
Brilliance Security Magazine Podcast · 2026-06-08 · 45 min
Key moments - from our scoring
Substance score
46 / 100
Five dimensions, 20 points each
Abhay Kulkarni draws on 20 years building SaaS and cloud security platforms at Netscope, Cisco, and Symantec to explain why identity is the linchpin of enterprise cybersecurity. After analyzing 300 documented security breaches, Widefield identified that identity-based incidents account for 70-80% of data breaches, yet no single root cause exists - it's a whack-a-mole problem requiring comprehensive lifecycle visibility. Traditional IAM, SSO, MFA, and PAM platforms excel at provisioning and authentication but leave dangerous post-authentication gaps: they don't govern local identities in SaaS platforms, can't validate authentication policies across non-human identities and OAuth grants, and lack behavioral monitoring. Widefield's approach treats identity like data security - securing it at rest (entitlements, credentials, accounts), in transit (authentication quality), and in use (behavioral anomalies). By tracking every session for human and non-human identities, the platform establishes baselines, separates legitimate traffic (99%), and applies machine learning to detect anomalies with 90% fewer false positives than traditional SIEMs. This matters increasingly as AI agents become non-deterministic, requiring continuous behavioral validation rather than one-time authentication checkpoints.
IAM platforms excel at provisioning and federation but don't govern local identities created directly in SaaS platforms, OAuth grants, API keys, or non-human identities. This leaves enterprises with multiple unmanaged identity providers and no unified visibility into their full identity surface area.
Rather than applying rules-based detection to all traffic, Widefield tracks every session, establishes baselines for legitimate sessions (99% of traffic), and applies machine learning only to suspicious sessions that deviate from baseline behavior. This precision-recall approach reduces false positives by 90% versus legacy SIEMs.
Sessions can be abused to grant unauthorized OAuth access to third-party applications, exfiltrate data over time, or conduct lateral movement. Non-human identities and API keys last indefinitely and can deviate from their baseline behavior, requiring continuous monitoring beyond the authentication event.
Traditional governance focuses on provisioning, deprovisioning, and authentication policies, while identity lifecycle security validates identities at rest (accounts and credentials), in transit (authentication quality), and in use (behavioral anomalies) across human, non-human, and AI agent identities.
AI agents are inherently non-deterministic and operate at scale with non-human identities, making it impossible to rely on static authentication policies; continuous behavioral validation is required to distinguish legitimate agent activity from misuse or compromise.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuine operational insights - session-level tracking beyond authentication, the reframe from 'who has access to what' to 'who is accessing what,' and the data-security analogy for identity - but they are diluted by significant product pitch, filler affirmations, and well-worn industry observations. The 300-breach analysis is interesting but never meaningfully unpacked.
you should flip that question around and ask the question instead, who is accessing what? Uh not who has access to what, but who is accessing what?
just like we secure data, uh, when you secure data, you secure data at rest, uh, in transit and uh, when it is used, you should start to think about identity the same way
The 'identity at rest / in motion / in use' framing borrowed from data security is a tidy rhetorical move, and the parallel-session detection scenario adds some texture, but the bulk of the episode recycles standard identity security vendor messaging - behavioral anomaly detection, MFA gaps, non-human identities - without meaningful contrarian or first-principles argument.
we said uh, let's step away from the acronyms and then let's think about what are the problem to solve
A very motivated attacker might use the same network location, similar ISP that you have used before. So it's really hard to kind of convict based on what we call vital signs of your session
Abhay carries genuine practitioner credentials - early VP of Engineering at Netscope during the SASE era and SVP/GM running WebEx at scale through the pandemic - which grounds his product perspective in real operational experience. The interview skews promotional, limiting how much depth that background actually surfaces.
when I was at Netscope especially, we Wrote a proxy. We were inspecting network traffic and we uh, always used to wonder, uh, oh, wait a minute, what if the same traffic actually happened, but it didn't go through the proxy
when I was uh, at WebEx, um, we were running a very large platform at WebEx, uh, went through the pandemic. We scaled the platform
There are several concrete anchors - named threat actors (Shiny Hunters, Scattered Spider), a 90% false-positive reduction claim, a 300-breach corpus, and named platforms - but dollar figures, customer names, timeline data, and breach specifics are absent, and key statistics are hedged with 'some numbers say 80%, some say 70%' vagueness.
a couple of our customers kind of compared us with their legacy sim environments and some other competing players and they found out that we reduced the false positive rates by 90%
When you look at what Shiny Hunters is trying to do, what Scattered Spider is trying to do, they mount a massive social engineering attack
The host asks topically reasonable questions but consistently leads with 'great question,' accepts all claims without challenge, and narrates back what the guest just said rather than pushing for precision or disagreement. There is no probing of the 90% false-positive claim, no challenge to competitive positioning, and no productive tension throughout the 45-minute conversation.
