Welcome to our next panel discussion. The topic for this one is identity-centric security and how to separate buzzwords from useful stuff. Don't you think that kind of identity-centric security on its own is a buzzword? And this is why we have a distinguished lineup of speakers to discuss, to dig into this problem. And let's start by letting you guys introduce yourselves. Happy to start.
Hello, everyone. My name is Guido Grillenmeier. I'm the principal technologist at Semperis. And we as a company protect your on-prem and cloud identities and backup and vulnerability detection. And of course, like our panel will discuss, there's a lot of buzz as to like how to proceed to really be safe. Not an easy world. Plenty of solutions here. And we'll try to get some sense into that. So everybody, my name is Gal Diskin. I am the head of the AI labs at Delinea, which I guess is fairly well known in this audience. And that's pretty much it.
Hello, my name is Matt Graves. I'm coming from Charlotte, North Carolina. I work for OpenText. I'm a CISO and previously a CISO. And also a practitioner for almost 28 years doing this business of security. So I see a lot and hear a lot from customers and partners. I was once a consultant. So I played all three sides of the table. Now I'm on the vendor side. But I've heard a lot of these pains. Dealt with a lot of these pains myself. Have the scars from it. So I can speak to it with some authority. Andrey Pribyl, I'm the CTO of IC Consult.
So happy to be here on stage with three of our partners talking about identity security. Because as we are completely focused on identities, it's about not just protecting applications, IT assets, resources, but of course, also identities.
And yeah, therefore, very excited to have the conversation together with you here. Okay, so we have started our previous panel discussion with an elephant in the room, AI. I guess let's kind of stick to the same tradition. So the first question will be, so what about AI behind all this kind of identity-centric security buzz? Is there anything valuable behind it? How does it fit into the IIM story? And I guess, Kyle, could you probably start? I'd love to. That's my area, I guess. So I think it's very important when we talk about AI and identity to first distinguish between two different areas.
One is, how do we secure or protect AI? And two, how is AI used in identity products to improve them? And it's very important to make this very clear distinction first, and then deal with each of these cases separately. So when we think about how do we secure the use of AI in our companies, it all starts from discovery. And the identity team has to have a seat at the table. It actually has to be one of the key players that decides on who has access to these identities, right? Because permission management is at the basis part of what we do in identity.
And managing the permissions to the LLMs, to the agents that are being used across your company, is really important. Also, discovering those and applying the right governance, saying, OK, these models are too risky for us because they expose us to an IP risk. These models have too much hallucination or too much bias. So having these type of controls and every company is creating their own AI governance body, a governance committee, and managing that is really important. And there are products coming out to do that across both our industry and other industries.
I believe it should come from the identity products. So this is one area that is really important. And managing the entire lifecycle. One of the things that I think a lot of AI solutions were hastily built, and they are not using proper management of credentials. And this is also very risky. And you should look into that in your companies and the way they use AI because eventually, you don't want to be part of a breach in that sense. So this is on the side of securing the use of AI. And then securing with AI how AI affects identity products.
This is where I see a potential profound change in a lot of things. Because I think in a lot of senses right now, there are things that we can't do. For example, if we think about privileged access management, then we can't really review every session recording, right? Because it's not humanly possible to have a person review all the minutes of the session recording of every session that was actually done. But it is AI possible, inhumanly possible to do the same. And that's actually something that actually exists out there in the market for my company and maybe others.
And similarly, it is not possible to review every identity, privileged access request, privileged elevation request, or secret access request. But it is possible for an AI to do the same review, right? It is possible for an AI to go into the business system and see that the ticket actually exists for this person to handle a problem for this customer, for this specific need, right? And it is possible for an identity system, for an agent to do a security review before granting the access. All of these things a human could do, but it wouldn't be possible in terms of scale, right?
It's not the story in 1984, but we can actually apply these principles in reality now. So I think it's really a very exciting era where things that were impossible for humans, not practically to do, but at scale are now possible and will become part of the way of life in our industry. So I'm very excited about that.
Yeah, and maybe to add to that, I like that approach of separating it into different topics. And when it comes to the bus around AI and security products, I would distinguish into, well, that part of AI that is leveraged by security products since decades. So machine learning, detect outliers, these kind of things, also building decision trees in order to detect threats in a better way.
And then, well, everything related to gen-AI, agentic AI, because I completely second your point, it's about scalability. We are able to do things at scale we were not able to do before. And I think that's really kind of a game changer and something what we have to leverage as security professionals, as security vendors, because attackers are doing the same, right? Yeah. And let me just add a different angle to that whole topic, because I believe it's one thing that our tools need to evolve to utilize the new technologies in a good way, and of course, fight the bad guys that are doing the same.
But in general, the problems that we are seeing these days with AI is that they show where just basic good security is not being put in place, where people don't tag data properly to market what's sensitive, what's not. The normal user might not even utilize data that they have access to, because they didn't even realize that they were permissioned to do so, because they never needed it in their everyday work.
