Okay, let's get started. Welcome to the Non-Human & AI Identity Workshop. My name is Lalit Choda. I'm the founder of the Non-Human & Identity Management Group.
Firstly, I'd like to thank KuppingerCole for asking us to return back here for a second year to host this workshop. We've also got a pavilion that we're hosting the event.
Last year, the demand for non-human identities was really, really exceptional across everyone that attended our workshop. We decided this year we're going to do it again.
Obviously, now we've included sort of AI, agentic AI into the discussion because that's clearly what everybody's talking about at the moment. It feels like the NHI problem people have forgotten about and it's all about agentic AI now.
So, I'm going to make sure we kind of clear the air on that point. So, our group sort of educates, trains, advises everyone in the industry around non-human identity risks. I've developed a nickname, Mr.
NHI, along the way as well for all the work we do trying to educate around the topic across the industry. So, what have we got coming up today? I'll do a little bit of a talk on, look, why is this moment different from I guess when we were talking about NHIs last year and how kind of agentic AI is totally transforming the way we think about kind of the non-human identity problem. We then got three great panel sessions, some great thought leaders, SMEs across the industry, sort of hands-on practitioners. We've got some folks sort of from the industry that are developing solutions.
So, session one, we're going to talk about autonomous, overprivileged, and ungoverned and what's the new reality for NHIs with agentic. Then we'll talk about how to govern the ghost in the machine, maybe give some insights around kind of identity architecture, what's going on from kind of a standards, best practices standpoint.
And then finally, we'll talk a little bit about what's coming up, what do people predict around the next 18 months as organizations start to think about how to tackle both NHIs and sort of agentic AI, what are the things to maybe look out for, what might be coming to help you think about solving these challenges within your organization. Hopefully, you'll enjoy the 90 minutes workshop. You'll learn some things. You'll be able to walk away with some tangible insights that you can then take away to start thinking about within your own organization. Okay.
So, look, let me just give you some thoughts. Last year, we did our workshop. We had eight sessions.
Again, it was a full house like we have today, a huge amount of interest in NHI. I think in the eight sessions that we had, we only talked about AI and agentic AI in one session.
So, you can see in the last sort of six, nine months, how this whole agentic discussion has kind of just transformed everything that we do. Agents, it's just everyone's focused on that. Everybody wants to deploy agents. And the big question is, how do we govern?
So, hopefully, you'll get some great insights on that. Look, I think, as I said, we still haven't, in terms of the NHI problem, solved that across most organizations. I think people, over the last couple of years, were trying to understand what to do, how to tackle it. Some orgs have started to tackle the problem. But it still was a huge challenge.
And now, everybody's saying, well, forget that. We need to do agents and deploy them and manage them. What I would say is, look, unless you've got your foundations right for how you manage non-human identities overall, then throwing agentic AI agents on top of a weak foundation is a sort of recipe for disaster.
So, I think you've got to look at things holistically. Don't just think about agents on their own right. You've got to think about it. I guess our view is they're a subset of non-human identities.
So, you've got to make sure you tackle that whole thing holistically. Look, I think we're already seeing big mistakes people are making across the industry as they deploy agents, agentic AI, all the issues that we've talked about for years around NHIs, static credentials, hard-coded credentials in source code. The issues with static credentials really cause so many issues in terms of managing NHIs. We've been talking a lot about, recently, dynamic ephemeral credentials. We need to move away from static credentials to dynamic ephemeral just-in-time credentials.
But what we're seeing is, as people are deploying agents, MCP servers, we're still deploying lots of static credentials and following a lot of the bad practices that we've already had with the legacy NHI estate. So, I think that's something you really need to think about as you're deploying agents. They're going to be autonomous. They're obviously going to be goal-driven. The old models that we had in IM for human and for NHI, while some of the concepts, the lifecycle processes work, it's very different. It's all about now intent, context, and real-time authorization.
I'm sure you're going to hear a lot about that through the workshop. Just before we kick off with the first panel session, I'm going to do my regular ask three questions to the audience. Question one, how many of you in your organizations are actively addressing NHI risks? Can you put your hands up? Maybe about a quarter. A bit better than last year, so it looks like at least folks are listening to what we're saying. Do you think AI or agentic AI identity is its own identity class separate from NHI and human identity? Hardly any. That's a surprise.
In previous questions, we've had a lot more people put their hand up. I'm assuming the people that didn't put their hand up think it's in the NHI camp. Do you want to put your hand up for that? Do you agree?
Okay, good. You all agree with me. That's great.
Finally, do you think agentic AI agents will lead to mass unemployment? Put your hand up if you do.
Oh, wow. Not a single hand has put their. Okay. That's encouraging. I may have a job. All right. Okay.
With that, I'm going to hand over to Pranav, who's going to do the first panel session around autonomous, overprivileged, and ungoverned. Thank you, everybody. Shall we start with a round of introductions?
Carlos, would you like to introduce yourself? Of course.
Thank you, Pranav. I'm Carlos Garcia. I'm just moving to Berlin. My background is the previous around eight years working on Santander Bank, which is a large organization, but working specifically on, let's say, subsidiary that is a lot focused on speed. It's like a speed boat inside of the large bank.
So, I get a lot of experience dealing with developers' speed. And I say speed a lot because when you need to implement things with less process and more speed, a lot of these problems that we are going to talk about appears.
So, that's it. And I'm Carol Linkvist. I'm the CMO of GitGuardian. We are a secret security and non-human identity security platform. I've been with the company five years, and we sell secret security to very large organizations, above 500 developers across the world. 70% of our customers are in the U.S. And we start to see more traction coming from the identity part of the organization. We used to talk a lot to application security and CTO offices. But as you noticed, non-human identity is becoming something for the identity people.
And we are happy to be here today to explain a bit what the problem is. Thank you both. My name is Pranav. I lead security and threat research at Onosecure. We are a unified identity fabric organization, which deals with all sorts of identities. And my background is in security engineering and strategy. And I'm a security engineer by trade, moved on to strategy and leadership over the years. All right.
So, Carol, I think your organization literally scans for all this at scale. Would you be able to share some of our stories or maybe some case studies that you've seen at your customer site when it comes to when you first get into service accounts and API keys? We'll get into the AI agents. I'll focus on, I would say, the more classical things.
So, at GitGuardian, we look at different parameters. We look at the public parameter. We monitor GitHub realtime. When we monitor realtime, we just issued a state of secrets poll. We find 29 million secrets. That's a huge number. And that's an even bigger number than previous years. The acceleration is really there. And we'll talk about the AI agents. They're the source of this.
So, that's looking at the public parameter. Then we look at what we call the internal parameter. When we come up to a customer, we scan their sources. What type of sources?
