The Next Security Battleground: Agentic Identity
In this interview, Shahar Tal, CEO and Co-Founder of Cyata, discusses how the company is building the control plane for agentic identity. With deep roots in Israel’s Unit 8200 and Check Point, Cyata is tackling one of the next big security challenges: governing, securing, and managing identities in an agent-driven AI world.
Transcript
Hey, everyone. Welcome back here to Tech Junk tv. I'm really happy to introduce you to our next guest.
He's the CEO and co-founder of a company called sata. Um, we're gonna find out about what that name means and where it came from. But first, let's find out more about him.
Say hello to Shahar. Taal. Shahar, welcome to Tech Drunk tv.
It's great to have you on here. Thank You. It's great to be here.
So, Shahar, I always like, you know, our audience are tech people like me and you. Yeah. And, um, yeah, they always wanna know who's this talking to them, should we believe 'em?
What does he have to say? Give people a sense, kind of, of your background, Shahar, if you don't mind. Sure.
Um, so Shahar, uh, quick 20 years, uh, in the cybersecurity fronts. So starting out in the Air Force, then you need 8,200. I've, uh, done the rounds.
That was the first decade. Um, then I joined Checkpoint. I led the malware and vulnerability research over there.
So I used to be the guy speaking at Black Hat Defcon, R-S-A-C-C-C, or pretty much every other conference. And I used to go and speak at CISO conferences, like speaking about yesterday's big breach and the vulnerabilities, explaining all that. So that was really my thing kind of 10 years ago.
Um, and then I got the opportunity to join Cellebrite. Uh, so doing digital forensics for the next eight years or so, uh, joining to lead the company's research. And then six years in, I crossed over to the dark side and joined the corporate business development team.
It happens, it happens, It happens to the best of us. Um, yes, I was, uh, maybe, you know, preparing me for my next role, which is the CEO and co-founder, uh, of, uh, sata. So first of all, it's a great journey, right?
And I, you know, I, I just, I think it was today, the annual report from YL Ventures came out, 40%, 40% of all, uh, VC money invested in cyber, went to Israeli cyber companies. I would venture, no, you know, I'd venture to say no, no pun intended, that 80% of those companies have co-founders with a somewhat similar path to yours, right? They come out of the IDF, whether it's 8,200 or what have you, they go to work for a big security company, a checkpoint, maybe a Google or a Microsoft or someone.
They then go to a startup and get the bug right? They catch that virus, no pun intended. And, and they start thinking, well, you know what?
I, I could, I would like to start my own company. I I see a problem that I think needs a good solution. And lo and behold, they got a few friends, maybe people they were in IDF with maybe people they worked with and, and such as The, the, the, the community, the founder community is really, uh, astounding.
And I think, I think like I've been experiencing it just for the, the last few years, but it's the way that people put themselves kind of out there and very leaning into kind of being helpful. Uh, yes. I think that has been really something that stood out for me, you know, going in quite later than most founders, you know, kind, you know, you have, you have those, those people who come out of the army and then, right.
You know, Company 23, 24. Um, and, and, and, and some, you know, maybe like myself, uh, you know, a a bit gray haired, uh, uh, not, not At least you have hair. It's okay.
Yeah. Um, but, and then, you know, it's, it's a bit of a different context. So we've been, we've done, you know, a few done, done the rounds, understand how, you know, commercial cybersecurity gets done, and then you have something to say about that, right?
So that's, that's a part of our journey as well. Uh, and, and, and, you know, I was blessed and, you know, for so fortunate to have a, a great team of co-founders, you know, Alta alumni, um, the other are the, you know, 8,200 graduates who have been also very deep and security research realms, vulnerability research, very deep understanding of what makes technology kind of work, observing these transformational shifts, one generation at a time, right? We've seen cloud, we've seen mobile, and now we're, we're seeing Gentech, um, which is, which is really making us rethink what is this kind of, you know, software concept?
What is happening in the world? What is knowledge work going to look like? Uh, so for us, that was really kind of a, a moment where we took, you know, we took pause and said, listen, something is, something is about to change big time, and people don't really understand it yet.
Agreed. Agreed. So, I mean, you touched on it a little bit, but let's dig a little deeper.
No one wakes up and says, I'm starting a company today. There's a lot, especially, you know, with co-founders, and there, there's a lot that goes into it, right? Financially, uh, just resource and everything.
I mean, you, you put your guts into it, right? And what, you can't do that unless you're passionate, because you can't fake it. You can't fake it, right?
And, and You need this, and you need an internal belief, right? So that internal passion for, uh, uh, you know, for making something happen. And, and I think that that really, when, when we were kind of in this journey early on, we had these conversations about why we wanna do, you know, wanna do something like this and andro, you know, great jobs and, you know, give up, you know, other Yeah, no, Absolutely.
