The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Business of Cybersecurity
The Business of Cybersecurity artwork

When Identity Becomes The Front Line Of Cybersecurity

The Business of Cybersecurity · 2026-05-20 · 23 min

0:00--:--

Key moments - from our scoring

Substance score

51 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality8 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft11 / 20

As attackers increasingly exploit compromised credentials to gain access rather than breaking through hardened infrastructure, the cybersecurity industry is shifting from network-centric to identity-first security. David Cottingham of RF Ideas explains how organizations can address the "password problem" - the insecure habits and friction that legacy password systems create - through practical, workflow-integrated authentication solutions. Rather than pursuing the difficult leap to fully passwordless environments, Cottingham recommends a phased approach using secure second factors like RF credentials, smart cards, mobile credentials, and passkeys that authenticate without slowing employees down. He emphasizes that successful implementation requires understanding actual user workflows in healthcare, manufacturing, and other industries before layering security controls, preventing the resistance that poorly designed security creates. The conversation highlights the convergence of physical and logical security, the vulnerabilities of legacy proximity cards that are easily cloned, and how organizations should build technology roadmaps that allow gradual migration toward more secure credential types while maintaining current system compatibility through multi-technology readers.

Key takeaways

  • →Organizations should focus on adding a secure second factor - such as RF credentials or mobile credentials - rather than attempting an immediate shift to fully passwordless authentication, viewing it as a journey rather than a destination.
  • →Legacy proximity cards remain a significant vulnerability because they are easily cloned; moving to modern secure credential variants is essential to preventing compromised identity cards from becoming an entry point.
  • →Security implementations must be designed around actual user workflows to ensure adoption; authentication methods that create friction will be circumvented or resisted, particularly in time-sensitive environments like healthcare clinics.
  • →The convergence of physical security (building access) and logical security (application and data access) is evolving, requiring multi-technology readers that support both legacy credentials and next-generation secure credential types.
  • →Layered security combining network hardening, anti-phishing tools, team training, and modern secure credentials is more effective than relying on any single security measure, particularly as AI makes phishing attacks more sophisticated.

In this episode

  1. 1The Rise of Identity-Based Attacks Over Infrastructure Breaches
  2. 2Why Passwords Remain Embedded Despite Security Risks
  3. 3Practical Steps Toward Passwordless Authentication Without Full Transformation
  4. 4Balancing Security Controls with Employee Productivity and Workflow Efficiency
  5. 5Evolution of Authentication Methods and Credential Technology Roadmaps
  6. 6Layered Defense Strategy and Overlooked Security Steps
  7. 7Industry Trends: Convergence of Physical and Logical Security

Mentioned

DenodoRF IdeasNordlayerDavid CottinghamWave IDTech Talks Network

Guests

David Cottingham

Topics in this episode

Multi-factor authentication (MFA)PasskeysRFID technologyZero Trust securityRF IdeasWave ID productsSecure credentials and physical cardsProximity cardsSmart cardsMobile credentials

Questions this episode answers

What's the most practical first step for organizations that aren't ready to go fully passwordless?

Add a secure second factor such as a physical RF credential, mobile credential, or smart card to existing password systems, rather than attempting to eliminate passwords entirely. This avoids cumbersome methods like SMS-based two-factor authentication while creating a realistic path forward.

Why are attackers increasingly targeting credentials instead of trying to breach infrastructure?

Infrastructure has been heavily hardened over the past decade, making it a harder target. Credentials remain vulnerable because they depend on human behavior, and AI-powered phishing tools now allow attackers to craft highly convincing messages that compromise passwords at scale and enable account takeovers.

What makes legacy proximity cards insecure compared to modern credential types?

Legacy proximity cards are easily cloned using publicly available how-to videos and inexpensive devices; once cloned, an attacker gains the same access as the legitimate cardholder. Modern secure credential variants prevent cloning through cryptographic protections.

How can organizations implement stronger identity controls without slowing down employees or creating resistance?

Engage the workforce early to understand their actual workflows, then design credential-based authentication (such as tap-to-access RF readers) that fits seamlessly into existing processes rather than adding friction. When security feels integrated rather than imposed, adoption improves and workarounds decrease.

What should leaders prioritize when building an authentication roadmap?

