AI-Driven Identity Management with Zilla Security’s Deepak Taneja
Deepak Taneja, CEO of Zilla Security, discusses the challenges of managing identity and access in today’s cloud-driven environments, emphasizing the complexity of traditional identity governance solutions and the increasing importance of identity as a security perimeter. He highlights the need for AI-driven solutions to streamline role management, access provisioning, and security monitoring in order to mitigate risks from over-privileged and orphaned accounts.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Deepak Tanja, who's CEO for Zillow security, and we're talking about reinventing identity access management, the controls and everything that goes with that.
'cause while we're entering this new age of ai, Deepak, welcome to Sean. Thanks, Mike. Great to be here.
I'm wondering about what it is we need to reinvent. Exactly. 'cause I mean, a lot of organizations are still using, I don't know, active directory to manage this stuff.
And other folks are more advanced in talking about zero trust. So I feel like we're all on some sort of extended journey, but, um, it doesn't seem to be working either. So what exactly is wrong with the way we manage identity access today and what should we be thinking about?
Yeah, great questions. I think, uh, Mike identity, of course, has been around for, for, for ages. Um, we've struggled with, with identity and access and permissions, uh, but going back 20 years, um, the idea of managing access, managing permission started to become really critical for compliance reasons.
And the, uh, identity governance space was born out of that. So while, so identity management is sort of split into two parts. There's sort of the, the authentication and single side sign-on side of identity.
And there's the identity governance, identity compliance and provisioning side of identity, which has become its own its own area. Um, and, and we've struggled with that. It's been a lot of the identity governance deployments in the last 20 years have been complicated, manual, expensive, um, hard to deploy, really very services intensive.
Um, but in the last 10 years, what's happened is the cloud's come along. And now in the last five, the adoption of the cloud has been so rapid that organizations have this explosion of applications and permissions. And, and while that's happened, it, there's this growing realization that identities become the new security perimeter.
So we're dealing now in a world where there's hundreds and thousands of apps. Um, the ownership and administration of those applications is decentralized, and identities become this critical new security vector. So that identity governance side, you know, the, the half of identity that's been focused on governance has become super critical and has become even harder to use and deploy.
Right? And in fact, that decentralization, the decentralization of context has led to companies kind of throwing up their hands and, and, you know, they, they don't know how to get their arms around access. They don't know how to get their arms around permissions, which of course, um, it, you know, requires new technology, new solutions, which is where Zilla zilla Zola's comment.
Aren't we even aware of the extent of the challenge? And I'm asking the question. 'cause a lot of times the permissions for accessing something are managed by some administrator somewhere who may belong to a business unit or a business team.
And they're not really cyber security experts. They're just in charge of handing out access. And these are the tools that you need to do your job.
And then people's job roles change, but they don't change the permissions or, um, the privileges or overextended in ways that give people access to something just in case, and they never need. But eventually their credentials get hacked and suddenly the cyber criminals have access to everything. And it just seems like we're kind of our own worst enemies here.
So, um, who's in charge? Yeah, that's, you're exactly right. Um, all of those points you were spot on.
In fact, most data breaches today are rooted in some sort of identity and access exposure. And to your point, um, you know, the, the application owners in the far-flung corners of the enterprise, they're not security experts, right? They're not compliance experts.
So it's a, it's a, um, you know, a, a problem that a centralized team in security and compliance is grappling with, and yet they don't have the context to really deal with it. The stakeholders, the folks who have the context are, are out there in the enterprise, uh, owning and managing their own applications. And what's needed is a new approach to all of this that somehow brings all of those stakeholders in and brings their context in to this to a centralized approach of problem solving, right?
Um, where you mentioned the word role, right? So the idea of roles are back role-based access control has been around for decades. Um, what organizations have struggled with is defining them, defining business roles, and then maintaining them through all the changes that are happening.
And now, if you look, think about the cloud era we live in, that's become almost impossible because the context is all out there with hundreds of application owners, and there is no centralized role team that is capable of defining business roles manually, right? And of course, that makes, it's a great opportunity to leverage ai, in fact, to, to reinvent, uh, RAC and, and have AI managed managed roles. Um, so in all of this, I think, uh, what identity is complex and identity governance is not easy.
And yet, um, there are new approaches. There's new technology, new solutions that can be applied to the problem to make life much easier for enterprises to take all that manual work out of the equation to get, um, application owners and data owners to collaborate with a centralized team in a way that, that builds identity processes like compliance, like provisioning, like security, just into the fabric of the organization. I don't know if this is possible, but I always find that changing human behavior is hard.
