Inside monday.com’s Security Strategy: When App Growth Outpaces Identity Control
Hello, everyone, and welcome to our webcast about crafting a successful strategy when app growth outpaces identity control. I'm Mike Shima, host of Application Security Weekly. Thank you to our sponsor, Cerby, and thank you to everyone who's joined us for today's discussion. One of the most foundational security tools that every org starts out with is the spreadsheet. And these days, every spreadsheet gets a built in LLM. We've added tokens to our tables. But what spreadsheets really represent are manual effort to keep track of something. Assets, apps, users, data. And those lists quickly become burdensome, out of date, and sources of misplaced confidence in what an org's attack surface really looks like. For example, even more important than tracking apps is tracking how users authenticate to those apps. Well managed identities reduce the risk of credential theft and avoid ever increasing consequences of access and data exposure. Plus, those LLMs and agents probably should have some identities too. So if you're spending more time and money on maintaining a spreadsheet than you are on enabling pass keys and SSO, then you're just gonna be adding even more rows to another kind of spreadsheet, the risk register. Here to help you mature beyond the burden of rows and columns are Matt Coyote and Lior Zagari. Over to you, Matt. Mike, thank you so much for that, warm intro. Thanks everyone for joining today. So wanna start out with one of my favorite statistics, and that's this. Sixty percent of breaches involved the human element. I'll say it again. Right? Verizon's latest data breach report came out mid last year. They said that sixty percent of breaches involve the human element. And if you scroll forward to this year, CrowdStrike and their latest global threat report, they found that eighty two percent of detections are now malware free. That means there's no signature, no payload, just valid credentials. What Lior and I are gonna talk about over the next thirty or so minutes is how you can optimize your existing identity stack to minimize the human element. But first, Lior, why don't you tell us a little bit about yourself? Hi, everyone, and thanks, Matt. Happy to be here. My name is Giorgio Zaguri. I'm the director of global IT at monday dot com. I've spent about, like, twenty years in the IT and security, including times as an IT manager at some cybersecurity company. So I live the pain from both sides. And yes, DJing is a thing is real. It's how I decompress after dealing with identity management all day. So that's that's it. What what kind of music do you DJ? You know, everything, everything that just make me happy. Just as an hobby right now, so, you know, everything that's coming up, it's good for me. I love it. And you did tell me about one time that you did it in the desert, some kind of desert show. I thought that was pretty awesome. Yeah. Definitely. It was, you know, very very magical place, and the energy was really great. So I really enjoyed that for sure. I love it. And if you Google Lior's name, you can find, like, old music that he did, like, a decade ago. So troll him and and then you can find it. So I'm Matt Coyote, chief strategy officer at Cerby, formerly chief security officer at Palo Alto Networks. My claim to fame is that I was one of the first one hundred CCSKs in the world way back when the cloud was was new and everybody was scared of it. Kind of like how everybody feels about AI today. So that is us. I wanna start out with this. All of us most likely have some type of investments in a single sign on platform or an IGA platform. Right? Whether it's an Okta, SailPoint, Savient, or Entra. Right? In fact, maybe just drop it in the chat right now. Just drop, like, a a one in the chat. If you've got any one of these four apps or platforms in your environment, just put, a number one in the chat. I'm just kinda curious to see. Typically, I speak with organizations, in fact, if it's a large multinational that's done a lot of mergers and acquisitions, a lot of times, they say, yeah. I've got all four of those platforms in our environment. So let's see. Drop some jump it in the chat. I'll take a look in a minute. So here's the premise. We all have made identity investments, and those platforms, they're awesome. Right? They're great, but there's an exception. Right? They are great with apps that support identity standards. Right? So if you've got Okta or Entra or Ping in your environment, you can do things like single sign on. Right? Something that we consider very basic security one zero one these days. You can do that. If you are a SailPoint or a Saviant or a Visa customer on the IGA side of the house, you can do things like managing all of your permissions in one place. You can do automated, user access requests. You can do all of these types of things for these applications. Multi factor authentication. Right? Microsoft came out with this stat. I think it was about two or three years ago that said, when MFA is enabled, ninety nine percent of attacks fail just from having MFA turned on. So these platforms, they enable you to do great things in terms of security in governance in your environments if you have apps if all of your apps support standards, which we know is not the case. So let's look at some let's look at some data just to, orient you with this. Right? So left hand side of your screen, this is actually two separate pieces of research. Left hand side of your screen, we have data that we did, research based on the top ten thousand applications that are using the enterprise. That includes on prem, legacy, and SaaS based applications. Alright? That's gonna be the data on the left. On the right hand side is newer research that we did where we talked with over five hundred IT and security professionals in the US, and we asked them questions. And so you'll see as I build this out the cause and