The code, of course. That's where you think first when you think non-unified identity and secrets. But we also look at JIRA, Confluence, Slack, and all tools that, basically, developers use every day. And what we find there is usually people completely underestimate what we will find, right? When we find one secret in the public space, we usually find between six to eight secrets in internal environments. People think because I'm behind my walls, I have my repos, they're just mine. Nobody will come.
So, if I hard code a secret, that's okay. Because I'm within my boundaries. The problem is if your castle has a door open and people enter, they'll find everything. They'll find your crown jewels, the secrets.
So, when we enter an organization, usually we find more than 10K secrets. And for the largest parameters and not the largest company, but for the largest finding, we are more around 100K number of secrets.
So, you could say, oh, my god, what do I do with this, right? Because it's kind of� and one thing you have to remember is at GitGuardian, we look at two types of secrets and non-unified identity. You have the one that leaked, the one that are the most dangerous for your organization because they are not where they should be. Your secrets should be in vaults. Point. They should not be into a JIRA ticket. They should not be into the code. They should not be into a Slack conversation.
So, when I say 10K secrets or 200K secrets, these are leaked secrets that are not where they should be. So, what we do now also at GitGuardian is inventory all the secrets you have in your organization. Looking at your vaults, looking at the different environment they could be in.
And so, imagine if the one that are leaking are 200K. How many do we find when we look at all identities that you have in your environment?
You know, millions. They're all over. And usually in large organization, you don't have one vault. You have sometimes thousands of vaults all over the place. And to know, you know, that's what I brought today is to secure, you need to know. You need to know where your secrets are. You need to know who uses them. Because the day you have to revoke, if you don't know where it is, if you don't know what it's for, you could break production, right? You could impeach your business to run.
So, you have to absolutely not only inventory, but also prioritize what you'll do with these secrets. The most dangerous being the one, if I put a hierarchy, the one that are in the public space, of course. You have minutes to tackle them. I don't know if you read the press, but this morning, we had a very interesting article with Krebs on security. He's a very, very well-known journalist. We found CISA.gov.
So, CISA is the U.S. agency for cybersecurity. And they leaked secrets in a public space. Massive ones. That could have been a horrible breach. As we are on the watch, we warned them. We were able to remediate that. But all organization, even the most cybersecurity savvy and technical, they have that happening.
So, our motto is, you know, attackers don't break in. They log in. And you can't protect what you can't see.
So, it's important, you know, to look. Thank you. Thank you for sharing that.
Carlos, how has your experience been? You know, you worked at Sandender, which was a big banking organization. And now you're at Motable.
And, you know, you're at Solidus now. It's a modern fintech. How do you see that, you know, getting into NHI and the stark difference between banking and into a fintech organization? To be honest, I think there is not too many difference.
So, raise your hand if you found secrets on your code. Probably all the room, right?
So, it happened on all the companies. And keep your hand raised if you found the secrets, but you are not able to remove. Because when you ask someone in the company, okay, I found this. I used a tool. We need to remove this. Nobody wants to take that responsibility. Because maybe broke something on the production. Or I'm not the owner of that secret.
So, the problems that we have, we have on all the companies. Maybe we have a different scale. Because the number of repositories of the code that we generate. But the problem is the same.
So, I think that the thing that we need to do is to start assigning the ownership to the things that we create on the companies. I don't care if it's a banking company, a fintech, or any other business. Because at the end of the day, the code is the same. And on the last year, with the rise of artificial intelligence, we are generating more code, more fast, but with less control.
So, more secrets, and less ownership. The problem is becoming more bigger, more bigger all the time. So...
So, your answer is, you know, we need more processes and, you know, ownerships regarding... Yeah, I wouldn't say processes.
Yeah, we need processes. But I talk more about ownership. But especially about visibility.
Because, as you said, we cannot protect what we don't know. We need visibility. We need to implement some different techniques, like just in time, or... I think that we are not going to be able to remove all the secrets, or to train the people at the level that they are not never going to put a secret on Slack, or any other place.
So, we need to control from other perspectives. It's like, okay, you are able to create that secret, but the secret is not valid for more than five minutes, or whatever. Or at the organizational level, you are able to disable the secret creation.
I mean, you need to create different strategies, because the user... I mean, how many years are already saying that you don't need... you need to put the secrets on about, or on other places, and the people are still doing.
So, I think that we need to change a little bit the approach to revoke the permissions from the security. So, now if you were to layer the AI agents on top of it, the agents can spin their own instances, spawn their own other sub-agents, and have their own skills and accesses of their own.
So, how do you... is the approach the same when you're finding, you know, looking at ownerships, or looking at the inventory? How do you tackle the AI agent problems, and their sprawl across the organization? The approach, I think, is the same. The problem and the risk that we have is way more bigger, because right now we are able to create agents, and we are giving permissions to that agent, so the agents, on behalf of the user, do a lot of things. And if you think, when you use artificial intelligence, like a chat GPT, you always get a response.
I mean, even if the response is not true, those models are trained to satisfy the user. So, if you ask your agent, okay, you need to go to this system and do whatever you want to do. If the agent doesn't have the right permissions, but have the ability to create a token, or to grant permissions to himself, he's going to do it.
So, from this point, you start creating shadow IAM, shadow secret, shadow IT, and you don't know what your autonomous system is already creating. And I think that you have another problem.
So, for example, how many of you now, what is this? MFA token, right? How do you use these MFA tokens with autonomous agents? You can't.
So, we spent years telling the people, you need to have two-factor authentication. You need to use, you are not able to go into the system if you don't have.
And then, we create authentication token, we create a bot that is able to perform administrator actions without this. Isn't that the same with the service accounts as well, or technically users, and other integrations, where you can't really put an MFA?
I mean, yeah, it's the same, but now this, let's say, service account or autonomous account are working alone, and can replicate. It's like a ransomware or something. If they need to do something, they are going to create the necessary tokens or permission, and do it. Unless you configure in the proper way, and you have good monitoring controls, and so on.
Well, what's your thought? Yeah, I love that you show this, right? Because we have identity people in the room.
Usually, people tackle human identity. This is your token. You've been given it by one person in the organization. They issued your credential. They know what you have access to, and they can cut your access, remove your access, and everything. This is the human identity type of environment, right? When we move non-human identity, this is the jungle. Everybody can create those.
Before, just like a year ago, it was only human, but already it was a nightmare, because every developer can take a decision to create a token, an API key, whatever they need to perform. It's the same. They have to perform. They have to produce code at the speed of even faster and faster.
Even then, it was a problem. But now, what do we have? We have autonomous agents that do the same as developers, with a probabilistic approach. AI agents are not deterministic. They will do A. The second time, they might do B, because they want to perform on the request they have been asked, as you said.
So, I think one mistake that the industry is doing, or I hope will shift, is that trying to apply human identity behaviors to non-human identity. We are in a totally different world. We need I think the basic concept is we're not able to tell only non-human identity will go through one door. This is not even possible, I think, frankly. We could go ephemeral, but it will take years.
