The Business of Cybersecurity · 2026-08-30 · 25 min
Key moments - from our scoring
Substance score
49 / 100
Five dimensions, 20 points each
Spencer Young, SVP of International Markets at Delinea, discusses the fundamental shift in identity security needed for AI agents. While traditional security focused on authenticating users once at login, autonomous agents operating at machine speed can exploit legitimate access to perform unauthorized actions - exemplified by breaches at HuggingFace and OpenAI where agents completed their intended tasks but accessed unintended systems. Delinea's research found 80-85% of organizations believe they can discover non-human identities, yet only 30% validate their activity in real time, creating a critical confidence gap. The solution involves runtime authorization that evaluates every proposed action before execution, injects credentials just-in-time scoped to specific tasks, and immediately revokes them upon completion. This approach eliminates standing privileges and prevents compromised agents from accessing credentials. Young emphasizes that while technology enforces controls at machine speed, humans must define policies, set risk boundaries, and maintain accountability - security leaders cannot outsource accountability to AI systems.
Runtime authorization evaluates every action an agent proposes to take before execution, rather than just confirming identity once at login. It ensures that each tool call, database query, or command is approved in real-time based on whether it aligns with the agent's intended task, whereas traditional authentication only verifies who or what connected to a system.
Agents use legitimate credentials to complete their assigned tasks at machine speed; if an attacker injects hidden instructions or the agent's logic is compromised, it can access systems and move data in unintended ways while appearing fully authorized. A single agent session can involve dozens of tool calls across different systems, each of which can be exploited.
Credentials are injected only when the agent is about to access a specific system for its assigned task and revoked immediately after. The agent never stores or sees the credential, so if it is compromised by an attacker, they cannot find or reuse the password to access other systems.
Delinea's research found that while 80-85% of respondents felt confident they could discover non-human identities, only 30% were able to validate their activity in real time - a significant gap that leaves organizations vulnerable to undetected agent misuse.
First, identify sensitive systems that could cause material harm and enforce pre-execution evaluation of every access attempt. Second, provide agents access only when needed for specific tasks, then immediately revoke it (avoid standing privilege). Third, define agent-specific policies, establish clear ownership and accountability, and maintain detailed audit trails of all agent actions.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode surfaces a genuinely useful framing - continuous per-action authorization vs. one-time authentication - and a credible confidence-gap statistic, but the core ideas are repeated across the 25 minutes rather than built upon, and there is significant host throat-clearing and vendor framing that displaces new ideas.
80 to 85% of the companies we talk to say they're very confident in their ability to discover non human identities. Only 30% of them actually validate non human identity usage and AI activity in real time
we take away the notion of any standing privilege or access to the credential that typically a human would use to get access to things. And we inject the credential at the point that the agent is about to get access to the thing
The reframing of PAM (privileged access management) concepts - zero standing privilege, just-in-time credentials - applied to agentic AI is a reasonable extension rather than genuinely novel thinking; the one mildly contrarian claim is that agents don't introduce new risks but amplify existing ones, though this isn't developed into a deeper argument.
I don't think the agents themselves introduce new security risk per se, but what they do is they instrument those risks that are already there and they can do that at a speed and a scale that we have just never contemplated or seen before
authenticating them once is just not enough. We've got to be able to effectively authenticate, think of it this way, authenticate it with every single action that it's taking
Spencer Young has genuine practitioner depth - 34 years in IT, hands-on background in secure software for NHS and financial trading systems before moving into identity - but he functions primarily as a vendor SVP promoting a recent product release, which limits the candour and independence a higher score requires.
