What's Next for IAM: AI, Identity, and Disconnected Apps
And welcome to today's dark reading webinar, Identity in Flux, navigating what's next for IAM leaders in twenty twenty six, sponsored by Cerby and broadcast by Informa Tech Target. Terry Sweeney here, contributing editor with dark reading. I'll be your moderator for today's discussion. It's safe to say that identity programs have entered a a period of transformation like like most of the security landscape. Ai adoption is driving a lot of that and creating lots of excitement and concern in its wake. Also, some compliance expectations that are rising alongside it. Users are adopting applications faster than IT can govern them, and identity sprawl, disconnected systems, and poorly controlled credentials put new pressures on IT and security teams. With with all that in mind, our speakers will be breaking down what the next eighteen will mean for identity and access management and for security leaders. They'll examine legacy identity practices that impede progress here as well as how to modernize governance at scale. They'll also be looking at where AI is creating both new risks and new tooling opportunities. On that note, I'm excited to introduce our speakers. I'm joined by Bell Lepe, cofounder and CEO of Cerby. He's joined by Youssef Khan, venture partner from Ridge Ventures and also a former CIO. Gentlemen, welcome, and thank you so much for doing this webinar today. Terry. It's great to see you. Before I hand it over to you, Bell, I just wanted to remind our audience of a couple of logistics. If you've been here before, you know this webinar is designed to be interactive between you and the speakers. At the bottom of the screen, there are buttons you can click on to learn about today's speakers, download a copy of the slides, and also share this webinar on social media. This is also where you'll participate in the q and a session that takes place at the end of today's presentation. You can also use that q and a window to let us know if you're having any technical issues, and our team will do their best to assist you. Okay. I think that's that's it from my side. Bel, Youssef, the the floor is yours. Excellent. Well, Terry, thank you so much. And, Youssef, always an honor to be able to, share the stage with you, virtual, here. But, regardless, looking forward to to this conversation. And to our audience, thank you, to those of you joining us live and to those of you that are watching this after the fact, very excited about this conversation. So as Terry mentioned, we are at a very exciting point in the trajectory of identity. We are seeing now that more and more, you know, there's there's the cliched line of identity as the new perimeter, but it's become increasingly obvious that that's you know, that that there's actually money being put behind that statement. And so where we wanted to start the conversation today is is, you know, talking a little bit about some of the headlines that we've been tracking that, you know, we believe are very much pace setting and context setting for where we are, generally speaking, with regard to identity, and then also how we wanna be talking about identity over the course of these next, you know, several several minutes. And so, you know, Youssef, feel free to jump in at any point in time, but one of the backdrop items that we wanna talk about, again, is this idea of identity as the new perimeter. It is a sentiment that has been uttered for at least the last five years, but what is very fascinating about what's been happening over the last three to four months is you're actually seeing money being put behind that statement. Right? I'd argue with Palo Alto Networks. They kind of, you know, broke the ice with their announcement of the acquisition of CyberArk for twenty five billion. And then in fairly quick succession, you saw other multi hundred million billion, in some cases, investments, whether it's Savient or ServiceNow's acquisition of Vesa or CrowdStrike more recently signaling their intention to acquire Signal. And so this is this is the context that we're in. Right? Everyone is realizing that, again, identity is a new perimeter. And if they do not have and I'm saying this more from the vendor side, if they don't have an investment in identity, they are making very major investments to acquire those capabilities. And so, Youssef, maybe starting there, I'd love to get your thoughts on how are you looking at some of these these investments, and what do you think they indicate? Yeah. So I think, first and foremost, I think it's really important to to talk about the fact that, ultimately, identity has now become a much bigger component of both the security budget in general. I think that's increased probably at a pretty exponential pace over the course of the last, I would say, probably five years. I mean VESA was founded in twenty twenty. I helped the founder, Turin Takara, at the early stages when that company was being formed. And prior to that, of course, it was started it saw the IPOs of companies like Okta and others come into place. But I think the real transformation and prioritization of identity and identity management has really come to a level of maturity as you pointed out. Part of the validation in that of course has been the acquisitions. But let's actually talk about why that is. From my standpoint, having been both a CIO and CISO in standing in a number of companies, What we've discovered, and I speak to a number of CISOs just like you do, is that ultimately landscape of the enterprise has really become a multi platform and has done so in a very accelerated pace. Initially it was just the core on prem applications, the enterprise applications that we're using. As of course the emergence of more cloud and SaaS came into place, that started to come into place from a perspective of just management of those identities. And people said, well, just integrate it into your single sign on provider or otherwise. But it wasn't simple as just access. It's actually about the data that's going in, it's about the fact that you are now having companies that have a much closer customer experience. Like if you are able to if it's easier for you to be able to create an application and therefore put that on the App Store for example or be able to distribute that on the web or and actually increase the marketing of that application in social media and other channels. Ultimately, you have more eyeballs and you have people who are looking to access that application either as a partner, either as a customer, and of course, know, vendors or otherwise. And so I think the harsh reality is that people underestimated how big of a real estate an enterprise needs to have. I mean, if you just look at a a standard company, you are looking to basically consolidate people to be able to access data, to be able to run workflows. It may well be as simple as a vendor accessing