The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Valueprops
Valueprops artwork

Why Identity Governance Is the Missing Link in Cybersecurity

Valueprops · 2026-02-10 · 42 min

0:00--:--

Identity governance represents the third pillar of identity security - audit - yet most enterprises still rely on prehistoric spreadsheet-and-email workflows to manage user access reviews, privilege creep, and compliance requirements like SOX, HIPAA, and PCI DSS. Garrett Graciak built Untest to automate this gap, integrating with existing identity providers (Active Directory, Okta, Entra ID, JumpCloud) within five minutes to audit identities across siloed resources in healthcare, finance, insurance, and other regulated industries. The platform's core innovation is the Identity Trust Score, powered by AI, which identifies high-risk accounts based on review frequency, segregation of duties violations, and permission sprawl - helping organizations avoid the 15% orphan account infiltration rate seen in enterprises without automated reviews. Unlike legacy GRC tools from Accenture and Deloitte that cost a fortune, Untest prices at one-tenth the cost with no upfront fees, making it ideal for MSPs, MSSPs, and consultants managing multiple customer environments. The platform has completed 4.3 million attestations and works equally well for enterprises with 100 to 10,000 users, with sweet spot adoption between 750 and 1,500 users.

Key takeaways

  • →Enterprises still conduct user access reviews via spreadsheets and emails rather than automation, leaving 10-15% orphan accounts vulnerable to hackers seeking dwell time in systems.
  • →The Identity Trust Score uses AI to flag high-risk accounts by analyzing review frequency, privilege violations, and permission creep without manual triage, providing a signal for zero-trust reauthorization decisions.
  • →Untest integrates with any identity provider in under five minutes and can audit siloed resources across healthcare, finance, and insurance without replacing legacy GRC tools - pricing is one-tenth of incumbent solutions.
  • →MSPs and consultants can offer user access reviews as a recurring revenue service with simplified RBAC administration and no upfront costs, allowing them to double Untest's price and undercut legacy vendors by half.
  • →SOX, HIPAA, and PCI DSS compliance budgets (averaging $1M+ per year for large enterprises) can be substantially reduced by automating attestations and eliminating manual governance spreadsheets.

In this episode

  1. 1Identity Governance: The Three A's of Identity Security
  2. 2The Problem: Spreadsheets and Manual Auditing in 2026
  3. 3How UITest Automates User Access Reviews
  4. 4Target Industries and Customer Profile
  5. 5Orphan Accounts, Privilege Creep, and Drift
  6. 6MSP and MSSP Partnership Models
  7. 7AI and Identity Trust Score for Risk Detection
  8. 8Cost Savings and Budget Optimization for Leadership

Mentioned

Garrett GraciakWaleedCloud PSOUotasSilversideSecure offOktaMicrosoft Entra IDJumpCloudPingActive DirectoryUITest

Guests

Garrett Graciak

Topics in this episode

HIPAAEntra IDActive DirectoryOktaPing IdentityJumpCloudUser Access ReviewsIdentity GovernanceIdentity Trust ScoreSOX (Sarbanes-Oxley)

Questions this episode answers

What percentage of user accounts in a typical 10,000-person enterprise are orphaned or should not have access?

Without automated identity governance, enterprises typically find 10-15% orphan accounts - inactive user identities that haven't been removed, leaving them vulnerable to attacker impersonation and dwell time exploitation.

How does the Identity Trust Score work in Untest?

The Identity Trust Score uses AI to analyze identities across your enterprise, evaluating review frequency, segregation of duties violations, and permission sprawl; if no one has reviewed a privileged account in months, the trust score degrades, surfacing high-risk accounts on a dashboard.

How quickly can Untest integrate with existing identity providers?

Untest integrates with Active Directory, Okta, Entra ID, JumpCloud, and other identity providers in less than five minutes, and can also audit siloed resources in healthcare, finance, and insurance directly.

What is the pricing model and how does it work for MSPs?

Untest charges based on monthly usage with no upfront costs or setup fees; MSPs can double the license price and still undercut legacy vendors by 50%, with multi-tiered RBAC so one FTE can manage multiple customer accounts.

What is privilege creep and privilege drift in identity governance?