I've been in it for about 34 years...been in cyber probably for about half of that time. Started in secure software development, so I was leading teams that were building secure applications for things like financial trading systems, patient record systems for the nhs
the most mature and successful customers that we work with within those 9,000 tend to be folks in regulated industries
There are a handful of concrete data points - the 80/85 vs. 30% gap from Delinea's own research, the 9,000 customers and 60% Fortune 100 figure, and a passing reference to European retail ransomware - but named breaches like Hugging Face are mentioned without any mechanistic detail, and the source and methodology of the headline stat are never examined.
the uptick in investments from the retail industry over the last 18 months was a direct result of the ransomware attacks on, you know, four or five of the major retailers in, in Europe
Delineon currently works with more than 9,000 organizations, including 60% of the Fortune 100
The host structures the episode reasonably and surfaces the right topic areas, but every question is multi-part and leading, the guest's stats are never probed for methodology, and there is no moment of genuine pushback or productive disagreement throughout the entire interview.
And um, of course what we're talking about is nothing new here. We've already seen incidents where stolen credentials, synthetic identities and authorization gaps have been chained together into successful attacks
And uh, of course AI is helping defenders automate their security operations. But on the flip side of this, it also gives attackers new capabilities. So as this AI arms race of sorts continues, where do you think the human expertise remains indispensable?
Computed from the transcript - who did the talking, and the words that came up most.
What happens after an AI agent presents valid credentials and enters your business systems? In this episode of The Business of Cybersecurity, I speak with Spencer Young, Senior Vice President of International Markets at Delinea, about why authenticating an AI agent is only the beginning of the security challenge. Spencer has spent 34 years in IT and around half that time in cybersecurity. His experience covers secure software development, vulnerability testing, application protection, data security, and identity security. Our conversation begins with the changing economics of cybercrime. Spencer says attackers increasingly prefer stealing or compromising legitimate credentials because logging in can be cheaper, faster, and easier than forcing a route through network defenses. He estimates that over three quarters of attacks involve a compromised credential somewhere in the chain. AI agents add speed and scale to identity risk. They can access applications, databases, financial systems, development tools, and infrastructure while performing dozens of actions during a single session. The danger is not limited to an agent being denied access.
Transcribed and scored by The B2B Podcast Index.
Speaker A: The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And denodo applies guardrails across your entire data estate by, uh, aligning your company's data infrastructure under one system. These guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more. What if an AI agent has valid credentials but uses them to take action that nobody intended? Yeah, it's the stuff of nightmares right there. And my guest today is Spencer, uh, Young. He's the Senior Vice President of International markets over at Delinea, and he joins me here on the business of cybersecurity today to explain why connecting securely is only the beginning. Because attackers, well, they increasingly prefer logging in with compromised identities, which is so much easier than forcing their way through a network perimeter. And it's autonomous agents that can amplify authorization gaps and do so at machine speed. So my guest today will explain why every database query, tool, call and command might need approval before execution. And he will also discuss how short lived credentials reduce exposure and why legitimate access never actually guarantees safe behavior. So, if you're interested in joining me in exploring the confidence gap, I think you're going to love this one today. And we'll also mention Delinea's research that found that 80 to 85% of respondents felt that they were genuinely able to discover non human identities and only 30% were able to validate their activity in real time. This is a gap that deserves every CISO's attention. And with that scene perfectly set, let me introduce you to my guest right now. So thank you for joining me on the podcast today. Can you tell everyone listening a little about who you are and what you do?
Speaker B: Thanks, Neil. So, I'm Spencer Young. I'm the senior Vice President at Delinea of, uh, our international markets. So I look after our EMEA and APAC regions. I've been with the company for just shy of five years now. It's coming up to the end of my fifth year. Um, been in it for about 34 years, which is always painful to say when you realize how old I actually am. Um, but I've been in cyber probably for about half of that time. Started in secure software development, so I was leading teams that were building secure applications for things like financial trading systems, patient record systems for the nhs. And then I moved into code vulnerability testing tools, and then application and data security before I landed at, uh, Delinear in identity. So, and I think in reality like so many cyber practitioners, I quite like the adversarial nature of what we do. And so many folks, certainly at Delinear and the people that, you know, my peer group, I think a lot of us feel that way. So it's, um, a great space to be in and one that's obviously changing very rapidly around us right now.