a procurement portal. It may be a partner that is adding in information for a partner event. It may be a customer accessing access to their account. It may be, you know, contractors, for example. So that has really evolved and exploded as a result of customers and companies evolving their products and wanting to get closer to their constituents. Right? But that comes at a cost. It comes at being able to manage it from a cost perspective. It comes from managing it from a security perspective, and then being able to actually analyze and figure out how to basically make sense out of it. So I I think people are just have thought, well, identity, well, must be, well, it's just accessing your cloud environment like or Snowflake like what Fezza has done, or like Cerby has done to be able to say, look, all the unmanaged applications. And I think that's one of the things that I was excited when we looked at your company was the fact that you are solving a problem that has been around for a while, but needs to be solved for. And the latency in appreciation and recognizing that as a problem is the opportunity, but that's really a parallel to what's happened in the identity industry as a whole. Like, people have realized, woah, there's actually more people that we need to be able to manage and provide a good experience for. How are we going to do it? It turns out that there's a there's a very big market for those solutions. So that's the way I've I've come to have a reading of it. Absolutely. No. And to and, you know, that's a fantastic segue into one of the key topics that we're gonna talk about around identity sprawl across, you know, the the growing application landscape. To put some numbers behind some of the trends that you've mentioned, there was a recent survey, I believe it was by PwC just in this month, in which they surveyed a number of IT and security professionals, and eighty four percent of them said that they were expecting to increase the amount of investment that they were doing into identity and access management. And across that group, the average percentage that identity and access management, is going to take up of the overall pie was between twenty and thirty percent, up from ten to fifteen. So it's a substantial increase that that we're seeing. And, Youssef, to your point, it is this realization that identity is the attack service, but I think it's important to double click into that. How is it, you know, the new new perimeter? How is it the new attack surface? You know, we do a lot of work with both highly and, you know, quick kind of background on Cerby as as Youssef mentioned. We focus on the last mile of identity. We help organizations like L'Oreal and Fox and Dentsu protect the applications that historically have been unmanaged. And one of the key trends that we've seen from our customers that are both in the highly regulated spaces as well as our of more of a consumer brand, consumer technology type is that when they look at the threat activity over the last half decade, more often than not, the initial point of entry is an unmanaged identity. It is a username and password for a partner. Right? For example, one of our common use cases is helping to protect the marketing stack. And the number of times we hear about a situation where the marketing team lost advertising spend because a partner identity for an agency that they don't manage was compromised, well, it happens a whole lot more than than you would expect. And so one of the motivators for this, for the focus on identity and, you know, in a more comprehensive fashion is that there's a realization that you need to be looking at all forms of identity, not just within the organizational boundary, but beyond the organizational boundary, protecting what your partners use, protecting those government reporting portals maybe that use if you're a Fortune two thousand to report out, you know, quarterly earnings. They are all valid entry points for an attacker. And if you are a business that has achieved any sort of revenue traction, these are components that you need to be, you know, that you need to be mindful of. Now, Youssef, maybe a a a question back towards you. You know, you've been CIO now multiple times. You know, I'm I'm curious as you look at this backdrop, the attack surface is becoming not only larger, but the ability for the threat actors to go after more of that attack surface comprehensively is also becoming, well, just they're they're more able to do it because of AI. How would you encourage folks in a similar position as a CIO, lead leader of IT, leader of security to think about investments in the time ahead? Yeah. So I think so first and foremost, I think we have to recognize, and CIOs and CSOs have to recognize, that identity management is a full time job. It it requires focused and dedicated effort. I don't think I mean, in the past you could kind of have this as a part of a role for a system administrator when they were, say, rolling out a single sign on solution for access. But the harsh reality now is that because of just the sprawl, the number of applications, the platforms that you're using, identity needs to be managed in a full time focus. So that would be first and foremost. The second is, you should actually look at this as a strategic initiative from the security perspective. It's clearly, it's a way to be able to measure it, it's a way to be able to demonstrate that you're able to reduce security risk and improve your cybersecurity posture. That's, for example, one of the things that Servi is able to. You're able to discover a number of applications and say, Look, let's go and get these all integrated and in a place where there is good hygiene in place and it's following best practice. And then the third ultimately comes down to really focusing on being able to run a good program when it comes to looking at new vendors or new solutions that sort of come into place. And to be able to make sure like even now in twenty twenty six, the number of applications that are coming into an enterprise which don't have a good identity posture or security posture, it's not just like SOC two type two with your vendor. I think it has to be deep, and that is if you are integrating into an environment, have a thoughtful conversation about thinking about what data they actually access, how that should be audited, how it should basically run. And that just requires to be a little bit strategic about it. I think overarching this, I think CIOs need to understand that it's a multifaceted problem. I think it's going to grow. And I don't think and you have to remember, it's like I think as you have as CIOs have now deployed more software, built more software, as they bought more software, ultimately what happens is that the identity attacks are just going to be accelerating through not just the use case of AI, but because it's like there are multiple points of entry. And so as a