Privilege creep means users accumulate more permissions over time; privilege drift means users retain permissions from previous roles; user access reviews and automation combat these natural tendencies that lead to security risk.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B85%
  • Speaker A15%

Most-used words

access28identity26msps20user19today18governance18review18garrett17data17users15security14product14tools13real13test13trust12

Episode notes

In this episode of the Value Proposition Podcast, host Walid, CEO of Cloudpso, sits down with Garret Grajek, CEO of YouAttest, to explore why identity governance has become one of the biggest blind spots in modern cybersecurity. Garret shares how organizations are still relying on outdated, manual access reviews, leaving behind orphan accounts, privilege creep, and serious compliance risks. The conversation dives into how automation and AI are transforming identity auditing, reducing security gaps, and helping enterprises strengthen their governance posture. A must-listen for CEOs, CIOs, CTOs, and security leaders looking to understand who really has access to what inside their organization. Learn how Cloudpso helps enterprises address identity governance at scale:

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: If a CEO is listening to this today or CTO cio, what should they look for if they've never done this before?

Speaker B: One is what is your GRC budget and how are you spending for tools? The bigger companies in a good way do have budget for this stuff. They're just overpaying. They're overpaying on uh, services and they're overpaying on tools. I come in a license price about one tenth of, of what the big guys will charge and a service costs 1100.

Speaker A: Hi and welcome to the Value Proposition podcast. My name is Waleed, CEO of Cloud pso. Today we have a very, very special guest, Garrett Graciak, U. S CEO. Hi Garrett, how are you doing today?

Speaker B: Doing great. Looking forward to the conversation. Wally.

Speaker A: Okay, great. So you know Garrett, I've known you for a long time and um, why don't you give us a little bit of a, ah, background on yourself and how did you uh, became become CEO? Uotas.

Speaker B: Fantastic. Yeah. So uh, Garrett Gray Jack is what I got hired because I'm an identity guy. I literally got hired in Silence. They were building some real breakthrough AI technology and they scrubbed the bushes for it. Identity guy. And that was me. And we did, it was a lot of fun. Some of the ideas that we did at Silence I brought over here so that, that ah, had its course. And what had happened was I um, had uh, before Silence had left, a enterprise that has started called Secure off. Really great two factor company that uh, uh, changed the way people saw two factor because it integrated into the idp. Um, and some of my engineers while they're at Silence said, garrett, there's something missing, an identity that you should build. And you know, we always pick up our errors when we hear that. What's missing? What, what is what, what, what should it be be doing? And there's like, well, it's the governance part. And let me just, you know, for everyone out there, when people think of identity and security, they think two factories, okay. Or maybe they think single sign on. But there's three A's in identity. If you learned real early on in your career, there's authentication, authorization and audit and authentication. We're pretty good at that now guys. We really are. I mean I, I've been involved in authentication. I got like eight patents in authentication. That's, that's doing pretty good now. Okay. Uh, you know, I really do think the uh, the groups like at Microsoft and at Google for making two factor ubiquitous. And the second part, the second A is authorization is being done much Better now. It was 20 years ago. And is what you do with Okta, it's what you do with Entre ID, it's what you do with JumpCloud and ping and all that you come up with with authorization policies that at a single council can affect multitudes, multitudes of applications. And that's good. Centralizing is good. The third A is still a mess. This third A's is still 1960s auditing. Wow. Uh, it really is. It's really at, ah, you know, like a. A really prehistoric level. And people say we need AI. Well, we do need AI. I mean, we need a different A when it comes to auditing. It's called automation. And that's what uh, test is. It's automating the third A. And yes, there's a triple A. There's a AI component in there. But that was a, uh. That's my answer right there. Why does, uh, test is this? Why did we get started? Because the third A of identity is in prehistoric levels. Automating how to fill spreadsheets in Excel. Yeah.

Speaker A: Uh, and how do you solve the third A? Was you at S today?

Speaker B: So, yeah. So where auditing is today is real intelligent people, real smart people really inform people. I mean, you know, uh, there's no one that knows their codes and regulations more than governance risk and compliance people. You say SB53 or ISO 4201 or ISO 2701 or NIST, AI, RMF. They know exactly what you're talking about. Okay, how are they implementing that? The industry is implementing most of governance risk compliance with spreadsheets. Spreadsheets and emails.

Speaker A: You're saying 20, 26, they're still using spreadsheets today.

Speaker B: The vast majority of governance projects, when they say to do specific things like we need a user access review, which is what untest does. A user access review is what it is. Review the entities. Review all the entities in your enterprise and have a document that attest to who has access to privileged data, to sensitive data. PII for finance, PHI for health care, CUI for defense. Okay, that's not Garrett saying it. That's not other people saying it. That's the law. Okay. I mean, I can go down regulations that says you as a company, if you're holding sensitive data and you're letting people get it in, you have to attest to his access M. And what's going on today is most of that's like, okay, we got this, we got this. Here's, uh, Bob, go get Jane and the team to go run A user access review. What should, how should I do it? Ah, uh, here's some spreadsheets and emails. Just notify the managers and let the managers know they have to go through this spreadsheet and check off who should have access and that. And I'm not kidding, there's multi million dollar, billion dollar companies still doing that today.