That is super cool. Thank you
So that, that's kind of what you're doing. So what when you do that it'd be kind of interesting, kind of fun I think to understand what kind of risks you're seeing
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of the Brilliance Security Magazine Podcast, host Steven Bowcut speaks with Abhay Kulkarni, Co-founder and CEO of WideField Security , about the rapidly changing identity security landscape. Abhay explains why identity has become the linchpin of modern cybersecurity, especially as enterprises rely more heavily on SaaS, cloud platforms, API connections, non-human identities, and AI agents. The conversation explores why traditional IAM, SSO, MFA, and access reviews are no longer enough, and why security teams must understand what identities are actually doing after authentication. Steven and Abhay also discuss post-authentication visibility, session tracking, behavioral context, identity lifecycle security, and the challenge of securing increasingly autonomous AI agents without slowing down innovation.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: Hello, and welcome to the Brilliant Security magazine podcast. I'm Ava, your digital assistant. In this episode, host Stephen Bowkut speaks with Abhay Kulkarni, co founder and CEO of Widefield Security. Abhay uh is a technologist and cybersecurity executive with more than 20 years of experience building and scaling SaaS and cloud security platforms. Before founding Widefield Security, he served as senior Vice president and General Manager at Cisco, where he led the webex app business and platform. Prior to Cisco, he was an early executive and Vice president of engineering at netscope, where he helped pioneer the secure access service Edge or SASE market. At Widefield Security, Abhay is focused on securing the full identity lifecycle across human identities, non human identities, and AI agents. Wide Field's platform connects an organization's identity fabric across SaaS, cloud and on premise environments, helping security teams discover risky identities, harden authentication, monitor active sessions, detect behavioral anomalies, and respond rapidly to identity misuse. Today's conversation will explore why identity has become one of the most important control planes in CyberSecurity, why traditional IAM and SSO tools often leave dangerous post authentication blind spots, and how the rise of AI agents and non human identities is forcing security leaders to rethink visibility, governance and response. And now, here is your host, Stephen Bocut.
Speaker C: Abhay, welcome to the Brilliant Security magazine podcast. I am very pleased to have you on the show. Thank you for being here.
Speaker A: Thank you, Stephen, for having me.
Speaker C: All right, this will be fun. Um, I'm excited. So let's start with some questions. And uh, we always like to start with some kind of career background about the help our audience understand who the guest is. So let's start with that a little bit. So you've spent more than, uh, according to the biographical information we just heard, you've spent more than 20 years building and scaling SaaS and cloud security platforms. Uh, spent some time at Cisco and Netscope. So what experiences from that journey that you've had up to this point in your life most shape the way that you think about identity first security today?
Speaker A: Yeah, it's a great question. Whenever I look at my past and what I did, especially at Netscope and Cisco and before that at Symantec, uh, what I really found out was, uh, identity was really the linchpin when it came to cyber security. Uh, there are many different cyber security technologies that people have employed so far. Endpoint, cloud, network and whatnot. Uh, but, uh, the one thread that goes through all of them is identity. Uh, when I was at Netscope especially, we Wrote a proxy. We were inspecting network traffic and we uh, always used to wonder, uh, oh, wait a minute, what if the same traffic actually happened, but it didn't go through the proxy, but somebody else made uh, that call with the same identity? How would one detect something like this, an abuse, or some kind of a back door or side door? And identity is really the key for understanding cybersecurity, especially from an enterprise point of view. So that was really, uh, every single time we analyze something. In my prior jobs, uh, that was the key, uh, takeaway for us is that, uh, we got to think about identity.
Speaker C: Yeah, absolutely. Um, and I appreciate that and that's why I was so excited to have uh, you on the show. So let's drill down into that just a little bit. So you spent time at Netscope and you helped kind of pioneer this idea of SASE, uh, and then at Cisco and WebEx. So how did those experiences influence your view about how cloud SaaS, collaboration tools and identity risk, how they're all kind of converging at this point in where we're at with technology?
