The Access Trust Gap: Why SSO Alone Can’t Secure AI and Identities with Dave Lewis
Explore insights from 1Password’s 2025 Access Trust Gap Report, as Dave Lewis reveals how Shadow AI, unmanaged access, and identity risks are exposing critical gaps in enterprise security.
Transcript
Hey everyone. Welcome back here to Techstar tv. You know, I'm really happy to have this next guy on.
Um, you know, I've been in security for a minute, and so is he. I've known him under many nine names, right? True, true.
Uh, but today we just call him Dave, Dave Lewis. My friend Dave Lewis is the Global advisory CISO over at One Password, but he has a long and distinguished career. One of the original security bloggers, right?
That's true. When we, when we first started blogging security, he's worked well, you know what, Dave, without spending too much time, give him a brief kind of view into your, you know, your past. Well, I, I've been doing security now for I think 31, 32 years at this point.
And it's absolutely amazing when I look back to like early eighties when I was duping video games and selling 'em, the kids in school. It's just been, uh, it's been an adventure to say the least. And I've, I've pretty much had every role along the way except for doing cryptography because math.
Yeah, math is hard. Math is hard. No doubt about it.
So, Dave, you've been at One Password now, what about two years? Uh, a year and a half at this point. Yeah.
And of course our friend Wendy Nather is with you over there. That's true. And there, there's some other surprises that are coming down the pipe as well.
Really? Yeah. Oh, you'll have to come back on and tell us when that, when that's out there.
More than happy to. So, any pe any people I know. Oh yeah.
Oh yeah. I gotta be cagey at this point though. Alright.
Be kg. Be kg. Hey Dave.
I'm a one password user. We're actually, I think we're, I think it's an enterprise account and our whole company uses one password here. Excellent.
Appreciate It. Um, yep. We've been at, with OnePass in a while, but for those who don't know one password, give 'em a quick kind of elevator pitch.
Well, the, the quick, the, the quick and dirty of it is we were about 18 and a half years as a mom and pop shop doing one thing and doing it really, really well, which was a password manager. And last year and a half we've transferred over in, well, not transferred, but added in the enterprise play as well with extended access management. And we now have the security for AI tools that are coming down the pipe as well.
So it's been really an amazing adventure of figuring out ways that we can help organizations that have been sold a bill of goods along the terms of SSO and how they can better secure their organization with extended access management, things like that. As well as having enterprise password managers much like yourself and just finding ways to help organizations better secure themselves without having to pay, you know, that extra premium of adding in SSO, uh, tax into their, uh, you know, financial statements. Absolutely.
Pass keys mm-hmm. Is one thing I really like lately about one Password, but Dave, well, let's put it this way for people wanna get more information on one password, where can we send them? com for starters.
And the other thing too that we have, uh, just come out is our annual report, uh, called the Access trust gap. Yes. And this has been an amazing thing that has been pulled together because we did it as a double blind.
We didn't want people to think it was, you know, oh, it's one password. So I have to answer the question this way. We wanted raw unvarnished opinions, and there's been all sorts of different things that came outta that, like the rise of unsanctioned AI and unsanctioned IT systems or shadow ai, shadow it, depending on what nomenclature you prefer.
And it's just amazing to see the, uh, results of that particular study. Excellent. Um, I'm gonna assume that the report, you know, the report is downloadable on the one password site.
Oh, Absolutely. Well, we were thinking about doing, you know, stone tablets, but you know, that's been done. Yeah.
They're heavy and they charge you by the pound today at FedEx. So, but that is the way to go. But Dave, give us kinda, you know, give us the highlights here.
What are Gimme the three big key takeaways? Well, the big takeaways right outta the gate or the rise of ostensibly, was people can refer to as either Shadow IT or Unsanctioned a it a IT it rather ai. And it, and this has been really amazing because I've done a lot of CISO roundtables across Europe, uh, over the course of the summer, and all of them said that they had a real problem with all of these AI systems within their environment that they didn't have any really good control over or any sort of good governance to deal with it.
And when we're looking at these, you know, AI governance, really, there was like 73% of employees that were pulled were encouraged to use ai, but only 37% were actually following company policy. So it was really kind of interesting, uh, little factoid that came outta the report there. And the other part, Well, I think, oh yeah, you know, I think people who, we get the same thing here.
We encourage everyone to experiment and use ai. I think AI governance is a bit of an oxymoron still, right? Because I, I'm not aware of any government.
We just don't go forth and, you know, prosper and, uh, you know, it's, it's, it's a bit of the wild West Dave. Oh, a hundred percent. And that's exactly what, like one CISO in Vienna said it very succinctly is that we've closed the door to AI projects in our environment, but they keep coming through the window.