Speaker A: Well, I appreciate you taking the time to sit down with me today and dig a little bit deeper on identity, which has become the new security perimeter. Uh, and despite that, attackers seem to be focusing less on breaking in and more on simply logging in. So how have you seen the threat landscape change over the last couple of years? And why are identities now the easiest way into an organization?
Speaker B: Yeah, it's a great start. Start point, question, Neil. Thank you. I think what's changed over the last couple of years is that, um, hackers and bad actors realized fairly early on, actually, that it's now easier, less expensive, and faster to gain access to systems through compromising legitimate credentials rather than trying to brute force a way in. You know, the fact that, you know, bad actors, and we forget this, sometimes, they monetize on data. Right. And that's ultimately what they're after. Um, whether that's to extort or dis. But I do think the economics of the attacks have changed, for sure. Um, they don't need to exploit the perimeter and spend time and money trying to do that if they can get legitimate access into systems. And I think, and I know we're going to talk more about it in this session, the recent breaches in things like hugging face and OpenAI and anthropic and meta are showing really, how AI is making those attacks even faster and more sophisticated than they've ever been. And, yeah, you're right, Identity, even over the last couple years, has maintained and still is, um, the main way in. I mean, it's still over three quarters of the attacks that will involve some form of compromise credential along the way.
Speaker A: Yeah, and just to throw into the mix here, AI agents, they're creating a whole new category of digital identities. And I must admit, as an XIT guy, it does make me a little nervous. Uh, individuals, entire teams, and an entire organization are, uh, creating hundreds, if not thousands, thousands of these agents. So what new risks do they introduce, though? Why is securing an AI agent fundamentally different from, let's say, securing a human user?
Speaker B: Yeah, I think it's. First of all, I don't think the agents themselves introduce new security risk per se, but what they do is they instrument those risks that are already there and they can do that at a speed and a scale that we have just never contemplated or seen before. I think that that's the main uh, difference in terms of the business issues that get created for companies and government organizations when they think about securing agentic. I mean if we think about it in terms of your question around how it differs from a human. Human has a pretty defined role, right? And for those of us in the identity security space we tend to think of in the early days, the first sort of roles that we would secure would be those IT administrators, you know, the ones that had access to the keys to the kingdom. They had access to all the systems, all the databases, all the applications and then you had certain privileged business users, so board level kind of folks, senior people that would have access to things and then along came machines so servers would get access to systems and you'd want to make sure that you secure those. I think the difference with agentic is that whilst that role, you know, what they are designed and set up to do is quite defined, they can use legitimate access that they're given to take the wrong actions at machine speed. Good example is, you know, a uh, finance agent for example, that finance team would set up to help them with their payment systems could for example have hidden instructions put into by the agent or to the agent to change the payment profiles and start moving money around to places where it shouldn't move money. So I think, and doing that all the while as if it is a fully authorized identity doing exactly what it's supposed to do. I think that's one of the differences. And whilst through our own research for example, at least 80 to 85% of the companies we talk to say they're very confident in their ability to discover non human identities. Only 30% of them actually validate non human identity usage and AI activity in real time. And that, that's the real key to it is the, is being able to watch what that agent or any identity frankly does in real time. It's the difference, that difference between authenticating something whether it's a human or a non human or an authentic agent or a model, authenticating them once is just not enough. We've got to be able to effectively authenticate, think of it this way, authenticate it with every single action that it's taking. Is it actually authorized and approved to go and access that system at that time and what was it originally designed to do? You know, agents have uh, intent embedded within them, right? The humans say this is what we want, you to do for us. And agents obviously want to please us and they'll go. And the action that we've asked them to do, and they have no guardrails set with how they go about and do that. I mean, the hugging face, uh, breach was a great example of that. The agent actually didn't do anything wrong. It did what it said it was, did what it was asked to do. Um, and it wasn't given the guardrails to prevent it from accessing the systems that it chose to access to complete the task.
Speaker A: And one of the reasons I was excited to get you on the podcast today is having read how Delinea recently introduced runtime authorization for AI agents. So rather than simply controlling who or what gets access, you're now evaluating every action that an AI agent takes. So, uh, for people listening, tell me a little bit more about why that shift from authentication to authorization is so important.