the effect of applications that don't support standards. Right? So fifty four percent of enterprise apps, fifty four percent don't support SAML or OIDC. Right? Can't do single sign on. Well, what is the effect of that? Well, forty one percent of those we spoke with says they have to go out and manually rotate passwords. This could be shared accounts. It could be administrator accounts. It could just be someone leaves the organization. You've gotta go out and rotate that password because it's not part of your single sign on provider. Lior is gonna talk about that pain in a little bit. The second area has to do with apps that don't support the SCIM standard, the system for cross identity management. This is a standard that has been around for at least a decade, if not more, and only less than only ninety three percent of apps don't even support SCIM. The impact here is fifty nine percent of organizations have to manually perform some type of life cycle management. Meaning, if you have a joiner, a mover, or a lever, they often have to go out and manually do that work. Last but not least, when we look at how open are these enterprise applications, do they support APIs? Can you reach in? Can you do introspection? Can you pull entitlement data out of these applications? Ninety four percent have no security APIs. And the impact there is eighty nine percent of those we spoke with said they they cannot automatically enforce a basic protection like MFA or require pass keys. So there are impacts to not being able to do these types of things. And in looking back at the chat right now, I can see that a number of you have said you put the one on the chat, which means you have at least one of those IGA or SSO platforms. So not not a big surprise there. So, Lior, before we dive, you know, deep into the kind of the technical side of the Monday use case, tell us maybe a little bit more about the company and some of the insane growth that you guys have had over the last decade plus. I real this is I find this just super interesting. Yeah. Sure. Thank you, Matt. And for those who know who don't know us, Mode dot com is a WorkOS. It's a platform that empower teams across every industry to build, customize, and run their workflows, projects, core business processes. And there is a few milestones along the the way. So we started around twenty fourteen. We launched our first product, what become the Monday dot com WorkOS. In twenty twenty one, we became a public company in the Nasdaq stock market. And in twenty twenty two, we actually became like a multi product company, and we launched the Monday CRM, which is helping like expanding what we had before and helping, like, sales organization to handle their stuff. Then in twenty twenty three, we brought the Monday dev, a product dedicated for empowering software development teams, managing all their sprints and and all their development processes. And also in twenty twenty four, we hit a major milestone for us, one billion in ARR, which is a very significant number to say. And in twenty twenty five, we became we continue to expand, and we added the the Monday service, which is a really cool platform that designed for teams to manage their service operation. And now what's actually more excited me than everything that I showed before than other than the the the other four platform that I mentioned before, we continue in growing the AI, and now the AI is kind of infusing the core of everything that we do. We are not treating AI as a bolt of a future. It's embedded in in into how work actually gets done. We changed the entire marketing that we are doing. Everything has got changed, and now we are much more focused on the AI platform and kind of unlimited digital workforce and adding more applications like the Monday Vibe and the Monday Agents and the Agent Factory and Monday Magic and all of that kind of embedded into our platform. And it's helping us to grow and develop and add more and more cool stuff into our system. And today, have over two hundred and fifty thousand organizations around the world relying on Monday, serving two hundred different industries, of course, to two hundred countries and territories. And it's a massive diversity from education to health care to technology to finance to construction. You name it, everyone is just using it for their own needs. So you can see the growth from one hundred and fifty ks customers. We grow into around two fifty customers in twenty twenty four. And it's growing and expanding. And the growth is incredible, but it's also mean the IT and security challenge grows alongside that. So to support that, we have twelve offices globally, over three thousand employees in Europe, London, Tel Aviv, Tokyo, Sao Paulo, Sydney, and more. But here is the thing with the gross complexity. At the company, like in many hyper gross company, we face the challenge of scaling IT and security foundation while supporting thousands of employees and hundreds of SaaS application. Okta has been a strategic partner in helping us to secure and access through this SSO lifecycle and automation with SCIM, but as many as you know, not every SaaS app support these standards, as Matt mentioned before, and that's where the real story begins. I love that. I love that. So when Monday had such just insane growth right over that decade, right, you hit that a billion in revenue, Your employee headcount grew. Your customer base just grew by multiples. What what type of business challenges did manual identity processes result in? Like, what did that actually look like for for your team? And maybe tell us a little bit about kinda your team. Like, what did it look like and, like, what does it look like now? Give us a little bit of that context. Yeah. For sure. So a great question. And I think there are a few major pain points that I can show here and say like how we are dealing with it. And this is some of the business challenges that we faced along the years. So