And that's just did it is like, yes, you have governance in place for, you know, traditional IT systems, but AI has nuance involved with it. And, you know, when you're factor in agent AI and, uh, autonomous systems and things like that, it really does change the calculus for an organization a bit. The risk and the potential blast radius of what they have to contend with.
Absolutely. But on the other hand, look, I saw this happen with open source. Mm-hmm.
Right? Open source coming in the back door and the developer's briefcase or backpack right in into the enterprise. I, I remember being in an Army base when I was at Still Secure, so go figure 15 years ago, 18 years ago.
And I asked the deum, who's like the CISO of an army base, right? The mm-hmm. Information insurance officer, what are you doing about wifi security?
And he said, wifi security, we don't have a wifi security issue. We don't have wifi. You know, and as he's saying that, I'm seeing people unplug their wh and throw it under their desk as we're walking by.
As soon as we walk back, they plug it back in. And this is on the US Army base. Yeah.
So it, you know, it's the same thing with ai. People are gonna do what people are going to do and you could either accept it or stick your head in the sand. And that's just it.
We have to give them guardrails and how they can operate safely and securely. Like if you look back to the pandemic security really had their watershed moment where we were able to demonstrate that we were there to empower the business to operate safely and securely when overnight, in a lot of cases, these organizations had to suddenly find the way to be remote, Even if, even if Daddy was using his daughter's little Pink Barbie laptop, that God knows what was on it. Um, but yes, we, we lived through it, Dave.
We lived through those days. Exactly. And, and to your point earlier about PAs keys, that's another piece that came outta the report where we found that 89% of security professionals said that their company was actively encouraging the adoption of PAs keys.
So that is a really cool shift it, because normally when this sort of technology pops up, it's at least five years before adoption hits and now we're about, you know, that amount of time into it since basies have been really a going concern. And it's really amazing to see that that's really coming to a, a good place because it's just a, a better way to do security. 'cause passwords, uh, I've said time and again, they're very much like a house key.
Yeah, I, I agree with you, man. I, you know, and I think the last time I looked I had 250 odd passwords, right? I, I can't remember five of them.
Right. You know, and there are always variations of the same thing with me. So it's just like, it's crazy.
And then what I try to do is a double helix. So I, not only do I change my passwords around, but I change what email I use. 'cause I have, you know, I have a lot of email aliases and stuff, and It made it hard for me to get into your iTunes account.
I gotta admit. Yes. I I, it's hard getting in it.
Well, I have m FFA on there too. That's the other, you know, we didn't even discuss M ffa, but that's an another thing that it's like pulling teeth to get people to adopt And, and that's just, it is, we gotta give 'em the tools that are going to be easy for them to use. 'cause if we give 'em tools written by engineers for engineers is just not gonna work.
Because somebody might be in hr, they might be in finance, and realistically they're very good at what they're good at, but cybersecurity mm-hmm. Not on the List, not their thing. So we have to figure out how we can empower them and get that to work effectively.
You know, back back to the shadow AI thing, Dave, that's exactly why it's so successful and so alluring like a drug. Mm-hmm. It's so damn easy.
It's, it really is. And like, if you follow along, we're at that hype cycle right now. We haven't got to the disillusionment part yet, but that will come.
But the thing is AI really is a fantastic way forward in that there's so much potential and there's so many people that are very concerned about it and justifiably so. But don't throw the baby out with the bath water. Find ways to better secure it.
Like making sure that the credentials that ai, uh, agent AI rather is using are controlled, managed. And you have some sort of revocation that you can do in the event that something goes wrong. Because all of these agents need some sort of thing authentication to access systems, to access, uh, APIs, all the rest of it.
How are you managing that in your environment? Or are you, You know, for me, Dave, this whole issue is, is crystallized in another survey than I recently saw more focused on developers. Mm-hmm.
90%, 99 0% of developers are using AI to help generate code. Oh dear. 90%, 40% don't trust it.
65%, 65, 2 thirds or near two thirds say that it introduces instability into their code base. Well, yeah. It's like stack overflow on steroids.
Yeah. Yet 90% still use it. So what does that say about our reasoning here, that nine outta 10, you know, dentists, nine outta 10 developers are using it even though nearly half of them don't trust it and two thirds of them know, think it introduces instabilities, but they'll use it anyway.
Well, honestly, it's about time to market. You know, they are worried about meeting their deadlines. Fomo.
Yeah, Exactly. And if you look across the industry's, so many companies are cutting ties with staff that a, a a few of the companies are realizing the error of their ways, but, you know, people feel that pressure to be able to deliver. And then unfortunately, security gets compromised as a result because they're in introducing instability, um, you know, code issues.
