking vaults. That's really common as I talk to people in the industry. But PAM is a discipline. It's about risk control. It's about risk reduction. It's not really about the technology. And that's something that's really important for us. Because really, when we think about vaulting, it kind of came up in 2001 post Enron. Socks compliance in the US really was where that industry was or technology set was born from. But the threat landscape today is radically different.
The identities we have to protect today is radically different. We've got humans. We've got more of those we need to worry about with privileged type access. We've obviously got non-humans.
Really, the scale and complexity has changed completely. So the way we talk about this, we kind of use a Microsoft tiering model. So hopefully, most people are relatively familiar with it. But effectively, tier 0, critical to your business, Active Directory, PKI, all of those critical infrastructure services.
Tier 1, this is where your business runs. And then tier 2, we've got workstations your people are using to do their job. And what we commonly find as we try and kind of stretch the use of vaults into wider and deeper use cases, for example, trying to get into tier 1, we really find that the adoption of that is very, very challenging for a lot of business from an onboarding perspective, from a business change perspective. And this was exactly what I saw in my company.
So the end result of that difficulty and that stretching of the use case is we often see, and this is super common, your PAM covering vaults, covering a subset of kind of tier 0 maybe regulatory accounts, and then this unprotected privileged surface, right? Covering your business applications, often service accounts, non-human accounts as well. This is where we say that, you know, it's really about technology meeting people in terms of controlling risk, because it's not just about having technologies and tools, but it's also about the fit for your organization, right?
When I talk to people about privilege access, there's almost always a gap between where you want to be in terms of controlling that risk and where you can get to feasibly in terms of business change and adoption. That's where we say it's really about meeting technology and people together. It's quite a nice slide, I think. So this is how it felt to me. I'll give you an example. I have one account that needed to go in vault as part of our regulatory program.
It took us six months to get ultimately the CIO to agree to put that account in a vault because we did not know what we were going to break. The system was old. It was critical. We did not know what was going to happen. At the end of the day, it took five minutes work for my team to vault it, and we didn't break anything. But it just really shows how that meeting of technology and people is so important in success in controlling privilege access risk.
So at Silverthorpe, we asked ourselves, and this is something we've done for a number of years, what if securing those privileged identities, human, non-human, at the scale you want didn't have to be so slow, so complex, so expensive? And that's where we talk now about Vaultless PAN. So we talk about three things here, and this is really about building resilience in your environment. We talk about three things. So we say that our approach, and I'll go through it in the next slide, is better for security. So what we're trying to do is not build controls around identity to manage that risk.
We're trying to harden identity itself, particularly for that active directory environment. So we're trying to build in controls that can't be evaded, that can't be avoided. We're trying to harden it up and bring it up to modern standards. We say it's simpler to deploy because we don't have that onboarding process. We don't need to worry about that. We're applying controls by policy, by default. So it's simpler. And all of that means it's lower cost on a TCO basis, right?
So better, simpler, cheaper is what we say about this solution. So if I talk about how it works, because it's like, oh, great, Rob, that sounds fantastic. It's better, simpler, cheaper. But how do we do that? Why is it different? So there's quite a lot on this slide, but very simply, you've got people and things trying to do stuff in your privileged resources, servers, databases, whatever it is. What we do is we deploy a service on your domain controllers, in this case, that sends all of the authentication data telemetry to the Civil 4 platform, which then acts also as a policy decision point.
So if I'm RDP or SSH or SQL or PowerShell, I'm still doing what I normally do as a developer, but we're adding controls in real time as it's happening. So that could be for your human users, where we can level up with MFA and we can use things like Entra, Octa, whatever you're using to do that MFA like you would for a web app. So very consistent user experience there. We can move to just in time if you've got a zero standing privilege initiative.
Importantly, and this is something we see a lot of people coming to us for as we start these kind of PAM type conversations in terms of non-humans, because we see and understand all of that telemetry about what's going on in identity, we can profile your non-human accounts. But then really importantly, we can add protection. So we can what we call fence them in. So even if this service count is a domain admin, if it only ever goes from A to B on this protocol, we'll fence it in and restrict it to that. So we're really narrowing that blast radius through doing that.
And similarly, we've got kind of zero trust style controls. This is what we call a firewall, the power of deny, some people call it, where we're able to segment your identity environment. So for example, if you've got a critical system, if you know exactly who and how you want people to connect to that, we can start to move to denying by default anything outside of that baseline. So we're really able to build, meaningfully build, not just protection through MFA, but guardrails and resilience into your environment.
So if you've got a zero trust PAM type initiative, you want to move in that direction, it's fantastic for that. So the really important points here, I say they're really important, they're also really small on this slide, so apologies for that. The protection is real time, right? So people aren't changing how they work, but we're adding that protection in at the point of authentication. Active Directory will wait for a policy decision from Silverthorpe before it's then allowed to move forward if it's approved.
There's no agents to deploy on your endpoints, on your database, that kind of thing, we work with Active Directory. And we don't need to do that onboarding process, right? We're doing this without playing with credentials, without changing how people work, we don't have to do onboarding, we're applying policy for scale. And that's really important in terms of being in control of your risk reduction and your rollout over time.
So, we call that identity security done right, or the Silverthorpe way. And really what we try to do is, as I say, learn from what's gone in the past.
