Securing Machine Identities: The Next Big AI-Driven Cybersecurity Challenge with Oded Hareven
Akeyless CEO Oded Hareven explains why securing machine identities in the age of artificial intelligence (AI) is about to become the next major cybersecurity challenge.
Transcript
Hey guys. Thanks, fitro. We're here with ODed bin, who's CEO for Akili, and we're talking about well, machine identities and secrets, and maybe even how we're gonna maybe no longer need secrets in the future.
We'll see how this all plays out. Hey, ODed, thanks for being on the show. Thank you, Mike.
Yeah, good to have you. Good to, good to, good for you to have me, and thank you for that. All Right.
A lot of folks are trying to figure this out. Now. We've just started kind of wrapping our heads around the idea that humans need to be secure because of their identities, and they have multiple identities.
And now we're starting to understand that machines and heck, even software components, have identities as well. Are we able to manage all this, or, I kind of think a lot of people are looking at all this and they're feeling a little overwhelmed. Well, um, I understand why people are overwhelmed, especially within the cybersecurity industry.
Things are moving at the speed of light, and it has been only in the last, you know, you may say 10 years now, that the industry is talking about human identities and accounts and what does it mean, right? Uh, before, um, everyone understood that, you know, that credentials and passwords are need to be secured, and this is a notion that took some time for, uh, professionals to completely understand and for that to be a commodity. Uh, but recent years actually brought a new challenge, which is the machine identities or the non-humans, um, as a result of the rise of those machines, machine r um, automated processes, the DevOps, CI/CD processes, services, uh, service accounts, APIs that have been created in the organization, Kubernetes clusters, micro functions, the cloud provided, and basically gained, uh, uh, this whole, uh, motion of breaking the monolith of software.
And that brought a lot of different components. Those are those, those are the machines that need to communicate with each other. Each of those machines have their own digital identity.
And it got up, got us up to the fact that last year we all recognized that here one employee, you can, uh, you can find 15 machine identities, five oh. So that means 10,000 employees, half a million of machine identities. And just to conclude, this year we're talking about a ratio of one to 82 82 as a result of the AI agents rise.
So, uh, as you can see, it's very interesting. Think you might even be underestimating that number, but we'll see how it comes to be. Um, that also creates all these secrets that need to be managed.
And on the other side of that coin, most of the organizations I talked to were already struggling with that side of it. And now there are secrets, not just for all those people we talked about, but all those machines as well, including the AI agents. So how will we manage those secrets in a way that, 'cause theoretically they're gonna be constantly rotated and well, that's gonna be a headache.
So with humans, we were able to leverage, uh, NFA biometric, uh, information and things as such to replace the password. And that provided us with a passwordless trend. And that is, that is around, uh, for a while with machines.
They are leveraging those credentials, certificates, keys, and they cannot use passwordless rather than what we define as ticketless. Uh, we're helping our customers basically to reduce the number of secrets to the minimum based on just in time credentials, based on just in time certificates and, and short tokens as much as possible. Uh, that is the challenge because each and every one of those, uh, hundreds of thousands and millions of those identities require those secrets.
And they are, uh, found within the source code, within the, uh, uh, within different scripts within the DevOps platforms. Every component require connectivity to different one. And, and as, as we understand in, in a world of connectivity, everyone speaks with everyone.
And those machines require those passwords and those credentials and certificates and keys in order to operate. And that's exactly what we are here to do. A lot of people are already kinda struggling with the whole concept of, uh, rotating out certificates faster.
I mean, people are complaining about moving from 60 to 45 days. You're talking about just in time. What is it gonna take to get people to wrap their heads around this?
Well, uh, it's a matter of education. First of all, they need to change to make the, the change and understand that the time is now. You cannot no longer wait.
I know that, uh, you know, we, we see that all around that. The majority of secrets today, majority of credential certificates and keys are pretty much constant. It's static, it's unbelievable.
Uh, like, uh, everyone knows it, but try to deny it. You know, what does it mean for everyone? Because if a hacker finds it, you know, God forbid what things can happen, and we see it happen.
So the previous way to mitigate the risk was to rotate. Now, today, everyone understand that rotation is not enough. Rotation was complicated enough for everyone to do, and, uh, unfortunately, not everyone have been able to do so.
