Machine identities, service accounts, secrets, and now AI agents already outnumber human employees in most enterprises, and the gap widens every quarter. Most security teams cannot say how many non-human identities exist, who owns them, or what they can reach. That blind spot, not a shortage of tooling, is where breaches start.
This panel brings together an independent analyst and One Identity practitioners to examine how AI agents and non-human identities are changing workforce identity models, privilege management, and governance, and what to do about it now.
Machine identities get created and never cleaned up, accumulating as orphaned, over-permissioned accounts. Credentials get hardcoded and rarely rotated, so one leaked key can open a path to critical systems. And IAM built around job titles and static roles has no equivalent for software that requests and escalates its own access in milliseconds, while approvals still run on a human calendar. Agentic AI doesn't create these problems. It scales them.
The fix starts with discovery: inventory every non-human identity, assigning a human owner to each. Then extend the same discipline already applied to people: least privilege, defined lifecycle, regular certification, revocation in minutes rather than quarters. Treat privileged machine access as a first-class PAM problem: vault secrets, rotate credentials, replace standing privilege with just-in-time access. The controls that govern human identity are the right controls for machines. They just have to be applied before agentic AI closes the window to do it by hand.
And non-human identity is the leading edge of a larger shift. Identity and Access Management is at an inflection point, where AI-driven machine identities, decentralized trust models built on blockchain, and the coming cryptographic disruption of quantum computing all reshape how organizations think about workforce identity, authorization, and governance. Agents and NHIs are the pressure teams feel first. Getting those controls right now is what prepares a program for everything behind them.
Nitish Deshpande, Senior Analyst at KuppingerCole Analysts, frames the independent analyst's view of how AI agents and non-human identities are reshaping workforce identity models, and where current IAM programs fall short.
Larry Chinski Global Vice President of Strategy and Rob Kraczek, Field Strategist, bring the practitioner perspective: how One Identity customers are discovering, governing, and securing machine and agent identities today, and what a realistic first-90-days plan looks like.
Who should attend
If you are responsible for governing machine identities, securing privileged access, or preparing your IAM program for AI agents, this webinar is for you.
Okay. Hello, everyone. Welcome to today's KuppingerCole webinar, The New Workforce Identity Challenge, where we'll speak about AI agents, NHIs, and the IAM Gap. My name is Nitish Deshpande. I'm a Senior KuppingerCole Analyst, and today I'm joined by Larry Chinski and Robert Kraczek.
Larry, Robert, welcome to today's webinar. Thank you for having us. Hi. Good afternoon, everybody. I'm Larry Chinski. As Nitish just said, I'm Global Vice President of Strategy here at One Identity.
Hey, everybody. I work for Larry. I'm a Global Strategist for One Identity, and I'm happy to be here. Perfect. Thank you so much, Larry. Thank you so much, Robert. I'm looking forward to today's conversation. Today's webinar is very interesting, very interesting topic. We have received a lot of interest in this special topic. So I look forward to starting this, but before we begin, here are some quick housekeeping rules. So you all are centrally muted, so you don't need to mute or unmute yourself.
As always, we try to have these webinars a bit interactive, so we will be running a couple of polls during this webinar. So I would like to request all our attendees to participate in these polls, provide their inputs, and we look forward to discussing the results of these polls in the final Q&A session. But if you have any questions in between the webinar, you can always enter them using the Livestream control panel, and we will try to answer as many questions as possible towards the end of the session.
And finally, we are recording this webinar, so the slide deck and the webinar video will be available for download in the coming days on our website. Let's start right away with the first poll of today's webinar, and that is, what is the ratio of NHIs compared to human identities within your IT environment?
Is it one, NHIs are 0 to 10 times more than your human identities? Is it two, NHIs are 10 to 20 times more than human identities? Is it three, NHIs are 20 to 50 times more than human identities? Or is it four, NHIs are more than 50 times your human identities? And you can enter your choice in the control panel, and look forward to seeing the results towards the end of the session. Maybe Robert, I would like to bring you in here, is Robert, Larry, both of you, is that, what do you think about this, the current explosion of the NHIs compared to human identities?
Maybe can you share your thoughts on this? Yeah, I can jump in really quick on that. I was going to, Nitesh, I love that opening question. By the way, I'm coming to you live from Belgium, where I'm at a global, or a regional event for a bunch of our customers and partners, and guess what is the big topic of the event?
NHIs, AI agents, you know, so we've got several sessions on that, a lot of really good conversation, but I love your opening question there. I would add a fifth option, and the fifth one is, we don't know. We don't know what the is, because we don't know where they are, which I think might be an easier one for a lot of the folks to answer.
So, yeah. That's 100% correct.
You know, I think both of you have an interesting perspective on it. Larry, you're interacting with customers and partners all the time. You're getting their perspective. There's so many different ways that they measure their NHI and the test you have, you know, you perform excellent analysis of the current industry trends.
So, you know, when I look at it, and this is why I built this slide, I look at it as like, can you spot them? Do you even know where they are? I've seen both spectrums. That's why that survey is the way it is.
I've seen, you know, large customers say, well, we know where all they are. We don't know what the big deal is. And then I've had other large customers say, we have no idea what we have. We don't know where it is. We don't know how or where people are standing up in our environment.
So, in this slide, what I wanted to point out, you know, how many of you could spot, well, here's an interesting one. Maybe you could put it in the chat. How many of you can spot how many humans are in this chart? It's represented by icons.
