Despite decades of effort, identity programs are still falling short. Slow onboarding, fragmented tools, and limited innovation have left enterprises struggling to meet governance and security goals. With identity management increasingly seen as a data problem, the need for a new approach is urgent—one that simplifies processes, integrates technologies, and addresses overlooked areas like non-human identities.
Modern advancements in AI and centralized platforms offer a way forward. By integrating ITDR, CIEM, ISPAM, and IGA into unified solutions, organizations can streamline onboarding, improve entitlement management, and achieve contextual visibility. This webinar will explore how data-driven strategies and automation can transform identity security programs into scalable, efficient systems that deliver real value.
John Tolbert, Lead Analyst at KuppingerCole, will discuss why identity security programs fail to deliver meaningful outcomes and how reframing identity management as a data problem can drive innovation. He will also explore the role of AI in entitlement management, the consolidation of ITDR and CIEM into IAM strategies, and why Rule Management is the future of governance.
Amir Ofek, CEO at AxoniusX, will share insights on overcoming IAM fragmentation through automation and pre-built integrations. He will highlight strategies for managing non-human identities, improving identity hygiene, and leveraging centralized platforms for governance. Attendees will gain actionable steps to reduce complexity while enhancing security posture.
Good morning, good afternoon. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole. And today's webinar, our topic's going to be Taming Identity Chaos, How to Finally Get Control of Your Attack Surface. And today I'm pleased to be joined by Amir Ofek, who's the CEO of Axonius-X. Welcome.
Hi, John. Great to be here. So a little bit of logistics info before we begin. Everybody's muted centrally, so there's no need to mute or unmute yourself. We're going to do two polls during the webinar, and we're going to take questions. We will try to take questions as we go, and if not, we'll check them again at the end. So there is a control panel. Feel free to look for the questions blank in the control panel and enter those, and we will address those as we can. And lastly, we're recording this, so the recording and the presentation will be available in a few days.
So really we're not presenting much to you today. This is going to be a discussion. Both Amir and I will kind of go back and forth on some of these topics. We've got about ten different topics related to identity chaos and how to tame it. I thought we'd start with a little overview. So what is the cyber threat landscape?
You know, we've been hearing for at least 15 years identity is the new parameter, so let's just say it is a parameter. ATO's account takeovers have been increasing. This is a real threat, you know, for both the consumer side as well as the workforce or enterprise side. And you probably know this already, but just about every cyber attack or data breach that we hear about in the news has some sort of identity component. Compromised credentials are the way in. These days they say attackers don't break in, they just log in. And that's because they can buy compromised credentials on the dark web.
And there are even some cases where ransomware attackers don't even bother with malware anymore. They just get, you know, credentials off the dark web, maybe disgruntled employees or whatnot, and log in and conduct their attacks that way. So identity as a perimeter really is a big attack surface. Perimeters these days are porous. We all know that. It's been that way for many years now.
VPNs, customer portals, all of these different technologies that enable business today also bring with it additional risks. And if you think about it, with so many organizations using, you know, I've seen a wide variety of statistics, how many different SaaS apps, you know, the average organization is using, one to 500 maybe. How else do you control access? Identity really is the primary access control mechanism, especially when it comes to the cloud, because as a SaaS customer, you don't really have that much control over the infrastructure. And really your only line of defense is identity.
And, you know, the one to 500 SaaS applications that we hear about are the ones that IT organizations are aware of. Shadow identity in the cloud has become an even bigger problem because lots of business units will feel empowered to go out and, you know, contract with SaaS providers as needed, and it may not even be running through, you know, the IT organizations. They may not be aware of it. So I wanted to start off and just briefly talk about ITDR, what it is, what does it do. This has been a hot topic for the last year or two especially.
And I think it's really designed to, you know, plug a hole that we see in identity-related security. Amir, feel free to jump in here at any time too. Sure. But why do we need something like ITDR, Identity Threat Detection and Response? Because IAM systems have developed sort of on their own over the last 20 years, and they're in many cases very feature-rich. But it's really been about enabling access. Identity security is now saying, okay, it's great to enable access, but we really need to make sure that that access is appropriate.
So knowing that identity is, like, the key vector to get inside an organization and potentially steal data or, you know, wreak havoc in other ways, you need a really comprehensive view. So that's why, you know, here we're saying you need enterprise-wide telemetry collection, not just your on-prem systems, not just your Active Directory or other LDAP, but you've really got to be able to look at what's going on in the cloud with regard to identity.
And you need to be able to figure out what's a normal baseline of what regular user activity is, things that we have authorized and, you know, should not be interfered with, but also be able to figure out when is something looking not quite right and then what to do about it, and then being able to put that together across many, many disparate systems. I think ITDR is a really interesting technology. I think it serves a real purpose. And some of the more advanced solutions we see in the space can do things like attack path visualization, help with investigations.