So, we have to cope with the jungle, the mess, and the probability. So, that's, I think, the reality of the non-human identity world today.
So, how do we, you know, like I work with quite a lot of banking and financial sectors, and they all have their own approaches, especially in the dark region, or in Germany, if you're regulated by BaFin, or have data compliance, you have a set of critical applications, and, you know, you're allowed to do your own things within the approved hyperscaler, you know, like a lot of hyperscalers there on AI development environments, and so on.
So, I have seen like different approaches where you can put guardrails on it, rather than each developer going and signing up for their favorite LLM and letting the agents run amok. So, if you were to design a, you know, inventory or policy for having agentic governance, how do we go about it?
I think, obviously, you need to understand how big is your problem, and start looking into the criticality, because, obviously, as he said, it's not the same to have a token that is meant to do something in production, that is exposed, let's say, public, or on a more internal way. So, you need to classify, like the rest of the cyber security problems, you need to make some prioritization.
Then, also, I would say that you need to understand what this non-human identity is meant for, because maybe it's a token, let's say, read-only token or something, okay, it's bad, depending on where this token are, so it's about context, because maybe a read-only token for read informational API is bad, but not so bad, but if the read-only token is for read customer data, it's super bad. So, it's about giving all the context.
And then I need to create something or to improve my detection rules, and when I say detection, I mean about the SOC system, because, okay, let's assume that we are going to have a problem at some point, but we are able to detect, no, yes, we are able to understand the alert that we have, because normally we have alerts on the SOCs for the people, for the humans. So, when Carlos goes to some system, makes some clicks, then I get an alert and say, okay, Carlos with this email, this ID on this computer, do whatever, but what happens with the non-human?
We have problems, because normally the analyst goes and says, okay, I'm going to call Carlos and ask why he is entering to this system, because I have an alert that says that if you enter this system, I need to ask the user to understand if he's authorized it or what is the business behind. How did you call an agent and ask? And then who is creating this agent?
So, the next step for me will be attach this non-human to a human responsible, and that's a hard part, because nobody wants to take that responsibility. So, if you map these two, at least when you have this token on this system or this agent doing something, you are able to call someone. Probably this guy or this lady that you call is not even know why you're calling, but at least you have someone to speak about this.
So, that will be my other suggestion, try to map things together. Yeah, I mean, it's not easy part, but you need to get that contest and start looking small pieces, because if not, the problem, as he said, is massive.
I mean, if you do a scan today and you have 100k. Yeah, and it's a multi-layer topic, right?
So, yes, if you get 100k, what we do is we prioritize, as you said, there is the risk, there is the validity, there is the context, and there is the capacity to know what it gives access to. So, that helps of the prioritization, and that's critical. You don't want noise, you don't want all those alerts to completely panic your organization. You want to focus on what are the ones that are critical first, that's for the leaks.
When it comes more to best practices, I think, I mean, we talked about ephemeral, I think we have to go to that route, and we have to organize so that agents consume at least very short-lived credentials, because if then they leak, you have less of a risk, right? What we also push for is what we call intrusion detection. You may have heard about honey tokens or honey pots sort of stuff. What we recommend when we enter an organization with thousands of leaks is to protect each place where we have found leaks with those tokens.
At least if someone breaks in, you know it, and you know where to focus. And I don't know if you followed, but in the past, I've been very busy in the past six weeks, because every other day, there is an attack on developer endpoints. What happens is you have packages that are compromised, that are installed automatically by agents, dependable being one, on developer laptop, and what do they contain? Credential harvesters. What they do is they just take everything that is on a developer machine, and guess what? Where are the secrets? On developer machines.
And usually, they're strong and powerful secrets. When there is a honey token on a developer machine, and this happens, at least we know, okay, we've been breached. We have those, you know, 15 tokens that have been compromised. We need to rotate them fast. Here is the context. Here is what it gives access to. Let's tackle first production. Tackle first access to data.
And so, I think we can imagine systems where everything is guardrailed. You have your one single place for agents to be created and all that.
First, I think it's a dream. I think we need to be ready for the problems, because they're here, and they're here to last. And unfortunately, you know, attackers, they don't wait for us.
AI, we talked about it. They help attackers, too. When you look at before, I think we looked at some data, and beforehand, it took, you know, 19 days for an attacker to move laterally in an organization. 29 minutes now.
You know, once they're in, it's game over. So, I think you said it. I could have said there, but if you don't know, you know, what is there, then you can't really protect yourself.
And yeah, that's, I think. And AI agent is, for me, as you said, it's just another type of sprawling of identity. It's another actor in the organization, alongside human, that is even less behaved than a human. And it's there. And we won't stop it. And I'm a CMO, and I'm using agents, and I'm using code, and I use code, and I'm not very much trained on cyber security.
Imagine, you know, it's everybody in your organization is going to be like me. It's definitely happening.
I mean, we get those kind of attacks all the days. Supply chain attacks. Yeah. We get them. The last week, we get, try to.
I mean, happen all the times. Light LLM, Shia Loot. Yeah. Another thing, and the companies, the code that we create right now is splitting three-party codes. We don't really create code. We create a connector between different parts of code. So we need to also understand that the code that we fetch from the internet or from other repositories are going to be incorporated on the code that we create. So if this code have secrets, have access to the other things, we have a problem. So another part is also trying to govern the artificial intelligence.
Yeah, we need to inventory the agents. So one other thing, we said inventory the secrets, right? But inventory the agents, same thing. You inventory the identity and what surrounds it, who created it. The ownership is, as you said, critical. What we fear, and it's starting to happen, is orphan agents. When people leave as orphan secrets, we have orphan agents. Who will maintain them? Who will make sure they're not becoming rogue agents, kind of, in your organizations? Because they have no owner.
So we have to inventory the layer of AI as we inventory the layer of humans and as we inventory the layer of access. For me, inventory is the start. Yeah. Great. So if I were to summarize for the audience, so we need to have inventory, we need to have clear ownership, and we need to understand whom they're talking to and what accesses that they have.
And I guess HoneyTokens is a great idea to understand if there is a credential harvester or like Infostell or Malware comes in and get installed in the developer machines, and they steal everything and try to replicate these sessions from somewhere. It's a great idea to know. And later on, how to see the blast radius, how to prioritize, and how to go and fix this if we know the ownerships. All right. Yeah. Wonderful. I guess that summarizes our panel.
Thank you, everyone, for listening in. And thanks for our wonderful guests. Okay.
Thanks, Pranav, Carol, and Carlos for that introductory session. Hopefully, that's got you warmed up. I'm going to invite our next panelists for our next session. So if Martin and Chris can join me, and hopefully, Malhar is online.
Malhar, are you online? Unfortunately, Malhar was coming from Australia. And last minute this weekend, he wasn't able to fly, given some of the challenging situations that we've got across the world at the moment. So hopefully, Malhar from ANZ is going to join us.