Yeah, that's a good one, because my NHI discovery tool that's embedded in my brain took me a while to find them, Rob, which I think might actually be the point of your slide, which is they're hard to find, right? Yeah, I agree with you. I think it took me a while as well to point down the humans in this slide. I think that goes back to, again, discussing the, and say the exclusion of the NHIs in the current space. And I agree with you that maybe there's also another slide around, we don't know it yet.
And that is also a case we have heard of from several people is, like, when we were doing the analysis last year, it was just many of the companies were just at the discovery stage, or they're still trying to find where they are in this NHI space. So, I think this is a good slide to begin with, yeah.
Yeah, and, you know, just jumping onto what you said there, Nitish, you know, what do you think about the NHI explosion? And, you know, and your question, it sums up pretty nicely, you know, is it 20 to 1, 51, 41? Because I think, and Nitish, you know, we've talked about this a few times before, you know, you and I have had several calls together, you know, and one of the things that's interesting to me is that, and I like to say is, it doesn't really matter what the ratio is.
You know, when you look at, the numbers are all over the place. And I'll give you a true customer example. We have a customer in North America who's doing a POC around NHI discovery and, you know, and then governance.
90,000 user employee, 90,000 employee company, they uncovered 47,000 NHIs and the proof of concept. Now, but really to them, it doesn't matter. It's still 47,000 NHIs that were discovered, and they knew about a couple of thousand of them, you know, and they're spread across about eight different categories of NHIs there. But I think that's the point. It really doesn't matter because all it really takes is one. The attack chain is really significantly different for NHI breaches than it is for human breaches, because there's a move laterally concept, elevate privileges, create more.
So the ratios almost don't matter because there are, there's still a bunch and they're still unmanaged, right? I agree with you. Everyone has a different ratio, but like, this is a good example that we have always heard NHIs being 10, 20, 50 times more, but the example that you gave is a good example that there are also cases where NHIs are maybe 0.5 times of identities. But I guess the question then comes down to after you have done the discovery is that what's the main issue around it to the ownership part as well?
I guess, Robert, maybe do you have anything around that point? Yeah, that's exactly it. That's what I was just thinking about is, okay, you found them all. Who owns them? Because typically, a lot of environments, those NHIs have been aggregated or built up over time. So added a system here, added a system there, needed a quick service account to attach some router or switch to your network to collect telemetry or do some sort of LDAP connection. And we'll touch on this a little bit, but there's a lot of, those NHIs have probably been there a long time. Yeah. Wouldn't you guys agree? Yeah.
But the ownership chain has typically been in siloed sections. Oh, we don't need to worry about that. It's a service account. It's been there for 15 years. Bill set it up and he's retired. So whatever, right? I think you bring up a great point there, Rob, when you talk about how old they are, because let's face it, when you look at the skills shortage for cyber and IAM and things like that in general, a lot of people leave and they move on. So those NHIs could be there for years and really no ownership or no accountability because why they were created in the first place may not be needed.
And the person who did it is no longer there. So that it's definitely a kind of a systematic thing that could happen very easily. Yeah. I agree with you. Yeah. I think there's also a case that, let's say the people in organization, their responsibilities are scattered across different teams. So nobody knows who owns which identity and who's accountable for it. So I guess that's when, as I mentioned, the case of let's say orphan account comes in is the credential, I guess, are not rotated. So nobody remembers who created the service account. And so it's, I guess, that's the next step as well.
But maybe for, let's say for people in our audience who are starting just right now with NHIs and agents, what do you think from your experience will be their initial response? So initially, and I'm going to try to answer your question this way, Nitish, because part of the problem of there being so many and unmanaged and unmonitored, I used the three uns, they're unknown, unmanaged and unmonitored, and they all kind of three form in there. But kind of the key thing that has to happen, because when you look at the 10 governing principles of NHIs are very similar to human identities.
When you understand how you have to what they're comprised of, et cetera. A lot of those principles, zero trust, all those things apply, but the discovery of those really becomes sort of the key, what I'll call component to them is being able to go off and locate and find them. And then you can manage them.
And one of the things that, one of the other problems that falls on top of how many there are is exactly how you're going to manage them and why isn't there one single vendor that can manage NHIs, because they're spread across tokens and API keys and CI pipelines and service accounts, workload identities, machine identities, et cetera. So by the time you then do find them, it's hard to manage them with one single vendor because you're just spread across so many.
So looking at an organization, the first thing to do is actually knowing where they are and what types they are and what the categories are, because then you can at least put together a plan for figure out which ones have elevated credentials, which ones are really low risk, just basic service accounts and things like that. Things like printers, a lot of printers have elevated privileges, believe it or not. So finding them, then you can actually put together a plan to categorize them, figure out where the privileges are, and then manage them with your IAM protocols and things like that. Great.
Robert, maybe you have any thoughts Yeah, so a thought just occurred to me while we were talking. I mean, I've been a practitioner and a consultant in the field and when I look at this type of sprawl conversation, I don't know about you guys, but it reminds me very much so of when people started first adopting JML or IGA tools. Yeah. And we were trying to understand where your identity or where your accounts were in your environment from source systems, directory services, that sort of thing. I see this as the same paradigm or similar. I think the big differentiator is agentic AI.
I think NHIs, service accounts and that sort of thing, I think we have a relatively clear understanding of what they do or what they can do. Now things have gotten a lot more advanced with OAuth tokens and we have to safely inspect to make sure that those things are doing the correct things at the correct time.
And then, like you said, Larry, the silos of NHIs, that needs to come together, but agentic AI is a little bit different, particularly if they're operating as a human. So I'd be curious to hear, see what you guys say.
