The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cyber Defense Radio
Cyber Defense Radio artwork

Cyber Defense Radio - Jeremy London - Keeper Security - Hotseat Podcast - 2026

Cyber Defense Radio · 2026-05-07 · 15 min

0:00--:--

Key moments - from our scoring

Substance score

30 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality5 / 20
Guest Caliber9 / 20
Specificity & Evidence4 / 20
Conversational Craft4 / 20

The conversation centers on identity as cybersecurity's most critical - and most complicated - frontier. Jeremy London articulates how traditional single-username-password access has exploded into environments where individual users manage 10-20 identity types simultaneously, especially as AI agents and citizen developers autonomously integrate tools with corporate systems. Keeper Security addresses this fragmentation through a unified platform - one pane of glass - where passwords, secrets vaults, and privilege access management exist in enforced concert. Rather than disconnected point solutions, Keeper auto-injects ephemeral credentials, rotates keys after single-use sessions, and eliminates standing privileges that remain the golden key for attackers. London highlights databases and API keys as prime attack vectors, with info stealers and supply-chain actors hunting stored credentials to breach data. Keeper's database access tools scope-limit users to auto-generated ephemeral accounts, making post-breach persistence impossible. Looking forward, he describes post-quantum encryption (using NIST-approved algorithms) as critical for forward security, and outlines Keeper's roadmap: user behavior analytics and generative AI to surface anomalies across thousands of identities, making admin workload manageable at scale. Organizations adopting cloud services, SaaS, and automation should prioritize password rotation policies and automated key lifecycle management across hundreds of cloud accounts.

Key takeaways

  • →Organizations now manage 10-20 identity types per user due to AI adoption and citizen developers, requiring unified platform approaches rather than disparate tools.
  • →Ephemeral accounts with least-privilege access and automatic rotation after use eliminate standing privileges that serve as attackers' primary targets for lateral movement and persistence.
  • →Database and API credential theft remains the most lucrative attack vector; centralized secrets vaults with auto-injected, auto-rotated credentials prevent info stealers from obtaining persistent access.
  • →Post-quantum encryption using NIST-approved algorithms is essential now to protect stored credentials against future decryption capabilities of quantum computers.
  • →Automated password rotation policies and user behavior analytics at scale help security teams manage thousands of identities across hundreds of cloud accounts and SaaS products.

Guests

Jeremy London

Topics in this episode

Zero TrustPost-Quantum EncryptionKeeper SecurityZero Knowledge encryptionPrivilege Access Management (PAM)Secrets vaultEphemeral accountsJust-in-time accessLeast privilegeNIST-approved algorithms

Questions this episode answers

Why are standing privileges a major security risk today?

Standing privileges remain available for attackers to exploit and reuse; if compromised, they provide persistent access and admin control. Ephemeral accounts generated on-demand with automatic rotation after use eliminate this foothold, making post-breach persistence impossible.

How does Keeper's unified platform differ from point solutions?

Instead of disparate tools that struggle to audit access trails, Keeper uses one pane of glass where passwords, secrets management, privilege access, and enforcement logic are interconnected - making it impossible to lose visibility into who has access to what or where credentials originate.

Why should organizations prepare for post-quantum encryption threats now?

Attackers can harvest encrypted data today and decrypt it later using quantum computers; post-quantum encryption with NIST-approved algorithms protects stored credentials and sensitive data against future decryption, even if a breach occurs.

What is the main attack vector for database breaches according to Keeper?

Info stealers target hard-coded database passwords, API keys, and secrets with the goal of compromising databases to steal or encrypt customer data for ransom; centralized credential management with auto-injection and rotation prevents attackers from obtaining and reusing standing credentials.

How do organizations scale identity security across hundreds of cloud accounts?

