Managing Non-Human Identities in Cybersecurity with Itzik Alvas | RSAC Conference 2025
Itzik Alvas, CEO of Entro Security, discusses the management of non-human identities. These credentials, often created without security oversight, pose significant risks. Intro Security aims to connect developers and security teams to enhance identity management. With the rise of AI, the complexity increases, but Intro offers automated solutions for lifecycle management, improving security for clients and planning future growth.
Transcript
Welcome to Techstrong tv. I'm Lisa Martin, live from the show floor at RSAC. This is our 10th year covering RSAC from Techstrong.
We're gonna have some great conversations all week to stick around with us. Alan Shimmer will be here. Mitch Ashley, some other great folks.
I'm joined by my first guest of the day, IIK Elvis, the CEO and co-founder of ent, intro Security. Iic. It's great to have you on text on.
Yeah. Thanks for having me. Talk a little bit about, the launch was about two and a half years or so ago.
Yeah. I saw recognition from nasdaq. That's exciting.
Yeah, very much. Give us a picture of what you saw gap wise. You, you mentioning before we went live that you were a cyber practitioner for a long time.
What gaps in the market did you see and go, I, we can solve this. Yeah. So RO is a non-human identity lifecycle management company.
We are helping organizations to protect their non-human identities, like service accounts, API keys, and so forth. Uh, so prior Toro, I was responsible for the internal security at Microsoft. Uh, prior to that I was a CSO for an healthcare services company.
I was positive, breached few times by non-human identities. Ah, yeah. So that's what led me to start intro.
So yeah, the, the main problem we're seeing in the industry is that usually developers are the ones who are creating, uh, permissioning using those non-human identities. And they also scatter them around, like come committ them into code and sending them over Slack and so forth. And the main problem we're seeing is that security teams don't really know how many non-human identities they have, where they are.
Debs are working on their own without security involvement. With no security oversight. None whatsoever.
Wow. Yeah. So you came on and said, we can help.
So are you, are you bringing those, the developers and the security folks together? Is that kind of one of the main things that you were facilitating? We, we, We letting development do what development are doing best, which is develop and develop fast and enable the business.
But we an overlay, uh, platform that finds all of those non-human identities and then gather them, um, doing risk assessment, abnormal behaviors around them, and basically giving visibility and risk assessment to security teams while we are not touching anything the development teams are doing. Okay. So completely out of Bend.
Okay. Excellent. That's a great, uh, collaborative, uh, environment, which is exactly, it's, it's essential these days.
It's not even a nice to have, it's essential. Right. Talk a little bit about non-human identities.
What are they, why, what are some of the critical functions that they handle? So, nonhuman identities, those are, uh, the credentials, if you will, that applications are using in order to access and authenticate to resources those application needs. So if you have an application that needs to use the database, they need some sort of a way to authenticate against the database.
And that's the faction of non-human identity, uh, programmatic credential basically. So they're, they're becoming more and more common, yet they're also opening a door from a security breach perspective. Talk a little bit about That.
Correct. Yeah. So what's The balance there?
Currently we're saying that for every human identity, like human user, there's 92 times non-human identities, 92, Which is insane. That's an insane number. How do you Even manage that?
You unable to manage it without any sort of platform to help you do that. Yeah, yeah. Uh, and again, because developers are the ones who are creating them and managing them, or are managing them, security don't really have even an inventory to answer the question of how many they have and where they are.
So of course, doing risk assessment. Yeah. Uh, rotating them, like resetting their passwords and so forth.
Those are something that the organizations are really struggling to do. Yeah. Yeah.
Yeah. The this di visibility on it 92 times NHIS versus humans is Correct. I I imagine we're just seeing AI assistance are just becoming indispensable Yeah.
For every type of organization. How do you manage that? So it's the same problem.
Ai, it's another application that needs to access resources within your organization. Yeah. And they are using non-human identities in order to authenticate against the resources Right.
Within the organization. So that's only increasing the current problem of non-human identities. Is it time organizations start treating these assistants like employees?
Like I, I, I believe so. I believe so. I believe that in the near future we will start seeing those non identities, uh, being used by AI agent, creating more non identities and starting to do stuff within the organization on their own.
Uh, and they will be kind of an employee. Yeah, I believe so. So the challenge is there, from a manageability perspective for security teams to get their handle on all of these non-human identities, get the developers really focused on developing code Right.
But also managing this growing probably exponentially growing. Yeah. Opportunity slash challenge.
How does intro come into the picture and and eliminate those challenges for organizations? So again, the main problem is they don't have any visibility or risk assessment around them. Um, so what intro is doing, we are able to find all of them and basically automate secure other lifecycle.
We are treating them as if they are human identities. Yeah. Uh, like your onboarding human and offboarding human, we are doing the same for non-human identities.
So we are finding all of them, uh, giving you an inventory. So you will be able to answer the question for many non-human identities you have. And where they are.
We then enriching them, uh, to a point, you know, which applications are using water, non-human identities to access water resources and other vital data around them, like human ownership and so forth, permissions. And once you have the inventory and the classification, the map of what they're being for now you can do risks assessment. Okay.