Really interesting alternatives to make this happen. But I was, you know, me personally sitting across the table from like two people that I admire with technical talent, like, hold on, this is, you know, we are the team that you get in the newspaper, you know, that and, and all the stories there. Yes, I, I know we are, we're that material.
So that gave me kind of the confidence, said, listen, we have to do this right now. This is the opportunity. Um, and, you know, all of us leaned in very hard and, uh, we started, uh, sata.
So let, let's, first of all, what's the website for sata? Let's get that outta the way so we don't Yeah, Sure. Forget that's, that's SATA ai.
Um, it's SATA is C-Y-A-T-A. Uh, we have been, uh, there are quite a few stories recently because we released a lot of interesting research, um, about kind of vulnerabilities and agent frameworks. Uh, we really picked them apart.
And when you start looking at them over and over, you realize those patterns of where things kind of fall, you know, fall apart, and where, where subtle vulnerabilities are. Again, coming from the res from the research background, that kind of our team comes from, um, uh, we released a lot of research. So we had, uh, you know, a few stories about us.
Uh, there's gonna be, uh, quite, quite some, uh, some more stories coming up. Um, but yes, sata, ai. Excellent.
And just while we're here, we might as well mention it. Talk to us about where the name comes from. Well, uh, uh, the, the, there's a few stories, the origin story for sata, uh, but, uh, I guess in Hebrew or ame, uh, you would say, uh, Beata ish may, right?
With help from above, uh, or with help from the skies. Uh, and, and, and that resonated, uh, for us. And, you know, we started out with, uh, you know, with, with, which is BSD, and then we say, well, in Hebrew, that's bas, which is the, the common acronym for SI May.
And then we just went with it. Very cool. I always like the, I've been through exercises like this myself, so I I know what you mean.
Uh, it's better doing that sometimes than going to spend $150,000 with a hotshot agency another time. I'll tell you how we came to be known as Techstrong. Okay.
$140,000 later was my idea to begin with. But anyway, um, okay, Fair Enough. Let's move into what sayad does though.
What, what, Yeah. Okay. If I had say, all right, Shar, tell us, what's the problem you solve?
How are you making the world better? We, we help organizations discover, explain, and control their new AI workforce. Okay?
So we are seeing, uh, ai, uh, transition from being the kind of a, a, a nice chat bot or assistant to being a full on digital employee, right? They are in your, your new workforce. This is where your employees now have their own kind of helper employees that do tasks for them, sometimes on behalf of their identities, sometimes on behalf of certain functions.
But things are happening today, or we are letting things happen today that we would've never let happen with any other of our employees out there. We've built decades of security or identity security controls around human employees, around how we onboard them, around how we grant permissions, how we audit their access, et cetera. But we are absolutely at a loss of these controls, the exact controls that allow us to govern and control, you know, our human workforce are, uh, uh, you know, incapable of doing that with a dynamically reasoning entity that is stochastic, that has access to arbitrary tools.
Sometimes that gets, you know, ultra connected and hyper connected to all sorts of, uh, uh, you know, databases and, and, and resources that your company has. Um, and that's exactly what we're trying to help with. Um, so the first thing, typically we help people understand all of the agents that are already working for them.
Uh, one of the key problems here is shadow agents, right? These are sprawling out of control. People are onboarding these agents, uh, as, as their own experiments, as you know, and sometimes just for lack of a better term, it was shoved down their throat, um, by kind of a vendor where, you know, they introduced a new agent for something and now there is another agent working for your company.
Um, and, and, and this is super interesting. It, it's, it belongs to, we see this in coding agents, we see this in ingen browsers, we see it on the SaaS platform like agent builder platforms. Each and every platform now has is releasing those new digital employees that run off and kind of do tasks in the background, um, which is w which it just out of control right now.
Agreed. Agreed. And, and which just at the beginning.
Yeah, no, absolutely. Listen, it's, uh, for every engagement where we come in and we do the scan, we see that, that jaw drop moment where they realize what they did, or they had a suspicion maybe, but they realize everything that's right, that's happening right now within their, their networks and on their endpoints and in their kind of SaaS environments. So, and, and that's exactly, we try to bring all of this into a singular control plane, right?
So make sure that there's one place where we can govern when we can set policy, um, set your posture guardrails, right? This is, um, uh, and the, the agentic, SPM, so to speak, right? We have the security posture management for so many of these other areas, but they miss the focus on this abstract entity that we wanna solve for, which is the AI agent.
Agreed. Very cool. Um, so here we are in January.
Yes. You know, we, uh, in many ways, all of us were touting 2025 is the year for agent AI really going mainstream. But as we look back, you know, to last year, I think the consensus is a lot of these agents didn't work as well as we thought they would, right?
A lot of these agents sucked, quite frankly, right? But they'll get better in 2026. But what we're also seeing is that constant jockeying, right?
With security versus new technology, right? First you security seems to dig their heels in and say, no, no, no, no, you gotta make sure it's secure. And people say, well, no, we're going without you.