Create a multi-year plan that supports both current legacy credential types (which may be required for shared building access) and future secure credential types like passkeys, using multi-technology readers that accommodate both during the transition.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode covers identity and authentication fundamentals that are increasingly mainstream but not deeply novel. While the guest mentions legacy technologies like proximity cards being easily cloned and the shift toward passkeys, these points are well-trodden in security discourse. The practical advice about workflow integration and layered defenses is sensible but lacks granular, non-obvious claims that would surprise an informed B2B operator.

attackers can write very, very compelling messages that look extremely authentic
if you are constantly asking someone to log in again and again and again using a long form password, they're going to find ways to circumvent that

Originality

8 / 20

The framing of identity as the new attack surface is now mainstream, not contrarian. The guest recycles standard security tenets: layered defense, workflow integration, moving away from legacy credentials. There is minimal first-principles thinking or counterintuitive insight; instead, the conversation reinforces conventional wisdom about MFA and secure credentials without challenging industry assumptions.

layers continue to be one of your best lines of defense
make sure you have all of these pieces in place

Guest Caliber

13 / 20

David Cottingham is president of RF Ideas, a relevant practitioner with 25 years in the identity and authentication space. He has direct operational experience and speaks from real customer interactions at conferences and deployments. However, his company sells identity solutions rather than being a neutral infrastructure operator, which introduces a sales-focused lens rather than purely objective expertise.

I've been in this space for 25 years now
We help our customers every single day kind of sort that out

Specificity & Evidence

9 / 20

The episode lacks concrete data, named customer examples, specific metrics, and dollar figures. The guest mentions healthcare and manufacturing success but provides no case studies, deployment numbers, or measurable outcomes during the conversation itself (though he references them on the company website). Claims about phishing efficacy and credential cloning remain illustrative rather than evidenced with hard numbers or named incidents.

We've had a lot of success in the medical space
You can find countless how -to videos and even devices that will assist you in cloning that

Conversational Craft

11 / 20

The host asks reasonable opening questions and invites the guest to explain concepts, but rarely challenges claims or probes deeper when opportunities arise. Questions about workflow integration and MFA vulnerabilities are surface-level. There is no productive disagreement, no follow-ups that press on trade-offs, and no skepticism about the guest's assertions. The conversation reads more as a structured interview than a critical dialogue.

what should leaders be thinking about when choosing that right approach
how can businesses introduce those stronger identity controls

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

credential20security17secure16today13identity13authentication12passwords12access11workflow9helping8physical8towards8long8customers8help7real7

Episode notes

What happens when the biggest cybersecurity weakness inside your organization isn’t your infrastructure, but the people using it every day? In this episode of Business of Cybersecurity, I speak with David Cottingham, president of rf IDEAS, about why identity has become one of the most targeted attack surfaces in modern business. From phishing attacks powered by AI to the growing risks tied to compromised credentials, David explains why traditional password habits continue to expose organizations across healthcare, manufacturing, finance, and enterprise environments. Our conversation looks at the uncomfortable reality that while businesses have spent years hardening infrastructure, attackers have shifted their attention toward human behavior. David shares why fully passwordless environments may still be out of reach for many organizations, but why the move toward stronger authentication methods, secure second factors, mobile credentials, passkeys, and biometric workflows is already reshaping how businesses think about trust and access. We also discuss the growing tension between stronger security and employee productivity.

Full transcript

23 min

Transcribed and scored by The B2B Podcast Index.

So a huge thanks to Denodo for supporting the Tech Talks Network, helping us produce more than 60 interviews a month. And when it comes to trusted data products, it all starts with the right foundation. And trusted data products start with Denodo because they can help you create, manage, and deliver business -ready data products faster. with secure real -time access across all of your data sources.

And you can learn more by simply visiting denodo .com. Well today's conversation takes us right into that tension between risk, usability and real -world business outcomes. Because while headlines often focus on ransomware or infrastructure breaches, the reality is attackers are still increasingly walking through the front door using compromised credentials.

They don't even have to think about breaking in through the back. So today I'm joined by David Cottingham. He's the president at RF Ideas. And they are a company focused on secure access and authentication across everything from healthcare environments to factory floors.

And my guest spends his time helping organisations rethink how identity is managed at the edge. whether that's through physical credentials, mobile access or smarter authentication workflows that actually fit into how people work. So today we will try and unpack why going fully passwordless still feels just out of reach for many businesses, but what a practical next step could look like and why the shift from protecting networks to protecting identities is something that is playing out across every industry.

And hopefully we'll also get time to get into the balance between tightening security measures and keeping employees productive and not complaining to security teams for slowing their teams down. So if you've ever wondered where to start on that journey towards stronger authentication without creating friction, this conversation today should give you plenty to think about. So a big thank you to Nordler for backing the podcast and supporting the kind of real -world cybersecurity conversations that we need more of.