Speaker A: I see it with my own eyes by the way, especially in governance.

Speaker B: Governance is really smart people often using very behind the time tools.

Speaker A: So this is what led you to start uh, test, um, to offer identity governance. Like what's your, how does your platform work first of all? And what's your target? Like what, what's the perfect customer for you?

Speaker B: Yeah, so great question. First, first the product. So, so what I do is uh, I look at what is this? I'm a, you know, hands on engineer that you know, worked help desk was an se, all that and I'm like how can I solve this problem? How can I solve this problem rapidly, okay. Without throwing a lot of bodies at it? Because there are solutions that work and there is as our, our industry does create solution that works. But they're right companies. Uh, which I'll get into the ICP then. Okay. M, the, the, the, the product, what it does is takes what people have everyone by 2026 has an IDP. What am I talking about? What's the acronym? Yeah, an identity provider that's active directory, entre id, okta, jumpcloud, ping something. You have something like that and you're holding the identities. I hook into that thing in less than five minutes and voila. Then I have a system that will audit those entities. But more relevantly, your healthcare, finance, insurance, our big industries, you have all these siloed resources. I don't care if you're connected to your okta or your entre id. I have a system, uh, test has a system that audits those directly. And that's our, that's our secret sauce. How quickly we can get audience anything out of it. And it's an ideal not only for enterprises but for MSPs and for the uh, uh, consulting who want to, you know, basically help their customers out. So our ICP of this is this. Now do we work with the companies that have the big legacy GRC tools? Yeah, we do because our product simply is better for the user access reviews than the legacy products. But I'm not a big rip and replace guy. I'm a real greenfield, you know, hey, uh, I go after. There's so many people who are still on spreadsheets or our ICP is we work with anyone from. We got uh, customers up to 10,000 uh, users running um, about 900,000 roles through this thing. Every audit. But our ICP, the ones that really hit are the 100 users to 2,500 users. With the sweet spot being 750 users to 1500 users. Because we work with customers, they have a hundred users, you know, employees, whatever. But they'll have 500, 700 entities.

Speaker A: Wow.

Speaker B: Non human identities. Your partners, your contractors. There's a lot of identities now that aren't employees anymore. And this are, you know, those are real, real problems.

Speaker A: How much do you find um, uh, people who like when you, when you, when you run the audit. What do you say the percentage of. In an average enterprise. Let's just say 10,000 user enterprise. What percentage of uh, people should not uh. What. What do you find uh, as far as percentage wise?

Speaker B: That's a really good question. You're going right at it. You know the ghost orphan accounts, if people haven't been doing, haven't been doing automated. Automated reviews that they'll find easily 15% orphanage. Wow.

Speaker A: That are just hack too, you know.

Speaker B: But uh, the biggest concept in hacking is dwell time. What hackers want is to stay in your system. Okay. Now the problem with, with the, you know, if you look at. From the hackers. What about the active accounts? There's enough of those. Yeah, but when you have an active account, they. People kind of recognize what you're doing because there's the amount of it. What they want to find is the orphan accounts that people aren't using so they can impersonate act them and they basically you're able to act in impunity. So if you got 10 to 15 of your accounts are orphan accounts that you know, really don't have a real user associated. And let me explain what that means because what it could be is, you know, it was in sales. So he had access to Salesforce, but he actually switched over to marketing. And he's not in marketing anymore anymore. He's not in sales anymore. But he has access to all these sales tools. So that's orphaned. Garrett still is an active account in Salesforce because no one's ever removed them. You know. And there's two concepts in identity governance you should always be aware of. Privilege creep and privilege drift. Creep means you keep on adding privileges. And privilege drift is sometimes you get off from your where where you meant. Wow. And that's the natural state of identity is to grow and to grow. The reason governance has things that are called controls. Is that's supposed to mitigate and to circumvent that natural state of moving on? Yes. So that's what user access reviews. And that's why we automate it to combat privilege creep and privilege drift.

Speaker A: And which industries do you guys focus on today? Is it healthcare?

