Delinea’s Art Gilliland on Increased Identity Security Spending in 2025
New research from Delinea finds 78% of organizations plan to increase identity security spending in 2025. Based on a comprehensive survey of 300 technology and security leaders, the report highlights the critical role that identity and access management (IAM) plays in managing and safeguarding the complex relationships inherent in modern digital ecosystems – which now encompass both human and non-human identities.
Transcript
This is Textron tv. Hey guys, it's Alan Shimmel here for Techron tv. I've got a gentleman I want to introduce you to.
His name is Art Gilliland. Good morning. Yes, that right.
Art Gilliland. You did it. Hey, Good morning.
Thank you very much. Excellent. Art is the CEO of a company called Deline.
We're going to find out all about Deline and about a new report they've recently released. But before we do that, let's find out a little bit about art. Art.
Give us kind of the, uh, the art story, if you will. Uh, the quick two, uh, two second version of it. Uh, so Alan, thank you for having me on the show.
I really appreciate it. Uh, so hello folks. My name is Art Gilland.
I'm the CEO of Delineate. As Alan said, I've been in the security industry now for about 26 years or so. I, I like to say I tripped over it on accident at a startup back in the late nineties, uh, and then have been a part of the ride.
Uh, Did most of us. Yes, exactly. We a we accidentally Same thing here.
I've been in it since then and no one Oh, for security, then that unheard of. It Was, but it was not so cool then. But now think, of course, people are making movies about it and it's in the news all the time.
So it's been a, it's been quite a ride for sure through, for me, through small companies, startups, as well as, uh, very large companies running, uh, the businesses at Symantec and hp. And then, uh, a time as a CEO of a startup that got acquired by Cisco and now, uh, here at Deno. I love it.
com. And again, by Access Slam or Worm and all that excitement. Well, we were, we were operating data centers, and the next thing you know, we, we had to do manage firewalls and, and people started caring about what was kept in those data centers.
And that's right. Then my next company that I, I also did a lot of startups, was, was a full on InfoSec company, as we called it. Um, how long are you with De Linear Art?
I've been here now, uh, almost four years. It'll be four years in March. Uh, so I was part of TPG who owns us, uh, when we brought these companies together to, to create delineate in the identity security space.
Ah, TPG. We deal with them also on, uh, oh, do ai, a DevOps company also kinda a little bit of a roll up with it. That's right.
Um, give, give, if you wouldn't mind. You know, let's talk about delineate. So it sounds like it, it's the, the product of a, a roll up of a couple of companies put together.
Give us kind of the genesis there, if you'd Yeah, Yeah. So I mean, I think, uh, I'll, I'll give you a, a quick history if that's all right. A little, uh, it's a little bit of a stroke, but I'll I'll do that.
And so I think one of the, it de Linea was really formed at the, uh, at, at a conversation we were having around sort of what areas of security was I most interested in. Um, and I think the, the two areas in security that I think are the most going to be the most impactful and the most interesting right now are identity, security and data security. And the reason I think that is because if you look at what's happening for most companies today, they're in some part of the process of moving a lot of their infrastructure into cloud or SaaS computing.
Um, you know, back, you know, when we started, it was all walled gardens and you had firewalls and stopped everything, uh, kind of at the edge. But if you look at it today, most companies are basically renting infrastructure from someone else, whether that's the application you use for SaaS or the, the infrastructure from like a hoster or something. And the reality is, is you don't control the policy in those.
They, they attest to you what they're doing, and you, and you try to set, uh, sort of boundaries for what they do. But the reality is the only place that you really are gonna be controlling the policy is on your users and what your users are allowed to do. Uh, and then hopefully at some point on the actual information itself, no matter where that information is living.
And so when I look out over the, you know, the horizon of where do I think the most interesting innovation and challenges, where are they gonna, where is it gonna occur? Um, that's kind of how this came about. And so, uh, we started looking at the identity security space and saying where, uh, where are there opportunities?
And, uh, the opportunity was really to build a platform for authorization. Um, and so that means like being able to set the rules, centralize and set the rules on what are users allowed to do in any environment, whether it's your own environment, whether it's your laptop, whether it's in the DevOps space, whether it's in cloud. Um, and so Delania is building that platform for intelligent authorization, essentially to define what privileges, what entitlements are available to the users after they, uh, after they log in.