And then the R, the response, you know, that's important, too. What are the things that it can do in terms of responding to these kinds of threats? That could be, you know, turning off accounts for a while or, you know, enforcing some sort of MFA, step-up authentication or authorization, or even time-limited blocking.
So maybe, John, just a few points maybe to add here. First, I would say that the first point here around kind of enterprise-wide telemetry, I think that's kind of the foundation or fundamental thing of all. At the end of the day, in order to monitor today identities in the organization, you need to have full and comprehensive visibility around all identities and in all sources of those identities. So it's no longer a case where an employee in the company has just this one specific place where he has permissions, let's say in your ERP systems. Today those identities reside everywhere.
And myself as an identity, my account as, let's say, an R&D manager or as a domain admin or as a DevOps person can have actually permissions residing in GitHub and in JIRA and in AWS and in AD and in Okta and you name it. So you need to really view first the identity from a totality of it. The second thing that I think is very relevant for ITDR is the fact that today identities are much more dynamic than they used to be. So you can change roles within a company.
I'm not just talking about kind of restructuring or kind of HR, you know, reshaping of the organization, but you really have a very dynamic permission set. Even with new tools that are being adapted in the organization, either it is because you need to have access to various service accounts that are popping up, popping down. When you're talking about kind of non-human accounts, you need to constantly kind of have your passwords managed all across. So it's a much more dynamic environment.
And the fact it's more dynamic, you need to really monitor the behavior of those identities to see how they trace over time. And correct, as you said, you need to kind of first understand what norm is looking like, which is very difficult to understand. It's very difficult to understand, like, what's the actually the baseline that you need to compare against, because this baseline is almost ever changing. So that's kind of the new, I would say, dimensions that are quite challenging when it comes to ITDR. And the last piece is really ITDR today is not just about kind of the detection of things.
It's really about also recommending action and taking action on securing kind of specific identities, shutting down even specific identities, locking service accounts and so on. And also keeping in mind that, you know, for those of us who've been working in IAM for a number of years, we tend to think of it as an internal thing.
You know, but business relationships are so complex these days. We've got contractors, partners, customers. Right. All having accounts within our systems of one kind or another.
So, you know, being able to understand what's normal for those accounts and, you know, applying governance to that and then being able to alert when something looks anomalous there is really important, too. Absolutely. So quick look at the use cases. It's really all about protection, I think.
You know, protect your let's call them on-prem solutions like AD or LDAP directories, your identities of service from the cloud, prevent ATOs. And then thinking on the attack side, you know, stopping things like APTs. APTs are still out there. They don't get talked about as much. But this is, you know, something that is ongoing every day. And thinking about MITRE ATT&CK Matrix, all the different, you know, phases of that, identity is involved in so many of them because it really is the enabler for moving around, you know, creating other accounts, exfiltrating data and things like that.
So we also need to find those insider threats. And like I said, insiders might be contractors or partners. And then tie that back to something actionable like enforcing MFA and looking for MFA bypass attempts, even. Monitoring MFA in general, I would say, is something that is quite important, even beyond just the scope of ITDR. Like at the end of the day today, MFA is the holy grail of controlling the gateway.
But if you are not ensuring that the right identities are using those MFAs in place and using strong MFAs versus weak MFA and you're checking the usage of MFA, then you're missing the boat on really having a grasp on what's going on in your environment. Exactly. So we've come up to our first poll question. Let's take a minute and vote here. Do you have any plans for ITDR?
No, we're not really planning for it yet. We're considering it while we're starting it. We're in the process.
Or, hey, we've already implemented it. So feel free to look at the polls tab there and enter your response. Let's see. So first topic, you know, we have so many acronyms in identity. And really, what do they have in common?
Well, I is part of all of them. We've got identity and access management. We've been talking about ITDR. IGA has been around for quite a while. ISPM is another one that gets bandied about quite a bit. Identity security posture management and NHIs, non-human identities. I even heard of a new one that is probably up and coming called IVIP, Identity Visibility Intelligent Platforms. So I think every conference I go to, I hear another acronym, which is a bit, I would say, I can understand where it's coming from.
Because I think this is actually maybe an indicator to the fact that the identity space is changing. That there's new technologies out there that don't really fit, you know, the traditional IGA. So there's a need to kind of define them in a new category. There's new elements, new visibility, like non-human identities that didn't exist like a few years ago. So there is a need to maybe put kind of a spotlight on it and to call it a category by itself. Personally, and I just came back from both IAC in Berlin, and then I was in Identiverse in Las Vegas.
So personally, I think that there is actually too much influx of all of those categories. In my mind, at the end of the day, you need to try, and I guess customers, that's what they're really looking for. You need to try and tie it all together. You really need to try and tie the ability to do identity governance along with the ability to monitor both human identities and service accounts and other non-human identities. You need to have very strong visibility of your identity, which drives the ISPM, the posture side of things.
