Or left to right, right to left, or ladies first, of course. Yeah, I can go first. Hello everyone, I'm Manmeet Bawa. I'm Director of Product Management at Microsoft, leading the Entire ID Governance product line specifically. And a big thank you to Manish for that very, very educational talk. Andre Priebe, I'm the CTO of iC Consult, a system integrator completely focused on digital identities with around 900 employees around the world.
Yeah, and happy to be here and talking about one of the most exciting topics of our industry right now. And I was the least active on the email thread. My name is Nico. I'm a Principal Engineer at StrongDM. We are an emerging software company tackling some of the kind of more traditional problems in the PAM space. Before that, I spent about five years in a company you may know called HashiCorp. We were also doing kind of secrets management, managing non-human identities. And before that, in our two and a half years in a company called Wyss, soon to be Google, also just so I heard.
Yeah, that's it. Okay, so let's start by kind of reiterating the wise words we repeated thousands of times before, that zero trust is not a product. It's a mindset. You cannot buy it. You have to work hard to implement it in stages. So it's a journey. And it's a journey which just kind of become even more complicated, I guess, by the introduction of a new elephant in the room, the AI. So let's kind of kick off the discussion with the elephant. And so what will be the role of AI? How will it change zero trust as a concept? How will it affect those journeys in the long term?
So Manmeet, maybe you could start. Yeah, in fact, I think when you started, you said, oh, the most interesting topic, and I half expected to say AI, because it's all about AI. And then I realized the topic of the panel is zero trust.
But yeah, if you haven't been tracking all the AI news that has been coming out over the last couple years, we wake up every morning, and there is a new set of news that is coming, and there's new technology developments that are coming online. And as security professionals, we also wake up to new ways that the cyber criminals are harnessing this technology now to go cause harm. So it's the most exciting time, because you wake up every day thinking about how you're going to infuse AI into the solutions and services you're building to make your customers' lives better.
And you also wake up with a huge sense of, let's just say, increased vigilance on, oh, this is how the cyber criminals have figured out how to further attack my customers, and this is how I need to go respond to it. So that's, as a security professional, that's the biggest impact of AI right now, the innovation aspect, which is extremely exciting, and the response aspect, which is extremely important, and our customers rely on us to actually do that in a very diligent way.
I mean, 90% of all security flaws, we know it's social engineering. Go back to the UK, two weeks ago, three of the biggest brands in the UK got hit. Most of them, it was social engineering, right? I don't think as an industry, we are good at understanding how to get around social engineering, just with, how do I put it? Normal human intervention, if we add AI to that, and yeah, it's complicated.
But again, just as you have the adversaries, you were saying, we can also use that for defensive capabilities. Something that we are looking is actually, how do we train models in terms of understanding the existing patterns of users' behavior so we can start detecting anomalies? It's as usual, double-edged sword. We were talking about that yesterday in the booth.
Yeah, so it's about, it's a mighty tool, and when it comes to Gen AI, we can't compare that to any other developments in our history over the last decades, right? It's maybe something like the invention of the steam engine. When it comes to the impact, it's not, yeah.
So, and this is a tool we must use to defend our organizations because the tech are leveraging it quite well already and getting better with that every single day. There's so much development around that. So therefore, it's absolutely necessary to move into the direction, understanding how to leverage to improve the security posture.
Otherwise, we will not be able to compete against the threat actors. That's, from my perspective, it's mandatory. I just want to underscore one point. Even as so much changes so fast, some things stay the same. To your point, the most common attack vector still remains social engineering. It's the how that we need to go, kind of the deep fakes, for example, instead of that phishing email. Now it's like my mom calling and it's her voice or the deep fake, that video call.
And so, yeah, I keep grounding myself in the evening saying, yeah, as much as things changed overnight, there is consistency on the most common attack vector, and we need to always remember that. Absolutely, and to add on that, so I'm quite sure that even if this is not the case in very short future, when it comes to social engineering, GEN AI will do that much better than any human could do, because one thing is critical here when it comes to building trust, dealing with our attention, that's something what GEN AI will do on a completely different level.
