Your next privileged admin might not be human. As AI agents, service accounts, APIs, and automation platforms increasingly perform administrative tasks, a new class of non-human identities (NHIs) is emerging across enterprise environments. Operating across cloud, on-prem, SaaS, and OT/ICS systems, these identities often hold elevated privileges yet lack the governance, visibility, and behavioral oversight traditionally applied to human administrators, creating new and rapidly expanding attack surfaces.
Alejandro Leal, Analyst at KuppingerCole will outline how the identity and privilege landscape is evolving in the era of AI-driven automation, discuss the growing security risks associated with non-human identities, and explore emerging best practices for extending PAM capabilities across cloud, infrastructure, and operational technology environments.
Erhan Yilmaz, PAM Product Management Director at Kron Technologies will present practical approaches to securing privileged access across hybrid infrastructures, covering network PAM, governance of non-human identities, integration with CIEM, and the role of AI-based behavioral analytics. Sefa Yildiz from Turkcell, a Kron Technologies customer, will share real‑world insights from implementing PAM for network environments and non‑human identities.
Who Should Attend
This webinar is designed for security leaders, IAM and PAM architects, cloud security professionals, and IT decision-makers responsible for protecting privileged access in modern hybrid environments.
Hello, everyone, and welcome to the webinar, Rethinking Privileged Access for Non-Human and Autonomous Identities. My name is Alejandro Leal, Senior Analyst at KuppingerCole.
And today, with me, I'm joined by Erhan and Sefa. Maybe you guys could introduce yourselves. We can start first with Erhan. My name is Erhan Yilmaz, and I'm the Director of Product Management for Privileged Access Management at Kron Technologies.
Thank you, Alejandro. Hi, everyone. It's great to be here. And I'm Sefa Yildiz, and I'm Leading Access Management Operations at Turkcell. Thank you. Thank you so much. Awesome. Thank you very much, guys. It's great to have you on board. As we know, it's a very exciting topic. There's a lot of momentum these days. And without further ado, let's just move on. Looking at the agenda, as I said, we're going to start with my part of the presentation. I'm going to sort of set the stage for today's topic. And we'll move later with Erhan and Sefa. They'll talk more in depth.
They will also give some practical recommendations. And then we'll have, in the last 15 to 20 minutes, we'll have a Q&A. So I encourage the audience to be engaged. You can enter questions at any time in the chat, and we will be addressing those at the end. So just a few more things here. All of you in the audience, you're muted centrally. So there's no need to mute or unmute yourself. We'll also be conducting two poll questions. And I will be really happy if you can answer those so we can discuss them at the end of the webinar.
And as I said earlier, you can enter questions during the webinar by using the Livestorm Control Panel. And yes, we will be recording the questions and the presentation slide decks will be available in the next couple of days. So just to begin, first poll question, which is, what is your organization's biggest challenge in managing privilege access today? You will see it on the screen for some time, but I'm going to be moving forward. So here we have a quote. We are delegating privilege to entities we cannot fully observe or explain.
As we know, many people in the industry are aware there's a lot of noise on agentic AI, a lot of talk on artificial intelligence, and a lot of talk on artificial intelligence. A lot of talk on agentic AI, a lot of talk on NHIs.
So we are, in a way, increasingly delegating privilege access not to people, but to entities that we don't fully understand, we don't fully observe, and in many cases, we cannot fully explain. And that sounds like a very philosophical problem.
However, that's a very identity and security problem for organizations today, because privilege, as we will see in the next slides, has always assumed accountability, visibility, and intent. And now those three things are being challenged by the rapid technological developments that we see in the market. So for today's webinar, I'm hoping that you will be able to understand not only the challenges that we see, but also a path forward. And together with Erhan and Sefa, we'll be able to share practical scenarios of how organizations today are addressing the challenges that we see today.