first, we can talk about like the manual user life cycle. For most of our application that support Scheme, everything works seamlessly. We don't have any issues, works nicely with Okta. But many critical application doesn't support that, which means that we need to provision and deprovision often require a manual IT intervention. When someone joining or leaving the company, our IT had to step in and manage access by hand. This didn't just slow things down. It's introduced a risk of a human error, especially when you are dealing with hundreds of apps and thousands of employees. Eventually, you will do the mistake. And by the way, just like you can throw here in the chat whatever you like, how many of you still have at least one application in your company that doesn't support SCIM or SSO? I guarantee most of you just can say in the chat, I'm sure I will see more than one application that doesn't support SSO or SCIM. So feel free to drop it here. I will look on it afterwards. The second thing, we're talking about the human dependent on password management. We have many applications that, as I mentioned before, we don't have SSO or scheme enable, and we had to manually manage those credentials. So when an employee leaving the company, we had to rotate those password by hand. There was some shared account, shared password, things like that, and eventually we needed to handle it manually. And this process was time consuming and error prone and it delayed and increased the risk of linerging the access. Eventually, you know, when we have multiple application, the risk is becoming more and more significant and we wanted to avoid that. The more we scale, the more we realize that was a security and compliance gap. We simply couldn't ignore. And if you want to also drop in the chat, I know I can say it by myself. Me and my team like chase after people to let us know what are those applications or what are those accounts that we need to rotate those password. So how many of you had to chase down shared credential after someone left your company. And we were there too. We were definitely there. And we needed to chase after people, after those credentials, and needed to rotate those password, which was a big pain for us. And the third thing, something that we call the SSO tax. Some apps just don't integrate well with identity provider, forcing us to maintain manual login. And those disconnected application create two problems. One, friction for the employee. People had to remember and reuse password. Nobody enjoyed that. I'm sure some of you have some password vaults. But again, it's eventually not updated, not very persistent and creating a lot of manual work. And eventually everyone hates passwords. So as long as we can avoid that, that's a blast. And the second thing, we call it security vulnerability, password reuse and credentials stuffing attacks become real, tangible risk. So overall, we were left with situation that we have a manual process and a hidden risk that we are holding us back, creating inefficiency and increasing our attack surface. So I know we've got over a hundred and fifty people watching live, and I'd love to get just a quick pulse from the audience. Right? So if you have if you've had to do that, right, let's just you know, you don't have to put specifics in there. But if you've had to chase a team down or chase an app owner down after someone has left to rotate a password, just drop that in the chat. Just just drop a one in the chat so we can guess get a pulse of how common this is. Lior and I did we did a version of this talk at a event last year, and there was I don't know. There was probably two hundred people in the audience. And when we asked this question, it was, like, three quarters of the room, like, raised their hand. Yeah. Look at it here. It's just streaming in in the chat. This is such a common common issue that so if you're if you're on this you're on this call, you're you're not alone. Right? This is a really common challenge. Lior, question for you. Right? So many IT leaders, security leaders I've spoken with about manual provisioning and deprovisioning, they see it as unavoidable. Right? They just see, well, it's just it's just the way it is. What was there a moment for you where you realized, like, we just we can't we can't keep doing it manually. It's not good enough for us. What what was that like? Yeah. So, you know, we really like to work with data. And everything that we are doing starting from very basic service support to system to everything that we are doing, we really like to use data, and we have, like, incredible dashboards all our office spread it with tons of dashboards. So, you know, we just did the math, and we understood how much time and how much effort it's causing us to handle all this, like, manual processes and manual handling. And the number made it impossible to ignore. We calculate that and we are spending more than three thousand three hundred hours annually on manual life cycle management alone. That's equivalent of eighty three forty hours work weeks, almost two full time employees doing nothing but provisioning and de provisioning by hand, which is incredible number. And we don't want to waste our employees' time just with that. And on top of that, we have more than two thousand four hundred hours in a year on a manual compliance test. You know, we are a public company. We are regulated with all the good stuff of ISO, SOX, and all of that. And we eventually need to take all those evidence and provide it to our auditors. And it took us a lot of time and manual effort that we needed to prove those evidence of, like, rotating the password, revoking access, and stuff like that. And we eventually hit like, we calculated everything, and we came up with around two hundred and fifty k in a year. And the average of cybersecurity salary in the US is about one hundred and forty five ks. So we were essentially burning the equivalent of almost two senior