Speaker A: Yeah, great question. I mean, uh, when I was at netscope, uh, as I mentioned to you, Stephen, we, uh, inspected, uh, wrote, um, various deep connectors that inspected traffic going to cloud and SaaS platforms. That's what Netscope started off as, a cloud access security broker. And when we saw that, uh, we saw this interesting phenomena there where every single transactions used to have some kind of a session cookie or some kind of a token authenticator, uh, outside of what a user would or Identity would authenticate using username passwords and things like that. And we always used to say that, hey, that token is the key to all things Identity. You steal that token and all bets are off after that. And then when I was uh, at WebEx, um, we were running a very large platform at WebEx, uh, went through the pandemic. We scaled the platform. Uh, one of the things that I realized was now on the other side, I was an application developer. I was a SaaS application developer running WebEx. Uh, identity was really key to every single thing that we did, whether it was everything from provisioning to deprovisioning to access. Um, uh, we used to think that if Identity was not done within our product, uh, that would expose us to serious problems, security problems. So it was taken very seriously. In fact, we used to have a common identity. I think it was like an internal platform within Cisco and WebEx as well. Um, and then we kind of went through some very interesting times, uh, where, uh, like every other security company, we had some incidents that further informed us, uh, how critical it is to understand the entire identity attack surface landscape. It is not just about your workforce, your human identities, but you also need to understand your non human identities, the automation scripts, the bot accounts and whatnot. Uh, and you also need to then understand not just the accounts and their credentials, but what are they actually doing. Uh, not just what they are set up to do or what they uh, have been given access to do. So, which is what led to this whole idea around, can we build a platform that tracks the entire identity life cycle, uh, addressed, uh, which is your entitlements, accounts, credentials in motion. Like what are they doing while they're authenticating? And then once they're authenticated, what are they actually doing? Are they doing what they're supposed to do? Is their behavior changing in any way? Uh, which is actually super important for us to track any types of abuse or any, any types of potential misuse that uh, we tend to see from time to time that happen to lots of enterprises.
Speaker C: Absolutely. Thank you. So I think that gives us a pretty good insight into, um, your history and why you see things the way you do. So let's, let's look at it from like the present moment now. So, um, and I guess I'm interested in maybe two things. This question may be kind of twofold. So, um, wide field security uses this idea of identity. And you're not the only ones. But there is an idea in our industry about identity life cycle. So what I'm really curious to get your perspective on is why this idea of identity life cycle security becomes, why is it so critical right now? What are we doing right now that makes it more critical than it was even five years ago or 10 years ago?
Speaker A: Yeah, no, great question. Um, there are lots of statistics that say that identity, um, based incidents are really the ones that lead to a data breach. Um, by a large majority, some numbers say 80%, some numbers say 70%. But a majority of the data breaches are caused by some kind of an identity incident. Um, then what we did at Whitefield was we literally went through 300 past, uh, security breaches that were documented that we could get our hands on. And we analyze, uh, every single root cause that we could find from the public Internet. Um, once we analyzed that, we found out that when it came to identity based incidents, uh, or data breaches, there wasn't a single root cause for all the different types of breaches that happened across organizations. Uh, it was almost like a whack A mole board where you fix one type of problem, the mole will pop up from another place and you whack it. And it will pop up another place.
Speaker C: Yes, the whack a mole, sure.
Speaker A: Uh, now if you could build lots and lots of different technologies to kind of stop these moles from propping up from different places. But what you really needed was a comprehensive view of identity, uh, across uh, various different uh, lifecycle events to really be able to piece together the picture and then help build technology that can now stop these type of incidents from happening in the first place. Um, and uh, that is what led to our idea around um, uh, just like we secure data, uh, when you secure data, you secure data at rest, uh, in transit and uh, when it is used, you should start to think about identity the same way as well. Very nice analogy for cybersecurity practitioners, uh, when they think about identity because otherwise you will get thrown into the three or four letter acronym world of platforms. And then you're trying to say where does this fit? Does it fit here or does it fit there in that acronym? So we said uh, let's step away from the acronyms and then let's think about what are the problem to solve. And the problem to solve is there is a vacuum more root causes for identity incidents. You want a single platform to be able to solve all of them across your human, non human and now agent AI identities as well. And that's what led to our complete lifecycle approach for identities. Uh, and we start off by being a validator of your identities at rest. We make sure that your entitlements are right. You have not left somebody, uh, in your, you know, in your, in your identity ecosystem, an employee who has left, who has left the company or a non human identity that has not been properly deprovisioned, uh, or it is left dangling and it's dormant, et cetera. Uh, to then understanding the credentials, uh, is somebody using a weak credential for a non human identity that is not being governed properly. It has not been rotated since uh, a past employee has left the company or it has not been rotated since there was an incident or what have you and then look at all the other aspects of it in motion. Um, and our key differentiator was once you log in, you need to start to track what the identity does as well. Because Stephen logging in today into slack, uh, is very different from what Stephen does day to day in his slack. And guess what, you log in only few times. Uh, the activities uh, happen over a long period of time. So you cannot just stop at authentication. You've got to go beyond that and track behavioral activities as they're happening, uh, in near real time. And that's what really led to this whole idea of we need to start to cover this end to end all the way from addressed all the way to, uh, in use. And that's why we came up with this notion of the identity lifecycle. Um, I know you said we are not the only ones, but this definition of identity lifecycle is actually quite unique to Whitefield. Uh, no other identity security company thinks about identity in this way. Um, and that is actually kind of unique for us. And the reason we came up for this, Stephen, was, uh, customers would ask us, okay, exactly where do you fit? Are you an IAM platform? Are you a governance platform? Are you a privileged access management platform? Um, what do you do? Uh, and then we'll say, yeah, we do help you detect identity threats, uh, in your environment. And people will struggle to understand exactly what that means. And now if you now say, hey, we are a validator for all your identities. Address in motion, and then we detect threats, we help you with posture, it sort of starts to paint the picture around what exactly Whitefield does and how we do it. And that helps also understand organizations. Understand that, okay, I'm getting these type of coverage from this platform, which is very different from what I have in my current security stack. Uh, that also helps people understand the value prop. For what we provide.
