Video: The Privilege Spectrum: Securing Human, Non-Human, Cloud, and AI Identities | Duration: 1336s | Summary: The Privilege Spectrum: Securing Human, Non-Human, Cloud, and AI Identities | Chapters: Welcome & Introductions (2.48s), Rethinking Privileged Access (56.719997s), Privilege Spectrum Framework (291.24s), Practical Use Cases (594.57s), New Chapter (1240.6699s)
Transcript for "The Privilege Spectrum: Securing Human, Non-Human, Cloud, and AI Identities": Alrighty. Welcome, everyone. I'm just going to wait a few more moments while everyone is getting settled in. Alright. I'm going to go ahead and kick us off. I'm Lauren Rugge, Campaign Manager for PAM here at Saviynt. And I'm so excited to be joined today by Anupam Nandan, Senior Manager of Cybersecurity at EY. Welcome, Anupam. Yep. Thank you, Lauren, for having me. I'm looking forward for a great conversation here. And I have to call out that you were definitely destined for this career because PAM is in your first name, and I know that's not the first time you've heard that. I'm also happy to introduce the one and only Theo Walker, Director of Product Management for PAM here at Saviynt. Welcome. Thanks, Lauren. Happy to be here. Awesome. Let's get started. So for years, organizations have asked a simple question. Is this identity privileged? But today's environment looks very different. Human users, service accounts, cloud workloads, AI agents, and business users all hold different levels of privilege that can and do change over time. So maybe we are asking the wrong question. Today, we're going to explore a new one. Rather than is this identity privileged, the new question is how privileged is this identity. But first, we're going to take a look into why the binary model no longer works. So, Theo, what's what's changed? Why is the traditional definition of privileged access becoming obsolete? Yeah. There's a few different variables that have changed the dynamic of privilege. The first thing is the blurring of lines of access. So traditionally, there was sort of a small subset of, you know, IT or technical users that were assigned privilege for various privilege tasks. Today, there is a much wider spread of access that goes across the organization, workforce, IT. It goes across, all types of identities. And so with these lines blurred, it's it's more important to have a more detailed view on what exactly these entities are accessing and managing that effectively. The other impact in this is the introduction of AI. So with these autonomous agents, this provides a larger blast radius towards access across different applications, across different endpoints that may even be connected to each other. So with this broader access, it's really critical that, again, we understand in a more nuanced fashion where these identities are falling. Okay. Thank you for that. And what exactly does every identity is privileged actually mean? Yeah. So this essentially just means that all identities are privileged to some extent. Just depends on how much. And so we really want to be able to align them, across some sort of identifier to figure out, you know, how do we want to treat these identities going forward. Awesome. Alright. Now Anupam, what are you seeing in customer environments and why are organizations struggling to keep up? That's a good question, Lauren. Right? What we are seeing in the field is that, one, privilege and two has access to sensitive data. And that has been treated as two different groups and most companies are only watching for the first one. We are expecting to find risk concentrated in 50 admin accounts, everyone already monitored. Instead, it spreads across thousands of identities nobody flagged. An employee who can export customer data, build a pipeline that can push straight to production. An AI agent reading financial records to write a summary. None of these get level privileged today, but the access itself looks like just what PAM was built to control. Asking a yes or no question is missing most of the real risk. So modern enterprises are facing significant challenges in maintaining security for several reasons. The existing governance tools and audit structure remains tied to binary classification, lacking the native capability to evaluate risk risk as a fluid spectrum. This is compounded by fragmented ownership where identity management is siloed between IAM, DevOps business units developing AI and without oversight. Furthermore, a critical speed mismatch exists while new workloads are provisioned almost instantaneously, traditional access model and control framework requires months to update. And, hence, the identity lands landscape evolves faster than the governance can adapt. Alright. So thank you for that, Anupam. Pam. It is clear the binary model no longer works, and we need a different way to think about it. So, Theo, if privilege isn't binary, how should organizations think about privilege instead? Yeah. So we should really be looking at privilege going forward as a relationship between the targets that the identity is accessing and the job function of that identity and really creating some sort of formula on identifying, okay, with these two variables, where does this fall in terms of the blast radius? Where does this fall in terms of access risk? And so what we've just what we've established is the idea of the privilege spectrum. The privilege spectrum helps us identify these categories of sensitive assets, data, targets, as well as job functions and what the job functions we're likely gonna be doing with those targets. Once we have that, we're able to establish an identity on this privilege spectrum and then therefore enable certain things like policies by default, that that essentially, get triggered by where on the spectrum that entity falls. So we really believe that privilege is expanding across, as we mentioned before, the workforce. All identities are privileged to some extent, and so we really need to figure out this matrix of those variables that allow for us to assign a proper, more accurate, version of privilege. The other thing I'll mention on this is because this is a spectrum of privilege and functions change, targets change, access changes, this allows for the sliding of an identity up and down the privilege