headcount on work that could and should be automated. So I think that was for me like the moment that I understood that there is a problem, not just a security problem, but also a people problem. And our team was drowning in the repetitive error prone work and risk exposure and growing faster than we could manage manually. So we needed to automate, not as nice to have, but as a strategic imperative. I've always appreciated that about Monday. Know, we at Cerby, we've got, you know, over a hundred and forty customers. A lot of times when we ask questions around, like, ROI, we ask questions around cost, a lot of people don't know. They haven't they haven't taken the time to do the math to see what is it actually costing us to do the manual work for all these apps. I've always appreciated that about about Monday. You guys are very data focused, and you always you always have been. So, I love that. I appreciate that about you guys. Alright. So let's talk about just what are some ways that you can approach this from, a solutions perspective. Right? So what if every app in your environment, whether it was cloud, mobile, on prem, could be brought into your identity ecosystem. Right? We talked earlier about SailPoint, Okta, etcetera, Entre. Like, what if you could bring all of your apps regardless of their support for standards into your identity environment? What would you do? Right? Even if the apps didn't support federation, even if there was no standard support. Like, what if you can connect them to your existing stack and you didn't have to build any custom code, you didn't have to create brittle connectors, and you could just extend your existing identity investments to every app. What would you do? Well, you would you do a couple of things. One, you would automate provisioning and deprovisioning across the board. Right? You would likely totally eliminate all of those manual apps, all the hours you just saw, from Monday that they were spending doing manual work, you would completely eliminate it. On the single sign on side, right, or lack of single sign on, you would go out and you would lock down credentials everywhere. Right? If there was an enterprise app that somebody was using, you would make sure that they no longer have to use a password. And what would the results be? Right? You would greatly reduce all of those manual touch points. Right? So today, in most organizations with disconnected apps, what you need to do is if someone needs access, a ticket goes into, like, a ServiceNow queue or Monday queue or something like that. It goes in there. An admin has to log in, then go out to that source system, and it's just an extremely manual process. You would completely eliminate that. It will give you a stronger stronger compliance posture, and you would reduce many of the blind spots in your environment. By going back to the stats we started with, you would demonstrably reduce that sixty percent of incidents or breaches from the human element. This is why we developed the Cerby platform. We saw there was a gap in the environment. We do this two different ways at Cerby. Right? So one, on one side of the house, we streamline your identity governance and SSO. Right? So if you've got these applications in your environment, which all of us do. Right? We all voted on this. We all saw that we all have these apps. It doesn't matter if you're a modern, you know, cloud native company like Monday or whether you are a environment like a financial services company that's been around for over a hundred years. We all have these apps. So Cerby helps bringing those disconnected apps into your environment by extending your existing identity in IGA investments. Right? Not replacing. We extend what they do to those apps. So that's on that one side. Right? Joiner, mover, leaver, workflows, identity automation. On the other side, and this is an area that is is been growing on the list of risks for security professionals is protecting their corporate social media accounts. Right? After COVID, social media became the primary channel by which organizations, whether you're b to b, b to c, learn about your company. And oftentimes, these accounts, whether it be Facebook, whether it be, Twitter, whether it be any of these social media platforms, they are ninety nine point nine percent of the time disconnected from an enterprise identity, which means someone leaves the organization, they retain access. So Cerby covers these two different areas with our platform. And just to give you a a high level view of what it looks like, right, left hand side of the screen, you have your existing infrastructure. You've got your IGA. You've got your SSO platforms. You've got your workflow automation platforms, whatever those might be. I think we need to add a Monday icon in there. And, you've got those on the left. Cerby sits between those existing investments and your downstream applications and is able to carry out those automated actions so that you can completely eliminate the manual work that goes into this today with your disconnected applications. Alright. So, Lior, let's let's talk a little bit around, what things were like. We talked a little bit about some of the challenges, but when you think about before you started using Cerby, like, how did your talk us a little bit about how your team was managing those, what I would call, islands of identity, like business critical apps that didn't support SAML or SCIM. Like, what did that look like? Yeah. So, honestly, it was a lot of, like, manual work and a lot of chasing. And, you know, let me break it down. So when we are talking about, like, the onboarding, when employee join, it could take days, sometimes longer before they had, like, a full access to every app they needed. That's days of lost productivity for new hire. Think about it. Like sometimes the person joining the company need an application. He sometimes needed to wait some days until he was able to just start