Welcome. Hello, Germany. Hello.
Hello, Berlin. Hello. Good morning. I don't know how many of you were here last year when I was on stage, and I thank the German people for the mercifulness. This is the year of the World Cup. Who's excited for the FIFA World Cup?
Come on, round of applause. Yes. Yeah. So do you think Germany has a good chance this year, the World Cup? No? Are there any Scottish people here today? Raise your hand. Nobody. Good. You know why? Scotland is the first team Brazil will face in this World Cup. So I'm a little shaky. So thank you for coming. My name is Enrique. An honor. An honor to be here. It's a closing day of EIC, and what I like the most about EIC, Copenhagen and be here in Germany is how multicultural this event is. I think it's becoming this great World Cup of identity, if you will. So thank you for having me.
Today, we're going to be talking about butterflies, and how many of you are familiar with the Glasswing project? Okay. More than Scottish people. And you know me. I like analogies. And when I saw the name of the Entropic project, Glasswing, they launched, I think it was April 7th.
I said, why did they choose that picture, right, to represent the project? And I think because, and I research, of course, the butterfly wings are transparent, just like vulnerabilities, that they scan the vulnerabilities in code that are invisible to the naked eye. Apparently, those type of butterflies are quite resilient as well. The wings are quite hard to break. And there's a lot of uncertainty, a lot of perhaps fear about this model represents mythos, mythos, how do you say that in German? I don't know.
But the challenge with mythos is, I think, both things, a little bit of hype, a little bit of reality, and that's what we're facing today in identity. There's several forces facing identity to change. And how many of you here were or did participate on the session from Marco Venuti today? I'm going to steal the title of that presentation. I think he said it was Italian precision, German creativity. This presentation today is about Brazilian speed with Canadian sense of human. So all those, yeah, okay. Those forces are really shaping the way we do business.
I'm going to go real fast, because it's a lot to talk about here and unpack. We got what we wished for. We as identity practitioners, we've been claiming for a seat at the table of cybersecurity, and we got it. We got the largest seat. We got the most important seat. So endpoint security, network security, cloud security, those are all important things. But they now depend on identity for context. There's one terminology. How many of you heard about identity as the last perimeter? Right? That is wrong. I disagree with that. Identity is not in the perimeter, because there's no perimeter, guys.
My people, identity is at the center. So if you know Jim and Jeff from the Identity at the Center podcast, I think they predicted this. And what my clients at Saviant, leaders that I speak with, what are they feeling is similar to this lady here. The pressure of adopting AI as fast as they can, but they can't make mistakes. Sometimes I treat Claude like that.
I say, Claude, do this for me. Don't make mistakes. But it is a very real pressure, because more than 90% of AI projects in 2025 had to be rolled back because they didn't show the results that business were waiting for. The ROI was just not there. And when we think about AI, I think not us, but a lot of people outside of IT, outside of cybersecurity, still think of AI as this chatty app on our phones, or Gemini, or Microsoft Copilot. But it's not.
AI, it's more than an app. It's a whole new abstraction layer that runs on top of Cloud. And to manage that abstraction layer, what I recommend those clients are feeling the pressure is a three-step approach. It sounds basic, but we got to repeat the basics, because we know how bad we are in just doing the basics. Number one, we got to discover. We got to find out. We got to inventory everything that exists in our environment in terms of identities. And when we think about NHIs, machines, AI agents, that is a whole new problem.
We got to govern this, add the adaptability on our IAM programs to change as we discover those things. And third, we got to be able to enable control, guardrails in runtime, so the business and the services we provide can be trusted. So this presentation today, I want to cover five things, five big trends that I've seen when talking to our clients, when talking to many of you, talking to my colleagues in the profession of identity, starting with platformization 2.0.
Last year, 2025, there was more than $25 billion involved in M&A, acquisitions and mergers of companies. Palo Alto acquiring CyberArk, which is now Idera. CrowdStrike, they bought Signal. There was a lot of M&A, a lot of M&A. And the promise here of M&A is to create that single pane of glass, which I think, yes, from my times at Gartner, a lot of times when I saw RFPs and RFIs of organizations that wanted to buy identity, it was not because of a longer list of features. They want something simpler. And when we think about M&A, about the platformization, my recommendation is this.
Does it make sense to you to combine single sign-on MFA with endpoint? I don't know. But there is, and there are, capabilities that make a lot of sense to go together. Privileged access management with IGA. You guys may have heard the joke of the pizza, the half pepperoni, half margarita. I know it's a dad joke, but it people that those two things should never be separated. So think of clusters of capabilities and identity that make sense together.
There will be, for example, the same way we see in cybersecurity in other domains like security operations when we combine endpoint and EDR with XDR. That makes a lot of sense to be converged. MCP. I don't remember the last time I that spread out as quick as MCP. This was invented in 2024. And it's almost, it feels like legacy a little bit already. It's super new. And it's super efficient. So if you heard about MCP for the first time here, wow, it's okay. Don't feel bad. But MCP is just another way of interoperability.
What API was for the cloud world, MCP is that interoperability way in the AI era. It's a new API for agents to talk. My recommendation here, we got to avoid the mistakes we did with APIs. Cloud is 25, 26-year-old. Yeah. The first company, the first company was Salesforce launched in 2000. 26 years old. Cloud is old. And it's not going anywhere. Cloud is still there.
