So my name is Joseph Carson. I'm the Chief Security Evangelist and Advisor at Segura. I've been in this industry for a long time, even though I look, you know, very youthful, based in Tallinn, Estonia. So I was one of the architects in helping Estonia build their digital identity infrastructure.
Hi, I'm Steve Hutchinson. You can call me Hutch. I'm the Director of Security Architecture for Mitsubishi Bank at Tokyo. I actually presented earlier this week on Wednesday on ITDR. Very good. And I'm Rob Ainscough. I think most of you were probably in the room 20 minutes ago. Chief Identity Security Advisor at Silverfort. I've been in identity a long time, formerly Head of Identity or Head of IAM at Tesco in the UK. I've been there for about 10 years. Right. So maybe like, allow me to start with a silly analogy.
Like 20 or 10 years ago, we used to have this thing called big data, which was expensive, complicated, and completely separate from the rest of data. Now it completely disappeared. Everything is just data, but everything is also big. Do we have the same convergence with privileged identities? On the one hand, everybody is now privileged, and we have agents and whatnot, NHIs. So complicated. But on the other hand, if everybody is privileged, it doesn't mean like nobody is. So how do we tackle this things disappearing border and the whole environment becoming a gray zone?
So, yeah. I mean, I can start with my input into it.
Yes, everyone has privileges in some fundamental way or another. They have access to email, they have access to file systems, they have access to cloud applications. I think we look at it, sometimes just like we do with AI, we look at it too much of a broad perspective. And just like when we talked about big data as well. I think about privilege, we really need to start focusing on as risk.
And that's the most fundamental thing is that, yes, while everyone has access to something in the organization, even third parties, we need to start correlating it back to what is the potential risks or potential outcomes that those entitlements and access gives the human, the agent, the process, the workload, whatever it might be. So we have to fundamentally think back is going back to risk assessments understanding about what can these do in the environment.
So I think even earlier, one of the sessions I listened to with Martin and Enrique and Laura was around zero trust and getting into the recertification side of things. And also kind of comes back to that as well as that, how do we make sure what the outcomes of these access have and should be persistent as well.
Yeah, I would say that just what we keep talking about identity is the new perimeter. And we said that first back in 2012. So the perimeter is collapsing, but not only is the perimeter collapsing, but I think your statement is correct that our concept of what constitutes a privileged access is also collapsing, which is why we're seeing now the rise of more ephemeral identities to represent privileged entitlements and the use of those with just-in-time things to kind of limit the blast radius of what's being used.
And using, and I saw it, I was happy to see in your presentation, leveraging more continuous access evaluation protocols to monitor that risk. And kind of special shout out to anybody who's working on the shared signals foundation work that's going on in the OIDF. If we're going to talk about ITDR, we need to talk about how we're going to leverage those standards and those signals to do things like bring context back into those decisions.
Yeah, and I think just kind of echoing points you both picked up on there, the way I see it is with today's threat landscape, I think the old distinctions we've had over like access management and privileged access management, they're going to collapse in my view. And I think the thing I think about is the difference between protecting identities to protect things versus protecting things that matter through identity.
And being centric about what your business cares about, what's really important to your business, how you're setting guardrails, how you're really understanding how that's coming to life and what it means for your business. And that's something that I think about a lot, which is kind of a different conceptualization kind of brings that big problem down a little bit in terms of what's really important to our business.
But I think for sure those kind of walls and silos are coming down and need to come down further, I think to your point, Hutch, to kind of make us effective here and make sure we're bringing in all of that rich context that we can from across identity and elsewhere as well. Right. So when I am attending events like this, I hear a lot of highbrow discussions, theoretical, philosophical, introducing new concepts and whatnot. This is great, this is moving the industry forward, but not everybody gets that immediately.
On the other end, and I'm coming from the developer's background, I hear a lot of very technical, very practical and very confused questions. How we do implement it from below? What's completely missing is this kind of middle tier, if you will, the organizational one, the process, the risk management one. How can we help to close this gap from both direction? Do we have to start with like really basic stuff, like ditching old confusing terminology like PAM and inventing something new, which better explains the whole thing?