Keeper recommends automated password rotation policies, just-in-time access provisioning, and AI-powered user behavior analytics to identify anomalies across thousands of identities, making threat detection manageable without manual auditing of each account.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode covers real concepts like ephemeral accounts, just-in-time access, and post-quantum encryption, but most explanations stay at a conceptual level without delivering non-obvious insights. The discussion of AI agents needing credential management is timely but the content is largely introductory and promotional.

ephemeral accounts, meaning we create them on the fly. Those ephemeral accounts have limited permissions. They have least privilege. And as soon as that session's over, that credential's gone.
a hacker in the post-quantum space can potentially have gotten that data and then decrypted it later when the compute power makes it a simple process

Originality

5 / 20

The episode recycles well-established cybersecurity frameworks - zero trust, least privilege, zero knowledge, single pane of glass - without offering contrarian or first-principles thinking. Every concept raised is standard industry discourse repackaged as product messaging.

Standing privilege has worked for many years. It's still been risky. A lot of teams just do it because it's simpler, it's easier.
The number one route that a hacker is going to be looking for. If you get that, that's the golden key.

Guest Caliber

9 / 20

Jeremy London holds a legitimate technical leadership role at a real product company and demonstrates genuine engineering familiarity with cryptography, credential management, and AI agent pipelines. However, he functions primarily as a vendor spokesperson throughout, limiting the independent practitioner value.

we can stick on a little bit of user behavior analytics and explore using generative AI, as well as some deep learning methods to identify patterns
Our database tools try to take away the credential implementation. So we auto-inject the credentials, we create those ephemeral accounts

Specificity & Evidence

4 / 20

The episode is almost entirely devoid of concrete numbers, named customers, specific CVEs, named NIST algorithms, or cited breach data. Vague references like 'some companies have hundreds of AWS accounts' and 'supply chain attacks this year' are the closest it gets to evidence.

Some companies have hundreds of AWS accounts, so the problem really gets out of hand quickly.
We've seen a lot of the supply chain attacks this year target InfoStealer-type tools

Conversational Craft

4 / 20

The host's questions are transparently structured as product demo setups ('Can you talk a little bit about Keeper's platform and approach...what sets you apart?') with no pushback, no challenging of claims, and constant affirmatory filler. There is zero productive disagreement or probing follow-up across the entire episode.

I know Keeper does it differently. Keeper is very proactive at the forefront of anything identity related.
That's huge because that, like you mentioned, eliminates a lot of the risk

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

access16security15identity14password12user10accounts10keeper9privilege9organizations9today8management8admin8cyber7defense7systems6tools6

Episode notes

NEW EPISODE LIVE ️ Hosted by Annabelle Thomas - Cybersecurity Champion of Cyber Defense Magazine AI Is Moving Fast - But Security Must Move Faster In this Hotseat episode, Jeremy London of Keeper Security breaks down how AI is transforming cybersecurity operations - and why traditional detection and response models are no longer enough. As AI agents, automation, and privileged access expand across enterprises, Jeremy explains how real-time threat analytics, behavioral monitoring, and AI-driven security controls are redefining how defenders stay ahead. ️ What You’ll Learn How Keeper Security is helping organizations: Detect threats in seconds with AI-powered analytics Monitor 100% of privileged sessions in real time Reduce false positives and analyst fatigue Secure AI agents and prevent credential exposure Enforce Zero Trust with continuous behavioral analysis “Security teams should not have to trade velocity for operational safety.” - Jeremy London, Director of Engineering, AI & Threat Analytics - Keeper Security If you're dealing with AI, automation, and identity risk - this is a MUST-LISTEN.

Full transcript

15 min

Transcribed and scored by The B2B Podcast Index.

This is Cyber Defense Radio with your host and cybersecurity champion, Annabelle Thomas. Annabelle brings to you another globally recognized cybersecurity executive in the hot seat today. I'm your host, Annabelle Thomas, and joining me today is Jeremy London, the Director of Engineering, AI, and Threat Analytics at Keeper Security, a company that's focused on zero trust, zero knowledge, identity security, and privilege access management. Jeremy, welcome to the hot seat.

