The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Authority On...
The Authority On... artwork

Guide to IoT/OT Visibility and Control

The Authority On... · 2025-06-06 · 33 min

0:00--:--

Device identity has replaced the network perimeter as the primary security focus in an era where cloud adoption, remote work, and the explosive growth of IoT/OT deployments have dissolved traditional corporate network boundaries. With 90% of organizations experiencing identity-related breaches and 84% experiencing direct business impact, the scale of the problem is staggering: organizations manage an average of 45,000 machine identities that are dynamic, ephemeral, and tied to cryptographic keys and certificates. The episode breaks down three categories of IoT risk - consumer IoT, corporate IoT (printers, cameras, smart lighting), and enterprise industrial OT (manufacturing, healthcare, critical infrastructure) - explaining why these devices are such high-value targets. Over 18 billion IoT devices exist today, expected to reach nearly 40 billion by 2033, with 42% of machine identities having access to sensitive data. Traditional security approaches fail because they were built for human identities and static network perimeters. The hosts discuss how SaaS-delivered identity security solutions like KeyScaler automate device onboarding, certificate management, and policy enforcement at scale while addressing regulatory mandates (EU Cyber Resilience Act, US Cyber Trust Mark), bridging the cybersecurity skills gap, and enabling visibility across agentless and legacy devices through combined passive and active scanning techniques.

Key takeaways

  • →Machine identities outnumber human identities by approximately 82:1, with organizations managing an average of 45,000 machine identities that are constantly multiplying, making manual management impossible and driving demand for cloud-native automation platforms.
  • →IoT devices are disproportionately targeted (53 exploit attempts per week in 2024, a 46% increase year-over-year) because 42% have access to sensitive data and traditional security controls cannot be installed on legacy or edge devices, making them initial attack footholds for lateral network movement.
  • →Cloud-delivered SaaS solutions for identity management are becoming mandatory due to regulatory shifts (EU Cyber Resilience Act, NIST CSF 2.0), cybersecurity talent shortages (7.1 million professionals but 2.8 million unfilled roles), and the inability of manual processes to scale across dynamic device fleets.
  • →Comprehensive device visibility combining passive network traffic observation and active probing (OS, firmware, open ports, certificate expiration) is the foundational security step, with KeyScaler Discovery providing identification of unmanaged devices, security risks, and actionable reports for CISOs.
  • →AI-powered autonomous agents introduce novel security challenges including loss of determinism, identity role fluidity, data integrity risks, compromised supply chains, and policy violations that demand dynamic context-aware identity management and hardware-anchored identity solutions.

In this episode

  1. 1The Shift from Network Perimeter to Identity-Centric Security
  2. 2The Scale and Vulnerability of Machine and IoT Identities
  3. 3Challenges of Securing Diverse IoT and OT Devices
  4. 4Why Cloud-Delivered SaaS Solutions Are Essential for IoT Security
  5. 5Achieving Comprehensive Device Visibility Through Active and Passive Scanning
  6. 6The Role of AI in IoT Security: Capabilities and Risks

Mentioned

Microsoft AzureAWS IoTkeyscalerNIST CSF 2.0EU Cyber Resilience ActUS Cyber Trust MarkMicrosoft

Topics in this episode

EU Cyber Resilience ActIoT (Internet of Things)Zero-trust security frameworkMachine Identity ManagementOT (Operational Technology)KeyScalerCloud-delivered SaaS securityDevice identity and PKI (Public Key Infrastructure)NIST CSF 2.0Certificate management and lifecycle

Questions this episode answers

Why are IoT and OT devices such attractive targets for attackers compared to corporate laptops?

IoT/OT devices are vulnerable because they often weren't designed with traditional IT security in mind, run legacy operating systems, are deployed in remote locations with infrequent connectivity, can't run traditional security agents, and 42% have access to sensitive data - making them both easy entry points and valuable assets for attackers to use as initial footholds for lateral network movement.

How many IoT devices exist and how fast is the market growing?

Over 18 billion IoT devices were connected in 2024, expected to more than double to nearly 40 billion by 2033, with growth occurring in sensitive areas like critical infrastructure, transportation, and government, and with 53 exploit attempts per week in 2024 (a 46% increase from the previous year).

What is the ratio of machine identities to human identities in organizations?

Machine identities outnumber human identities by approximately 82-85:1, with organizations managing an average of 45,000 machine identities that are highly dynamic and ephemeral, tied to cryptographic keys and certificates that spin up and down automatically.

Why is cloud-delivered SaaS becoming mandatory for IoT device security rather than on-premises solutions?