Okay, while we wait for Malhar, there you go. Hey, Malhar, can you hear us? We can't hear you. You're on mute. All right. Let's just give it a minute. I guess for this session, we're going to be talking about governing the ghost in the machine. And how do we look at identity architecture for agentic AI? I guess whilst we hopefully sort out Malhar's challenges about sound, Martin and Chris, why don't you just do some quick intros, please? Go ahead and try again. I got one. Permissions for me have been granted. Let's see about you. And I guess I'll start.
I'm Chris Weber, VP of Product Marketing at Teleport. We are AI infrastructure identity company for the last five years and across hundreds of companies, especially those with high data sovereignty requirements. A lot of folks we've been talking to here in Europe and across the globe. We're helping unify identity across humans, across NHI, across AI in a way that makes it so that we can actually accelerate work, accelerate the engineers who are out in front of us sometimes with this AI, and add resiliency, reduce blast radius, often in times by reducing the credentials that can be lost, stolen.
We'll talk a little bit more about that as we get through, of course, but that's us. So yes, it works now. So my name is Martin Sandron, and I'm the Identity and Access Management Product Lead at Interakia, which is the mother company in the Ikea group.
At Ikea, we do flat packages around meatballs and emotional support animals. Okay, Malha, let's try again.
Okay, still having sound issues. Can you hear us, Malha? Okay.
All right, we'll come back to Malha. He'll be hopefully taking the lead on the second question.
So look, let's set the scene. As I said in the opening, we've been talking a lot about how do we deal with non-human identities. It's a huge challenge. The previous session talked about some of those things, and what does that mean from an agentic AI standpoint.
Look, I think when I talk at various events over the last few years, we've only just started to deal with the non-human identity problem from a tooling, identity standards standpoint. Everything was built for human identity, and then in the last few years, people started to develop capabilities for handling non-human identities that are very different challenges to human. We've talked about some of the hot topics around dynamic, ephemeral credentials. Just in time, this is really the future for how you deal with the issues with non-human identities.
There's various things out there that help you, like federated workload identity management, Spiffy Spire, OAuth2. You've got various things that are out there already that we were recommending that people do to tackle the non-human identity problem. Now pops up agentic AI. I'm going to ask you, Martin, when you start thinking about how to develop agentic AI capabilities, what do you think are the essential architecture elements that we need to safely run agentic AI?
Well, I think the main thing to think about this is that it's very interesting because it's an area that kind of really accelerated the problems we had before. It's just like you add all of our previous problems, and then you add agentic, which then adds a factor 10 to a lot of the issues. It's a lot of things that we knew that we were not handling very well. Unless you're a very well-regulated organization, very kind of strict, you don't have as good handle on your NHI as you would like to have.
Now, that problem is substantial, especially if you're in a multi-cloud environment, especially if you have a culture of freedom for your developers trying to meet the needs of the organization, accelerating change, lack of proper frameworks, lack of proper process. Then when you get into agentic, you have perhaps a factor 10 more problems. So if you look at, for example, the consent area, and consent is a little bit of a wrong expression, I'll say, but it used to be that one of the things that you had to figure out a good way to handle is that, okay, your users wants to use applications.
If you're a Microsoft shop, this is a quite common thing. You had a consent framework. You might have the settings where you have that your users can, if it's a low risk, they can pick, they can consent by themselves, and then otherwise it needs to go into an enterprise risk management. And then suddenly AI showed up, and suddenly you had lots and lots and lots of your users started consenting to all kinds of stuff. And of course, usually they could only consent their own stuff, but that kind of aggregated quite quickly.
So one important part is to not kind of let perfect be the enemy of at least moving the needle a little bit to a basic framework. So first part is to see, okay, how can I get some visibility on my agents? And if you're, most users want to do the right thing, so at least have an agent registry, so they can register the agents.
Now, next part is to say, yes, most users do the right thing, but most users are also creative, and they may not read all of the instructions, and depending on your culture, you're probably going to see a lot of agents and your vendors start pushing in agents. I remember finding 4,000 agents in one of my products that they just showed up. And so some form of an IWIP system where you are able to detect these agents in an effective manner, so you can see them.
Because at some point, either when people start leaving your organization or when you start having an intrusion, you probably want to know, okay, so this user has now been either left or they have been compromised. What agents are they running? So the third part is the ability to see, okay, how do I connect this into my existing frameworks? Because you do have, hopefully, some form of identity security framework, some form of an ITDR. What does that mean then for agentic?
A good example in the previous panel, I said, okay, I have, I require MFA, okay, but that is not as, there's different ways to do it, of course, but not 100% applicable to NHI and not to agents. How do I handle that? If I lose that control factor, how do I get an alternative control to protect that? So I think those are very basic things. And then it gets to the whole thing about, okay, I want to have the ability to create short-lived credentials. That will be very useful. I want to have the ability to have managed NHI of some kind for this, so I don't have to rotate keys or equivalent.
And I do want to have an ability to apply policy-based access control and intent-based access control. But those are more of the advanced things.
Step one, at least have somewhere where people that behaves nicely can register agents and then get an ability to at least see all these agents and their associated NHI. Okay, thanks, Martin.
I guess, Chris or Mehran, anything else you wanted to add to that? I don't know, Mehran, you want to try again, see if we can hear you? Am I able now?
Oh, yes, we can hear you now. Well done. Thank you. Good morning. First of all, good morning, everybody. I wish I could have been there in person with you all, but yeah, unfortunately. Maybe next year. I'll try my luck next year.
Okay, do you have anything else to add on that initial question? Yeah, I think just to echo what has been discussed, yes, the world of the AI agent moving is so fast. And as a security practitioner, it's always sort of catching up to that world. The developer needs their, you know, maybe they are because of the, you know, under the time pressure to build the software or the agents. But whether the question is, are all the right controls being followed, right standard being followed?
Yeah, I think a thing I really liked that I heard you say right to start off is not to have to start by doing everything, right? Find a small section.
I myself, it's been a few years, but I was in IT security for a long time back when like Active Directory was the thing I went to locally downstairs in the data center to go try to solve a lot of these problems. And certainly, I was only thinking about human beings, and then moved into network, moved across more broadly. And what I realized then, and it's kind of the same now, we always talk about inventory, we always talk about understanding and alerting.
But I don't know about you guys, but 15 years ago, I had hundreds of thousands, maybe millions of alerts every week to go look at to try to prioritize. It wasn't like I was going to get the top 10 and really feel like I'd done my whole job. I needed to take action. But I couldn't do it everywhere. I couldn't stop every attack, I couldn't find every attacker, I needed to find discrete places to work and then feel like I'd won. And I think this is a time when that's really critical. Because this new threat, you said it's a 10x problem. I think you're exactly right.