Speaker B: Healthcare Finance, Insurance. Healthcare finance, insurance. We have, we have customers in education, we have customers in uh, uh, retail, uh, we have customers even in defense because they have cmmc. But the biggest ones are healthcare finance and insurance because they're actually the most mature and everyone has a problem with this. But as much as we put down health care and blah blah, they're always behind, they're least cognitive that there's a problem. So in many ways, you know, I'll give them, um, let's give my hats off, they know that there's a problem. Okay. In all industries, I mean all industries have this problem. I mean, and remember in all industries that are under regulations are you go to a elementary school, they're holding phi for kids and they have this problem just as much as others do.

Speaker A: So how do you um, do you work with MSPS today? And if so, yeah, I'm glad you

Speaker B: uh, pivoted to that MSPS. So let's talk MSPS, managed service providers and MSSPs, the managed uh, security service providers. Why do I make that distinction? Because MSPs are your delivery point now. They manage people's entitlements and they manage their, a lot of the device management and et cetera. Okay. They have their skills and what we're saying is, hey, we built a really simple tool that you can review your identities. Now we're working directly with some MSPs and training them and it's a good thing they're coming on board. We're also working with MSSPs. And what's that? Those are those service providers who provide services to the msps. Okay. And it's a real, real uh, um, simpatico relationship. Whereas the MSSP says hey, I'll just put this as, as a contract to you. We'll manage these, we'll run the user access reviews and the msps are grateful that way so that it's a shout out for both industries either way. The way it's going is there's more and more outsourcing, more and more outsourcing of this type of task to MSPs, MSSPs. And the third party, I'd say straight out, are consultants, I swear. Well, I just got off a call and the guy goes Is he an uh, MSP or a consultant? And I go, I think that distinction is a distinction without a difference. Okay. Yeah, right. So many consultants are taking over work that the MSPs do and the MSPs are taking work that consultants do. And it's really a distinction without a distinction or whatever the phrase is. I see it so much, I have the exact same conversations with consulting services as I do with the MSPs, the MSSPs.

Speaker A: Right. What do you say, um, what's the process to become an MSP? And also what do you guys offer to the MSPs today from.

Speaker B: Yes.

Speaker A: Uh, is this a long training period to learn the tool or this is just a plug and play?

Speaker B: Well, first of all, there is nothing more important than the msp, than the bottom line in a good way. Right. The margins are low. So when I went and built the MSP product, I want to talk to a whole bunch of MSPs at convention and still do and took in their input. They said, garrett, there's two things you guys do wrong. And you guys being the uh, uh, uh, guys who build tools for the MSPs in the theory to use. One is your pricing's wrong. You expect us to know how many users are we're going to use. They don't. And let's respect them. They, they offer things and they let their customers decide. Now I have MSPs who have actually become the adult in a room and say, hey, if you're in healthcare, finance, insurance or in government, you have to take this package. And I think that's the right way. But anyways, so we did the pricing that way. We did the price and it says we do not charge you up front. There is no, no upfront choice. There's no, uh, there's no setup costs. All you do is how many you use that month. Okay. Right. And that's, that's. And they can, they can make a real good profit off of that. The way we align this, we can actually. Where we align this is, uh, they can double our price and still be half the price of the big guys.

Speaker A: So I think that's very compelling. It's just, it's an easy entry. It's, uh, an easy. It's not, you know, and the other

Speaker B: thing is we greatly simplified. That's the other thing they asked, is it pricing? And then your admin council. Because the people build these products for quote unquote, for the MSPs, but they don't put any RVAC in it, you know, and we have multi tiered RVAC that one FTE at the msp. Msp, uh, MSSP or Consulting Services can get on there a new granular control, go to this much control as his whole console where he has all the different enterprises, uh, that he's managing. So we're ready for the MSPs for this.

Speaker A: Okay, so here's another question. Um, if someone wants to try, uh, the uh, test platform, is this a,

Speaker B: a free trial or how, how we uh, uh, practical. All of our sales have been through POCs. Good. Literally about 90.

Speaker A: So it really gives the customer, uh, time to try it out and.

Speaker B: Yeah.

Speaker A: And see how it works and all that stuff.

Speaker B: We have people trying to remember thing with uh, input in their HR data to putting in their PAM data, put in their IAMs. Always use your IAMs. Or they got these siloed resources because they're in healthcare and finance and insurance and they just do it straight. That way we have a really, really simplified way of inputting information into this.

Speaker A: Here's another question, Garrett. Like, as far as AI goes, where is IG going with AI? Is this going to be a lot more integration with AI and so forth?

Speaker B: I really think where AI is the best in governance is helping reduce the time of what should be investigated.

Speaker A: Right.