Because as someone that records 65 plus interviews a month, I've personally seen a huge increase in browser -based attacks over the past year, whether that be phishing, malicious extensions, account takeovers, the list is long. And it's all happening where people spend most of their time, inside the browser. So Nordlayer's new business browser that's built to address exactly that. It blocks malicious sites before they load.

It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps. And it also helps you stay compliant by controlling access and enforcing policies. without the need to rely on multiple disconnected tools. So for anyone listening that is thinking seriously about reducing risk in SaaS heavy environments, this feels like a smarter and more focused approach.

And you can learn more about it by visiting NordLayer .com slash browser. But enough scene setting for me. Let me introduce you to my guest now.

So a massive thank you for joining me on the podcast today. For everyone listening, hearing about you for the first time, can you tell them a little about who you are and what you do? Hi Neil, I'm David Cottingham. I'm the president of RF Ideas and we deliver a series of identity solutions for our customers, primarily leveraging ID cards or RF credentials that can take the form of a physical card or increasingly a mobile credential.

And everything we're about is helping our customers automate workflows by leveraging that credential to help them go about their work in a secure, efficient way. Well it's a pleasure to have you join me today especially because we're talking at a time where everyone is having conversations around agents, agentic AI, digital identities and I think it has thrown the topic of identities right back into the mix right into the spotlight as well and passwords they've been known as a weak point for years for us humans yet they do remain deeply embedded inside business systems we're starting to see pass keys more often now in our personal lives.

So for organizations, though, where should they realistically begin with going fully passwordless is still out of reach. It's somewhere we're all heading towards. It feels within touching distance. But what does this mean for organizations?

Yeah, you're absolutely right. Passwords still are firmly embedded in processes throughout businesses and What we talk about is helping customers get on a journey to more secure authentication, and that typically right now means adding a second factor. And adding a second factor can be a physical credential, a mobile credential. We're all familiar with things like two -factor authentication, receiving a text pin.

in a lot of business settings, that's just a really cumbersome, inefficient way to do it. So we encourage people to just get on that journey to start. And you've spoken about identity becoming the new attack surface for a long time now. And as I said, it's now going mainstream.

So what would you say is driving that shift away from infrastructure and why are attackers finding credentials such an effective and possibly easy entry point today? Yeah, you're right. I think it is moving a bit away from infrastructure because there's been so much emphasis on hardening infrastructure over the last maybe decade. I've been in this space for 25 years now.

And I think identity or passwords are becoming a more common threat vector because it involves people, right? And people continue to be one of those points that can be exploited. And tools like AI is allowing attackers to write even more compelling phishing messages that the long ago days, five years ago, where you would get this clumsily written phishing message that you could quickly identify and discard, I think are gone. you can now, with these AI tools, attackers can write very, very compelling messages that look extremely authentic.

And that allows for phishing and account takeover and passwords being compromised in a way that some, you know, just continue to grow and grow. And I was watching an episode of The Pit recently and the cyber security risks and it going down in healthcare was plain to see that. What I took away from that more than anything was how it has entered the mainstream now. So when you look across industries like healthcare, manufacturing and finance, how does that move from network security to identity first security?

How does that actually play out in real world environments for people listening? Well, I'm a big fan of that show as well. So I think the way the way it is moving is I guess if I understand your question, what's changing or how is that moving from passwords to other forms or leveraging additional forms of identity? Yeah, that's right.

We talk about here at RFID is we talk about the password problem. When we say that, what we refer to are the bad habits that come from reuse of passwords, shared passwords, processes that are put in place in front of people that almost encourage them to avoid good processes. So if you are constantly asking someone to log in again and again and again using a long form password, they're going to find ways to circumvent that or at least avoid doing that as often as they do. So the way we help customers address that.

at RFID is our Wave ID products allow you to simply tap a credential to a reader or begin to leverage pass keys and get people into those workflows more efficiently in a way then authentication just becomes this seamless thing that doesn't slow them down. You mentioned the medical space. We've had a lot of success in the medical space of helping clinicians automate that authentication workflow. So instead of walking in to a clinical setting, turning their back to a patient, fumbling with a password, clinicians that use our solution are simply tapping their identity to one of our devices and immediately accessing that record and engaging with the patient.

So you get better. patient interaction, you still have a secure interaction for the clinician with that data, and they're more satisfied because they're not typing passwords all day long. And I think many organizations are layering on multi -factor authentication, trying to do the right thing. But of course, not all second factors are equal.