Should we kind of marry two separate teams, one dealing with identities and the other one with security and say, now you do both? Or are there more practical, more sensible ways to do it for a real organization in a real realistic time frame? It's a big question, right? It's a big question.
I think certainly, even from my perspective, where I think about the, and we touched on this the other day at the breakfast, you know, the proliferation of acronyms that we've got and different facets and sub areas of identity, you know, is that helpful to helping your business understand what this means, what needs to be done, what's important? Absolutely not, right? In some cases, I'd say it's not that useful for us, in fact, right, as practitioners.
But I think it's about coming away from that technical and coming to the implications and helping your business understand as far as you can that pretty much everything you do as a business operates through identity, right? Whether it's your human employees, your future agent workforce, or your systems talking to other systems and delivering business outcomes, they've really got to understand that that gets delivered through identity. The acronyms of how we do that, absolutely not helpful in explaining that and what we need to do.
But I think the base concepts and bringing it back to something they relate to and what it means to their business, right? That's really, really important for me. But I know it's a challenge that we see across many companies in terms of explaining this thing. It's a difficult one. Not only that, as we do with a number of different projects within IAM, we tend to look at, okay, what is it going to take to fully implement this? And the scope and scale of what you need to do is awe-inspiring and can be scary. Yeah. And then people feel like, well, I can't get that done, so I'll put that off.
You can start small. And I think I said in my presentation that implementing ITDR is a maturity process, moving from the telemetry that you already have today. It's just in – normally, it's in silos and things.
But also, picking partners to start with. And I think the SOC is a natural partner in the beginning. A SOC – you said it very eloquently in your presentation. But the SOC is an organization that understands how to do monitoring, how to do alerting, how to build playbooks for containment, all the things that identity needs. Identity needs to teach the SOC how to correlate all those identity events to network events, to business systems, to networks, to all those things.
So, the acronyms, not important to teach except to explain what our telemetry means and what are the best ways to correlate all that data together to build things that are going to result in our ability to quickly contain, do attacks. Absolutely. I think I always remember one of the lessons I learned in Estonia was they take a very much a service-defined approach to things. They look at everything as a service.
And I think that's ultimately what we need to be doing, is looking at ourselves as a service to the business and correlating it back to what the business actually demands or needs from us. And I learned a very valuable lesson in this whole process that some of the most meaningful conversations I've had, it means that, yes, we have to leave all of our terminology and acronyms behind us. And when we're communicating with our peers, whether being in the finance team or the executive team, we have to translate into the language that they understand.
And some of the most meaningful conversations I've had is typically with the CFO. The CFO understands risks, they understand finances, they understand business risk as well, kind of comes on to how much they're willing to mitigate and spend to reduce risk. And ultimately what it comes down to is when you're working that scenario, I think there's going to be also a big convergence as well as that when I have the conversations about reducing fraud with the CFO, they get excited. If I talk about adding an ITDR system in, they don't get excited.
So what I have to do is translate what does ITDR mean in reducing fraud to the business? And there's a direct correlation. ITDR can reduce the number of potential financial impacting incidents. It can reduce the number of potential penalties from failure of compliance. So we had to start looking at about how do we translate those tech and acronyms and tools into something that's meaningful to the business side of things. And that's what we had to become masters at.
We really have to make sure that we're able to translate that and go back to I think when we're looking at bringing identity into the SOC, it means we have to add the identity skill, whether it being an agent skill or whether it being actually having somebody who's been trained in identity metrics and monitoring, we have to bring that to the SOC because they become the eyes and visibility and transparency of the business when it comes to alerts and knowledge. Right. If anybody in the audience has a question, please raise your hand.
Otherwise, we can just kind of tackle the invisible elephant or like very visible elephant in the room, the AI thing. So everybody's now talking about AI identities, AI security, AI whatever. And I think a lot of companies just feel that this is so new, this is so greenfield that we have to build an entire new stack of supporting technologies, including the whole identity stack. But is it really true? Hopefully not. How do you explain that to laymen, if you will?
I think a great example, if you look at Joe's presentation, talking about here's an accountant who's now leveraging his rights and his entitlements in a way that one, he's never used them before. So two, we never worried about him before, but now that identity is being used in ways that we didn't think about. I think the, not the danger, but the complication in AI is solving that problem. We're so used to, I don't want to say in a bad way, but we've been lax in our governance of entitlements and overprivilege and those things because we've allowed to, been allowed to.