result of that people are you know, there is a trade off. You can say, well, I'm just going have one monolithic application, but that doesn't exist anymore. That's not really a concept that has ever worked. And so ultimately you need to have understanding and appreciation of that. So you have the right partners in place to build with that. Hopefully, Cerby is one of those, but you have to actually have this as an identity stack versus thinking it as just part of a a larger stack. That's the way I would look frame to it. Absolutely. Absolutely. And and, again, I I'm a big fan of numbers. And with my you know, since we're on the topic of AI, my trusty AI copilot here in the form of Gemini feeding me statistics. But, but, you know, some of the statistics that, you know, support what you're saying, you know, the average enterprise has around three hundred and seventy applications, right, to your point about, the the surface area that they need to be protected. But, typically, IT team is the the ITT team and security team is unaware of forty percent of them. Right? And so that that's that's the situation. Now and I'd love to maybe get your perspective on this. You know, the the fascinating thing about security is that by definition, it is historically, it has been very asymmetric, which is a attacker only needs to be successful once for them to do damage. Whereas a defender, you know, typically on the enterprise corporate side, they effectively need to be perfect across the board in order for you to say that they have been successful. And so you have that situation, and then you also have the situation where you don't necessarily want to slow down the pace of innovation for your employees. You want them to experiment. Right? You want them to be able to go out and use the latest and greatest technologies. But you end up in a situation where, again, another recent survey indicates that a typical enterprise of five hundred or more employees will be using north of a hundred different AI powered point solutions. I mean, just crazy. Right? And fifteen percent of the time, employees are putting sensitive data into those those platforms. And so, you know, still on that topic of investments and as a former CIO, how do you balance that that contention and, yeah, that risk of enabling your employees to be able to experiment but not putting the business at substantial risk in the process of doing so. Well, you do that by understanding and appreciating the level of risk that you're willing to take and the impact of, bad posture as well as bad security practice and what that means. I mean, you know, the the challenge of CIOs and CISOs typically have will always be about prioritization. How much rich risk they are willing to accept? And ultimately, what that comes down to is aligning yourself and your strategy around corporate objectives. And if you take the most fundamental ones, which are customer experience and customer data and be able to look at revenue profitability. Like, security strategy is now directly linked to revenue generation. Okay? If you have a breach in a company, ultimately, customers lose trust in that company. And, you know, that's not the chief marketing officer's job. That's not the, you know, chief, you know, the chief procurement officer's job. That's the CSO's job. And I think that's where a large part of the industry has to wake up to the fact that their work has considerable impact on on the company. Right? And I think that's so first and foremost is put the customer and put the corporate strategy at the very heart of your strategy, and then work your way down to be able to actually understand and figure out what those risks are. One of the challenges that a lot of CSOs and CIOs is they are not able to adequately articulate and advocate for being able to give bigger priority and bigger investment on the security side. And so my hope is that that's something that you are able to do when you're when you're able to go to customers and to be able to give them. And I think the data you're sharing, you know, as much as, you know, stats are stats, like this is useful education enablement that's required in the industry. People need to be able to actually understand how big a problem this is and what it could lead to. If you think about some of the biggest breaches that have typically happened, we can go through the list, twenty three and me. They didn't have they didn't have two factor authentication on customer identity. Guess what? The company barely exists anymore. Right? Just went through an you know, and and went through pretty much got destroyed in value. Target, the CEO, got fired. Why? Well, because somebody's able to get into a place, into their EPOS system. You know, if you think about Home Depot prior to that, that was also, you know, due to basic some way down the line, this identity is related. Access to your systems is related. And so you've got to understand the downstream impact of not doing this well. It requires you to be thoughtful to be able to have a strategy in place to do it. I think the other big thing I would highly recommend is to really push both vendors and figure out a way to be able to run a program of audit and be able to do that. Some of the examples you mentioned, you know, when we first started talking, you know, years ago, it was kind of obvious to a certain extent, but it wasn't being dealt with. And I think the other thing with the AI piece that's important is the nonhuman identity piece is now starting to become much more of a bigger issue because agents, of course, are being deployed. Agents are not just being deployed centrally when you're looking to do as a customer service solution that you want to sort of put into place. But yeah, there's a bunch of people by coding. There's a bunch of people being able to that. You can't solve all of those problems. Let's be real. Like, you can't go to you can do as much as you can to tell an employee, well, don't share this sensitive data or mask it this way if you're gonna have chattyPT, but there's only so much you can base control. There's a level of accepted risk there. What you can do is is what's within your control in terms of best practice and to be able to drive that further forward. Absolutely. Absolutely. And and, you know, so many important bits of guidance there. You know? Again, just to highlight a few of them from a statistics perspective, you know, starting with nonhuman identities. The numbers that I've seen indicate that in the typical enterprise, for every one employee, they're usually one hundred machine identities. And so wow. I mean, talk about a asymmetric ratio there. I mean, that that's a lot of machine identities. And all of them need to be appropriately permissioned. And let's let's be honest, more often than they're not. Right? More often than not, the OAuth token that they've been given gives them far more access than they than they should