Speaker B: I think it comes back to what we've just been talking about. That authentication is typically that one time process. And that one time process will absolutely be able to answer, uh, who or what connected to something.
Speaker A: Right?
Speaker B: What it does after it's had done that connection is the piece that's the missing component of it. And what runtime authorization does is it determines whether every proposed action. So before the agent's going to do anything, or any human for that matter, we have customers that have runtime authorization in place, you know, for their human, uh, identities as well as for machine and for agentic. And so it then, as I said, makes sure that we are preventing access at each action that it's trying to take, rather than just saying it has the credential, it is able to access everything, um, that that particular identity is able to do. I mean, a single agent session, it comes back to this thing we were talking about earlier, about the speed with which agents can use above an IT administrator or a human. A single agent session can involve dozens of tool calls to different things with different task profiles. So you have to block each action or you have to elevate the privilege on each of those actions at an individual basis. And I think, you know, the, the way that we think about it quite uniquely as a company right now is we almost, we take away the notion of any standing privilege or access to the credential that typically a human would use to get access to things. And we inject the credential at the point that the agent is about to get access to the thing it's going to get access to soon as it's done that action. We remove it and revoke it, and the agent never sees it. So if the agent's compromised in any way by a bad actor or a hacker, they're not going to be able to find the credential or the password that was associated with, uh, that agent. And I think that, to me, is the real value. Certainly with all the current conversations we're having with our current customers, our prospective customers, and the industry. Any industry event you're going to right now. Neil, I know this is the topic of conversation in terms of how people secure it and customers are, and companies and even tech companies. We're all at different varying levels of maturity with how we think about securing AI and how we think about using it. To my mind that, uh, if the only thing an enterprise did or a government department did was ensure runtime authorization for the agents, I think that goes a significant way to solving that. How do we work out what it's doing and make sure that it does what it's supposed to do and not step out of line? I think that's probably the most significant impact that that could have on any right now.
Speaker A: And something else we often hear of is least privileged, especially in cybersecurity. So what does least privilege actually look like when we're now dealing with autonomous AI agents that are making, uh, decisions at machine speed? Anything you'd like to add on that, too?
Speaker B: Uh, yeah, I think, first of all, as you just said, first of all, you have to be able to score the map machine speed. And that's been a big shift in the market. As I said earlier, when Delineo first created as a company, our main focus was on securing, you know, highly privileged individual humans. Um, and they work at human pace with autonomous agents. As I said earlier, the best way to enforce least to privilege, or zero standing privilege, or whatever other acronym the industry wants to come up with, and we're good at doing that, we love our acronyms, is to just make sure that, as I said, those credentials are injected just in time scoped to the task that the agent's been asked to do, and then they're revoked as soon as that task is completed. But at the end of the day, it still is. And Art Gillina, our CEO, uh, um, was interviewed, I think, this week, and he made the commentary around. It is still beholden on human beings to define the policy and the risk boundaries of those agents around the controls. We can provide, and technologies like us can provide the controls that enforce those things automatically and do that at machine speed. But it is still beholden on humans. Humans are still the most important factor in this around. It's us that set the boundaries. We set the ask for the agent. We should also be setting the boundaries that it's able to go stay within and what it cannot do much more clearly than we've been doing today.
Speaker A: And uh, of course what we're talking about is nothing new here. We've already seen incidents where stolen credentials, synthetic identities and authorization gaps have been chained together into successful attacks. So we've seen examples of this already. And for people listening, what lesson should security leaders take from these kind of breaches that we've already seen? And where are organizations still possibly leaving themselves exposed from what you're seeing?