But when you then have a gen-AI tool to support you in whatever type of question that you ask it, and it has access to all the data that you have access to, it suddenly can reveal secrets and make things available and publicize them potentially that you had no idea that you had access to. And that is basically where the standard permission settings, standard tagging of information, what's sensitive and what's not, it's just not been done.
So that goes into other areas as well, where standard permissions are not used to well protect stuff without even needing a tool to protect you, just stick to the basics, and then you can also get the best out of the AI tools. I would agree. I think there's an important distinction here about application security leveraging the scanning of the code that's being written for those tools, those AI tools, to be able to leverage the identity correctly.
When you're doing those scanning of those applications, are those, is the code being written in a way that's leveraging the identity appropriately and for the just-in-time access or the zero standing privilege, again buzzwords we're talking about, that that AI agent, the agentic AI, only has the access that it needs to do what it needs to do at the time it needs to do it for the amount of time it needs to do it. I need to take a breath between that whole sentence, but yeah, a lot in there.
I would add to your point that it's also very important in cases that it's reflecting the user request, to your point earlier, that the permissions are enforced down the line, which is what we see a lot not actually happening. Yeah, and looking from a different perspective on that, so when it comes to large language model, agentic AI, putting guardrails into place, that's a huge challenge and I think we as identity and access management experts have to do our part to contribute to that story by bringing authorization in place.
So that's a one dimension, the kind of guardrails thing we have to put in place around the agents. By the way, so if you're kind of going back to discussing general AI in general, pardon the pun, if we take kind of every vendor's claim at its face value, general AI will basically do everything, solve everything, and it's completely easy to use and to deploy. From your experience, especially to the veterans like you, Matt, are there any ways to kind of actually differentiate those buzzwords, those false claims from real things that general AI can actually provide?
Yeah, I think I get this question asked quite a bit actually, and I don't want to use the consulting answer of it depends, but there's an important distinction to make and a nuance here as it relates to that question. The value to an organization in any of this is really, I wouldn't say primarily dependent on, but it is dependent on the size of the organization, the risk appetite of the organization, what is the organization trying to, what is the business that they're in, what is their industry, all of those things come to play.
So you could say, yeah, it depends on, quote, all those things that I just mentioned. Once you have that established, then it's really back to the guiding principles of identity to begin with, right? Know and understand your requirements, the scope of your requirements, how big they are, but also zero trust. We all talk about zero trust and have now for several years. So it's that concept that works for almost everything in security, not just in identity, but then you look at how to measure, right? What do you want to measure to show that it's successful?
So lots of things involved in answering that question. And I would say, depending on the person that I'm talking to or the organization that I'm talking to about it, I'm qualifying where their pain points are, where their issues or solutions might be to be able to show what is the real value of some of this buzzwords we're talking about in terms of an organization, your size or in your industry or in your regulated landscape, right? Those types of things. But certainly I have many, many examples to speak to as it relates to this. Non-human identities is a great example.
We talk about that here with AI. I would say this concept of just-in-time provisioning or zero standing privileges, this is only the access that you need when you need it. Non-human identities, there's no better example than how that can play into this conversation as well, right? So you have one identity as a carbon life form in an organization. HR knows you as a certain title in the organization. You have a certain job role. You have certain privileges or entitlements or permissions that you have.
But now you also, because you connected your calendar to this third-party service called Calendry. I don't know how many people know what that is. Or you have another third-party thing that you decided you want to do with your email or your scheduling thing or your Salesforce or whatever tool you want to use and you connect it to something else just because you can. Your organization doesn't know about it necessarily unless they're scanning and monitoring for that sort of thing.
So there's lots of ways to example the value in controlling and governing access to applications and services that we could talk about a lot longer than we have time here to talk about for sure. In general, I'd say it's great that AI exists because it basically took away the buzz for zero trust, right? So we have a new buzzword.
But yeah, we need zero trust no matter what. That's the whole point. And providing that to your AI tools might just be the challenge. Yeah. So from my point of view, when it really comes to understanding the value, yeah, it's not easy. You have to understand your current landscape very well. I like to use three dimensions for that. First dimension, taken from zero trust, are the different pillars. So identity pillar, device pillar, network, and so on and so forth. And that's the first dimension. Then the second dimension are the phases in the cybersecurity framework.
Are we talking about identifying? Are we talking about protecting? Are we talking about detecting an attack, responding to it? Or are we talking about recovering after an attack, right? So that's the second dimension. And the third dimension I have to look at is really the scope I'm talking about. Am I in my Microsoft ecosystem? Am I talking about SAP? I'm talking about my workloads running on AWS, on Linux, whatever. So what do I really cover? And based on these three dimensions, I can really figure out the solution I'm looking at.