working. And the biggest problem was also in the off boarding side. So it's even more painful for application where IT didn't have admin rights and we have like, you know, hundreds of different application, different business owners. We had to rely on those business owners to manually remove the user that often meant waiting several days until the removal was completed. And in the meantime, IT was responsible for constantly chasing those business owners to make sure that it's actually got done. Security risk, operational evidence, terrible experience all around. It caused us a lot of pain and time that we needed to chase after those business owners. And on the password side, they were stored in different places, rotating consistently, and sometimes persisted beyond policy limits. And obviously, as mentioned before, as a regulated company, it created a lot of like compliance risk and had a bad user experience. So this brings up a good question, right? So one of the things we often talk about in security is there's a trade off between security and productivity. Right? If you turn, you know, security up too high, you make it too too rigid, then productivity almost always trades off. It almost always drops. If you take a very liberal approach and you just say, well, let's go ahead and do what you want. Like, productivity goes through the roof and then you end up in the news. Right? You end up in the news. So there's this, you know, there's this constant struggle. I'm curious, like, how did your colleagues react to having, like, a unified experience for apps that that used to require just so much manually, whether it was managing their own credentials, their own passwords. You mentioned that, you know, it used to take days to get their access. Like, what was what was what was the reaction when all of a sudden, you know, over the over the course of a couple months as you rolled apps and it became automated? Yeah. So I think that's, you know, my favorite part in the story. And, you know, like, what we achieved with Cerby and Okta wasn't like a trade off between security and productivity. It was a a win win. You know, sometimes you need to say, okay, I'm compromised on security to have better productivity. But here I feel like it was a real win win situation. On the on off boarding side, we had like automation in place. Onboarding became immediate. Like every employee joined the company, he get immediately the application that he need. He didn't need to rely on any different business owner, anyone else. Will just get the application on the same day. And sometimes when you are we had weeks, we had like thirty, forty, fifty people joining as a hyper growth company. We added so many people joining every week. And think about it, multiple this like two, four, five application by forty employees joining every week. It's hundreds of different application that we had a delay and some blind spot and the access and on the off boarding side, the access was revolt also in the right time. We had an integration between Okta and Cerby. Once people is removed from Okta, after a trigger came from our HR system, automatically it got removed from the Cerby side. Together with Cerby, it got removed from the application side and then immediately it got removed. On the password side, you know, everything now runs through the Okta portal. So think about this experience that now you have, like, the entire Okta portal, like, they have the other application that support SSO in scheme. Now they see kind of a bookmark with the application that they need. They're just clicking on it, and then seamlessly, they don't really recognize the service doing the magic behind the scene, and then just right away connecting to the application, invisible to the user, and just simply connected without juggling between credential, copy paste, need to move between the password vault and whatever it is. And obviously, everything is much more secure than that. You know, when people need to do password, they usually go with the most memorable one or the easier one, and it's just not in the standard that we are asking for. So obviously, as I mentioned before, the reaction from our colleague, you know, was definitely super positive. People were actually excited about the security change, which as an IT leader know is rare. You know? Usually, when I'm doing things that are improving productivity, I'm usually creating some gaps or issues for security and vice versa, by the way, the security team doing the same thing for me. So here, I think, like, we felt the change. Everyone was happy. Less friction and much more, and, you know, the magic just happened. When security gets out of the way and just works, adoption follows naturally. So the combination of, like, a strong compliance and a smoother user experience has been a game changer for us, definitely. That's really powerful. You know? Usually, in security, we are applying controls that are very restrictive that, you know, people usually reject. Right? I don't wanna use a new tool. I don't wanna change my workflow. But then there are also security tools where users there's very few, I should say, security tools where users opt in because it makes their experience better. This sounds like those examples. Right? So this is a a great win for IT and security teams. So let's look at it from an ROI perspective because this is I I was just there was a post on LinkedIn. I think it was last week. People are arguing about, oh, you can't show an ROI of security tools. And I was like, apparently, you can't do math because it's actually not that hard. But so why don't you why don't you walk us through this? Right? So we know that manual deep provisioning, it's it's a lot of times where security gaps hide. Right? Because people retain access long after they left the organization or they change roles. Maybe talk a little bit with us about how automating the process for disconnected apps helped you recoup almost four hundred