#382 - Sponsor Spotlight - HYPR

#382 - Sponsor Spotlight - HYPR

This episode is sponsored by HYPR. Visit hypr.com/idac to learn more.

In this episode from Authenticate 2025, Jim McDonald and Jeff Steadman are joined by Bojan Simic, Co-Founder and CEO of HYPR, for a sponsored discussion on the evolving landscape of identity and security.

Bojan shares his journey from software engineer to cybersecurity leader and dives into the core mission of HYPR: providing fast, consistent, and secure identity controls that complement existing investments. The conversation explores the major themes from the conference, including the push for passkey adoption at scale and the challenge of securely authenticating AI agents.

A key focus of the discussion is the concept of "Know Your Employee" (KYE) in a continuous manner, a critical strategy for today's remote and hybrid workforces. Bojan explains how the old paradigm of one-time verification is failing, especially in the face of sophisticated, AI-powered social engineering attacks like those used by Scattered Spider. They discuss the issue of "identity sprawl" across multiple IDPs and why consolidation isn't always the answer. Instead, Bojan advocates for a flexible, best-of-breed approach that provides a consistent authentication experience and leverages existing security tools.


Connect with Bojan: https://www.linkedin.com/in/bojansimic/

Learn more about HYPR: https://www.hypr.com/idac


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at idacpodcast.com


Chapter Timestamps:

00:00 - Introduction at Authenticate 2025

00:23 - Sponsored Episode Welcome: Bojan Simic, CEO of HYPR

01:11 - How Bojan Simic Got into Identity and Cybersecurity

02:10 - The Elevator Pitch for HYPR

04:03 - The Buzz at Authenticate 2025: Passkeys and Securing AI Agents

05:29 - The Trend of Continuous "Know Your Employee" (KYE)

07:33 - Is Your MFA Program Enough Anymore?

09:44 - Hackers Don't Break In, They Log In: The Scattered Spider Threat

11:19 - How AI is Scaling Social Engineering Attacks Globally

13:08 - When a Breach Happens, Who's on the Hook? IT, Security, or HR?

16:23 - What is the Right Solution for Identity Practitioners?

17:05 - The Critical Role of Internal Marketing for Technology Adoption

22:27 - The Problem with Identity Sprawl and the Fallacy of IDP Consolidation

25:47 - When is it Time to Move On From Your Existing Identity Tools?

28:16 - The Role of Document-Based Identity Verification in the Enterprise

32:31 - What Makes HYPR's Approach Unique?

35:33 - How Do You Measure the Success of an Identity Solution?

36:39 - HYPR's Philosophy: Never Leave a User Stranded

39:00 - Authentication as a Tier Zero, Always-On Capability

40:05 - Is Identity Part of Your Disaster Recovery Plan?

41:36 - From the Ring to the C-Suite: Bojan's Past as a Competitive Boxer

47:03 - How to Learn More About HYPR


Keywords:

IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Bojan Simic, HYPR, Passkeys, Know Your Employee, KYE, Continuous Identity, Identity Verification, Authenticate 2025, Phishing Resistant, Social Engineering, Scattered Spider, AI Security, Identity Sprawl, Passwordless Authentication, FIDO, MFA, IDP Consolidation, Zero Trust, Cybersecurity, IAM, Identity and Access Management, Enterprise Security

Jaksot(392)

Identity at the Center #56 - What is FIDO with Andrew Shikiar

Identity at the Center #56 - What is FIDO with Andrew Shikiar

Jim and Jeff talk with Andrew Shikiar, Executive Director and Chief Marketing Officer of the FIDO Alliance, about what FIDO is and the challenges it seeks to solve. FIDO Alliance website: https://fidoalliance.org FIDO paper: https://fidoalliance.org/white-paper-cxo-explanation-why-use-fido-for-passwordless-employee-logins/ Authenticate 2020 conference (free!): https://authenticatecon.com/ Krisp.AI is the microphone noise reduction software mentioned on the show. They are not a sponsor of the show, but a software we like. You can learn more at https://krisp.ai/ or you can use Jeff's referral link to get a free extra month of pro by clicking here: https://ref.krisp.ai/u/u5dc480464 Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

10 Elo 202046min

Identity at the Center #55 - Solving Identity Challenges with MFA

Identity at the Center #55 - Solving Identity Challenges with MFA

Jim and Jeff talk about the challenges of multifactor authentication and solving some of the unique challenges that come with it. A Security Update From Instacart: https://news.instacart.com/a-security-update-from-instacart-89beb7bf5121 NIST 800-63-3 and Levels of Assurance: https://pages.nist.gov/800-63-3/sp800-63-3.html Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcaston Twitter.