So in the next slide, we can say that traditionally, PAM has been framed as an access problem. Who gets access when and under what conditions? But in reality, PAM has always been an identity problem. At Kupinger Co, we are going to publish a leadership compass report on PAM in early to mid-May. We conducted research on 36 vendors. And before going into the research, we had to define privilege, because there's a lot of definitions out there. And as I've been hinting, the traditional definition of privilege has changed from the past.
So in a way, what we try to define in this report is that privilege in the enterprise should not be understood merely as access granted to a small set of admin accounts, but as the ability of any identity to perform actions that affect systems, security controls, infrastructure, or other identities. So in this context, privilege is defined less by who holds a specific account and more by what an identity is capable of doing within an environment. So this definition shifts the focus of PAM from managing privilege accounts to controlling and governing privilege actions across an environment.
And as I've been referring earlier, the challenge today is that many of these identities exist but remain unseen. Some of these identities outlive their owners. They operate without any clear ownership. And they also accumulate privilege over time. That creates blind spots. Attackers don't break into systems anymore. They operate within these blind spots. They log in. So the issue is not just access control. It's identity, visibility, and governance. So just to go back a little bit, here we see a sort of timeline. And what we're seeing is a structural shift in how privilege access works.
So we move from legacy PAM, mainly driven by human admins, to service accounts and automation, to machine identities and APIs, and now and potential future scenarios to AI-driven and autonomous identities. Each step expands the attack surface. But more importantly, each step moves privilege further away from human control. And the key issue is this. Our governance models have not evolved at the same pace. In this slide, we have what we call the invisible workforce.
And again, there's really no consensus on terminology. Some people like to say machine identities or NHIs. I'm not going to get into that area. But to keep it within the scope of this webinar, NHIs now include machines, workloads, APIs, service accounts, and increasingly AI agents. And they behave differently from humans. Some are long-lived. Some are ephemeral. Some are autonomous and adaptive. But they all share one thing. They operate with privilege, often without sufficient oversight.
And in many organizations, they already outnumber human identities by orders of magnitude, which is a problem. Now, I know that none of this is new. We've been talking about machines outnumbering humans and cloud and DevOps expansion, governance gaps, for many months and years. But the difference today is scale and speed. Manual identity and access management processes cannot really keep up. And as a result, identities multiply faster than they're governed. Privilege accumulates faster than it is reviewed. And trust is eroding over time. So the problem is no longer awareness.
The problem is execution at scale. In the next slide, we see that with recent developments, last week there were interesting things happening in the industry. And that brings the question of how agentic AI is breaking those assumptions. AI is fundamentally changing how attacks happen. So we are seeing autonomous discovery of vulnerabilities, automated privilege escalation, exploitation of identity infrastructure itself. And that is critical because identity systems are no longer just controls. They are now targets. And privilege escalation is no longer manual. It is automated.
It's scalable and increasingly autonomous, which fundamentally changes the threat model. So what does governance look like in this world? We need to start treating AI agents as privilege identities. And that means, let's say on the control side, dynamic, short-lived credentials, behavioral constraints, and monitoring with intent, not just with actions. On the governance side, full observability. Many organizations don't have that across their entire systems.
We need clear ownership and defined escalation paths because the key risk is not just misuse, but it's unanticipated behavior, behavior that we did not plan in advance, that we were not expecting. Because agents don't just follow instructions, they adapt. And governance models must reflect that. So now I would like to shift gears a little bit and show you the results of our leadership compass on non-human identity management that we published in 2025 last year.
As I said, we're now conducting research on PAM, but that will be published next month in May. So I encourage you to stay alert and reach out to me or check out our website in one month to see the latest results in the PAM space. But here we look at the vendor landscape. We see that the market is evolving rapidly. The leadership rating is structured from the challengers in the center to the leaders on the right. And something that is important here is that there are no followers in this space on the left side. And that reflects the maturity and innovation happening here.