Speaker B: And that's where we have a patent and we have it built in a product already where we uh, came up with an Identity Trust Score. And the Identity Trust Score.

Speaker A: Okay.

Speaker B: Yeah, yeah. Look up, uh, uhs, its Identity Trust Score. What it does is it goes through your enterprise, goes through your identities and says these, these accounts and these users are at risk. They're at risk for the enterprise security because.

Speaker A: So cool.

Speaker B: Yeah, yeah. Using AI, they have segregation of duties, uh, violations. The groups, uh, are out of whack. Right. And there's something completely different. This is a whole brand. I have. One of the big problems in IT is that we have very intelligent people in grc, but the IT cyber people do not know what they're doing. And it's not like they hate each other, not like they're big companies. Everyone's running, you know, like, you know, cats and multiple hats. Yep. Yeah. So what. What our product does is it takes in account the work that the GRC folks have done. Have they done a review? If they've done a review of this account, a USS review in the last month, last 30 days, whatever. Okay. There's some confidence. If no one's reviewed this nhi, this admin, this user account for three months, six months, a year, we degregate the Identity Trust Score and That's not being done by any other product in the world, and that's being done in UITest, and that's with AI. And that's as simple to read on the dashboard.

Speaker A: Wow. So that technically, uh, is it running in the background, um, to monitor M?

Speaker B: Yeah. And then all you do is you run a report and you say, hey, I want this group, I want to know the itss of all this group, I want to know these. And then you go to that dashboard and it shows you. Yes.

Speaker A: And how long does it take to do all this? Like, you know, 10,000 people is a lot of people. So how long does it take?

Speaker B: The reviews themselves are all automated and the ITS is just pulling the information from the, from the reviews.

Speaker A: Wow.

Speaker B: So it's, it's, it's all there. And remember, where this is all going to go is, uh. Remember I started with the three A's, Authentication, authorization and audit. Well, where we gotta go with AI is the feedback loops. That's why we get hacked so much. Guys, there's M. One group doesn't talk to the other. The feedback loop is I'm the third A the audit, but I can feedback via, uh, a signal back to the second A. Should I be trusting this user at this level? And that's where the ITS comes in. And we have APIs that can pull that. This is not, you know, on, um, Mike itself. Guys, this is what Zero Trust is supposed to be. Zero trust is supposed to be a reauthorization. And you want to call it authentication, fine. It really is a reauthorization of, uh, a user at each step in the transaction. And what, what you're supposed to be doing in Zero trust is you're supposed to be grabbing signals, Signals, the best signals you can get at that time for this information. Okay, and that's what you attest is providing. It's providing a signal that you can do a better decision. You know, let's say someone's trying to, uh, ah, exfiltrate a terabyte of data. Right. But it authenticated, Garrett. So it's gotta be trust. No, in the authorization phase it should be. I haven't. No one has inspected this user for a year and a half. It's got way over permission. My ITS trust score would be very low. And then the automated enforcement point, using the US ITS signal can flag it and shut it down. That's how this should all work.

Speaker A: Interesting. So what, what CEO is today? If, if a CEO is listening to this today or cto, cio. What's you know, what should they look for if they've never done this before?

Speaker B: Well one is what is your GRC budget and, and how much you spending for tools? I mean the bigger companies in a good way do have budget for this stuff. They're just overpaying. They're overpaying on services and they're overpaying on tools. Tools like UITZ come in, I come in a license price about one tenth of what the big guys will charge and a service cost 1/100th. Wow. Okay, so your budget right now there sees you uh, know, CIO C CEO is, is too high for this. You're, you're paying the money you're paying to review this stuff. You're paying, you know, usually large sis. Using large things. You're just paying them too much. And I, I can uh, give, give you a test, a try in your, in, you know, in demo accounts or that kind of stuff and we can show you we can greatly, greatly reduce your course and, and governance posture. The product works. I've done, we've done like 4.3 million attestations and uh, we've been reviewed by all the big guys, the Accentures, Deloitte's, the E and Y. All the companies we don't get reviewed but the reports that we generate at the customers get reviewed by these enterprises and that's ready for it.

Speaker A: So it's a signal then for CEO, cto, cio, um, is it just budget or, or should they be looking at obviously their whole security posture. But is there a specific one thing that you see, people tend to say okay, I gotta do this now, you know, I can't wait anymore.

