Podcasts

Identity Is the New Edge: A Field CISO’s Playbook for Identity Security and AI Threats

Listen on:
Share this:

Episode Description:

Attackers don’t need a zero-day anymore. A stolen username and password, accelerated by AI, is cheaper, faster, and harder to detect. In this episode, Brian Zimmer, Field CISO at CyberMaxx, joins Shawn to break down why identity is the real perimeter, how managed detection and response has to evolve to match identity-based attacks, and what CISOs need to do right now to build governance programs that protect users without creating the friction that drives them to bad habits.

What You’ll Learn:

  • Why credential-based attacks are the attacker’s preferred playbook and how AI has made them even cheaper to execute at scale
  • How the shift to remote work collapsed the castle-and-moat model and put user identity at the center of every security decision
  • What a strong identity governance program actually looks like, from joiners and movers to certificate management and privileged access
  • Why authentication and authorization are not the same thing, and why conflating them is a governance gap CISOs need to close
  • How to minimize friction for your users while maximizing cost and noise for attackers
  • Why AI agents need identity governance just as urgently as the humans using them, and who in the org actually owns that problem
  • How modern MDR has to evolve from isolating machines to responding at the identity layer
  • The practical steps a CIO or CISO should take today to start treating identity as the new edge

Transcript:

Shawn Cordner (00:13.038)

Hey everyone, welcome to the Amplitude of Tech podcast. I’m Shawn Cordner, Chief Marketing Officer of Amplix. Today we have Brian Zimmer. He’s the field CISO from CyberMaxx. Had a great conversation about identity as the new edge, as well as human-centered design and security. I think we covered some really interesting topics on this one. Hope you enjoy.

 

Shawn Cordner (00:36.878)

All right, Brian Zimmer, welcome to the podcast.

 

Brian Zimmer (00:39.155)

Thank you very much. Good to be here. Well, I say that for now. We’ll see how goes.

 

Shawn Cordner (00:44.27)

I’m gonna say I’m happy to have you here except that you’re a Penguins fan and I’m a Flyers fan and the hockey players are going about to go as we’re recording this so we’ll see if we’re still friends in the next couple of weeks. Why don’t you just take a few seconds here and tell everyone who you are, where you’re from and what you do.

 

Brian Zimmer (00:55.741)

Peace in our time.

 

Brian Zimmer (01:04.013)

I’ve prepared an 85 slide deck to cover my background, so it’s going to be very exciting. I’m Brian Zimmer. I’m based in Charlotte, North Carolina. Place is terrible, tell your friends, nobody move down here anymore. We’re good. I’m the field CISO at a modern managed detection response company called CyberMaxx. I was a North American CTO for a competitor that I won’t mention.

 

before that and ran global pre-sales at E plus security before that. And done a lot of, a lot of stuff in my career, but solely cybersecurity. It’s the only thing I’ve ever done in my career. And I’m not saying I’ve done it well. I’m just saying I’ve done it.

 

Shawn Cordner (01:45.662)

You’ve seen quite an evolution over your career in cybersecurity. Why don’t we just like zoom out for a second before we get into the good stuff here and just, know, what, what has the journey been like?

 

Brian Zimmer (01:59.16)

is the journey been like? It’s okay. So it’s been interesting. That’s a lame thing to say. What I feel is I get to the 15th hole of a whole career. It’s kept me young. It’s kept me involved. It’s kept me learning. It’s kept me around younger.

 

people who are experimenting and have open minds and new ideas. And I’m really grateful for that. And I’m also grateful for frankly, the evolution and the change as well as the gravity of this space. I’ve been very fortunate and one of the best pieces of advice that I ignored when I was at Bank of America and a guy who was in the unified communication space route switch, tell me that I was too focused on security.

 

And then I needed to broaden my horizons. I’m glad I didn’t take that advice.

 

Shawn Cordner (02:58.134)

Yeah. You don’t always want to take advice. have to make sure you consider the source, but I do wonder, you know, I come from the telecom side so I could be forgiven hopefully if I’m a little bit off on this, but when I started in this industry almost 30 years ago, security was not something talked about a whole lot. Exactly. Right. And so I feel like today what’s different is everything needs to be looked at through the lens of security. So, know, what has driven that paradigm shift?

 

Brian Zimmer (03:25.998)

will validate what you said first of all. Part of the reason that you’re right is that we have gotten better. We as security practitioners, because I will tell you, me and Copa, a lot of us were not good at our jobs, myself included. In fact, I was particularly terrible at conveying risk, conveying priorities, understanding, being sympathetic and empathetic to lines of business.

 

Right? If you’re running a contact center and Zimmer comes in and tells you, stop the presses, you have to do all those things. Well, that’s not very health. And I think what we have security practitioners have done, especially in the last 10 years is really understand the business and understand where we fit in the business’s journey and outcome and goals. We are now in the boardrooms and we are doing a decent job.

 

in that boardroom, whereas 10 to 15 years ago, we were not, especially 20 years ago. So we’ve brought, we’ve upped our game to speak business, not security. And I went off on that tangent so long, I forgot the core of your question. Refresh my memory.

 

Shawn Cordner (04:44.014)

Yeah, I’m just, you know, I was wondering how the paradigm has shifted from security, not getting much love to security being, you know, really a whole piece.

 

Brian Zimmer (04:51.342)

Right. So along those lines, the one thing that we’ve done is we’ve started speaking in outcomes. We’ve started speaking in business continuity. We’ve been, we’ve started speaking in risk, risk minimization. And these are things that I’m not an expert in. You want to talk expertise and risk, talk to my friend, Jack Floyd, he’ll get you squared away. I will not.