But I know that we can start 10x effort, we can start in small distinct places, maybe with our developers, maybe with a subset, maybe just around a certain set of tools or APIs, and then see what we can do there to change without impacting the hard work we've all done for our people, for sure. And then maybe we move backwards, we start with AI, we move into NHI, and then we collect all the human beings because then we're working big to small, even if we start in small places because of the scale of the problem.
Anyway, but I like that idea of carving off a small spot and starting there. Okay, thanks, Chris.
All right, look, clearly, with kind of the agentic AI, well, kind of the model changes significantly. You've got users, right, including shadow AI, that are using agents, you know, then agents will start to decide, you know, based on the goal that has been given to then decide its path, it may then spawn new credentials, it may start talking to other agents to get the task done.
So I guess, when we think about access, least privilege, and auditability, which are key things from a control regulatory standpoint, I guess, Malhar, what are your initial thoughts, right, on how should we from a kind of an identity standpoint now be thinking about access, least privilege and auditability? And how does that change from how we used to deal with things for humans and sort of the standard static workload kind of processes?
Yeah, I think I would start by saying that the first obvious thing is that no agent should have more entitlements than the human who delegated the task to that agent. Because what is happening in the reality is that, you know, when all those orchestrations tool like LangChain and many others, you know, when they start creating the workflows, it leaves up to the developers to decide. And maybe the developers, you know, maybe, you know, they are under the delivery pressure, so maybe they might not follow the best practices. And often the entitlements remains across all the agents and sub-agents.
So that's the first thing. The second thing is the entitlements should never be inherited completely as a wholesale. Every handoff between the human, the agent, the sub-agent, it should all be, you know, it should be reached that there has to be a re-issuance with an excluded scope. The scope should be reduced gradually. For example, I hope am I audible clearly?
Yeah, you're great. Perfect, perfect. Cool. So one example I would like to mention over here is that, let's say, you know, in a financial environment, you know, one of the manager, you know, wants to get the credit review report for a particular client.
So, you know, he or she creates a task or a workflow, which then goes to the, you know, the sub-agent. The sub-agent has the right access. Now that right access is, you know, just enough right access to do a particular task. Now that sub-agent creates one more sub-agent and that sub-agent only has read access, which is good. So in this way, the entire chain is basically controlled, you know, appropriately and only the sub-agent who is intended to do the right task is the required level of access.
And the third thing which I would say, there has to be some attributability or some controls in place. I would often think that, you know, when all this complex workflows, you know, agents and sub-agents are, you know, being nested hierarchically, horizontally, there has to be a path, a clear path.
You know, there has to be a way to define how the agent are moving across. It should not be just a flat log file where, but it has to be a very detailed log. For example, you know, it could be something like a policy decision log to elaborate what permissions were given to that particular agent, why it was given, which rules were allowed, what classification it was given, what was the context of it. And that also, there has to be a way for any sub-agent, you know, that cannot be re-escalated at entitlements. Okay.
Thanks, Malhar, for those insights. Look, I think there's a lot of different things that are discussed in the industry at the moment, whether it's agent gateway for doing governance, shared signals, right, for continuous assessment of what's happening, you know, across the call chain and transaction tokens, right, that confirm sort of call chain integrity, I guess, to what Malhar said.
I guess, Martin, Chris, anything else you want to add on this topic around, you know, as we move from human to agent, agent to agent, you know, what additional challenges does it create and how do we need to tackle them? Yeah, I think it's well said.
I mean, the practitioners here are well ahead of the game. It's good to hear, right, starting to think this way. I think there's a real opportunity if we're looking, as well as Malhar just described, right, we're seeing sort of the intent and the outcome of what an agent's trying to do, like what is expected, what systems should have access, where do we expect this to go in order to have his job complete. If we do a really good job, it's bound very tightly to that. That's great. We can see, because of the nature of agentic, when it wants to do something else, right.
Unlike me, where that's just stuck in my head and I'm sitting at a keyboard and I say, man, it would sure be easier if I could go into this S3 bucket and do whatever I need to do. With an agent, it's going to attempt it. And when we see that delta, that's a really good signal, right, what should happen to that. And unlike me, we can just go ahead and kill that agent, or at least I hope unlike me, that would be a difficult day at work, at least for my wife. But they don't have to live forever, right. It's certainly the case that sometimes things may break.
We talked earlier about having hard-coded secrets inside the app and it's a little scary to get in there. I'm sure we'll see some similar things with agentic use cases. But the agent itself doesn't have to live forever.
In fact, it doesn't even have to live for 30 seconds. Likewise, some of our compatriots in the cloud world, right, think about Kubernetes and sort of the orchestration there. In the NHI side of things, containers don't have to live forever.
In fact, we don't like that at all. Why not have agents in containers or in micro VMs that also don't live forever? Can we use some of our NHI learning where we have scoped, limited, just-in-time credential for an environment? And that be the only place that an agent can live. So if I can't control that little agent, I can certainly get rid of the whole environment. Anything that they collected, any of the data that they have, the file system that's there, gone. That's multiple levels of control that we don't have for me and that we don't have for NHI that we are afforded with this problem.
And I think seeing what they're doing is critical for making that sort of close that loop. Well, I think it's also a little bit about, if you look at the maturity setups. So initially when you use AI, one of the things you do is that you have it kind of like an intern.
You know, you ask these questions and it goes merrily around and looks for information. It's really, really good at that. Especially if you train it a little bit and especially if you have an ability to connect it to your systems that can actually see what configuration you have. But even I've been amazed how good Copilot is on just being a super loaded, super charged search engine. What you do see is that then you come to the place where you have agents acting more like systems. So the NHI that is running our IGA system, it has a lot more access than I have on my personal account.
It has write rights to a lot of stuff because it needs to provision the provision stuff. And I do see a similar situation for agents. But then comes the question, how do you make sure that you have the right amount of access at the right time? Your IGA system is hopefully rule based and does the same thing based on the same inputs every time. Your agents won't do that. So how do you make sure that it doesn't decide that today is a good day to delete all the users because they are clearly causing a problem? I saw that movie a hundred times.
Yes, the office is a very good TV show to watch. So we have a little bit of a ten times problem. You cannot really apply the same approaches as you used to do. And of course I think anyone who works for an enterprise, one of your favorite activities is that a happy developer coming saying I want global admin. Why do you want global admin? Because my supplier said that I should have global admin.
Look here, in the instructions it says login as global admin. Okay, no, you won't get that. And probably you're going to have ten times the amount of those requests. But from happy agents who think that it should be global admin instead. Because documentation said that.
Okay, thanks Martin. All right, look, final question for our session. Clearly orgs will have existing IAM stacks, PAM stacks that span across hybrid crowd and on-prem.
So look, what advice would you give to orgs? Where do they start when they think about identity infrastructure for agentic? Maybe one of the things they should avoid doing early on as they're on their journey. So maybe Chris, you want to get started on that?