have. And then to your point about, CISOs and and CIOs and other IT and cybersecurity leaders, helping them articulate, what's at stake. You know, a a recent, customer, case study that we launched was with monday dot com. And what is so fascinating about that case study that we launched is that the narrative that we've been able to tell together as, you know, customer and vendor is not just about improving the security posture of these two hundred applications that they were not able to otherwise manage by way of Okta, which is their identity provider, but also being able to tell the story of the productivity gains that they've gotten from working with Cerby. And so, you know, this is potentially an an obvious statement, but security and productivity, believe it or not, actually go hand in hand. I I I think historically and certainly prior to the AI era, the perspective was that proper security meant inconveniencing the end user from a user experience perspective. But now what you're able to do with certainly with platforms like Cerby is you're able to both improve the security posture and make your employees more productive. So what what are examples of that? You know, at customers like Monday and others that we've worked with, we would see numbers like an average of two to five business days for an employee to get access to an application that they requested access to, which is mind boggling. Right? Think about all the lost productivity while you're waiting to get that ServiceNow ticket completed. And with a platform like Cerby, we're able to reduce that down to less than five minutes. And so using the right tooling, using the right automation, training your employees on how to leverage these these capabilities both for your connected applications that do support standards and for your applications that don't support the standards, which is, you know, our our focus area. When you're able to get approach working across the business, it has a tangible impact not just on improving the security posture, but also in terms of improving the productivity of of each individual user. And so we help our customers. We enable them to be able to tell that story, and we find that that's a that's a compelling story because it's, again, not just about these soft savings that you might drive. There there are hard savings around productivity that that materialize. You know? And and curious, Youssef, from your perspective as a CIO, is that have you found that that's a compelling way to tell that story to articulate why investment in this area is necessary? I so I think, yes. But I think there's one additional piece to it is that ultimately you can look, you can try and automate as much as you can on on some of your processes on the on the on the identity side and to be able to drive that further forward. And so, yeah, I was, you know, startled by that by that stat, I think. I think that would be supremely problematic. But I think there's other aspects to it. For example, there's just basic aspects of cost. Right? I mean, if if if you do not manage this, the added the additional cost of just seats and data ingest that maybe a particular application because it's tied to an identity is is put into place, it's gonna go through the roof. So the the ROI piece is is real, and you just like, having a good having a good process and having a focus in this area is going be helpful from a bottom line dollar perspective. Second is you can weigh the costs and implications of a major breach as a result of identity, PR, reputation, customer brand, all of that stuff, versus how much you wanna be able to spend on being able to solve this problem. Okay? And I think that's also important to be able to talk about. Third is it's also about experience. I think most people sort of forget this. Like, if you think about having a much more unified like, you know, if you don't have a good identity strategy, the people who are you are providing access to will start to get a negative experience. I mean, they'll start to feel, well, why was I able to either not log in or was I not able to access? Or by the way, if if if it's so easy for me to either bypass or, you know, not not basically be be tracking some of this stuff, then what does that mean for my data? I mean, that's ultimately sometimes it comes out that companies that have had breaches when it comes down to it. You lose trust. You're like, well, you know, a lot of my data is now out there. Now look, I'm not saying that, you know, there's more breaches happening than before. But if you are a CIO and a CISO, you need to be able it's better for you to be able to robust plan, be able to basically drive towards that success, and understand that there is a much wider impact positively towards the entire company. And productivity is is part of it, but productivity and improvement of that has a number of other benefits that sort of come as a result of it. Absolutely. Absolutely. And and, you know, where I see some difficulty as we're working with our our our IT and cyber security counterparts is quantifying that. Right? Yeah. Because it is very possible to, at a high level, understand and appreciate that. But when, you know, dollars hit the spreadsheet and you're presenting to the CFO CFOs, you know, how do you quantify that? And, you know, another anecdote that I I I think is is very helpful, you know, with one of our other customers, Similar situation to Monday where we're managing about two hundred and fifty applications that have historically sat outside the identity perimeter. After we onboarded the first fifty or so applications, we identified about two hundred and fifty thousand dollars worth of licenses that were assigned to individuals who were no longer at the business. And and so, you know, there there's to your point, Youssef, about hard costs and hard savings, I mean, you know, that's that is one of the nice benefits when you're, running a proper, consistent, predictable, identity access and governance program, across all of your applications. Yeah. Now, we're oh, sorry. Did you have something you wanna mention? Well, I I think the the point I'm making is it all adds up. If you think about it, it it it really it all adds up, and it it comes down to the center of it. One thing that basically add is the number one threat every single time in every CISO server for the last five years has always been phishing. And the fact that there is an employee who will unfortunately click on a particular link which and look, they're getting more sophisticated than ever before. Right? So if we appreciate and understand that that is will always be a threat vector that we it's going to be difficult to close, then let's work our way backward and say, well, if that's the case, what are they going to probably divulge? One of course is the fact that you click on something and it's ransomware. But the other piece is, as you run an identity program, for