So we see leading vendors like Microsoft, Delinia, CyberArk, BeyondTrust, the usual, let's say, PAM suspects, but we see Keeper Security, One Identity, and Chrome. And these vendors are delivering both core PAM capabilities and increasingly advanced automation. So this is not a static market. It's an emerging one where capabilities, positioning, and leadership are still shifting. And that's important when evaluating solutions. If you're an organization looking for NHI management, that's something that you should consider.
So I think by now it's, in a way, should be clear that privilege access is expanding. And one of the key developments is that PAM is no longer a standalone discipline. It is converging with adjacent capabilities. So from machine identity management to cloud infrastructure entitlement management, SIEM, secret management, and behavioral analytics. Each of these addresses a gap in traditional PAM, and together they form a more complete view of privilege identity. So instead of thinking of PAM in isolation, we need to think in terms of integrated control across identity types.
And that will bring me, in the next couple slides, to the identity fabrics. But before going into the identity fabrics, we need to understand that many organizations today have a hybrid reality, and that's when things become difficult. Organizations operate across multi-cloud environments, on-prem and legacy systems, and increasingly OT and ICS environments. And each of these has a different control model.
In cloud, we see fragmentation and permission sprawl. On-prem, we see static credentials and long-live access.
And in OT, we see limited visibility and external access dependencies. So the challenge is not capability alone, but consistency of control.
And again, as I was hinting earlier, this is where the concept of an identity fabric becomes relevant. It provides a way to unify NHIs across applications, infrastructure, and environments, including OT, here on the left side. And it connects identity governance, access management, PAM, and analytics into a cohesive model. So identity fabric is not based on one solution or one technology, but it's more of an approach, an architectural way of looking at identity. So instead of fragmented controls, we move toward coordinated identity enforcement.
We have plenty of material on identity fabrics on our website. We have white papers and webinars on the topic, so if you're more interested, check that out. And we're also working on the upcoming Leadership Compass on Identity Fabrics, which will be published later this year. So the identity fabric approach, it translates into four key principles.
First, integration. So NHIs must be part of a broader identity architecture.
Second, lifecycle management, which is something that I believe Erhan will talk about later today. So how we go from discovery to decommissioning, just like human identities.
Third, entitlement oversight. So using tools like Keem to continuously enforce least privilege. And fourth, accountability. So having clear ownership across teams, because without ownership, governance breaks down. So this is the last slide before I give the stage to Erhan and Sefa. Future directions and recommendations. So where do we go from here? I tried to, you know, it's a very rich topic, so it's not quite easy to summarize everything in just 15 to 20 minutes.
But my idea was to introduce you with the challenges that we see, the developments in the market, some of the vendors that are addressing these challenges, and some potential recommendations that could be very useful. And in the second part of the webinar, Erhan and Sefa will go more in depth into these areas and offer some practical recommendations on that. So here we have some key priorities.
So first, move from static to dynamic privilege. Access must be time-bound. It must be contextual and adaptive.
Second, treat non-human identities as first-class identities, including agentic AI. Third, integrate PAM with adjacent capabilities, because no single tool solves this problem, and having this identity fabric approach can be beneficial to see the full picture and to be able to connect all the dots. And fourth, enforce least privilege continuously, not just as provisioning. And finally, build for hybrid environments, because privilege is no longer centralized, but governance must be.
Privilege access is no longer about controlling who logs in, but it's about governing how identity operates across humans, machines, and increasingly autonomous systems. So we see also some convergence between PAM and IGA, and it's something that we go a little bit more in depth in our leadership compass that will be published and available next month. So with that, I would like to now give the floor to Erhan and Sefa. And after their part of the presentation, I'll be back and we can have a Q&A discussion.
Thank you, Alejandro, for this great presentation. In this part of the presentation, I'm going to walk through how privilege access management is evolving and why non-human and autonomous identities are becoming one of the most critical security challenges for today's world.
But first, I would like to start with Krone. Krone is an identity and data security vendor with nearly 20 years of experience.
Today, we operate across multiple regions and industries, serving more than 400 customers in 35 countries. I'd like to start with privilege access management evolution.