Speaker C: Yeah. Well, it seems to me from other guests that I've talked to that there is some movement in the industry, I guess I could say, toward what you've described. Now, you may be doing it, um, different than anybody else, but I think, and I'm glad to see that our, uh, you know, if you, if you go back a few years, you know, what you just described was so obvious. Let's just get everybody at the door and we'll let the right ones in. But once they're in, we're going to trust that they're only going to do the things that they're supposed to do. And then we realized, of course, in the industry that that's, that's not the case. We don't. We need to know what they're doing the whole time that they're, they're in the system. So trying to find a way. And that kind of leads me to my next question. So if I'm a security leader, uh, practitioner, and I've got, you know, identity and access management, and I've got SSO and MFA and Pam and edr. I've got all these tools in place now. I can see some advantages into having a unified platform. That makes sense, right? It should be easier, maybe more efficient to have a unified platform. But if I understand what you're saying, there are still some gaps, right? There are still some gaps. What you're doing is more than just providing a unified, a unified platform for those various tools that a security organization, organization may have in place. So what are some of those gaps that you're looking at and providing a solution for?
Speaker A: Great question. We think by the way, that all these other tools, we complement them quite well. Um, we are not really there to replace them at this moment. We complement them well. And let me give you some examples which uh, will throw shed some light on why you still need a platform like Whitefield, uh, in this scenario. So um, let's start about identities at rest. Uh, your IAM platforms, your identity and access management platforms are fantastic at figuring out federating your identities, giving single sign on provisioning, deprovisioning identities. What they miss however are local identities that are provisioned in Cloud and SaaS. They have no visibility around that. In effect every single enterprise out there actually has multiple IAM platforms, multiple identity providers. Because every Single Cloud and SaaS platform that they onboard, they're going to have a local identity there, whether it's human, non human, a connected app or a credential that is given to a third party, uh, you know, whatever, what have you. All of these are typically not governed by the IAM platform. Uh we bring that under a single umbrella. So your identity people can say okay, I know exactly how many accounts I have across all my cloud and SaaS environments and my on premises environments. I know exactly what credentials they have, I know how many credentials uh, need to be rotated or are weak or stale or strong. Uh, and I know exactly what uh, the surface area of my identity looks like. And unfortunately there isn't a single product that does that today across human and non human identity. So you kind of have to go to your single sign on IAM provider for your federated identities and then you go to go how to go log into your AWS environment or your cloud environment or your salesforce environment to check each one of those. And that's just impractical for an identity person in uh, a large enterprise. So that's number one. Number two is uh, you main because you have now multiple identity providers in your enterprise. Um, uh, you cannot just say that my IAM authentication policy governs all authentication, uh, and Guess what? That authentication policy does not even govern your non human identities either because they are logging in with the different types of credentials that are not managed by iam. So you go to manage that, govern that, make sure there are no escapes. These policies are easy to say, oh, I have 100% MFA coverage. And then you find out that oops, sorry, a small group of identities were uh, not covered in that. How do you know, uh, there are no escapes there. And you know what the attackers are looking for? Just one to get into your environment. And then uh, beyond that is where the real value, uh, for a platform like Whitefield comes in is like if an identity starts to misbehave, if a session that is started using authentication has to kind of deviate, uh, how do you know that it's actually working correctly or not? And how do you know it's actually behaving the way it's supposed to behave? Especially true in the new AI and agentic AI world because agents are uh, inherently non deterministic. And so you need to kind of find out whether the behavior is kosher, uh, is it supposed to happen or you need to start to take some action and stop that from happening. So that is why the existing platform don't really cover what we do with Widefield. You need uh, a visibility, a platform like ours, you need a policy validation platform like ours, you need a detection and response platform like ours in order to kind of complete that identity stack that you have. And we are seeing enterprises acknowledge uh, that this is true. And that's what our customers are saying. You know, they're really putting us front and center, uh, off their security strategy.