Speaker B: Well, you know, the real thing, especially in the bigger companies, they have, you know, yearly. One of the big reasons you do a user access review is your socks, your Sarbanes Oxley sox. Okay? Mhm, mhm. Those are costing enterprises on average and a low average of a million dollars. A lot of that is user access reviews. Where is that budget going? It's just one of those line items that people say well okay, I gotta do my socks audit, you know, shuffle off on uh, one point million to this hole, you know. Okay, where's that money going? Right? You know, maybe you want to break that down and it goes for other, you know, the HIPAA compliance for uh, uh, uh, for, for uh, PCI dss, which is your retail, your bank ins, the ncua, your uh, FFIC and uh, and insurance. Insurance has tons of regulations. Okay, cool. What? Look at that line item for user reviews. User attestation user recertification. Why is that so hot? It doesn't need to be. There are products. This is what, uh, test does. We can greatly, greatly reduce your costs. And we have ways to do this. We can train your own team. We have MSPs and consultants and do it. And we can do it ourselves with our product. But. Wow. Yeah. Uh, uh, and we have great loyalty from the people who use this product. There was a very large company, very large company. All know the name. I'm just not allowed to say. And they use this product. They've been using it for multiple years. And the, uh, CAO came in, new one said, hey, we got too many vendors. You got 25. I want to get this down to three. And so they were going to remove UATASS from the governance group just, you know, based out of the, the rough cut. And the group said half of the team said they were going to quit because they're like, I can't do the job. And that's, that's what we offer. We offer a product that works for, you know, one tenth the price. And it has great stickiness because it works. It allows you to review not just the users, but now it allows you to review your file shares, your Microsoft Teams, OneDrive in, uh, SharePoint. You know, especially if you're in a PII company. Right. You know, you're in healthcare, in the pharmaceuticals. Do you know what files have been shared? You're supposed to.

Speaker A: Nobody knows.

Speaker B: Are good regulations. We should know. You know, good God. You know, a little thing, but called the F35. It would have been good note where we were sharing those files.

Speaker A: M. And, um, this is very important. The more I listen to what you're saying, it's very important to do this even for companies are not running through, um, a security audit. They should really take a deep dive about, um, their security posture, who has access to our data and so forth. Because again, this is how you get hacked. Right. But also is having a peace of mind, um, when it comes to your security, um, your security footprint. Here's another question yet. You know, you've been doing this for so long. Um, you know, what is the growing pain, uh, of cybersecurity today, do you think? For, for.

Speaker B: I think. I think it's. It's converging to identity. You know, they always say in me, I think it gets lost on people new to the industry. Why do they always say it's converging to identity? Well, security guys, when Walid and Garrett got into the world of security and it's worth saying when you said security, you were almost assumed to be a network person. You really were. You know, you knew how to segment, you knew how to route, you knew how to do layer two to layer four and you knew how to set up a firewall. That was most enterprise security was at the network level. Mhm. Network doesn't even exist anymore pure cloud with someone with a mobile. Okay. So the most important security component now is the identity, the identity and the authorization that identity has. Now the network didn't go away. They were the first adapters of Zero trust, which is reauthorize the user. So identity and network works together great. But there's a lot of places where there is no network. You know, the cloud has taken over and the only enforcement point you got in the cloud is a secure identity.

Speaker A: Yeah. And especially if you have a multi cloud infrastructure today, uh, aws, Google, Compute Engine, Azure and all this stuff, you know, that's so much information to manage and not knowing who has access to what. So your platform does all that stuff.

Speaker B: Yeah. Without, without automation it can't be done. It literally can't do it. There's no way any enterprise over I think the numbers getting pretty close to like 2025 users because of all the contractors and can do this stuff manually and know who has access to. So if you're you know, a real company, you got 100 users which means you probably got 300 to 500 entities managing your services and all that. And if you haven't automated those reviews, you've got, you've got a lot of hidden, hidden, you know, uh, uh, gremlins running.

Speaker A: Okay, this is the last question and give me five points of what leaders in IT today should look at. Um, five steps that they should take immediately today after watching this podcast.

Speaker B: I like what you said that. What's the first step? Mhm. Working with some consultants right now and msps. Like I said, it's pretty much the same thing to me to how they work. When they take out a new client, both consultant and whatever, they always give them in a good way, a pen test. And I go great. What do you think? What are you pentastic? You know, they're pen testing ports, they're pen testing application flaws. Good, good, that's good. Given that 75 to 80% of your hacks are coming from identities, don't you think you should start your new job as a C. Right. Your new gig as the MSP provider, your new gig as a consultant service in doing an identity pen test. I'M working with this one great guy. Um, he is a concept, uh, of adult in a room. He goes, garrett, they're hiring me to be the adult in a room. And then he looks him in the eye and says, okay, uh, I'm going to take you on as a new client. One of the first things I do is. And he does, he, he goes, I'm going to get you a managed identity service, something octa, you know, entra id, you know, single sign on. I'm going to put in two factor and we're going to immediately conduct a identity pen test. That's what I call it. That's what he does in his work. It's just a access review.