SaaS solutions provide the scale and flexibility needed for millions of dynamic devices, enable compliance with emerging regulations (EU Cyber Resilience Act, NIST CSF 2.0, US Cyber Trust Mark) requiring continuous controls, bridge the cybersecurity skills gap through automation, reduce human error in manual certificate and policy management, and provide future-proofing through continuous updates without infrastructure upgrades.

What is KeyScaler and how does it address IoT security challenges?

KeyScaler is a cloud-native SaaS platform that automates device identity management, securely provisions digital certificates and cryptographic keys, fully automates public key infrastructure (PKI) operations, enforces dynamic policy-driven security across a device's entire lifecycle, and integrates with major cloud platforms like Azure and AWS IoT while providing centralized real-time visibility and reporting.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B54%
  • Speaker A46%

Most-used words

security72devices50device49identity36guide24compliance20critical19identities18trust18visibility15data15systems15network14scale14dynamic14risk14

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Okay, let's dive in. Think about all the connected things around us these days. I mean, it's not just your phone or smart speaker anymore, right?

Speaker B: Not at all. It's the thermostat in your office, sensors on a factory floor, medical devices, traffic lights even.

Speaker A: And that old idea, you know, the security perimeter, that hard shell around the corporate network.

Speaker B: Yeah.

Speaker A: It's just gone blown wide open by the cloud, mobile work. And especially, uh, this tidal wave of

Speaker B: connected devices and securing all these non human identities, the devices themselves, the software, everything that isn't a person logging in, that's become a huge security challenge. Traditional methods just weren't built for it.

Speaker A: Absolutely. And we've been really digging into this comprehensive guide that tackles exactly this problem. It's zeroing in on the identity of these devices, the m evolving security landscape and what the future looks like. So our goal today, our mission if you like, is to give you the absolute shortcut. We've pulled out the really critical insights

Speaker B: from this guide so you can quickly grasp, you know, why identity is now the fundamental security focus, especially for devices.

Speaker A: Yeah. And the sheer, almost unbelievable scale and vulnerability of these machine identities.

Speaker B: And why we need totally new approaches, things like automation, deep visibility and yes, even AI.

Speaker A: And crucially, how making sure a device can be trusted right, right from the very start, the moment it comes online, is the absolute bedrock.

Speaker B: It's really about cutting through all the noise to understand the core shifts and the essential strategies you need for cyber, uh, resilience and compliance In a world where the network edge is, well, it's everywhere a device exists.

Speaker A: So where do we start? The source material makes it really crystal clear. Identity has basically replaced the network perimeter as the main security focus.

Speaker B: Yeah, that traditional corporate network boundary, it's dissolving with cloud adoption, mobile access, ot merging with it, everyone working from everywhere.

Speaker A: That old castle wall analogy, it's more like a really porous membrane now.

Speaker B: And because of that shift, identity is now the number one target for attackers. It's also your main line of defense.

Speaker A: The guide highlights some pretty eye opening numbers here too. In 2024 alone, something like 90% of organizations reported at least one identity related breach. That's huge.

Speaker B: A staggering number. And out of those, 84% had a direct business impact. If an attacker can compromise an identity, whether it's a person's login or a device's credential, they've got a privileged way in.

Speaker A: And that's where the sheer volume of machine identities becomes such a critical factor. Yeah, the statistics in the guide are Honestly, they're mind blowing.

Speaker B: They really are. Machine identities outnumber human identities by a ratio of at least 82 to 1.

Speaker A: 82 to 1?

Speaker B: Yeah. And we're talking about organizations managing on average 45,000 machine identities.

Speaker A: Wow. And that includes not just devices, but software, workloads, applications, APIs.

Speaker B: Exactly. And they're multiplying constantly as companies automate and go digital.

Speaker A: Unlike human identities, which are relatively static. Right. M. Machine identities are incredibly dynamic. Ephemeral even.

Speaker B: Exactly. They're tied to cryptographic keys, certificates, spinning up and down automatically. Trying to manage this explosion manually, it's, uh. Well, it's basically impossible.

Speaker A: Yeah, you just can't.

Speaker B: And that lack of effective automated management infrastructure leaves this huge landscape incredibly vulnerable.

Speaker A: And within that massive pool of machine identities, the guide really points to devices, the whole IoT and OT world as a uniquely challenging and major vulnerability.

Speaker B: The growth numbers alone are pretty astonishing. Over 18 billion IoT devices connected in 2024.

Speaker A: 18 billion.

Speaker B: And that's expected to more than double to nearly 40 billion by 2033.

Speaker A: Unbelievable.

Speaker B: And that growth is happening everywhere, including really sensitive areas like critical infrastructure, transportation, government.

Speaker A: And these connected devices, they're high value targets for attackers, aren't they?

Speaker B: Definitely. The source points out that 42% of machine identities actually have access to sensitive data. That's compared to 37% for human identities. Add to that the fact that 90% of organizations had an identity related breach last year. You see why attackers are focusing here.