There are a few vulnerabilities in some of those too. So what should leaders be thinking about when choosing that right approach for their workforce and for their organization? Yeah, I think they should be thinking about security, obviously, right? We're talking security here, but making sure that it is a secure credential that will be used and leveraged and that it's a modern credential.

So, you know, the industry of physical cards and physical identity has a long history of continuing to leverage legacy technologies such as proximity cards. that are easily cloned. You can find countless how -to videos and even devices that will assist you in cloning that. And now you've compromised that identity card that's used in one of those secure workflows.

So we encourage people. Yes, get a second factor, but make sure it is a secure second factor and one that will be easily leveraged. So if you were using Crocs cards before, move to one of the more secure variants to make sure that you don't have a credential that can be easily cloned. And there is often tension between tightening security and maintaining productivity.

So a question on behalf of business leaders out there, how can businesses introduce those stronger identity controls that we're talking about here, but without creating friction for employees or slowing operations down where IT suddenly gets accused of being a blocker rather than a business enabler again. We've done so much positive work over the last few years, but how do you continue that? Because it is a tough balance sometimes. It is a tough balance.

So what we encourage our customers to do is engage that workforce that's going to be part of this, right? Don't shove down an edict that feels like you don't understand how I go about my work. So understand what that workflow looks like, take that into account, and then find ways while still maintaining security to easily insert that into the flow. That's why Again, I go back to this, whether it's using RF or we also increasingly are seeing biometrics enter the workflow space, that ease of use of a credential that is still secure is vital.

Because if you don't think about that workflow and you don't do it in a way that can be efficiently adopted by the users, you're going to have great resistance. And people are going to find ways to work around it. So look at the workflow. How does a secure credential go into that?

And then make sure that the users can repeat and repeat over and over again. Use that as they go about their day. And with technologies like everything from smart cards to mobile credentials and even proximity based access evolving so quickly right now, I'm curious, how do you see authentication methods changing over the next few years and anything organizations or leaders listings should be preparing for now? How do you see this continuing to evolve?

Well, it is certainly a rapidly evolving space and, you know, I think The way this leader should be thinking about it is begin to walk, if you're not there already, walk on this journey of moving towards more secure credential types. The industry is absolutely moving towards pass keys away from some of the other legacy types. If that's too far of a leap, pick a technology that will allow you to go on your journey. In RFIDA's case, we make a lot of multi -technology readers or devices where you can read a legacy credential, but you've got a future proof and a ready device that can also move to that next secure credential type.

So put in place things that you can ease into leveraging the current credential and then move towards more secure credential types. Build it out, think about it in a roadmap sort of a way, knowing that it's likely your building physical access system may require a legacy credential type for quite some time, right? Maybe you don't own the building, so you can't control the physical access system. So you maybe have to carry around a prox cart while you're leveraging that next technology in the workflow, getting access to information or securely retrieving a document.

So think about that as a roadmap. And for any leader listening who is concerned about breaches tied to identity misuse, because it is a growing threat there, what is the most overlooked step that they should take, do you think, to better reduce risk before it turns into a real incident? There's a big focus on proactive approaches to security rather than reactive. Any advice here?

I think it's layers. That has always been true. Like I said, I've been in this space a long time and layers continue to be one of your best lines of defense. We're talking a lot about passwords here this morning.

No one is saying go back, roll back to simple passwords. Make sure you have all of these pieces in place. Have your network security buttoned down with appropriate tools there. Make sure you're using anti -phishing solutions at the edge.

continue to train and also drive your teams towards more secure credential types. So still complex passwords at the core, network security at the edge and layered throughout, but then also adding a secure credential on top of that, that is easy and efficient to use is where you need to go. And before you join me on the podcast today I was having a quick look on your LinkedIn page for the organization and I could see you guys spend a lot of time on the road a lot of different conferences I'm curious if you would put all those conversations into a big melting pot any kind of Trending conversations that people are coming and asking to you for help with what what are people talking about?

They're out on the show floors. I think people are asking for help kind of sorting out what can feel like a very overwhelming and complex set of decisions. We help our customers every single day kind of sort that out. We have people say, okay, I need to automate workflow on the factory floor because I'm really concerned about who's kicking off that process at HMI panel, but I don't know where to start.

So we're helping them. kind of walk through understanding what they have in place today and then helping them sort out what can be a daunting set of terms and technologies. So we're walking them through everything from base technologies all the way to pass keys and where the industry is going in terms of standards. So we help our customers sort that out every single day.