The problem I want to solve, what of these dimensions are covered by that? But also, where are my white spots? What are my capabilities? And then really understanding, hey, what value do I get out of that? But honestly, it's not an easy exercise. And we as system integrators, as vendors, but also analysts, I would say we're not making lives easier as we love to use that kind of buzzword.
Hey, we are providing zero trust. We are providing ITDR. And at the end of the day, we are talking about completely different things, right? And that's something that is, well, important to have that kind of understanding to drive through that landscape without having redundancy or not getting the value from my organization I would like to get out of that. Yeah. If I put my CISO hat back on for a minute, I think about the policies and the controls that I influence in my organization to protect the environment and protect the crown jewels, protect how we make money in an organization.
If I put that hat back on, I want to know that the controls are operating effectively. And these types of controls that we're talking about with identity can be tested and should be tested constantly to ensure that they're operating effectively. And then you have this risk mitigation already built in if the control is operating effectively and you can prove that it's operating effectively. So that brings the additional value to me as a CISO in an organization about how these identity controls are operating and working in my environment. All right.
I'm not sure if it's maybe a tricky question to ask, especially a person from a vendor company, but can you maybe give us an example of like a red flag, a buzzword, which whenever someone hears in a sales pitch, they should immediately stop and think twice and kind of look for, like, dig deeper to understand if it's really worth it. I heard one today and there's like, what? And this is AI authentication.
I mean, wait a minute. AI authentication. Let me think about what that means for a minute. It took me a while to try to dive deeper into that conversation to understand that better. And it was not so much authentication as it was more about the verification of the person, right? And then I get into this quandary about, okay, are we talking about proving, proofing? Are we talking about verifying? Are we talking about validating? Because I don't know, in the English dictionary, those three words mean three different things, right?
So proving something is you have a physical passport and you can hold it up to your physical face and you know that those two things are linked, unless I'm wearing a mask, right? Then you have to validate that the passport is a valid document. Was it made by a government agency and is it valid, right? That's a valid thing. The verification thing, we've been doing verification for 30 years with identity. You're validating, excuse me, you're verifying who you are by your credentials that you're logging in with.
And then we came along with MFA to step up that another level to be able to get us there. So now I heard this concept of AI authentication today and it was like, okay, well, help me understand what that means. So it encompassed all of that in the conversation about, I could log in and not even know I'm logging in because AI is doing all the authentication for me. It's proving, it's validating, and it's verifying, and I'm in. And now the governance of that is somebody has to attest that I'm supposed to have those rights, those authorizations as a result of being authenticated by an agent. Yeah.
So I think that this is a very important thing, and it's also very important to think, so what is a very big red flag for me is whenever somebody tells me AI something, right? AI something doesn't work. Tell me what is the use case and how does your AI help achieve this use case, right? So if the use case is you need to review the session recordings, AI can do this better.
Okay, I can buy this, but I would never buy somebody that tells me I have AI in my product. This is like my red flag personally. My red flag more generically is if any company out there promises you 100% security, because that just simply doesn't exist, yeah? We can all work on reducing risk. That's what we do, yeah? And reducing the likelihood of an attack or to get back on your feet if things really go bad. But there is nothing like 100% security. That's something that we all realize every day in the news.
And the bad actors are sometimes it just seems like they're always a step ahead of actually utilizing also the new tools in a negative way, you know? AI code to generate malware is active out there, yeah? And it's very efficient, yeah? So just do as well as you can to reduce your vulnerabilities, but they'll never be zero. Even with zero trust, there's zero days, yeah? And the zero day vulnerability is something that we even know about, and then there's plenty more that we don't even know about, yeah? And never been used. So you have to add to your protection level, but it'll never be 100%.
So whoever promises that, that's clearly a red flag. Yeah, I agree to these points. And I would add, so typically, and I know that vendors don't like to hear that, but typically if someone is saying, yeah, we have that unique feature, nobody else is able to do that. Only we can do that, yeah? And if this comes up, then there are likely two reasons. One reason maybe, yeah, because nobody's doing it because it's irrelevant. It doesn't provide any value, right? That's the one thing.
Okay, then it might be just not true, yeah? And the other thing is then, please explain to me in layman terms what you are doing, yeah? And if I don't understand it, yeah, then it's also likely not worth investing into that, yeah? So if they can't understand the concept, the idea, what do they bring as a value, how they are doing, achieve it, just saying, yeah, our AI is doing it, then it's likely not good enough to really spend time and effort into picking it and try to understand it.
Yeah, but Andrei, one thing, sometimes the feature is on the cutting edge from the product side, right? And then maybe others are not doing it yet. It's not that they are unable to do it, but they don't have it yet.
Okay, well, that was awesome, I think, and basically it all boils down to, again, zero trust means zero trust for anyone and everything, including vendor claims. And in that regard, thank you very much. A round of applause for our panelists. If anybody, yeah.