It's not like AI has hallucination problems and also kudos to whoever who came up with that term because saying it, it turf toed something by calling it hallucination is actually great marketing. I, I, I've always loved the hallucination thing. It's brings me back to my youths.
Um, but anyway, you know, I'll give you another factoid metric I came across recently, which is, um, CIOs, 60% of them are asking for more budget this year for AI projects. Mm-hmm. Because their board encouraged them to do so.
They're not even sure what they're going to do with it, but their board is telling them, you better go do something with ai. Well, it's, it's not just the AI too. They have to look at it from the perspective of SaaS sprawl because all of these organizations have all sorts of SaaS implementations which are directly connected to AI projects.
And if they're not managing that, you know, their budgetary issues could go through the roof, their exposures for stuff that they don't know about. I remember back in the day working for a financial institution in Canada, we went through credit card statements for the corporate cards just to find who was using AWS. Obviously there's a, there are much better tools like that, uh, that are available to do that sort of thing now.
But yeah, it it's absolutely amazing. You, It's like, you know, back then that's what you had to do. Mm-hmm.
But, but here's my, and and you know, being in security as long as you have it, me too. How many of them are increasing their security budgets because of ai? I don't believe we're at that point yet.
And that is a industrial indu Yeah. Industry maturity issue, right? Because everything's so new, everything is so fast that we are fundamentally ha gonna have to play catch up.
It's sort of like, like I always like to use the analogy of when the internet was born it was point A, point B and just make sure it worked. Security came later. Unfortunately we're seeing this same behavior repeated again.
We saw it in cloud, we saw it in, you name it. And now here we are with artificial intelligence where honestly we are playing catch up again. Yeah.
So that bums me out, right? Sorry, I'm done. It's okay.
At some point, Dave, I always felt like we're going to do better this time. Mm-hmm. Right?
For once we're going to get out ahead with it for once. They're gonna say, Hey, what about security? Earlier in the conversation, I have hope that we will get to that because if you look at jurisprudence, you look at the medical profession, they have hundreds of years of canon.
They've learned their lessons over time. For the most part, we're relatively in our infancy from an industry. Right.
And I believe that as we learn to capture the details and learn the lessons learned and sharing them with the folks that follow after us, I believe that ultimately we will get to that better place. So I do have optimism on that front, but it's gonna be an ugly, bumpy road until we get to that point. And honestly, I think that that will happen after you and I have gotten onto a boat and wandered off to have a couple of my ties.
Yeah. Alright. And there's Dave's happy moment for today, Dave, where you go?
I know you globetrot more than I do even Where are you headed to next? Man? I'm actually gonna be running around the Nordics then, uh, very shortly.
So that's gonna be fun. Copenhagen, Stockholm in Helsinki. Oh, that's a, Oh really?
I love Stockholm. Oh yeah. It's a great town.
Stockholm the old city there. The old town in there is beautiful. Nice stuff.
Absolutely. This time of year it'll be dark, but or getting dark anyway. Yeah.
But Yeah, a lot of the holiday markets will be set up and things like that, so it'd be, you know, brightly lit. It'd be really cool. You'll, you'll be at RSAI assume?
Oh yes. I can never miss the Super Bowl. Yep.
March. End of March. I was just working earlier on some stuff we got going on there.
Dave, what else in our, in our report here, one password's annual report, anything that you read Dave and said, geez, I didn't have that on my bingo card. Uh, honestly it was really bringing home what I saw with the CISO roundtables that I've been doing throughout Europe over the course of the summer. All of the pieces that were like the AI security governance and you know, the weak credentials being a problem, like all of the stuff that we've been talking about for so long, uh, the adoption of passkey, all of it really was validated in a lot of ways.
And, you know, this, this, you know, to be fair, this was a survey but it really did reinforce all the things that we were concerned about. Um, and we really do have to get better because we have all been collectively working at this for so very long and we keep seeing the rep repeated behaviors because we don't have the core fundamentals of security in place. Or we get hyperfocused on the new shiny thing, in this case AI and suddenly we're playing catch up again.
And I really enjoyed absolutely, I really enjoyed this report simply because of the fact that it highlighted the concerns that CISOs have from shadow ai, shadow IT, legacy issues and organizations. And all of these things tie together to really present a potential blast radius for organizations that's just gonna get bigger unless we get our hands around it quickly. Agreed.
Man. Hey, I gotta run. We gotta do another one.
Dave, come back and talk to us. So, well you already teased us with news, so now you gotta come back and tell us You got it Anytime. Don't be at ease Dave Lewis ciso, a global advisory CISO at one password talking about one password's annual report for 2025 about the access trust gap and shadow ai.
It's real. You are watching text Drug TV will be back in a moment.