example, employees, you're helping to improve cybersecurity posture and awareness with them, you know, as a result of that. But they're able to understand that we're able like, that's there's that's the subtext. Like, when you put in, you know, authentication, when you're able to basically say, okay. Here are the practices we have have in place. They themselves, as a result, appreciate that, and it becomes something that they become a little bit awareness of. So I think it's important to be able to point that Absolutely. Absolutely. And and that that strategy or that sentiment of it all adds up, and there are multiple layers to how you should be thinking about your identity perimeter. Think that's also represented in a lot of the broader macro movements that we're seeing here where they're doubling up on different identity capabilities. And so I think the vendors definitely acknowledge that. We're now at about the halfway point. And one additional topic that I wanted us to tackle here before we open it up to q and a, and it's on the topic of AI moving fast and and raising risk. And and maybe as we we've sort of been touching on AI, but as we touch on the topic a little bit more, maybe starting with a fun question. I'm curious, Yousef, both wearing your CIO hat and also your investor hat, what have you been most excited about from an AI perspective within the enterprise? You know, whether it's a particular platform or tool that you're spending a lot of time on or or trends that you're tracking very closely. Yeah. So I I think, you know, I speak to I've, you know, spoken to tons of founders, of course, as as part of job, but also speak to a number of CIOs and CSOs, and I think that's been the kind of community that I've, you know, been embedded in. Here are the few key things I I'm saying which which I can save to say are are a real thing and are basically making traction. Code generation for sure. I think solutions out there that are really having an impact, the productivity uplift that is sort of coming in from those are is real. I don't think that should be a surprise. But what should be a surprise is the use cases that people focus on. For example, you know, Cognition, original creators of Devon. The solution is fantastic when you speak to CIOs about the backlog that they are unlocking in their work. If you think about Claude Code and Cursor, those have been phenomenal for not just backlog, but also net new applications. So I think code generation continues to be something that it's really, really impactful, and and companies are looking at. I think the second is really and this is much more not emotive, but it is the fact that it the emergence of AI, it's just captured so much more mindshare that it has opened up both the imagination and drive to be able to really transform an organization from all aspects. It's not just, you know, CIOs are at the heart of it because they're more involved in being able to bring this all together and make it real by enabling the right platforms and overseeing the right level of security, as well as able to integrate the data. But, you know, definitively it's clear that people have woken up to the fact that and it could be as experimentation as vibe coding. I'd to say that you can't vibe code your way into enterprise. It's not really the way to do it, but you can look to make things what you've been thinking about a reality or at least see what they look like. And I think that's definitively. And you look at companies like Replit, have seen an explosive growth, I think that's worked out really, really well. I think the the third piece has really been about looking at at data and how now more precious and valuable it is as an asset. The the use of data in an enterprise that is being used for training, one. Number two, it's also very messy. And I think that's one of the challenges that I continue consistently hear from CIOs is that a lot of AI projects are failing because of the the issues in data quality, and so work that needs to be done to be able to clean and organize unstructured data is required. I think that's that's super important to do. But generally speaking, the infrastructure, you know, it's been three years post JetGPT, right? And so we've got to be thoughtful about why there are a lot of AI projects that are failing. And I think it comes down to really being able to re architect and rethink your organization from an application standpoint, and security is a part of that. If you are now deploying an application or a product that requires somebody to be able to access it and provide to customers, and you're having AI integrated into it, how is that being managed? How do you basically look to cater? And so all of that tooling from observability to identity and others, all of those need to be taken into account, and that's seeming to be a topic of conversation amongst the CIO and CSO community on a regular basis. Absolutely. Absolutely. It's it's so very well said. And if I could add maybe two additional things that from my end, one an anecdote and one a trend that I that I think is very critical. You know, from the perspective of Cerby, one of the other ways to think about Cerby is, you know, we've all probably seen that metric that anywhere between eighty five to ninety percent of the the data that we have in the enterprise is unstructured. Right? It's it's in a form that we're not able to access. And so what is so exciting about generative AI capabilities is the ability to programmatically and automatically go and find that data and structure it and activate it. And, you know, we're we're recording this, you know, middle of January in twenty twenty six. There's a lot of conversation going on right now around the context graph. Right? That those that own the context graph are the ones that are actually going to be the ones that win the the AI race. I mean, obviously, NVIDIA, etcetera, they're they're in a league of their own. But outside of those folks, if you can build that context graph and for CIOs, for CISOs, those of those of you on the technology side within your businesses, being able to active activate that unstructured data, build that context graph, that on that not only helps you internally, it also helps you turn around and create a much better product and, more importantly, much better customer experience. And so that's something that, you know, for us, as a last mile identity product, we're doing our part to activate the part of the overall graph that historically has had unstructured data. And then, you know, the the anecdote that I wanted to share is, you know, we we're a growing team. We closed our series b late last year early last year, I should say, fifty four million dollar round, and, you know, we're we're expanding into new regions. We brought in a new CFO. And one of the my favorite things favorite AI stories that I've shared is our CFO vibe coded our pricing calculator. Wow. And