15, 20 years ago, privilege access management looked very different. At that time, privilege access management designed primarily for humans and approach was straightforward. Storing credentials in a password vault, controlling access to critical system, and monitoring the session.
But today, the landscape has fundamentally changed. First, our infrastructure are highly distributed. Organizations now operate large number of network devices and many of them remain unmanaged or insufficiently controlled.
Second, we have the rise of OT and ICS environments. That systems are critical but often difficult to secure.
Third, we have moved from single data center to multi-cloud and hybrid environments. These environments significantly increase the complexity and expand the attack surface. And finally, and maybe the most important part, we now have more non-human identities than human identities. With the addition of agentic AI, these identities are not just increasing in numbers, they are becoming autonomous and making decisions on their own. Let's start with network layer.
In most organizations, there are tens, sometimes hundreds of network devices, but many of them are overlooked from a security perspective. These devices typically rely on local accounts, which are often static and shared across multiple users. That means no strong control and more importantly, very limited accountability. In other words, every network device you trust may be accessed without clear visibility. And this is how we address these challenges.
First, we start with network discovery. ChromePen builds a complete inventory of all network devices by scanning your environment. We scan your environment with a simple network scan or we can import inventory from Active Directory or from an inventory database.
Next, we enable centralized authentication by integrating with enterprise directories like Microsoft Active Directory, Microsoft Enter ID, and any other servers. This allows users to access network devices using their corporate credentials. And we also extend this authentication mechanism with multi-factor authentication, leveraging existing identity providers. On top of that, we provide centralized authorization using protocols like TACACS+, and values. So access decisions are no longer static, but controlled centrally.
And finally, instead of basic policies, we provide context-aware access control that enables more advanced dynamic decisions based on session and user context. Next, let's look at OTA-ICS environments. These are the systems we typically don't touch. They are often legacy and highly fragile. There is no tolerance for downtime, so they must remain continuously operational. At the same time, these are some of the most critical systems in your organizations, but they are often least controlled from a security perspective. And this is how ChromePAM secures OTA-ICS environments.
First, our approach is completely agentless. There is no need to install anything on the target systems, because target systems are critical for fragile OTA environments. We establish a secure tunnel between users and target OTA systems. Through this secure tunnel, we enforce session isolation so users don't need to access the full system but only access specific application or port they are authorized to use. And we also enable secure, governed, remote access for third-party vendors without exposing underlying systems. Let's continue with multi-cloud environments.
Today, organizations operate across multiple cloud platforms, creating users, roles, permissions in each of them. But in most cases, these roles are over-provisioned and actually a large portion of those permissions are never used.
Over time, they are simply forgotten, creating unnecessary risk and expanding the attack surface. With ChromePAM's TM capabilities, we address these challenges in a structured way.
First, we identify excessive permissions across cloud environments. ChromePAM shows what users and roles can actually do versus what they should do.
Next, we reduce risk by eliminating over-privileged identities. We continue to monitor for risk roles and generate alarms when excessive permissions are detected. And finally, through continuous analysis, we enforce and maintain least privilege over time. Most attackers today don't go directly to critical access. They target privileged identities. Once a privileged identity is compromised, it can be used to access multiple systems across an internal network. And the challenge is that traditional security controls are not designed to detect this kind of misuse.
As a result, compromised accounts are often undetected. At the same time, our environments are becoming more dynamic, but many of our detection methods still rely on static rules.
And now, with the rise of AI agents, this challenge becomes even more complex. ChromePAM's AI-driven user behavior analytics address these challenges. First of all, we establish a behavioral baseline for each user to understand what normal activity looks like.
Then, as we continuously monitor sessions and privilege actions, we can detect any deviations from that baseline. When an anomaly is identified, we generate a risk report. And based on that risk report, we can trigger automated responses like sending an alarm to a system manager, or terminating sessions, or blocking users.
So, instead of relying on static rules, we adapt to behavior in real time. Let's move to non-human identities. ChromePAM is no longer about just administrators. It's about identities.