Hey, thanks for having me, Annabelle. Yeah, super excited for you to be on today. Now, I know identity has become one of the most complex challenges in cybersecurity today. It's no longer just about managing employee access, right?

We're seeing a lot of organizations are dealing with thousands, sometimes even millions of identities across users, applications, services, systems. What are you seeing right now as the biggest challenges for organizations, and what are they experiencing when it comes to identity? Yeah, identity has definitely changed over the last few years. AI and AI agents have kind of taken over the enterprise space.

So there's citizen developers building their own tools, building their new workflows out. So that has opened up kind of this new era of identity management. used to just be your username and password and logging in on one laptop. And now that same user might have 10 to 20 different types of identities that they have to manage.

So we've noticed that a lot of enterprises struggle with dealing with people building tools, leveraging AI, trying to build out new platforms, and they want to connect them to their Google accounts and databases. And all of a sudden now this one single point of contact has turned into a big mess for IT and security teams to try to manage. Right. And I know Keeper does it differently.

Keeper is very proactive at the forefront of anything identity related. I know your platform is built around that identity for security, right? You're talking about password management, secrets management, privilege access, zero trust, all of that. Can you talk a little bit about Keeper's platform and approach as it comes to identity and what sets you apart?

Yeah, totally. So the biggest component that we try to focus on is unification. One of the hard problems here is you can have all different solutions and have them kind of be disparate and discreet and try to connect and talk to each other. But it makes it very difficult to know where the password come from, who has access to this password, can this other tool access what it needs to, and can an admin kind of audit the trail of user activity through that.

So that's been the number one piece that we're trying to set ourselves apart with. We have a single plane that we kind of look through. So your passwords are in the same locations that you might access the systems from. Everything's interconnected, and all of the same enforcement logic exists around that.

So if you don't want users to have access to certain passwords, they're not shared automatically. You have to go through and kind of set up your applications and set up your groups and roles to access that. From a password perspective, that's kind of the core business that we've started in. So we have our secrets vault or password management vault.

That's where all your records and user groups and everything live. And then recently we've been moving towards privileged access management where you can now take those same user records and actually authenticate sessions, other sessions, the SSH, RDP. And then beyond that, there's SDKs and CLIs where other tools can integrate back into that. So if I need to get a password for a database I no longer storing that in a plain text file I just grabbing it from the password vault using those CLIs or SDKs We seen that process really grow as AI agents have been tapping into those systems Now when an AI agent needs to access something, they can call into those same tool chains now and be able to access those systems.

Right. And that's a huge thing with a lot of the AI adoption that's happening across all organizations. is usually people adopt AI and they don't think about the identity side. They don't think about the security side until they've got a huge mess on their hands.

So that's always something that's awesome to see that you're incorporating. Now, a major theme that I feel like is across security is least privilege and just-in-time access. Can you talk a little bit about that? Why is standing privilege such a major risk in today's environments, especially with everything that's going on with adopting all of these new tools.

How does that kind of affect the identity side and the security side for organizations? Yeah, you're hitting right on the biggest point of the era is standing privilege has worked for many years. It's still been risky. A lot of teams just do it because it's simpler, it's easier.

The next generation is looking more at ephemeral accounts, meaning we create them on the fly. Those ephemeral accounts have limited permissions. They have least privilege. And as soon as that session's over, that credential's gone.

You can't reuse it. You don't need to reuse it because if you need it again, we'll make another one. So just-in-time access is a big component to that. Maybe we don't want to be creating admin accounts at 2 a.

m. Maybe we do. And having some controls and a workflow around that allows teams to kind of move more proactively rather than just having an admin account with everything open. And as we've seen AI agents in the news be able to pick up those admin credentials and possibly do things that we don't want them to be doing, or moving down a path that a traditional user wouldn't have gone down and potentially doing something that we didn't want it to be doing.

So all of that least privilege concept is really important. Being able to create fresh accounts for those systems that need them and then be able to rotate those accounts out when they're not needed anymore really reduces a lot of those threat vectors of just having a standing privilege available. One of the big problems that we see with Windows admin controls is that's the number one route that a hacker is going to be looking for. If you get that, that's the golden key.

