Why Identity Governance Is Becoming the Front Line of Cybersecurity
Roy Katmor, co-founder and CEO of Orchid Security, discusses the growing risks posed by ungoverned identities and the expanding challenge of managing both human and machine access. Drawing on recent research into excessive privileges and orphaned accounts, Katmor outlines why stronger identity governance is becoming essential to modern security strategies.
Transcript
Good morning everyone. Welcome back here to Techstrong tv. My next guest is Roy Catmore.
It's joining us from New York where it's pretty cold today, almost as cold, well colder than it is here. But, um, Roy is the co-founder and CEO of Orchid Security, and let's welcome him. Hey Roy, how are you man?
I'm good. I'm good as the, as cold as you can think. Yeah, yeah.
Well, you know, I, it stays like that, that I remember why I moved from New York to Florida, but it's, it ain't warm, it's not warmed down here either, so I get it. Roy, I mentioned you're the co-founder and CEO for orchid security, but, you know, give us, give us kind of your own personal arc. You know, how'd you come here today?
So, um, Ellen, it's, uh, it's not my first rodeo. So I've been, uh, doing startups for a few years. I had a startup before, which we sold to Fortinet in, uh, 2019.
I ran the business unit there for endpoints, um, security for more than three years. So I'm, I'm definitely not a stranger to, uh, ramping up, uh, uh, startups and also not starting products from scratch. But actually my story is a little different than, uh, just, uh, yet another one with a good idea.
That figure that the market actually meets is great advice, but it's actually came from the market. Um, in my journey, actually, I would say, uh, more than 10 years ago, I was part of a founding of, um, of a VC that had a different state of mind named Team eight. And Team eight had a different point of view of market, basically to say, don't come to us with solutions.
Let us offer you problems and let's see you figuring out the right pain and the right solution for the right pain. And the way they do this is through a village. And then that means, you know, if I'm working security, and that's, yes, uh, by all means I did security my entire life.
But, um, that means that you actually going to, um, a villagers of professionals in security space, that that's the area that I'm, I was, uh, interested in. And asking them what bothered them the most. Where's the biggest budget, you know, how much timing the date actually takes them to do something.
Where is the biggest surprise on budget? Where's the mis misalignments between where they thought they're gonna be and where they are? You know, where did they miss?
And, and there's a lot of questionnaires and they're very structured as opposed to what I just did. But the sense is very well known, right? The idea is where does it hurt?
Feels like a doctor, right? You're punching, you're pinching, you're punching, you're pinching. And then when you hear the ouch, like, okay, we got a pain, now let's see if that pain is repetitive.
And we actually ran through a process of 250 round, kind of give or take, uh, global 2000 CISOs. And when we had a solution, we actually pitched it back to the same 250 to say, would you buy? Because it's not just finding a pain, which is, I would say 80% of the problem.
'cause then you can understand the ecosystem competitors, partners, um, um, you know, FS versus allies, everything is sitting right there how to go to market. It's also about, is the market ready to accept like the solution? So yeah, we hit the problem, but can you take that pill and does your body actually gonna react to it the way we thought?
And so that's how I came to it. Validation, pain, figuring solution, uh, alignment, and of course people that actually customer that actually converted fairly quickly. And you got yourself orchid in, uh, in funding.
Excellent, excellent. Um, so as a result of the, the prodding, the pinching, what was the problem that orchid security is, is designed to, you know, what, what, what is the itch that orchid scratches? I like the itch.
And I'll give you the itch from a, um, from a somebody who did a few things before. Very simple. If you get a solution in endpoint solution, right?
I want to protect your iPad, then I'm gonna put something on your iPad and it's gonna protect your iPad. Simple. Same thing with the network.
You're gonna say, Hey Roy, I got a problem at home with my network. I'll put something on your network. It's gonna protect you, endpoint.
I'm not asking you to do anything other than putting me there, right? And I'll do the work identity is, is does fundamentally doesn't work like that. When you deploy identity, let's talk, what is identity?
Identity is authenticating, which we running into every day because we're getting these a little annoying messages into our phones and into our computers. And that's the authentication. And there is an authorization, right?
What do I, what type of privilege and entitlement do I need to provide to Alan to do his work, right? That, that's what I need anywhere within those solutions. And, and there's a lot of point solutions out there.
And they're great solutions require you. Now, when you finish the deployment of those, you're gonna ask, okay, so where, where's my message? Right?
And they're gonna say, well, wait a second, Alan, you need to onboard that app that you wish to have that message to our solution. We just broke the model. We ask the user to do something for us in order to extract the added value.