And today, non-human identities already outnumber human identities. And before explaining the security issues, let me explain what the non-human identities are. Non-human identities include service accounts, API access keys, access tokens, and identities used by automation tools. These credentials are used by our applications, our custom-developed software, our workloads, and these are everywhere.
And now, there is a major shift in the security landscape, a new power center. The most powerful identities in today's environments are AI agents. These identities operate autonomously. They act with delegated privileges, open without a real-time human oversight. They enable machine-to-machine access at a scale, chaining multiple systems and permissions in a single flow. And doing so, they can bypass many of the traditional controls that were designed for humans. The result is that with the single-compromised non-human identity, attackers now have a much greater impact than before.
So, the challenge is no longer just managing access. It's controlling how these autonomous identities behave in our network. And this is how ChromPam secures non-human and agent identities. We need to move from uncontrolled machine access to fully controlled privileges. The first step is controlling access. As we do for human identities, ChromPam can scan your network to identify non-human identities.
Then, we securely store credentials and rotate them regularly and after each use, and eliminate hard-coding secrets from source code, configuration files, and CICD pipelines. The second step is controlling access. Non-human identities should follow least privilege and just-in-time access principles. ChromPam applies least privilege, policy-based access control, and clear boundaries on what they can do. And finally, we need full visibility and monitoring. ChromPam tracks every action performed by machine identities, records sessions, and continuously analyzes their behavior.
In this new world, it is not just about accessing systems. It's about these identities, what these identities are doing, and if the behavior is expected or not. Let's sum up everything together. ChromPam provides a comprehensive platform to secure privilege access across all identity types and environments. We cover core capabilities, such as password voting and secrets management. We manage and monitor privilege sessions. We extend protection to endpoints and databases. And our platform also includes AI-driven behavior analytics and detect anomalies.
And importantly, we provide all these features within a single unified platform. And today, we have a guest from Turcell. Turcell is one of our long-standing customers. I would like to give the floor to Mr. Safa Yildiz. Mr.
Safa, can you please share information about Turcell and how ChromPam helps you to secure your human and non-human identities? Thanks, Erhan, for the great presentation, first of all.
And hi, everyone. It's great to be here. Before I go into details, I would also like to congratulate ChromPam for their leadership position in the recent Copinger Call reports. And I am Safa Yildiz, and I am leading the access management operations team at Turcell. My team is responsible for managing privilege access across our infra, especially for network systems and critical environments. And I'll try to share our experience in a simple and practical way. So just to give a bit of context first, Turcell is a telecom operator with around 45 million customers.
We operate in Turkey, Belarus, and northern Cyprus. And at this scale, everything becomes bigger. More users, more systems, more access, and of course, more risk. And honestly, our story started with a very simple problem. We had too many devices and not enough control. And as Alejandro mentioned earlier, this is not only an access problem. It's really an identity problem.
Now, this is where things become more real. Erhan, next slide, please. Thank you. This slide shows our actual scale with Chrome.
Today, we manage around 210,000 network devices and around 2,500 users are accessing these systems. If you look at the activity level, we had around 135 million logins every month and more than 280 million commands executed. So this is not a small environment, right? At this scale, manual control is simply not possible. At this scale, you cannot manage access without understanding identities. Now imagine this. Every engineer, every operation, every intervention needs access to these devices. So the key question for us was who is accessing what and what are they actually doing?
With Chrome, we centralize everything. Every login is authenticated, every action is authorized, and every command is recorded. At our scale, this is not optional. It's absolutely necessary. And once you solve access, you start to see another problem. Credentials, especially service accounts and non-human identities. These accounts are not always visible. They are sometimes shared and they don't behave like normal users. So they create a different kind of risk. With Chrome Vault, we started to manage this properly.
Now credentials are stored securely, passwords are rotated automatically, and access is fully controlled. We are managing around 175,000 credentials in that vault. This gives us much more confidence, especially for the critical systems. If I summarize the impact, we moved from limited visibility to full control and traceability. And that changed everything. Because now we can see what is happening, we can prove it, and we can react faster.
