Hello, Martin. How are you? Good. Thank you. Hi, Oded. Nice to be with you on this webinar. Yeah. Definitely. So as you can all see, today we're gonna discuss together with Martin Kupinger, the principal analyst and co founder of KuppingerCole, a leading analyst firm. We're going to talk about the twenty twenty six Identity Threat Outlook. Let's talk about secrets and AI agents and NHI and what's not. So without further ado, I'll just start together here with you, Oded, the CEO and co founder of Akeyless. So we're gonna start by talking about threats that are accelerating in general, and those are identity based threats or identity based breaches that have happened in the past few years. But it looks like going ahead twenty twenty six, we continue to see more and more attacks and breaches that have been enabled by either stolen credentials or expired certificates, tokens that have been found either within git repositories or the ones that have been found within configuration files. So as you can see here, different types of examples with API key, OAuth tokens, credentials at GitHub, standing privileges with all of those known brands. And obviously this is just a sample. Well, Martin, you know, before I move on and maybe, you know, going through something very relevant on your end, how do you look at this this trend? What's what's your opinion on this? Yeah. So so so basically, when we start with this trend and, you know, I don't care whether it's whatever sixty five or seventy or eighty percent of cyber attacks are identity based or identity related. It's a maturity, it's a huge ratio of all the attacks that are starting with identity theft with access to credentials with whatever the purchase of stolen secrets, whatever else, identity is always there. Challenge I think we are facing is so one challenge is attackers don't stop. A couple of years ago, we had the impression if you go to whatever SMS out of band authentication, we're on the safe side, we were not. Right now we see a lot of other types of MFA attacks. When we learned, I think this is one of the major themes, that not only attackers don't stop, but IT doesn't stand still. Because IT doesn't stand still, there are two major things that impact this entire field and that add a lot of sort of risk and a lot of new challenges to the entire field. One thing is what a lot of people call NHI for non human identity. I think we can just quickly discuss the entire webinar just about the terminology. Doesn't make much sense. At the end, it's really workload identities. It's identities of connected things. This is, I think, separate thing to a certain extent, it's also AI agents and their identities. And the problem we are facing is, it's a massive scale. So, again, is it forty x or eighty x or even more of the human identities? Doesn't matter. It's way more. And it means we have a much bigger attack surface, which is only one problem. Second problem is volatility. The secret sometimes don't live long, or there's a lifetime. They may pop up, they may disappear, they may also be around for a little longer. We lack ownership, we have issue with lifecycle management and when we can then go to AI, and I don't want to go into every detail here, we'll have a lot of conversations later on in this webinar about various facets of that. We add the challenge of autonomy, complex identity relationships, because with a workload, it's you have a workload, some software running, which is accessing certain resources somewhere. Still relatively simple. With AI you have humans or workloads interacting with agents that interact with agents, that interact with MCP servers and whatever else, way more complex. And that means we are facing more areas of risk escalation, so often abandoned in AI. I'm pretty confident that very few people listening to this webinar could say, okay, yes, I have full control about all my non human identities. Most likely not. They are reused frequently. So you have one hour, this is just that secret, oh, very convenient to use. We did this before with functional technical accounts, And we repeat the same mistake, excessive entitlements. I think when the idea of keen cloud infrastructure entitlement management appeared, where it was about understanding which access to service accounts have to cloud resources. We learned that our worst nightmares from at least a security perspective become true because it was massive over entitlement, they still exist, and we don't have a proper governance here. So what basically is happening, and as I've said, we will touch a lot of these points later on. We are in a world where complexity grows and risk grows. And if we don't get a good grip on identity threats, we will experience way more and way more severe attacks over the next years. And that's what my my twenty twenty six outlook is, it will get worse if we don't act. What if I'm choosing I think, you know, in summary, it is gonna get worse, if if not even worse than you think, unfortunately. We need to make sure that we all understand exactly those risks. So I want to name here, and Martin, excuse for stopping you there, we'll continue on that. But I want to take that approach that you're mentioning and go even more specific with how we look at things, right? And of course, we talked about the number of AI agents and the number of machines and workloads in general. Obviously makes it more complex, right? But let's go even deeper and