Yet the technology moves much faster and require adaptation, a strong and fast adaptation that the IT teams, the DevOps teams, security teams IM teams, would advocate and implement just in time approach that advocates to zero standing privileges. That's basically the main goal. Think about an entire it, uh, uh, environment, uh, entire IT DevOps.
The newer environments that basically, uh, are not just builds its own on ephemeral resources like in the cloud, like resources are running for a short period of time and allocating CPUs and memory and, and, and, and disk space, et cetera, rather than also the identity and the permissions and entitlement resources. So whenever a certain machine spins up, it requires a certain account and identity in order to authenticate. When it spins off, then, uh, those identities are being released.
This is exactly what is needed. And, uh, education more than everything. And Gartner is helping, and many other IDC and Forrester, many other understand this concept, co coal, uh, understand this concept and they help to advocate and to, uh, um, educate the industry.
As we kind of move down that path. What is it that creates that moment where people go, aha, we have to change this. We have to do this.
I know we're saying we need to do it now, but I feel like people are looking for some sort of catalyst or something that moves this up, their priority list. So the good news with what you're saying is that with what you're asking is that for years we've been waiting for, you know, as a, as security teams, right? I, I'll speak for the name of security teams and I am guys, we were waiting for a lot more attention when communicating the needs of security with engineering teams, okay?
And it is known that security and engineering right there, you need to find a way to connect between the two because engineering wishes to, uh, wishes to, uh, make the business more happy and to provide whatever deliverables that are being required while security are looking to, you know, basically secure. And that sometimes create a friction, right? So the good news in that is that the move, the, the shift to DevOps and the shift to containers, Kubernetes, OpenShift and so on, the, the, the way that those are being architectured is by, um, a fal use of a femoral slash temporary resources, okay?
So that you would find this aha moment actually within engineering and platform teams that understand that they need to allocate resources for temporary usage. So for them, actually, the, the, uh, the quality of, or the benefit of creating credentials and identities on the fly actually makes a lot of sense. It contributes to the hygiene of the environment, because otherwise it's not even possible to have static credentials for hundreds of thousands and millions of stacks AI agents and workloads.
So there is no other way, rather than just cooperate, get the security and engineering and to point out to the, uh, to the, uh, uh, benefits of having the, the environment to be much more with a higher hygiene. He remind me of the fact that we've spent an inordinate amount of time trying to defend against this piece of malware and protect this network perimeter, but increasingly, it just feels like cyber criminals today, they're just logging in. They're not really going to a lot of trouble to go right malware and do all this complex stuff when they already have the credentials at hand.
So, um, is this kind of where the fight needs to be won and lost? Um, not sure. Yeah, it needs to be won more than, more than lost, for sure.
Mm-hmm. Uh, and you're totally right. That breaches, um, as it, as it says today within the, uh, accept literature and reports that we see in the industry, 82% of organizations, they testify that they have experienced an identity related breach.
It means that something around the identity have been compromised in most times. Those are credentials, certificates and keys that either have been found or nont rotate that have been able to be somehow hacked. Uh, but this is exactly where we find the silent killer.
I may call, call it the silent killer, uh, where we see that again and again in, in different breaches. And yet, uh, identity and access management and the just in time approach and zero standing privileges have yet to be mainstream. We're just starting to educate the market in general.
I feel like the process may be a little bit broken because the developers are usually involved in, uh, assigning authentication and identity within their software. Sometimes you hear about them leaving secrets exposed in their software, and the security people are theoretically responsible for ensuring that, you know, the credentials aren't stolen. Is there another way to think about this that should bring these two motions together a little more cohesively than we've seen in the past?
Sure. The whole shift left movement, which is having the engineering to be much, uh, uh, you know, much more in charge of security, we now see today security folks that are within the engineering, like platform security engineering. You see all kind of positions that have shift out of the traditional CISO organization to a platform organization.
Uh, and on the other side, you see more of product security under the CISO that are responsible on the engineering side. So you see more technical folks on the security side and on the other, on the way around you see more security guys in the engineering. And those are part of the ways to basically make it, make it closer to invest further in DevSecOps in security engineering, uh, with further having those groups to communicate with each other.