I mean, I'll fire up the next slide here so we can have a talking point, but from my perspective, from a broad perspective, the management model is very similar for these things, but where they differ is how you manage them or the mechanisms behind it. So I'd like to hear, what are your thoughts, Nitesh, on human identities, non-human identities?
Obviously, the management paradigm is very similar, but what are the major touch points where people need to consider the technologies that they're using to manage the different aspects of NHIs, particularly agentic? Yeah, definitely. I think this is a really good slide, and I guess if you look at it, there's more similarities than, I guess, just the differences. You have your first step of identification, classification, authentication, but as you mentioned exactly, it's what's inside those steps.
So it's a bit different for your human identities versus your NHIs, and that's where, I guess, the changes are seen. For example, if you look at authentication for human accounts, yes, you have someone entering your passwords and FAs, but for NHIs, that's a bit different case. So you need to have rotations happening, and machine identity, I guess, needs constant, continuous vaulting and rotation. So what you need, I guess, is there's no human loop in this situation.
That's, I guess, the difference here. Again, similarly for, I think, if you look at the second point, which you have highlighted here, is the own and govern. That is the main one, I guess, for NHIs is to really have someone who owns these identities, someone who is really accountable for these identities. And I think with this, I guess, this slide's really good, summarizes what are the differences and similarities in here as well.
Maybe, Nare, do you also have anything you would like to add? Yeah, so thanks, Nitish. I think you're right on. I agree completely. As a matter of fact, if you were to break some of these down, if you just start with the very first one, identify and classify. So for human identity, that's pretty simple, right? You see your list of users. We've identified them. We've classified them. They've got different roles and responsibilities and things like that. For an NHI, the identify is a key one. So you have to identify they are before you can govern them at all. Because I'll use the three uns again.
They're unknown, unmanaged, and then they're unmonitored. So we have to do that before we can even begin that process. And I'll use an example. As a matter of fact, one of the comments, Jeff, just talked about AI agents running as NHIs. How about agents running as humans, right?
Well, one of the examples I used there just today is we were talking about the function of RPA, Robotic Process Automation, and the things that bots actually do inside of an organization. And a lot of organizations are actually using bots as a, I'll call it a low or a kind of a slightly lower version of a JML process or an IGA platform, where they're actually using bots to create users, delete users, assign privileges, and things like that. And they're unmanaged.
And again, they're unmonitored. And they have a lot of access and a lot of rights. So those are one of the things that we talk about to sort of answer Jeff's question is, you know, AI agents have a complete different set of challenges, I'll call that, with regards to NHI, because they operate kind of at a different level. A lot of NHIs are fairly static.
You know, service accounts, they're there, they do one thing. Bots are there, they do one thing. So some of those are, a lot of them are pretty low risk. But AI agents are different, because they're constantly changing, learning, adapting on the fly. So I could almost have a whole separate conversation on the classification of AI agents as NHIs than other different categories of NHIs. Yeah. I have a fourth one to add to your list, Larry. Okay. Untrusted.
Ah, yes. Good one. Good one. Yeah. It just occurred to me.
So yeah, I think this is a great part of the topic, because when you're looking at these, and I like to build this type of slide for the practitioners and the professionals, you know, which I'm sure the complete audience is, you know how to do this, right? You know the process to control, or not control, but to govern and manage identities. Yes. You just need to apply that process in your head to NHIs, particularly agenic AIs, because, you know, Jeff asked a great question. I view agenic AIs, they're an extension of what you're doing.
So the responsibility of the organic person transitions to that agenic AI. Now, obviously, you need to have guardrails from an organizational perspective.
But, you know, if I asked Claude to do something naughty in my lab, it'll do it happily, right? It doesn't, it has no repercussions. There's no, especially if you introduce an AI model that doesn't have moral guardrails put on it. Say you spin up your own Olama or some other, you know, open source LLM that doesn't have guardrails. You as an organization need to ensure that your governance model can still control that, even from restricting access to it all the way down to, yeah, I'll let you use it in a closed environment.
But I think the people that use these types of tools and are in our sphere of professionalism, they know how to do this. They just need to figure out a new methodology. So I think you're exactly right. It's a little bit of a paradigm shift, isn't it?
So, I mean, just because we know they're not, matter of fact, the first example of this, and by the way, this NHI problem, as we'll call it, or concern, I'll put quotes around it, really isn't anything new. You know, I remember, you know, Rob and I, you and I go way back, almost 30 years now, unbelievable. But you remember, you know, there were instances, I remember the very first customer that was a waste management organization that sucked in all of their actual garbage trucks when they first outfitted them with GPS locators and things like that as objects in their directory service.
You know, so those became NHIs all of a sudden. So then it became like, oh, now we can manage them as real identities. So the tools and processes now in, you know, IM platforms, obviously, you know, map directly to the governing principles of NHIs and how they're managed, just like we manage human identities. Understood. Okay. I think this then brings to, I guess, a similar question was that, do you need a separate tool for this NHI governance or an existing IGA PAM can be extended to it? So in your experience, when you speak with your customers, what is it they are preferring?
Maybe we can start with Robert here. So that's an interesting question. I was just thinking about that, because if you look at the discover and classify exercise, you would think, and obviously I'm a bit naive sometimes, but you would think that once you discover and classify once, you'll establish a process. You won't necessarily need a tool after that initial discovery and classification. You'll have something that needs to continue to perform maintenance, but it's not going to be this bulk discovery function. I'm of one opinion there.
On the other hand, if you're doing a lot of M&A activity where you don't know what you're getting, say for instance, you're purchasing another organization that you don't know what their IT is like, or they don't have a really very organized, well-organized IT, you're going to need to have a tool that can continually churn that discovery process.