ask ourselves, what is exactly within the complexity? What is it that we are fear of? And those are the cases where we all understand that AI agents can actually expose secrets. And this is something that we haven't seen within the usual machines or workloads, right? When we couldn't just ask a machine, tell me your secrets, because the API is pretty much fixed. While with AI agent, it's a thinking entity. Right? And actually, researchers have shown back in Black Hat this year, few months ago, this year, they've shown using a poisoned document that was added into the prompt of ChatJPT, they were able to extract back the secrets that this particular agent was actually using. Right? So the secrets, the credentials, the certificates, the API keys that are used within the AI agent boundary to access data, to access the MCP server, to access the LLM model, whatever it is within AI Orchestrator, there are a lot of secrets there that are being used, and we can leverage the prompt in order to actually retrieve those secrets. And that's a major change and a major concern when we need to solve for AI agents and to make sure that they don't have those secrets and credentials much better than we've done with workloads. The next thing that we see particularly with AI agents and more specifically is the fact that they require much greater cross domain connectivity. What does it mean? What does it mean? This means that within, if traditionally applications were created in one cloud environments, the database, the front end, the backend servers within one environment, either one cloud, one on prem or whatever, the connectivity between application was pretty much moderate, okay? Today with AI agents architecture, by nature, there's a greater need for even within the components to speak between the cloud provider that might run the AI orchestrator, the LLM model that is being run potentially within a Neo cloud environment, and now in on prem that actually has the MCP server and wraps the information, the data that sits on prem. All of those and AI agents to communicate between different zones. That means different IAM environments, and they need to communicate maybe with federated approaches. I'll pause here, but Martin, what's your view on those more specific concerns? This is clearly an area where we could spend again hours on. But but I think I had an interesting exchange just this morning with a very large player in the field of cloud services this this morning. And talking about the security of their MCP server approach. And just having a policy for an MCP server, for instance, is not sufficient anymore. Because we need to have multiple authorization layers, we need to bring things together because there's something that there's a policy of me saying to the agent what the agent is allowed to do on my behalf or not. That's something which restricts the agent. There is the MCP server. The MCP server deals with hundreds of agents. So there can be a single policy, but the policy depends on the agent and the human. And so we need to really rethink the entire way of authentication and authorization, because it's way, way more complex and networked and everything we've seen before. I always tend to say, intellectually, this is probably the most interesting challenge we've been seeing in identity management since I'm around in identity management. This is probably the last thirty five years, depending on when you say identity management started. So but interesting, intellectually challenging also means it's a big challenge we are facing. Yeah, definitely. I believe, you know, talking about federation was actually here, talking about workloads not to have any secrets. Those are the kind of conversations we've had in the past few years. But now there's something within AI agents that just pushes us make it solvable, to solve this basically, and not to keep it as is. And the industry can provide definitely tools for that. We'll talk about those tools obviously, and the solutions that Akeyless is the one to provide using an identity provider to federate between IAM and how to communicate between cloud to Neo Cloud to on prem, how to provide this. But yes, definitely exciting times, Martin, exactly as you mentioned. Also being a person that is within IAM for around twenty years now, seeing how we were very much focused on the human identity management and with time going to the privileged and with time moving to the machine identities, how to secure those APIs that speaks with each other. And what's happening right now with AI agents, there's a lot of great fusion that is happening between them. But let's summarize on that end because if we want to use a practical title and to warn I'm professionals and others that look at this webinar, and I'm being very, very specific here. You know, if there's one thing that I'd like you to, you know, that we'd like you to take with you is that rotation that has been here a lot for a lot of time saying, you know, we can surely we should rotate passwords and we should rotate certificates, etcetera. Right. And everyone knows it. Unfortunately, it was not very much well deployed because of the concerns of shutdowns within, you know, services within production and rotation was not very well implemented also within certificates. But now with the great definition of, you know, forty seven days to rotate certificates, we're actually being enforced to do so. Anyway, in twenty