So there's, there's authorization saying, okay, you, you can go here, but you can't go there. But then, you know, a another piece of of this of course, though, is identification, right? Before I could let you hear there, I gotta make sure you really aren't, Yeah.
So I break identity into sort of three basic spaces, just, I mean, look simple. Mm-hmm. But it helps me 'cause I, I, I think simply about stuff.
Um, so step one is authentication. That is I am art and prove it. Right?
And so in that world, you have obviously the Microsofts and the Pings and the Okta's and those folks, Okta and Yeah. And so my my view of that is that go, that world is gonna continue to commoditize, right? You're gonna look at Microsoft and Google kind of owning the I Am art and I can prove it.
There may be open source. If you look at what happens right now in consumer, it's kind of a bring your own. I can authenticate to websites using my Google ID or my Facebook, and people still are using that.
Yeah. That throws zero off or whatever. Yep.
Yeah. And so this, this ability to authenticate. And so that's step one.
Step two is then deciding after I've proven I'm art, what should art be allowed to do in my environment? And that's the area where we are focused. Um, and then the next part is governance.
So tell me everything Art has access to give me a workflow for making sure that I refresh those things. And so if you look at companies like SailPoint and Savvy, and, and yeah, to a certain extent, uh, Deline as well now too. 'cause uh, because of an acquisition, we made those, that whole workflow of defining and, and reporting on and governing sort of the privileges that people have, that's step three.
And so if you look at those sort of three steps, we are very focused on the area that I think is most interesting, which is tell me what ARC should be allowed to do. Yep. Yep.
And, and, and, uh, and you're right that that is how the identity space is sort of broken down. You know, I've always felt that identity was kind of the, the killer app for cloud security, right? Because when we moved away from the, you know, moat and castle model to a cloud model, having big boxes on a perimeter that doesn't exist anymore was trying to, We've been talking about that for, uh, for like a couple decades, Alan, with the Jericho Forum and the sort of perimeter, Yo, you Still do pretty good.
So ERs, But exactly now micro ones. But PA, companies like Palo Alto and others have been continuing to just, uh, to accelerate. And I think, you know, there view is, there are some, there are digital boundaries, and I think that's still gonna be a really important part of the security landscape.
But I do think identity is gonna become more and more critical in partnership with these kinds of technologies to really secure the environment. Look, You know, those technologies are, are their traffic cops? Yeah, that's right.
Right. They, they could lower the gate, raise the gate, yep. What information they use on when to lower the gate or how to lower the gate, the kind of stuff that Right.
And that, that's the kind of stuff I imagine they could get from a delineate. But that's a great way of looking at it. Yeah.
Um, and it, it more true than ever. Uh, you know, for me, of course the big thing in identity and then authorization is non-human identity and authorization. The explosion in that is humongous.
It's uh, it's really, and then AI obviously just adds another layer of that kind of connectivity. Well, I just had this discussion with another vendor. What about agents, right?
Everybody's talking about this is gonna be the year of Ag Agent ai. Yep. You and I are gonna have dozens of agents doing our bidding, and we'll have an agent orchestrator hopefully that manages orders.
But quite frankly, how do I know arts agent is arts agent? And that Arts Agent one is okay for this, but Arts Agent two isn't. And you know, just a another level of complexity that I'm sure you guys are already thinking about and, and how do we go there?
Yeah. I think what, when you're looking at the, when you look at sort of the, the explosion of what I'll call service accounts, uh, and you know, these were API connecting to another API and those things talking, and you see it in DevOps, you see it in the way we build applications. You know, when outside talks to inside through an API connection, there was already a lot of investment in trying to lock those down and find them all and secure them.
And that, that, if you look at sort of the environments that we serve today, there's the human privileged users, but then there's also these connect connections and service accounts and non-human connections. I think what is happening with AI is now you're giving that, uh, that intelligent quote unquote, uh, connection. You're connecting it to a bunch of stuff because that robot, we'll just call it a robot.
'cause I think it's easier that robot is actually needing a bunch of different information from different places. Typically, those API connections have very, very broad rights and they can get access and take actions and do things. And so, uh, there's going to be a lot of focus on how do you manage those robots?