Speaker C: Okay, that's excellent. So I can certainly see how a solution like uh, Wide Field Security would kind of help would help you with this post authentication blind spot, uh, if you will. Um, how do you provide that visibility into post authentication? Is it a set of rules that are just going to flag when someone, when some uh, identity that you're kind of watching go through the system does something that you know in context doesn't really make sense and then it just throws a flag or how does that work?
Speaker A: No, it's exactly. Actually um, a set of rules is not going to cut it, Stephen. Uh, people have had a set of rules uh, in their sims to detect anomalies. What we have found out is that uh, most of the detections in um, all the top sims today are extremely false positive prone. Uh, the reason for that is identity signals are not coming from a single source. Uh, like your endpoint Signals. Our endpoint signals are coming from the same endpoint provider, whether it's Cloud Strike or Sentinel 1 or Microsoft or what have you. Uh, identity is coming from various different signals. You're getting some signals from your IAM, some signals from your cloud and SaaS. So you got to be able to correlate that, uh, those signals, correlate the identities, normalize those signals. And then what we do at Whitefield is we actually start every single, we actually track every single session that any identity creates, whether it is human or non human. Because these sessions are long lived and that session tracking helps us find out first of all what is good. We can say that, oh, Stephen's session is great because he logged in with an identity. It's MFA enabled. The MFA M quality was very high. I don't suspect this session to be any bad. So we can actually separate all the good sessions, which is probably 99% of your enterprise traffic. And then we only inspect a, uh, small number of sessions that are potentially suspicious or they deviate from the normal. And then we apply machine learning and AI on those sessions to really identify which one of them are the ones that are problematic. Uh, and so because we do all of that, our false positive rate is extremely low. Uh, in fact, uh, a couple of our customers kind of compared us with their legacy sim environments and some other competing players and they found out that we reduced the false positive rates by 90%. Uh, and we actually pride on that internally we have precision and recall goals for our product and we track that very, very closely. We're obsessed about that. Uh, any false positive makes me, ah, very nervous and so does any false negative as well. We don't want to miss any. So that's why we track both precision and recall, uh, making sure that there is the right balance between uh, uh, our false positive rates and also the fact that we shouldn't be missing any of these attacks if you were to supposed to detect them.
Speaker C: Right. So in that scenario that you've just kind of described, so my human identity logs into the system and everything looks good. I get a high score or you're not really, um, concerned about what I'm doing? Because I'm just doing the things that I'm supposed to do at the times that I'm supposed to do them and that kind of thing. But I think if I understand correctly, um, the reason that a solution like yours adds more value is that maybe I've been logged on for an hour or two and then my behavior changes. So then the behavior of that Identity starts doing some things that maybe it shouldn't. So you have to keep one eye if you will, uh, on, on what everybody's doing because they could have been on. And particularly if it's a non human identity, it could have been on for weeks, it could have been on a long time. Uh, yeah, behavior changes. So that, that's kind of what you're doing. So what when you do that it'd be kind of interesting, kind of fun I think to understand what kind of risks you're seeing when you, when you keep an eye on an identity. That was fine, everything the logon was good. Uh, but some period of time down the road the behavior changes. What kind of risks are you exposing?
Speaker A: Yeah, um, I think what you said is absolutely right by the way, when I said that we look at a session and mark it as good, doesn't mean that the session stays marked good forever.
Speaker C: You don't leave it alone.
Speaker A: We don't leave it alone. Definitely track it for behavioral changes going forward. But that also establishes uh, certain things from a baseline perspective. Any behavioral tools require baseline for what the behavior is supposed to be. Now here's the rub though. Um, when you think about identities and sessions and non human identities, you think about people who are authenticating, logging into your favorite products like Slack or Zoom or you know, Salesforce etc. What you tend to miss is that it's not just the uh, the human logging in, but even the human might be granting access to these tools via an OAuth grant or some, some kind of an API key. Those sessions last forever. Uh, and to your point they are sort of, you can call them the non interactive delegated by a human sessions. I don't even know if you get called them non human sessions. They last for a long time so you got to be able to track their behavior. Um, and then secondly any non human identity. So going back to your question, what kind of uh, threats or attacks do we detect from based upon this? Um, we have found out uh, all kinds of things with our customers by tracking sessions like that. So we have found out um, from a risk perspective, which is not necessarily a threat, um, that somebody might have granted access to an application that is just not a very secure application either. Um, for example we had an ah, incident where a C suite, uh, uh, had granted access to their mailbox, uh, uh, to a application that was posted. Uh, in a country that you probably don't want to be doing business with. Uh, these are kind of things that um, you kind of get exposed by inspecting Traffic, you can understand what's going on. You can say, wait a minute, you shouldn't be kind of using these type of, type of uh, uh, applications or you shouldn't be providing access to your data, uh, to any third party that uh, you don't know about.
