The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cyber Security Business
Cyber Security Business artwork

Identity

Cyber Security Business · 2023-09-20 · 23 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density7 / 20
Originality5 / 20
Guest Caliber11 / 20
Specificity & Evidence9 / 20
Conversational Craft6 / 20

Rob Preta shares four years of experience building ACV Auctions' identity program from the ground up, offering practical guidance on why identity must be the foundation of any security architecture. He emphasizes that in mobile and cloud-first organizations, identity is literally the primary entrance to networks. The conversation covers essential table stakes - multi-factor authentication paired with SSO solutions - and explores how to mature beyond basics into governance, lifecycle management, and privileged access management. Preta advocates for Okta as a modern IAM platform that consolidates universal directory, SSO, adaptive MFA, and IGA capabilities, while acknowledging that no single vendor solves all identity needs; organizations must evaluate solutions like Ping, Microsoft Azure AD, and specialized PAM tools like BeyondTrust or CyberArk based on their specific architecture. A key theme is balancing people and process with technology - early alignment with HR, legal, and business units prevents implementation delays. The discussion also addresses board-level budget justification through cost avoidance and ROI metrics, and looks ahead to passwordless authentication as the next evolution in identity security.

Key takeaways

  • →Multi-factor authentication paired with SSO should be table stakes for every application, regardless of organization size or maturity level.
  • →People and process must precede technology; align with HR, legal, and business units early to avoid rework and accelerate identity program rollout.
  • →No single IAM vendor solves all identity domains - assess SSO, MFA, IGA, PAM, and secrets management separately, choosing tools that fit your cloud-first architecture.
  • →Identity programs justify budget through cost avoidance and ROI (e.g., automation of access provisioning saves FTE time) rather than solely on compliance risk.
  • →Passwordless authentication based on device trust, network context, and behavior - not just passwords or push notifications - will replace traditional MFA over the next 2 - 3 years.

In this episode

  1. 1Introduction and Rob's Background in Cybersecurity
  2. 2Identity as the Cornerstone of Security Programs
  3. 3Multi-Factor Authentication and SSO Implementation
  4. 4People, Process, and Technology Balance in IAM
  5. 5Identity and Access Management Tool Selection: Okta and Alternatives
  6. 6Challenges and Cross-Departmental Buy-In
  7. 7Budget Justification and Business Alignment
  8. 8AI, Passwordless Authentication, and Future of Identity

Mentioned

Kevin PouchetRob PretaKlogixACV AuctionsDelaware NorthOktaActive DirectoryAzure ADPingBeyondTrustCyberArkMicrosoft

Guests

Rob Preta

Topics in this episode

Multi-factor authentication (MFA)Active DirectorySingle Sign-On (SSO)OktaPrivileged access management (PAM)Ping Identityidentity and access management (IAM)Identity Governance and Administration (IGA)BeyondTrustAzure AD

Questions this episode answers

What is the most important aspect of an identity and access management program?

Multi-factor authentication on all applications, paired with SSO, is the most critical foundation. Rob Preta cites this as the first priority and uses the saying 'MFA all the things' because every password is compromised and only MFA truly mitigates that risk.

Should identity be the cornerstone of established security programs, or just new ones?

Yes, identity must be the cornerstone regardless of program age. Everyone has an identity and must log in somewhere; securing those logins is one of the easiest ways to stop attackers, so it applies universally across all organizations.

What IAM platform does Rob Preta recommend for most organizations?

Rob favors Okta because it provides universal directory, SSO, multi-factor authentication, adaptive policies, and built-in IGA and lifecycle management - reducing the need to manage Active Directory or separate vendors. However, he stresses no single platform fits all organizations.

How do you justify identity program budget to executives and boards?

Frame identity through cost-benefit analysis and cost avoidance (e.g., automation of access provisioning saves FTE time). Identity resonates with boards because they understand it intuitively and recognize it protects executive access, unlike technical terms like XDR.

What is the biggest challenge when implementing an identity program?