So I guess it depends on maturity level, whether you're at, you know, you're somewhere where you're just beginning to understand how to manage agenic AIs and NHIs in general, and you have a lot of churn in your organization from an organizational perspective. And then you have more mature organizations that are very static. They kind of know where everything is already. They just need to turn on things in their existing IAM infrastructure to be more aware of NHIs in general. So I don't know. What do you think, Larry?
Yeah, well, I think you're exactly right. And you know, you kind of listed two different models there. And I think that what you're leading to, as a matter of fact, a question popped up similar to what you were just talking about. Ari was asking about, you know, how you can't manage with a single vendor. And like you're talking about the discovery aspect of that.
And what I mean is, you know, when you look at how far these NHIs are spread across all these multiple platforms and the different categories they are, you know, a lot of them have elevated credentials, which you want to use some type of privilege access management solution to help manage. You need to discover them.
So most PAM solutions and IGA solutions aren't going off polling for NHIs because it takes a different type of methodology for that in that typically, you know, you would track activity or activity or what's happening across the ecosystem and then look for programmatic changes about those identities that are doing those things. Are they logging in at specific times? Are they logging in and out at specific times? Is it an automated process of some kind? So then those get categorized that way. And then once you determine some are elevated, they need to be managed through a PAM solution.
Like I said, if they're related to SAS or AD, there's certain tools you have to do there. So when I say that, you know, one vendor hard to manage is because they're spread out across so many different platforms and they have so many different rights and privileges you need, you know, those things.
So, you know, jumping back into kind of what you said, Rob, that whole discovery aspect and then how do you get to manage them is all a part of that entire process that I think that we've been doing for some time. It's just like you said, a little bit of a different shift in how you have to manage that. It is. Absolutely. Yeah. So I have a question for, or a comment.
So, you know, we've, Larry, you opened up with some interesting statistics, you know, 0.5 to one ratio at that customer. Right.
Natasha, you talked about, you know, there's statistics all over the place. I'd say it varies quite a bit depending on industry usage, how static your environment is, all sorts of numbers, but I would say that it's all over the place. So when I say every identity used to have a face, that's a little bit sensationalistic because I say most identities used to have a face. We always had NHIs, but now most of them in some scenarios don't. When you look at this statement, do you say, no, that's wrong? Or do you say there's nuance? Or do you say that's 100% right? So Ditesh.
Yeah, I think this is a, I think we start with, I guess, these two terms that I mentioned earlier in the session is around ownership and accountability. So who owns the, who owns the NHI, yes, that is a face, but I guess that is just the starting point. Accountability is the more, the more stronger idea around that NHI or that faceless identity. It answers who is responsible for when things go wrong or when you need someone to be responsible for certain actions.
And I know we are talking about now AI agents as well, and that gets even more interesting as you have your own AI agent, and if that AI agent gets its own agent, then who owns that sub-agent? So I guess it flows back to deciding who will be the So if I were to summarize it, I would say is that, yes, ownership, I guess, is important for having a piece of the identity. But I think what you need a bit more is around accountability is who will be responsible for the life cycle of that agent for that NHI. I think that's where the differences are for me as well.
Maybe Larry, do you have anything you'd like to add? Yeah, no, I think you're right on again, Ditesh. And you know, that's an interesting quote most used to have a face.
And, you know, we're trying to put a face to them, I guess, is the best thing I can say. And to add to what you just said, Ditesh, and figure out the account owner. The problem with when you say used to have a face, we're talking about a human identity. It was like one thing, one category. It's a user. It's an end user, right? But in NHI, there's multiple categories.
And Rod, we've got them listed right here. Employees, contractors, service accounts, API keys.
Well, I mean, employees and contractors probably have a face, but service accounts, API keys, pipelines, agents, OAuth tokens, workloads, things like that, that actually don't have a face. Mapping those back to an account owner, or, you know, putting some type of wrapper around it, that gives it a virtual face, I'll call it.
Yeah, very critical. And, and, you know, then going in to manage those, right?
Yeah, that's exactly the point that we need to reattach. I think that, you know, going back to some of the questions we got, attaching those non-human identities, particularly agentic AI, but all of them, I would say, to ownership, then they can, then they can be placed under some sort of comprehensive management structure is the most important part. The ratios, to me, don't really matter that much. Yes. What matters, right?
What matters is that I, Rob Krawczyk, I'm responsible for these agentic AIs and these service accounts, and I have, you know, accountability through governance, you know, in my organization, whatever that governance process is, there's accountability, right? So that if something, if it needs to be maintained, or it does something bad, then you go in and you fix it, or you slap my wrist because it did something bad. But I think, I think that's the point of this for everyone who's watching. It's not that there's a ratio that you have to worry about.
It's that you have that ownership chain established. And back to something you presented before, Larry, you also have to have not only an ownership chain, but a joiner JML chain tasked with that. So you know exactly what's going to happen to that thing when it does an action, but also how you, how you bring new ones on board and how you expire them and get rid of them, which I think is the big gap that we have in a lot of these organizations today during their discovery phase. There's probably a lot of that stuff. They don't even need it anymore, right? Yeah.
Well, and I think you're right on the ratio, right? You know, Rob, let me ask you a question. I'm going to ask the moderator a question, which is an interesting switch here. How many NHIs does it take to wreak havoc across an identity ecosystem? How many? One. One. Exactly. Exactly. So the ratios don't matter because, you know, like this customer I talked about that uncovered, you know, 47,000 of them, you know, you can bet they were like, oh my gosh, because they were thinking a few thousand based on, you know, service accounts and things like that. But it really only, it only takes one.