twenty six, when you're looking at your strategy of how to actually solve for the current concerns and threats, unfortunately, rotation is not enough anymore. Workloads and AI agents are ephemeral by nature. They require permissions to be created whenever they are being ran and to be deleted upon usage. Rotation basically still opens up a lot of identities that are waiting to be attacked when there is an identity, an account, it waits to be brute forced. Think what does it mean in twenty twenty six with a lot of compute power that actually can brute force more easily than it was in the past. So rotation basically assumes that there is a constant entity that is waiting to be used, and we cannot work with that any longer. Need to transition to zero standing privileges, to dynamic approaches, and we'll talk about that. And both it's true, right, with the increase of the volume, etcetera, because the exposure of a certain secret is going to happen much faster than it was. Again, with AI agents, much more people would have the opportunity to prompt and to try to hack those models and to get those secrets and credentials. So it's time for us to evolve and to really examine the dynamic creation of credentials and dynamic creation of tokens, etcetera. Martin, your reference? I I think that there's one thing I'd like to add, which is very important to understand. For the world we are in now, not that which is which is whatever evolving, it's here. We can't rely on proven methods from workforce, from traditional identity management. So human based processes will not work for a very dynamic, very high scale world anymore. We need automation. We need stuff that works automatically without waiting for a human. We can't afford this anymore. So we can't just transfer traditional IAM to the new problem, we will fail inevitably. Yeah, and going straight, you know, pinpoint on that, you know, when we look at transitioning from how we used to do things before twenty twenty five and how we are about to make it happen next in twenty twenty six onwards, right? So obviously taking from and focusing now on the world of workloads, okay, of machine to machine interaction, not necessarily humans, but more of machine to machine interactions and AI agents, right? With IAM and how do we need to look at things because it does revolutionize things. We had the tendency as an industry five years back, four years back to say, okay, the way to protect the identities of workloads of machine to machine interaction is using credential management approach, right? To centralize the secrets, to govern who has access to what, to run some sort of rotation, right? To go application by application with service by service and to act automatic rotation capabilities, or to just try to do it by hand, which was not very fruitful. Generally speaking, long lived credentials within the credential management approach. Some secrets management capabilities were already there to provide even more, But when you look at the Cloud Vault as an example, it's very static by definition, rotation is not even supported and so on. Moving to twenty twenty six and beyond, there's a shift and this is where Akeyless is also calling the industry to shift the thought from credentials management to try and think at the definition of machine identity provider. We used to talk about SSO for humans, now it's the time to start talking about SSO for machines, SSO for AI agents with the concept of machine identity provider. That means to start issuing tokens whenever a request is being taken, is being requested with just in time tokens that are created on the fly and being deleted with dynamic identities that are being created whenever a certain access is being requested. For instance, AI agent that requires access to a certain MCP server or to a certain data source, then those permissions can be created on the fly. It's just a request that goes to the machine identity provider and that permission is being created on the fly and later being deleted after the prompt algorithm is actually being ran. Rotation obviously must be automated and as we just learned, it's just it's not enough. And the notion of completely eliminating the static secret must be our north star. It's almost impossible to completely eliminate because there are eventually, are, you know, there are administrators and there are default accounts that we all understand, but we can definitely rotate much more for the ones and whenever we can to leverage those just in time and zero standing privileges. Martin, on your end? I just can can back back your position because this is really where where where we need to rethink. So revolutions require a sort of a bit of a radical thinking. And I I think a lot of things we currently do in in many areas, and related to this, my favorite example is always TLS certificate lifespan. So yes, we I remember there were three years a while ago, we are down to whatever forty five days, but obviously, this is just curing symptoms. So it's not the solution. The solution would be to rethink the protocols behind, to think about how can we make this really ephemeral and how can we make things just in time? So I think we really need to think beyond and really step back from some of the things that have been worked, that worked for a while, they don't work anymore. We need to reinvent a lot of the things we're doing here. Yeah, I totally agree. But now pausing a little bit