Speaker A: Yeah, the math adds up.

Speaker B: The average number of IoT exploit attempts per week in 2024 jumped to 53. That's a 46% increase from the previous year. They're actively probing these devices.

Speaker A: So why are these devices so vulnerable compared to, say, a standard corporate laptop?

Speaker B: Well, often they just weren't designed with traditional IT security in mind. Many are older legacy systems.

Speaker A: Right. Or they're deployed in remote locations. Maybe with infrequent connectivity.

Speaker B: Exactly. You can't easily install agents or traditional security controls on them.

Speaker A: And the potential consequences, they couldn't be higher. Really?

Speaker B: No. A, uh, compromised device isn't just a single point of failure. It's often that initial foothold an attacker needs to move laterally across your network.

Speaker A: Meaning they use the compromised device's access to jump to other, maybe more valuable systems.

Speaker B: Precisely. And, and in industrial or healthcare settings, this could mean disrupting critical operations, stealing

Speaker A: sensitive patient data, or even causing physical harm.

Speaker B: Absolutely. The stakes are incredibly high.

Speaker A: Plus, these IoT environments are constantly changing. Devices get reconfigured, moved, replaced, retired, all the time.

Speaker B: And if you don't have a way to secure the entire lifecycle of that device from its first moment online right through to decommissioning, you leave these gaping

Speaker A: security holes, like forgotten credentials, still active on a retired device or a device that still has access it shouldn't after being repurposed.

Speaker B: Exactly those kinds of things. So the critical takeaway here is that securing the full device journey, onboarding its operational life, decommissioning it's absolutely non negotiable

Speaker A: in this new landscape, which really highlights a core problem the guide discusses. The cybersecurity market itself is kind of struggling to keep pace with this dynamic identity centric challenge.

Speaker B: Yeah, it's a bit fragmented. It's like having a toolkit full of highly specialized wrenches. But what you really need is a unified platform, right?

Speaker A: Most security solutions were built in silos, weren't they? Traditional IAM for humans, different tools for network security, separate systems for endpoints.

Speaker B: And these siloed approaches just can't keep up when threats, especially those powered by AI, can just jump between these different domains using compromised identities.

Speaker A: And historically, security has often focused on, uh, detecting and responding after a breach happens reactive.

Speaker B: But the guide and Newer frameworks like NIST CSF 2.0 are pushing us to shift security left to make the identify

Speaker A: function foundational, especially for IoT and Edge devices. You have to establish a strong verifiable device identity first.

Speaker B: Exactly. Without that, your ability to protect, detect and respond is fundamentally weakened. How can you protect a device if you don't even have a reliable way to know what it is?

Speaker A: Makes sense. The source material then clarifies the different layers of identity we're talking about. First, you have human identities. We're kind of familiar with those managed by traditional IAM systems. Passwords, mfa, all that.

Speaker B: Still critical, obviously, but as we saw, they're a shrinking minority compared to the machines.

Speaker A: Then there's the broader category of non human identities, or nhi. This includes software entities, legal.

Speaker B: Legal entities, and the huge subset within that, machine identities. These are those ephemeral workloads, applications, APIs and devices we mentioned, right?

Speaker A: Relying on cryptographic keys and certificates, like digital passports.

Speaker B: Kind of, yeah. And they're incredibly difficult to manage manually, which leads to that vulnerability we discussed. They're estimated to outnumber humans maybe 85 to 1 now.

Speaker A: But perhaps the most challenging subset of machine identities is the IoT OT devices. These aren't your standard servers or laptops.

Speaker B: No, they're often deployed in tough environments. Factories, hospitals, smart cities, remote Pipelines, they

Speaker A: might have limited computing power, maybe legacy operating systems or unique network protocols, making

Speaker B: traditional IT security agents pretty much impossible to install. And they're incredibly diverse, meaning there's no single security approach that works for all of them.

Speaker A: And because they can be the weakest link, attackers actively target them.

Speaker B: Right. They might launch massive distributed denial of service DDA size attacks using hijacked devices, or use a compromised device as that initial entry point for lateral movement.

Speaker A: So to get a better handle on this, the guide offers a more nuanced way to classify IoT breaking it into three types. First, there's consumer IoT.

Speaker B: Yeah, the devices in our homes. Smart thermostats, cameras, wearables, generally outside corporate control, but still pose a risk if employees connect them to the corporate network or use them for work.

Speaker A: Then corporate IoT these are devices within the business environment but managed by it. Things like connected printers, office security cameras, smart lighting.

Speaker B: And these are often overlooked in security strategies, but they could be easy pivot points for an attacker already inside the office network.