Speaker C: Or at least if you are, you should understand what the risks are. He may decide anyway, but he needs to know what the risks are.
Speaker A: Exactly what the risks are, um, in terms of threats. Um, you know, these are the kind of uh, techniques used by many of the threat actors. When you look at what Shiny Hunters is trying to do, what Scattered Spider is trying to do, they mount a massive social engineering attack against uh, enterprises. They're trying to convince the help desk user to reset somebody's credentials to uh, enroll a new Multi Factor Authentication, uh, provider to somehow launch a phishing attack so that they can capture session credentials. Um, once they do that then they want to hide their tracks. So they would then be accessing data uh, from a completely different location. So your session might start off good. But if you are victim of a phishing attack, your session token might have been stolen and then there might be a parallel session going on. Um, while you are accessing your data from your regular location, there might be a parallel session going on, uh, that is completely suspicious. And parallel access is something that ah, we determine and find out fairly quickly. Um, then the patterns of the parallel access might also be different as well. A very motivated attacker might use the same network location, similar ISP that you have used before. So it's really hard to kind of convict based on what we call vital signs of your session. But then they might actually do certain things, uh, to exfiltrate data, um, or take some actions that are completely not obvious or things that you don't do. Like they would enroll a new device, uh, um, as a authenticated device to your platform. Or they would enroll a new Multi Factor Authentication provider, um, a new way of doing mfa. Or they would start to do certain things like do bulk Downloads, bulk uh, GitHub, repo clones, et cetera, which are also kind of interesting triggers for us to find out. So if you look at this entire thing, if you look at the mitre, ATT and CK kill chain, there are certain things that we detect at initial access. Like this initial access doesn't look great. Certain things that we detect from a behavior point of view, when certain uh, we call them sensitive operations are being done by the identity. And then certain things we do when we want to at least detect any data exploration Attempts that are happening. If you're trying to do bulk downloads or do any massive changes uh, to the system, we should be able to figure that out. There's a lot of different ways you can start to track those and sort of bucket them into a risk or a threat. Uh, risk is obviously something that you can mitigate, accept or mitigate like you said, or a threat which you absolutely have to pay attention to and try to respond to it.
Speaker C: Yeah, okay, so, and this is so fascinating to me and one of the most fascinating parts and I'm going to try and steer us back there just. I know we've talked about this and ah, and we may have covered it adequately but this idea of behavioral context versus static access reviews. So, and I guess what I'm most interested in getting your opinion on right now is um, what, what is different about how we do things today than maybe five years ago or 10 years ago? So is it, is it AI agents that are, that are being given uh, you know, identity access? Or um, why is it no longer enough to ask whether the identity should have access but instead we have to asking how is the access being used? Uh and obviously that question said well yeah, that makes sense. But uh, we have a different threatscape um, than we had even five years ago. So kind of describe that for us. Why is that no longer enough?
Speaker A: Yeah, I think um, typically the uh, governance on identities try to ask the question about who has access to what. Um, and they try to get a sense of okay, all these identities have access to certain data sources, some crown jewels assets that ah, enterprises care about. Um, the problem was these type of reviews occurred every so often. Somebody would do monthly, somebody would do quarterly, etc. Well things change quite rapidly nowadays. Uh, a quarter or a month might be too long a duration. Um and then the second problem is the fundamental question of who has access to what is actually not answered adequately just by looking at static permissions or static access grants. Because there are so many different complications with uh, Cloud and SaaS has brought about and the API economy has brought about is that uh, who has access to what now has to kind of look into various different access, you know, different types of policies, uh, delegated grants, uh, assume roles and whatnot. So different types of permission grants that affect that. That's that simple question. So uh, we think that you should flip that question around and ask the question instead, who is accessing what? Uh not who has access to what, but who is accessing what? Which gives you a sense of in the past X hours who is accessing um, my data, uh, through what mechanisms, uh, through what credentials. And then you can start to piece that back towards what you're doing now. What has changed that lead us to doing this? Even before the advent of AI, uh, we had a massive proliferation of SaaS and cloud in most enterprises. And not only that, these were not standalone entities, they were connected to each other. Uh, most cloud providers talk to each other and they need to, in order to kind of be more productive. So you actually want to enable that uh, uh, SaaS to SaaS or SaaS to cloud type of, type of interactions. And when that happens your identity starts to sort of cross pollinate from one source to another source. Uh, so that itself uh, led uh, to this whole question around who has access to what wasn't really well answered if you just uh, let it be at that level. So you had to ask about who is accessing what. Then with the advent of AI, uh, uh, it further got exacerbated in a way because now with AI, these agents, uh, that have been given access to. I have gladly granted my cloud code access to my GitHub repos. So now cloud code is doing things on my behalf to my GitHub repos. Um, I may know some of those things, but do I know exactly what it is doing? I don't. So you got to. Now, uh, a different thing has gotten into the mix, which is not just what your static risks were or what an adversary was trying to do, but this non deterministic piece of code that you're running in an environment, is it actually doing the kind of thing that you actually expected it to do? Uh, uh, we heard about horror stories of AI deleting production databases and whatnot. Those are actually honestly, uh, quite predictable and uh, quite expected outcomes because it's a non deterministic system. So AI is now shedding a new way of us to think about. And that's why you cannot just look at it at a static time. You need to kind of look at it dynamically, say who is accessing what, including my agents, including my non human identities, including my human identities. And then try to decipher and say is this access that they have or what have they done? Is that right? Is that what I expected it to be? Yeah.