So is it, can we separate the governance of the identities from the provisioning of the identities so that, um, even when people decide to do something, that's probably not a great idea, there's some team behind them that can go in and see that and kind of adjust those permissions and controls in a way that is lined up with a best practice. Yeah. You know, the challenge of course is that, um, you know, this idea of least privilege access, which is central to, to governance, um, starts with on day one with provisioning, right?
So if, if, if, if John in finance starts with a company Monday morning as a financial analyst, and if right off the bat he is given access to 47 applications that he doesn't need access to, or is given, um, you know, elevated access, administrative access, more access than he needs to do his job, you know, we're already in a hole right now. Now there's work down the road for someone to start cleaning up that access. Is this, is this overprivileged?
Why is it overprivileged so provisioning, even though you, you, you're right. And I think conceptually we think of provisioning, um, you know, as being something that, that is off on the side. It really isn't anymore.
'cause identity is such a, such a critical issue. Access is is such a critical issue. It's, I think provisioning has to work off of the same, uh, the same centralized view of permissions, the same approaches, the same, um, uh, the same model, if you will.
Um, which, which leads us again to the idea of, of roles. Um, you know, we at Zillow call them AI profiles. So right from day one, people, new employees, for example, through AI based profiles only get the access they need to do their jobs.
Right? And that makes, and the same profiles are then usable when it comes to access reviews and compliance, so that people just have to review the permissions that people have outside of their profiles, right? So it, it, it is, provisioning is very much now plugged into, um, the same, um, um, overall model of, of identity and access governance as compliance and security, if that makes sense.
Mm-Hmm. I think one of the things that has changed over the years is so much of the breaches back in the day were what I would call a smash and grab. And now it seems like the bad guys are stealing credentials and acting like a regular user, and they're quote unquote living off the land, and they may be in there for weeks and months before they strike.
So, um, is identity also part of the way we need to think about maybe containing breaches because, um, otherwise, you know, when they get in there, they just wreak total havoc? Yeah, absolutely. So if you follow, um, you know, a phishing attack, um, you know, and what, what a rogue actor will do typically is someone will get phished and they will then take over that person's account, and oftentimes they will actually not use that account to, to do their mischief.
They will then go create a new account. And the reason for that is they're worried about the account that they've just taken over being watched, particularly if it's a privileged account or an administrative account of some sort. So, um, so they will either create a new account or they will try to get elevated permissions with the existing account, right?
That's, we need to be watching that, right? To your point about breaches, if, if we can stop them in the tracks right there, um, you know, you, you basically, uh, prevent major damage, right? But what happens today with most of these data breaches is, is new admin accounts get created, new service accounts get created, existing accounts that orphan accounts, um, that perhaps are left behind by, by departed employees get taken over, um, people elevate their existing privileges.
And some systems like the cloud infrastructure platforms, uh, you know, there's ways in which they can do that. Um, and not now. No one's watching, the enterprise isn't watching.
And so that's, that's what, um, that's what we do at Zillow. One, you know, when we talk about our security functionality, we think of identity governance in terms of compliance, lifecycle management and security. So our security functionality is all focused on watching, constantly watching for identity and access exposures like this, look, a new account just got created, A new privileged account just got created.
Look new, someone just got a new permission. Well, is there a ticket for that? Is that an approved assignment of a permission or not?
And that's what will stop these, these problems from, from happening. Uh, it is a hard problem because there's just so many applications out there. And so it all starts in some sense with the ability to integrate into the reality of an enterprise, the a, the access reality.
What are the accounts out there? What are the permissions out there? And if you can't do that, then of course you can't recognize any changes.
Mm-Hmm. And it also seems like there's a lot of rogue accounts that people have created and forgotten about, or people are sharing with other folks in ways that are probably suboptimal. Um, do we just need to have better behavior?
Well, I think we can certainly, you know, security awareness training, we can train people on better behavior. But, um, in the end, there needs to be a system of record for what was done when, what was assigned to whom for what reason. There's this service account that was, it's, it's there.
Well, who, why does it exist? Who, who created it? Who owns it?
You know, for literally for every non-human identity, they should be an identity owner. 'cause otherwise you have no context about it, right? So that system of record, I think is what's missing in most organizations.