Speaker A: And finally, the most complex and highest risk category, enterprise industrial IoT, often called OT for operational technology.

Speaker B: This is what you find in critical infrastructure. Manufacturing plants, healthcare facilities.

Speaker A: Super complex, often involves legacy systems you can't easily take offline. Requires continuous operation.

Speaker B: And IT teams often have very limited visibility into them. A security incident here can mean operational shutdown, huge financial loss, or even physical safety risks.

Speaker A: So pulling this together, the market's fragmentation and the unique challenges of securing these diverse device types, it really highlights a major hurdle.

Speaker B: Definitely the need is for an integrated framework that can manage all these different identity types, human and non human, in a unified way. You see reference architectures from big players like Microsoft trying to address this integration challenge.

Speaker A: Okay, so we know identity is key. We've got this massive, diverse and vulnerable landscape of devices and the existing tools are kind of fragmented. How do you even start securing this at scale? Um, the guide points strongly towards cloud delivered solutions, specifically software as a service or SaaS.

Speaker B: Yeah, a cloud approach provides that fundamental scale, scale and flexibility that, you know, traditional on premises security solutions just can't match when you're dealing with potentially millions of dynamic IoT devices.

Speaker A: Takes the burden of managing the infrastructure off your shoulders too.

Speaker B: Exactly. And there are some really compelling drivers making the shift to SaaS for IoT security. Security almost necessary right now. Well, first up, the modern regulatory landscape is changing dramatically. New laws, new frameworks emerging globally. The EU Cyber Resilience act, the US Cyber Trust Mark various national critical infrastructure mandates.

Speaker A: And these aren't just asking for periodic security checks anymore, are they?

Speaker B: No, they're demanding continuous, demonstrable security controls, proof of compliance throughout the entire device lifecycle.

Speaker A: Right, and a SaaS platform makes that centralized policy management, real time auditing and consistent enforcement across maybe thousands of distributed devices actually achievable.

Speaker B: Yeah, it does. Another massive driver is the cybersecurity skills gap we all know about.

Speaker A: Oh yeah, that's a big one.

Speaker B: The guide notes There are what, 7.1 million cybersecurity pros globally, but 2.8 million jobs unfilled. And the shortage is even worse in specialized areas like IoT security.

Speaker A: So SaaS solutions can help bridge this gap?

Speaker B: They can. They abstract away a lot of the complexity, provide simpler workflows, automate policy enforcement means you rely less on that scarce, highly specialized talent for day to day operations. With these huge device fleets.

Speaker A: And let's be honest, relying on manual processes for thousands, maybe millions of devices, it's just guaranteed to introduce human error misconfigurations, missed updates, inconsistent policies.

Speaker B: Absolutely. Automation is key here. A cloud platform can handle critical operations like device onboarding, binding identity managing, cryptographic certificates consistently and at speed. It drastically reduces errors and accelerates response times.

Speaker A: Plus, for these large dynamic fleets, manual methods simply don't scale. It's impossible, right?

Speaker B: Cloud platforms enable policy based automation for everything from provisioning devices to enforcing access control. They can make real time security decisions based on continuously updated information.

Speaker A: Which is exactly what zero trust, never trust, always verify requires.

Speaker B: Precisely. And finally, a major benefit of SaaS is future proofing. You get continuous updates, access to the latest security innovations, evolving compliance features, all without having to constantly upgrade or manage on prem infrastructure. That agility is essential against fast moving threats.

Speaker A: The guide highlights keyscaler as a service or KSAAS as a prime example of a cloud native solution designed to address these specific challenges. It's basically a hosted version of their identity security platform.

Speaker B: Yeah, it focuses on automating, uh, device identity management, securely provisioning digital certificates and keys to onboard devices quickly.

Speaker A: And it enforces dynamic policy driven security across the device's entire lifespan.

Speaker B: Exactly. And it integrates with major enterprise cloud platforms like Microsoft Azure and AWS IoT.

Speaker A: It also fully automates public key infrastructure PKI. That's the underlying system for managing those digital certificates, right? Issuing, renewing, revoking them.

Speaker B: That's right. It's built on a scalable architecture and provides that centralized real time visibility and reporting that's so critical.

Speaker A: So the benefits listed really mirror the drivers we just talked about. Enhanced security at Scale, cost and resource efficiency. Faster time to value, making regulatory compliance

Speaker B: easier and providing future ready security capabilities. Yeah.

Speaker A: Looking ahead in this section, the Guide makes an important point about security support for agentless devices. Those are things like simple sensors, PLCs, older legacy systems at the far edge that can't run traditional security software.

Speaker B: Right. Securing those is going to become increasingly important as we push computing and connectivity closer to where physical processes happen. They often lack basic visibility and enforcement capabilities, creating these significant security blind spots.