 

And the other thing, and Sunil Yu talks about this, and I’m very fortunate to be in an event with Sunil in a month or so, or maybe less. He talks about us being in the age of recovery. What he means by that is, you know, products and services and defensive strategies are all built around stopping and sometimes even containing. But we know from experience that something will slip past us and we will have to

 

recover. And so what we’ve gotten better at over the last five years or so is thinking about what recovery looks like, minimizing business impact, getting business operations restored quickly.

 

Shawn Cordner (06:01.474)

Yeah. So if I think back to what it was like back then, the enterprise was a little bit like a castle in that it was small and within the walls of the actual building, that the people were working in for the most part. And so it was easy to defend the same way that a castle is easy to defend. You could have high walls, you could build a moat, you could do all the things, to keep people out and

 

The surface area was a lot smaller because it was just these four walls or however many locations he had. Right. And then, you know, I really didn’t pay much attention to the evolution until really COVID happened. And at that time, people got pushed from the office and outside of those walls to their homes. And they had multiple devices that were then connecting to the, to the corporate network. And of course, this didn’t happen over overnight, right? It grew exponentially overnight because of.

 

the pandemic, but you know, I had worked from home before then and I had a laptop and there was security. So I understand that, but more of the story is it accelerated so much and the surface area of the average enterprise expanded, you know, really multiplied by the number of employees they had and probably two to three devices for each employee. And then you have things like IOT starting to gain some momentum in the enterprise. So that perimeter has become a lot bigger.

 

The surface area is a lot larger and it’s a lot harder to defend. So is there a more modern paradigm that businesses should be operating under?

 

Brian Zimmer (07:39.414)

Yeah, I think, I think you’re pro the premise is exactly right. There’s no, but we all lived it. We all experienced it. It wasn’t really all that fun. think that’s why we see the rise of, of SASE. So secure access service edge technologies. think that brings us to one of the main themes of what we wanted to talk about, which is identity. think when you, when we, when that architecture, when that

 

operations changed that was sloppy conjugation of verbs and nouns there, but I think, I think everybody knows where I’m going. I think that put the emphasis on the user, the user’s identity, the user’s authentication and authorization. It put a premium on securing all of those devices that you’re talking about, the user’s endpoint, their Mac, their PC, their mobile phone, even their in-home infrastructure. So I think that is the big.

 

We were going that way anyway, but I think COVID was the one thing that just pushed us right over the edge.

 

Shawn Cordner (08:45.368)

So for better or for worse.

 

Brian Zimmer (08:47.406)

worse, right? Because, you know, I talked to somebody yesterday and they said, you know, thank, thank God COVID got my organization comfortable with remote work. So, I don’t know. There’s, there’s good and bad out of it, Yeah.

 

Shawn Cordner (09:01.038)

It’s hard to see where things would have went without that. It certainly accelerated, but I think it was going that way anyway. mean, you always had some portion of your workforce that was on the road, right? Typically salespeople are out and about in their local territories. And then you had executives and people that might’ve been trainers, know, traveling throughout the country and those people always needed to be online. But like I said, I was working from home, I mean, probably a decade before COVID happened, right? So.

 

people were doing and I think it was, it was starting to increase businesses were seeing the benefits of letting employees at least have some flexibility, if not completely work from home. But this definitely, you know, set the world on fire and, and sped up that process. and I, know, as far as I know that the jury is still out as to whether or not this is a good thing for productivity for businesses. You hear a study come in and say that people are more productive and then you, you.

 

see a conflicting study the next week. Right. So I don’t know really where we stand there, but that’s the reality of where we are is it’s a ratchet effect, right? It, pushed us into this position and it’s really, really hard to go back. And you saw a lot of CEOs driving a back to office mandate and then kind of back from that. So that’s our new reality. And I, when we did a planning call here, I liked what you said. You said identity is the new edge. So unpack that for me.

 

Brian Zimmer (10:17.08)

Yeah.

 

Brian Zimmer (10:26.69)

think the premise here is that our identity, whether it be our, know, mainly our user persona, is the one thing that attackers want. And so what goes into that persona? That’s your logon credentials, your email, your password, your one-time password, your multi-factor authentication. We’ve seen that intercepted in a couple of attacks.

 

Once an attacker has that, can do a lot of, they can be profitable. Let’s speak that way. They can be profitable. The other thing, since we’re all business people here, when you look at these attacks on the identity, they are low cost. They are low cost, high reward. So if you are out there researching remote code execution, or God forbid you’re having to buy what we call a zero-day exploit, that

 

But those costs are astronomical compared to the low cost of user ID, password, et cetera. In conclusion, there are very few things that are cheaper and more effective than the user credentials and the user persona.

 

Shawn Cordner (11:42.536)

And this is a lot easier to scale now because of AI. So that’s going to be compounding the problem, right? Yeah.

 

Brian Zimmer (11:49.864)

I would say so, yes. And to paint the full picture, one of the use cases or one of the plays that AI can make for an attacker is it can scour forums and boards, and we’ll just say places where those things are held or stored or sold or brokered, et cetera. We use your verb. It can then quickly adapt to…

 

and implement passwords or a credential stuffing, et cetera. So it raises, raises the game because it takes something that is already low cost. Now it adds speed and the it in the sentence is AI. So I’ve got something that is low cost. Now I have AI, which is allowing me to attack an organization and get results quicker than I could 18 months ago.

