Challenges of Preventing Identity Fraud with HYPR’s Bojan Simic
HYPR CEO Bojan Simic dives into the issues that make preventing identity fraud so challenging to prevent when continuing to rely on passwords for authentication.
Transcript
This is Textron tv. Hello. We're here in the Techron TV studios and we're talking to Boy and Sim, who's CEO for Hyper, about a new report that they have put together about identity fraud and how prevalent it is and maybe what we should do about it.
Hey boy, and welcome to show. Thanks for having me here. Mike, Give us some of the high points of this report.
I mean, I think everybody knows that there's a lot of fraud involving identity. I'm not sure we know the extent to which it occurs. Yeah, it's fascinating to be in this industry right now because when we, when we in, when we interviewed many different organizations and surveyed individuals at large enterprise companies, many of them seem to have a false sense of security.
So they think that their security controls that organizations, organizations have implemented are secure, but most of them have had identity related and fraud related breaches in the last 12 months. So something doesn't really add up, and I think it's one of those situations where the hackers are just moving much faster than the defenders and the industry isn't being able to catch up fast enough. It seems like, to me, the bad guys are getting very good at this.
I mean, they seem to be able to assume entire people's identities, their lifestyles, everything. They know everything about it. Maybe we share too much on social media, but, um, what's to be done about this?
I think with, with regards to identity, the core component that we need to get to is find more deterministic ways of verifying individuals. Right now, there's a lot of guesswork. There's a lot of human involvement in terms of authenticating users, verifying their identities, onboarding them as individuals, and there's not enough technical checks in place throughout that entire employee lifecycle to make sure that it's the same person on a day-to-day basis.
How do I do that in a way that everybody won't complain about the process? Because, uh, one of the reasons we're still using usernames and passwords is 'cause people can, you know, within a certain parameters master that, of course, they probably use their same password everywhere. But, um, how do we do this in a way where people won't resist or rebel?
I think, you know, change is one of those things that nobody likes, even when it's a positive change. And so the number one things businesses can do is make sure it's a positive user experience. You can't add more friction to the, to the employee's day if you want to improve security.
Uh, we've seen that time and time again. So one of the things that's happening in the industry is the Fido Alliance itself, uh, and other standards bodies have put together best practices and guides around adopting pastoralist technologies, adopting better identity verification programs, and really focusing on the user experience benefit and the return on investment that that provides to organizations, not just from a security perspective, but also a productivity perspective. Uh, and once organizations get around to that understanding, they very quickly, uh, latch on and choose to prioritize those identity programs that they can get a double win on, right?
They can improve the user experience and they can get higher security, and it just takes a little bit of time, but once they get there, they never look back. How far away are we from this passwordless future that the Fido folks have been talking about for a while? I don't think anybody wants to remember their passwords and write them down anyway.
And basically all they wind up doing is making a nuisance in themselves calling a help desk somewhere, and nobody likes that experience on either end. So where are we on this journey? The organizations that are really prioritizing pastoralists currently are the ones that had the most to lose.
So we mostly see it in highly regulated industries, financial services, insurance payments, critical infrastructure, but it's also now moving to e-commerce and social media with the big name brands. Actually, just this morning Twitter announced that they implemented PAs keys on their mobile app, uh, which is massive for the industry, especially recently, they've had several issues around, uh, credential stuffing of phishing attacks against Twitter, Twitter users. So it's nice to see them, for example, taking this uh, path.
But I think it's a long tail set of events. I think the, the laggards in the industry, uh, you know, very conservative organizations will only do it when the regulators require them to, but most organizations who, you know, want a competitive edge and a productivity boost, we'll prioritize eliminating passwords sooner than later. One of the buzzwords of the day is zero trust.
Mm-Hmm. Um, what does that mean? And is this something I'm only applying to say my internal employees or to everybody?
Or is there a spectrum of different levels of trust that I apply or, you know how zero is zero trust? I think zero trust is, is a strategy that most security executives have in place for this year, next year, and over the next several years. And Zero Trust is not a one-time thing that a business does.
It is a mindset. It is a long-term program and, uh, that they will have to keep investing in and it will evolve as the years go by. Now, identity is one of the core pillars of identity trust.
Uh, when you look at all the current implementations out there, and more and more organizations are starting to realize that it's probably the most important pillar because it is the perimeter of the organization. And most of the time when there's a major cybersecurity breach, it's because a, an identity was compromised. And it's not that like, it's not like the identity was compromised using some malicious zero dig nation state backed attack.