Also, as mentioned earlier, the identity landscape is changing. It's not only about human users anymore. Machines and non-human identities are growing faster than human users. We clearly see this trend in our environment as well. That's why non-human identity is becoming very, very important for us. We are still at an early stage, of course, but we are exploring this area with Chrome. From our side, what I can say is this. At our scale, reliability is critical. And Chrome has been a strong partner for us. So that was our story in a nutshell. And thank you for your time.
And I'll give the word back to Alejandro. But Alejandro, before I finish, maybe I can also briefly share our perspective on the poll question.
Or, I don't know. Thank you, Erhan.
Thank you, Sefa. Just to be clear, that was the last slide, correct, Erhan? Yes. Okay. Okay. I will share the second poll question here. First of all, thank you, Erhan and Sefa. That was a very engaging and interesting presentation. It's also good to see how Chrome has helped us implement all of these and address all the challenges. So now if we look at the second poll question, how much use your organization's spam program?
And it's interesting because I was having a conversation the other day with some end user organization, and they told me that all this noise around agentic AI and NHIs is too much for them to handle. And they're just looking for password rotation. So it's also something interesting that I tried to highlight in my report that for some small and medium-sized businesses, spam is still foundational, and they're still slowly entering, let's say, the area of NHIs and all of this. So for some of them, they just need the foundational capabilities.
And something that I noticed in this report is that there are some vendors and some new vendors here in Europe, at least, that are addressing the needs of small and medium businesses because they don't really need some of the solutions that mainly focus on big enterprises. But anyway, I will just go quickly through some of my remaining slides, and then we can go to Q&A and talk about the poll results. So we have some related research.
As I said, we'll be publishing the PAM report next May, but we also published an ITDR report in October of last year, and we have some other reports on team NHM management, DevOps, and the signal-driven identifier for 2040. Some of you know that we'll be having the European Identity and Cloud Conference in May taking place in Berlin. We have it every year. So if you're interested, you can use the QR code to get more information on that, and I will be there.
I'll be doing a presentation on PAM on the 20th of May to discuss the results of the Leadership Compass, and there will be hundreds of people there, so we can continue the conversation there. If you're from the audience or someone from Chrome will attend, I'll be happy to connect. And just a brief reminder of the services that Coupling and Call Analyst does. We do research, events, webinars, and advisory work. So thank you so much. That's all from our side. I know that we have some questions in the chat, so maybe we can go over the questions first, and then we can talk about the poll results.
So there's one question here, the first one. If we have dozens or even hundreds of devices, what's the easiest way to onboard them into Chrome PAM and bring all privileged accounts into the poll? I think that's a question for you, Arhan. Okay.
Actually, this is one of the first questions when we install Chrome PAM to the customer environments we get from the customers. And yes, there could be thousands or hundreds of devices in the network, and sometimes our customer doesn't know where they are actually. Maybe they have knowledge about service databases, but network devices especially, they don't know where they are because they rarely log into that device. So they don't have an inventory list of these devices.
When we install Chrome PAM to the customer environment, actually we have some different approach to scan or import device inventory to Chrome PAM. First, we can scan, basic network scan for the network devices. So we can detect network devices, servers, databases, and web applications in the network, and then import them according to their types, according to their sizes, and then group them in our device inventory.
And also, we can integrate with Microsoft Active Directory or CMDB databases, so we can import these devices automatically from that inventory as well. So customers don't need to import devices one by one and add devices one by one to Chrome PAM.
No, that makes sense. Yes, as you say, some organizations don't really even know which devices they're not using anymore. So PAM platform should provide these discovery capabilities to scan directories, network segments, to identify the privilege accounts, service accounts, and credentials. That's really good to know. There's another question here, Erhan. So in financial institutions, even a short network outage can be critical. So if something like that happens, how can applications still access the passwords they need without any disruption? Yes.