And, but, but if you don't know where that one is, and a matter of fact, I'll, I'll, I'll jump it onto one of the questions. I think his name is well, Fonch, most vendors expecting that everything would go through their solution. I think you're exactly right. A lot of them do. And the critical part of that question is how important is the discovery part and what are the current best practices?
Well, I think the discovery is the actual most important part. Because I think once you, once you find them, then you know how to govern them because then it becomes just another identity.
You know, and obviously AI agents are maybe a little bit different there, but yeah, that discovery part to me is this is something I think everyone, every organization should be looking at a discovery process of some kind, if nothing else, just to validate your sanity and check that you actually know, because I think that you'd probably uncover a lot of knowledge by, by doing that. Similar to a pen test, you know, you run a pen test and, oh, wow, we didn't know we had these things going on. And we didn't know we had this, this breach point here.
I think that, you know, running a discovery exercise of some kind would reveal a lot. Yes, I agree with you. I agree with Larry as well. You can only, I guess, govern what you see. So discovery is really important. And then only you know what you need to govern them, what kind of hard drills you need around them.
Yeah, those are all great comments. I'll just say, leave with one funny thing for you guys. When I was an IT manager, I had a service account attached to some scripts and cron jobs, and it literally, if I had, if that had gotten compromised, it probably would have taken down six, seven, eight systems, primary system. So naive younger Rob built that. I wouldn't do it today. But I bet you there's a lot of people in this audience that have some magic scripts that do a lot of dangerous things through NHI. So great conversation, guys. It's excellent. So let's go to the next one.
So now we've talked about, you know, the people and the process, some of the technology. But I'm going to posit a question for you.
Natasha, I'll start with you. Legacy. And what I mean by legacy is the structure that's been built, not necessarily the products. Legacy IAM was built for managing people. People have moral compass, they have responsibilities, they have limits to what they're allowed to do with an organization. Agents don't necessarily have that. So my question is, legacy IAM was built for humans and human roles and human policies. What makes it so different to manage NHIs? I know we had the chart where we showed the parallels, but what were the limitations?
And I have some, obviously, these boxes here explained a lot of it, but I'd like to expand a little bit more on what we mean by no life cycle or off-boarding and so forth. Yeah, I agree with you. I think you have a really good point around that legacy IAM was not built for this kind of NHIs, machines, agents. It was mainly for your human accounts. The first point you mentioned here is around no life cycle and no off-boarding. For example, for a human account, when someone leaves a company, you have a proper off-boarding process. But for an NHI, there is none.
It stays there until someone realizes that the owner is gone, it stays active. So you need proper off-boarding for that. So that's why the first point makes sense of no off-boarding. The second one is that these agents are sitting quietly, that they're holding their passwords, they're actually doing things. As you mentioned, they're reading emails, they're querying databases, which the traditional IAM systems were not designed to handle these situations. And they're also not designed to trust each other on this situation.
And I think the trust boundary, I guess, gets a bit wider as soon as you realize what kind of functions are allowing the agent or the NHI to go through. So I think I agree with you on this slide as well, that legacy IAM was not built for machines. But I would like to hear maybe Larry's thoughts as well, what would be the things of this shift? Yeah. And I think one of the obvious ones is, what makes it so hard is just the sheer volume and the number. Like the example I used, companies got 90,000, now they have 137,000 all of a sudden.
So one of the best practices, and there's been a few questions around best practices for certain things. One of the thoughts I always have is, OK, if you look at, let's take that 47,000, how many of those can actually just be deleted right now and removed? Probably a ton. Probably a ton. Just like human identity, before IGA came along and access and all that kind of stuff, you had to manually go out and there were many cases where breaches had sat around for, because identities were there two years with still rights after they were long gone.
So I think what makes this a little bit more challenging is just the sheer volume and getting underneath, do they need to be here? Are they actually doing anything? And then going off and doing a cleanup exercise, just did some migrations for organizations recently where we had to do a ton of cleanup on all the target systems platform. Otherwise we just sucked in a bunch of unnecessary identities into the new system. So I think that's another one is just getting underneath the volume and which ones need to be there and which ones don't need to be there.
I think Larry, you wrote an IAM piece on the genies out of the bottle, right? So how do you set up the guardrails as you're doing the cleanup process? Because you definitely don't want to bring things in that shouldn't be there in the place. That's exactly right. Yeah.
And that's my point of the whole thing is that, when that happens, I remember writing that here a few months ago and around the guardrails you have to put in place because you have to, when you look at the, just the level of the privileges that they would have, you've got to understand what that is and then map that to, one of the governing principles doesn't really need it. If so, okay, we've got to categorize that and put it over here. We got to get a PAM solution involved or whatever, or whatever other tool might do that.
It may be something that we have to use, some type, if it's an Active Directory account, for example, or Entra or something like that, we have to use some type of elevated tool set to manage that. But yeah, so I think exactly when you kind of blend all these things together, that becomes such an important part of how we actually look at that, the cleanup process, moving of the elevated credentials.
When you look at, if it's a thousand, it could be more than half or just leftover things that, since we didn't know about them in the first place, now we know about them, now we can just get rid of them. So we have to put a process in place to actually do that. I got one more thing before I transition to the next slide. Our favorite topic, security standards. So as part of this, NIST, DORA, the new, the EU digital identity wallet controls, they're trying to react to this pretty quickly. And as we all know, governing bodies are just so fast to react to things, right?