It was somebody picking up the phone, calling up the help desk and tricking the help desk person into giving them access to the enterprise environment. Mm-Hmm. I don't think everybody knows who hyper is, but what's your investment in this space?
What, what part of that equation do you solve? So hyper has been in this identity assurance space for nine years now, and so we started this company in 2014 initially to eliminate the password. And so we were one of the first commercial implementations of the Fido standards, and we brought that to many of the large Fortune 500 companies in the world today.
And so we have the privilege of being on the ground, uh, level working with these companies to eliminate passwords at scale. And in recent years, we've introduced new capabilities to provide much more of a broader set of capabilities around identity assurance, including identity verification, continuously monitoring, uh, users for identity based risks, and then most importantly, being able to stop those attacks as they are happening, uh, and require users to make sure that they are who they say they are at all times of the lifecycle, not just when they first join a company, not just as they're authenticating at a day-to-day basis, but continuously throughout their entire journey at a company. And for those that are not well versed in all things password and Passwordless, what is the Fido Alliance and who's involved in that and and what are they trying to accomplish?
The Fight Alliance is a, a group of about 250 companies currently. Uh, many of them the name, the, the name brands that we are all familiar with, like Apple, Google, Microsoft, Wells Fargo, bank of America, so on and so forth. Um, and it we're, we're on a mission there essentially to get rid of shared secrets, and the password is the primary shared secret that gets stolen all the time today, but anything that's a credential that is stored in one place, but also stored in another place and then communicated between those two is seen as insecure because it can be intercepted, stolen or, or guest.
Uh, and the Fight Alliance has created a standard, uh, that all those organizations have rallied around to finally get rid of the shared secret. And it's been a tremendous success. Uh, you know, the participation of the big platform providers like Google, apple, and Microsoft is critical because they're implementing these controls at the operating system level, uh, so that then the broader ecosystem can take advantage of it.
How much have we lost control of these secrets? I mean, I know developers occasionally leave them inside applications where they forgot to encrypt them so they're in plain text, but I think that's only one example. There's the dark web, how, where are all our secrets?
So I think they're everywhere all at once. Uh, and, and so for what, what we can do as an industry is just stop using them, right? It, it doesn't matter if my password was leaked a year ago, if I no longer have a password to access my bank account, it really doesn't matter.
It's not usable to that organization. Now, to your earlier point of like, who's gonna do this first? Um, I think a lot of non-mission critical type of applications out there will probably continue to use passwords because, you know, if, if it's an app where it's tracking the recipes I make for dinner at home, like I don't really care if that's breached necessarily.
But if it's my bank account, I don't want to be using a password there. I beg the difference. My mother-in-Law would care deeply that somebody stole her recipe, but continue.
But yeah, I, I agree. Yeah, I agree. I Agree.
Alright. Um, what is your sense of, uh, we talk about AI all the time these days. Can we apply AI to identity and maybe safe as from ourselves somehow?
Does this have a role here? I think AI can simplify the role of many of the identity related job functions out there. So, so much of an identity, uh, analyst at a company, for example, so much of their role is just chasing false positives that certain tools bring, uh, bring up.
And I think AI can be much more efficient at doing things like that. Um, however, AI can also be used by the hackers and, and so, and they only have to be right once, whereas the defenders have to be right all the time. Hmm.
What is your sense of what is the financial loss that we're seeing because the hackers are impersonating identities, essentially? I mean, that idea goes back to, I don't know, since the telegram people have been impersonating people, but um, is it, what what level of scale is this criminal activity today? Yeah, it's, it's massive.
I mean, you know, I think there was a recent report that said, uh, cyber crime was like a trillion dollar industry, uh, which is crazy to think about that, that scale. Um, when it comes to, uh, the financial loss in particular, we see that, for example, the, the MGM breach last year that was costing them $10 million a day and that just was up, you know, from not being in business. Uh, that doesn't take into account all the, um, reputational damage and everything else associated with it and the stock price that was affected.
I think also financially we see that the average cybersecurity attack, uh, from an identity perspective is in the four to $5 million range, very conservatively speaking, uh, that we can attribute. And many organizations have multiple every single year. So the cost is pretty significant, even if it's happening just once or twice.
What do you see organizations doing that just, you've been doing this for a while, but you know, that just makes you shake your head and go, folks, we're better than this. The, the thing that makes me shake my head the most is when I see companies still using things like SMS for two FA mm-Hmm. Um, or using legacy mechanisms such as that.