Actually, in enterprises, there could be different purposes, there could be different needs to use non-human identities. So we have different options to get password from our password vault.
First, we have APIs. So using basic RESTful APIs, applications can fetch the password from password vault if they try to get the password. And we have some plugins for Jenkins, Kubernetes, Ansible, and other CICD tools. So they don't need to fetch the password from our password vault using RESTful API. They can use these plugins to fetch the password. And especially for the financial institutions or critical systems, if they are using their custom-developed application, they're really very sensitive to fetch the password.
So even if a network issue happens in the environment, they need to get the password as soon as possible. So we developed a solution for that. We have Secrets Management Agents, which can be installed on application servers. So even if there's a network outage, and even that application server cannot reach the Chrome pen, they can fetch that password from Secrets Management Agents, which store that password for a specific time. So our Secrets Management Agents has a caching capability. So the applications can get the passwords without any disruption.
Thank you, Erhan, for sharing that. Yeah, I'd say that in general, PAM solutions are designed with high availability and resilience in mind. So including these potential scenarios and incidents that can happen, so many offer secure local caching or credential retrieval mechanisms for applications to ensure connectivity. I just want to now change topic, because there's a very good question in the chat on NHIs. So the question is...
I'm sorry, I'm having an issue here. Here. So how will be the governance of NHI agentic AI accounts handled? Will they be hand over full responsibility to agentic AI admin to manage the whole account lifecycle, or we will continue to use human oversight slash intervention to some extent? If I can take that first. I'd say that it's a sort of a hybrid governance model. I think the industry is talking about that sort of the human at the helm. So moving away from purely manual reviews, there were more automated and policy driven management.
So in a way, the humans will continue to define the guardrails, the policies and the boundaries for what agents can do. But then the agent role can manage the more, let's say, technical details, the technical lifecycle, the creation, rotation and revocation within those boundaries established by the human.
But Erhan, do you have any thoughts on that? Yeah, actually, our approach for agentic AI and agents, AI agents has three parts. One of them is the identity used by these AI agents. So as you said, we need to govern that identities, which used by AI agents using our secrets manager. So we can actually we can let them to use a credential for a specific time. And then we can rotate the credentials after each use. And second part is as humans, as humans, we do for humans. They need to they have a session to their decision between AI agents and an MCP service.
So we need to govern that sessions between AI agents and the target systems. So right now, we are working on a solution to manage the session between AI agents and the target systems as we do for humans. And the third part is identifying anomalies using AI, actually machine learning. So actually, we are adapting our AI based anomaly detection for non-human identities and AI agents as well.
Yes, I remember from our previous conversation a few weeks ago, that was one of the things that stood out to me from the solution. There's another question here. How do you manage AWS and Azure API keys with Chrome? Is automatic key rotation supported?
Yes, actually, this is another key topic, another popular topic that we get questions from our customers. Right now, as our applications installed on the cloud or using cloud services, they need to get access to AWS, Azure or Google Cloud Platform API. So to do that, they need to use AWS, Azure or Google Cloud Platform API keys. Using our secrets manager, they can actually store these API keys in our secrets vault. And then we can rotate periodically and after each use these API keys.
So even if somehow their source code or configuration files are breached or accessed by a hacker, the credential that they breached is actually useless because we already changed them. There's another question in the chat. Is there any way to gather telemetry information for shared accounts? Like what clients using the same shared account to access critical resources?
Actually, using our session manager, police session manager, end user doesn't need to know the target system's username and password. We store that credentials in our password vault. And during the session, we inject that credentials to the session. So end user doesn't need to know the target user's password. But we lock all this information in our session log details. And also we send this information to CM servers so they can check from our session logs and also they can check from CM servers to which credential is used for logging to the target system. Got it. OK.
Well, there's one more question and then we can take a look at the poll results. So the last question is, can Chrome PAM respond automatically to suspicious behavior or does it always require manual intervention? I think you already alluded to that, but maybe you can elaborate more. Yeah. Using our AI-based behavior analytics module, when we detect any anomaly, we generate a risk score. So based on that risk score and based on the configured threshold, we can do some automated actions like terminating session, blocking user or just sending a notification to system manager.