And ITDR, as we discussed before, is yet another feature in my mind to help you track the behavior and the governance of those identities. So it's really all, I would say, more of, let's say, the new evolution or the involvement of IGA at the end of the day, the way I see it, to various elements or various new functionality that you need to ensure exists in your IGA infrastructure.
Yeah, I think you make a good point, too. And, you know, as techies, I think we sometimes get excited about new technologies, things that can help us out. But from a business perspective, I think we want to stay focused on just protecting the identities and the other infrastructure that we have. So in looking at these different tools, whether we call it ISPM or IVIP or whatever, we need to be mindful of how does this help me in my organization? Do I have a gap in coverage that this might help protect? Exactly.
I think it's also a good point that IGA has its tendrils in each and every one of these different pieces here we see on the screen, governance, lifecycle management. And, yeah, that even extends to new things or at least new categories of things like NHIs.
I mean, NHIs have been around for a long time, but now they're finally getting some attention in a distinct category and the challenges. And we'll get more into the NHI discussion in a little while.
So, you know, our topic, you know, taming identity chaos. I think Anir and I talked about this a few weeks back, and one of the emphases we wanted to put on this was the data problem at the heart of identity security. And this ties directly to what you were just saying about, you know, identity governance. So I think we've known for quite a while that identity has a data problem.
You know, you have to think about the different sources, the quality. And, again, this is where IGA comes into play. How do you do lifecycle management? How do you do access reconciliations in a way that's actually meaningful?
You know, I've seen over the course of many years the spreadsheet approach, you know, and if you're in a large, complex supply chain where maybe you're the prime contractor, you're depending on other members of your supply chain to provide you with quality data. And how seriously do they take that when they get that spreadsheet and, you know, with a list of usernames, you know, should this person have access or not? And then how out of date is that, too?
You know, maybe you could ask for annual, semi-annual, or quarterly updates on the access recertification, but is that enough? What are your thoughts on that, Amir?
Yeah, so we at Axonius, we're a data company. So, you know, to me, it sounds very, very trivial and it resonates very, very much.
Again, in all the discussions I recently had with a lot of IAM practitioners, both in Berlin and Las Vegas, I would even change this title now in hindsight, you know, versus when we prepared this slide. I would say identity security, it's not that identity security has a data problem. I would say identity security is a data problem. It all really, really stems from the data. And at the end of the day, the issues that we are tackled with today is because identity is not being addressed as a data problem.
The fact that we cannot have one single data model that can hold all of permissions, all of entitlements, whether they're on the cloud, whether they're on-prem, whether they're on DB, etc. The first point here on sources, like the industry has tried for so long to implement scheme, for example. But unfortunately, you know, scheme has been picked up maybe, I don't know, in a good day, maybe 20% of the application today out there in the world support scheme. The industry has tried to kind of break those silos and try to bring kind of one single identity lake or sort of speak.
But how many organizations truly have a single identity lake today, data lake today? And I think that's kind of the foundation today, because identity is everywhere, because it's broken, because it's siloed. Because of what we spoke before about the dynamic aspect of it, of it ever changing and constantly new identities are being introduced into the company. You need to have the foundation of a single data repository under a single data model as an underlying infrastructure.
Only then you can start kind of looking, of course, at the quality of this data and analysis of this data and making sure that, you know, you can then do the right kind of governance, the role mining, etc, etc. But unless you have the data, the data problem solved, I don't think you cannot build your identity tower on top of it.
Yeah, and I just thought of another one, another bullet point I could have put here, normalization. Absolutely. You have different data silos, how do you normalize it? Or if you're, again, working in a complex supply chain and you've got different identities, you know, coming from different domains, different federation partners, data normalization can be a difficult thing to get a handle on. Exactly. And that's kind of the main, I would say, shift that a lot of IAM teams are facing today.
It's moving from more process oriented, of like monitoring the access reviews, monitoring the identity lifecycle, and so on, to really having a good handle on the identity data. Understanding that the identity data is normalized, is correlated, that when you talk about specific permissions, you know that those permissions exist all across the organization. You know that when you speak about a specific identity, these are the users that are associated with it, these are the groups that are associated with it.
And you know that you're walking on solid land, sort of speak, and not kind of in a swampy environment, because you want to know that the identity data is configured, is set, is correct. Only then you can start doing the analysis. The fact that the historical view on identity has been more on the monitoring the process or chasing the process, I think is becoming less and less relevant today.
Yeah, I think you can't really stress enough the need for quality and timely data. I mean, think about how many attacks have happened, you know, over the last decade that involved accounts that have been abandoned.