 

And that’s where we as defenders, in my opinion, need to really level our game.

 

Shawn Cordner (12:52.77)

Yeah. And it allows them to, do more shots to, borrow from the, the hockey, conversation earlier at the same cost. Yes.

 

Brian Zimmer (13:05.602)

Yes. Yeah. Yeah. Shots on net shots on goal shots. Like take a shot, put something on net. Let’s see what happens. Let’s see. And, and here’s the thing. Here’s the way I like to talk to, to business leaders and my peers. It’s a really, it’s really about cost. Are you imposing cost on an attacker? Are you making them burn through time? Are they, making them burn through money? Are you making them.

 

burn through opportunity. What are you making them burn through stealth? Are you causing them to be noisy? What we want to do is impose cost on the attackers and we do that through a variety of controls, but I will get off on a tangent. So I’ll stop talking there.

 

Shawn Cordner (13:53.666)

think that’s a good tangent because I don’t often think about it in those terms. I think about it as blocking shots, but that makes sense if you just become a less desirable target or a cost effective or a target that is not as profitable, then they’re likely to move on to the next one. Is that what you’re saying?

 

Brian Zimmer (14:12.462)

Yeah. In, in essence, think the other, the other way I like to speak is time, especially with the swift implementation of AI as an, as an attacker. As an attacker’s tool, we’re seeing the, the time to take on what we call action on objectives, highly compressed. It’s highly compressed. So what we want to do is impose time costs.

 

And what that time does, it allows us as defenders, and again, I work for a managed detection and response firm, it allows us the time that we need to see, evaluate, eradicate, all around respond, and then evict that threat actor. We need that time. We need that noise from that attacker, because if they move fast and they move quietly,

 

We can’t see them. They’re operating in our infrastructure. They’re moving to action on objectives, which is the last stage of their attack.

 

Shawn Cordner (15:18.83)

So I’m going to keep talking in hockey analogy, but how does AI, how does AI now help you, you know, go where the puck is going to be rather than where the puck is.

 

Brian Zimmer (15:22.208)

Bye me.

 

Brian Zimmer (15:31.5)

Yeah, I think it’s there’s a couple of things in no particular order. It also gives us speed. It gives us speed. It allows us to have a level one analyst in an agentic workflow, constantly looking, constantly running. And for smaller organizations, that matters a lot. And that really helps them level up. The next thing is it reduces these esoteric high learning curve.

 

barrier to entry situations, meaning I’m going to get a sock analyst on day one and he’s going to use AI. is it, we want a sock analyst that knows what he or she is doing? Absolutely. Do we want them trained? Absolutely all that. But here’s one of the other advantages. I can, as a sock analyst, as a level one sock analyst, speak in plain English to my prompt.

 

So if I have Claude code, I’m in the system, hey, query Splunk, query S1, query Microsoft defender, query Sentinel. Now take into account, here’s the third thing I think, I think that’s what number I’m on. Let’s take into account enrichments. So where am I vulnerable? I’ll give you an example that that’s sort of thematically related. Take a look at this credential involved in this suspicious behavior.

 

Now query all of my intelligence, including in open source intelligence. Is this user in a password breach? Is he on, is he or she on, have I been pwned? Have her credentials been compromised? Let’s use that as an enrichment with that information. I can move much quicker than I could even two years ago.

 

Shawn Cordner (17:22.114)

Yeah.

 

Brian Zimmer (17:22.71)

So those are three just quick elements. Forget about orchestration, forget about automation, which, you know, we had SOAR tools going back a decade. Where we are now with AI underpinning and driving a lot of our SOAR capabilities is far advanced from where we were way back then.

 

Shawn Cordner (17:43.916)

Yeah, it’s incredible how quickly things are moving. And I want to go back to the user issue because you know, we’re talking about identity and we’re talking about it in terms of users, but, this is where AI is going to come back up into the conversation. But, a user is not just a human, right? Or identity is not just a human, but we’ve got identity of machines and devices and we’ve got browsers and now we’ve got AI agents. So talk to me a little bit about how that.

 

adds a little complexity to the issue of authentication.

 

Brian Zimmer (18:16.928)

It always has been a complex environment and an environment that is shifting. But now again, it’s just faster, broader. What I mean by broader is if you, if you’re of a certain age, you could remember service accounts or daemons that machine that would run as the machine, cron jobs, et cetera. We are well past that era.

 

these non-machine identities, APIs, secret keys, they are everywhere. And we still, as an industry struggle with the basics, like managing a CMDB, you know, what are my assets, who owns them, what’s the IP? Then we struggle with managing vulnerabilities. How in the world are we going to effectively manage these machine identities? The secrets management, APIs, et cetera, is at the forefront.

 

of a strong identity governance program. And a lot of organizations continue to struggle. And this is not me with the Judge Malatang. Like I said, the attack surface, the situation is broad. And getting a smaller regional hospital in Nebraska or Oklahoma, just, you know, picking places to successfully manage that in the face of attackers, that’s a tall task.

 

Shawn Cordner (19:40.802)

How do they do it? How do you set up proper governance and what is the risk of bad governance?

 

Brian Zimmer (19:45.836)

Well, let’s talk about good governance. know, good governance names, it names them. First of all, good governance exists. And a lot of organizations simply don’t do data governance and they don’t do identity governance. And data governance is a topic for another time, probably. But identity governance in a lot of organizations doesn’t exist. It’s the what, the why, the who, the policies, the standards, that framework, that reporting.

