Rebuilding Identity for the Agentic Era
Identity has become the control plane of the modern enterprise — and, as attackers have figured out, its weakest link. Zohar Alon, Co-Founder and CEO of NewCore, joins Alan Shimel on TechStrong TV to introduce his new company, fresh out of stealth with roughly $66 million in funding from Cyberstarts, Index Ventures and Evolution Equity Partners. Zohar, who previously built and sold Dome9 to Check Point, argues that legacy identity platforms were designed for a world of humans and a handful of machines — not for the agentic era, where AI agents may soon outnumber human employees 100 to 1 and operate at machine speed. He walks through why centralized IDPs have become high-value targets, why passwords, SMS and six-digit codes must die, and how NewCore has rebuilt the identity provider from scratch to distribute trust between the vendor and the customer. He also explains how agentic technology powers side-by-side migrations from incumbent identity platforms in hours rather than years.
Transcript
Hey everyone. Welcome back here to Techstrong TV. My next guest here, I've been interviewing him for I think as long as I've been doing Techstrong, just about, and maybe even before Techstrong, when I left Still Secure, and I was doing my thing freelancing and so forth.
My friend Zohar Alone, Zohar, I think I met you, you were still by Check Point? Or you had- Oh, before ... it was before Dome9.
Before Dome9, yeah. Yeah. And then, of course, Zohar was the founder of Dome9, which was a real flag in the ground for web-based firewall and stuff like that.
It really set the market. It defined that whole market. How are we going to defend stuff in the firewall?
In the cloud, excuse me, not web-based, a cloud-based firewall. And this is when the biggest impediment to cloud adoption was security. Maybe it still is.
But anyway, I went all through Dome9. Then Zohar sold Dome9. Dome9 was acquired.
I talked to Zohar there. He left there. He became more of an investor and advisor and helped several companies.
I've been through up, down, all around with him, but I'm really happy to have him here with us today for an announcement I'm going to let him make. Zohar, my friend, it's good to see you. I hope all is well.
All is great, Alan. So great to be with you again. And we'll probably do it 10 years from now also.
So we're only- If I could get that in writing, I'll take it. But until then, I didn't want to steal your thunder. Why don't you make the announcement?
What are you here to talk about today? Yeah, we're going to talk about my exciting new baby. Nothing like when you build and run companies, you enjoy it, and then if I'm not doing that, I'm doing errands for my wife, so nothing is more important than building.
And we're in a day or an age where the world is changing again. Early days of internet, early days of cloud, and now really early days of AI, if we look at the big picture. Mm-hmm.
And to build something fundamental that also had my personal pain of being an employee in large enterprises, Check Point, and later on, let's say, several other companies that are quite large, and to understand that the identity experience that the user is going through could use an uplift, could use a real upgrade. And we launched, a couple of weeks ago, Nucore Identity, my new venture. We're already 60 people, so we grew it quite large while in stealth as they do now.
Announced the fact that we raised almost $70 million from the world's best cyber and general investors that we could hope for, Cyberstars, Index Ventures, and Evolution, to really solve a big problem, which is workforce identity, as the agentic wave is hitting our enterprises so dramatically and so vividly now. I'm here to talk about it. Excellent.
I just want to get one thing clear so I don't want to confuse our audience. Nucore is the name of the company or Nucore Identity? Nucore.
Nucore is the name of the company. And the website? com.
Excellent. That's what I wanted to make sure we had. So you know Zohar, it's funny.
" And I was only half kidding. We never really solved it anyway. But what the most important piece of the whole cloud security thing, or the one piece that we have worked on, is identity, right?
Identity and access control is the moat and castle of cloud security, right? It's how we control who goes where and does what. And I've had this discussion with security friends in the past.
If you look at it, the first challenge was just identifying people. Right? You're Zohar, I'm Alan.
Based upon who you are, who I am, here's what we can do and where we could go, and what we have access to. That was hard. Still is.
And it still is. We never quite solved it. But then another straw on the camel's back.
Now we started getting machine identities. Every container has a unique identity. Every kube, the whole thing, every IoT, OT device has a unique identity.