how cool is that? Right? I mean, he he he turned that around and iterated on it. And and so the level of productivity, the the level of of experimentation that it's aligned when safely deployed is is something that's that's tremendously tremendously just great to see. So I'm gonna propose we transition to the q and a section now, Youssef. So, Terry, I'm gonna and we already covered this next slide, so we'll we'll go ahead and and skip it. But, Terry, back over to you before we jump into the q and a section. Thanks, Bill. Really great context and perspective and and and even great guidance on on building and managing identity in today's enterprises. Thank thank you both for that. Really, really you you set up the q and a really sweetly. So we have some audience questions. But before we go there, just as a reminder to our audience, to participate in the q and a, strangely enough, you type your question into that text box located to the right of the presentation window. You can also click on that q and a icon question mark at the bottom of the screen. If for some reason we can't get to all the submitted questions, we'll be sharing them with our speakers who can reply offline. So, let's see here. We've got a question from Vikram in our audience. He's he's asking, how do we measure the effectiveness of maturity, of identity and platform, of identity platform and identity as a security perimeter? He notes that with firewalls, you can effectively show what the external domains, IPs, DDoS sources, intrusion sources are. With identity, how do you show the same? What what are what are some powerful metrics that are emerging in in this new world that we're discussing right now? I I can I can provide a perspective on that if that's okay? Please. Thanks, Youssef. Yeah. One word, coverage. Okay? So think about your application landscape. Think about what the most high priority of those are, the most expensive of those applications are, and think about what coverage you have from where the identity management is locked down. If you think about it from from that perspective, you are able to both prioritize and then you are able to work through a program to be able to sort of close that up. Some of that can be automated, some of that can be driven by a particular tools, either native within the application or otherwise, but it doesn't that's how you basically are able to demonstrate coverage. Way the analogy to think about it is, you know, if you are looking to be able to make sure that each of your, you know, each your perimeter is secure, you've got to think about where the most vulnerable pieces are. And that the analogy of this firewall is consistent with that. If you think that really the data firewall, if we call it that, or the customer experience firewall, if we want to call that in specific applications you have, they also need to be covered. And they are exposed in very, very specific areas. It could be as basic as the fact that there are external third parties that are accessing core applications, maybe using, for example, Bell's example, marketing agencies looking to be able to look at product marketing or social media accounts for a company that's just very, very common. And it could well be that you have former employees or third party contractors asking your core application and how that's typically managed, right? And so, I do think that being able to have a workflow attached to it, being able to have that programmatically done, and now with the power of AI actually doing that autonomously is real and possible now. And I think that that could be done. So that's the way I would look at it. Absolutely. And if I could I could add two points there. First, on that point about coverage, absolutely so so well said. We we do a lot of work across highly regulated industries, and we have a a big pharmaceuticals company as as a customer and chatting with their head of governance risk and compliance. One of the things that that person said was the fewer risk exceptions I have that are identity related, the better off I am and we are. And so it is this person's goal to get that down to zero, but that that's transformational. Right? If as part of their review, they have zero risk exceptions or or entries in the risk registry relating to identity. And so that's one of the metrics that they take a look at. And then we also do a fair amount of work with SIs and VARs. And, you know, I've I've always been blown away by how they're able to, and I don't mean this in a negative way, but reduce the identity programs to effectively the unit economics. And one of the things that's often talked about is what is the additional cost of achieving one percent more coverage or two percent more coverage? Like, what's the financial model behind it? And so one of the really exciting things that we're seeing now with modern AI technologies is that unit economics are actually improving around adding one additional application integration that's part of your identity parameter, where it used to be maybe fifty thousand dollars, a hundred thousand dollars to protect that additional application. And then you do the math and the cost benefit isn't there. Now with systems like Servi, you're able to bring that down to five hundred dollars per application or a thousand dollars per application. And so it becomes effectively criminal negligence, I would argue, not to protect all your applications when the cost per app is just that much, much lower. And so efficiency of of running your program is where I'm going with that second point. Yeah. Thanks, Bill. Bell, let's let's stick with you. This this makes me think, or or wonder about security practices in identity management that may have once worked really, really well, but don't really hold up in, this era where things are changing really fast. The the attackers are getting more sophisticated. AI is is as we've pounded the nail in here, just really, really changing everything. What what are some of the ones that you would point to that may be outmoded or maybe even obsolete at this point? Yeah. For me, it's it's I'm I'm I'm constantly impressed, surprised, horrified by how much inertia there is around how certain things operate within the modern identity stack and what expectations are. We will chat with identity teams, and they'll say, yeah. You know, it takes we average about four days to turn around an app approval process. And that just it blows my mind. Right? The idea that I wanna get access to an application, and I might need to wait four business days for it. And so maybe what I would emphasize, and Youssef, was appreciate your thoughts on this, is it's the expectations around what a next generation identity system can look like with regard to the end user experience. You shouldn't have to wait four business days to get access to an application. The end user shouldn't have to be on the hook to enable MFA for all of their mission