Sure, we see it often. I like the end of your question, I'll start and go backwards. What to avoid? Certainly I think there's a lot of reticence, or at least we're coming out of it, I saw some in the questions you were asking up front. But there was a lot of heels dug in over the last couple of years around AI.
Like, well, we're just not going to do it. And I think we've seen that no matter how strongly we want to put our arms around that, it's happening anyway, right? Our employees are figuring it out. So similarly, we know we need to take action. But what I think is often the wrong thing to do is to try to whiteboard out a universal solution that's going to work perfectly on day one for everything, right?
Like, well, if we're going to do just in time, let's say, right? Let's do it for all of our people. Let's do it for all of our systems. Let's make sure agentic AI, that's a tough strategy session. That's a lot of systems to touch. And like I was saying up front, I think a lot of folks have a pretty good handle on us, right, on the people. It's not maybe perfect. We've always struggled, but we've gotten the biggest part of the problem out of the way. We know how to validate what we've got. We've got our compliance in place. So I think a thing to avoid is breaking that, right?
Just starting by trying to upset everything. I personally like looking at AI as its own, especially agentic AI, as its own problem set, because there's a lot of room to, just like your developer is going to come up and say, hey, can I have global permission? Can I have global admin to everything?
Similarly, if you use clod code, right, the dash dangerously skip permissions is just built right in. It's only supposed to be done in air-graft environments. But I can just tell my little agent to never ask me again. Just go ahead and elevate privilege as much as it needs to to get things done. We should start there, right?
How can we get something in place that gives an identity to that agent, maybe gives an identity to the infrastructure in which that agent lives, and use all of our knowledge on how to govern that, our permissions, our role base, and our just-in-time to really govern that and then move out? I think that's a great way, because that way we're not trying to boil the ocean so it doesn't take so long that folks are out in front of us.
But secondly, if we start with something that can work everywhere, and of course that's a little self-serving, but I really do mean it, if we use standards, right, sort of security primitives, if we use X.509 as a baseline, that works just as well for all of you as it does for the newest agent that's going to come out as it does for a container, a cert-based system that says, hey, scope privilege to only what it needs. Let's base it on some sort of hardware root of trust, which is all around us. It's in my pocket. I've got a phone that knows me that can go ahead and do encryption.
There's TPMs in the entire data center of all the clouds that we use. We should take advantage of that. It exists. So let's pull back cryptographic identity where we can and then solve small problems and then move broader to the problems we've already solved and improve those. So rather than starting at the 10% difference, let's start at the 90% difference and move that way.
Yeah, that's some great advice, Chris. I guess, Malhar, any further thoughts from your end?
Yeah, I would like to add that I think what I've experienced is, particularly in the NHI, is not knowing what it is there, given the size and the complexities of the organizations. There is always blind spots of how the agents are created. So in my view, I would start first with the discovery and the classification. I wouldn't rush to put the controls first. I would just go and discover what things are there. There's a problem over here.
So yeah, that would be my first is to discovery first, classify them, and then think about the controls later on. Thanks. And I guess, closing thoughts?
Well, I'd like to take a bit of an enterprise application owner perspective on this. And a few years ago, it used to be that we had these very nice boxes. We had the IGA box, we had a PAM box, we had access box. And they were not a huge amount of overlap, and you kind of bought one of each, and then your enterprise was happy, or at least a little bit less unhappy. Then the different boxes kind of blend together. And for many enterprises today, one of the things to think about is, okay, do I have a modern IGA solution? Can I expand the IGA solution to also cover Gentic, perhaps?
Do I have a modern PAM solution? Can that be the starting point for my visibility part? Or do I need to go and buy a specialized product for this? And I think that's an important question to start asking, to see. Because at some point, you do want to get at least the visibility.
At least, perhaps not on everything, but at least on your biggest cloud, or a couple of biggest clouds. And if you don't start thinking about that, then after the first couple of intrusions, you will be asked very nicely by your CISO to start thinking about this.
Okay, that's some great insights. If I was to recap, I guess there's a key theme around visibility. I love Chris's thoughts around maybe treat the agent problem as a unique problem and sort of then work backwards from there.
You know, again, do things in small chunks. Because this is too, I mean, the NHI problem was too big an elephant to tackle anyway. And I think Gentic is now even bigger. So I definitely think being very focused, right, and having control over who can access, what can it do, you know, just get the basics right. And then over time, layer in all the advanced stuff around standards, ephemeral, you know, and then moving to the Nirvana, right, which is real-time, intent-based authorization. I'm sure in the next session, we might hear a little bit more about that.
So thanks, Malhar, Chris, and Martin for your insights. Great session. Thank you. Thank you. Thank you.
Okay, final session of the day. We've got Jessica that's going to help moderate and give some insights on the next 18 months and where do we think NHI and Gentic AI security goes next. Hi. Hello. Over to you, Jessica. Good morning, everyone. Looking forward to this discussion today. And we're going to get our crystal ball out for this. So I'm Jessie Stone, Managing Director of the Identity Underground. For those of you who don't know, it's a global community of identity security executives and practitioners. And I'm joined here by Yos Rogerio and Matias.
So Yos is a tribe architect over IAM at Rabobank. Rogerio is a senior manager at PWC. And we have Matias, who is a practice director over IAM here at Kupinger Coal. So I want to come in hot here. We're all making bets on where this goes, NHI and Gentic AI. So if you had one prediction that you would put on the record right now, something that you would stake your reputation on, what is it? Shall I start? Please.
First, I'm hoping everyone's still sort of awake. I know it's warm in the room, but this is a really interesting panel. So wake up. I'd say somewhere in the next 18 months, I don't know where, I don't know what organization. I hope it's not going to be mine. We are going to see a big, big security issue due to, well, too much trust in NHI's agents just being okay, being used everywhere. And then it's going to go really wrong and it's going to hit the headlines.
And then I think we all think, you know, NHI has our focus now, but then suddenly it's going to get a whole different level of management attention and all our planners are going to go out of the window and we have to fix whatever went wrong in that other organization, in our organization yesterday. All right. Let's think about the good side of the NHI and Gentic AI. I expect some development specifically in NHI from the traditional voting thing to the NHI governance.
And for non-human identity, I've been discussing a lot about, I'm sorry, for agentic AI, discussing a lot about the need of data authorization. And I think data authorization is one topic that has been out of the identity and access management. And I believe it needs to be a part of it. Okay. I want to take a different approach. I'm 30 years in identity right now.
So, and we have heard really great sentences from the last panelists where they say, we know how to do things properly and we know the way to move forward, but knowing how to do things right and doing things right is, there's a gap between that. And today we are creating the authorization, the delegation chains, which should be good. And I expect that it will not all be good. What is in 18 months, we will have tons of delegation chains that are not completely secure, that are not least privileged, that can be exploited, that nobody understands because it's not two hops, it's 12 or much more.