And we got to give them a unique identity and again, secure what they go to, what they can access, when, et cetera. Now all of a sudden, a problem that we never really solved got 10 times harder. Now we come to this next agentic thing.
They're saying we're going to have 100 agents for every person. Right. So we never solved the identity, we never solved the IoT.
Now we've got to solve agents, too. Is it impossible? Look, we are taking part in the biggest workforce expansion in history.
Yeah. Organizations are going to grow by 100X the amount of elements, let's call them, that are doing work. It's people- Yeah ...
it's agents, people that are operating agents, agents that are operating agents. We're going to see so many combination, and it's going to happen, I want to say overnight, let's say over a couple of quarters and maybe even a few years. This is a dramatic shift because agents operate at a different scale, at a different speed.
They also produce a lot more work. Yeah, it's expensive. Tokens are not cheap, but the reality is that you can, once you learn how to operationalize them, you can run 100 in parallel and thus really strive to the outcome and really ignore the tools, really rethink a lot of how work is done.
And enterprises, especially those in competitive environments, are really being pushed to utilize and to embrace that growth and this technological change as exactly like in the early days of cloud. And the poor CISO, we are there to essentially help them say yes, because the unknowns and the potential minuses in the change of embracing in production concepts and technologies that we didn't have a year ago. Identity space is pretty conservative.
We still use passwords 40- Mm-hmm ... years later. It's conservative in terms of we are in a position where the blueprints and the protocols and the standards are, reality just outslipping them in a ways that we now have to gather ourselves and say, "Okay, how do I enable that?
" And identity is critical because it was already crumbling to begin with. This is our concept. So you're talking about 100X on the sheer number of elements that are going to have an identity.
You're talking about also another 100X on the volume, on the speed, on the strain of-- You and I, we use one Chrome tab at a time. An agent, this is- No, it's AI scale. Not then first.
It's not just speed. It's truly- Exactly ... scale.
Mm-hmm. And so we talk about identity events. You're talking about several orders of magnitude, like four at least orders of magnitude more identity events.
Just to enable that in a safe way on an environment or on a technology or a platform that was designed for yesterday's load would present a problem. But it's not just load, it's also security. The process or the thesis behind building Nuco was that there was a lot of things in identity that could be done in a much more secure way fundamentally.
There's so much trust in your cloud-based IDP today, whether it's Entra, Okta, Ping, whatever you're using, JumpCloud. Those platforms hold so much trust. They decide that you are who you claim you are.
I am who I claim that I am. But they federate that decision to hundreds, sometimes thousands of applications that are- Yeah ... and this kind of meeting point has so much value for the bad guys that they're not hacking in anymore, they're logging in.
They- Right ... realize that compromise you or my identity is so valuable. And sometimes because we are the weak link in, especially compare us to the new frontier models, how can you and I deal with the onslaught of attack that would want to compromise our identity to gain access to our workforce systems that essentially is allowed to us by this central federated system?
And moreover, those systems are a target themselves. We have the several large Okta breaches that happened over the last couple of years. Those systems are the target themselves because they hold so much trust.
So when we put our cybersecurity hat on solving that trust problem, we realize there are several things that could be done without changing the protocols, without asking you to retrofit or to rebuild how your employees are working and how the applications are connected to reduce a lot of risk of the poor CISO's plate out of the get-- Without just giving us the chance, we'll show you how there's a dramatic reduction of the risk that you're dealing with day to day. Now, when we compile on top of that the agentic enablement On behalf agents that are working on behalf of users, agents that are system agents that how are we going to call them? How are we going to refer to them?
What stress and strain are they going to put on our audit trails? Remember, we talked about Lambda function security 10 years ago. Years ago.
An agentic mind is not a single-purpose function. It's a monster. It can do everything.
And we are in such a great position to enable that because we're going to have enterprises embracing it. They are embracing it now, and we just want to make sure that they can enjoy the best technology to support them in this very critical point. But Zohar, there's an old story here.
Progress waits not for security, right? And so people are going to use agentics. They are using agentics.
We're seeing it. The adoption curve is it's not even a hockey stick. It's vertical.
Right? But security is always a laggard, right? Security trails.
It's like a trailing indicator. What can we do? Let's talk about Nucore itself.