Or, you know, again, supply chain, you've got a partner, they have 50 accounts in your system, you know, and 10 of them have left for whatever reason in the last six months. If you're not doing really, really up-to-date checking on those accounts, then those accounts themselves are vectors for attacks. So it's really important to keep it clean. So you mentioned the keyword a minute ago, silos of identity data.
You know, it really does make security harder. Again, I've been thinking oftentimes in terms of on-prem, but think about, you know, you mentioned identity data lake. I think that's a really great term. How do we centralize? How do we keep our identity security systems aware of the different silos, keep them in sync? You mentioned SCIM. I think there are other protocols that come into play here. But I think the idea, the problems that identity silos bring are something that has often been overlooked. And this is another area where things like ISPM or ITDR can certainly help with.
There's actually a question here. Alfred is asking on how AI agents can be stopped from abusing privilege access. And I think it's a bit tying into this. So I think first and foremost, in order to kind of stop AI agents from accessing what they shouldn't access, you first need to break those silos. Like one of the most kind of common cases I've seen, at least, of AI and even not AI, of like overtaking accounts or of orphan accounts that have been existing in some silo area of the organization.
Some neglected AD or some neglected, I don't know, some neglected, even an Octa instance that are not used, et cetera. So I think first and foremost, you need to have a good handle on the totality of all of the identities, all of the permissions that you have existing. Because at the end of the day, an AI agent will do its job, by the way, by getting access through permissions of specific identities that he's getting access to, of triggering additional service accounts, additional actions within kind of the workflow that this AI agent needs to handle.
So first you need to know everything he can access. It can, I'm saying he, it should be it. It can access. So this AI agent, you need to know the full parameter, the full totality of identities that it can access. That's first and foremost.
Secondly, as we mentioned before, I think the moment you have ITDR in place, you can start tracking on the behavior of those AI engines and then see if all of a sudden there is a privilege account that is starting to look abnormal and have kind of different traits. And then you can react on it. But unless you have, you can see with AI, it's very tricky because unless you have 100% visibility, which you will never achieve, let's say 90% visibility, AIs will be always elusive and they will always find a way in the least expected place in your environment.
Yeah, this is a great place for ITDR because one of the fundamental functions of ITDR really involves user behavioral analysis. And an AI agent is just either another kind of user or a user acting on behalf of another user. So understanding, again, what's normal, what's the baseline and where the deviations occur. I think that can help you alert when AI agents have, you know, gone off course.
Yes, exactly. We mentioned a bit about this already. Identity lifecycle management, you know, provisioning. I think we've gotten provisioning down, Pat.
You know, with things like SCIM, we can easily do like just-in-time SAML account creation for employees or partners or customers or even temp workers. But the deprovisioning part gets to be a little bit harder.
Recently, I've been hearing from companies about the needs for very, very short-term accounts like for the temp workers here. So deprovisioning, getting rid of that account, you know, before it can be used for abuse is something that needs a lot more attention, I think. And I think it's a place where ITDR and the UBA that comes with that can be helpful. Absolutely.
So, again, this point on abandoned accounts, I think, is very, very crucial. And in order to avoid those abandoned accounts, it's exactly like you mentioned. It's making sure you have more kind of just-in-time provisioning, tighter control that you deprovision immediately the moment that identity is not needed, that permission is not needed. That's probably how you can handle the abandoned account aspect.
And for companies that have, unfortunately, history or baggage of identities, I guess the way to address it, as we see with some of our customers, is really to conduct kind of very profound role mining exercises. And when I'm saying that is really understanding kind of all of the roles.
So, for example, we have an insurance company in the U.S., 20,000 employees. They've been having, you know, IGA for ages, but they've, over the years, have accumulated a lot of roles within the company.
And, unfortunately, today, because they don't have a good handle on their data, they needed an ability to analyze the data of the roles in order to come and recommend them on how to right-size the amount of roles in the company. And that's kind of what we help them implement by bringing all data in one single place in a very normalized way, correlated way.
We can then apply very smart AI, machine learning capabilities of clustering, of showing which profiles can be clustered together and which profiles are actually a group of one that maybe should not be at all, that should be deprecated, should not be at all in the organization unless there's very good justification for that. But also there, you can have actually AI, ML in your advantage of analyzing those big data problems, and clustering is not too complex. But it works only when you have the right foundation of the data.
If the data is noisy, if the data is dirty, then your clustering will be a bit meaningless. Yeah.
You know, one kind of extreme example I heard about here is I think it was a logistics company where they hire people to do a job that might take two days or three days. So if you're doing your access reconciliation through IGA on a quarterly basis even, I mean, that's a lot of days. Right.
You know, or you've got accounts sitting around that could be exploited. So, again, another place where things like ISP and ITDR, that approach can certainly help mitigate the risks that come from these inactive accounts.