Speaker B: Well, I think that comes back to the fact that with those breaches that you mentioned, it was all predicated on that one time authentication. I am an agent and I wish to do this. I'm given the credentials and the authorization to go and do anything, uh, from there onwards and be um, ungoverned. And I think those successful attacks that have combined together have always started from legitimate credentials that it was given. And then it's able to get excessive privileges as it goes through that process. And it uses gaps in how organizations control their logging capabilities, et cetera. And the key point really is that that legitimate access doesn't mean that it's safe access. Right. It's security teams must make sure that they validate continuously what that identity is doing, whether it's an identic agent or a human actually shouldn't matter. It really shouldn't. But again, so many companies that we help, um, and that other identity vendors in our space help companies do is we help them reduce exposure through things like long lived credentials that have just been sitting in systems for so long. The agents will find those if uh, it helps them to complete the task they've been given or it speeds up their ability to complete that task, they'll go and look in those places and they'll utilize it. That's not them doing anything wrong or bad or very deliberate. It's just them completing that task. So again, it's about comes back to that one time authorization does not secure, uh, an agent working at that type of pace and velocity.
Speaker A: Then a quick look online revealed that Delineon currently works with more than 9,000 organizations, including 60% of the Fortune 100. So uh, I'm curious, looking across that kind of customer base and that kind of scale, what is it that's separating organizations that are successfully managing identity risk from those that uh, are Constantly just firefighting and reacting to the latest threat.
Speaker B: That's a great question. I think there's two components to it, to be honest. Now I think the first one is the most mature and successful customers that we work with within those 9,000 tend to be folks in regulated industries. So they're almost forced through either industry regulation or government regulation to ensure that they have the appropriate controls in place to secure their businesses. And I think they're the ones that have. And still today, I mean the vast majority of our customers are either governments, financial services, telco, utilities, critical infrastructure type companies who are governed by third party regulation and um, compliance. And so that forces them to an extent to not become reactive to security issues and become a lot more proactive about putting the controls in place to deal with it. The others that we see are the most unfortunate ones, to be honest, which are the ones that are reacting to bad things happening to them. I mean, a great example is, you know, the, the uptick in investments from the retail industry over the last 18 months was a direct result of the ransomware attacks on, you know, four or five of the major retailers in, in Europe, um, that took place I think around a year ago. And, and now we're seeing the retail industry is becoming actually very mature with how it's thinking about the way that it secures all manner of identities. But it still comes back to that, that thing we started at, which is their focus is on ensuring that any identity cannot get access to the data on which it will want to monetize on. Um, and I think that's what separates the most mature from those that are catching up. There's certainly industries that are catching up for sure, but I think they're not facing fewer threats. They've just turned identity security from getting away from an incident response kind of point of view on it to more of a continuous risk management discipline that they're making sure that again, their governance is constant, um, on the identities that are in their organizations.
Speaker A: And um, of course AI is helping defenders automate their security operations. But on the flip side of this, it also gives attackers new capabilities. So as this AI arms race of sorts continues, where do you think the human expertise remains indispensable? And where should organizations get more comfortable letting AI take the lead? And I appreciate that question. It's almost an episode entirely on its own. But any, any takeaways around that?
Speaker B: Well, I think it comes back to what we said earlier. It's people, it's human beings that define the intent of that agent and the policy around it and, and the accountability. The AI is not accountable in of itself.
Speaker A: Yeah.
Speaker B: And what the AI will do will handle the speed and the scale and the, and consistent in enforcement. It's people that, that define the, the intent and the policy. And I think the, the governance piece of it has to establish boundaries around certainly in the first instance what high risk actions would be. Um, rather than needing manual approval for every use case that an agent is going to want to invoke, the controls have to be automated. They have to be contextually aware. And as I keep saying, and I know I'm probably becoming like a broken record, they have to be enforced in real time constantly. Right. You know, they have to and companies are going to need to. As I said, the AI in of itself is not, is never going to be held accountable. It's the company, they have to remain accountable for the systems that they build and what they deploy. And simply coming back to the AI did it is not going to be a get out of jail free for any company, uh, if there's a breach or bad things happen.
Speaker A: And if we do have a CIO or a CISO listening who knows that AI agents are um, about to become part of their workforce. If not this year, early next next year. What are the first three practical steps they should be taking right now to ensure that they can govern, monitor and control those identities before they become tomorrow's biggest security threat? It feels like there's a great opportunity to build the foundations now. But where would you advise that they start?