Speaker A: Mhm.

Speaker B: Let's go through your users, let's find all that, you know, if.

Speaker A: Right.

Speaker B: If they've never done one, it's a lot higher than 15. Sometimes they got 30, you know, 40% of just garbage in there, you know, excess privileges, ghost accounts and all that. That to me is the 2026. I'm the new it guy. Uh, it's my responsibility. The bullet goes to the bat. My back. When did we get hacked? This is the first thing we have to do. We have to review all the users and privileges. And that's what UHS has. We, we call it a one time identity. Identity pen test. You just run this product over the relevant services, remove those users and get going. Mhm.

Speaker A: And the second thing?

Speaker B: Oh, second thing. Uh, after that. Well then you have to, once you have that set up, you have to manage it. You know, I mean every culture has its flaws. Americans are really good at starting something, consistencies, you know, you know, it's not sexy to keep doing, you know, the right practices. That's what we have to do. It's maintenance.

Speaker A: Got it. So the first thing is. So the first thing, as a CEO, watching this, get, get in touch with your IT and review your user access. Review. Second thing? Um, you know, managing it. And what's the third thing?

Speaker B: That's what I'm saying. The second thing is it should be, uh, what is your practice as procedures? That's what a SoCS report is supposed to show. It's supposed to quantify the practice and procedure. Same thing for AI guys. I'm doing a lot of consulting and talking to people around ISO. AI. Um, uh, iso4201, which is your practice and procedures around data and algorithms for secure and governable AI.

Speaker A: Okay, so this is, hold on. This is very important. Yeah. So AI is, you know, everybody's given access to AI. How is that going to work with it? This is very important.

Speaker B: AI is, you know, it's just the extension of our IT systems. It's algorithms, it's data and its users and we have to quantify. And that's uh, the, uh, ISO 4201. The other ones do a good job too, especially OSH top 10. They're straight out and saying, okay, you can't trust, you can't trust the AI if you don't know who has access to it, who had access to the data, who had access to the retraining. You can't, it's not governable AI without that information.

Speaker A: Yeah, because sometimes even, Even when using ChatGPT, for example, you know, um, sometime I wonder if they're, if they're archiving my prompts, you know, and, and what they're doing with that data, you know, 100%.

Speaker B: Yeah, yeah. And, and what is your, who are the people that have access and what are they doing? Okay, Especially the AI that enterprises are building and all that. If you can't, if you can't trace back, that's people. If you're trying to stay up on the laws on AI, look up AI transparency laws. That's what it's all being called. Transparency means that you, the enterprise, especially if you build your own AI models are transparent. And what they mean by transparent is that you actually understand and can demonstrate who built the models, who built the data, what type of data you actually put in. And that's just hardcore governance. The same way we did it is that we know who in the AI world, we know who collected the data, we know where it's stored, we know who wrote the algorithms. This is all documented. And when this is all comes back to access management, it should be groups. I authorize people to have the data if they were in this group. This is the AI data governance group. Okay. And then you should be able to show two things with, uh, test type attestation reports. And you should be able to show the auditor, this is who has access to. So that's what all has to be set up. That's the way AI governance should be. Yes. This is, I would say you should be challenging your team. This is the last part of this one to always looking for automating processes. So you come in there and you go, we got to do a review immediately. Then we got to set up our practices. And then you look at the team and go, okay, now that we've got things settled and things are decent, how do we do this? Every quarter. How do we do this every month? Right. I mean, they're saying now that, you know, healthcare and finance, insurance, industry say that you should be reviewing your, uh, admin accounts every month. Yeah, right. And that's, and that goes back to your automation. But that, that's really, it is, is, you know, you got to do your triage, come in there and say, guys, we got to find out what we don't, we don't know what we don't know. Two, we gotta, uh, set up this regularly, and three, we gotta put the automation tools in.