So, my prediction for an 18 months, if we don't do things really properly today, we will have a real issue with compromised agents using those weak delegation chains and really causing havoc. That is what is my, yeah, my prediction and my hope that it does not happen, but that means we start today doing things right.
Well, we'll see in a year, we can come back and talk about this again, see if you guys are right. But moving over to the attack service, so most organizations don't have a complete inventory of their human identities, let alone non-human.
So, as agentic AI scales, how does that visibility gap become a critical vulnerability and what does an attacker do with it? Ruggiero, let's start with you.
Yeah, I can start. So, in fact, this visibility gap is already critical on NHI without AI anyway. The differences on the NHI, it's more on the stat key way of thinking.
So, the credential is there, this NHI, this visibility, it's hidden somewhere within the application, but to be breached, it needs to bypass some human control. That's how we have seen.
So, someone needs to have an insider threat or some mistake that a human with overprivileged has been breached and then the attacker gets access to all these credentials. When we move to the agentic AI, so we take out this human element, but we have the agent accessing these credentials, these credentials that we don't know exactly where they are.
Recently, I was reading, last week or so, what we call the Grok code morse haste, which was an attacker within the Grok platform. Someone ingests a prompt, a morse code, and this Grok bot was able to contact another banker agent and transfer bitcoins of 100k amount.
So, that's the risk. So, we don't know where it will be.
Josse, you want to add to it? Yeah, I think I can add to it. It's always a bit of a vision, but I suspect the way we need to do security and identity security is really going to shift, right? A lot of our traditional models still rely on a sort of structured rules, and I think it'll shift more to, I think the best comparison is a sort of immune system. We all see all the threats are happening faster. If there's an exploit, if there's a gap, it's now being exploited in hours or even minutes instead of days or weeks. And that means the way you need to defend your environment will change.
It means you can prevent every attack. It means you need to monitor everything and then, like an immune system, say, hey, this is strange. I'm going to stop it. I'm going to attack it. And sometimes you can break things to stop it, just like your immune system causes your temperature to rise. It's not always fun, but it's necessary.
However, the only way to stop things, if you know what's supposed to be there and what's not supposed to be there, and all those identities, all those accounts, all those managed identities, whatever category you want to put them in that you don't know what they're there for, your immune system won't know how to stop, won't know how to react because it doesn't know if it's intended behavior or if it's a cancer going out of control, breaking the system. So I think that's the real issue we have.
The new way in which you need to defend your systems requires you to know what's expected behavior and what's not. And you can only do that if you know why things are there.
Thanks, Janos. And I want to move over to controls. And Matthias, I want to start with you on this one. But as adjective AI scales, which gaps in our existing control frameworks are you most concerned won't get addressed fast enough?
Yeah, it goes hand in hand with what I said before. It's the lineage issue. It's really that we are applying really just static role-based access control and try to solve issues with that. We all know that doesn't work. We do it anyways because we are used to that. And when it comes to decision-making processes that are along the line of those delegation chains that I mentioned earlier, you won't have the insight. You won't have even an understanding who called whom at which time and what did they request with which intent issued by whom.
So this documentation and understanding what this lineage actually means and why this decision has been made, I think we are just not yet prepared for that. And that is something where we are really lacking solutions and even concepts, standards. Do either of you want to add to that? I think I recognize what you're saying. So and I think a small addition to that, we don't just lack the concepts, we also lack the responsibility in the organization. So really think about it, who's responsible for deciding intent, deciding why certain permissions are being assigned?
I think we all know the concept of yes, yes, that's a line manager or that's a application owner. But if you really poke into it, that data isn't very good.
Sure, someone's hit approve, but that data really isn't going to be good enough if you actually need to base your security off of that. I feel like this is a good segue.
Matthias, you mentioned standards. So moving over to regulations, obviously regulations tends to lag behind the threat landscape. But when it does come, it generally reshapes how organizations prioritize. So what regulatory pressure do you expect to hit the NHI and the Gentic AI security first? And how do you think teams should be preparing for it now?
Rogério, should we start with you? Yeah, so the pressure exists. I think even in the Gentic AI, so the EU AI Act is in place. Act is in force already. And then there are some elements inside, mainly related to risk management and the need of companies deploying AI agents to assign a human, they call human oversight. So that's something that if you need for whatever reason, you need to be compliant with the EU AI Act, organization need to think about and implement certain controls. And the same for others, regulatory compliance like NIS2, DORA.
So they are all at somehow including NHI within the text, if not explicitly, but at least for example, in the NIS2 in one specific topic about cybersecurity controls, they mention authentication, authorization, risk management within all identity systems. So all identity systems imply that NHI also should be governed somehow, which means if you need to be compliant, you need to be able to demonstrate that you control and control NHI as well. So that's the pressure that I keep coming.
And maybe to add to that, you've mentioned DORA, you've mentioned NIS2, they don't, I'm not a lawyer, I'm not an auditor, but they don't mention human or non-human identities. They manage decision-making processes. You need to prove why or you need to have evidence why something happened within an organization because this is what you have to be able to present evidence for, no matter whether this was an agent or a person. So your question was what will hit us? It is hitting us right now because DORA and NIS2 are there.
The EU AI Act will come in August, if I remember correctly, but this is already there. We have actors acting within an organization, transferring money, doing things, and we need to provide evidence of that. So the regulation is there. Maybe we are not yet prepared.
Yeah, I'm thinking if I have anything to add to the other good comments that are already given. I think one addition, when I look at agents and also non-human identities, but especially agents are moving up in the stack and doing more and more with the actual data in your systems. So your traditional NHI, at least in my view, is static, is rule-based, and generally doesn't touch and transform the data that much. And I suspect agents will be doing that a lot more.
And I think from a compliance perspective, that'll give us a lot of challenges because data access management often isn't that well controlled. And then when people put the magnifying glass on them and say, why is this agent doing this? With humans, you can get away with, oh no, it's just part of their job. With agents, you're suddenly going to have to explain that and hence be in control of their data access, which a lot of organizations currently aren't. So I want to move over to the vendor space.
And obviously, there's so many security vendors we're going to meet a lot of them upstairs a little later today. It's totally exploded in the last 18 months. So by the end of this year, do you guys think that we'll have consolidation, or do you think the problem space will fragment even further? I'll be happy to take that one first. Call me a pessimist, although I'm generally an optimist, but I actually think it'll fragment further because we're just seeing the scope of AI use growing.
And primarily, we haven't really nailed down what the problem is we're trying to fix yet at a detailed level or how we're going to fix it. So I think it's going to fragment further until vendors have really proven their technology works. And I suspect that won't be by the end of this year.
Yeah, so one of my role within PwC is to look at the vendors because we have so many alliances, usually big alliances. But it's to look at the vendors landscape and see which vendors we can bring to our portfolio. And in the last year or two, that became even harder because there are so many vendors in many different space. And one thing that I've seen is they usually, the vendors will use different terminology. So you look at the product, it sounds like the same, but they call it differently. And I don't see this as a consolidation in the next year, 18 months, it will be even more fragmented.