Uh, and, and it's just obvious that there are now automated tools that hackers can leverage to bypass these controls, and a 12-year-old can do it, right? So spending millions of dollars and, and hundreds of hours, uh, of resources from the, an enterprise perspective to put in a control such as that is just really depressing at times when there's much better alternatives available. I think if you read between the lines of what the Biden administration has been saying is they're holding more people accountable for how their software gets used.
Mm-Hmm. Including the passwords. Do you think we'll see more stringent regulations coming down the pike to specifically address this area because the legislators may finally figure out that, hey, we can actually do something about credentials?
Yeah. We see right now from the government, we see mostly guidance being issued, which is a prelude to we're gonna start hitting you, uh, in your checkbook. Uh, if, if you don't do this, and we see it more at the local level right now with like, for example, the New York Department of Financial Services where if you don't implement certain controls, it is a very steep penalty, multiple percentage points of your total revenue.
Uh, so if organizations fail to have some of these controls in place, it's the, the monetary, um, uh, impact is significant and I think we will start seeing more of that at the federal level, but probably not for several years. Some of the things that the SEC is doing, for example, is pretty interesting, where they're actually prosecuting chief security officers, uh, because they haven't implemented the proper security control. I'm not sure if that's the right strategy at this point.
Uh, frankly, I think these people are doing their best given, uh, given the resources available to them. But everybody agrees that something needs to be done to improve the overall posture of, uh, our, our country because the nation state attacks continue to persist, um, on a daily basis. Well, and who should be held accountable for this?
And I will ask this question in this context. If my house burns down, I don't, you know, go blame the fire chief, right? So why are we blaming the poor security people?
So ultimately, somebody did something silly in my house and the house burned down and, um, or as many of my friends that I grew up with who work in the fire department said, always remember Mike, when your house is burning down, we're not coming to save your house, we're coming to save your neighbors. So who ultimately is responsible? I think with a lot of these companies, the chief executive and, and, and the board are ultimately the mo the responsible parties, right?
It is their responsibility not only to grow and maintain a business, but it's also their responsibility to make sure that their customers are protected. So we have customer protections with, with regards to the financial industry today. You know, if my bank was to get, um, if somebody breaks into a bank fault and the money gets taken, there's protections for the, uh, consumers for that.
There is, that does not exist today for cyber crime, where the impact can be just as significant. Other people would say, if we blame people, then we're blaming the victim and these folks, you know, would say the other per person committed the crime, go arrest them. So what is that fine balance between, you know, going after the bad guys and kind of blaming the good guys?
I think we have to ultimately focus on the end customer and how we are protecting them. And so it's not about necessarily protecting the bottom line of the business at all times. It's about how are we protecting the, the customers.
Like I have a 2-year-old and he's, he's growing up in a fully like digital world and I'm concerned, you know, when he is an adult, like what are going to be, uh, what are, what's the attack landscape going to look like and how is he going to be protected in a world that is far more digital than even the one I grew up in? Alright. So ultimately, what is your best advice to business execs, not just to cybersecurity folks, but the people that the cybersecurity folks work for?
What's your advice to them? And for that matter, how should the cybersecurity people talk to those people? I think we have to put everything into the, into a business context when we talk to business owners as security practitioners, and we have to show how it is a partnership with the business and not just us doing security for security's sake to make their lives harder.
And I think we have to tie it back to core principles and just keystone habits that we want to exhibit to protect our customer base and to protect our employees. I think everybody, that's something that everybody can align on. Um, and at the same time, we have to be realistic around like, hey, there's an infinite set of permutations of attacks out there.
Like, what are we truly going to spend our time in terms of what controls we implement to get the most value? And how are we going to track it? Uh, organizations these days have a really difficult time quantifying risk, right?
And the data speaks for itself. If you continue to use insecure identity practices like SMS and, and other insecure forms of MFA, if you continue to, you know, let people pretend like there are other people just because they know the date of birth of an employee like that does not work. So how do you implement controls that have a significant business benefit and also have a quantifiable way of actually bringing value to the organization, both from a money perspective as well as a risk reduction perspective?
Right? Hey folks, you heard it here, but I think we've been using the password since the first caveman grunted who goes there and many, many centuries later. I think we need a different approach.
Hey, thanks for coming by. Thank you, Mike. All right, back to you guys.