Remember, AI runs on top of cloud. AI runs on top of cloud. Remember that. Because the mistakes we made with cloud, that's why we have so many startups doing NHI stuff today to clean up that mess that we created. So when you are deploying MCP today, MCP needs credentials. Don't let the credentials just explode. Okay? Vault them, control them. And how do you vault them? How you control them?
Well, modern machine identity management. I have a friend, Felix Gattingens. We're still friends. We compete now. But we're still friends. And he used to say, static credentials.
Sorry, I can't make a German accent. Static credentials are like asbestos. And he's right. The same way that we use asbestos as insulation for houses, right? And now it's illegal. It's illegal to use it. And Felix uses it.
Yeah, we can't continue to build houses with asbestos. So that's it. We can't build new apps that use static credentials. That's how we contain the problem from becoming bigger. But we've done that for 26 years. So we go back and retrofit those houses that we built using static credentials with things like Spiffy and Spire. And that leads me to visibility. How many times you heard in this conference about the visibility? I can bet a lot.
Gardner, they created this new acronym. I don't think we need platforms. Because it's a real problem. And especially when we shift from humans to NHIs and agents, we really don't know where those things are created anymore. So number one, to fix that legacy of asbestos that exists. But also the new things that will come up. The open clause of the world. Agents running on Mac minis. The visibility will become super, super important. And what I suggest here is to start with the identity data.
Yes, we can think of sophisticated things like network monitoring for activity. Just start collecting that data.
So, for example, if you're using Zscaler, if you're using CrowdStrike on endpoints, use that to collect information that is happening on the endpoint and send that to your platform of choice for managing identities. And last but not least, I was talking to another analyst. And he mentioned this to me. Imagine the agents that we create.
Which, by the way, agents are harder to build than we think. And I'll get back to that. But this analyst said this. Agents are like these robots walking around the network trying to access things on our behalf or with their own permissions. It's almost like this dumb employee with a lanyard with their credentials on their necks. And somebody could just snatch it up and steal it. And it is quite problematic. Because if you look at the way attackers are looking at this opportunity today, they're not gonna be stealing Vlad's credentials. They're not gonna be stealing human credentials.
Because a human, when you are hacked, you're gonna raise your hand, hey, I think I've been hacked. I've been locked out of my account.
However, if you are hacking an NHI, if you're hacking a machine identity or an agent, the agent doesn't know. So, that's a very clear path, low-hanging fruit for the attacker. When we think of what we can do here, and if you are running an identity program today, okay, if you are a practitioner, if you have some sort of responsibility of running IAM in your organization, the one thing I recommend you is to expand the scope of what you're managing to include those non-human entities. It sounds like a very basic step, but it's something that we can do today.
When we look at this trend, and I want to be very clear, those are things happening today. Those are things that took us here. Mistakes that we did for the last 25, 26 years. Remember a few things. AI runs on cloud infrastructure. Building an agent is more difficult than we think.
So, don't feel bad if your manager, your director says, yeah, we should be adopting more AI. Everybody can create an agent.
Well, I tried. How many of you have tried to deploy an agent?
Well, the last two months. How many of you?
See, it's a minority. Just last week, I was in Washington, D.C. at a Gartner event, and they showed me this statistics on the screen that only 8% of people in organizations are launching agentic AI in production. I'm not saying this is some sort of issue or some sort of problem. It's just a reality. It is difficult. It is harder. Because when I tried and I used clouds, hey, I want to create an agent.
So, yeah, it's very easy. So, you show me the Python code.
I say, hey, what is this? I'm not a coder.
No, you got to put this code. It's very simple. You just put it in a container in AWS. I need an AWS account.
So, I need to call the IT guy. So, it is difficult.
So, that's why Mac meetings are so popular, because you don't have to call the IT guy. Anyway, I talked about five big trends. Like I said, those are not future things. Those are not predictions. Maybe predictions is a talk for another time. This is happening today. This is perhaps a good slide for taking a picture and taking home. But I hope you enjoyed the fast ride of a Brazilian Canadian here.
Thank you, again. You've been great. And it's Friday. Thank you for having me. My name is Enrique. Thank you very much.
Thank you, Enrique. It's been great having you. You left us with lots of great images. I like the pizza one. I like the asbestos. Unfortunately, you used the G word, which is kind of verboten here at EIC.
But hey, we'll forgive you, seeing as you're such a nice guy. I just have one question here. Machine communication protocols are, and machine IAM, which you referred to, are evolving quickly. But governance, as ever, still lags behind. Which category do you think of machine identity is enterprises currently understanding the least from a least well from a risk and accountability perspective? I'm thinking of things like workload and infrastructure and so on. I think most leaders understand the concept of service accounts. I think those are perhaps the easiest to understand.
Between service accounts, API keys, OAuth tokens, I will go with OAuth tokens. I'm not putting agents in that same category. But between those static type of machine credentials, I think OAuth tokens, a lot of people say, oh, is this authentication? Is this authorization? There's a lot of unknowns in that.
Okay, great. Thanks once again. Give it up for Enrique Teixeira. Thank you.