Speaker C: Okay, so let's pivot just a little bit here. How does it change, uh, what you're doing? How does it change? Like the deployment model model. So if you're agentless, um, how does one deploy a solution like yours? And how is that different than what A security leader may expect.
Speaker A: Yeah, uh, so we uh, are a startup so we wanted to kind of provide the most frictionless way for us to provide value to our customers. Um, deploying an agent is actually quite onerous. Uh for most enterprises nobody wants yet another agent running on uh, somebody's laptop because you've got to manage it, you've got to patch it, you've got to do all kinds of things you need to do to make sure the agent actually stays up and running. Um, and uh, similarly uh, when it came to network based uh folks, most of uh, the enterprises now have a SASE solution. I worked at netscope in the past and other companies like Zscaler, Auto Network, etc. Have really deployed uh, a network based proxy uh, across most enterprises. So us asking for a proxy was going to be a hard uh, uh insertion point for us. Uh, which is why we decided to say like hey, you already have. And this is a, this is one of the realizations I had is that as I built this product, as we build this product we found out that most enterprises actually have an abundance of great signals and telemetry already. Uh, and building a product like ours requires you to, to use those signals and telemetry the right way. Um, and these signals are not just available to Whitefield, they're available to any other product out there as well. Where we come in and why we are different is we know how to use those signals and telemetry the way uh, they should be to solve the identity problem. And that's where we came in. So we actually a customer calls us the Viz for identity, the famous CSPM product like Viz, which you connect to your aws, your Azure, your GCP and off you go. It will scan and tell you all the good things you need to fix in your cloud environment. Well the same thing for us, you connect wide field to various sources across your identity cloud SaaS, uh, endpoint platforms and we will tell you what is, we'll do an assessment, we'll tell you what's potentially wrong with your posture but we also now start to detect any particular threat actor that might be doing attacks uh, on your environment. Everything from a potential uh, old school password based attacks on your non federated identities all the way till uh any uh, behavioral anomalies that we talked about uh, on a post authenticated session so we can start to track that as well. So very simple to deploy, uh, we say that you can actually deploy and customers have done this uh, in a wide field in less than an hour at least. Like the initial deployment. And yeah, you can sort of keep on uh, adding value to it by expanding the deployment. But the initial deployment can be done within an hour. You can start to get benefits of it within a day or a couple of days at most. And within a week you can actually have a very comprehensive report that tells you uh, like a full view of your system. Uh, I call it the Identity State of the Union. You kind of get a state of the union report, uh, when you look at your entire surface area, uh, it's actually extremely easy to get value out of a platform like Whitefield, uh, and start to use it right away in your security program.