How do you let, how do you make sure that those connections should happen, number one, and, and verify it. And then how do you control what they're allowed to do once they make that connection? So certain eight robots will connect to the same API, but they may only need to use a small little piece of it.
And I think that's mm-hmm. Me, that's the, that's the place where customers are really gonna focus on privilege management solutions like deline, which is, yeah, you can authenticate it, you can make sure that password is safe, but then how are you managing that rotation of the password? How do you make sure those connections are, uh, sort of rebooted that the passwords are not hardcoded in the robot's mind, that it actually is a token that gets changed a lot so that if the robot gets compromised, you can turn it off, uh, and you can stop its actions.
And then also how do you limit, just give it enough, just enough or just in time access. Um, and I think that's gonna be that the pace of that and the speed of that is going to require systems, centralized management systems like ours to be able to help companies take advantage of it. Um, and personally, I'm excited about it.
Zero trust. Zero trust, just right, isn't enough. There's, there's gonna be Exactly Layers and layers, But I'm excited about it 'cause it, for the first time I'm seeing sort of a pathway to having a security product be a business enabler with an ROI behind it versus just insurance.
I mean, I think our, your, your life and my life, we've been sort of glorified insurance salesman. And I think now you can have a conversation that basically says we have ROI calculators. Exactly.
I'm sure you did too, right? Yeah. You can tell a company, I'm gonna help you go faster.
I'm gonna help you adopt this cool stuff. 'cause I'm gonna help you manage it a little better. Kind like the brakes on a car, you can drive faster breaks.
I think we can do that And you're gonna need it because it's just, as you said, the, it's not just people. When you start adding these agents and API and a APIs API traffic already accounts for majority of the traffic out there. Right.
It's crazy. Anyway, art, I wanted to move along. You guys recently released a report on, uh, identity and, and one of the topics was, you know, what do budgets look like?
Yeah. Yeah. I think, look, if you look at the, the overall sort of output of that, uh, report, there's not a lot of surprises, at least in, except for in one area.
And I think, uh, the things that are not surprising, but, uh, but just reinforce what we see is this growth in budgets. Um, for identity in particular, uh, companies are spending sort of 20 to 30% of their entire budget on identity solutions, whether that's the authentication piece or the authorization or the governance. They're spending a massive amount of their budget, and that's only growing.
Um, and so we see a lot of, uh, data like that. I think the other thing that's, uh, not surprising but interesting, um, is just how much, uh, security risk identity has posed. And sort of part of the reason the budgets are continuing to go up is just, uh, you know, still explosions of, uh, attacks on and sort of focus on, uh, using identity as a, a way to get access.
And so, you know, huge percentages like 80, you know, in the 80 percentage range of sort of identity based attacks. Uh, and I think those, uh, areas are sort of reinforced again by this research. And you see a lot of research out there that is showing that.
And so, you know, it's, it's one of those sort of, again, like a little bit like the insurance side. You're like, great budgets are growing in security, uh, attacks are becoming, uh, more, uh, sort of more, uh, more, more relevant. Um, yeah.
But again, I think the, those things I think are, uh, are clear, they're reinforced, um, by, um, by the research for sure. Yeah. I, I, I couldn't agree more with you.
Um, if you don't mind me asking, when was the data for this report assembled? Like how, how? Yeah.
So this was, this was, this was research done over sort of the November through December, uh, and early January term. So it's, it's there, it's fresh shots. It's an interview at somewhere 350 or so, uh, different it security folks.
And so this is, you know, this is 2025 data for sure. Uh, and how we and how we go there. Um, and so obviously there's that whole, but This is, yep.
Go ahead. Mm-hmm. No, no.
I'm sorry. I'm waiting to stop you. Go art.
Yeah, no, I, I, I was gonna say, like there's, there's that interesting information that we, that we see from, from the, the data. I think the part that is the most interesting in the research and the, the place that I spent, uh, a lot of time sort of trying to interpret and think about sort of what is it actually telling us is the, the, the massive numbers of companies that are thinking about using and being attacked by ai. And so, uh, that part of the report, I think, uh, is kind of an eye-opener, right?
And so the other ones I think people will read and go, yep, yep. That seems reasonable. I think the part that is the most impactful is, is the AI one.
I I, I seems that's the story everywhere, right? The AI being most impactful. Yeah, but I mean, but, but here's the thing.