Speaker A: Which leads us perfectly into the foundational step for securing any device, agentless or not. You really can't secure what you can't see.

Speaker B: Exactly. Comprehensive visibility into your device's state is absolutely fundamental for any CISO aiming for cyber resilience and compliance.

Speaker A: You need to know every device on your network, managed or unmanaged, to understand its vulnerabilities, prioritize efforts, allocate resources.

Speaker B: Effectively unknown or undocumented assets, especially those hidden away in complex OT environments, are massive blind spots major risks.

Speaker A: The Guide discusses how to achieve this visibility in IoT environments, explaining the difference between passive and active scanning. Passive scanning just observes network traffic.

Speaker B: Yeah. It's low disruption, which is often preferred by IT and OT teams in sensitive environments. Doesn't interfere with operations.

Speaker A: But active scanning directly probes devices, asks for details like their os, open ports, protocols, firmware versions.

Speaker B: Right. And that's faster for detecting things like misconfigurations or outdated software.

Speaker A: So the key insight is that the most complete picture really comes from combining active and passive methods.

Speaker B: Yes. That gives you a deep comprehensive view while balancing thoroughness with operational safety, especially in those critical environments.

Speaker A: And when you combine that scanning data with a software bill of materials, an sbbom, uh, which is basically an ingredient list for the software on a device,

Speaker B: then you can instantly cross reference detected devices with known vulnerabilities, vulnerabilities related to their specific software components. It allows for incredibly rapid identification and response to new threats.

Speaker A: Active scanning is also crucial for some niche but vital tasks. Like getting ready for post quantum cryptography PQ readiness.

Speaker B: Exactly. It helps identify legacy or hard coded cryptographic certificates across your devices, which is essential for ensuring long term crypto resilience, particularly in OT systems that might be operational for decades.

Speaker A: But you have to be careful scanning, especially in ot. Right. To avoid disrupting critical operations.

Speaker B: Absolutely. The Guide offers practical planning. Map your network first. Use discovery tools specifically designed for OT protocols. Definitely engage and work closely with your OT stakeholders.

Speaker A: And always throttle your scan interactions. Don't overwhelm sensitive devices.

Speaker B: Right. You need to Be cautious. The Guide presents keyscaler discovery as a tool specifically built for this comprehensive visibility across both IT and ot.

Speaker A: It scans IP ranges, identifies device details, ip, Mac, M, os, open ports.

Speaker B: And crucially, it also detects specific security risks like expired or maybe long duration TLS certificates. And it flags those unmanaged devices that are basically invisible security risks.

Speaker A: And it provides actionable reports through a user friendly Interface.

Speaker B: Yeah, for CISOs, the benefits are pretty clear. Enhanced cyber resilience. Because you know your attack surface, improve compliance by documenting assets and their security posture and efficient resource allocation by prioritizing the most vulnerable devices.

Speaker A: Framing this section, you really truly cannot protect assets you don't know exist or understand. The security state of visibility is just the absolutely crucial first step.

Speaker B: Definitely. And looking ahead, real time data visibility and dashboards are going to become even more indispensable for CISOs. Managing these massive device flows consolidate device

Speaker A: identities, access logs, vulnerability exposure, policy compliance into a single dynamic view that enables much faster, more informed decisions.

Speaker B: And the Guide notes that what we consider indicators of compromise IOCs on these dashboards will broaden beyond just traditional signatures. It'll include detection of anomalous behavior as a key indicator of risk.

Speaker A: So automated AI enhanced dashboards are becoming essential to process this scale of information and flag what truly matters.

Speaker B: Which brings us rather neatly to the role of AI itself, A uh, technology that's both enabling incredible new capabilities in connected systems, but also introducing some novel security challenges.

Speaker A: Especially with the rise of agentic AI, these autonomous decision makers.

Speaker B: Right. And given the sheer speed and sophistication of modern cyber attacks, which are increasingly leveraging AI themselves, automation in our defenses is no longer just a nice to have.

Speaker A: It's an absolute imperative. Manual security processes just cannot keep pace, especially with thousands or millions of distributed IoT devices.

Speaker B: AI introduces some specific security challenges we really have to grapple with. First, there's the loss of determinism, meaning

Speaker A: the dynamic constantly learning behavior of AI, uh, agents makes establishing fixed security baselines and static policies really difficult.

Speaker B: Exactly. Security systems have to adapt to monitoring things that are designed to learn and change. It's like applying rigid rules to a constantly evolving system.

Speaker A: Then there's identity ambiguity and role fluidity. Autonomous agents can operate across different domains, adopt different roles, interact with all sorts of systems.

Speaker B: This demands dynamic context, aware identity management, not just assigning a single static identity. A, uh, digital identity needs to reflect its current role and context.