So, Nitesh, when it comes to NIST, DORA, the EU digital wallet, I think that the token topic is very topical, if you'll pardon my pun, but could you tell me more about what your thoughts are on the, how people are going to be, how organizations are going to be able to react to these new standards as they come out? Does the tooling exist today, number one, and number two, how concerned should they be about token expirations and non-persistent type of access for particularly agentic AI?
Yeah, so I think maybe what I can start with is that where it doesn't, let's say, and it's, I think it's three things that are, that defines them is, first is the number of legacy applications that they have that are not maybe designed for the short-lived tokens and that you mentioned here. Second is also the SaaS to SaaS integrations, where you don't have the lever to pull, you know, the vendor has this.
So the third is just again, back to the sheer scale is you would have to touch, I guess, every single application individually unless you've got something, something like a vault or layer that is sitting in front of all of it that is enforcing this policy. So I think the token point is very relevant as well right now. I think we have to be honest, you mentioned around the one-hour lifetime. So that is a bit, that's optimistic, but I think it's achievable.
But maybe I can maybe ask this, I guess, passing this question to Barry to see what, from a vendor point of view, what do you see in this scenario? Yeah, and I think you're right on the one-hour, the one-hour, you know, what I'll call best practice.
So, and I think the, what we'll call short-lived token hygiene. I think it's, it's a pretty proactive industry practice. Like I think everybody understands that that is a best practice. But I think, you know, deeper life cycle pieces, like, you know, when you look at the cross vendor revocation signaling, you know, consistent workload patterns, things that are, that are kind of outside of FedRAMP supply chain, that kind of stuff, it's probably going to need some type of mandate lever, I would think, you know, kind of the broader market along.
Because I don't think that's going to happen voluntarily. Like you said, I think that's very optimistic.
You know, so it's very fast moving. You know, the standards are, they're kind of all over the place. When you look at the best practices, NIST and all that, the problem with a lot of those standards is that there's really no ramifications. It's not like you're going to be punished or something from the government, whatever government it is, except if you are a government agency, maybe. So there's, I think there's a lot of caveats to the whole token thing. And to your point, Nitish, it's pretty optimistic. It's a best practice. I think we all know it's a best practice.
But, you know, as these deeper, deeper processes come along, it's, it's going to probably need some type of mandate to make it certain. Right.
Yeah, absolutely. But do you have anything you would like to add?
Well, I mean, I think it's laughable, even a one hour token expiration, what kind of damage can an AI do in an hour? And the example which you have given here around the sales loft drift, I think that is a good example of token lifespan.
Yeah, absolutely. And what actually, an interesting, I wanted to address Scott. Scott posted up a question in a comment. How do you prove these identities are trustworthy as quantum computing arrives? That's a diabolical aspect. So I thought about what you guys were just talking about with standards and tokens. I think by the time that stuff is ratified and passed as law or as a standard that you need to adhere to, quantum computing will be closer than ever. And that's going to make all that obsolete.
So I don't know if you guys have any comments to that, but I just look at quantum computing as that next level of concern that we're going to have to worry about. Yeah, no doubt. Quantum computing and as AI moves into what I'll call phase two, where it's no longer just only trained on the publicly available data sets, it's, you know, as organizations start to open up their own APIs, proprietary information, how that evolves, that's definitely going to change things. That's a good point that Scott raised there, because that is the diabolical thing. It is.
So I think, you know, I'm sorry, Nitesh, I think it's important to go back to your guardrails, right? Yeah.
Yeah, we can go there as well. But I think I was just reading again the comments. We have another question. It's again around the regulations. What are your thoughts about organizations using NIST AIRMF and ISO 42001? Maybe Robert or Larry would like to take this one. I can take it. I think it's a great place to start.
I mean, they're already ratified, and they have the guidelines in place as best they can reacting to the technology that's available. So I think if your organization is structured enough that these will fit within your current governance policies, I think that's great. I think if you have to re-architect your time to do that, and I think, Nitesh, that falls into your purview of like, how long should you wait to adopt these? And then if you adopt them, how much pain are you going to experience internally, right?
Because that's really the friction point is typically an organization trying to react to these new standards in a way that it's timely. You know, Larry, you've seen it from our major customers worldwide that they try to adhere to something like the new NIST standards, and it takes them five years to get there by then. That's exactly right.
Yeah, because some of those regulations require pretty deep core analysis and reconfiguration and reconstruction of what you have. But they do, there are a lot of really solid guidelines and guardrails in there that if you're able to adopt those quickly, and what I like to do is look at what's mission critical. So if you understand what's mission critical, go for that first and see what you have to do there, and evolve out from there. And you just start moving laterally across all those different downstream applications and systems and things like that you have where those exist.
What do you think, Nitesh, do you do a lot of analysis on these things? Yeah, definitely. I think for me, the question that we get around is how long does it take for an organization to start from zero and get to that level of maturity? Maybe as a vendor, when you work with your customers, what do you come across? What should an organization expect? And I think there's a similar question for us as well here is that if an organization is an SMB, what should they expect as well?
Yeah, so in an SMB, you know, again, so we all have different acronyms just in different terms. So SMB, when I think of it as a small medium business, is that what we're talking about?
If so, yeah, you know, and here's the thing, you know, and I'll equate that to, you know, kind of it's an analogy that I've had for a long time when I look at, you know, different types of levels of organizations that it doesn't matter, the data, for example, I remember when the biggest people or biggest organizations concerned about breaches were finance institutions, healthcare, things like that. You look at, because they had very important sensitive data, finance, you know, finance data, you know, things like that, you know, very critical.