You ask about what am I hearing? It's also this convergence of physical security and logical security. That's continuing to slowly march towards from that door entry all the way into the office suite. And we've talked a lot around the defining the problem and the solution that you guys are offering here But with everything you're focusing on throughout this year is anything that particularly excites you because yes There's a lot of scary headlines out there, but there's also a lot of opportunities to stop this stuff for good, right?

Yeah, I think you know you talked about some of the the AI technologies and I know that people maybe say, wow, that's an overused term, but I think the organizations, I'm excited to see how organizations are going to continue to use some of these tools to begin to make even smarter zero trust decisions and we play a role in that. at the very edge of that authentication stream. So from the moment someone presents a credential to one of our devices, we're part of beginning to understand who did that?

When did they do that? Was it a proper credential presented? So I think all of these tools, while there are many of them that are being used to threaten our enterprises, can also be used. to very logically identify who is attempting to access information.

I think our industry is going to be able to leverage a lot of those things all the way from the edge into the core to make sure we're making smart decisions about who is truly accessing that information and do they have the right to do so at the appropriate time, location, and access level. Well thank you so much for sitting down with me today and bringing all this to life and as business and technologies inevitably begin to change for anyone listening that are not just looking at improving their security but also maybe partnering with you, working with you or just finding out more about how to turn trust into more productivity.

Where would you like me to point everyone listening? They can easily start out at RFideas .com and they'll find information, not just about our products, but also case studies and examples of how we have helped our customers. solve the password problem, work on identity at the edge, and I'll also see examples of all the industry solutions we've worked with, from securely retrieving documents to logical access into critical business applications to workflow automation on a shop floor.

That's a great place to start. Well, so much we covered today from how to balance cyber risk, innovation and business outcomes, all that align with other conversations that we're continuously having on breaches, AI driven risk and so much more. I'd love people listening to check out everything that you've just mentioned there. I'll put links on the show notes, make it nice and easy.

But more than anything, just thank you for sitting down with me and sharing your story. Really appreciate your time today. Thank you, Neil. Great speaking with you.

One of the things that stood out to me in that conversation with David today was just how much of this comes down to behaviour as much as technology. Yet we can talk about zero trust, multi -factor authentication and pass keys all day long. But if the experience doesn't naturally fit into someone's workflow, it simply won't stick. And I think this is where the real challenge lies.

because lead is a challenge with designing security that people will actually want to use or almost make it feel seamless so they don't feel any friction and this is where I think there's a bigger shift happening here because identity is no longer a small piece of the security puzzle it is now becoming the foundation that everything else sits on and as AI continues to make phishing and social engineering more convincing That focus is only going to intensify. So if you want to learn more about how RF Ideas is helping organisations tackle the so -called password problem and rethink authentication at the edge, I'll include links on the show notes and you can visit me at techtalksnetwork .

com. There's a blog post for every episode. and the links to the guest and everything that they mentioned too, so please explore their work and take a look at some of the real world case studies there. But as always, more than anything, I just want to hear your perspective.

Are passwords still embedded in your organisation more than you'd like? Or are you already moving towards a passwordless future? Let me know your thoughts. We'll continue this conversation together.

So pop over tech talks network .

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • When AI Stops Assisting And Starts ActingAI Proving Ground Podcast · on Zero Trust security90 / 100
  • Aaron McCray: Ferrari Security: Speed With GuardrailsKitecast · on Multi-factor authentication (MFA)88 / 100
  • How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200MThe SaaS Podcast · on Zero Trust security87 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Multi-factor authentication (MFA)82 / 100
  • How to Talk About Cybersecurity to Clients & Prospects with Mark Lamb from HighGround.iothe RocketMSP Podcast · on Multi-factor authentication (MFA)82 / 100
  • Security isn’t a cost - It’s your biggest growth engineDevOps Sauna from Eficode · on Zero Trust security80 / 100

More from The Business of Cybersecurity

All episodes →
  • Closing the AI Vulnerability Remediation Gap With Cobalt74 / 100
  • Mimecast CISO On Why AI Has Become A Cybersecurity Risk60 / 100
  • Orange Cyberdefense On The New FCA Cyber Reporting Rules76 / 100
  • Deepfakes, AI Agents, and the Collapse of Traditional Identity Security66 / 100
  • Index Engines On Why Cyber Resilience Has Become A Boardroom Issue77 / 100
All The Business of Cybersecurity episodes →