 

The driving of separations, separation of duties, privilege management, auditability. I mentioned reporting, but also data visualization. So that’s the what it is. And in just mentioning that, you can see why organizations would struggle to do that because they’re just, going from one problem to another and building that it’s a big task. Now there are platforms like Okta. I don’t work for Okta. I’m not partnered with Okta.

 

Okta is one I’ve implemented Okta in the past. It was wildly successful, but you still need to have the policies, the procedures and the oversight to set up that good governance. So I’ll pause there and then let you steer me appropriately.

 

Shawn Cordner (20:55.95)

Well, let’s take a second and talk about what Okta is. I know it at a high level, but it’s basically an identity management single sign on platform, right? I’m sure I’m oversimplifying that by miles and miles, right? But what else can you tell the audience about that or similar type of platforms and the role that it plays?

 

Brian Zimmer (21:14.584)

will, I will, since you did a good job of setting it up and explaining it high level, I’ll do, I’ll, I’ll tackle what its role is because its role is so, so important compared to, and it’s a huge step in where, where we are now compared to years ago. In essence, what it allows you to do is have one identity, one identity that logs into your ERP, one identity, one password that logs into your

 

book or your Google mail. It simplifies the experience for the user so that the user is not writing down passwords, writing down user accounts in a spreadsheet. That’s what we don’t want. The other thing that it does, it relieves the burden on the organization and allows the user to self-help. So do a password reset.

 

manage their credentials, manage their entitlements. They can open up a request that says, Hey, I don’t have access to system. Why please grant that to me. And it can be a whole lot faster when you reduce that friction as a security person. My position is you make a user a lot happier and you prevent them from having to write down their passwords, write down their usernames, write down all of their keys and their

 

It allows us to have one thing and one place that greases the skid, so to speak, for a better user experience, but better doesn’t mean less secure. That’s what I love about these like Entra, for example, from Microsoft. It allows us to make a much easier user experience, but a much more secure user experience.

 

Shawn Cordner (23:00.644)

How is it different from something like LastPass, or is it?

 

Brian Zimmer (23:03.662)

So this is a different topic and one that I’m really excited about. LastPass, one password, I use another one. Beekeeper is what I’ve seen organizations use, Dashlane. These password managers are fantastic. They allow something very similar for you to have a secure vault, which is protected by a longer, let’s say, passphrase, usually a key or some stronger, I’d, I’d,

 

authorization, authentication and authorization. And it allows you to again, remember one as opposed to multiple writing them down, storing them someplace insecure, insecurely. also allows you to have that ability to do it everywhere. So they are related, but I would say they’re complimentary technology. So you could use BeatKeeper with your, your identity management, your single sign on platform, and they should be integrated.

 

Shawn Cordner (24:02.548)

Here’s the multi-billion dollar question. When are we going to have some sort of centralized blockchain driven identity that allows me to just log in because it knows it’s

 

Brian Zimmer (24:15.094)

me think, I think we’re getting dangerously close. We’re getting dangerously close to two things. Number one, that user experience, that technology, but we’re also getting dangerously close to outside of my area of expertise. So it’s two things, but I think with a lot of the protocols that exist web auth and for example, we have secure keys now.

 

I think we’re getting dangerously close and the, to be overly positive, but we are a lot further along and a lot more secure in this realm than we were a couple of years ago. think organizations have made a lot of strides. know, I think most organizations have now implemented across the board, one-time passwords, two-factor authentication, multi-factor.

 

sometimes Yuba keys, cetera, et cetera, card authentication like they do in the military. So we’re a lot further along than, that we were years ago and for the better.

 

Shawn Cordner (25:22.542)

We are and we aren’t right. It’s, still such a, fractured and siloed experience. And I’m going to rant for it. So just indulge me. But just this week, right. I, I was locked out of Outlook and Teams for 12 hours. And it was because something happened on the backend and it logged me out and forced me to reregister the machine. And then when I started going through the process that Microsoft was prompting me through.

 

It just kept taking me to a dead end. And it was this, this circular process of this, this, that, and then dead end and then exhale. And then it pops up again. And then I have to do that again. And this went on and on and on. And then eventually the pop-up window itself would unload and it just was spinning. And so then I had to restart the computer because that’s always what you do. And then finally I got worked out, but, but also.

 

Just this morning I was logging into a portal and it requires the two factor authentication. then it also wants, so it wants my password first. Well, I have a passkey set up, but is it the Apple passkey where sometimes it pops up on my iPhone and I have to validate it or authenticate it on my iPhone? Or is it the Google Chrome passkey? I don’t even know. And so the password that popped up was wrong. So I had to figure out where that was going. And then I had the

 

change the password in there and then I had to get logged in and then I had to do the two factor. This one goes to my email. Sometimes they go to my text messages. Sometimes I can’t get in at all and I got to call customer service. So moral of this story and what I’m trying to get at here is there’s a lot of friction because of security and I understand how necessary it is, but what is the cost of all of this friction to the economy in general, to enterprises specifically as they, you

 

create barriers to bad guys getting in, but also to their employees getting in as well. And is there room or at least is there a movement, hopefully coming, of human centered design insecurity?

 

Brian Zimmer (27:29.654)

Man, I love the setup. love the rant. I think we can all agree with it. I think we’ve all been there. I think it highlights a couple of things. Number one, it just accentuates this topic of friction. Ease of use. you… Okay, I’m a security guy. If I impose friction, I have to understand what the results of that friction are. And from an engineering perspective, have we created a desire law?