But when you look at how breaches occur now, look at the JBL, a meat processing plant that was breached a few years ago, that was held in ransomware. They never thought they'd be a target of a breach because who cares about a waterhouse? Who cares about meat? Who cares about that kind of thing? But you know, who does care about that data? JBL. And so when that data gets breached, then they can't operate as a company. That becomes a real problem.
Well, I look at SMBs as the same thing, same set of, you know, maybe at a smaller scale, but same challenges exist. Same type of threats exist.
You know, when you look at some of these breach points now, and I'm talking about breaches now because NHIs are such a huge target of those now, even more than human identities, because they're able to get in undetected because the NHIs are unmanaged and they're unmonitored. So then once they do that, if you look at the eight steps in the kill chain for an NHI breach, they spread laterally, then they elevate their own privileges, and then they create more.
So now, not only did one NHI get breached, they've moved across multiple systems, they've added more and elevated the privileges. So now it's spread everywhere, and then it's even more out of control. So getting back to SMB, same set of challenges, sure, at a smaller scale, but when you look at these type of breaches, ransomware, for example, you hear about the big ones that demand millions of dollars, but what you don't hear about are the hundreds and hundreds of thousands of them that only want a couple thousand bucks.
Get in, get out. EFL, easy, fast, and lucrative.
So SMBs, same thing. The same set of challenges need to look at this the same way, because your data, besides your people, is the most important thing that you have. And that's what, you may not think it's important, but threat actors know it's important to you.
Yeah, I agree with you. I think it's organizations now of every size are prioritizing security and compliance as well. We recently are working on a report that is focused on just SMBs lifecycle management and governance in them. And we came across findings such as that, even for SMBs, companies that have size of 2,000 or maybe below, NHI governance is becoming an important part for them as well. This report will be soon live in the next month on our website, but I think I agree with you. For SMBs as well, it is equally important, and the ransom is not that high, but it's still there.
So yeah, maybe Robert, yeah, go ahead, Rob, because I know you and I have talked about the SMB challenge before. So the interesting thing for me is SMBs, many of them are not islands. They do not operate as individuals without any connectivity to large organizations. And so I have, actually, I have a really good friend that works at a very large retail organization. He manages all their external security, contractor relationships, third parties, from an IT perspective.
And he's been visited by, in the States, by the FBI, because they had contractors that supplied very small SMBs, say 50 to 60 employees. They manufacture an item, and then they have a federation to this organization. And they're able to transfer financial data and financial data exchange and other things, and they were breached. So this little small 60-user organization was breached, and from that breach, they were able to get into the large organization with 180,000 users and distribute, just like Larry just described.
So I'd say SMBs, it's just as important, if not more important, because they're going to target that organization because, you know, no offense to anybody on the call, but you probably have less resources and less manpower to manage identities like a very large organization. So they're going to try and get you first. I agree with you. They have leaner teams, so it makes sense that they are the target. And I think this is a good time to introduce our second poll. The second poll is, what do you think will close this NHI agent governance gap first? Is it first, is it better tooling catch-up?
Is it two, major breach forcing the issue? Is it three, regulatory compliance? Or is it four, budget and internal ownership alignment? That's a good one, Atish. I like that. That's a good question. Yeah.
Yeah, thank you. Yeah, I think, looking forward to seeing what our attendees select. This is a really good question. So I think we have a few minutes left still, but maybe we can go back, Rob, to your slide, and then after that, we can discuss the poll results.
Yeah, excellent. So this is my bombard everyone with slides. So I wanted to make some broad recommendations, and then I want Nitesh and Larry to give me their thoughts on that. So we talked about finding the accounts, finding the orphan accounts, and blast radius. But I'd like to know, Nitesh, what's your perspective on these recommendations? Could you add any color to these? Any others? Are they wrong? What's your take?
No, I agree with the recommendations completely. It definitely starts with running the discovery. You need to find what you have in your system. Then only you can go towards governing them. And you need, with this discovery and governing part, you need the observability as well. We talk about human in the loop for the collections, but for AI agents, I think we also need some sort of a human over the loop, someone who has full visibility and all the actions of the agents from start to finish.
And then once you know what your agent is doing, once you know your NHIS are doing, you define its policy guardrails, and then keep an eye on it on what is doing. You, as mentioned, the third point, you kept the blast radius. So I completely agree with these points. And I think this space has grown really rapidly in the last 12 months. I think if I remember correctly, we started the first NHI leadership compost last year, and there was a strong, strong interest into that.
And even before we published the report, we had several queries that when is the next version, because we have already made new capabilities, add new capabilities, and AI agents was a much more evolved topic back then. Right now, it's here. So I agree with this recommendation. So start with understanding what you have, and then you can move towards governance. Larry?
Yeah, I think you're right on it, Tish. I mean, you got to, Rob, go find them, run a discovery process, clean up the ones that are irrelevant, that you don't need. And for whatever is there in your capitalized races, I mean, you take your least privilege, you know, you can enforce those same principles on NHIs, just like, you know, human identities, and manage them. And so that's, it sounds like overly simple, but that's, you know, really what that is.
And, you know, French asked a question, from discovery to cleanup, is there a standard practice across vendors for a data format that can be shared? And I don't know that there's a data format necessarily, because really once you, and, you know, like discovery vendors, most vendors that are dealing with identity, we've all been working on, you know, either IGA, or access management, or PAM, or AD defense, you know, kind of in silos.
And, you know, like one identity here, we try and blend all those together in an identity fabric, you know, just, you know, just like Kubrick Cole, and, you know, have you guys been talking about that for such a long time? But, you know, when, so the data format is not there.