So, you know, I've been working on ITDR for a while, EDR, EPDR, all these DRs. I think we get very focused on the detection part, but really the R is just as important. So what do you do? How can you remediate? What are the things that you can expect, let's say, an ITDR solution to be able to do to help tighten up identities to prevent attacks or to limit damage when attacks happen?
I mean, most of these are pretty straightforward. You'd think, yes, force step-up authentication. Make sure it's the right person. Maybe it's just an anomalous signal. But then if it is pretty well determined that it's, you know, malicious activity on the other end, you want to be able to terminate that session, revoke access, maybe disable the accounts, of course log it. But with all the different tools that we've got in play out there, which one do you want to do?
I think from an architectural perspective, it's good to take stock of what you have and where these capabilities lie and then decide how do you go about performing these responses? Because there are a number of different tools that any given organization may already have in their architecture that can do this. So your thoughts on the response piece, Amir? Yeah. I think you hit on a very good point. You don't need to reinvent the wheel. You don't need to add additional maybe tools, additional products that can help the remediation. You need to trickle, trigger them.
You need to trickle the process of remediation in the right context, in the right place. And the way to do it is by first doing kind of the detection part very well. But then automate as much as possible on workflows. You mentioned here kind of SOAR. I believe you need to have SOAR almost kind of inherently integrated in any IGA foundation that you have because you want to automate as much as possible the workflows. You want to make it easy to automate them with an easy drag and drop capability.
And you want to make sure that you can change those workflows if the remediation environment changes. But at the end of the day, and I said it before, just driving visibility, just driving detection without the actionability at the end of it is a bit meaningless. So this is kind of what we hear a lot, a lot from customers. We in Axonius are kind of very known for the visibility capabilities that we have, et cetera. But what we've heard over the recent years is that visibility is great. But at the end of the day, without the actionability side of it, it's kind of only halfway through.
And that's why I believe all IAM organizations, all security organizations really need to look at identity governance end-to-end and identity security end-to-end all the way to the remediation and taking action of things. Just curious, what are your customers' appetites for automating responses?
Yeah, so I would say it varies. So, for example, one of the key use cases that we start seeing is around what we call PAM enhancement, Privileged Access Management enhancement. So think about a lot of PAM solutions that are being deployed. They have the privilege accounts that are being managed there. But there's always a growing gap between the privilege accounts in the PAM versus the actual privilege accounts that exist in the environment.
And there is privilege accounts within the PAM that maybe should not be there anymore because they're not privilege accounts that are relevant in the organization or that are not privileged anymore. So there needs to be constantly hygiene aspect of your PAM.
Now, that's something that we get more and more asked to actually drive constant automation. So to constantly kind of clean up, remove irrelevant privilege access accounts within your PAM and constantly making sure your PAM is up to date with new privilege access identities that needs to be added. And that's something we automate on the remediation side of really kind of locking in, let's say, an account or terminating an account. That's kind of where I see customers more wary.
They want still just the recommendation with their ability to decide kind of whether there should be an actual locking in of that account or not. The place where there is more openness is what we discussed before around the just-in-time access. And that's becoming very, very common of providing kind of a privilege, let's say, for just 90 days of specific privileges or specific kind of permissions set just for 90 days. After 90 days, automatically deprecate them. And only if the user shouts that he needs that permission again, only then opening it up.
That's actually something that I see more and more common these days. Yeah, you know, late last year, I was working on the XDR report. And it's interesting because so many vendors build in a lot of sophisticated capabilities, not only on the automated analysis, you know, and creating cases and routing cases and gathering threat intelligence and making it easy for, you know, an investigator to start an investigation. But they also allow pretty strong responses that could be automated, things like terminating sessions or, you know, immediately revoking access.
And at that time, and I would imagine it's still similar, there's still some reticence on the part of customers to fully automate that because, you know, they don't want to cut off finance people's access to finance applications unless there's a human in the loop who can look at that and say, yeah, I really think this is a significant threat and it's worth pushing the button. But they want the button. They don't really want to fully automate it. Exactly. It's just kind of to have the ability to say that you can automate something but not really automate it.
So it's great these capabilities are there. And maybe, you know, over the coming years as we learn to trust the output, maybe that fully automated response will, you know, see more uptake. Yeah. So here I wanted to throw in our latest identity fabric slide just to sort of illustrate how complex not only IAM is and all the different parts of it.
But, you know, the identity fabric approach, I think ITDR, ISPM, all these different I tools that we've been talking about kind of fit into this. And the important thing to note here is, you know, IAM systems, including IGA, are very large and historically have been these monolithic things that are very difficult to to change or even update properly. But when you can bring in new identity security technologies in the identity fabric model that can coexist with the infrastructure that you already have. And I think it's important for companies out there today who have sophisticated IAM systems.
