#382 - Sponsor Spotlight - HYPR

#382 - Sponsor Spotlight - HYPR

This episode is sponsored by HYPR. Visit hypr.com/idac to learn more.

In this episode from Authenticate 2025, Jim McDonald and Jeff Steadman are joined by Bojan Simic, Co-Founder and CEO of HYPR, for a sponsored discussion on the evolving landscape of identity and security.

Bojan shares his journey from software engineer to cybersecurity leader and dives into the core mission of HYPR: providing fast, consistent, and secure identity controls that complement existing investments. The conversation explores the major themes from the conference, including the push for passkey adoption at scale and the challenge of securely authenticating AI agents.

A key focus of the discussion is the concept of "Know Your Employee" (KYE) in a continuous manner, a critical strategy for today's remote and hybrid workforces. Bojan explains how the old paradigm of one-time verification is failing, especially in the face of sophisticated, AI-powered social engineering attacks like those used by Scattered Spider. They discuss the issue of "identity sprawl" across multiple IDPs and why consolidation isn't always the answer. Instead, Bojan advocates for a flexible, best-of-breed approach that provides a consistent authentication experience and leverages existing security tools.


Connect with Bojan: https://www.linkedin.com/in/bojansimic/

Learn more about HYPR: https://www.hypr.com/idac


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at idacpodcast.com


Chapter Timestamps:

00:00 - Introduction at Authenticate 2025

00:23 - Sponsored Episode Welcome: Bojan Simic, CEO of HYPR

01:11 - How Bojan Simic Got into Identity and Cybersecurity

02:10 - The Elevator Pitch for HYPR

04:03 - The Buzz at Authenticate 2025: Passkeys and Securing AI Agents

05:29 - The Trend of Continuous "Know Your Employee" (KYE)

07:33 - Is Your MFA Program Enough Anymore?

09:44 - Hackers Don't Break In, They Log In: The Scattered Spider Threat

11:19 - How AI is Scaling Social Engineering Attacks Globally

13:08 - When a Breach Happens, Who's on the Hook? IT, Security, or HR?

16:23 - What is the Right Solution for Identity Practitioners?

17:05 - The Critical Role of Internal Marketing for Technology Adoption

22:27 - The Problem with Identity Sprawl and the Fallacy of IDP Consolidation

25:47 - When is it Time to Move On From Your Existing Identity Tools?

28:16 - The Role of Document-Based Identity Verification in the Enterprise

32:31 - What Makes HYPR's Approach Unique?

35:33 - How Do You Measure the Success of an Identity Solution?

36:39 - HYPR's Philosophy: Never Leave a User Stranded

39:00 - Authentication as a Tier Zero, Always-On Capability

40:05 - Is Identity Part of Your Disaster Recovery Plan?

41:36 - From the Ring to the C-Suite: Bojan's Past as a Competitive Boxer

47:03 - How to Learn More About HYPR


Keywords:

IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Bojan Simic, HYPR, Passkeys, Know Your Employee, KYE, Continuous Identity, Identity Verification, Authenticate 2025, Phishing Resistant, Social Engineering, Scattered Spider, AI Security, Identity Sprawl, Passwordless Authentication, FIDO, MFA, IDP Consolidation, Zero Trust, Cybersecurity, IAM, Identity and Access Management, Enterprise Security

Episoder(393)

#281 - An Identity Conversation with Henrique Teixeira of Saviynt

#281 - An Identity Conversation with Henrique Teixeira of Saviynt

In this episode, hosts Jim McDonald and Jeff Steadman welcome Henrique Teixeira, Senior Vice President of Strategy at Saviynt. Henrique shares his journey into the identity field and reveals how he became a leading figure in digital identity. He discusses his time at Gartner, where he shared his expertise as the conference chair of the IAM summit and created identity scopes such as Cloud Infrastructure & Entitlement Management (CIEM) and Identity Threat Detection & Response (ITDR). Henrique also provides intriguing insights into the role of AI in identity and his transition from Gartner to his current role at Saviynt. The episode ends on a lighter note with Henrique sharing some memorable experiences from his skiing adventures. Connect with Henrique: https://www.linkedin.com/in/bernardes/ Learn more about Saviynt: https://saviynt.com/ Identiverse 2024: As an IDAC listener, you can register with 25% off by using code IDV24-IDAC25 at https://events.identiverse.com/identiverse2024/register?code=IDV24-IDAC25 Meet up with our RSM team! Schedule at https://rsmus.com/events/2024-events/join-rsm-at-identiverse-2024.html Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter. 🔑 Episode Keywords Identity And Access Management (Iam), Access Management Research, Magic Quadrant, Identity At The Center Podcast, Jim Mcdonald, Jeff Steadman, Customer Experience, Atlanta Hartsfield Airport, Identiverse Conference, Continuous Access Evaluation Profile (Cape), Identity Week Europe, Identity Week America, Identity Week Asia, Henrique Teixeira, Savian Strategy, Bmc Software, Control Sa, Rsa Conference, Cloud Infrastructure Entitlement Management (Ciem), Identity Threat Detection And Response (Itdr)