3 Elo 202049min

Identity at the Center #54 - Mark Perry on Open Banking

Identity at the Center #54 - Mark Perry on Open Banking

Jim and Jeff talk with Mark Perry, CTO for Ping Identity APAC region, about his Identiverse talks around the user experience with IAM and the Open Banking Standard. Connect with Mark on LinkedIn here: https://www.linkedin.com/in/markperryau/ Mark's Identiverse Talks: https://portal.inxpo.com/ID/PingIdentity/IdentiverseVirtual/ June 15th - Stop Blaming the End User! Using Empathy and Understanding to Deliver Better Identity Experiences. July 28th - Will User Experience Kill Open Banking? Learn more about the Open Banking Standard here: https://standards.openbanking.org.uk/ Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

27 Heinä 202042min

Identity at the Center #53 - Twitter, MGM, and ITSM IGA with Darran Rolls

Identity at the Center #53 - Twitter, MGM, and ITSM IGA with Darran Rolls

Jim and Jeff talk with Darran Rolls, former CTO and CISO at SailPoint and current "Identity Dude" about the recent Twitter breach, the new revelations as to the scope of the MGM data leak, and how ITSM is positioned as a platform to build IGA services on. Visit Darran on the web here: https://darranrolls.com/ Connect with Darran on LinkedIn here: https://www.linkedin.com/in/darran-rolls-068b84 Get Darran’s book here: https://darranrolls.com/general/identity-attack-vectors/ Twitter Breach: https://www.chicagotribune.com/business/ct-biz-twitter-bitcoin-hack-cybersecurity-20200716-frecqlxiczf7nipn7yiwrv6uz4-story.html MGM incident update: https://www.zdnet.com/article/a-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web/ Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

20 Heinä 202056min

Identity at the Center #52 - Jackson Shaw, IAM Jedi

Identity at the Center #52 - Jackson Shaw, IAM Jedi

Jim and Jeff talk with an IAM Knight of the Old Republic, Jackson Shaw, about his 36 years in the IAM space, some of his observations over the years, and the intersection of IT Service Management (ITSM) platforms and Identity Governance & Administration (IGA) technologies. Connect with Jackson on LinkedIn here: https://www.linkedin.com/in/jshaw Follow Jackson on Twitter @JacksonShaw "Jackson’s List of Things About IAM"™ (Working Title): Conferences & Organizations: Martin Kuppinger & KuppingerCole – Their conferences (identity, CIAM, security) and YouTube channel – www.kuppingercole.com Gary Rowe & Techvision Research - https://techvisionresearch.com/ Gartner – www.gartner.com Forrester – www.forrester.com Identiverse conference – www.identiverse.com IDPro – www.idpro.com Books: Powerful, Patty McCord Death by Meeting, Patrick Lencioni Steve Jobs, Walter Isaacson Surrounded by Idiots, Thomas Erikson Power Presentations, Jerry Weissman & his website www.besuasive.com Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

13 Heinä 202054min

Identity at the Center #51 - Insider Threat with Phil from Preempt

Identity at the Center #51 - Insider Threat with Phil from Preempt

Jim, Jeff, and special guest Phil Meneses from Preempt Security talk about insider threat and an upcoming report that Preempt is releasing about the hidden risks of workforce identities. Click here to access the Preempt Whitepaper "2020 Identity Risk Infographic": https://www.preempt.com/white-paper/2020-identity-risk-infographic/ Visit Preempt Security here: https://www.preempt.com/identity-information-detect-threats/ Connect with Phil on LinkedIn here: https://www.linkedin.com/in/philmeneses/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

6 Heinä 202041min

Identity at the Center #50 - It's Our Birthday!

Identity at the Center #50 - It's Our Birthday!

Jim and Jeff talk almost nothing about IAM and instead reflect on the show turning 1, some of their favorite episodes from the first year, a new show website, and what to expect in the future of the podcast. Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

29 Kesä 202034min

Identity at the Center #49 - Role Mining Lessons Learned

Identity at the Center #49 - Role Mining Lessons Learned

Jim and Jeff talk with IAM Architect and fellow Identropian Helio Gomez about the lessons they have all learned when it comes to role mining and engineering. Thanks to listener Andrew C. for the topic suggestion! Connect with Helio here: https://www.linkedin.com/in/helio-gomez-1507765/ Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Email the show at questions@identityatthecenter.com or send us a message on LinkedIn.

22 Kesä 202042min