That, okay, okay, we'll, we'll, we'll go do it. And they try to, you know, keep pace and, and then they try to leverage the technology to make better security. Mm-hmm.
I abs I'm gonna assume this is very much part of your journey right now. Yes. So, and, and lemme tell you, there's a couple of things that, that I wanna say.
One, I think the narrative is changing. We've seen the 20, 25 pieces with, uh, the, I'd say the kind of disappointment everyone says, you know, and the analysts were like, oh, you know, so many of these projects are going to fail. We're not seeing any production re and yet, right?
So that was, that was, you know, the, the notion, the sentiment that wa that that came about in the second half, 20, 25. But it's starting to change. And I think the reason for the change is how much, uh, better and how quickly reasoning models, uh, improved in the, in the way they're able to deliver consistent kind of, you know, longer term tasks or longer term goals translated into tool calls, into, into action.
And the, and this, uh, uh, and, and it came with, with a few models. I don't want to, you know, pick and choose kind of the vendors, but it really seems like the whole, the entire industry is moving into a place of higher productivity, more reliability, um, you know, it's gaining trust that, you know, you can let this thing run off and, and, and do, uh, kind of a longer term goal. So, you know, that's on, on, on the framing of the narrative.
Um, and, and I think that, that in terms of, um, uh, uh, uh, adoption, again, adoption comes from everywhere. We are seeing the, you know, all the early adopters and everyone's doing their own experiments, right? So they're experimenting with AI and they're trying this agent, they're trying this, they're giving permissions over here.
They're giving permissions over there from the top, you see boards and kind of CEOs mandating how fast are we gonna, you know, accelerate AI adoption. And so, and, and then everyone has like, tasks to do this. So in the middle, you get this nice, you know, risk sandwich, uh, of, of, you know, stuffing all of the ai, uh, into the organization.
I think 2026 is where we're gonna see a lot more, uh, long-term agents starting to work. Um, again, for companies, we're already seeing this with a few platforms that are now, and I mean, the trend is very clear. You see platforms releasing background agents, right?
I don't know if you've, if you've seen some of them, and background agents is exactly what we mean when we say longer term. Like, you know, long-term goal oriented, uh, uh, agent technology. Um, so this is, I, I think this is where we are going as, as an industry and knowledge work, uh, uh, altogether.
Now, there's a lot of people speaking about kinda multi-agent systems, right? And a to a and this, and this really complicates some of the, uh, uh, you know, controls that, that you want to have over, uh, uh, you know, over, uh, in, in this area. Um, I think this is a little further along.
This might be the end of 2026, or even 2027, but longer term, uh, digital employees are happening right now. I love it. ai, that's C-Y-A-T-A.
Yes. Um, I didn't ask, so ata, sp m all of this, it, it, it's, it's publicly available right now. Yes.
Yes. Absolutely. We, you know, we have, we have a product out, uh, lots of paying customers in the us, uh, primarily financial services, uh, you know, uh, uh, and financial, uh, tech heavy institutions in the United States.
This is where we're seeing a lot of adoption right now. But it's not limited. It's everywhere.
Everyone realizes that this is a gap. Uh, if you look at budgets for 2026, they have aligned for, let's say, AI security, and then they try to figure out what's the right approach, what, you know, how, you know, where, where do we wanna, uh, you know, put our chips on? Um, and, and for us, it's, it's really clear the, the right approach to tackle this problem is from the identity security prism, right?
You cannot treat this as an AppSec problem. It's, there's not code you could statically analyze and figure out whether that, um, whether that agent is going to behave nicely or not. Uh, it, it, it's just a black box that will make decisions on its own.
And so identity security is really the only viable, practical control that you can place around such a aa construct if you want, you know, uh, uh, again, to, to make sure that things are happening in a way that's controlled, that's measurable, that's audited, uh, et cetera. Excellent. Shah, we're about outta time.
First of all, best of luck with Sciat continued success. Thank you so much. Don't be a stranger.
Keep, keep us, uh, keep, you know, keep us posted on what's doing. Will you guys be at RSA this year? Yes, absolutely.
We're gonna be at, at the early stage Expo. Um, oh, Very cool. The sandbox or just the early Yeah, no, at, at, at the hall.
Just early stage in the hall there. That song, we'll have, have A session there as well. Very cool.
We, we of course, will be there broadcasting live. We put on, you know, we put on the DevSecOps thing every Monday there. Mm-hmm.
Mm-hmm. This year it's really about, uh, AI native dev Right. And securing AI native dev.
So we'll absolutely be talking that. Or maybe stop by, by, uh, broadcast alley. We'll catch up with you.
Absolutely. Uh, we'll meet up then. Thank you.
Have a great rest of your day. All right, you too. Shatal, CEO Co-Founder SATA here on Tech Drug tv.
We're gonna be back with more. Stay tuned.