spectrum and then therefore applying the proper policies accordingly. Okay. So privilege isn't something an identity either has or doesn't have. It's something that exists on a spectrum as Theo mentioned and changes based on context. Anupam, let's take this from theory to reality. The privilege spectrum makes intuitive sense, but does it actually look like what does it actually look like in organizations you are working with every day? Let's run through a few questions here. So what's surprising you the most? So what surprised me most is that almost every time, it's the same thing. The Organizations do not actually know what and where their privileged accounts are. Then we run the discovery exercise, and find double, triple the accounts that showed up in their official in the inventory. The idea is that if you cannot see, you cannot secure, and most organizations are flying with a partial map. Absolutely. This is yeah. Alright. So where do organizations still think in binary? So the most important aspect is that organizations still think in binary privilege or non privilege. I see all see mostly at the two moments that matter most, onboarding and access review. When someone requests access, the system asks one question. Privilege? Yes or no? That follows the answer for that particular account forever. Review A reviewer at the same time, a manager gets a list and check checks a box and still needs to say yes or no. There is no room in either process to ask what privilege, how much pro privilege, just whether they exist. There's no control around that. Absolutely. Okay. That makes sense. Now which identity types create the biggest blind spots? The biggest blind spot, nonhuman identity hands down. SSH keys, service accounts, API keys, these get created to solve a problem quickly. They rarely expire. Nobody knows them once the original engineers leave, and and they almost never show up in the access review. A human account gets flagged if it's being dormant for ninety days. A service account can still an be untouched for years and nobody notices because nobody is watching watching it. Alright. And then the next question, Anupam, what patterns do you see across customers consistently? So the shape is always the same, a small well managed core of accounts, everybody agrees are privileged and much larger growing shadow population that nobody classified because it never got a formal review or because it looked low risk on paper. That shadow population is almost where the real risk exposure is sitting. Okay. And I know this is a really important question. Why prioritization matters here? So you cannot secure everything at the same standard at once. And trying trying to do it is why programs fail or stop. The organizations making progress aren't starting with "let's fix all privileged access", but they're ranking identity by actual impact and starting with the ones that they could do the most damage and then working down the spectrum from there. Okay. Thank you. So I think the big takeaway here is that privilege is often much broader than what shows up in the, you know, official inventory. And once you have that visibility, the next challenge is prioritization, understanding which identity carries the most risk and applying the right level of control. Alright. Now I'm going to pivot back to Theo, and we're going to take a look back at the privilege spectrum and go through a specific use case. Yeah. Absolutely. And before I jump into this, I just want to mention really quickly to Anupam's point. One of the great things about discovery outcomes is typically we were applying binary assignment to privileged identities, which wouldn't allow for that, more detailed ranking of prioritization. And so now that we have a more specific way of looking at this, we can more accurately rank priority in terms of of onboarding and setup, which I think is really great. So if we look at some use cases here, like, let's look at the privilege spectrum in a practical sense. What does this look like when you have real identities? Real. So first example would be, a dynamic access governance example where let's say we have an AI agent and that AI agent has read only access to a repository as an example. This may fall into a somewhat elevated, privilege location because it does have access to some important, organizational information. But over time, maybe that agent starts to to gain some more visibility as software developers use this agent in a more comprehensive sense. So for example, it gets integrated to the CI/CD pipeline and maybe that moves it up to a slightly more elevated privilege. This would mean that we would have a, An example of how to solve this would be have a baseline policy for an elevated identity that requires that credential or whatever the access method to be managed directly within your PAM solution. Right? Once Over time, once that does develops some additional access, for example, and add admin rights to the DevOps platform as an example, maybe that moves into slightly above a privileged identity. And then at that point, the policy may say, hey. We really need to apply some just in time or ephemeral access policies to this agent and apply some more PAM concepts where we traditionally would not. So this is an example of how an identity, in this case, an AI identity sort of moves up the spectrum over time as additional, permissions are given. This is also an example in a real life world today, how we see it, where identities are getting a bigger and bigger blaster radius blast radius as time goes on, oftentimes without the oversight. The second scenario here, let's look at a more traditional human identity scenario. We have an IT administrator account as an example. This is going to be likely by default set on a more highly privileged location as this would have access, to perform admin activities on an endpoint as an example. Let's say this account is being accessed for off hours. This is a behavioral signal that can trigger back to your posture signals and say, hey. This is actually maybe a more critically privileged identity than it was previously because the behavior is changing. Right? That privilege assessment may increase maybe for a period of time, maybe forever, depending on what the policy is, and then