And that's everybody at this point, you know, with a with a mix of on prem and cloud services and services that you're trying to keep integrated and interoperating. Taking the identity fabric approach allows you to add identity security tools like ITDR. Any thoughts on this? How have you encountered situations where you have customers that are taking the identity fabric approach and adding on discrete identity security services to improve their own security posture?
So first, I would say the identity fabric concept I see actually picking up a lot and a lot. So like if a year ago, it was still kind of viewed as more of a potential vision, etc.
Even now, when I was in identity verse in Las Vegas, everyone was talking about having an identity fabric, you know, understanding and identity fabric visibility and so on. So first, I think this concept of identity fabric is something that is really picking up in the IAM community mainly.
Now, I think from kind of addressing elements here that that's kind of you should look at it as a blueprint, sort of speak. So as a head of IAM, head of identity security, the identity fabric is a great blueprint to see that you're really covering all grounds in terms of having full coverage of capabilities, full coverage of services, and the necessary tools that help you address. And what I've seen a lot of customers these days, they're starting to see kind of new areas that they feel that they have gaps in.
The most common one is NHI, of course, of coming and saying there's kind of this NHI component, we don't get coverage for that from our existing IGA capabilities or PAM capabilities. This is an area that we need to make sure we cover. Another area has been kind of what I mentioned before around kind of role mining. We're not getting this kind of role mining understanding to have a good kind of grasp on our identity fabric. So let's add this role mining capability.
Those I think are kind of the most maybe two common areas I've seen as augmenting existing kind of foundation, leveraging the identity fabric. But at the very baseline of it, the identity fabric, it goes back to what we said at the beginning of this discussion. It's a full visibility of all of your identity infrastructure in its totality. That's exactly what it is.
And, of course, the synergies between it and how it aligns, et cetera. But you need to have that kind of full visibility, and that's kind of what you should aspire for. You should aspire to always have full visibility all across data types, data sources. And I think that's a great blueprint to follow. Yep. We have another question here. If attackers can buy leaked credentials to my organization from the dark web, how do I protect against that?
Well, I think that's a good place for tools like attack surface management, those especially that are focused on dark web reconnaissance, looking at those caches of compromised credentials that are out there and then letting their customers know about it. Can you go into more detail on that?
Yeah, so actually one of the former companies I was CEO of, that's what we did. Cypress was acquired by Checkpoint. And what we did there is actually look in the dark web constantly for those leaked credentials. I think first you need to do is to make sure you have ability to target, to know about leaked credentials early on of your organization that has been leaked, and then, of course, making sure that you deprecate those accounts. But the moment they are out there in the dark web, you should assume that already somebody is abusing them. That should be your assumption.
And therefore, the moment you know about leaked credentials, you should go and make sure that those accounts are locked or changed password or kind of taken care of and all the relevant people have been aware of. One of the things to protect against that is some very basic hygiene. So first we spoke about abandoned accounts. Usually most of those credential leaks, at least based on my experience, are accounts that are no longer active in the company. Employees that left, subcontractors that were terminated, service accounts that were terminated.
So accounts that were neglected over the years and were not taken care of and nobody is aware of their existence anymore. Those are usually what are getting very easily to the Internet. The fact that they're not being used doesn't say that you cannot abuse them. That's the point. They could be the admin accounts that nobody is using, but they still have the access and the credentials, very, very sensitive data and very sensitive systems. And that's what you should always kind of think. The fact that they're not active doesn't mean they're not dangerous.
So one thing is making sure you have a good grasp on all of those abandoned accounts and remove them. The second thing is what I mentioned before, right sizing the amount of roles in the company. The less roles you need to manage, the more good handle you have on it, both from security perspective and even from IT perspective. So just think about it. Your IT help desk, the less amount of tickets they have to manage in terms of roles, permissions that they need to allow or new groups that they need to open, etc. The easier it is to have a good grasp on it. So that's the second part.
And the last part is really that the ability to constantly do easy things like access reviews, you know, so it sounds very trivial. But if you are doing access reviews on a regular base and in a systematical manner and not access reviews that are quote unquote dumb access reviews, which is usually the case that where managers just approve all because they don't have time now to go and investigate each and every request of permission.
But you do kind of more smart access reviews that can come with recommendation of what has been approved before in the company, what has not been approved before in the company. Has that employee got new privileges in the last quarter or those are all privileges they had before. The more you have a good handle on those access reviews, the less you are prone to kind of a sabotage of taking over an account without you being aware. And maybe the last point that we also discuss is also monitoring the identity behavior.
So ITDR can help a lot of seeing whether all of a sudden a specific permission is not being leveraged, not being used the right way, whether an identity all of a sudden is behaving in a strange way that has not been behaving before, which can potentially be malicious. I just want to quickly go back and give a thumbs up on the minimizing roles.
You know, roles, many more roles than people in an organization, and they wind up with all these privileges and entitlements that they don't need. And they're they just really increase risk.