Speaker B: It is, and actually our advice has really been born out of all of the customer conversations that we've had. This is with our current customers in terms of how we're going to help them first. And I think the first three things that we're seeing that the most mature companies are doing are, uh, first of all, they're saying, okay, we need to control the sensitive actions first. Right. We need to identify those systems that could cause material harm if they were breached. We need to make sure that every attempt on access is evaluated before the agent executes anything. So as I said earlier, define stop it from doing it prior rather than working out what it's done after the next part of it is, as we've actually been talking about for the last 25 minutes or so, is make sure that you only give the agents access when they need it, limit it to very specific tasks, and then remove that access as soon as it's done. Don't give it what we would call in the industry standing privilege, um, to continue to work in the systems that it's had access to. And then last but not least, it comes down to setting the ownership and accountability, defining the agent specific policies that you need to do. That's where I think companies are not right now. Spending the, you know, the level of time and energy on, in terms of bringing humans into the really high risk decisions that agent would want to take. Retaining an action level record showing who did what, what it did, why it did it. It's that ownership and accountability that I think is the third piece that we're certainly already seeing across the most mature companies working with AI.
Speaker A: I think that is a thought provoking moment to end on. But before I let you go, where's the best place for people listening to find you, your team online, find out more information about anything we talked about today around Delinea, the recent releases, et cetera. Where should they go?
Speaker B: Uh, the very best place, uh, is our website, which is very simple. It is www.delinea.com and my LinkedIn page. I am, I think I'm the only Spencer young, fortunately on LinkedIn, which does help. You know, I curse my parents for the, for the name, but it helps. But, um, so yeah, my leads in page is there. And as you'll see in the biography, what we try and do is whilst we've spent a lot of time on this session talking about the technology of it, one of the things a lot of our customers are worried about is the budget implications of all of this. How do they show value and how do we as cybersecurity vendors help them to get the right budget allocations in the right places to see the right kind of returns? And so we tend to do a lot of that. Um, you know, that's something I've been focusing very heavily on since I got into cyber rather than. I love the technology, as I said, I love the uh, the adversarial parts of what we do. Fundamentally companies are running businesses and governments are trying to secure citizens. We do spend a lot of time trying to help them work out where they should be investing first and why, and then building the business cases for that. Um, so some of that you'll find on the LinkedIn page as well. But, um, it's been a real pleasure to spend some time with you, Neil. Thank you, I appreciate it.
Speaker A: Uh, thank you. And love chatting around how securing how an AI agent connects is no longer enough. A very clear message there. We do need control over what it does once it's inside. So I'll include links to everything you mentioned, uh, the website, your LinkedIn, the company's LinkedIn, and some information around the runtime authorization for AI agents we discussed as well. I'd love people to feedback, have a look in the show notes, have a look around, let me know your thoughts, your experiences. But more than anything, thank you for your time today and bringing all this to life. Really appreciate you.
Speaker B: Thank you, Neil. Thank you. Really appreciate it.
Speaker A: I think Spencer's warning is simple. Legitimate access does not guarantee a safe action. An AI agent might be properly authenticated, remain within broad permissions, but still move money, query sensitive data, or execute a, uh, command that nobody intended. And security has to follow the action, not stop at, uh, the login screen. And I think his practical plan begins with identifying systems where misuse could cause material harm, and then evaluating access before execution, granting temporary permission for specific tasks, and keeping a record of who did what and why. It's the humans that must define these policies, these boundaries, ownership, and moments when approval is required. So massive. Thank you to my guests for joining me today. And remember, you can find out more@delinea.com connect with my guest on LinkedIn. And before I let you go, I'm going to leave you with a question. Could your security team explain every single action that is taken by an AI agent inside your organization today? How they, um, answer that or how you answer that might determine if you need to go a little deeper on this. So, as always, TechTalksNetwork.com let me know your thoughts on experiences and I'll return again real soon with another guest. Thanks for listening. Bye for now.
Speaker B: M.