Speaker A: We also face data integrity and provenance risks. Autonomous agents process and handle data without strong crypto verification. That data could be Compromised, leading to

Speaker B: things like poisoned input data for training models or manipulated outputs. Knowing where data came from and that it hasn't been tampered with is critical.

Speaker A: The compromised AI supply chain is another big risk. We increasingly rely on external AI models, APIs, datasets, firmware, updates from third parties.

Speaker B: And this introduces risks like tampered models being deployed, vulnerable data sets, maybe even hard coded backdoors. Securing the full development and deployment lifecycle of AI components is necessary.

Speaker A: And AI agents could potentially cause autonomous policy violations and overreach.

Speaker B: Yeah, due to misaligned goals, maybe manipulation by external factors or just unforeseen interactions, an agent might violate security policies without explicit instruction.

Speaker A: So you need policy constraints baked into the AI's environment, runtime enforcement of rules and the ability for real time overrides.

Speaker B: Right. And finally there's the challenge of trust calibration and explainability. It's inherently difficult to quantify and calibrate how much we should trust an autonomous

Speaker A: agent, especially with complex or black box models where it's hard to understand why the AI made a particular decision.

Speaker B: Security teams struggle to evaluate trustworthiness without that explainability.

Speaker A: So how do we deal with this? The guide suggests that platforms like keyscaler address these AI challenges by anchoring identity right down at the hardware and cryptographic

Speaker B: level, providing a secure foundation even for autonomous agents. It offers dynamic policy enforcement that can adapt to changing AI behaviors, certificate backed device identity for verifying agent origins, real

Speaker A: time risk assessment using things like SBOMs

Speaker B: and threat intelligence, and even leverages AI for security tasks itself through integrations like Microsoft Copilot.

Speaker A: So the key takeaway here is that even as systems become more autonomous and distributed, with AI, maintaining security accountability and control is still possible. You just have to focus on that foundational layer of strong verifiable identity.

Speaker B: And flipping the coin. AI isn't just a challenge, it's also becoming a really powerful ally in securing these connected devices.

Speaker A: Because traditional security methods just can't cope with the scale, complexity and rapidly evolving threats in IOT and ot.

Speaker B: Exactly. This is where AI shines. It can analyze vast amounts of device data, telemetry logs, network traffic to detect subtle anomalies that manual processes would completely miss.

Speaker A: And it can enforce dynamic risk based policies in real time, making access decisions based on current context and risk.

Speaker B: Yes, it enhances device trust and automates security decisions at, ah, speed.

Speaker A: The business benefits outlined are pretty significant too. Enhanced threat detection by spotting those subtle

Speaker B: anomalies, scalability and automation that lets your security efforts grow seamlessly with your device

Speaker A: Estate faster incident response due to real

Speaker B: time detection and analysis and improved regulatory compliance through AI driven policy enforcement and evidence gathering.

Speaker A: The Guide specifically mentions KeyScaler AI as an example of an AML module designed to bring this intelligence and automation to IoT security.

Speaker B: Right. It uses AI, for instance, for frictionless device onboarding by validating new devices against

Speaker A: trusted patterns and enabling adaptive policy driven security by continuously learning from device activity patterns.

Speaker B: Exactly. It's also essential for detecting anomalous device behavior, flagging deviations from normal operations that could indicate a compromise or a malfunction.

Speaker A: And it helps automate compliance and risk management, aligning device behavior and configuration with zero trust principles and standards like NIST and ISO.

Speaker B: One particularly fascinating feature mentioned is its integration with Microsoft Copilot.

Speaker A: Ah, yeah, this allows security teams to use natural language queries. Just asking plain English questions about critical identity security data.

Speaker B: Exactly. Imagine asking something like hey copilot, show me devices with expired certificates last week

Speaker A: in critical infrastructure locations that could dramatically accelerate threat response. CoPilot pulls together real time device info, compares it against sbombs, checks vulnerability databases,

Speaker B: identifies weaknesses faster and provides actionable recommendations right within the tools teams are already using.

Speaker A: Like Microsoft Teams that improves visibility by making complex data accessible, speeds up response

Speaker B: by instantly interpreting vulnerability data, produces manual workload for security analysts, enhances operational resilience by, uh, quickly identifying high risk devices.

Speaker A: It ensures consistent protection across potentially millions of distributed assets.

Speaker B: Wow. As ah, cyber threats become more distributed and adaptive, embedding AI into device identity management platforms like this becomes essential not just for keeping up, but potentially getting

Speaker A: ahead and looking forward. AI's role will almost certainly expand beyond just reactive detection. Right. In a proactive regulatory alignment and risk

Speaker B: forecasting that seems likely. AI combined with ML and maybe even large language models will be able to continuously assess devices against evolving regulations, mapping configurations, software components via SBOMs, crypto usage,

Speaker A: real time telemetry to identify where assets are non compliant now and even predict future compliance gaps.