So, yeah. I mean, going back to it, we're in a panel on zero trust, right? If any of you, you work at an international company, you know how it is. We get text messages from, sorry, I meant to go with Steve Ballmer instead of Satya, but like, take whatever name. We get like text messages with the name of your CEO going like, hey, can you go and buy 10 gift cards and send them to me because I need to give something to a client, sign Tim, our CEO.
It's like, so far the patterns in social, or at least those patterns in social engineering are quite basic. It is scary how GEN AI can go into that, but we go back to zero trust, right? Do you trust the person that sent the message? Can you validate that identity? The same patterns that you start applying in real life, you need to start finding the correlation in terms of how are you going to do it for your infrastructure, for your identity practice?
Well, if there is one thing that kind of GEN AI has promised us all is that it will make everybody's life easier and simple and so productive. But in reality, I mean, nothing is easy. If anything, everything has become mind bogglingly complicated and complex. Where are the reasons for this complexity from your perspective? Like what is actually the difference of how to deal with all this in really complex environments?
Well, yesterday I learned a very interesting quote. So who of you knows Gregor's law?
Ah, okay, a few hands going up. So it's something in the direction of extensive complexity is nature's punishment for organizations that are not able to take decisions. But I just would partially agree to that.
Of course, there are things that drive complexity that are based on the nature of your business. So when it comes to different business units, different kinds of user groups, application devices, touch points, there are things you can't streamline then. And then it's a complexity really brought into the organization by the outside world. When it comes, for instance, to all the inventions related to Gen AI's improvements, there is a kind of strong support attackers get based on Gen AI. So there's a kind of complexity you have to deal with. You can't get rid of that.
Doesn't matter if your organization is able to take decisions or not. I think if you just zoom out a little bit, what at least helps me is you internalize what we are going through is change management. And change management has just three phases. The first is where you're just like, wait, I'm losing everything I knew well and was familiar with, which is by the way, what kind of made it feel simple. And then there is this unknown, which then feels complex. And as you start getting a little more familiar with the new and the unknown, you actually start skilling up on it.
Things start getting a little easier and simpler. And then of course you get excited about the possibilities. I think I personally have crossed that road where I think Gen AI is going to solve world hunger, but I do fully internalize AI is going to help me become more intelligent and more productive for sure. So that is helping me embrace it and use it to simplify my life. I really want to underscore what you said. Complexity comes out of that inertia to make decisions. The inertia to make decisions is many times driven again by I know this, even though it's like twisty turny, but I know it.
And even if this new thing promises me simplicity, just learning it is going to be hard. So there's resistance to go there. But once you make the decision and it's super important, I'm not going to plug any Microsoft products here at all. But the one thing I'm going to encourage everybody who's serious about implementing Zero Trust in their organizations is to go read the Microsoft SFI reports. We put them out every quarter. And you'll see in real time a company that is large and complex had half a million tenants that were not being used. And why? Because there was inertia.
Nobody, people just didn't want to make the decision to go clean them up until a forcing function came and we went and cleaned them up. Three quarters of a million apps that were just not required. People weren't using them. Should we have cleaned them up? Yes. Nobody made the decision until somebody had to make the decision. So if you're serious about Zero Trust, go read that. See how one of the largest, most complex IT organizations in the world went on that journey, made the decision, became very intentional about going enforcing Zero Trust.
And you could probably take quite a few best tips and practices from that. Yeah, I mean, there is particularly identity space. We have a lot of inherent complexity in diverse ecosystems, right? I am going to plug Microsoft products today. But effectively, when you look at, you know, operating the Microsoft ecosystem, I'm going like, yeah, I'm fine. I'm running an Azure. I have Entrust as my identity source.
You know, I have SQL Server as my database. You know, you can't transpond an identity from here to there and almost achieve kind of that Zero Trust principle where I can track the movement from the user to the application, to whatever it may be. The moment you start diversifying, and most organizations actually diversify, it's not that much of a clear approach where effectively, yeah, you can go and integrate, enter in a business application. Can you go and integrate into a database? Can you use an Azure system-managed identity in order to establish as identity source?
The moment you branch out, there is some complexity, but going back to your point, the moment you start letting that tech debt pile up, right, and you go, oh, I'll just fix it this way. Oh, I'll just hard-code a password there. That's it. You're still losing the battle. You have to stop that complexity before it starts growing. And when it grew, start acting decisively into regaining control on your identity aspects.