I think, you know, attribute based access control, policy based access control, much better mechanism than role based access control. Plus, our back is really old.
I mean, there's a lot of good music that came from the 80s. And this is something.
Yeah, this is something maybe for a separate webinar. We even had a blog, but something I've been discussing with Martin Kupinger a lot on of this kind of notion. He keeps preaching for moving from roles to rules. And this is something that we very much adhere with. I very much agree that the world should move from role management to rule management. And those overarching policies, it will make life much easier and much more secure in my mind. So let's take our second poll. I'm just curious. What do you think on ITDR functionality? Where do you expect it to reside?
Do you think that it's going to continue to be a standalone product? You think it will eventually roll into full IAM suites? Do you think it should be part of XDR? There are some XDR companies that are offering ITDR now. Do you think it should be part of SOAR? Or as maybe another feature of attack surface management? And I don't think at this point there are really any wrong answers. So I'm just real curious what the audience feels like, where it will be going. So feel free to jump in there, answer that question. It will remain up on the polls tab. And we'll just keep going.
We'll take a look at the results at the end here. So we've mentioned NHIs a couple of times. We've said that they've been around for a while.
Because, I mean, if you look at the different types of NHIs, it's not like these things are new. You know, we've had mobile phones for a while, tablets for a while, service accounts, obviously, for decades.
I mean, we do have new things that we need to worry about. You know, with the advent of the cloud, we've got all the cloud-related NHIs.
But, you know, think about IoT devices. And connected vehicles is one I kind of wanted to highlight here, too.
Because, you know, large companies that manage fleets, they do access control based on which users, allowed in which vehicles sometimes. That can get very, very complicated to deal with. And we've already had one question on agentic AI.
So, you know, there's lots of different kinds of non-human identities that we now realize we have to manage somehow in conjunction with our IEM systems, privilege access management. Any thoughts on the use cases that you've seen, Amir?
Yeah, I think the most common use case that we are seeing today is around the token and certificates and service accounts. That's by far the most common use cases. I would say all the rest are kind of, of course, existing there, but they're much less common. And the one, of course, everyone is recently concerned about is agentic AI as the new kind of buzz of the hour.
There's, again, a question by Alfred on how you can detect compromised NHIs before they become insider threats. So I think on all of those NHIs, you need to have, again, good ITDR foundation to monitor the behavior of those. And at the end of the day, like you said, if a smart vehicle, for example, has its pattern for clear.
Actually, with most NHIs, they even have much stronger patterns than human beings, because usually what they are being tasked of doing is something that is very kind of rudimentary or something that is very periodical probing or something that is very, very kind of falls into a specific trait pattern that can be easily traced. A human actually is more unexpectable than a non-human identity. So those non-human identities can actually relatively easily be tracked through ITDR by their behavior.
And that's kind of one thing that is very, very important to have like a proper detection of those identities. And the moment they start kind of behaving strangely, raise a flag, making sure you go and do the analysis. The second one is that you need to make sure there is strong ownership of those NHIs. So one of the common use cases that we see today with customers is making sure there is a good process, a good workflow for associating an owner with an NHI identity, making sure that every NHI in the organization is mapped to a human owner.
And the moment that owner leaves the company, there is immediately assignment of that to somebody else. The moment this owner changes, there is some kind of logic of who that NHI. One of the most dangerous things that you can do is leave NHIs abandoned because they're not being looked at unlike humans. They're not being probed in like humans and they can be neglected very easily. So that's kind of what I would advise.
Yeah, you know, the underlying functionality there that ties all these things together in ITDR and other tools is the user behavioral analysis. I think you're 100 percent correct. The only way to really understand what's going on with an NHI and whether or not it might be being used maliciously is to know what is it supposed to do? And what does it look like when it's doing something it's not supposed to do?
And, you know, you're absolutely right, too, about the ownership, because let's say you find an NHI that's misbehaving. What do you do about it? You've got to alert somebody, figure out, hey, is this yours? Is this can we can we deactivate access? Yeah. So those those two pieces are very critical. I think you're right about that. So we've been dancing around the agentic AI subject.
You know, there are lots of agents that are out there already. These are some common examples of agents that that we see and we have to learn to deal with in our IAM systems and our CIAM systems. Do you have any stories or use cases about customers that are deploying these things and looking for identity security solutions specifically for these kinds of agents? Yeah.
So, again, it's very, very early days. And I would say I've yet to seen kind of a full blown agentic AI operation within a within an enterprise that has everything triggered by bots and and kind of leveraging all all actions with bots. I haven't seen that, but there's definitely pockets mainly around the development teams, engineering teams that are toying around with with agentic AI.
And over there, actually, you see kind of product security teams that are very cognizant of the need for putting security measures early on and making sure that you track those agentic AIs again, mainly from an ownership perspective. So making sure that there is like a developer or an operator that is assigned with monitoring this agentic AI early days to see how it behaves, to see that it functions well, that even from an operational perspective, that it doesn't break and making sure that there is always this time of an owner, a human owner to every agentic AI.