Right. How does Nucore help us even this out, put security on par with what we're doing here? So far what first we did, we rebuilt the IDP from scratch with a way to distribute the trust between us as your identity provider and you as a customer that can maybe hold part of the secret that allows this great enablement of access of your workforce to your application.
So by sharing the trust, we stop becoming a single point of compromise or a single point of failure for your environment, which is the architectural issue that we've identified in existing solutions. We came up, we built, we have a new way of doing MFA. People stopped trusting MFA, especially the great-- Now we have great, we have supercomputers at our fingertips, and I'm holding my iPhone up.
But we don't trust MFA anymore because it became phishable. People are exploiting trust over the phone. We found a way to regain trust in that.
And essentially every direction we looked at, we found ways of improving the inherent security of how things have been done in the identity space because realistically, it's not done by cybersecurity companies. The core identity providers, the core identity platforms, how they solve security, they patched it. I'd acquired a cool small Israeli startup to essentially fill the security gaps that were building around the stack as it grew.
Funny, the day we announced the Nucore funding, two small Israeli companies were acquired by two large identity giants as an anecdote. And this reality is not going to change, but I'm also building with AI. We can build so much faster today.
We can migrate you faster because agentic technologies can onboard users and move your apps from your incumbent, from your traditional identity platform to ours. So the way you even look at an identity project could change dramatically because we are enjoying the same values that this revolution brings. And what my guarantee to our customers is that there's still a lot of things that could be solved and could be a lot of risk to be taken off their plate, essentially to enable them this crossing over to this new amazing world that we are all seeing.
Agreed. So does Nucore sit on top of the federated identity people, or it replaces that? Replaces.
We will sit side by side. We'll show you the value, but remember, I'm talking about taking risk off your plate. Once you see how the promise of that is realized, and once you realize also that agentic technology is for migration of old incumbent, the platforms that are not necessarily providing the value that you think, how those two things connect together, you essentially the customer says that, "Okay, let's not just migrate three applications, those my crown jewels.
" You got the new MFA technology. You see how good it is for 5% of your employees. Let's onboard it to 25% of your employees.
The other element is passkeys. We're talking about passwordless. It's a promise.
Today we have two and a half desktop operating systems, two mobile operating systems. To build around passkeys today or to leverage the fact that you are introducing Or effectively, hopefully replacing your core traditional identity provider with a modern one, and by leaving passwords behind, literally showing passwords the door. " This is not true.
The passwords in a modern enterprise that's talking about agentic should die. Literally, my-- And not just that, SMS-based authentication should die. Even WhatsApp-based authentication should die.
And even the six figures that you get from your authenticator, I can trick you over the phone to give me your six figures, right? Your six digits. So I would not want to enable that in a modern technological, modern and prospering enterprise because you're always as strong as your weakest link.
And if you enable that weakest link to survive, you're sacrificing- That's how strong you are, right? That's- That's the level you're at Absolutely. And also, going into the future of agentic, in order to enable that, we will have to make some compromises around usability or around security to enable people running, doing that.
So my promise to our customers is that this partnership is around taking you through that journey and not leaving you. Really satisfying your needs as a cybersecurity company doing identity and not the other way around. Got it.
Let me dive in the weeds a little bit, Zohar. Is product available now? Customers are using it?
How can people go get it? How is it packaged? No, absolutely.
com. We have plenty of customers already using the platform of all sizes, small startups and some large multinational companies that are experiencing the value of the different capabilities. Obviously, the agentic capabilities are drawing a lot of people in.
But the nice thing to see is you come because of you need to solve for agentic, but then you see, oh, you guys also do this from an IdP perspective. Let me introduce you to the person that runs our core IdP platform, and then we start a completely new discussion. Yeah, and experience it today.
Reach out to us and you can have it in your hands tomorrow. I love it. com.
Zohar, I wish you luck, but I know how hard you work and what you've done. There's no doubt in my mind this will be another great company that you've been involved and started. So congratulations.
Do come back. Keep us posted here, okay? Thank you.
All right. Fantastic. Zohar Alone, co-founder, Chief Executive Officer, Nucore, here on Techstrong TV.
We're going to be back with more in a minute.