I'm sorry. And that is where the biggest problem in identity is. That creates fragmentation because who are you gonna onboard?
The one that you are aware of, not necessarily the one that are most disposable, you're gonna do the ones that are easiest because you wanna show progress, right? We all wanna show progress. Hey, look how many we did, but are these the right ones?
Are these the, um, high priority from security, from, from usability, from accessibility, from everything that we need? And that created the, what we had coined as the identity dark matter. You did not onboard Alan to a certain app.
And so you allow him to do things local, but now you're not governing him. So when Ellen decide, okay, I'm done here. I I'm, I'm leaving the company, I'm removing you from the yellow pages.
Oh, but I forgot to remove you. And then I got myself a user that is actually can use it now, or an orphan account or dormant account. There's a lot of terminologies in this space, but the risk lays down in the fragmentation between those connectivity.
And if you're trying to quantify that 46% of an enterprise identities are ungoverned. So now think about it. Let's digest it.
When we are making an informed decision in identity, we are making it on half of our data. How good are you feel about that Now that is the problem that that is the itch that we are as orchid coming to itch for you. Yep.
So Roy, I, I don't know, I've been in security a little bit myself. Um, you know, and I've done a few venture backed startups I've co-founded. I really believe that.
Well first of all, I always believed that IAM identity and access management was the killer cloud security app, right? When we moved a lot to the cloud, identity became the, the focal point. 'cause you no longer had the Moton castle, you no longer had the big firewall at the edge there.
You no longer had your access. You know, data was everywhere. Apps were everywhere.
And the only way you had any control was the identity. But then we nev and we never quite solved that, to tell you the truth, right? We never got that straight, frankly.
But then machine identity, let's call them non-human identities, came into the picture, right? Whether we're talking IOT devices or, or containers, internal infrastructure that had to have its, you know, their own identities. Now of course you've got APIs and, and you've got AI agents.
And, and when you look at these non-human identities to human identity, human identities, probably 20% of the identities that we need to manage if it's that much 20% of the identities we need to manage out there. Is this something, when you talk about how Orchid is giving you a complete picture, is that non-human identity as well? That's a good question.
One, I didn't refer to what we do. I just referred to the itch. I didn't refer to how we scratch it, but you are absolutely right.
You, you know, if I refer to the dark matter, which is again, the fundamental deployment of, of identity creates a dark matter, a fragmentation, because we're not gonna do it all. The world is not perfect. And it's so much not perfect that the traditional like human identities are 46% dark, meaning I can't see them.
Now you can ask me Roy, that's great, but you know, what's new here? And, and, and my point of view would be you are right. It didn't change a lot since the cloud exploded and, and our amount of applications have grown, but it's growing now faster.
The 46, like the dark matter is now PO to take over. And if you would've asked why, because everything became a hybrid, you may think that your app is to completely governed, but guess what? It has a machine to machine that does some things on the backend to do disaster recovery.
And that does not govern. You cannot, you cannot challenge the machine. And of course if you add to that service accounts, because we need third parties because maybe API and on top of everything, the, the beast in the room that nobody knows how it's gonna grow up, right?
We just see a little, a little, uh, puppy right now. But that puppy could become in a huge tiger and take over. But the agent's ai, why is that even bigger?
Because think about it, the problem is now ex it's exponentially bigger because the, what you're seeing is one, an agent working on behalf of who, who is typing that check. Do you know what we are used to? Kind of the check GPT, who is the operator?
What is the operator authorization of doing it? So it's great. And what is the context on what intent is this working?
Things that we knew on human, we don't know on machines. Yeah. And that is, this Weekend was a great exam.
I'm sure you are following what went on this weekend. Uh, a great example of it, a great exam. And then to find out these things, there's security like everything else that gets built, they thought about security.
We'll get to it later. And, and now, I mean this is a disaster waiting to happen. You're, and you said it, right?
You know, even when, you know, I always, when I walk in this, I walk exactly in the same steps that you did. I said, listen, we started very easy. Everything was on premise.
We were in the late nineties, beginning of two thousands. Even then the dark matter was three out of 10, 30%. So even in a easiest world, we were not perfect.
Then we had the clear, We never figured it out. Yeah. Then we had a cloud explosion, 46 invisible.
Now with agent ai, the idea is that we're gonna go over 60%. And the why now from a business perspective is because we are really looking at the, you know, at the EB, like the tiniest portion of it. And we are making decisions on a portion of a very little portion of the data.
And that is not the way you can make decisions. And you know what the best thing is? You got good point solutions out there, great vendors that can do the work, but you are not onboarding 'cause you don't know who, when and why.