Speaker C: That is super cool. Thank you. Um, I want to ask you about, um, this is an experience that I'm sure that's happened to you just hypothetically. You're at a conference like I think you are now, and the security that you get, you strike up a conversation with security leader and he starts talking to you about his tool fatigue. Right? So he's got all these tools, these acronyms that we've just talked about earlier. Uh, what's your response to him? Uh, when that's the conversation, I think
Speaker A: tool fatigue is real. Um, um, proliferation of tools definitely adds a lot of operational overhead to security organizations. So there is no doubt about it. Um, and my key ask from them, uh, people is like you should absolutely try to go and standardize on a single platform. However, security is also a best of breed. Uh, uh, product, technology, space. Good enough is not enough. Uh, so you cannot just say that hey, I standardized on this platform. Hence I have turned a blind eye towards some of these very important, uh, potential risk and also threats that are going to impact my environment. Uh, uh, I would say every single security leader would have their own set of priorities. Ah. What we have found out in Identity, securing identities is at the top three priorities for a very large number of security leaders out there. And uh, they are actually very open to trying out new solutions like Whitefield, especially in identity. Um, last thing I'll say is that no matter, um, whether you go with a platform or not, uh, every single security product has to work in an ecosystem. No one product can do every single thing. So that means you got to have integrations so that you can reduce, uh, customer calls, it click offs, reduce the click offs. So I don't have to click on something to do something. So for that reason Whitefield has done a lot of things. We have inbuilt automation in our product. So you can actually kind of do a set it and forget it policies. So you don't have to literally have hands on keyboard to do certain things. Um, we have APIs, we provided APIs, MCP servers. You can hook us up with other uh, like other automation that you have within your product, uh, within your enterprise or even with a cloud code or something like that so you can actually start to get uh, answers out of Wide Feed and you don't have to literally log into a ui. And then we also then integrate with your existing providers, your SIEM providers, your endpoint providers, et cetera. So we are a firm believer in the ecosystem. We want to make sure that we fit in the ecosystem. But we also think that a single platform may be uh, an oversimplification uh, for any enterprise right now, especially for identity, uh because it is a best of breed, uh, type of uh, type of technology area. You want to make sure that you're bringing in the best to be able to solve some of these problems.
Speaker C: Okay, thank you for that. So we are about out of time but I do want to leave with one more question. This is kind of a future forward looking question, uh, if you will. So obviously I think we'll all agree that AI agents and other non human identities are likely to become more autonomous. We'll see more of that. Uh, so you know, aside from you know calling the Widefield security sales team, but other than that, what should um, security leaders, what do they need to do right now to kind of get prepared for this future that is coming at them oh so rapidly, uh, what uh, do they need to do to be ready for that?
Speaker A: Yeah, I think the agentic AI has you know, future is here whether you want it or not. And I would say that I would venture that uh, if you look at like the Fortune 500 right now, almost all of them have AI agents in production at this point of time in some way, shape or form. Um, you know, for example you might have procured an agent and is running uh today in your environment that you just don't know about. Um, uh, or you think it is just a chatbot, but it actually has an agentic uh in a way of doing certain things so you can actually use it to kind of automate and somebody in your team is going to figure it out and do it. Uh, so it's, it's uh, you know it's actually, it's actually here now. The one thing that I, I am seeing common pattern across all customers that we spoke speak to is that um, the, the biggest uh, uh, sort of not I would call Afraid. But what they're worried about, uh, when it comes to agentic AI is how do I make it more deterministic, how do I remove uh, the non deterministic nature of AI, uh, without sacrificing all the gains that it provides for me. Um, so, uh, to do that I think you kind of have to kind of think about your agentic uh, life cycle and then start to see what are the different ways you can provide guardrails or safeguards against any non deterministic behavior that your agents are going to uh, take. Uh, and uh, this is not a self promotion, but you've got to start to think about identity first when you think about that. Because uh, you can sort of guard, uh, you can put really good guardrails by not providing excessive permissions or privileges to these agents, uh, and making sure the identities that these agents run or use, uh, are governed the right way and are tracked the right way as well. Um, I think that's where you want to start. But there are other things you need to do. You need to find out, uh, is there any threat of prompt injections? You need to find out if there any way you can uh, stop an agent from um, uh, uh, performing any sensitive operations, uh, even if it might be a legitimate use case. And then obviously you need to start thinking about what happens when these agents are controlled by a potential malicious insider, which is like probably the highest or the most difficult problem to solve right now in cybersecurity. So there are a lot of different things you need to think about. But I think uh, most people are starting to figure out if I can make an agent be more deterministic and not let it run amok and do sensitive operations. I'll feel better about running these agents in my environment and then the business can have what they want and I will know that these are done in a secure way.
Speaker C: Yep, perfect. Okay, thank you. Really appreciate you being on today. This has been fascinating. Uh, I know I've learned a lot. Uh, I'm sure that our audience will have learned a lot as well. So thank you so much for spending some time with us today.
Speaker A: Thank you Stephen for having me. I really enjoyed it.
Speaker B: Thank you for listening to the brilliant Security magazine podcast. Our thanks to Abhay Kulkarni, co founder and CEO of Widefield Security, for joining us to discuss the evolving identity security landscape and the growing importance of securing human identities, non human identities and AI agents across the full identity lifecycle. This episode explored why traditional access controls are no longer enough. How post authentication visibility can help uncover identity misuse and why AI agents introduce a new layer of complexity for enterprise security teams. To learn more about Brilliant Security magazine and to find additional podcast episodes, articles, and cybersecurity thought leadership, please visit Brilliant Security Magazine online. Until next time, stay informed, stay resilient, and stay secure.
Speaker A: Sam.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.