Speaker B: Exactly. This enables prioritized remediation and makes continuous audit readiness actually possible.

Speaker A: Okay, so all of this advanced security automation AI, it all relies on a fundamental critical foundation establishing trust in a device's identity right from the very beginning, before it even connects to anything sensitive.

Speaker B: Yes, and the Guide introduces dynamic device key generation or DDKG as the solution to the specific problem.

Speaker A: Ddkg? What is that exactly?

Speaker B: It basically allows devices to generate their own unique cryptographically secure identities at the earliest possible point in their life cycle,

Speaker A: like during manufacturing or upon first boot, or when they first connect to A

Speaker B: network, any of those. The key thing is that the necessary cryptographic keys are created on the device itself and are bound to its unique hardware identity.

Speaker A: And this process establishes an incredibly secure immutable root of trust for that device.

Speaker B: Precisely. And that root of trust is then used to issue digital certificates and enable all subsequent secure communications and authentication for the device's entire life.

Speaker A: So why is this so important?

Speaker B: Well, firstly, it truly enables zero trust, starts at zero touch. It establishes a verifiable cryptographic identity for the device from day one completely automatically, no human intervention needed.

Speaker A: Aligns perfectly with zero trust principles. Don't implicitly trust anything. Verify trust cryptographically from the source.

Speaker B: Exactly. Secondly, it provides security without supply chain risk because the keys are generated securely on the device and never leave it. You eliminate the risk of those keys being exposed or tampered with during manufacturing, shipping, staging, installation, which is a really

Speaker A: common and dangerous vulnerability point in the supply chain.

Speaker B: A huge one. And finally, it enables accelerated onboarding at scale. DDKG supports fully automated, policy driven onboarding for potentially millions of heterogeneous devices.

Speaker A: So devices can essentially introduce themselves securely and be automatically brought into your security framework, reducing manual overhead and errors compared to trying to provision keys manually.

Speaker B: Right. It streamlines the whole process. Incredibly, the guide also notes the significant value this brings to partner ecosystems, manufacturers, system integrators, by simplifying their onboarding processes and helping them meet compliance requirements for their devices.

Speaker A: So the key takeaway is that DDKG solves that fundamental challenge of securely onboarding devices at scale. It eliminates a critical vulnerability early on, building trust right from the ground up, uh, that's foundational. Now, layer over all of these technical challenges and solutions is the constantly evolving regulatory landscape for IoT and OT security. Governments, standards bodies worldwide. They're definitely stepping up their expectations.

Speaker B: Oh, absolutely. As connected devices become more critical to society and the economy, the requirements are getting stricter.

Speaker A: We're seeing a wave of new laws and updated frameworks. The EU Cyber Resilience act, for example,

Speaker B: mandates secure by design principles clear processes for vulnerability handling throughout a product's life.

Speaker A: The US Executive Order 14028 and the NIST IoT frameworks emphasize supply chain security, integrating IoT into zero trust architectures.

Speaker B: The UK PSTI act mandates basic security features in consumer devices. And established standards like ETSI EN 303645 and IEC 62443 for industrial control systems are constantly being updated.

Speaker A: And critically, these frameworks are moving beyond just checkbox compliance at the manufacturing stage.

Speaker B: Right. Completely they're demanding demonstrable proof of continuous compliance across the entire device lifecycle. Production, operation, end of life the NIST

Speaker A: IoT security guidelines themselves are being revised for 2025 and the guide mentions initial discussions highlighting an increased emphasis on governance, identifying all assets, integrating IoT security into broader enterprise practices.

Speaker B: And what's crucial is this revision positions device identity and trust as that absolute foundational element. It has to be established before you can even effectively implement, protect, detect, respond or recover functions.

Speaker A: Early NIST workshops identified three key themes for this revision. Shifting to lifecycle centric security, improving risk of visibility and evaluation and ensuring effective communication around IoT security.

Speaker B: All of which ties right back to identity and visibility.

Speaker A: Given the scale and complexity we've discussed, maintaining this level of compliance manually for a big IoT deployment.

Speaker B: Mhm.

Speaker A: It's just impossible, isn't it?

Speaker B: Utterly impossible. Think about the obligations securely onboarding devices, continuously managing their credentials and certificates, maintaining audit trails, managing vulnerabilities in real time. These tasks would completely overwhelm security teams without automation.

Speaker A: Relying on manual processes just dramatically increases the risk of missing critical deadlines, overlooking vulnerabilities that could lead to breaches and ultimately failing audits.

Speaker B: Definitely looking ahead. Compliance assessment isn't going to be a periodic activity anymore. It's going to be a continuous central priority.