 

Desire line is you’ll see a sidewalk and then you’ll see a path. So for those of you that don’t know, that’s a desire line. A desire line is what the user of the system has decided is the place to go, is the path. You designed it one way, the user has said, I’m going to use it a different way. I think we are getting better at identifying desire lines. I think we are getting better at understanding user behavior.

 

And I think this goes back to exactly what I said at the beginning. I think we were getting better at listening in the boardroom, conveying these concepts in the boardroom and building solutions that minimize friction to our users, but maximize friction to the attackers. Are we there yet? No. Will we ever be there? No. I don’t know, but I know we’re held a lot farther along than we were. And I think.

 

You know, it’s, it’s what do you, what do you, what do you do when you’re in a hole? You stop digging. I think we’ve stopped digging. I really do. I think we are much more attuned, much more attentive to the risks as well as the operational friction we put on our admins and our users. And especially in the identity space.

 

Shawn Cordner (29:16.994)

Yeah, we in marketing, we talk about user experience and user interface design and they go together. Right. So I mentioned it a few times on this podcast, but I don’t think I’ve ever really got into what it is. What it is is using data about users and their behaviors and doing stakeholder interviews to understand, know, intent and designing an information architecture and then a user journey that gives the user affordances.

 

to find what it is that they’re looking for in an intuitive way and lead them down a path that allows them to achieve their goal, but also achieve the goal that we as the enterprise designing the website have for them. Right. So, it’s all about using design and design cues to leave a breadcrumb trail to get people to do what you want them to do. And hopefully

 

What you want them to do is also correlated with what they want to do. so then everybody’s happy, right? That’s good user experience design. And then when you design those paths, you have to then create the interface to match the paths and give them those affordances so that they can find their way around. So it’s very well established that you can influence behavior with design. We see it in CX now where people are intentionally designing customer experiences or patient experiences in healthcare.

 

Where they’re giving them a path or a journey to accomplish what they need to accomplish, but also accomplish what the enterprise wants them to accomplish and have a good experience while doing it. so what I’m trying to get at with this is people are an enterprise’s biggest risk because we have cognitive biases, because we get fatigued of doing things that we have to do that are overly complex because we’re always seeking out shortcuts.

 

It’s just how our brains work. just evolved to be that way and you can’t fight human nature. So if you want better compliance, I feel like the best thing that you can do, and I mean security compliance, is to reduce that friction. And that will ultimately lead to them doing what you need them to do in order to be safe and secure, but also increase or at least reduce the impact to productivity.

 

Brian Zimmer (31:34.958)

here and let’s turn over some new ground. There’s another user community that we haven’t tackled and that’s the admin community and the developer community. So we talked about our end users. Your scenario applies to them, but your scenario also applies to admins, developers, et cetera. And if we’re going to, again, stay thematically congruent, that’s my SAT phrase for the day. mom would be very proud of me, apparently. Big, big.

 

Polysyllabic words. So, privilege access management, privileged identity management, secrets management. I think that is, that’s another area where we, we have identified a high risk, the user, the admin, and we’ve introduced attacker friction and we’ve tried to minimize the friction for that user. So we’re automatic, we’re automatically updating secrets.

 

We are scanning our infrastructure for them. We’re rotating keys. We are providing temporary root access, temporary admin access, or maybe even a step down as appropriate for those users. Those users being admins, developers, et cetera. So that’s another completely different user base where the identity is the edge because what better person, if you’re an attacker,

 

to go after than a developer who has access to important keys. What better person to go after than an admin? What better person to go after than an admin who left the organization eight months ago and you didn’t disable his or her access and she still has it up and running. And I can’t remember what attack used that. And I don’t know if it was Snowflake and maybe Snowflake, the Snowflake compromise used an older user account, but

 

And those scenarios are not hypothetical. Those are happening in the here and the now.

 

Shawn Cordner (33:37.77)

Yeah, I guess the challenge with all this is being intentional, right? And if you’re a lean IT team that’s got a lot of things that they have to cover, are you ever going to really be able to step back and say, Hey, let’s reimagine the security experience that our users, because I feel like I’ve certainly never sat on the other side of this conversation as a CISO, right? But I feel like what happens is there’s, end up with an ad hoc

 

defense posture. It’s, we need to do this. Okay, now we need to go do this and now we need to go do this. this thing’s not working with this thing. so when can you actually sit back and say, let’s look at this holistically and let’s intentionally design how our users and the outside world are going to interact with our network and our digital properties.

 

Brian Zimmer (34:29.09)

That’s, that’s a tough one. So the boilerplate answers are when the project begins, when the new CISO comes in, when there is some sort of event that drives the ability for the organization to take a breath and to do that. I think the other major event is probably the adoption or recertification of

 

and vis-a-vis a framework like ISO, like the CIS top 18 controls. I think you have to look for those events in order to spot the time, the right time to do that. But that is a tough question. And the CISO’s role and the CIO’s role, because remember we’re talking about identity governance and data governance, although we said we were going put that aside, which have security elements, but they are not security per se.

 

So it’s a CIO, CISO activity and it is a fight worth having, but you know, from the cheap CIS, we need to be careful about saying, well, they should have just, they should have just done it. Well, they’re doing other things, right? So I think it’s spotting the right time. I think I listed four potentially right times to rehab that conversation. And I think those are, those are.