and going deeper into the Akeyless identity security platform for the AI area, which we launched recently. I know pretty quickly for the overview of that everything within identity starts with a strong photography foundation. And this sits very well with our Akeyless DFC, our ability to run basically encryption and cryptography in a non trusted environment and actually fits very well with close domain environments where there is no one entity that have the permission to access the data. The DFC stands for Distributed Fragments Cryptography. Very interesting as is the ability to run cryptographic operations using fragments of encryption keys without ever combining them. So we leverage this technology to provide both data protection capabilities, but actually to encrypt as a service, to encrypt the secrets, to sign the certificates as they go, and to decrypt them while zero knowledge is being provided. So we, as a provider, we cannot access the customer's secrets, although this is a SaaS hybrid solution. So the pillar that I'd like to emphasize within our platform, within our identity security platform is the first one that we feel very comfortable with. This is something that we've proven into the industry and known for, the machine identity security solution based on our secrets management or certificate automation capabilities, full blown PKI solution that provides also Workload Identity Federation to how to connect between different environments, acting as a translator between those environments with a multi vault governance capability to look at different vaults as well. So both acting as a secret manager with automatic quotation, with dynamic identities creation, with secretless capabilities like OAuth and so on and so forth, but also multi vault governance, the ability to look at other vaults as well. The second pillar is within human identity security. Some of our customers can also practice that and implement those solutions. We're actually leveraging the good, the strong technology of Akeyless DFC and our ability to inject credentials and to provide them on demand and to create the permissions on demand. But we created the modern PAM, which is, by the way, very similar in requirements to Zero Trust Application Access, the Modern Privileged Access Management, to allow seamless interaction and the injection of credentials on the fly within the session. So it acts a mitigator, as a secure remote access, if you'd like, with the ability to provide enterprise password manager, a mobile application, and an in app plug in to browser extensions. Combining those two provided us the ability to provide to the market with a full GA product that is specifically intended to AI agents identity security, that provides what we call the first AI agent identity provider in the industry, where basically AI agents are able to ask for permission. They're getting those tokens or dynamic identities that Akitas is creating on the fly. And the whole intention is to completely eliminate the secrets within the AI agents themselves, within the MCP servers, within the AI orchestrators. And whenever you're at your calling the LLA model or the MCP or the data itself not to have the secrets within the code whatsoever so that the AI agent, whenever it generates the code in order to solve the prompts request, it will be without secrets at all. On top of that, the privileged AI agent access basically to monitor and govern the actual actions that the agent is having. During 2026, we're about to release the Akeyless Jarvis AI powered Insight Discovery and Response to basically complete this whole solution into a whole 360 degree solution for all of the needs with regards to the privileged access, the access management, as well as for the IGA part. So this is within the platform itself. So pausing here and Martin, well basically this is going even further to AI agent. I think we've had more discussion about it, the need to provide this federation between environments, right, on one hand, to eliminate the certificates and eventually to also have the session recording. What are the things that you're hearing from your customers with their concerns that are relevant for this area as of recent days? So I would say currently the cybersecurity people they have a have a an understanding that they are facing a huge problem. I think everyone understands we don't have the answer yet. So we see a lot of things coming to the market. And the challenge is that the problem I think we just touched it before is really complex in its nature. The other challenge is that most people outside of cybersecurity have even lesser understanding of the risks behind it. Think our so to speak daily news about a new MCP server related incidents, cybersecurity incident, that already shows we are a lot of people are really not understanding the risk that is behind. And so, I think the art will be to educate that we need a good security posture for AI before we start using AI at scale. That's the one thing I personally believe we need. So that sort of people outside of the cybersecurity bubble understand, they need to invest, they need to, to understand the challenges. And the other thing is we, as the cybersecurity industry, I think we need to be very careful in finding the balance between solutions that work now, certain aspects of it, without leaving the impression that this is already the holy grail for everything. So that will be a very