20 Mai 20241h 8min

#280 - OpenID’s AuthZEN with Omri Gazitt of Aserto

#280 - OpenID’s AuthZEN with Omri Gazitt of Aserto

In this episode of Identity at the Center, hosts Jim McDonald and Jeff Steadman delve into the intricate world of authorization within the IAM space with Omri Gazit, co-founder and CEO of Asserto, and co-chair of the AuthZEN working group at the OpenID Foundation. They tackle the evolution of authorization, from the days of basic role-based access control to the current landscape of fine-grained authorization, including policy and relationship-based access control models. Omri shares his insights on the importance of standards in authorization, the role of developers in adopting these standards, and the journey towards a single authorization control plane for multiple applications. He also discusses the challenges organizations face with over-provisioned access and the potential of AI in enhancing authorization decisions. Listeners will also get a personal glimpse into Omri's life outside of IAM, learning about his passion for kung fu and how the discipline and journey of martial arts have influenced his professional ethos. Tune in for a comprehensive discussion on the future of authorization and the steps IAM practitioners can take to evolve their organization's approach to this critical aspect of identity security. Connect with Omri: https://www.linkedin.com/in/ogazitt/ Learn more about Aserto: https://www.aserto.com/ AuthZEN: https://openid.net/wg/authzen/ Google Zanzibar: https://research.google/pubs/zanzibar-googles-consistent-global-authorization-system/ Identiverse 2024: As an IDAC listener, you can register with 25% off by using code IDV24-IDAC25 at https://events.identiverse.com/identiverse2024/register?code=IDV24-IDAC25 Meet up with our RSM team! Schedule at https://rsmus.com/events/2024-events/join-rsm-at-identiverse-2024.html Attending the European Identity and Cloud Conference in Berlin? Use Discount Code: EIC24idac25 for 25% off. Register at https://www.kuppingercole.com/events/eic2024 Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com and follow @IDACPodcast on Twitter. 🔑 Episode Keywords Authorization, Identity Management, Iam Podcast, Fine-Grained Authorization, Authentication, Digital Identity Consulting, Pci Compliance, Qsa (Qualified Security Assessor), Identity Strategy, Rsm Consulting, Identity Governance, Role-Based Access Control (Rbac), Policy-Based Access Control (Pbac), Relationship-Based Access Control (Rebac), Identity At The Center, Asserto, Authzen, Openid Foundation, Zanzibar, Sso (Single Sign-On)

13 Mai 20241h 8min

#279 - AI in IAM with Patrick Harding of Ping Identity

#279 - AI in IAM with Patrick Harding of Ping Identity

In this episode of the Identity at the Center Podcast, hosts Jim McDonald and Jeff Steadman sit down with Patrick Harding, Chief Product Architect at Ping Identity, to discuss the fascinating intersection between AI and the IAM industry. They explore Harding's journey into the IAM industry, his view on the definition of AI, and dive into a thought-provoking conversation about the future of AI, its potential impacts on identity, and the importance of AI governance. They also touch on the Ping + ForgeRock product roadmap. Don't miss this insightful conversation! Connect with Patrick: https://www.linkedin.com/in/pharding/ Learn more about Ping Identity: https://www.pingidentity.com/ Identiverse 2024: As an IDAC listener, you can register with 25% off by using code IDV24-IDAC25 at https://events.identiverse.com/identiverse2024/register?code=IDV24-IDAC25 Attending the European Identity and Cloud Conference in Berlin? Use Discount Code: EIC24idac25 for 25% off. Register at https://www.kuppingercole.com/events/eic2024 Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter. 🔑 Episode Keywords Identity At The Center Podcast, Iam (Identity And Access Management), Nonprofit Setup, Digital Identity, Conference Attendance, Youtube Growth Strategies, Ai In Identity Security, Generative Ai, Deepfakes, Cybersecurity, Access Management, Ping Identity, Forgerock, Identity Governance, Chat Gpt, Phishing Attacks, Identity Verification, Security Policies, Artificial Intelligence, Identity Industry Trends