thousand dollars in costs. Yeah. Definitely. So we'll start with left side. So, you know, before jumping into the pricing and the numbers, we had more than three thousand hours that cut save with this life cycle management, which is a huge amount of time and money. And if we are breaking down this four hundred k, two fifty came directly from the cost saving of this manual life cycle management. It's a labor hour. I mentioned earlier, almost two full time employees' worth of work that was fully automated. And the remaining one hundred and fifty k came from two sources, eliminating what we call the SSO tax, the premium vendors charged to enable federation and from streamlining our auditing processes, everything like that, you know, saved us a lot of time and money. And what we use required to manual evidence gathering for compliance, all these became audit automated. So saving significant time and reducing audit at prep costs. Combining the two, we are getting a hard saving of around four hundred ks. And the total ROI with Cerby was two eighty percent. And it's not just theoretical projection, it's measure a real money that got saved to thanks to the the platform. So Lloyd Lloyd asked a question in the chat, which really fits well with this. He said, has automation of identity management also reduced the burden of adding new applications? Right? This fits well because, you onboarded more than two hundred applications in Cerby in just a few months. So maybe talk a little bit about that, Lloyd's question. Yeah, sure. So what is the I think it's really impressing that we went from around twenty percent of application coverage. This is what we get from, Okta, either SSO, Scheme. When we are looking at it, we are looking at it just under one umbrella. So we are talking about like one hundred percent of SSO and Scheme. And we started with just twenty percent of application that's supporting both. And now we are almost in eighty percent. In just six months, we brought, like, almost two hundred application that was unmanaged. And this the the rollout was practical in phase. We started with the highest risk, highest impact application, the ones that were deprovisioned gas, were creating the most exposure. Then we expanded the outward. Cerby pre built integration made the process much faster than I expected. We also like, you know, along the the year, we added more and more integration and Cerby worked with us and help us to do do all those integration and help us to create those custom integration and building those API bridges. And in term of like workload impact, it's like the time and the hours that we saved with that was definitely impressive. Two hundred application, that's a lot. I didn't expect that we reached this number. And we are expecting to add more and more application. And we see like Cerby adding more and more integration that helping us also to build it from without any like custom integration. But, you know, we just achieved that and it's incredible. You know, it's not something that was in a few days. We work on it together hand by hand and then with Cerby, and we got it in quite short time. I mean, six months, it's not too long time to reach to a two hundred application connection and doing it so seamlessly. Yeah. All of that. All of that. So if you've got other questions, feel free to ask them. But let's talk about like where you're going. Right? So as you look at your your identity roadmap for the rest of this year, talk maybe a little bit about where you're going, like how you're gonna be using Cerby and like what are you what are you most excited about? Yeah. So as mentioned before, our goal is to get to the one hundred percent. We started with twenty to seventy eight, and now in twenty twenty six is to reach to all those application that we didn't reach, the small ones, the ones that are more trickier, the social media, the marketing, the ones that you know, things that are not really straightforward. And those application, we want to definitely create a better automation. The second one is to we just adopted a Lynx security, which is our IGA tool. And now Cerby and Lynx working together in order to create, like, a better connection between the two and eliminating what we call the islands of identity, the disconnected application that create. This give us the unified oversight and control across the entire application landscape and creating us an audit ready evidence for our compliance portfolio, you know, meeting all those compliance stuff and, you know, replacing those manual spreadsheet with automated compliance workflow. That alone is a a huge ROI accelerator. I think that this integration will allow us to create like one umbrella that's connecting all the different pieces with Okta, with Cerby, and combining all of that goodies into one place that we will be able also to create all the access reviews, access management, and things like that. And the third one, you know, that's we cannot do a one present one slide without AI and agentic capabilities. Obviously time now. So, you know, like talking about AI now. Although we started with AI, but then we a bit put it on the side. But just, you know, we must add those agentic AI and auto discover and doing all those great stuff. We have so many AI initiative as part of the identity and governance side. So while we leverage AI for discovery and tree detection, we maintain dramatic slayer of permission assignment. That means like zero variability in identity workflows and it's helping us to be in a much more take more better decisions and be in a situation that we have like more precise and predictable results. And using all of that also for the nonhuman identities, we see that as a big benefit. So all of that, we see that it can be a definitely a big win for us. And I'm sure that also Cerby is adding more capabilities in the AI and the agentic area. So, you know, combining the two will create a definitely reduce the time that