We might have seen some acquisitions. We saw recently the Asterix by Cisco, so which is something that could be expected for like good vendors, so to say. But it makes for organizations buying product even more difficult. And like you said, so we need to look at the problem that you have, focus more on the required capability than on tooling, like buying a new tool will not solve the problem, but look more at the problem, the required capability, and then the vendor landscape. Right.
If we maybe apply a different angle, I think there are a bunch, a class of solved problems or problems that are currently about to be solved. And vendors who provide solutions there, I would expect consolidation because that is something that will happen naturally. So they will be taken over, integrated, and working together with larger ones. All the issues, all the challenges, all the clusters of problems that are not yet solved, this will fragment.
So there is no uniform evolution in the market, but we even have not fully charted the overall market when it comes to what do we need for NHI or AI agent or the bigger landscape surrounding that to have the proper terms for that. So we are still in a definition phase right there. So everything that are, to put it not that nicely, yesterday's problems, which solve NHI and AI agent problems, those are the ones that consolidate. But as mentioned before, we are lacking solutions, products. And in the best case, we have fragmentation. In the worst case, we have nothing.
Yeah, it'll be interesting to see what happens. So thank you guys for that. So before I get to my last question, I want to do a quick hot take. So you're going to agree or disagree, and you can tell me why. But the hot take is the industry is so focused on securing AI agents that we're neglecting the far more immediate NHI risk sitting in our environments right now. Agree or disagree? I think I would agree, especially because for the AI agents, we don't quite know the capabilities we need yet. We don't know how to solve it yet. For the non-human identities, we do.
It's a lot of work, but we do know how to fix it. But I think we also know if we don't fix it, then we're not going to be able to secure those AI agents because they are, well, I'm not sure clever is the right word, but they are unpredictable enough that if you know there's a gap they can use, the chance that they will use it is quite big.
Yes, I agree. I think we like IPs until it goes down again. But anyway, I don't think it's a bad thing in the end, because like I said, so at some point, if you really want to deploy agent-key AI in production at scale, you need to fix the existing problem. And NHI is one of these problems. And not only, we could mention even on the identity and access governance workforce, consumer identity, if you have consumer identity and you want to deploy agent commerce, there are some hidden issues there that will come up and need to be fixed before deploy agent.
So that in the end, the bad is for good, so to say. Maybe it's also dependent on how we define NHI. We tend to make the term NHI as an umbrella term much too large. And then we include things that for me are not NHI in the way that we currently think about it. But these are technical accounts, privileged accounts, secrets, API keys.
Yes, that could be considered as NHI, but why don't we apply the solutions that we had 10 years ago, patent, secrets management, API management, and solve these issues separately. And that could have been done years ago. And then we could build upon that and scale it to the scale that we have right now. So I think we are tackling problems under the umbrella NHI that are not really NHI problems that should have been solved earlier. And then we could focus on the fun stuff, on the agentic stuff.
But since we were not good enough, I said that 30 years in the business, we know how to do things, but we tend not to be comprehensive, covering everything. If we would have done that, we could focus on the real new concepts that are around, and securing a secret is not new. So for a final question, obviously, everyone's going to learn so much this week, obviously from this morning and all the sessions, but it has to be actionable. So I want to know, where should people start? So on Monday, they go back to their companies. Where should everyone start preparing?
What is one thing that they should do first? I think one message I would give everyone here is don't focus on all the very interesting technological challenges we'll be talking about, but actually think about the governance question. Who's actually accountable and responsible for ensuring your compliance frameworks are in place, setting up your rules and policies, and making sure this is all managed?
Because what I suspect you'll see, if you start thinking about it or writing it down, is that everyone in your organization sort of wants to reap the benefits, but everyone will also say, yeah, we're actually not responsible for securing those agents or securing even NHIs. And they'll sort of push around the hot potato and say, no, no, that's CISO, and then CISO says, no, no, that's us, that's them, and that's them. So actually have the conversation about who's responsible for fixing the problem, who's accountable for it, instead of focusing on the technology to fix it.
Because even if you have beautiful technology, if there's no one in senior management whose job it is to get it fixed, you're not going to get it rolled out. Yeah, I'll go on the same line. So I think organizations need to change the operating model, or the identity and access management operating model. So what we have seen until now is mostly three classical domains, identity governance, workforce, privileged access, workforce, privileged access, and sometimes consumer identity if you are dealing with consumers.
And all these are operating in their own silos, having PAM and workforce mailing as an IT security topic. And I think organizations need to remove these barriers, this silo, and bring all together a new operating model, and also involve cybersecurity operations. So we have been operating as an identity, as a separate group. I think we need to bring cybersecurity together. So removing silos and bringing cybersecurity together. So review this operating model.
Okay, much simpler from my side. Start on Monday and don't allow any agent being around without a dedicated human owner. That is a challenge enough, and maybe it will not work for every agent. But starting with that, it means finding all and assigning an owner. I think that's work enough and it's worth it.
Thank you, guys. Yos, Ruggiero, Matias, really appreciate the insights. Hopefully everyone learned something today.
Lalit, back to you. Thanks, Jessica, Matias, Ruggiero, and Joss. That was a great closing session. I guess if I was to conclude, look, we don't know all the answers to solve agentic AI. We're still struggling with NHIs. I think some of the advice given by the thought leaders, SMEs, were fantastic around focus on governance. That's kind of the basics, people, process, technology, look at your inventory, ownership. And I think some of the stuff that's kind of the exciting stuff from a technology standpoint around real-time, intent-based authorization, I think the team nailed it.
Look, I think there's going to be some consolidation on the stuff that we already know very well. But I think for all the agentic stuff that's coming to properly control it, I can see it already. I talked to a lot of vendors. It's so much fragmentation. There's so many agentic AI security players in the market now. I think for organizations, it's getting more and more confusing. So I think focus on the basics, just get control of what you have. I think the hacker issue, people breaking in, is going to be a smaller problem. It's still big.
And with Mythos, look, we've got lots of issues to tackle with there. But I think the shadow AI problem, just developing agents that are out of control without proper controls and governance, I think the insider threat issues are going to become bigger and bigger as these agents just proliferate within your organization. So I think looking at how you control them, how you manage them, how you govern them is really key. I just put up a few resources that people can look at, 5,000 different articles all about NHIs and agentic AI.
I definitely would encourage people to read, look at what's going on across the industry. Look, it feels like we've just touched the surface in this 90-minute workshop. We probably could have spent all day talking about this topic and gone into a lot more detail. I hope you found some of the content, the advice, insightful. And hopefully, you'll hear a lot more as you walk around and go to the other sessions and talk to vendors. So thank you for attending our workshop.