So, you know, previously, you know, visibility has always been a challenge in all aspects of identity, I think, because we see all of that telemetry, we can provide that visibility and understanding, which is then a springboard for us to go in confidently into protection. And proactive identity, for me, is the only way forward, right? Setting guardrails, setting rules, setting policies is the only way forward. And that's really at the core DNA of the company, is that protection first angle.
The other two, it's really about, you know, working with your environment, not changing how people work, not changing how systems work, but trying to work with what you've got and harden what you've got, rather than you saying, hey, you know, this isn't secure, I need to modernize, I need to go to the cloud, I need to do whatever and taking that cost and time, we're saying, hey, we want to work with that. The final one, you know, a lot of vaulting programs get stuck in trying to achieve their aims.
But then, really, for us, it's about getting there, but moving beyond it into those kind of zero trust concepts and into that segmentation to really control blast radius and control risk. Because for us, you know, PAM really is about risk control. Ultimately, that's what it's about. And we're really trying to segment and control blast radius, as well as providing that kind of basic protection.
So, what does that look like? And for time, I'm not going to go through all of these.
But, you know, coming back to our tiering pyramid that we had previously, you know, what we're able to do, where we previously had this unprotected account surface outside of the vault, we're able to extend those controls. So, that might be to your tier one admins, it might be to your non-human accounts. We work alongside that vault to really give you the risk coverage that you want. Right?
So, that's a really important point. So, it's not, you know, silver four and vaultless PAM or vaults. It's about getting the right mix of technologies to get to the risk appetite for your company. Right? And that's really, really important for us.
So, there's a ton of different capabilities there. You know, we talked about MFA, just in time, control for service accounts, but a ton of kind of intelligence and understanding type things there, as well.
So, coming back to that point, I think this is so important. Thank you, chat GPT, for this image. Because PAM, for me, is a discipline, not a tool. I think if we're still thinking about PAM as vaulting in today's threat landscape, I think it's a risky way to treat privilege access, from my perspective.
Because, you know, the demands for coverage are much higher. The diversity of identities, human, non-human, is much more complex than in the past. And it's really about risk control.
So, whether you've got a vault today, and you're not maybe meeting the goals you want, or you don't have a vault, because maybe you're worried or scared that it's too expensive, too difficult, you're going to fail. We see a lot of companies in that position.
You know, we can work without a vault to provide that kind of complete picture, or we can work with a vault to kind of complete the picture that you started. Right? Complete that journey that you began with the vault. And we're doing quite well on time, actually.
So, the same principles here. You know, we talked about runtime protection. That's really the core of what we're doing. Right? It's about proactive identity. It's about setting guardrails. It's about taking control of what's going on in your environment and setting rules that you can explain to your business to limit harm.
So, we talked about that from a PAM angle, and particularly Active Directory. But the same principles, the same capabilities we think really apply to agentic.
So, you might have seen HEDS talk about this yesterday on the keynote. You know, there's some really exciting moves forward we're making from an agentic perspective.
You know, integrating natively with the building platforms like Copilot Studio, Bedrock Vertex. Obviously, MCPs are part of the puzzle, but really the stage a lot of people I talk to, and we had an identity underground breakfast the other day where we talked a lot about, you know, just understanding the problem is the first step for a lot of people right now. How big is this problem? How extensively is it used in my environment? It's a really important one.
But that proactive runtime enforcement, that real-time control is something that we think is going to be really, really important to feeling comfortable with agentic for your business. So, it's really about taking a multifaceted approach for us, because I don't think the patterns for how agentic will be adopted are settled yet. We talked a lot more about MCP last year than this year, and I think the picture's changed in terms of how it's being adopted in enterprise.
So, we're kind of in a place of, well, protect the platforms that you use to build and make agents, protect MCP, but also then protect at the IDP level. So, you're really making sure you're not leaving room for that kind of shadow agentic usage in your business.
So, that's something we're doing, and we're bringing increasing autonomy to the decisions that we make in runtime as well, as Hed talked about yesterday. So, if you didn't see it, I recommend catching up on it on demand afterwards.
So, I think the other thing, the final thing I wanted to say is, you know, I think as an industry, we talk a lot about agentic and agentic adoption. Something personally I'm far more worried about is the threat side, right?
So, AI-enabled attacks. What we've seen through our work with Glasswing and through their testing of Mythos, particularly, is that it is as adept at exploiting identity vulnerabilities as software vulnerabilities. What that means to me is we need to finally take the step that our interior, from an identity perspective, looks a lot like our exterior protection.
I think they start to need to look very, very similar in terms of those risks, and I think, you know, the Vaultless PAM approach that we talked about, getting the coverage, covering humans, non-humans, not leaving any account behind, I think is going to become increasingly important over the next year. So, really pertinent subject. We're at booth 12. This is my LinkedIn QR, I promise. It's not malicious.
And also, just a quick plug, because we released it this week, we've got a new podcast called Identity Decoded. So, it's available on YouTube, it's on Spotify, it's on Apple Podcasts. The first conversation we're having there is with a guy called Sri, who's at Interactive Brokers. We talk about Mythos, we talk about frontier model threat, we talk about what it means for identity. I think it's interesting. I'd love for you guys to check it out and let me know whether it is actually interesting.
So, that's me, and that's, I think, pretty much my time. Well, thank you very much, Rob. Thank you.