6 Mai 202441min

#278 - IDAC Sponsor Spotlight - Stack Identity

#278 - IDAC Sponsor Spotlight - Stack Identity

In this Sponsor Spotlight episode of Identity at the Center, hosts Jim McDonald and Jeff Steadman sit down with Venkat Raghavan, founder and CEO of Stack Identity. They dive deep into the critical issue of identity security in the cloud, shedding light on the pervasive problem of over-provisioned access and the risks it poses to organizations. Venkat emphasizes the asymmetric challenge defenders face against attackers and the importance of continuous access management in reducing the attack surface. Throughout the conversation, Venkat introduces listeners to Stack Identity's innovative approach, focusing on simplifying the removal of access to prevent breaches. He illustrates how Stack Identity acts as a copilot, guiding organizations to identify and mitigate identity-related risks through their Shadow Access Risk Assessment tool, offering actionable insights within an hour of deployment. Listeners will also get a sneak peek into Stack Identity's presence at the 2024 RSA conference, where they will showcase their solutions to help businesses clamp down on excessive cloud permissions. Venkat also shares personal anecdotes, including his pre-competition rituals in competitive tennis, highlighting the importance of mental preparation in both sports and cybersecurity. For a hands-on experience with Stack Identity and to assess your organization's shadow access risk for free, visit stackidentity.com/idac. Connect with Venkat on LinkedIn and don't miss the opportunity to meet the team at RSA, booth N 6564 in the North Expo Hall. Connect with Venkat: https://www.linkedin.com/in/venkatraghavan1/ Learn more about Stack Identity: https://stackidentity.com/idac LinkedIn: https://www.linkedin.com/company/stack-identity AWS Marketplace: https://aws.amazon.com/marketplace/pp/prodview-yd2ezeebcfq3o 2024 RSA Conference Booth - N-6564 (in the North Expo Hall) Shadow Access Risk Assessment: https://stackidentity.com/shadow-access-risk-assessment/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at https://idacpodcast.com and check out our YouTube channel at https://www.youtube.com/@identityatthecenter

1 Mai 20241h 4min

#277 - IDAC & AI Answer Listener Questions

#277 - IDAC & AI Answer Listener Questions

In this episode, hosts Jim and Jeff reached a major milestone with 300,000 downloads. They took the opportunity to answer mailbag questions using AI, providing their own critique of the AI responses. Questions ranged from key IAM metrics for organizations to track, challenges of implementing IAM strategies in large multinational companies, and upcoming trends in the IAM sector. The hosts also posed a fun question: Would you rather have the ability to teleport or the ability to read minds? Tune in for their answers and more! Identiverse 2024: As an IDAC listener, you can register with 25% off by using code IDV24-IDAC25 at https://events.identiverse.com/identiverse2024/register?code=IDV24-IDAC25 Attending the European Identity and Cloud Conference in Berlin? Use Discount Code: EIC24idac25 for 25% off. Register at https://www.kuppingercole.com/events/eic2024 Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter.

29 Apr 20241h 1min

#276 - CloudSec with Kat Traxler of TrustOnCloud

#276 - CloudSec with Kat Traxler of TrustOnCloud

In this thought-provoking episode of Identity at the Center, hosts Jim McDonald and Jeff Steadman engage in a candid conversation with security researcher Kat Traxler from TrustOnCloud. They delve into the intricacies of cloud identity management, discussing the unique challenges and strategies for securing assets in cloud environments like GCP and AWS. Kat sheds light on the importance of understanding the resource hierarchy in GCP and the nuances that differentiate it from AWS. The trio also explores the evolution of IAM tools and their applicability in the cloud, the debate between least privilege and zero standing privilege, and the ongoing journey toward securing the cloud beyond IAM. As they unpack the complexities of cloud security, Kat shares her insights on the significance of asset inventories and the impact of policy inheritance on cloud platforms. The conversation also touches on the future of cloud security conferences and the value of hands-on experiences in understanding cloud security. Amidst the technical deep dive, the episode takes a lighter turn as the hosts and guest contemplate what life might look like outside the realm of technology, revealing personal aspirations ranging from farming to bronze sculpting. For those looking to expand their cloud security knowledge, Kat recommends checking out the GCP 101 series on her blog and the Forward Cloud SEC conference for a comprehensive learning experience. Connect with Kat: https://www.linkedin.com/in/kat-traxler-85a6592/ GCP 101 Series (Blog): https://kattraxler.cloud/gcp/iam/101/2024/03/03/gcp-series-101.html Google Cloud Adoption Framework: https://cloud.google.com/adoption-framework Learn more about TrustOnCloud: https://trustoncloud.com/ fwd:cloudsec conference: https://fwdcloudsec.org/ Identiverse 2024: As an IDAC listener, you can register with 25% off by using code IDV24-IDAC25 at https://events.identiverse.com/identiverse2024/register?code=IDV24-IDAC25 Attending the European Identity and Cloud Conference in Berlin? Use Discount Code: EIC24idac25 for 25% off. Register at https://www.kuppingercole.com/events/eic2024 Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter.