Now you can do answer questions like, do I have non-human identities with more permissions than needed? Uh, are they not in a secure location and so forth. And then we're doing abnormal behaviors, which means, let's say someone from North Korea is using your non-human identity to access your environment.
That will be probably no, you know, an abnormal behavior, little risky, little risky, something you would like to prevent, we're gonna prevent it for you. Uh, we're gonna move them to a secure location. And basically, once they're no longer in news, we're gonna offboard them for you.
Is it also part of shutting some of them down if they are, uh, insecure or also not really serving the right purpose for the business? Yes. So usually when we're entering an environment, when we are starting to onboard and through, we think that about 40% out of all non identities are no longer renewed.
They are enabled 40%. Wow. Very enabled.
Someone can use them, but no one is using them anymore. Idle, stale. Um, and yeah, that's, that means that we are disabling all of them, deleting them and basically decreasing their tax surface by 40%.
Wow. That's a, that's a big number. Almost half.
It's a big number during Like The first week Necessary. Unnecessary and opening exposure to risks for, right. What problem do companies come to you with?
I imagine they don't know what they don't know Exactly. So what's the customer conversation like when you're talking with a prospect, they say, it's sick, we've got a problem, but we Don't even know what it's Yeah. So like everybody has is aware, everybody are aware about the problem.
They know developers are creating, uh, permissions and non-human identities to access databases and storage accounts and other resources. They know it's being done within the organization. And they would like a way in order to control what Yeah.
Control it. Yeah. Right.
Control govern what those developers are doing. Uh, that's the main problem. Security wants to govern any identity that can access their environment and data.
And is it developers that are creating these or are there other users within organizations that are also usually Developers develop? Um, yeah, like developers, DevOps, accessories and so forth. Those are the ones who are creating Them.
And their objective is what? So again, those non-human identities, like service Council and so forth, are being used, uh, by applications in order to authenticate against resources like database. So the objective is to enable the application to authenticate and connect to resources the application needs, like storage, Offloading that task from a developer, for example.
Correct. Yes. Managing that.
So what is a favorite customer story of yours, yours that you think really shines the light on why you co-founded Intro and, and really big, uh, you know, reductions in these NHI that you're helping cus companies achieve? What's your favorite customer story? Yeah, so actually just like a fake one month ago, um, DevOps left an organization, I left an organization and he mis downloaded all of those service accounts, all of those non identity.
Whoa. And that was picked up by intro, by our abnormal behaviors. Um, so we helped them to find everything he downloaded, all of the credentials, all of the non-human identities, rotate them, like replace their credentials and so forth.
So stuff like that that we keep seeing. Yeah. Really giving me and the team, you know, the, the energy boost we need to continue on.
And the confidence that, that you saw the right problem to solve for these organizations. Correct. And is this across, I imagine this is across industries including government?
Including government For sure. Every organization that have internal development have non-human identities. Yeah.
Yeah. Wow. And lots of them, It, I'm, uh, some of the stats you throughout were, were shocking that there's a 92 x multiplier NHI versus humans.
Right. And that 40% of them are either not usable or not necessary. So They're usable but not in use.
They're not in use. Yeah. IL okay.
Um, and also, you know, by IBM, cost of data breach, probably the most, um, um, the, the best reporting industry and Verizon report, the second best, both of them are saying that non-human identities is the second most frequent attack vector and the number one most costly attack in organization. Wow. So that's a real huge issue within, It's a huge issue for organizations.
Yeah. Wow. What are some of the things that, that folks here that are attending RSAC can see and learn at your booth?
I know you guys are exhibiting here. Yeah. Uh, they should definitely come to the booth and understand, are we able to find all of them are, we are managing the lifecycle of them, uh, reducing their permissions, rotating them, assigning ownership and and so forth.
They should definitely stop by and see how they can fully manage and solve the nonhuman identity problem. What's the timeframe? I should have asked you this earlier.
What's the timeframe? By the time intro gets into an account where you're finding all of these nhis and getting, giving the control back to the organization, is it, is this something that happens fairly quickly? Yeah, very quickly.
Usually the onboarding takes like 15 minutes. We are able to connect like that. Wow.
And then to scale for everything few hours. Okay. So the time to value is really short.
Correct. That's outstanding. Yeah.
What's next for the business? You two and a half years old? Uh, what are some of the things that we can expect on the horizon?
Any, anything on the roadmap you can share with us? Yeah, we'll continue to grow. We are gonna, um, keep creating and doing lots of partnerships.
So we already partners with, we, we partners with other great companies. So we're gonna continue to, uh, expand what we're able to do and who we can work with. Uh, hopefully we'll keep leading the market.
That's awesome. Itsc, thank you so much for joining me on Techstrong tv, talking about non-human identities, the challenges there, but the opportunities that Intro is delivering to your clients across industries. We appreciate your insights.
Thank Yeah. Thanks for having Me. All right.
For Itzik Alvas, I'm Lisa Martin. You're watching Techstrong tv. Live from R-S-A-R-S-A-C.
Stick around. We have a full day of coverage today, tomorrow, and Thursday. We'll be right back with our next guest.