interesting balance, I believe, to find. But I'm also very confident at the end of we will solve it, you know, I think this is something I've learned over the past decades. There were new challenges arising. And yes, there were a lot of things going wrong. So look at the first phishing attacks on online banking or so huge peak and cost for the banks and then we added the industry, cybersecurity and the banks invested and brought it quite a bit down not to zero, but addressed a lot of it. The same will happen here. We will see a peak in incidents. We are already seeing this starting, but we will get a grip on it. Yeah. Exactly. And and, you know, it's it's feasible. And as as we've mentioned, there are solutions today that can help I'm professionals and cybersecurity professionals to start and mitigate those risks, but they need to operate right now. They need to act right now. I call that the shift from, you know, some kind of a reactive identity management to proactive because right now we are at the very much beginning of the revolution that is happening. Right now it's the time to influence the developers teams, the AI programs right now. And we have started to meet AI programs across our customers and to start talking with people that are not necessarily cybersecurity professionals and to talk with them about the concerns, you would not even imagine how great news this is for IAM leaders that actually, know for IAM practitioners, when you speak with your AI programs peers and your AI architects within the organization and you ask them about the challenges that they have in terms of communication and authentication between environments, they actually are now looking for those solutions, right? I had literally two days ago, one of our European customers that told me, you know, this is great, this is and he was not a cybersecurity professional. He was like, this is wonderful because we can now take one, you know, one of this big set of problems or challenges that we now have of federating, of authenticating between different environments, and we can remove it out the table. And it's great because we have so many things now that we need to solve for when we look at the architecture of AI agents. So actually this is a call for you guys, for IAM professionals in cybersecurity, to have those conversations because apparently the current needs and requirements are actually very fresh and it's a very good opportunity to interject your philosophy and your doctrine to right now to the way that they are starting to architect that. There are not a lot of opportunities like that. We've had one like that in the cloud. I might say as an I'm professionals, I believe that we've kind of been caught not ready for the cloud era, and we're still being very reactive to that and the solutions came after. But with AI agents, because it's such a great combination of workloads and humans, we actually have the tools and there are answers, and now it's the time to act. I call this as identity a shift identity left. I call this phenomena. Martin, I I yeah. I provided that to you. Which by the way, I think is the thing is when when looking for solutions, there's a a good likeness test to start, which is is that solution demonstrating a sort of a shift left thinking. So it's very clear, if we try and attach this to apply, let's call it proven principles that work in a static world to that new dynamic world is way more connected, way more complex world, we will fail. So I think the first Lekman's test is there a shift left thinking, that doesn't mean that the solution is perfect, but it already means at least someone is taking an approach that is different, and potentially could work for this way more complex environment we are dealing with. I think one of the points also to make around what you said, think we must not be shy as the identity management people because at the end of the day, and it's the same by the way for developers when it comes to standard workload identities. Developers don't want to set up walls, They don't want to manage the walls. They don't want to deal with security. They want to have a service. The same for AI. The AI people who are building digital services who are building stuff or using AI, they don't want to care about security. We need to deliver it, but that requires a fundamental thinking, change in thinking in I'm organizations. Right now, we have a bit of this attitude in IAM to say, okay, yes, we can do this and six months or so we will deliver something to you. No, we need to move to a service thinking at the speed of business. So we need to be ready when they need it, we need to deploy the service that is easy to consume. That is the way the developers need it. So, and that works, I think a different field take things like OPA, open policy agent became very popular because it was simple to use for developers and offloaded the security burden from them. We need to do the same here. Make it simple, deliver a service and change our IAM organizations to a really true service delivery organization that has the service available when it's needed at the speed of their customers, the tenants. Yeah, I couldn't agree more. Again, I think it's a it's a great opportunity these days. And we're definitely we're definitely in a great period of time. I'm sure that Martin, both you and I would be very much open to any questions that anyone within the audience might have. And if they're