critical systems. A lot of this can be automated. You can remove the dependency on the human nine times out of ten for any manual compensating control you have. And so platforms like Cerby have gotten really good at working with IT teams and security teams and identity teams to take that that weight off the shoulders of the end users and IT teams because you can automate it. Yeah. Yeah. Alright. Youssef, a question for you. Continuing with the the AI thread, talk about what you can foresee on with with with various threat vectors, where you think attackers will use AI to to really take it to the identity teams during the next year. I mean, this has been a target for at least the last five years. Identity is obviously really the keys to the kingdom, but what what sorts of tactics or or strategies can can you see on the horizon here? Well, I would I would argue that identity is probably after phishing the the number two, you know, security threat, to companies now than ever before. And the reason for that is, a large part of the AI piece to it. So let's let's go through that a little bit. So one is just the sheer power of compute and then intelligence means that you are able to be much more sophisticated in your identity attacks that you're looking to basically do. Let's look at that in multiple ways. One is of course mutating, constantly mutating and being sophisticated on the phishing side of things and the identity of what you're able to try and access, that's one piece. Being able to look at different configurations and do that at a pretty rapid pace. Second, classic in terms of dictionary attacks, and those being able to do for password cracking in some way, shape, or form. If you do not have good cybersecurity posture, identity posture, you're likely to get breached. Three, there's a there's a new one, which is deep fakes. So the use of AI to ultimately be able to replicate a personality and do that with a degree of sophistication, that's an identity problem. It's not and that's been that's an AI being used to be able to fake an identity. That is and the impact of that are disastrous. There is waits for intellectual property theft, of course, and then some, of course, financial theft. You know, that could just be a major issue. And then, of course, just the fact that you've got such a it's a public relations disaster, and we've seen a number of these being put into place. And I think the other piece is, yeah, you're using AI to be able to fake, say, voice or otherwise. And I think, yeah, you can use AI to automate, for example, your call center process in some way, shape or form, but you're also going to be using it the other way to be able to start replicating parts of an identity whether it's on voice, whether it's on video, and of course in the traditional ways. So I think the general notion is that whilst technology as it shifts, it will provide you with lots of benefits as we've seen, but it also provides you with adversarial tactics being deployed by nefarious actors. And so that unfortunately is a consequence when you have a major technology shift. And so that's some of those examples would not have happened without AI, but they are now happening now more than ever before, and that's just a consequence of it. It's it's it's crazy that these technological advancements I I mean, it ends up being the spy versus spy scenarios where these advancements ends up getting used against the defenders, but that's that's the world we live in. Excuse me. Bill, to bring you back into this, AgenTeq AI is, of course, a really popular and provocative topic that industry and and customers are are are all looking at and its potential and its peril and everything in between. Can can Agenetic AI actually help solve this disconnected app problem, or is is it still not tested enough that security teams can rely on it? What's what's your sense there? Absolutely. You know, I'm I'm not one to be a doomer, and and so please don't take my response as as indicating any of that. You know, what we always need to be mindful of with AgenTek technologies that is that you should you should always keep the task in mind and then also evaluate your tolerance for hallucinations. Right? Your your typical hallucinate or your typical agent may hallucinate anywhere between ten to forty percent of the time. And when you're dealing with identity workflows, my argument is you can't even tolerate a point zero one percent hallucination rate. You know, what if the agent inadvertently puts the credential set in the wrong field or permissions the user incorrectly? And so when we've looked at AgenTic Technologies here at Cerby and how we deploy it, there's absolutely a role for it. But architecturally, we've made sure that there's a reinforcing deterministic layer that basically runs alongside the agents who who build our workflows. And and so how would I generalize that? Agent AgenTek technologies are amazing, but you need to be smart about how you deploy them. And if there is a workflow you're working on where you cannot afford variability, you should avoid using the genetic technologies there. And and, you know, that's how we've employed the technology set in our stack that we ensure that anytime we're running a mission critical workflow, the outcome is always deterministic. But then there's a separate loop that helps remove the reliance on humans to perfect anything that, that humans would otherwise be responsible for. Fair enough. Youssef, I'm gonna turn back to you and ask you to put your your CIO hat back on for for just a moment. I'm really curious about how, as a CIO, how you decided which security initiatives got budget, especially when you have to juggle amongst so many competing priorities. I mean, obviously, everything can be urgent. Right? But what were some of the criteria that you used to decide really where to spend budget? So first and foremost was it came down to putting the customer at the heart of your decision making. What will impact and what is where is the customer most at risk? So that was the that was the overarching viewpoint to do it. Second was to then balance that out with level of complexity of what it takes to be able to do to to be able to make that work. Lots of things that you want to be able to do, but there are super complexity. There's interdependencies with potentially finding solution or working with an existing vendor or being able to work with a specific part of the organization that requires to do a major change or whatever that may be. And so you then basically have to balance that out with level of complexity of effort. And then the third is where you feel that it could basically make a difference. And that really comes from CIO instincts, it comes from CIO experience of being able to walk around the organization, look around the application landscape, and ask yourself where you can basically make a difference. The fourth is much more about research. So