Speaker A: And this is where the AI ML LLM UM technologies we discussed earlier come back into play.

Speaker B: Yes, they'll enable continuous assessment automatically mapping device configurations, software components via SBOMs, cryptographic usage, real time telemetry against evolving regulatory requirements.

Speaker A: This proactive approach can instantly expose assets that are currently non compliant, forecast potential

Speaker B: future gaps based on known vulnerabilities or expiring certificates. Yeah, and enable security teams to prioritize remediation efforts effectively. It's about being audit ready at any moment.

Speaker A: The Guide explains how the KeyScaler platform supports this complex compliance need by providing that essential automation and intelligence.

Speaker B: It aligns with core regulatory requirements by automating the identity lifecycle management, providing audit ready logging and evidence trails, integrating SBOM and vulnerability data for continuous assessment, enforcing

Speaker A: policies at scale across diverse devices and

Speaker B: its architecture is designed to be compatible with standards like NIST, ETSI and IEC 62443.

Speaker A: So the key takeaway here is that the compliance landscape is incredibly dynamic. Organizations need security platforms that can evolve

Speaker B: with these frameworks and automation is absolutely key to staying ahead and building a demonstrable evidence based security posture.

Speaker A: So pulling together everything we've discussed from the guide, it paints a pretty clear picture of the challenges in securing connected devices, but also lays out a path forward built on several key pillars.

Speaker B: It really does.

Speaker A: It strongly reinforces that achieving strong device identity security isn't just good practice anymore, it's a fundamental prerequisite for implementing zero

Speaker B: trust, for meeting those increasingly stringent compliance

Speaker A: mandates, and for ensuring the operational resilience of modern digital systems.

Speaker B: Based on the Guide's conclusion, the core requirements for success in device identity security are really boil down to a few things. First, automation absolutely essential for scale and real time response.

Speaker A: Second, full lifecycle management, securing devices beyond just onboarding, covering identity rotation, revocation, security commissioning.

Speaker B: Third, software based delivery like saws for agility and scalability. Fourth, visibility, continuously discovering and monitoring all devices managed or unmanaged, understanding their configurations,

Speaker A: credentials, vulnerabilities and finally, AI emerging as a powerful force multiplier for analyzing all that telemetry, automatically detecting non compliant behavior, even forecasting future risks and compliance gaps.

Speaker B: Organizations that prioritize and implement solutions built on these core pillars comprehensive identity management, automation, visibility, leveraging AI those are the ones that will be best equipped equip

Speaker A: to protect their connected assets, confidently meet audit requirements and securely scale their digital transformation initiatives. In this new identity centric world, it's

Speaker B: certainly a complex challenge securing this explosion of connected devices and it's clear traditional security methods just aren't sufficient anymore. But by understanding identity as the new perimeter and strategically leveraging automation, deep visibility and powerful technologies like dynamic device key generation and AI, organizations really can build significantly stronger, more resilient digital foundations.

Speaker A: So as cyber threats continue to evolve at breakneck speed and regulatory demands keep increasing, here's maybe a question to consider. How can organizations not just ensure their security strategies are keeping pace, but are actively anticipating the future risks and compliance needs, especially those stemming from autonomous systems in these really dynamic device environments?

Speaker B: M Something to think about? Definitely.

Speaker A: Absolutely. Thanks for diving deep into this with us today.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 064: CONNECTIONS vs COLLECTIONS: Why Telcos Keep LosingTechBurst Talks · on IoT (Internet of Things)86 / 100
  • The emerging world of machine customers - Interview with Katja ForbesPunk CX · on IoT (Internet of Things)81 / 100
  • Why Enterprise Software Buyers Now Demand a Data Encryption AuditB2B SaaS Talks with Fexingo · on EU Cyber Resilience Act68 / 100
  • Episode 159: The New Security Stack: Doors, Data, and AI With Jeffrey FriedmanThe Virtual CISO Podcast · on Zero-trust security framework61 / 100
  • BA Bites - From 5G to Smart Cities: Finding Business Opportunities in Connected Data and ProcessesThe Better Business Analyst Podcast · on IoT (Internet of Things)56 / 100
  • Innovating Across Borders with Lawrence EtaThe Innovators of Things · on IoT (Internet of Things)

More from The Authority On...

All episodes →
  • Post-Quantum Cryptography56 / 100
  • AI and Non-human Identities80 / 100
  • Strategic Security in a Connected World: A Conversation with Grace Cassy
  • Introducing DA Academy
  • What's the Emergency? Public Safety in a World of IOT and Cybersecurity with David Ihrie, CTO at VIPC
Explore the best B2B Engineering & DevTools podcasts →
All The Authority On... episodes →