Now, there may be different ways of doing discovery, and things like that, as those are pulled in, but a lot of the discovery vendors don't really manage them. So it's not really a data format question, necessarily.
It's, you know, you kind of pull them in, and then you can use your governing principles of your IM platforms, and then kind of manage, you know, those things. And Rob, I'll let you comment on that too.
Well, I mean, I'm a simple guy. So I look at it from the ISO model. Remember the ISO model, everybody?
Oh, sure. Yeah. Yeah. So hardware and work your way in. Yeah. So I look at it as a multi-faceted approach. So Jeff actually asked the question here, what are organizations doing today, or should be doing to have guardrails in place? And I look at it as, you need to know where your data at rest, and your data in transit is what it's doing, right?
And, and there's a lot of products that, that will provide stateful inspection of traffic. And that's a great thing to know.
You know, homegrown might be an answer too. You might have some, some homegrown systems that need to establish some guardrails around, but it comes down to governing the data and managing the data, governing the identities and managing identities. Those are the two things that I, the two big processes I look at.
So for me, guardrails should be data guardrails, and they should be governance guardrails. Now, one identity is an IAM vendor. We provide great identity guardrails. So through governance, PAM, AD management, that sort of thing. But you also have other products and vendors out there that provide networking guardrails, guardrails around ITDR practice type capabilities. So I think when you, when you look at your organization, you should look at it from the an NHI would touch and particularly a genetic AI, and then figure out where your gaps are.
I mean, that's, that's how I look at it from a big picture view. Obviously, I'm way oversimplifying the level of work there, but those are my thoughts. Right. Perfect. Thank you so much. I think we have just four or five minutes left. So what I would like to maybe do is maybe now discuss the poll results and we have the answers. So the first question we asked was what is the ratio of NHIs compared to human identities within your IT environment? And the option which has got the most votes is NHIs are 20 to 50 times more than human identities.
The second one is NHIs are a hundred times more than human identities. That is the second one. The third one being 50 to a hundred times and fourth one being 10 times. So I think maybe Rob, Nari, what do you think? Yeah. And that's very interesting. And I guess one of the, I guess I'll call it the good news about that is sounds like most people actually know what the ratio is in their organization. So that's good. If their answer was, I don't know, then, you know, that, that would be a bigger and I think there, you know, there are still a lot of organizations out there though.
But in that case, I think the conversation we had today on, you know, and the very last slide kind of summed it up on what we need to do, discover, clean up, and then minimize the blast radius by enforcing least privilege and really any other security protocols that you would, if it was a human identity. That that's my quick one, one minute or less summary on that. Yeah. Thank you so much. I think if anyone in the audience has an answer that is different than these four options, you can enter into the chat as well. Maybe Robert, do you have anything to add here as well?
Well, I mean, I, I, you know, I would back up Larry on that one. I mean, the issue we hear is we're, we're in a webinar and we're trying to, you know, we're attempting to solve these, these very large, broad problems. And I think we solved them all though, didn't we? I think we got the NHI problem solved now, right? We missed one thing. We missed one thing.
The organizational structure of a typical IT infrastructure or IT team, there needs to be more, if you don't have it already, which I'm not going to assume you do or don't, you need to have more cross-pollination of what you're doing with, particularly with NHIs. Because I found in my dealings with organizations that AD team, they care about service accounts. They don't care about these other things. They don't even know what this other team's doing. The infrastructure team's got service accounts that manage like the switches and routers.
You've got accounts, NHI,ogenic AI that maybe finance is using to do analysis. There's no, there's no mesh of the management of these currently. And I think it's more of an organization today. And you see these silos address them because I mean, AI is so fast, right? So you can't react at a human level to these things. You need to have a really good cohesive guardrail.
So, you know, back to some of the questions around guardrails, I would say, make sure your organization is prepared for not only the discovery, the results of the discovery, Larry, back to your 47,000, but also how do you react to it in a cohesive way through a centralized team, right? Whether that's a new steering committee or whatever. So that's my thought. Perfect. Thank you. And the second question we asked was, what do you think will close the NHI agent governance gap? And 50% of them have answered for major breach forcing the issue.
While 25% have chosen budget and internal ownership alignment. Regulatory compliance comes third. And then the final one is the better tool in catch up. I think forcing the issue seems to be high on the list. What do you think from your point of view?
Yeah, that's one that I probably, I kind of expected would be there. You know, that seems to change a lot of minds pretty quickly. And as far as where to invest and how to invest and how much. So that one doesn't, I'm actually glad to see that. But yeah. Yeah. I've smirked a little bit. Cause I remember back when I was a IT director, they would ask, somebody would ask me, what's the most important application in your environment?
I said, whatever is broken today. Right. So that's right. That's usually how it is too. Yeah. Right. So unfortunately us as IT, you know, professionals, we, the major issue is going to force, the major problem is going to force the issue.
And I, I I'm sorry that 50% of you feel that way, but it's, it's pretty much part of our business. Yeah. Perfect. Thank you so much. I think we have just one minute left. So I think we have also answered all possible questions that we got. Any final thoughts before we leave? Maybe start with you, Robert.
No, I appreciate about the great conversation guys and it was really fun. Yeah. Thanks Nitesh for hosting. It's been a great session. Perfect. Thank you so much, Larry. Thank you so much, Robert. And thank you everyone for joining us for today's webinar. You can go check out our other research material around this topic on our website and other events information as well. So thank you and we'll see you again soon for our next webinar.
See All Locations
See All Locations