So, I thought, so one, I want to sort of thank the conference and the organizers, KuppingerCole, because I think I got added last minute, so I was actually pretty curious as to how many people will show up, you know. So, as I was introduced, I call myself PG because my name has two R's, and it can get quite tricky to pronounce my name, and I didn't want to subject you to that. A little bit about myself. I joined One Identity a few months ago as the new CEO for the company, but I am not new to the identity space. I was part of the team that built Active Directory at Microsoft in the late 90s.
How many people use Active Directory or have used Active Directory? Okay.
So, I want to start by apologizing to all of you. So, you know, my only, you know, I think I've subjected you to a lot of pain over the years. My only excuse is that I, it was very early in my career, I had no idea what the hell I was doing.
So, that's my only excuse. But that was not the only thing I did in identity. I also ran all of AWS's identity and access services. How many people use AWS services?
So, AWS IAM, Secrets Management, AWS Organizations, many of those services I was responsible for and part of building. So, One Identity is sort of a homecoming for me in a lot of ways. One of the things that's very interesting, 30 years of being in the space or seeing it from the sidelines sometimes in my career, is how the identity space has evolved.
You know, 30 years ago, when we were talking about identity systems and building directories, the focus at that time was very much about inside, like we talked about least privileged and granting minimum access to users inside the organization. And in those days, we still had firewalls, we still had corporate networks and definitions of corporate networks.
And so, a lot of the focus was, hey, the malicious insider attacks. That's really where we worried most of the time, right? And it's super interesting, 30 years later, as we look at IAM and what has really happened, right? It's a whole new world out there.
Now, when you look at breaches that are happening to organizations, even from outside, right? The vast majority of them, over 90% of them, can be traced back to essentially an identity breach, right? So the world has dramatically changed from the world that we originally built identity systems and talked about IAM and what IAM's purpose was. We've come a long way, right? And it's actually getting worse and worse, right? Like it used to be, just a year ago, it used to be that it would take a pretty, like several hours for somebody to breach into the system and be able to exfiltrate data, right?
That number has gone one-fourth of that. Like it's now down to about an hour, right? And the cost of a breach is just dramatically rising. And when you connect them back, right? Now you think about IAM systems, it's not just about the malicious insider. Now this has become the security perimeter for the entire organization.
And so, the world is a very, very different place than what our original identity and access systems were built for and what has happened, right? You can actually look at, it's like when a breach happens, it takes a long time for organizations to clean up from that breach, right? The vast majority of IAM programs, if you actually ask the organizations, they struggle to keep up with them.
So, like we're in a very different world. So, what's happened? What has gone on, right? I think COVID and the cloud have transformed organizations. There is no such thing as a corporate firewall anymore, right? The corporate networks have dissolved in the context of a hybrid environment. And you look at IoT devices, the cloud is basically, and people have started working from anywhere.
So, the notion of corporate firewalls and physical locations don't really exist anymore. So, we're in a very, very different world. Then the new thing that has happened over the last couple of years is AI, right? AI is further accelerating that change in identity and access systems, right? Now we're talking about non-human identities. Back 30 years ago, we used to talk about service accounts, right? And worried about service accounts. But now non-human identities are orders of magnitude more than just few services running in your organization.
Now we have non-human identities that are acting on behalf of users and we have non-human identities that are autonomous running in the organizations with AI agents. So, when we think about IAM policies and we think about governance, it's a whole new scale of problem that we're dealing with in organizations. And just like with any technology, AI is a classic case of that. The bad actors are using the technology even faster than the good actors are using the technology, right?
So, you find that the AI is being used for those social engineering attacks, the deep fake, the phishing attacks, right? Like you look at those things, it used to take many hours at times to build a viable phishing attack. Now using AI, these bad actors are able to, within minutes, create very, very convincing phishing attacks and breach the attacks through the organization, right? Large language models themselves are getting attacked with that. And at a speed that is pretty scary, right? When you look at it.
The geopolitical climate is only making it worse with state actors now funding those kinds of things. Shadow use of AI in organizations is also creating attack surface where because you don't have control over what employees are using and what they're doing, that attack surface is actually climbing and becoming harder and harder to manage.