You can get into everything. You can change passwords. You can make new accounts. So instead of having that persisted, you can take that away, take that threat factor out, but still have a means to kind of elevate yourself using an ephemeral account to go still do the jobs that you need.

Right. And that's huge because that, like you mentioned, eliminates a lot of the risk that organizations are seeing across the board with that. Now, I know you mentioned earlier, Keeper really, really focuses on everything being in that single pane of glass. And Keeper's always introducing new capabilities like the secure database access, right, eliminating those shared credentials and untracked access paths.

Can you talk a little bit about why are systems like databases still such a high-risk area for organizations, and how does centralizing and controlling that access change the game for organizations? Yeah, so many of the latest attacks, we've seen them for years, info stealers go after hard credentials, things like database passwords, API keys, secrets and tokens, with the main goal of compromising the database, sometimes to steal information, sometimes just to encrypt it and hold it ransom.

So putting a stop in that attack vector is a very important feature You really wanna try to guard and safeguard those databases especially when customer data is there Sometimes companies have compliance and regulation affecting them So a breach could be affecting their bottom line. It could be affecting customer trust. And eventually that would lead to a company's demise. So hackers love that target point.

It's a high profit area for them. If they get in, they can potentially extract things. hash passwords, user information, and then go back and sell that. So it's a very lucrative process for them.

And we've seen a lot of the supply chain attacks this year target InfoStealer-type tools, where that's their main goal is get keys off of the system and into their system so that they can then continue attacking you or get into the databases, dump them, delete them. So it's a really important piece to monitor. Our database tools try to take away the credential implementation. So we auto-inject the credentials, we create those ephemeral accounts, and users are then scope-limited based on that new resource.

So only credentials that are generated by us are going to be able to be used and not those standing credentials, standing user privileges. So as an attacker makes a foothold anywhere, the second they disconnect, that user is useless again. So it makes it very difficult for them. They're going to get tripped up in that process.

And every time that they're connecting or moving through that system, a lot of audit logs are being generated. So we can easily build alerts and kind of inform the admin, there's something fishy going on right now. Right. Now, I know one of the other things that Kiba recently introduced is the quantum resistant encryption with the, you know, using the NIST approved algorithms.

That's not something that most companies I feel like are even thinking about yet. So I'm excited to ask you and learn more about it. But why is it important to start preparing for the quantum era threats now and even taking steps into future proofing identity security? What does that really look like?

Yeah. So our security model is very secure. We take cryptography as kind of a core concept for a lot of our product lines. And what that looks like is storing everything in a zero-knowledge way.

So in our database, it's just a bunch of encrypted data. Now, a hacker in the post-quantum space can potentially have gotten that data and then decrypted it later when the compute power makes it a simple process. So post-quantum encryption is a really important concept for us because we want to be at that cutting edge, make sure if there is a breach, if there is a problem, not even a quantum computer could be used against it. From a customer standpoint, it doesn't look any different to them.

They're still storing their passwords, but the way that that password gets encrypted and then stored safely really encourages a hacker to not look at us. It makes it very difficult to use any data if they were to try to break in and get that. From a compute perspective, it's challenging because post-quantum encryption that NIST is looking at takes a lot more effort, takes a little bit more care, makes sure that the cryptography is solid. So it's been an evolution for us to kind of step up to that gear.

A lot of competitors are looking at the same, but we definitely wanted to prioritize that, make sure the data is stored at rest in the best way possible and try to make it almost uncrackable. Right, because that's a huge component of identity security and really a lot of different security if we think about it. Now, a lot of organizations are adopting more cloud services, APIs, automation, AI workflows like you mentioned earlier which is really making identity even more critical as we seeing Where do you see identity security evolving over the next few years And what should organizations be doing now to stay ahead of that Yeah, so posture control is really important.