You know what, quite frankly we've been hearing when it comes to security budgets that a lot of organizations are saying, Hey, we've been on a binge for 10 years buying your shiny new trinkets, and, and our security is not demonstrably better than it was necessarily. Yep, That's right. And, and so the fact that they are still increasing their identity security spending this year says that may be true, but we know how important identity is and because of the rise of, let's call it machine identity, whether it's robots or APIs or what have or agents Yeah.
Um, people are recognizing that we're gonna need to spend dollars on that. Yeah, no, I mean, look, I think what they're, what they're seeing is that they believe, uh, you know, in the high eighties, uh, that they have, uh, seen identity based attacks. And so I think what's happened is they've done a good job of securing their endpoints.
They've done a good job of securing the perimeters. And so they have a lot of technology that's in place that actually is doing its job. And so because the adversary is a learning human, uh, environment or a marketplace or whatever you want to think about as the adversary, they've moved to the place that is, uh, that probably is the most vulnerable.
And so, you know, people really aren't breaking in as much as they used to. They're basically just logging in. And so they're stealing credentials, they're tricking the humans to give away credentials.
They're looking at applications that hundred percent. And so now they're just logging in. And so I think companies are starting to think about what do I do about that?
Um, and then of course you add AI on top of that, and now you have sort of a, a, an autonomous system to a certain extent attacking the most vulnerable place in the environment, which is the identity elements. And so companies are, are putting a lot of resources there. Um, Yeah, we, we just, you know, we were, the day you and I recorded this happens to be National Data Privacy Day.
I don't know if you're aware of that. Um, Right. You could actually go, you know, get a t-shirt down to the Hallmark store and get a card, something, right?
But, but the fact, and, and so we were having a discussion and a few people on our Textron gang we're like, well, we need to be encrypting our data. And, you know, and yeah. Protecting our data, and that was the point I made art, is that people are brute forcing their way in and they're going to steal all this salted dash, you know, hash data and no, they get in right through the front door with your credentials, and you do have access to that data.
And until we, until we hit that ha square on, you know, everything else is kind of secondary. So that, that should be job one as we ate data privacy di I think, anyway, yeah, go ahead. I was gonna say to your point, yeah, so I think to your point, um, the reality is, is there, there's a couple of levels of that security that need to happen.
One is obviously you wanna manage those passwords, you want to change them frequently. So if they do get stolen, it's hard to use. I think the other thing that I think companies are starting to realize is it's not just your admins and your super users, your privileged users, that you need to be thinking about sort of managing privilege in this way.
And it's, it's all your users. And so it, it's not to the same level of, of stringency that you would control your privilege, your admins, but you know, our, our GILLAND has access to our customer data. A GILLAND has access to our financial systems.
You wanna be managing that access in a more sort of privileged minded way. Uh, and so this expansion of authorization, this expansion of privilege, um, and then you wanna watch what ARC does with threat detection and other kinds of identity based monitoring. And so a lot of the work that we've been doing is not only building the foundation to do the authorization, but also expanding capabilities into threat detection and into governance and managing the sort of whole ecosystem.
'cause right now, a lot of those systems are separate in companies, and that makes it difficult. 'cause you're managing in different UIs, you're managing different data sets, you're sort of, sort of swivel chair trying to do it. And in the world of ai, you kind of need the system to also be smart about it and respond fast.
Um, and so a lot of our investment has been there. Fair enough. Hey, art, we're about outta time.
For people who want to get more, maybe download the report or get more information on the report, or maybe even just find out more about deline, where can they go? com. Uh, you can get access to this report and a bunch of it, and then also a lot more info.
Yep. Sure. Makes, well, it, it's on your background, so they should be able to read it from there.
Right. com. Yep.
com. And, uh, there's lots of information there, a bunch of reports, this report, and many others. Fantastic.
Hey, art, thanks for coming on here and, and telling us, talking a little bit about identity security and, and all. It's, it's a brave new world, right? Exactly.
But, but here's the good news. We're making progress. We really are.
We're here, we're here. Find bad guys with you. So thank you very much, Alan.
I Appreciate that. Exactly. We're here, we're here, we're here to spread the good news, art Gilad, CEO Delania, here on Tech Trump tv.
We're gonna take a break. We'll be back in a moment.