Yeah, and maybe to adding to that, in order to get rid of some complexity, it starts with having a good understanding of what do I actually have, what can I cover with different tools I have in place, with functionalities I have in place, but also what are areas where I just don't know? And that's a part of complexity that make it challenging because if you are getting aware of special things during the rollout, and then that might hit your heart. Knowing about upfront, you can deal with it.
You can clean it up, or you can bring mitigations in place or whatever, but having a good understanding of your landscape, that's the key, the key to move that forward at all. Yeah, and if folks were here from Manish's presentation right before this, he was talking about the continual access evaluation. One thing we learned, zero trust journey. You do all this work and you get to what we call like green, right? Like you've kind of cleaned everything up and now you have enforced your zero trust. That's just one step. It has to be an ongoing journey. We call it get green, stay green.
Staying green actually takes a lot of effort because you can stop inventorying your landscape, you can stop updating your policies, but staying green is as important, if not harder than getting to green. Yeah, Manish actually brought a great example because effectively what they're doing, and if you weren't here, what he said is there is an infrastructure as code tools to maintain their patterns in Entra as code, right? So every night they have an immutable tool. I'm not going to plug Terraform because I work there, but they have an immutable tool. They go back to green, right?
If someone went, implemented changes manually and so on, they go back to green every night. Every time they're introducing a change, that change goes through a normal code review process. So they're consistently striving back to continuing green. And they do it every night. If something breaks, they understand, but at the end of the day, these are the policies and the policies are hard-coded, un-understandable for most people. Unfortunately, there's sometimes a kind of situation that are somehow out of your control.
So for instance, an acquisition that's happening, a merger, a strategic alliance, and then there's a question, okay, how fast can you integrate it? I'm making business work, earning money for your organization, at the same time, accepting a few risks, getting back to not green anymore and then working on it. And doing the work, yeah, yeah, yeah. And to a great example, M&A, right? And then what if that, through that M&A now, you are part of a new geopolitical ecosystem and you have to acquaint yourself with all of the regulations, like talk about complexity.
I think I read this data point somewhere, 250 regulatory updates per day. So leave aside the complexity within your internal environment. There is also the challenge for all of us security professionals of keeping up with the complexity around us, right? And that's why I also read another data point, there's not enough security professionals around. So for everybody who is in this room, thank you for being part of this really important mission. And we need more people entering this field to help organizations, because there is just no environment now where we cannot have zero trust. All right.
So if you kind of go back to the original definition of zero trust and its initial appeal, it was its universality. It was a set of simple rules which supposedly work for anything. And now we have, again, the elephant in the room, AI, risks caused by AI, attacks fueled by AIs.
Are there, I mean, is there still a possibility to that kind of zero trust would apply uniformly to those risks as well? Or are there some new challenges, fundamental new things you have to be anticipating as an enterprise?
I mean, the concept's still the same, zero trust, right? There are a couple of basic principles effectively, right? If my workflow is I go and give this developer a service account because I trust that developer to put it into a server, that's a problem. So in terms of zero trust, what you need is a traceability, right? Understand what your sources of truth are. For humans, might be your identity provider, might be your entry or whatever it may be, right? Is that enough? Then we go into things like multi-factor, right? So we ensure the person is the person.
Do we trust the device the person is using? We need to look at that other angle. So Manesh was talking about like attributes, right? But even those attributes are a little bit static, right? We need to start evaluating all the attributes from the user, where are they geographically located? Do they match where they should be in the directory? And that's for humans, right? When it comes to machines, kind of the same thing. What is your anchor of identity for that machine? How can you prove that that machine is actually a certified build in your environment? Is it enrolled in the directory?
Can you go to the Azure API? They have a system managed identity. Can you go to AWS and check with IAM? Same thing with GCP. At the end of the day, the whole concept of zero trust is, let's stop with the assumptions. Let's not assume that because of devices within this network perimeter is trusted.
No, that device needs to enroll itself and needs to prove that can be trusted for a non-human identity access. For a human, we have a million angles, right? But it's important to go and look at them all. Something that one of our customers is doing, which is actually kind of funny. So their LMS, right? They actually need to recertify on their security policies. Every employee needs to recertify every year, right? Their LMS goes and adds a group in their directory when they recertify that year.