Actual system admin doesn't need to do manually. OK.
Thank you, Erhan, for sharing those insights. So now let's look at the first poll question. The question was, what is your organization's biggest challenge in managing privilege access today? So 42 percent of respondents said securing human and non-human privilege. Thirty one percent said lack of visibility into privilege accounts. Twenty three percent said integration with broader identity and security systems. And only four percent said legacy PAM tools that do not fit cloud and DevOps. So it looks like the number one challenge is to secure human and non-human privilege.
And I'm guessing you're not surprised by this. Yeah, but I can choose the second one, maybe lack of visibility into privilege accounts, because actually from our experience, visibility is the biggest challenge, especially at our large scale. So that's why our first priority was to understand who is accessing what and what they are doing. And before you were able to deal with this with Erhan and his team, what was your approach? What was the thing that you realized, OK, this is not working?
Actually, lack of visibility is the biggest challenge for today's work. So when we when we present our present our product to customers, the first question that we get from customers is how you will detect which accounts, how we will detect which identities in our network, even they are human or non-human. But this is the biggest challenge. Got it.
OK, well, now let's move on to the second question. How much is your organization's spam program? So 56 percent said we have basic voting and password location in place. Ninety percent said we've integrated them with IGA and endpoint controls. Another 19 percent said we are adopting just in time and risk based privilege management. And only six percent said we're just starting to define our strategy. So over 50 percent have the basic foundational features that we expecting.
Is that something that surprises you or you think this is mainly based on maybe industry, geographical location, because something that I also noticed when I spoke to you a couple of months ago, is that you have presence in regions that most of the vendors in the report that evaluated are not there yet. So I'm also very interested to see how different organizations in different locations, like in Latin America or in Central Asia, places of the world that usually don't get much research, at least from my perspective at Google.
So when you say that's something surprising to your hand, that we have over 50 percent saying basic voting, password rotation in place, that's our maturity. Actually, if you ask this question 10 years ago, maybe the answer would be different. But right now, everybody, much or less, knows what privilege access management is and what privilege access management does in our network. So it's not a surprise for me that everyone somehow has knowledge about privilege access management.
And actually, it is not a surprise for me to most of the people, most of the enterprises have password vault and somehow manage their identities. But they don't really use privilege access management with the full functionality, actually. It should be used for privilege session management as well. It should be used for endpoint privilege management as well.
And also, with the new approach, with the new technologies, it should be actual privilege access management solutions should use artificial intelligence to detect anomalies, detect user behavior analytics, actually. Yes. As I said earlier, based on my research, SMB-focused vendors are, in a way, gaining traction with simpler solutions that offer fast deployment and lower complexity because many of these organizations don't have big IT teams. So time to value is something that they're looking for. And I think that aligns with organizations that still view PAM as a foundational capability.
But I think we addressed the questions, the polls. Maybe any concluding thoughts, Erhan, if you have maybe, let's say, 60 seconds to speak to a CISO, what would be the key takeaways of today's webinar?
Actually, thank you for this opportunity to present our solution. And as I said, maybe the biggest feature that we have and the biggest differentiator that we have is we provide all these privilege access management functionality in a single platform. They don't need to install privilege access management in different services for password vault, for session manager. They don't need to use a huge deployment. So the best advantage of our solution is to install, is to use product, and then provide all this functionality in a single platform.
Thank you, Erhan. Sefa, any last thoughts? Thank you for your time, Alejandro, and Erhan, the Cron team, and the Digital team. And thank you for the great presentations. It was a great pleasure to share our experience also. Thank you so much. Thank you very much, guys. It was great having you. And if anyone from the audience, you have any questions, any comments, feel free to reach out to me or to Erhan or to Sefa for more information. And I wish you all a very good day. Thank you. Thank you.
See All Locations
See All Locations