Securing buy-in from non-IT business units - particularly HR and legal - early in the process. Delays in defining roles or obtaining HR data can slow rollout of role-based access and lifecycle management features.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

7 / 20

The episode is padded with widely-known security fundamentals (MFA good, passwords bad, SSO pairs with MFA) and generic lifecycle advice. A handful of practical operational points - like the challenge of getting HR alignment before rolling out RBAC, and framing lifecycle management ROI as FTE time reclaimed - add marginal value but are still not novel to any experienced practitioner.

I have now automated that process and given back an FTE time for half a day
SMS multifactor is weak sauce, uh, based on, you know, other means of exploitation

Originality

5 / 20

Nearly every claim is a recycled take from mainstream security discourse: MFA all the things, identity is the new perimeter, passwordless is the future, AI might bypass MFA. No contrarian arguments, no first-principles reasoning, and no perspective that challenges conventional wisdom in any meaningful way.

I actually had a poster that said mfa all the things
multi factor in the way that we've been doing it is starting to dwindle a little bit

Guest Caliber

11 / 20

Rob Preta is a genuine practitioner who built a security program from scratch at a real unicorn startup, which gives him credible operational standing. However, he speaks primarily at a conceptual level rather than sharing hard-won specifics, and his insights don't transcend what a mid-level security manager might offer.

With the idea to start and create a new cyber, start new cyber security program from scratch
I'm an old active directory admin engineer, architect

Specificity & Evidence

9 / 20

The guest names specific vendors (Okta, Beyond Trust, CyberArk, Ping, Microsoft E5/Azure AD) with some useful context about their capabilities and trade-offs, which is the episode's strongest dimension. However, there are no real metrics, breach data, timelines, headcount figures, or dollar amounts to anchor any claim.

they have workflows, uh, when you start talking about iga, they start now having IGA piece, uh, lifecycle management
Beyond trust comes to mind. Um, the old cyber Arc, uh, from a PAM solution

Conversational Craft

6 / 20

The host asks almost exclusively leading or open-ended softballs, explicitly avoids framing a question as criticism ('with your impeccable track record, maybe you haven't made mistakes'), and closes with effusive praise rather than synthesis. There is no meaningful pushback, no probing follow-up, and no productive tension at any point in the conversation.

with your impeccable track record, maybe you haven't made mistakes, but what, maybe what are the biggest challenges
This was awesome. Um, thank you for potting with me, if that's a word. This was great. Um, uh, thanks for coming on. There was so many great nuggets of information you provided.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A69%
  • Speaker B31%

Most-used words

identity33program20security16start14based10technology10important9leverage9podcast8sure8management8organization8multi8factor8understand7different7

Episode notes

Discussing all things Identity and Access Management with Rob Preta, Head of Cybersecurity at ACV Auctions - why IAM is so important, what are best practices, which IAM solutions he uses in his security program, challenges he's faced, advice for justifying budget, and how AI and ChatGPT are now affecting IAM.

Full transcript

23 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome to cybersecurity business. I'm your host, Kevin Pouchet, CEO of Klogix. In our podcast, we interview CISOs and other security leaders to hear their advice about the business of information security. This podcast gives our listeners actionable takeaways to help them increase the effectiveness of their security programs. And today we're joined by Rob Preta, head of cybersecurity at ACV Auctions, where he's been for almost four years. Rob has many years of experience with other large organizations managing successful security programs, and he's joined us today to have a discussion on the growing topic of identity. Rob, welcome to the podcast.

Speaker A: Thanks Kevin. Glad to be here.

Speaker B: I'm glad you're here too. I was really excited when I, uh, was told that you would agree to be on the podcast. Right. I had heard your name many times. Times, but we hadn't met. So I'm, uh, uh, I'm grateful you're here.

Speaker A: Thanks. Yeah, same on, same on the other end. I heard your name too. I was like, hey, what a great time to talk.

Speaker B: Perfect. So for those that actually don't know you, why don't we just take a minute or so, maybe give some background on your role at acv, sort of what, what you're, what you're doing there and uh, and sort of how you got to be head of cyber.