we are spending and also reduce the attack surface. So one of the questions, Dior, that I often get, and I'm curious about how you did this as well is, you know, when an organization has hundreds of disconnected applications, like like, how did you how did you guys go about deciding which ones to tackle first? Was it, like, risk based, usage based? Was it audit findings? Was it executive pressure? Was it something else? Like, how did you guys think through where to start? So I think like the way that we tackle it every application that's coming into our stack of application, we are a create we have some kind of a calculator that we built that kind of breaking down the different risk metrics of the application. How many people are using the application? Is it going to access like sensitive data? How many integration you have? If you have AI and agentic solution, etcetera, things like that. And all the combined, like we put different weights for each one of those numbers and then calculating everything, giving us a number of the criticality of the system, starting from low to medium to high to critical. And then according to that, we are defining our top applications from low to critical. Obviously, the SSO and Scheme, it's a major we are not allowing even to an application to step into our organization as long as you don't support those things. But eventually we started like now that we have Cerby, we combine the two, like now we have Okta, but we have also Cerby to be able to say, okay, this solution doesn't support maybe Scheme and it's a critical system. We will allow it to step into our organization because we have now the solution and we are allowing that. So the way that we structure it and the way that we tackle these systems, we start first with the ones that have like high security risk. We split it down to the ones that are more high and critical. After we touch them, we looked on the ones that have like the most usage or the more users and then started break it down, then medium and then low until we kind of cover the majority of the application that we had in access. And now, as I mentioned, going forward to twenty twenty six, we will see how we can cover and create like better coverage to the ones that are more trickier. If there's other questions, feel free to drop them in the chat. Another question that I've been asked is, you know, so you brought Cerby into your environment. Like, what did you have to make any changes in Okta, you know, in order to make that onboarding and offboarding immediate with Cerby? Like, what did that look like? So I will not say, like, changes in Okta itself, but in the process that we are working between Cerby and Okta. So the way that we did it, we just integrated Cerby into the system. And we said like, okay, now we will just put a bookmark, people pressing on this bookmark, and then it's just triggering Cerby. And it depends on the situation. So for example, if the platform is not supporting SSO, then what we did, we used the Cerby mechanism to ingest the username and the password instead of the user. The password is rotated automatically, so the user don't know the password. So this is, I will not say it's a change in Okta, but it's a change in the behavior because people used to put their own password or to use a password vault or to copy paste their password. Now Cerby trigger in and magically put the username and password. And then also the SSO, so sorry, the multifactor authentication. They serve you have also the ability to trigger a six digits code. And then the user is able to just, it's just ingesting it automatically. So instead of the user needed to do it, now Cerby can do it instead of the person. So this is a change. It's not in Okta, but it's in the general behavior of how people are using that. And then another thing, like the ones that don't support scheme, this was a bit more easier because it doesn't really matter for the user eventually, the reason that he's getting the things much faster. So in there, we just needed to trigger Cerby and Okta didn't support the scheme, we didn't need to change anything in Okta. But instead of to put my team and do the task manually, they just did it automatically. So just go into this application, go and do the clicks instead of you finding the right user. Whenever Okta is trigger, then Cerby is trigger and then removing the user from the application. One of the questions that I get all the time on this is, like, how does Cerby handle apps that break on it, like, automations typically. Right? So, like, a a very standard, like, an RPA based system. Like, how does Cerby handle that? Like, whether it's captchas, UI changes, like MFA prompt, weird edge cases without having to rebuild everything. And what I what I tell people is is part of the secret sauce in her in terms of how what Cerby does is we have our chaos engine. And that chaos engine has multiple different patents. You can go out and look at those around how we do these certain things. But that's usually a question people ask me. They're saying, were you guys just doing RPA? And the answer is is our platform will use that in certain cases, but our chaos engine handles what would normally be very brittle. Right? So if you've built r b RPA scripts before using like a UiPath or something like that, they work they work okay until something changes. Right? So I'm I'd love to see in the chat. If you've built r if you've used RPA before, just put a comment in the chat. I wanna see this because usually, it's very, very brittle. Right? It works fine until something changes. And when it changes, all of a sudden it breaks, and then you've gotta constantly monitor and maintain that. Part of what we built into the Cerby chaos engine is the ability to automatically handle Drift in an application. Now I will say that we are not to the point where it's fully autonomous. Right? We're not in a fully autonomous world, and our platform works in a deterministic