 

Shawn Cordner (35:52.588)

Yeah, it seems like, at least what you could be doing is as you’re making decisions on new technologies that need to be implemented or new vendors that you need to bring in thinking about that experience and how it’s going to work with the other security measures that you have in place that are user facing and impact them or end user facing.

 

Brian Zimmer (36:14.892)

Yeah.

 

Shawn Cordner (36:17.442)

Let’s run it all the way back for a second because I want to get back to talking about AI agents and their identities. So a question that I’ve asked a few times on this podcast, and I feel like it’s, it’s yet to be answered head on, but I want to pose to you is are we approaching a time where businesses need to start thinking about HR for AI agents? And what I mean by that is an AI agent is for all intents and purposes an employee, right?

 

upsides to it where you don’t have to pay them and you don’t have to manage vacation and you don’t have to deal with their medical issues and whatever. But what you do have to deal with still is their role, their org chart, where they kind of fit in the organization, who owns them, who’s accountable for them, what data and applications do they have access to, who’s onboarding them and how do you onboard them.

 

Who’s training them and how do you continue to train them? How do you manage and govern them? And what about conflict resolution? Because one AI agent could certainly be conflicting with another AI agent. so who wins? So that’s why I’m calling it HR for AI, not to be confused with AI for HR. What are your thoughts on this? Like, how do you go about approaching these, looking at it through the lens of identity management?

 

Brian Zimmer (37:38.542)

Well, first of all, I think you’re right. I think the premise is right. I think the premise is sound. I think there’s probably a handful of people, well, let me say many more people that are more qualified than me. Here’s what I would say, AI governance in and of itself, just like data governance, identity governance, corporate governance, has to be something that as a CIO and definitely a CISO, you did yesterday.

 

When’s the best time to plant a tree? 20 years ago. When’s the second best time to plant a tree? Right now. So begin that task. I think there are other really, really crucial overlaps that you highlighted. Number one, identity governance. The identity governance pursuant to an AI identity is a thing and it should be governed under your AI governance policy or your corporate governance.

 

That is a task that must be done. Data governance is what does AI crave? It craves data. That’s how it drives its decision-making. So the data governance is really important. I can say, parenthetically, I did data protection and privacy at E plus for a couple of years. Organizations are woefully unprepared.

 

for AI because they’re woefully unprepared and they were a decade ago for data governance. So now we’ve got AI governance, corporate governance, identity governance, data governance. All of those things are woven together in a Venn diagram. I agree with you that conflict resolution is really relevant. I agree. It is a thing. An agent or a user’s usage of a model.

 

There’s two separate things. They could be in opposition. How do we sort it out? How do we resolve that conflict? I agree with you. I don’t have a hard and fast answer, but I think it is an HR issue in some respects or a quasi HR issue, right? We’re not going to get somebody from HR to feel a complaint that someone’s model did X or agent did XYZ, but we are going to have this

 

Brian Zimmer (40:01.582)

quasi resolution or HR resolution. There was another thing that, that I, will throw two shout outs that are really important. Number one, Daniel Niesler has been doing a ton of work on this topic. Recommend viewers, listeners go check out Daniel’s work. More immediately, Dan Guigo presented, this was a couple of weeks ago, I think on how his company trail of bits. They do phenomenal work. He has been.

 

such a positive influence and leader in this industry for two decades now. Go watch his talk. He shows how they took Trail of Bits to being really an AI first organization and what their methodology was. Highly recommend it. You probably get more out of listening to Dan than you ever would listening to me. I can guarantee that. So those are my two action items for the viewers and the listeners.

 

Shawn Cordner (40:58.222)

Got it. We’ll, uh, we’ll put it in the show notes. We’ve never had show notes before, but now it seems like we need them. So we’ll put them in there. That’s, that’s, what all the podcast hosts say is it’ll be in the show notes. I don’t even know what that means yet, but we’re cool at all. So yeah, like, you know, it seems like I’m calling it. HR for AI and it does seem like it needs to.

 

Brian Zimmer (41:05.388)

You’re welcome, everybody.

 

Brian Zimmer (41:10.06)

he’ll be in the show

 

Shawn Cordner (41:23.704)

fit into HR in some way, at least from an org chart and responsibility and like role perspective, right? Because when you’re, when you’re looking at the organization and you need to understand who roles to what, and that’s for decision making and that’s for accountability. so these agents ultimately are going to, I mean, there’s a risk of them making huge mistakes. And so you need to know what, there’s gotta be an audit trail back to who is, is running the show for each one of these agents.

 

who’s using them and what are they using them for? Are they using them the way they’re supposed to be, right?

 

Brian Zimmer (41:57.998)

But they… And this is where we might actually delightfully come across a slight disagreement. Humans make mistakes and they make them at a much greater rate and a much greater pace. And sometimes with as big consequences or bigger. I shut down an entire time zone at Bank of America because I made a group policy push. You’re welcome. Thanks everybody. So I think we need to be… And Dan actually gets into this in his talk.

 

about our tolerance for mistakes and our tolerance as we grow and we foster the symbiotic relationship between our AI tooling and us as carbon-based life forms and our knowledge, skills, and abilities. The thing that Dan does in his talk that’s so great is he talks about how you’re taking a user and you’re enhancing that user. You’re enhancing it for the betterment of the company, the betterment…

 

of the customer and a betterment of that user and that user’s role. And let’s hover over that for a second because the user and the company are not the same thing. They’re able to take skill sets in cloud or in an anthropic and share them. They’re able to take functions and share them across the organization. The other place where I would maybe slightly disagree with you, you you’re talking in HR for AI.