But with what AI brings is not just the intelligence of like a mythos, which is actually chaining together a whole bunch of different exploits, which is scary. But just regular AI agents who are just trying to get, I've been told to do something, I'm going to go do it and I'll do whatever I can do to get to complete that process, which may mean leveraging entitlements that I've been given that we didn't intend for it to go after. So there's a huge amount of work that we need to do aside from just AI, but actually going back and re-reviewing all of our entitlements.
And the ironic thing is those entitlements have grown to such an extent that we can only use AI to be able to go through and evaluate them. And a thing AI does better than any of our human identity personnel is being able to go through millions of lines of entitlement data to start to pick out, okay, you're really over-provisioning some of these.
Yes, if anyone's ever done that, like myself, going through tons of logs and entitlements to find the one that's causing the problem, AI does it way better than we do. So what that fundamentally means is that we need AI. In order to scale and accelerate at the pace we need to, we need AI, but also AI needs us in order to put the governance and rules in place and make sure that it's only doing what it should be doing. To answer your question, do we need to re-completely change? There's certain areas, yes. Fundamentally, when I looked onto the very basis, I run my own agents.
I've got a ransom negotiation agent, which is a lot of fun to watch when it's arguing with other, you know, ransomware guys. Just watching that conversation, it's just as good as a documentary. I'll make a Netflix documentary out of that agent, that's all. But when it comes down to it, at the very basis core, it's just another service account, application account that has access.
The fundamental thing is when it gets chained together and it starts, when you start giving it responsibility and accountability, and then you start getting into the verges between, is this something that is legally binding versus a workload versus just a simple task or skill? This is where fundamentally we have to start understanding about the responsibility. I think responsibility is one of the key things that we probably need to start looking at much more when we start seeing AI agents growing.
Because ultimately, is this an agent that's got legally binding potential contracts, which means that we have to tie it back to accountability of Hubert's delegating that task to the agent. So I don't think we need to reinvent everything, but I think we fundamentally need to look at what unique things that authentic AI and agents are bringing when it relates to identity. And I believe the big area is governance, and accountability and explainability. Those are the fundamental things. If you look at the EU AI Act, that's what it raises.
Risk, accountability, explainability, and responsibility. And that's what we need to include as we build it into our environments. I'm probably pretty simplistic on this, because at its core, do we need completely different capabilities for this agentic change and revolution than we have previously from an identity perspective? I don't think fundamentally we do. Maybe they'll be expressed in a different way, but fundamentally we still need to have a way of controlling the life cycle. We still need to have a way of allocating appropriate privileges.
I think, Hutch, to your point, the main thing I thought as Agenta was coming out probably a year ago was really what it has the potential to do is expose those years of difficult history when it comes to identity that maybe we haven't got right. Those building blocks that maybe not everyone has in place to then build on top of and deal with this new world and the new challenges. So I think there is a challenge for some companies where maybe the past challenges haven't been easy for them.
But I think it also puts a real onus on being much more dynamic, being much more real-time about our controls. It really, I think, is a forcing function for making us think in that way, because it's non-deterministic. We can't predict it. We can't explain it in advance. So I think being much more dynamic as it happens is going to be really, really key from so many perspectives. So that's something that is enhanced over the top of what we're already doing that we need to make sure we continue to do really well and probably better than we have in the past. All right.
Just to add to that, I completely agree. One of the things that we also have to think about is the skill, is that right now we've been used to human identities with a certain direct relationship to normal employees, and we move it to non-human identities. We saw the skill of that to 100 plus to 1 now. And we add agentic AI and AI identities, that skill is just going to be huge per skill, per person, per workload, just in time and dynamic. That's a challenge as our system is ready for that. But do you really think that scale is a challenge?
I mean, we've solved it for big data. We solved it for clouds. Maybe we will solve it for AI sooner or later. I can't remember who, somebody in my organization equated releasing these AI agents into the enterprise as just unleashing an army of small children through like the physical, like your physical offices. And those kids are going to go run through and they're going to push the boundaries of everything that they find. If they're unlocked doors, they're going to get into them. So we were very careful.