So, how do you think about all of this? How are you thinking about it? Anybody has a thought in getting your arms around? Quiet.
And so, what we did is we're starting to think in terms of how do we create a maturity curve for organizations? How do we build tools on this maturity curve, right? Sanjay in a previous talk talked about this autonomous IM, right? And you notice on the spectrum, autonomous IM is sort of like that is a very aspirational goal to get ourselves to, right? Most organizations still live in this place which essentially kind of in the 30-year-old world, they're in a very fragmented place where their tooling is super fragmented. They have no unified view of identities in their environment.
They don't even have proper programs for dealing with human identities like forget non-human identities like joiners, movers, levers, right? Organizations that are getting somewhat mature, right, are in the controlled space where they do have a set of tools but most of it is super manual. And what I observe coming back into the space and being one identity is when you look at organizations that have gotten to the control state, tend to be organizations that actually really worried about insider attacks.
So, banks, right? Like some of our biggest customers are banks because they actually build an identity and access program over the years because they're really worried about insider attack. But most of the organizations never really thought of IM programs for protecting against the outsiders, right? And the surface area is actually getting worse, right?
So, banks that started building and most organizations end up stopping at control, right? Now we have customers in financial institutions that have moved to start talking in terms of an integrated surface area where they've taken their identity and access tools and integrated them so they get complete picture and they can actually see the signal, they can see breaches happening and they can react to that but it's still a matter of days, right? And now the speed at which these attacks are happening, we need to do a lot better than that, right?
Days is not good enough because the fact is exfiltration of data is now happening in hours, right? And so, the next phase of that which is I think where now with the technologies that are available to us that we can enable through our products is what I refer to as intelligent level where we have knowledge, we have information about the systems where we can see the breach happening, we can actually prevent it in many cases and if it does still happen, we can react to it in a matter of hours, right?
But the place where we all have to get to is that autonomous place and I've still framed that as aspirational. I don't think our systems are really designed or capable of getting to that place but when you now think about autonomous AI agents in our environment, we can truly imagine ourselves getting to a place, we can imagine our systems and our software getting to a place where we can leverage the autonomous AI agents to be able to do that in a self-healing way where we can detect it, we can clean it up, we can prevent it, all of those things autonomously done through AI agents.
So, that's where we need to get to. It's going to take us some amount of time to get to but that's the goal, right?
So, that last phase is I'll put it as an aspirational right now. Hopefully, when I come back next year and we have a conversation, we have the technology and the tools to actually help you get there but it would be great for all of you, for your organizations, evaluate where you are. You can absolutely get to intelligent. You can eventually then get to autonomous but if you're not as intelligent, your chances of getting to autonomous are very low, right?
So, I thought I'll share this curve with you and think about giving you something as a framework to how you evaluate yourself and get there. Thoughts? Reactions? I don't think we have a choice is the way I'll describe that. We have to get there and the good news with technology is it's that now we have technology and capability to get there.
Now, whether we have the time, I think because we eventually have to get there, I think it might cost us getting there in the interim but we will get there, right? I'm an optimist. I wouldn't be doing this for 30 years if I was not an optimist but I think if you get to intelligent itself, which is possible today, the tools are there and the technology is there, it's a huge step, right? And I encourage all of us to look at our organizations and can we actually get there because I think most organizations are still very much at best in a controlled state and that's not good enough.
I didn't want to give you a big presentation. I wanted to actually engage the crowd. Other thoughts? I think all the time because of the lack of speed, the thinking about either speed in enterprise, it's become, okay, we're going to integrate systems, then integrate systems takes a long time. Thank you.
So, yeah, just to elaborate on my question about the speed. I think the identity teams in general have evolved not voluntarily but as kind of a ivory tower inside those companies because it takes a very long time to integrate different applications into the system and to the identity governance and et cetera. And so what happened is that you had a lot of ungoverned applications, especially when you look at SaaS and cloud, which have already not been resolved properly inside that system.