And, and we tried as an industry in the on-prem era, sort of with identity governance products to create that. But the cloud and SaaS, the, just the growth of cloud and SaaS and machine identities, it's just broken, broken, all of that. So we need a new approach that's much more scalable, that's much less manual, that's much more automated, and that we believe starts to rely on AI because some of these things are impossible to track manually, right?
Mm-Hmm. And it's very hard, for example, to define these roles across hundreds of applications. No, no human can do it.
No roles team can do it. Um, so, so this is where the new new technology starts to come in and, um, and really help out, help out enterprises. So how does that AI approach work?
Because, I mean, am I creating a bunch of AI agents that are monitoring everything and that's happening or, um, how exactly does that AI know what's occurring and surfacing up a recommendation? Or is it taking action? Yeah.
Um, you know, the interesting thing about AI is we don't, while AI has so much potential, we don't just trust it blindly, right? AI has to be explainable. And, and that brings in a lot of user experience challenges as well.
How do you lead people through the conclusions that AI is making, the recommendations that AI is making? So our our approach to this at, at Zillow is to allow the AI to just build AI into the, into the platform, into the overall model, into the framework, um, and, and then have it automatically collaborate with the people who can validate the conclusions. So we don't actually think of it as recommendations.
'cause uh, I know that's a model that's popular in the industry today. Oh, we've got these 16 recommendations while you decide which ones you wanna pick. And our approach to that isn't recommendations as much as the AI has reached these conclusions, and this is why it's reached those conclusions.
Um, at a, at a granular level, we allow a, an application owner or a data owner or an, or a permission owner to say, yeah, this, I, I, I agree with this. Uh, and if they don't agree with it, that's okay. There's the nothing is gonna go wrong.
Um, you know, maybe 70% of a role that AI, Zillow AI defines actually goes into deployment, but that's still a huge win, right? Um, so it's not all or none, you know, we think of it as AI is creating these bundles of permissions for, for use in identity governance processes, and is collaborating with people who have context to get these bundles approved. But even if 20% of a bundle gets approved, that's okay.
That's still a big win, right? I think in roles, particularly the industry sort of went overboard. We tried to, we tried to get too smart for our, for our own selves, uh, defining nested roles and hierarchical roles, and pretty soon organizations had more roles than they had people.
And, and, you know, we, we think we should, AI can get us 80% of the benefit of, of roles, uh, with, with, with 2% of the pain, right? And that's, that's the idea here. I seem to remember there being a function in a lot of organizations called governance, risk management, and compliance.
GRC has all that kind of folded into cybersecurity now, or is that the, is that where we're headed? Yeah, it's, it's, it's still around and it's still critical. It hasn't folded in as much as it has become.
Um, um, you know, it's, it's still a key, a key piece of the overall, overall enterprise risk management framework. I think the GRC models and the GRC platforms, the GRC processes are more an assessment of the overall risk and the compliance, the evidence around compliance processes. Um, I think those GRC platforms need to be connected to the reality of the security practice or the compliance practice.
Yeah, there's evidence of, you know, you actually have to do an access review to have evidence that you're meeting that control. And so the GRC model might say, there's this control for sox, for hipaa, for GLBA, for SOC two, whatever these frameworks that I have, I must do access reviews, and I need evidence that the, an access review is being done every three months. Okay?
Now, something has actually, there has to be a practice that actually makes sure that an access review is done, and that, and then that has to be connected to this GRC model and has to say, okay, here's the evidence that it's happening. See, I did this last quarter and I found, you know, 600 permissions out of 60,000 were revoked, and out of 600 that were revoked, 598 were actually completed successfully. That's the evidence.
And here's an evidence package that an auditor could look at, right? So it's actually hooking up all of these pieces together so that, um, we, at the risk management level and a compliance framework level, we have a model, a risk model, and a compliance controls model. Uh, and we can judge based on that, um, that the organization is meeting, its, its requirements, it's meeting, its its risk levels, it's dealing with the regulatory mandates that it's subject to, and then that needs to get connected to the actual nuts and bolts of what people are doing in the organization and what the tools are doing, right?
So GRC is, if anything, is an even, even bigger piece of what organizations have to do today, but it still remains, uh, sort of off on the side, uh, connected to the compliance and security practice, but not really delivering the practice to companies if, if, if that makes sense. There you go. Well, folks, I heard it here.
I think it's fair to say that if we have a schizophrenic approach to identity, we're gonna have, uh, an outcome that is well less insane. Hey, Deepak, thanks for being on the show. Thanks, Mike.
Delighted to be here. All right. And back to you guys in this tune.