interested, are welcome to approach any of us with any questions about that. I'd like to use this opportunity, by the way, to invite everyone in this conversation, just to make sure that you can all see it right now. Identity Security Unleashed for the AI era, we're now streaming the whole series that have great guests that are coming all around the industry, practitioners, leaders, chief security officers, other vendors as well. And definitely the ones that are very much relevant both for the AI era as well as for workload identity security. So definitely inviting you all. You can enter into our website and to subscribe into the series and to enjoy this great type of content. I think that with that, Martin, any last comment, any last tip or calling to our audience? You know, there there are a lot of things. I think what might be really valuable for our audiences to to to really start thinking about what are the things they need to have a look at. So what what they are potentially overlooked, and we touched many of them, we talked about the complexity of relationships. So we're not just simple workload to cloud resource or so. We're talking about humans to agents to agents to a lot of resources. Ownership, I feel is something very worth to think about. Do you really have a concept of ownership? Do you know who owns which agent? Do you have have all these concepts in place because ownership, I think is essential. So I think it's very worth to spend a bit time maybe to look at what is what they are. But organizations tend to overlook and some of these things I believe you can at least get started on without, with sometimes trust organizationally and by really bringing together the people. Yeah. Ownership is definitely the next the next question. I wouldn't I must comment on on that, by the way, that, you know, ownership with regards to AI agents and understand who's responsible for. This is for sure one of the big challenges that we're gonna see. The question is also if we plan it right and we make sure that the AI agents request temporary access and they're getting temporary tokens, right? It means that we basically starting to provide them the independence, right, of asking for permission, getting those permissions. And we're also responsible of shutting down those permissions all the time. So that at the end of the day, the audit and compliance by the end of year, right, whenever we are leveraging just in time, zero standing privileges, dynamic identities mechanisms, OAuth tokens, PIFI Inspire, all of those great goodies within identity provider way of thinking, this should simplify very much the questions around who's responsible given that the agents are very much independent by nature. But with that, yeah, any Yeah. I take a bit of I think that there's one thing which which is important. So I I I generally, I'm a big believer in in trust in time and in policy based access in things which so I think we all know that static entitlements are are so in in some some means they are the the root cause of all patent identity management. But I I think we we also must ensure that and that goes into the direction that an agent does not have permissions, per se. So the agent if the agent doesn't do anything, the agent should be permissionless. Yes. And the permission must be derived from the contextual situation in which the agent acts. So in an ideal world, the agent is not capable of doing anything unless the agent is triggered to do something, whichever the trigger is in this autonomous world. And then it must get the permissions for exactly that. And these permissions clearly are what the agent can do based on who has been calling, but also then it must transfer. And I think that's where also your your concepts of trust in time access come into play. It must also ensure that the MCP server then only grants the agent the access needed. And so I think we must really goes back to your shift left thinking, we must think differently when it comes to the world of agents. Because if we give the agents certain entitlements, say, all this could be done by the agent. What will happen with an agent? The agent will use the entitlements because that's the drop of the AI agent. So if I think this is you know, we sometimes said okay, this is these are all the entitlements and a workload required potentially requires we give it to it. If we do it with an agent, it will get out of control. Yeah, with that, I, you know, the fact around ownership and understanding and all of those concepts would definitely make us, have us busy in the next following months and years to solve and to continue and improve on that and to provide more and more solutions to make sure that we all control, but also being comfortable of losing some of that control, right? There is a good philosophical debate around it, right? How do we share that control with the agents that now would become to take some of those responsibility? Martin Kuppinger, I'd like to thank you so much for coming to our webinar and to have this wonderful conversation, a very interesting one. But thank you for joining us. Thank you guys for being with us within the last forty minutes. We are welcome to watch the recording of this webinar. It will be soon available within our website, as well as again inviting you to go through into our and subscribe into our limited series of identity security for the AI era. Thank you again, and see you next time. Bye, Kyle.