22 Apr 20241h 2min

#275 - IDAC Sponsor Spotlight - Sonrai Security

#275 - IDAC Sponsor Spotlight - Sonrai Security

In this episode, Jim and Jeff welcome back Sandy Bird, the CTO and Co-Founder of Sonrai Security, for a sequel to their first sponsor spotlight. Sandy returns to discuss the groundbreaking Cloud Permissions Firewall with Permissions on Demand. The trio dives into how this new solution revolutionizes the way organizations can clamp down on excessive cloud permissions, streamline operations, and secure their cloud environments with unprecedented speed and efficiency. The discussion illuminates the concept of "default deny," the exhilaration of zapping "zombie" identities, and the seamless integration with cloud native tools. Sandy also shares insights on how customers can measure success with Sonrai’s solution and the significant security benefits provided. For a visual walkthrough of Sonrai’s Cloud Permissions Firewall, visit http://sonrai.co/idac to see the demo in action and learn how you can try it out with a 14-day free trial. And if you're at RSA, AWS re:Inforce, or Gartner IAM, look for the Sonrai Security booth and experience the epiphany moment for yourself. Connect with Sandy on LinkedIn: https://www.linkedin.com/in/sandy-bird-835b5576 Learn more about Sonrai Security: https://sonrai.co/idac Introducing the Cloud Permissions Firewall (YouTube): https://www.youtube.com/watch?v=ffQbM6KGDbY Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter. Episode Keywords Identity And Access Management (Iam), Cloud Security, Aws, Azure, Gcp (Google Cloud Platform), Least Privilege, Identity Risk, Cloud Permissions Firewall, Infrastructure As Code, Security Operations (Secops), Cloud Operations (Cloudops), Permissions Management, Excessive Privileges, Zombie Identities, Identity Governance, Access Analyzer, Sensitive Permissions, Role-Based Access Control (Rbac), Service Control Policies (Scp), Cloud Native Security

17 Apr 202452min

#274 - Deep IAM Thoughts with John Podboy

#274 - Deep IAM Thoughts with John Podboy

In this episode, hosts Jim McDonald and Jeff Steadman engage in a far-reaching discussion with John Podboy, a Senior Vice President in Cybersecurity for a major bank. They delve into the evolving landscape of identity in the banking industry, the impact of AI and indicators of compromise on identity data, and the potential future innovations like FIDO2 and passkeys. John also shares his insights on the importance of understanding business objectives and the role of identity in driving revenue and customer trust. Plus, don't miss the wine talk towards the end, where John reveals his passion for vineyards and the type of wine he would specialize in if he had his own. Connect with John: https://www.linkedin.com/in/johnpodboy/ Identiverse 2024: As an IDAC listener, you can register with 25% off by using code IDV24-IDAC25 at https://events.identiverse.com/identiverse2024/register?code=IDV24-IDAC25 Attending the European Identity and Cloud Conference in Berlin? Use Discount Code: EIC24idac25 for 25% off. Register at https://www.kuppingercole.com/events/eic2024 Attending Identity Week in Europe, America, or Asia? Use our discount code IDAC30 for 30% off your registration fee! Learn more at: Europe: https://www.terrapinn.com/exhibition/identity-week/ America: https://www.terrapinn.com/exhibition/identity-week-america Asia: https://www.terrapinn.com/exhibition/identity-week-asia/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com and follow @IDACPodcast on Twitter.

15 Apr 202457min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
rss-avskiltet
tomprat-med-gunnar-tjomlid
fornybaren
shifter
teknologi-og-mennesker
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
rss-impressions-2
smart-forklart
kunstig-intelligens-med-morten-goodwin
rss-digitaliseringspadden
rss-barekraft-pa-oret
i-loopen
pedagogisk-intelligens
kortslutning
rss-alt-vi-kan
rss-lb-techcast