That has been probably the most common use case that we've seen. Makes sense.
You know, I just thought we'd mention for a minute some of the other uses of AI and I am we've been talking a lot about user behavioral analysis and a lot of the stuff is based on, you know, older ML machine learning type technology. That's what we're using for anomaly detection. That's what, you know, is powering risk based authentication and behavioral biometrics and all these other things really where it's the new LLM kind of things that come into play are the AI powered chatbots.
So, even though, you know, LLMs are relatively new, it's older brother machine learning and other type of AI has been around for a while. And we've been using it for many years, just hasn't been getting the attention until the last few years, but ML has been powering our IAM and role mining and ITDR functions for quite a while.
So, so I think, again, because identity is a data problem. I think actually AI ML can be very well leveraged when it comes to to I am and to identity. It's a very good area to apply machine learning and AI on top because you need to deal with data. Anything that is data intensive that has actually a lot of structured data. Is fairly good place to start. And for example, we have been working very closely with Bedrock from Amazon, applying some elements of understanding patterns of rules, as I mentioned before.
Managing kind of role mining capabilities by doing kind of clustering models on the on the identity data that we collect. They're very fundamental of it, though, I believe, before you apply AI, before you apply ML, you need to make sure that the data that you are applying it on, especially with identity is a solid Zero noise all correlated or normalized data because the moment you have these even small areas of noise of kind of dirt that they see through the data.
I can be as good as the data that is applying on on top of and and i think that's why you need to get your, your baseline first in order, making sure that the data is all well and then you can do a lot of very, very cool things today with with ML and AI on top. Yeah, great point again on data quality and also the integrity of data source and enough data be useful, you know, you think exactly role mining, you can if you only have two individuals.
Yeah, exactly. Exactly. So wrapping up here. I just kind of wanted to focus on, you know, again, why it's important to think about tools like it are In conjunction with, you know, maybe built in ISP and kinds of capabilities attack service management, how they fit together because We all know if you have been working in identity for a while that once you put an IM system in place. It's going to be there a long time.
You know, and even doing upgrades. If it's an on prem system, you know, can take a very long time to do that, you know, even just running the RFP, you know, might take you six, nine, 12 months So, and then when if you're going to replace it, that can be years after you've decided to replace it.
Now, obviously, it's easier when you're doing, you know, I guess, but I guess is often just one side of the equation. If you want to be able to bring in these newer identity security technologies. That's one reason I want to emphasize the identity fabric.
You know, there are standards out there that allow for interoperability look for products that understand those standards so that you can add on these capabilities as needed. So, any, anything you want to Yeah, that's probably the key challenge is we talked about kind of data as one. The key challenge I hear today from IAM practitioners, mainly not so much even security, mainly IAM practitioners. On the kind of identity operational side of thing is the time to value. IGA deployments take for ages, very hard to justify for the business, the investment and so on.
And that I think is the key, maybe changing in the concept or kind of key things that the industry can change now of having new products out there that can actually shorten the time to value. Can shorten the time to value from the time of implementation by making sure that you really kind of collect data from multiple sources, etc. in a much faster way. That's something that, again, we pride in at Sonya's. The second thing is we just mentioned is also AI. By the fact you apply AI, you can also shorten the time to value by a lot.
By, for example, recommending new rules, recommending role mining, you can actually reduce the amount of kind of role mining exercises that have been going on for months and months to a much, much faster cycle. Even the comment I made before and like doing smart access reviews. So making sure your access reviews are actually more up to date, more leveraging kind of the true provisioning of permissions within the company can also help you realize that the faster time to value.
And that's what I would say is the thing that we are hearing most with every customer we're speaking with on how you can help me reduce the time to value of my IGA program. It's not necessarily kind of, like you said, it's not necessarily like a greenfield approach of how we put a new IGA foundation in place in a shorter time, but even with existing IGA foundation, how we can realize shorter time to value of our processes and our program.
Yep, very well said. So we're at the top of the hour here and just highlight some research that we've done on ITDR and also identity fabrics and also say that we're getting ready to kick off updates on ITDR. So look for that in about five or six months. This is a very exciting field and we're going to have quite a few more vendors participating than last time. So please stay tuned for that.
And just, again, wrapping up here, I wanted to thank Amir for being part of this today. I think this has been a really fun conversation. Hope you all, the audience, have enjoyed that. And feel free to reach out to us if you have any questions or want to continue the conversation. We would definitely like to do that.
Thank you, John. I enjoyed it a lot as well.
Well, thanks, everyone. And again, this should be available in a couple of days, the recording and the slides. So have a good rest of your day.
See All Locations
See All Locations