Speaker A: Okay, One other question that I always think about. Do you think because of AI and everybody rolling AI is gonna increase the cost of compliance? Um,

Speaker B: no, I think, actually, I think AI has helped, uh, I, uh, think two ways. So the average company is going to increase the cost? No, because companies like you with us are bringing you AI solutions that reduce your cost. But I will quote, uh, the, uh, uh, the gentleman who started Netscape and his name eludes me, but he said, what's the threat of AI? And he said, there's two threats to AI. One, China does it better than we do, and that's just standard competition. So, I mean, that's pretty. And no one's bashing the Chinese, but they're allowed to compete. We got to compete, uh, and keep up with them. Great. The other one he said is over regulation. And I, I, I, I like ISO 4201. I think it's, it's prescriptive. I think the OAS top 10 on AI is fantastic. It's not kind of good. It's fantastic because it's very prescriptive and how that AI should be managed in a good way. It just says straight up, number one, it says, you gotta know his access to this stuff. Okay. And that's, it's a great. The OAS ended up fantastic. Then there's other ones out there like nist, AI rmf, which are kind of scary. It's very nebulous and it's very nebulous. And how it's written, I, I almost see it as dangerous because if you have nist, air, uh, is not a regulation. But anyone who's been around the block knows that a lot of stuff that NIST writes does become regulation. M so that's where I'm just nervous. Got to make sure that we keep, we as an industry understand that we have a powerful tool here. Tools like the ISO4201 and the top 10, uh, uh, Oasis are very good tools to help us through Our governance. Okay. And then as a industry, we got to make sure that whatever regulations that are put on AI are helpful. You know, I mean, in many ways. Well, it's no different than, than, uh, PCI, um, DSS 40 years ago. And I go, where are you going with that? I go, well, there was a huge hack on, um, uh, I think it was TJ Maxx that they stole all the credit cards from and all that. There was all this nerviosity 40 years ago on the usage of credit cards because people weren't DNS secure. The industry put together pci, DSS and said, we've got to make sure that credit ah, cards are kept securely so the industry feels comfortable. And I kind of feel the same way about AI. Okay. Where it's not. We shouldn't look at regulation and governance as a threat. We should look at as a, uh, how we make people feel comfortable with AI. Okay. And, and that's, I think that is our challenge around AI is, is be an adult about it and enacting right now proactively acting governance. And then when the laws come out, make sure that those laws are actually attainable and helpful.

Speaker A: Right. I would assume all these laws coming in in the future, they're going to require, um, you know, tools like uotas, um, to run these audits on a monthly basis.

Speaker B: Um, they will, they will be asking because you can read them and I can show you that I've done, uh, intersections with my product to every single one of them, from AI, uh EU AI act to the SB53 pass here at NIST RMF M. They all expect the enterprise to have an understanding, a clear understanding of who has access to the data, algorithms, the retraining and the usage. Got it.

Speaker A: Well, um, this has been very interesting, um, listening to all this. So Garrett, thank you so much for your time. Um, how do people reach out to us today to try out your platform and um, maybe some pointers on that.

Speaker B: You attest that is it.

Speaker A: Why?

Speaker B: You attest. Move this thing a little over. Look at that. There it is. You attest. Okay. You attest.com or info@uatest.com or look up Garrett Grajak. I think there's only one of them on LinkedIn. I'm M on all the time.

Speaker A: You are the best. Thank you so much, Garrett. And guys, this was a value proposition podcast. Uh, please reach out to Garrett if you're interested in learning more about the, uh, test platform. I think this is great. Very important as you as a CEO, C. CEO, uh, of a company CTO to understand, um, your security and compliance and have a clear understanding of who has access to what. Garrett, thank you again. I appreciate your time. And, uh, we'll see you again, hopefully, in the future.

Speaker B: Great stuff, Wally. Thanks for having me on.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Rebooting Enterprise AI with MCP and KubernetesPractical AI · on Okta88 / 100
  • The Evolution of Human RiskSimplifying Cyber · on Okta83 / 100
  • How Consumers Are Defining Healthcare's Future w/ Dr. Daniel Kraft, Founder, NextMed HealthCareTalk: Healthcare. Unfiltered. · on HIPAA81 / 100
  • AI-Powered Forensics: How Attackers Automate BreachesCloud Security Podcast · on Active Directory78 / 100
  • Christina Tubb - The channel partner as your local bodyguardPartnerships Unraveled · on Ping Identity77 / 100
  • Harish Peri (Okta): When the Thing Accessing Your Systems Has a BrainThe Road to Accountable AI · on Okta77 / 100

More from Valueprops

All episodes →
  • The MSP Problem No One Talks About42 / 100
  • Your MSP Is Probably Overpromising Here Is How To Tell In 202678 / 100
  • Is Automation Solving Your Problems or Revealing Them?
  • Why do software projects still struggle even after hiring good engineers?
Explore the best B2B Ops podcasts →
All Valueprops episodes →