way. There are some that are trying to apply a fully one hundred percent autonomous approach to this, and that is not what you want. Not in the world of identity and access management. Like, the responses that happen need to be deterministic. Right? So if someone needs to, leave the organization, you don't want an AI making a decision saying, maybe this time it won't be provisioned. Right? It's gotta be if there's a deep provision event that's coming from my Entra or my IGA or my Okta, it's gotta deep provision that user every time in all the apps. So our chaos engine handles that. And in the case where our engine is unsure, we have human in a loop that can then take that supervisory action. So that's how Cerby does, handles that type of, UI automation and how it handles a lot of those workflows. So our workflows are deterministic. They've been audited many times by our hundred plus customers, and, that's how we handle that type of automation. So I know we're just about out of time. If you want more information on Cerby, how we do, we do. We have a webinar coming up. I believe it's next Wednesday. If you scan the QR code on your screen, that will take you to a page you can sign up to register. And what we're gonna cover in this is a bit different than what we covered today. So it's gonna feature our head of product and also our head of product marketing and they're gonna do a actual demo of Cerby. So if you wanna see how it works, this is a great way to kinda ask questions, get in behind the scenes, and actually see a platform in action. So you'll see that. You'll also see how we enable organizations to manage entitlements and then do flexible offboarding across cloud and on prem applications. And you'll see how we do this across various different platforms. So if you want more, scan the QR code now, sign up for the webinar next week, and you can learn how Cerby can potentially help you extend your existing investments to apps that you normally can't reach. So, Lior, thanks for joining. This is, always fun chatting with you, and, I think that is it unless there are any questions in the chat. I don't see any that are in there. So, Mike, if you are there, I will turn it back over to you. Oh, thanks so much, Matt. And, I I also just wanna say, give a great another shout out to Lior because those examples of talking through the ROI, I think you you you gave some great examples of showing what everybody shared pain is. But having that transparency and talking about the data, I think are really good lessons that people can take to figure out to go beyond just we have a problem, what should we do about it? So I think that part of the discussion really resonated for me. And I think I hope it did for all the attendees as well. And also want to say thank you, Matt, for walking through such a wonderful narrative of giving us an idea of what the problem here is. One of the biggest takeaways for me seeing this was not only you can save money, as I mentioned that Lior was showing, but you can also improve security. So huge shout out to just that user experience. And then if you throw on that example of scaling so quickly, suddenly, you know, if somebody gives me that choice of fast, inexpensive and secure, you can choose all three, why limit yourself to one or two? So I think I just wanted to really highlight that for the audience and just say thanks once again to both of you. Awesome. Thank you, awesome. This was great. Thank you. I wanna say just one more quick shout out to Cerby for sponsoring today's webcast. Thank you to everyone who joined us and stuck around and asked questions and were really wonderfully interactive for today's webcast, as well as everybody in the future who's listening to the recording. Please do check out Cerby. Check out, their presentation and demo next next week on the eleventh, And keep an eye on securityweekly dot com for more engaging webcasts like today's. Thank you.
As monday.com scaled, hundreds of business-critical apps that don't support SCIM or security APIs fell outside its existing identity tools. With thousands of employees relying on those apps, the gaps were hard to manage at scale, and manual access work raised risk and slowed IT down.
How did app growth outpace monday.com's identity tools?
Identity automation only reaches apps that support SSO and SCIM. As monday.com adopted more apps faster than those protocols could cover, a growing share of applications had to be managed by hand, which meant slower onboarding and offboarding, inconsistent access policies, and more room for error.
What did monday.com do about disconnected apps?
monday.com used Cerby to bring those apps under the same identity controls as the rest of the stack, automating access and credential management for apps with no SSO, SCIM, or API. That let the team apply consistent policies and lifecycle automation across every app, not just the connected ones.
What results did monday.com see?
- Secured more than 200 applications that fell outside traditional identity coverage
- Raised consistent access and credential coverage from 20% to 78% across applications
- Saved 3,300 IT hours a year by reducing manual identity lifecycle work
How does this fit with an existing identity stack?
Cerby completes the identity stack rather than replacing it. monday.com kept its existing tools as the system of record and extended their reach to the disconnected apps they couldn't connect to, so the same policies applied everywhere.
What you'll learn in this session
- How monday.com secured more than 200 applications outside traditional identity coverage
- How the team raised access and credential coverage from 20% to 78%
- How monday.com cut the cost and effort of identity lifecycle management, saving 3,300 IT hours a year
Presenters
Lior Zagury, Director of Global IT, monday.com
Matt Chiodi, Chief Strategy Officer, Cerby
Presenters
Lior Zagury
Director of Global IT
monday.com
Matt Chiodi
Chief Strategy Officer
Cerby