If they're not part of that group, doesn't matter if they got approval for access or just in time or whatever it may be, at the end of the day, they don't get access, right? Because that's a corporate policy overriding the access policy. So path to zero trust, point one, understand what are your sources of truth. Enforce them. I know it seems simple, it's rather complex, but that's the path to zero trust. Don't assume that because someone hit your network is actually someone or something that you can trust.
Plus one, the concepts are time-tested, assume reach, verify explicitly, and just in time access. And we have the benefit of the learnings of the last decade plus to bring in. We learned how to, we started with just saying zero trust for humans. And then we realized, oh, zero trust for applications, service principles, non-human identities. We are bringing all of that in as this new gen AI tech comes online.
I remember the first time somebody said, oh, AI agents, and we had a fantastic conversation in the hallways, in the water coolers, in the virtual hallways on is a gen AI agent a human or an app or something else entirely, right? And as an industry, we are going to come up with the right answer there, but we are going to end up applying zero trust principles to that. And we have the benefit of no matter what it is, we are going to make sure it is verified what it is we are going to bring.
In fact, if anything, we are going to embed the zero trust principles even now closer to the birth of that AI agent, right? Instead of applying policies later on, once they are alive, like from the time that they are generated, the app developer, if it is an app, is going to have to give it some basic birthright policies. Otherwise we won't even let it come online. By the way, these are debates that are happening, but the meta point here is we have learned a lot that we are bringing to the table and we'll be able to apply zero trust better to these new set of entities.
Sorry, and there is one last point. Don't shy away from brokering identities. It's not always the case where you can federate an identity all the way from the user to a system, right? Where you can do normal authentication, that's fine. Where it's privilege and you need to broker, don't shy away from brokering. Where you kind of need to rate your IDP into a system, broker an identity, as long as you have the traceability for it.
And again, you're applying zero trust principle, don't shy away from it. Yeah, I think the good thing is that zero trust principle stay in place, that's a good thing. When it comes to the impact of Gen-AI, I would say it's about scalability. Scalability of the threat actors, scalability of the use cases. So I recently read a study, so I was saying, per human identity, we have to deal with 15 to 17 non-human identities, but based on the Gen-AI, the assumption is that within the next two years, it's going up to one human identity to 90, 90 non-human identities.
And that scalability is of course also related to things that are not new insider threats, but on a completely different dimension. And most of them are ephemeral, so they come and go. I went and provisioned something to run a process, then it died, I still need to manage that identity. Absolutely, and also my assumption is that when it comes to putting the guardrails in place around agentic AI, identity access management has to play a crucial role for that, because at the end of the day, it's about authorization. What is that agentic AI allowed to do? And that's our core competency, right?
Yeah, well guys, time flies always with those interesting discussions, but I really want to give you the chance before we wrap the session, to just in one or two sentences, what do the people here need to take away before they leave the room from this panel? Just one or two sentences by each of you.
Yeah, really simple. The basics stay the same. So as soon as you can to enforce zero trust in your organization, no matter how complex or simple it is, phish-resistant auth, number one. Number two, gen AI, yes, it sounds intimidating, but we have learned a lot and we are going to bring it to the table to be able to manage this new wave altogether, including things like, and I'll throw my point in, cleaning up those ephemeral agents so that we are managing the life cycle better and not allowing a whole bunch of sprawl.
Yeah, so when it comes to zero trust, and completely agree, zero trust is there to stay, reduce complexity, makes it seem simple, as simple as possible, but not simpler than that. Complexity comes unfortunately from the outside, from the inside, we have to deal with it and we have to be in a very good shape to be able to deal with all the upcoming threats we have to face. Nail the basics, right? The basic principles haven't changed. The scale does at times, but again, nail the basics, right?
Make sure that everything actually has an identity, whether that's a machine, whether that is a pipeline, whether that is a human, and you can strongly validate that identity, not just assume that because it's in your network can be trusted. Okay, and with that, thank you very much for our panelists for valuable inputs and thought-provoking statements. Should we give them a round of applause? Thank you. Thank you. Thank you.