A lot of teams scale up. They've got cloud services, SaaS products. They may purchase and procure things over the next few years. Each one of those layers require authentication and control and management.

So the way we're trying to position ourselves is looking at how do we plug into those ecosystems so that we can also offer the same kind of management techniques. Can I rotate a password after you use it? Can I rotate a password on a schedule every time that we call on that? So each week, the key is being generated again.

That way, the user doesn't really have a foothold in any way. There's not a lot of standing privileges, even as we look at those SaaS products. So cloud accounts are a big one. That's where most servers might be running, most databases may be running.

And when I connect to a service using one of those keys, what does that key mean? Does that mean that I have admin control? And can I just copy and paste those keys locally and kind of bypass the system? Or once I use it, is it useless again?

and managing that at an automated way allows them to kind of scale that up. Some companies have hundreds of AWS accounts, so the problem really gets out of hand quickly. So having a system that you can say, rotate this password after I use it, rotate this key after I use it is incredibly helpful for that problem. Right.

Well, that's huge. And Jeremy, thank you so much for joining me today and sharing your insights. Before we close out, is there anything else you'd like to share with our audience? Yeah, really excited to see the progress that Keeper's made over the year.

We are actively looking at the next layer of threat detection and security. That's an area that I get to focus on heavily. So one of the cool things about managing these privilege sessions and identities is that we can stick on a little bit of user behavior analytics and explore using generative AI, as well as some deep learning methods to identify patterns and summarize that activity better. The hardest part is when an admin has a thousand people with 10 to 20 identities each.

That's a really tough problem to manage. Some companies only have a small team. So we try to do as much as we can to show keep or save the day, identify those points that maybe bad actors are working, maybe intentional behavior is happening, but it's not within the window of operations that you expect. So we're building all sorts of cool tooling around the use of AI to generalize some of that information, try to make the alerts and the reporting process much easier.

So I'm looking forward to seeing more of that stuff coming out from Keeper shortly. I love that. Well, thank you for that sneak preview of what's to come. For anyone listening, if you want to learn more about the incredible work Keeper Security is doing, go ahead and check out their website at KeeperSecurity.

com. That is K-E-E-P-E-R Security.com. Jeremy, thank you so much for joining me today.

You've been listening to Cyber Defense Radio. Stay tuned next time for another amazing and informative episode. CyberDefenseRadio.com is proudly part of the Cyber Defense Media Group, where InfoSec knowledge is power.

Cyber Defense TV and Cyber Defense Radio have launched 24x7x365 live streams. Visit them online today at Cyber Defense TV and Cyber Defense Radio with your host and cybersecurity champion and my good friend. Annabelle Thomas.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin JonesCyber Leaders · on Zero Trust88 / 100
  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Zero Trust87 / 100
  • Securing AI Agents: How to Stop Credential Leaks and Protect Non‑Human Identities with Idan GourCyber Sentries: AI Insight to Cloud Security · on Just-in-time access85 / 100
  • Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew GaultSecure & Simple · on Zero Trust83 / 100
  • Architectural Invisibility For Modern CybersecurityWhat's Up with Tech? · on Post-Quantum Encryption82 / 100
  • AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Zero Trust79 / 100

More from Cyber Defense Radio

All episodes →
  • Cyber Defense Radio - Phil Calvin - Chief Product Officer - Delinea - Hotseat Podcast - 2026
  • Cyber Defense Radio - Adam Bennett - Founder and CEO - Red Piranha - Hotseat Podcast - 2026
  • Cyber Defense Radio - Sumeet Singh - Founder and CEO - Aptori - Hotseat Podcast - 2026
  • Cyber Defense Radio - Chandra Shekhar Pandey - CEO - Seceon - Hotseat Podcast - 2026
  • Cyber Defense Radio - Idan Plotnik - Co-Founder & CEO - Apiiro - Hotseat Podcast - 2026
Explore the best B2B Engineering & DevTools podcasts →
All Cyber Defense Radio episodes →