 

So I think that function has to exist in AI governance. don’t think it’s HR proper. I don’t mean to say that that’s your argument, but I think it goes back to governance. here’s another example. Organizations have forever struggled with DLP, data loss prevention. Data loss prevention is part and parcel to a strong data governance program. Do we want people…

 

exfilling data, do we want them misusing it? Do we want them, are we going to allow them to make mistakes? What guardrails are we going to put in place? Well, that also applies to AI. It’s almost a one-to-one replacement in, in, maybe not replacement, but there is correlation between what we would do in a strong data governance, strong DLP program and strong AI governance and the guardrails that we would put on it.

 

Brian Zimmer (44:20.587)

in an organization.

 

Shawn Cordner (44:21.752)

So a few responses. Number one is we don’t allow disagreement with me on this podcast. So.

 

Brian Zimmer (44:27.064)

You’re firm and fair.

 

Shawn Cordner (44:29.038)

The second thing is, yeah, I certainly wasn’t saying HR owns the agents, right? But I do think that the agents would probably be reflected in HR just in the sense that, you know, if one of my employees is doing something and someone has to question it or there’s an accountability issue there, they’re going to come to me. Are they going to go to IT? Like I know IT is ultimately owning all these agents, right? But I guess it also depends on how these agents are deployed. And I don’t know how enterprises

 

How much autonomy people are having in enterprises. Like right now, I know there’s a lot, there’s a shadow AI problem, right? Like I could have an agent running right now that nobody in my business knows about. the future, maybe it’s on the map, but maybe I’m still able to create agents within a certain box that I’ve been allowed to do. Right. So I don’t know. I guess I’m just saying like from a mapping perspective, there needs to be some visibility in the organization, not just in the IT department for

 

Brian Zimmer (45:19.918)

from

 

Shawn Cordner (45:27.106)

Who rolls to or what rolls to who I guess. Yeah, I say it.

 

Brian Zimmer (45:32.27)

I agree with you 100%. And I think, I think the more we flush this out, think about what the ultimate goal of a DLP program is. DLP says this user or this user persona or this profile or this system account, whatever it is, did this to this data element at this time. This is the action that we took. We blocked it. We quarantined it. We allowed it, but notified.

 

What we need to wrap our heads around is the governance, which is lacking. You nailed it. We have a huge shadow problem, but we had shadow cloud, right? We shadow IT. We’re used to this. We know how to do this. Our muscle memory is there. What needs to be built in my estimation is the response action. And again, I see to a man with a hammer, everything is a nail.

 

I see things coming from a monitoring and response perspective where I want to know what that user, what that agent did to that data at what time, what response action do I take? This is why I come back to agreeing with you. That does look like an HR motion. User, you may not take protected information and drop it in your instance of OpenAI.

 

We have purchased Claude for that reason and wrapped guardrails around it. I noticed you did it. I stopped it. I have intervened with a strong talking to. That’s the HR motion that you’re talking about. And that element, you are a hundred percent.

 

Shawn Cordner (47:17.388)

Yeah, I don’t think Melanie from HR, and this is now her second shout out on this podcast, which is odd, but Melanie from HR is not going to be spinning up agents and training them and onboarding them. Like I get that. But, but yes, as it pertains to how humans in the business are interacting with them and who’s accountable for their actions, maybe, maybe to some extent. But anyway, the more interesting thing that, that I thought that you brought up there was you’re right about mistakes, right? So we, do.

 

put an outsized focus on the potential mistakes that AI can make compared to the mistakes that human beings make. mean, we see it with driverless driving and radiology and like there’s a million examples of AI outperforming humans in terms of error rate, right? But I think it’s because we are prediction machines, right? Like that’s how our brain works is we’re running multiple prediction models at one time. And then we kind of land on which

 

is the best prediction, the most likely prediction, but we’ve had our whole lives to have experience with human beings. And so we’re better at predicting because we have better priors in the prediction models where, there’s more data, right? Whereas this AI thing is so new to us that we just, don’t have the data to draw from and humans are, we’re bad with statistics. mean, it’s just, it’s how it is, right? Like we don’t really think.

 

Statistically, there’s always base rate neglect and all these other biases and mistakes that we make. So I think what you’re seeing here is a human physiology, a human neurology that has evolved for hundreds of thousands, millions of years without AI. And we just haven’t been able to kind of catch up to the new paradigm.

 

Brian Zimmer (49:08.27)

Oh, a hundred percent. Yeah. but, know, in, and I understand the stress, um, that a lot of folks feel I, I’m not so doom and gloom. I’m not so, I’m not giving into the hyperbole. Um, I think there are, I think the future is very bright. I think it’s going to, you talk about the, you know, we mentioned the word paradigm, the paradigm will shift drastically.

 

It’ll shift in the SOC. It will shift in the accounting office. It will shift in the GRC, the governance risk and compliance function. There’s it. But those are good things in my estimation. I saw a thing on Twitter a decade ago when it was called Twitter. Somebody said, you know, look at this picture. You got a bunch of guys sitting around with slide rules and calculators. This room right here is a spreadsheet. I think we’re in those times right now.

 

with air.

 

Shawn Cordner (50:08.364)

Yeah, I agree. So let’s bring it home. Let’s get into some practical advice for people that want to start to operate with this identity is the new edge philosophy. So what are steps one and two for the technology leaders listening to this?