And what we see with AI is just the next wave of that with even more than just applications, agents that are coming in and doing all of that. And so whether we wanted it or not, the identity teams are kind of sitting in their ivory towers, not really dealing with that mass of things happening on the site. So when I say do we have time, it's actually as the identity category, I would say, can someone faster with not in their ivory tower get that topic before we get it?
And then we have to work with whatever new category is being created there, doing that faster at a different layer, a different part of the organization structure. Or is it on our side to do it? But if we have to do it on the identity category, do we just have to do it much faster than whatever we've been doing before? Because cloud is already an issue and it's not been solved, right? Right. So let me say a couple of things.
I think I, so when I talk to customers and I talk to the IM teams that you talk, I don't feel like they're sitting in some ivory tower in their defense, right? I think to your point, the enormity of the problem, right? Number of applications are growing, right? The technology is coming at a speed that it is, right? So I think to be fair to them, what I find is that the enormity of the problem really that they're dealing with is just larger than we as an industry and we as vendors have actually helped them solve, right? And so they need help, right?
I think when I talk to customers, they are very much in that place where they need help, right? That's why I started with the place where we built IM systems mostly focused on malicious insiders, right? And the application surface area has just rapidly climbed, right? Cloud came around and SaaS applications came about. And then so the surface area just climbed around them. And now they are dealing with those inside applications and the cloud applications.
And soon enough, right, as you point out, they're dealing with now AI agents and autonomous AI agents because the business needs to, continues to push the value chain on those things, right? Because the productivity gains from leveraging those applications continues to drive the business to want to adopt that. So I think it's somewhat of it is upon us, the technology providers in the IM space is how do we help our customers, right? Like the previous session, I was listening, I made notes from it.
It's like, oh, how do we leverage the same technologies to help our customers get there faster, right? So I think it's as much an onus upon us and opportunity for us to serve our customers in that regard. Yeah. But we have to get there, right? I don't think we have the choice. I don't think our customers have the choice. We all have to get there because unfortunately, right, the geopolitical landscape is not helping either in that in terms of slowing this down, right?
And as one identity, like one of the things that we pride ourselves is like we are a very European company and Europe is sort of one of those places where a lot of the concern around this is very real, right? So that's how I think about that. Other thoughts? Anybody else? I don't want to just be sort of spieling at you, right? It's not as much fun. I want to hear your challenges, your concerns, and then we can have a dialogue about it. Yeah. Just a thought.
Looking at this maturity curve, I think for an IM professional, this might be more helpful outside the community towards management than inside the community. Because I think outside the community, there's so much talk about AI doing everything and us being able to reduce jobs and so on and so forth. But in order to capitalize from AI, you need to have reached a certain point, right? And I mean, to some extent, looking at the beginning of the curve and looking at the reality, telling someone who's in this fragmented space, oh, use AI, it's going to solve your problem.
That's a little bit like handing a computer to a caveman, right? So management need to be educated that you need to have a certain level of maturity in this topic, like with all other topics, to actually be able to use AI, to make it autonomous. And I think that's really the debate. I fully agree that we need this sooner than later. But I think we also need to kind of be in a situation where we make our bosses understand that this is not something we can do at snapping our fingers or something. That's all I have to say. Very true.
Prior to coming to One Identity, I was on the executive team of a publicly traded company, right? And it's a board level priority, right? So the requirements around regulations and for a publicly traded company and the assets you have, it's a board level audit that is done every quarter.
It's like, where are we with respect to our IM program, with respect to the policies we have and the governance and the certification of access that people need to, right? Because the organization is constantly evolving. New people showing up, people leaving, people changing roles. And now with applications and software coming in. So organizations need help.
And you, in this case, Alpha, partners like you are pretty critical to the process of helping organizations get there. But I think another challenge we have with IM space is the complexity of the space is so large. It's only people in this room likely understand it. People at the board level don't fully understand and grok the problem as well. And so they need help. With respect of time, I would like to cut it down here. Great. Thank you. Thank you very much. And thank you for the questions and thank you for the interaction. And thank you very much, PG. And I also have two R's in my name.
I know what you're talking about. So thank you very much.