We didn't want to stymie the organization because they're being told by senior leadership from well outside of our piece of that organization that they have to move faster. So we defined very deterministic guardrails. We talked about this. Very deterministic guardrails within certain environments. And then it's all dynamic and continuous evaluation and everything inside of those guardrails. And that has done more to allow us to observe things that maybe we wouldn't have seen. You can't plan for everything. You have to start somewhere.
So kind of building some nice walls around a smaller area and letting the kids loose in there and see what they do is a really good way to help build those things. So I think you're right. We've solved these problems in the past. We'll solve this one in the future. It's just the not scary, but unusual thing that we have to deal with now is the technology that we're trying to put in place. It's also the technology that we need to trust to be able to monitor that technology. At the same time. I think that's the interesting bit of this.
Where will those capabilities develop to be useful and effective first? I think that's kind of the race we're in. But it was really eye-opening for me the other day where someone was talking and they said they had 30 trial copilot studio licenses or foundry licenses they gave out to their development team. I think within a matter of months those 30 people had built a thousand agents. Incredible, right? And it just breaks that link between maybe the number of systems you have and maybe the non-human relationships or the number of employees you have and the humans.
But we've kind of broken that link. So from a scaling perspective, there's plenty of companies out there with a lot of people, a lot of machine accounts, non-human accounts today that are having to think like that. And we're only going to have to do more of it. So there's plenty of people working at really large scale today and that's going to continue into this agentic world. But you kind of probably lose control of that growth over time and that's where it's going to be interesting. Right.
Well, I would love to continue it for another half an hour. Unfortunately, we don't have that time.
So anyway, we'll wrap up with one short, hopefully practical and actionable recommendation from each one of you. I think, I mean, what it really comes down to is, you know, is really start to, if you don't have, if you haven't started already, you want to make sure if you've already done it in ITDR path, you want to start looking at indicators of compromise and start understanding about risk in your environment.
You're really going to have to have a proper strategy and understanding about where the potential data is in your environment and start understanding the data in order to help it actually give you the answers to the questions you might have. So every time you go down this path, I will say that what's the questions you want answered? And that's where you start with the questions that you would like to understand about your identity risk in your environment.
And once you understand those, it allows you to then go and find out where's the information, the data in my environment that can help me answer those questions. Start with the questions and lead it back to the risks. Great.
Steve, can I build on that one quickly? Because I think I completely agree. I think my extension would be, you know, and I think we've seen this with the Gentic as well. For some companies, it's such a big problem that they just don't know where to start, right? It's just such a big, you know, elephant that they can't deal with that.
And I think with ITDR, if it's not something that you're doing right now, I think understanding what really matters to your business, where it's really going to have the most bang for the buck, what you're really trying to protect, what you're really caring about as your instrument, I think just helps make that problem smaller and more manageable for you to get to architectures and patterns that really work for you and are effective and surfacing the risks.
So my only build on that would be, you know, that what your business really cares about, tying that into your resilience team, into your BIAs and that kind of thing. So you're really, really tuning into what matters for the business as you start that journey.
Yeah, I would say similar. I think the two things that you can do immediately to get benefit, one is if you are in the identity organization, start finding all of your different identity sources, your sources of telemetry, and start figuring out how to bring them into a single space. We developed a security data lake, and I don't mean to minimize the tremendous effort it takes to do something like that, but the value that you get out of that. And it's a thing that you have, if you, again, if you're in an identity team, these are all things that you have control over.
You don't have to go to another team. You don't have to do something. You can do that yourself. And the second thing is, and I can't emphasize this enough, our biggest bang for the buck came when we started forging that partnership with the SOC. And not only were the SOC open to it, but once they saw it, they wanted it. And I consider us now partners in that our success is their success and our failures are their failures. And I don't feel like at this particular moment in time with this particular project, we're any closer to any other organization than the SOC. So those are two things.
If you truly want to go down that ITDR path, that's your foundational stuff right there. Okay. Awesome. I think this is a great conclusion for our panel and our entire track.
Please, a round of applause for our panelists.