 

Brian Zimmer (50:24.342)

Yeah. think, I think recognize, number one, recognize its importance. Understand where it factors into an attacker’s mindset. And the answer that we already gave.

 

Shawn Cordner (50:39.811)

first.

 

Brian Zimmer (50:41.258)

It is the edge that is your crown jewels. Those are your crown jewels. So except reality, let’s start there. Number two, assess your governance program. Does it exist? What does it look like? How do you manage what we call joiners, movers, adders, leavers? Are you doing it in a programmatic way? Have you established the what, the why, the who, policies, the standards, et cetera? Next.

 

Assess and tackle authentication and authorization. Those are not the same things as a business leader, as a security leader, separate them out. Authentication, who are you? Authorization, what are you allowed to do? Look at your protocols. Are your protocols for authentication and authorization strong? Are they defensive? Identity management, different from governance. It’s a sub-subparticle, sub-particle, sub-part, I don’t know.

 

Again, back to those joiners, movers, adders, leavers, user identities, machine identities, and access control. The other thing that always goes mistaken or that goes overlooked is certificate management. Certificate management is huge in identity management and data management. lot of business leaders overlook certificates. Certificates are how we identify and authorize

 

users and machines. And then maybe the last part would be privilege access management, privilege identity management. Most organizations are, have rolled out a cyber org. They’ve rolled out a delinia. They’ve rolled out the other tools and products that manage those things. Those are really frontline tools now, if you accept.

 

our premise that identity is the new edge. And I guess the last thing I would throw in there is password managers. You and I talked about it earlier. It is time. We are well past time where you can, as a CIO and as a CSO, you can vouch for it. You can roll out a password manager to your users and it will be successful. And you can rest assured when you’re rolling out Okta, for example.

 

Brian Zimmer (53:02.7)

you’re rolling out Beekeeper, Dashlane, et cetera, that it will be successful and that you will actually minimize user friction and that by doing that, you will increase your security outcome.

 

Shawn Cordner (53:16.096)

And then anytime you introduce an intervention, people on video saw my dog just make an appearance again. She does that from time to time.

 

Brian Zimmer (53:23.502)

Talk about a leftover from COVID. I embrace it. I embrace it.

 

Shawn Cordner (53:27.406)

Exactly. So anytime you introduce any kind of intervention, there’s the potential for unintended consequences. is there anything that you can predict that could potentially become a challenge because of this change?

 

Brian Zimmer (53:43.596)

more of a CIO question. I would, I will like water go around that boulder and say all of these OEMs and all of these solutions allow you a nice slow ramp up and a demo period, a proof of concept period. My former CEO, Doug King at E +, he’s now moved on to another organization and they’re lucky to have him.

 

very, very slowly, methodically, in a time-bound and metric-driven way, rolled out Okta to our organization. It was seamless. It was seamless. Why? Because Doug knew what he was doing. Okta knew what he was doing. Mark Pelleccio and all the other players in that organization knew what they were doing and knew how to sort out those issues.

 

during that slow and deliberate rollout. But again, like, go ahead.

 

Shawn Cordner (54:47.694)

The takeaway sounds like folks on change management and as former guest Gary Sorrentino from Zoom said, human change management.

 

Brian Zimmer (54:56.716)

Yes. Yes. And communicating constantly with your users, especially your admins, because those, you know, they’re sitting on all the privileged accounts. They’re sitting on all of the secrets management. There’s one more element that we didn’t mention. If you, the user, accept Brian and Shawn’s premise that identity is the new edge, and you accept Sunil Yu’s premise that we have entered into the age of

 

of recovery and his architecture, the DIA architecture, distributed, immutable, ephemeral, big fan of it. If you accept all of this, what’s the one thing that you have to be doing? You have to be monitoring and you have to have the ability to respond to user-based attacks. So Shawn, you mentioned training up users, spot fishing, doing user awareness training. We all do that. That’s great. But on the flip side.

 

as SOC responders, as people that run a SOC and respond, reporting, monitoring, and response to user-based attacks and incidents is key. It’s not shutting a firewall port anymore. It’s not closing, it’s not isolating the machine. It’s responding to the user identity at the identity layer.

 

at the identity governance layer.

 

Shawn Cordner (56:28.622)

That makes sense. Last question, aside from what we talked about today, what’s something that you wish more CISOs were thinking about or talking about in this space?

 

Brian Zimmer (56:37.762)

Yeah, I think it’s, I think it’s true identity governance and minimizing friction and doing it because we are going to achieve achieve a more secure outcome in that minimization of friction to the user, imposing friction to the attacker. And that gets us where we want to be. But identity governance and also data governance is not a security topic.

 

It’s not, but it has whopping and massive security implications. so CISOs really need to, if they already don’t have a seat at the table, which I would find highly unlikely, then they need to push themselves in like a 13 year old at Thanksgiving who says, Doug, I need to be at the adults table. Been there. I was summarily dismissed from the adults table, but you know, fear CISO.

 

Yeah, you’ve got to push your way into that conversation because it is essential.

 

Shawn Cordner (57:42.44)

Hopefully you have a seat at the adults table at least at Thanksgiving.

 

Brian Zimmer (57:46.158)

Duck on it, I’ve earned it.

 

Shawn Cordner (57:47.598)

All right, Brian Zimmer, thank you so much for your time and expertise.

 

Brian Zimmer (57:50.798)

You’re very welcome.

 

Show more...