Speaker A: Sure. Um, so you know, doing some kind of form of IT work for 20 plus some odd years, uh, over the past couple years, really got into cybersecurity. Always was interested in security. Uh, but as my career progressed I wanted to really dive in and take on a more senior security role. Left my last company, Delaware, uh, North, as their manager, uh, of security and came over to acv, which was uh, one of Buffalo's first uh, or more prominent startups, uh, Buffalo's first unicorn. With the idea to start and create a new cyber, start new cyber security program from scratch. And that was where I begin my journey here.

Speaker B: That was four years ago.

Speaker A: Yep.

Speaker B: So let's, so let's jump into the topic of identity and let's sort of make it specific as it relates to your program. Right. The program that you've been building and maturing for four years. So how does your security program, how do you approach identity and access management and maybe even frame it with sort of uh, how you define identity and access management as a program.

Speaker A: Sure. So for me identity is paramount. We live in a world and specifically at acv, where the borders are malleable. I don't have old fashioned kind of infrastructure. I don't have a large castle and moat type system with, you know, big borders and big office. My workforce is mostly and primarily mobile. And of course if you go back to when I was hired, which was beginning of the pandemic, everybody was mobile at the time. So identity really is the primary source of entrance into my networks. So taking a really modern approach to how we want to handle identity based on authentication to a multitude of SaaS applications as well as our own internal applications, uh, became my foremost project when I started and from then on have just kept evolving it into the program that it is today.

Speaker B: Would you consider it your most important program?

Speaker A: It is, it's the cornerstone. In fact, I still think identity. I mean there's the old saying, you know, what's the biggest problem in security? And it's the users and how do you solve user problem? It's identity. So, uh, correctly and accurately being able to secure a person's identity throughout the lifecycle as they work in your organization, uh, has to be uh, to paramount or cornerstone of any program.

Speaker B: So let me ask you this. So you've had the luxury of being able to build a program from the ground up, right? You know, I say luxury. I know you've put in a lot of hard work and did a tremendous job. But organizations that have sort of been around or have, have had a cyber program around for many, many years, should identity be the cornerstone of those programs as well?

Speaker A: I think so. I mean everybody needs, no matter where you go, no matter how you're security program is created, no matter what you're doing, identity is part of your ecosystem, security wise, it wise everywhere. So everybody has an identity, everybody has to log into some system, I don't know any place that doesn't have a login of some kind, uh, securing those logins, that's the one of the easiest ways for an attacker to get in by having, you know, the old weak passwords or lack of uh, controls around them.

Speaker B: So when it comes to your program, you know, maybe talk about what do you think the most important aspects are or maybe even some of the least important aspects. How do you prioritize?

Speaker A: Yeah, so I think the, one of the most important, the two most important aspects, um, are going to sound pretty much what everyone will always talk about, which is multi factor, all the things. It's actually one of my, my favorite sayings in the world is uh, I actually had a poster that said mfa all the things. So multi factor to everything that comes into your organization. So using, you know, any kind of technology that you can multifactor the front door. That's one of the primary, you know, things that I will always do actually was the very first thing when I came to ACB is I said I want to multifactor all our applications. But to do that means you need a uh, program or a technology that's going to be able to put everything behind it. So when you pair it, you have to pair it with an SSO type application as well. So you have this idea of uh, being able to single sign on into your applications and then putting multi factor in front of that, giving you a secure experience for just about every application that can support it.

Speaker B: It's true. It should be table stakes. You know, it amazes me that even, you know, if we flip this on, on its head for a second and at me as a consumer that some extremely large banks, I won't name any, still don't have a built in, easily ready MFA solution for consumers. And that sort of blows my mind.

Speaker A: I think it's actually unconscionable in this environment nowadays multifactor in any way even. All right, so SMS multifactor is weak sauce, uh, based on, you know, other means of exploitation, not going down that road. But at least it's something, it's beyond the normal password. All of our passwords right now, every single one of us, anybody who listens to this, your password is compromised. I promise you it is. Um, so the only way to mitigate that in any kind of uh, truest form is a multi factor.