one of the things that I was able to do is to say, Look, if I was able to talk to a vendor and know, Bell had basically mentioned that on average enterprises have three seventeen applications. I think that's low. I mean, I can tell you that when I worked at an early stage startup, which was less than one hundred people, we probably had close to two fifty applications itself. That was, of course, an engineering led product, but still the reality is that that number is only going to increase. And I don't think it includes some of the AI agent tools that's being included in that. So I I digress, but part of it is as you speak to vendors, you also need to be able to ascertain and understand. This is not a typical, oh, a bridge letter and here's our data SOC two type two report. It's actually about, like, hey, Has that increased over time? What's their investment? Or have their partner or salespeople are able to talk about the improvements? One of the things that you noticed from some of the biggest vendors out there, I think they did a phenomenal job, is when you showed up at their, say, annual conference or you spoke to any one of the team, they were enabled to be able to talk about what they were doing. And I thought that was super impressive, that resonates the fact that this was security was a part of their organization and a large part of their culture that was being built into place, and that gave me heart. So if I basically took those four things, somewhere down the line I was able to help prioritize where I would garner the effort to be able to try and move it forward. What I would say is identity management is an incremental strategy. It is not destination. It will be multifaceted, it's complex, it's heavy to basically change, and some of the solutions that you get out there are able to help do that. I think one of things that I was excited about Cerby is that there was a very clear path to success. Said, you have three hundred applications, you have a single sign on provider that we integrate with super well, let's be able to make sure that we can take your security practices and take your identity management policy and strategy, and to be able to bridge that gap with these all of these unmanaged applications which haven't been fit for purpose, and we can do that. And that is a clear measure of success. You know, when you get that coverage, that's able to do it. And in those in that period, some are federally mandated and it's super complex to do, so you deprioritize that and maybe do it later on. Some are more critical, and you're like, okay. Let me try and best do that. But that's one of the things that you need to do as a as a general rule. That those are the vectors I would advise people to do. Thank you. Bell, close us out, if you will, with some thoughts around how AIM AIM leaders can can future proof or or use future proofing principles to guide their decisions in in twenty twenty six. And and and and why you you you feel that way. Love to hear your closing thoughts on that. Yeah. You know, as as over the last two to three years, we've we've been doing far more work on the identity governance side of things. And many of you, identity identity leaders, IT leaders, cybersecurity leaders, probably will not be surprised by just how many programs stall out after phase one, and they never get beyond protecting, you know, the the the mission critical applications to the slightly less mission critical applications. Right? You know, they're they're usually only able to cover thirty to forty percent of their enterprise applications. And so one of the concepts that I would maybe plant a seed around is a hundred percent coverage is possible. And in an economically viable way where it would be foolish not to pursue a hundred percent. Now it's not going to happen immediately and and overnight, but it is possible to get to a place where your attack surface does benefit. And I'm talking about attack surface, I'm referring to enterprise applications and their general identity security posture, it is possible to bring all of them within the identity perimeter. Modern AI technologies allow you to make up for the gaps that those applications present, and that's exactly what the problem that Servi solves. We can help you connect all of your applications to an Okta, to a SailPoint, to an Entra ID. And so a hundred percent coverage is possible. And maybe your target isn't a hundred but maybe it's ninety percent and you're at thirty, we can close that gap. Excellent. Well, that is that is gonna close us off. I I wanna thank both Bell Leppe and Youssef Khan for their their comments today. Dark Reading appreciates your time and expertise on managing identity in a very turbulent time with with AI rearranging the the landscape as we speak. Thank you both, gentlemen. Thank you, Terry. Thank you, Yusuf. Thanks, Terry. Take care. Thanks. Thank you as well to our sponsor, Cerby, as well as everyone in the audience. We appreciate your attention and participation and your questions. Sometime in the next twenty four hours, you'll be receiving a personalized follow-up email with a link to today's presentation on demand. You're welcome to share this with peers and colleagues who couldn't have been part of our live presentation. Now for the boilerplate, this webinar is copyright twenty twenty six by Informa TechTarget. Presentation materials are owned by or copyrighted by Dark Reading and Cerby, individual speakers solely responsible for their content and opinions. On behalf of our guests, Cerby and the dark reading team, I'm Terry Sweeney. Thanks so much for joining us. We'll see you next time.
Identity programs are entering a period of rapid transformation. AI adoption is driving both excitement and concern, compliance expectations are rising, and users are adopting applications faster than IT can govern them. At the same time, identity sprawl, disconnected systems, and poorly controlled credentials continue to strain IT and security teams.
In this forward-looking session, Cerby CEO Bel Lepe and investor and former CIO Yousuf Khan break down what the next 18 months mean for IAM and security leaders. They examine which legacy identity practices are slowing progress, how to modernize governance at scale, and where AI is creating new risks as well as new tooling opportunities.
Watch to learn:
- How to tackle applications that sit outside the IdP
- Close authentication gaps when passwordless is not enough
- Extend modern identity controls to legacy systems
The discussion also covers emerging regulatory pressures, managing distributed and third-party identities, strengthening privileged access, and applying AI thoughtfully to secure identities.
Watch to get a strategic roadmap to help future-proof your identity program and build resilience for the next era of identity security.
Presenters
Yousuf Khan
Venture Partner
Ridge Ventures
Belsasar Lepe
Co-Founder and CEO
Cerby