And then it's becoming very dynamic and yes, this is when orchid is actually coming into play. So, all right, let's, let's shift to how does Orchid actually do it? So Kind of think about it orchid as the solutions of solution.
I know that everybody likes to think about orchid, the nice flower, but also think about it as an orchestration of identity. Basically what we're saying is, as opposed to the network and endpoint where I started to say, well, there is a very known progress of deployment because the infrastructure is there, we need to have infrastructure for identity, which means I need to know what do I have, what assets are actually I have within my environment when it comes to applications. I need to understand how much exposed are they, how much risk are they providing me?
So I'm not gonna just gonna do the one that I know or the one that are the easiest for me to do, but I'm gonna do the right pieces, the right applications. And of course, if I can do all of this and I can do it from a compliance, I can do it from a security, I can do it from NIG, I can do it from a context. You can already imagine why LLMs are becoming a critical pass of this.
And I can do it by intent. So what Alan is trying to do to a finance system that has orphan accounts, and it is not by compliance by a certain level. And so I can highly prioritize it from the business point of view, from disposability point of view, from compliance point of view, and connect it with no code, no engineers straight to the tools that you already made, your investment in an identity.
And that is exactly what we're bringing into the, basically it's an infrastructure for the modern identities world, including agents, ai, but also the legacies that we didn't do 20 years ago. And so we need to do mo to the adherence of security and compliance. I love it.
You guys recently did a little research. I understand that you, uh, I don't know if that was what you were referencing with the 46% to 60%, but give us a little more on that if you don't mind, Ray. So one of the things that we are announcing here today is an audit.
And all customers were asking us, wow, you know, so the dark matter is really big and, but we do, how do you give us the evidence that these things that you claiming and we're not debating, but show me the money. You know, show me that, because for me it's a, it's a blind spot. And so what we started to do is to generate audit of users, activity of identities for applications that are ungoverned for the application that are governed or hybrid.
So just like you said, the non-human is not gonna be audited, but the human is audited. So we mesh those together. We generate for the ones who are ungoverned for their identity, we mesh the data that is already managed together to give you business insights.
And the research was once, now that we got that to add the dimension of context, intent into our prioritization, we started to look at the data. You know, we are a little upside down company, usually company starts with the small vendors. And growing up, we actually started with the Fortune 20 vendors and started to go to the Fortune five hundreds going to the global.
So we started at the top with vendors like, uh, like Costco, like Hub, uh, hub International, uh, um, uh, repsol, a lot of fortunes very high. Uh, and, and, and, and we started to look at, okay, then let's see what this new audit, let's see how bad the hygienists or how good the HY is. And what we find is that 85% of the applications estate, think about it, these are Allen business applications have accounts from legacy or external domains.
That means you have leftovers inside that are encapsulated within those 20% of those of these are consumer email domains. So you have a lot of mix of identities within them. 70% of the applications have excessive, six have excessive privileges in them.
60% have admin or, or already you mentioned API access to external third parties to them. And 40% of all of them were found as orphan. 40% thinking, I'm, if I'm a hacker, I'm not gonna go to the one that you're using the most.
As opposed to your strategy to say, well I'm using this app the most, let's start with this app and onboard it. Right? No, they know you're governing this.
You know, they're monitoring it. They're gonna go to the ones that have 40% of all the accounts have orphan accounts. I'm gonna go to the orphan account because it's not supposed to be there.
You are not tracking those. Definitely not governed. That's my base.
I'm working from there. I'm not going to the known very high profile applications of yours. Got it.
Very, very, very cool. Roy, I don't know, did we, I didn't remember us mentioning the website. I don't think we did.
You're gonna find a lot of our use cases, um, you know, um, uh, technology wise, patents, management team of course. Um, and it's all in the orchid doc security portal. So that's what I was looking for.
Orchard security. Very cool. Um, Roy, we're about outta time, but listen, I wanna wish you well here with Orchid.
This, this is, look, this is a problem, as I said earlier, right? It's been a problem that we never like a festering soar that we never really solved. But then what happens is stuff gets layered and laid on top and top problem gets bigger, right?
And you, you know, dark matter, like real dark matter, we can't see it. But the force it exerts on, on us, on the universe is, is substantial. So I love it.
Come back to us, keep us posted on orchid and best of luck. Stay warm up there. Same here.
Let's illuminate the dark matter with some light, right? We need some light in this World. Bring the light.
Thank you. A that's a good way of doing it. Roy Kamo, co-founder, CEO Orchid Security.
That's orchid security. Check it out. We're gonna take a break.
We'll be right back.