Speaker B: Right, Right. So talk a little bit then about um, people and process versus technology is one more important than the other.

Speaker A: Uh, they are on equal footings. Uh, at certain points in a program you could argue one will outweigh the other. Uh, but people in process is where you begin. Um, and then technology will always be the way to uh, alleviate some of that pressure. And large organizations that are well established, it's people in process that's probably been running the show forever. So they're going to be important to those programs to understand what they've been doing. Uh, I had the luxury and it really was a luxury. You weren't wrong about that Kevin, of coming into a place where we were at a smaller uh, juncture with users that I was able to put in and leverage technology and quote unquote, heavy handedly be able to roll it out to all the users in one fell swoop. Doesn't always happen in a large organization. So you really do need a balance too. And as you progress through Identity the people in process that, that are involved, uh, become more and more relevant because as you, you know, we'll probably talk about this a little bit, but you know, when we start talking about what's the basic table stakes. Sso, you know, a universal, uh, director or middle director, whatever you want to call it, um, and then the mfa. But you got to get into like governance and life cycle management and doing things like HR as a master, you know, and there you're gonna need people and other processes involved that'll really leverage those uh, tools.

Speaker B: Right. And I mean you do need technology as a means of enforcement for some good, good policy. So, so I get that. I think that's a pretty, pretty solid answer when it comes down to technology. I'm going to pre preface this question by saying, you know, there's no one technology in any space that is the be all end all for every single organization because every organization's environment and requirements uh, are different. But that being said, um, what IAM solutions or tools do you prefer? Are there certain vendors that you really rely on that you found, you know, meet the spirit of your requirements and your program better than others? And it could be IGA, Pam, IDAs, any of the, the categories you just mentioned.

Speaker A: Sure. Um, I mean, you know, you're absolutely right though, you know, and that actually comes, you know, just to reiterate, you know, when you have people in process, you can pretty much leverage almost any technology in any way if you're, we have the people or the manpower to run it. That said, um, for me an IM solution that I, that I tend to fall on is Okta. Um, I've been following them or a fan of theirs for years. A little background is I'm an old active directory admin engineer, architect. Um, I never want to look at that thing again, um, if I don't have um, but uh, that said, solutions like Okta actually give me the leverage to not have to uh, find things like, like having my own LDAP director or anything like that. I could use Okta's UD for my universal directory, for my centralized uh, management system of users as well as uh, they have all capability like sso, multi factor adaptive multi factor networking policies, user trust modeling. These are the things that I, that I, that I look for in a solution as well. And to top it off too, depending on your organization and how big you are and what you're trying to leverage, they have a lot of the, the next layers of identity too. So when you start moving down the list, you're talking about automation. So they have workflows, uh, when you start talking about iga, they start now having IGA piece, uh, lifecycle management which is, you know, taking somebody from a user who starts up and adding an application and then when they leave, uh, removing those applications. They have a lot of these features automatically built in at some level, you know, whether they're an add on cost or not. Um, so I like to leverage Octalattis for that. Uh, from other solutions too. You know, we can start talking about, you know, other parts of identity programs. So as identity matures you start having this conversation around, you know, privileged account management or privileged access management, what are we doing there? And then you have conversations around, well our keys and key rotation is that identity as well. So different product for those kind of leveraging. And for that, you know, I used, I've used different products in the past too. Um, beyond trust comes to mind. Um, the old cyber Arc, uh, from a PAM solution too. Uh, but that space is changing rapidly as well. Um, because again you know, I'm a cloud environment, I'm a SaaS environment. So the old fashioned technologies that I uh, used to be able to leverage don't exactly work the same in a SaaS environment. So.

Speaker B: Yeah, so in other words you have certain technologies that you rely on, but if you look at the full landscape of all the tenants under Identity. Right. There's no one button to push. Right. There's, there's multiple players and that's even changing based on how fast the security landscape is changing.