But when you ask that, I believe that there is one territory that have not been doing that very well, and I'm speaking as an IAM person as an identity and access management identity and access management, traditionally, were not necessarily related as they should have to, to, uh, engineering. And that's, this is exactly where we need to do as an industry to evolve as the next step to, uh, connect between also the IAM and engineering, and not just with in, in the impact of cloud security, DevOps, security, and so on. To your point, we hear people throwing around the phrase all the time, secure by design, but a lot of folks nod their head, but I'm not sure we all know exactly what that means.
It's a moving target. You know, the world moves so fast and you say security by design, and you can say that in many different aspects, but the actual component list of what does it include, this is a moving target, so I can definitely understand why people continue to, uh, to use that kind of of phrase. But definitely things are changing.
AI agents that we, we did not discuss AI agents even a year ago, right? And look how suddenly everyone are talking about it, everyone are using those different tools for ai because it is overwhelming. But what does it mean in terms of the enterprise environment?
How are we going to secure the connectivity of those AI agents into the environment? Uh, let's, let's imagine the next thing that is going to happen. Large vendors are about to offer AI components, AI agents that require an ANA that are about to perform analysis to the enterprise environment within database that have been considered to be very sensitive.
How do you have, how do you now make the power of compute of AI agents to scan very sensitive information and to enable that kind of connectivity? Okay? And it requires not just, and I'm not talking about just the network, obviously identity and access management, encryption, decryption, uh, this is about to be the next challenge of, of the industry in terms of security And the risk levels associated with that are a lot higher.
And I'm not sure everybody appreciates that. But if I have an AI agent that can autonomously manage a process and then go talk to a bunch of other AI agents, I mean, we could see entire workflows hijacked by cyber criminals, right? Yes.
And imagine that this AI agent, uh, was compromised, right? And the authentication has not been properly provided or not properly, uh, engineered. This is a major risk in terms of AI agents and how do they cooperate with each other?
You know, just think of a financial, uh, analyst, right? That used to have, uh, to, to run a query that took that particular analyst because we're human. It took, you know, that person a whole day to scan it, to get to a certain, uh, analysis.
Today, you do that with a single prompt of going to the reporting of the company to some, uh, sensitive databases and to, to so many different data sources that are not public, right? So even the amount of access to different resources is now about to be exponentially regrown. What is that going to do to the size of the logs and the audits and the recording?
How do we, how do we monitor this kind of behavior? That's a major challenge. Uh, and obviously within identity and access management, uh, the use of just in time and, and what we just, you know, I just provided more information about the zero standing privileges.
This is just to facilitate, uh, the connectivity of this, this exact orchestra of AI agents. So among the folks who you've engaged as customers, what are they doing differently than others are? I mean, how did they get to this aha moment?
Again, as, as, as I've mentioned, uh, the I identity access management today looks at machine identity as a rising topic, given that they're just seeing the number of service accounts and API keys and the number of breaches out there, and the level of them being so exposed. So for, for human not to be the center is, is already known. Okay?
You can see that all around the industry with vendors that secure identity, the big ones, and the one, you know, uh, uh, that cares about innovation, speaks about machine identities and non-human identities. So again, education is, is there, uh, in terms of meeting the actual, you know, potential customers that we meet and, and professionals that I meet, I'm happy to say that at least they are aware that something is coming. What I'm yet seeing is for them to understand the urgency of that part, because in many cases, they're not familiar with the engineering environments and the great revolution that have happened within engineering in the last 10 years.
And again, the next revolution is gonna take much less than 10 years, right? Uh, going back to 2015 containerization, that was the number one conversation. Kubernetes in the rise, et cetera, um, function as a service that was the rise of, of cloud and, and all across.
And whether we're gonna stay on-prem or cloud, that was the question. But today, 10 years after, there's no question about cloud, but there's a question of how are we going to deal with the next revolution of, of ai, and that's gonna bring aha moments whether they will wait for that or not. And folks, you heard in here, history is littered with examples of countries that were, were prepared to win the last war with predictable results.
And we're pr pretty much in the same position now in cybersecurity. It's a whole new battle and a whole new world. Un Unfortunately, very difficult as a group to forecast for the next challenge.
But I, you know, what, what we can do as, as vendors in this industry is at least to shout out and to make sure that people, as much as possible understand what's about to come. This is why, you know, that's, that's a reason of us, uh, to make a living and to, for the business to exist. All right.
Hey, I'm Dan, thanks for being on the show. Thank you so much for having me, Mike. All right.
And back to you guys in the studio.