Speaker A: Yeah, I mean I really like, I mean I'm a, I'm a big fan of vetting new technologies. Even, even incumbents, even big incumbents like Okta. I mean listen. Or any identity solution super sticky in your organization for sure. Identity is a horrible thing. Let's not, I'm not going to. You can't lie about it. Nobody likes to do it. You try to do it one and done two. But it doesn't mean someone's not building the better mousetrap out there. So you start looking at some of the, the newer vendors that are coming out, you start revisiting the old ones. You know, I've looked at Ping again recently just to see if they're keeping up with the Joneses, you know. Yeah, what about uh, some of the other ones that are coming up? There's even a point where you and I can have a conversation around Microsoft and having a large E5 license or a huge uh, EA structure with inside Microsoft where their um, Azure ad makes sense for an organization, it really is important to understand what you're trying to accomplish with your identity program and how to leverage it.

Speaker B: We could do an entire podcast on what components make sense out of Microsoft to use and what don't. But that would be a pretty amazing podcast. But maybe next time for another day. For another day for sure. Uh, as you've been building out the identity aspects of your program over the past four years, what were, were there any sort of, you know, mistakes you made that you, uh, may want to pass on or. I, you know, maybe that's not the way to phrase it. With your impeccable track record, maybe you haven't made mistakes, but what, maybe what are the biggest challenges you've, you've faced or face? How's that?

Speaker A: So I think, you know, one of the, one of the bigger things is it's going to come down to buy in from other parts of the business. So you'll get buy in almost all the time, 100% from security, 99% from IT. But when you have conversations around, well, what's your next step? So for example, I would have preferred to say leverage conversations with, you know, HR and legal, um, a little earlier on based on their requirements to be able to roll out parts of the program sooner. Um, so for example, when um, we're trying to do things like role based access, well, you need to have your roles in order first. Um, and for that, that's a, that's a heavy lift and you can't expect, you know, an entire HR department to start fixing, you know, HR roles or um, titles because you want it. So leveraging those conversations with business units first and then, you know, one of the, one of the bigger things I want to start stressing is lining up with business and business outcomes and objectives based on their priorities as well. So not that I had much of a pushback with it too, but having that ability, um, and having those as a driver on your. Any program you're doing doesn't have to be about identity is always going to benefit, uh, and behoove you as you try to move something forward or press it.

Speaker B: So you mentioned buy in, right? Let's talk about buying at a higher level in terms of justifying explaining budget, say to your cio, uh, and, or even the board. Like, is this challenging? You know, I imagine, at least from what I see, identity is one of those topics. A, it does cross departments for sure, as you just mentioned. But not only the CIO deeply cares about it, but, uh, it seems boards do as well because, well, frankly, their boards, or at least the executive leadership team, those are some of the most important identities that you're actually trying to protect. So does that make it easier to justify budget?

Speaker A: Sometimes? I mean, it does. You know, identity, I will say, generally speaking, from, from I've justified it a couple different times to different groups of people and different executive boards doesn't usually have a huge amount of why are we doing this Conversation. But, um, regardless of that, you still have to have the ROI conversation. You still have to talk about, you know, cost benefit analysis, all the, all the fun business terms that every CISO and security professional loves to talk about. It is a requirement no matter what we're doing. Uh, in this, we know, we start talking about cost avoidance. For example, if I'm justifying, uh, something like life cycle management, I then can say there's an offset based on engineering cost that I don't need to have someone sit behind a computer and click into seven different applications to give somebody, uh, access to them. Instead, I have now automated that process and given back an FTE time for half a day. How about that? So we do it. We can talk about those kind of benefits. Um, so we, so I do those things when I'm trying to present. Um, but when it does come to the conversation. You mentioned this before, you know, multi factor and things like this have been now permeated out through these executives through the boards and you know, just talk about other parts of, you know, government agencies are now getting really involved in cybersecurity. Uh, it does make the conversation a little easier, especially on things that boards understand. Identity is something that boards understand. They don't necessarily understand something like if I start talking about xdr, I think I lose them, but identity, they really grasp onto.

Speaker B: Well, some other buzzy terms that we're hearing a lot from executives and boards are things like AI. Right? I mean, people understand what AI is, but I don't know if they necessarily fully understand what role AI is playing in your security program and I guess more importantly what role it could play in the future. Right. Same chat GPT like it. Will identity become a larger issue because of these types of things?

Speaker A: Well, I think it, you know, is it unaffected? Uh, I think it's in a similar issue to, you know, just about anything else. You're going to require access to these tools. You know, uh, there will be some, you know, I guess it's an overall concern with, you know, AI and what's going on with inside, uh, recent exploitable attacks and them using AI to create them. So it's yet to be seen. Um, I think the AI chatgpt is just a general worry around the cyber community right now and what is going to behold for the rest of us in the future here, um, and how it's going to be malleable based on some of the information, uh, that it's going to be able to find on its own, um, and then crater or, or execute their own attacks. So I'm interested especially you know, when we talk about identity too. You know, are ah, they going to be able to do anything around like bypassing multi factor in those kind of ways too? They've already, I mean people already do this now but you know, uh, an automated system doing it, I don't know. So there's a concern there for sure.

Speaker B: Well, you've touched. So I have one more question for you and you've sort of started touching on that, but really just through the lens I think of like AI for example. But what I'm wondering is like how do you think identity is going to change like over the next three year period? I don't know if you've built that into your sort of two or three year roadmap, if you sort of have some ideas in terms of what to expect.

Speaker A: Yeah, I think passwordless is really going to be the key to this conversation.

Speaker B: Okay.

Speaker A: Uh, and you know, identity verification, not based on you know, some of the old fashioned methodologies. I would even argue that multifactor in the way that we've been doing it is starting to dwindle a little bit. Uh, so over the next couple years, know that real passwordless, that real you are who you say you are. You know, you are Kevin. You know, not based on, because I know your password, not because I know I have your phone and took a push notification. Um, but you are because the network you're on, the computer you're on as well as the phone as well. You know, all these, all these little tidbits and pieces add up to your identity. You know people talk about um, this passwordless and if you look at it on the surface right now it looks like it's cool technology. But also I think that it's becoming harder and harder for uh, us to implement it only because a lot of the companies that we are dealing with still aren't getting the hint that we have to get rid of the password.

Speaker B: Yeah.

Speaker A: Wow.

Speaker B: I totally agree. This was awesome. Um, thank you for potting with me, if that's a word. This was great. Um, uh, thanks for coming on. There was so many great nuggets of information you provided. I know I'm looking forward to hearing this in its entirety again. So thank you, Rob. That was really helpful.

Speaker A: Great. No, thank you.

Speaker B: Um, I'm sure our listeners are going to think the same. Um, and if anybody wants to hear this podcast in its entirety, you can hear this and all our other podcasts@klogicsecurity.com podcast and if you have any questions for us or for Rob, uh, you know, you can certainly reach out to us@infoailogicsecurity.com or directly on any of our linkedins. Rob, thanks, uh, again, it was a real pleasure.

Speaker A: Thank you, Kevin. Enjoyed myself.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Rebooting Enterprise AI with MCP and KubernetesPractical AI · on Okta88 / 100
  • Inverted Podcast #24: What’s Happening in Identity?The Inverted Podcast · on Identity Governance and Administration (IGA)80 / 100
  • AI-Powered Forensics: How Attackers Automate BreachesCloud Security Podcast · on Active Directory78 / 100
  • Christina Tubb - The channel partner as your local bodyguardPartnerships Unraveled · on Ping Identity77 / 100
  • Why AI Agents Are a Security Wild West with David from Arcjet and Johannes from CakewalkThis Much I Know · on identity and access management (IAM)77 / 100
  • Harish Peri (Okta): When the Thing Accessing Your Systems Has a BrainThe Road to Accountable AI · on Okta77 / 100

More from Cyber Security Business

All episodes →
  • AI Compute as a Business Risk70 / 100
  • The Path to CISO61 / 100
  • Creating an AI Security Culture63 / 100
  • Future-proofing and Storytelling80 / 100
  • Hungry for CISO Trends72 / 100
All Cyber Security Business episodes →