that would apply certain controls. Maybe that requires additional level of monitoring, recording, a multi factor authentication, whatever it might be. But this is an example of how, you can have a sort of creeping governance scenario and then also a behavioral trigger that may increase the privilege of an identity. Awesome. Thank you, Theo. And in the theme of use cases, let's continue to make this even more tangible. We're going to walk through a few more different identities, put the privilege spectrum to the test, and talk about where each one might fall and why. So Anupam, in scenario one, we have Sally in HR operations. She has two different accounts, an admin account and has axe access to things like payroll, employee records, onboarding, offboarding, executive compensation workflows, as well as a daily account with her access to training systems, hiring platforms, company social events. Can you talk us through a little bit how you would see her, landing on the privilege spectrum? Yeah. So Sally is a privileged user. There's no doubt about it. Right? I mean, her infrastructure admin account clearly represents traditional technical privilege. Her HR responsibility also gives her significant business privilege through across payroll, employee records, off boarding, onboarding, of of the and compensation data. The impact of misusing error or compromise of these permissions could result in financial loss, privacy violations, regulatory issues, and reputational damage. The the business risk Sally represents extends beyond system administrator. HR access could enable unauthorized change to employee records, payroll manipulation. In many organizations, these business functions can be critical or even more critical than traditional infrastructure administrator. Business privilege deserves the same level of security as infrastructure because risk should be measured by the potential business impact to access, not just by technical permission. The privilege spectrum from helps to simplify security standards by treating privilege as a as a continuum rather than a binary concept. Instead of focusing only on IT, administrator organizations can consist consistently identify, classify, monitor, and protect. For Sally here, the just in time and ephemeral dynamic elevation is is going to be very important. This approach will provide a uniform frame framework for managing both business and technical privilege while reducing security and compliance risk. Awesome. Thank you. Okay. Let's jump into another scenario. Theo, we have an AI campaign agent, and they are accessing things like Salesforce, PII, budget documentation, opportunity data, creating an updates of around CRM records. Where would they land on the the spectrum here? Yeah. So this is an interesting one. Traditionally, a, you know, marketing identity may fall somewhere on the elevated category with some controls over the business applications they're accessing. So maybe something that's managed directly through the IDP as an example. But there's two variables here that's sort of bumping the privilege up of this identity. One is the access to PII. So that's something that's going to elevate it up to to privileged. And then the second thing is the fact that this is an AI agent. So there's a by default, we would consider this to be a higher blast radius and higher risk, so this may even bump slightly into a higher privileged, maybe between privileged and highly privileged on the spectrum and what this would mean is that we would want to put in controls that may exceed what would traditionally be set on a on a marketing campaign manager human identity, and so that could be some additional level of monitoring, that could be some additional level of authentication requirements to be able to access the said targets. We we likely will not trigger something like session recording as that can be tricky with PII, but you can see these examples of how PAM concepts could apply to this agent, as it starts to creep up the the spectrum. Absolutely. I love hearing about this because it's how it's impacting my world in day to day as well. Alright. So we're jumping into the third scenario here, the legacy service account. Theo, they have they're the domain admin. They have password rotation as manual, and it's an unknown owner. Where are they landing on the privilege spectrum here? Yeah. Maybe less of a mystery here, but I'll kind of speak into to the why. So this is most likely going to fall into that critically privileged section of the spectrum. Traditionally, these are those identities that you would or accounts and identities that you would assign as privileged. Right? And so in this case, on the spectrum, it's going to probably fall on the highest level mainly because of its administrative privileges, the fact that it does not have managed credentials on a sort of automated checkout based rotation, which should be a standard practice for an admin account. And then for the activities that this account would be doing, we will have to have, you know, the highest level of monitoring and visibility over this. So this would really fall on the the the top end of the spectrum. Alright. Thank you. So it's kind of clear we see a pattern there. None of these identities are simply privileged or not privileged. Each has a different level of privilege, risk, and blast radius, which is requiring controls that match that specific context. Alright. We started today's discussion with a simple question. Is this identity privileged? What we've heard today is that for modern enterprises, that's no longer the right question. So I'm going to ask each one of you for one takeaway. Theo, if there's one mindset shift you'd like security leaders to leave with today, what would it be? Yeah. I think Anupam actually said it best with the word continuum. You know, the spectrum concept is sort of leading to the idea of a continuum, but I think that also applies to how we should view, visibility into identities as a whole, specifically in the privileged world, which is this is not a one time discovery, assign it to something, and then apply those policies and then periodically evaluate. This is an active ongoing process where we're discovering, we're monitoring, we're updating the, the posture assignment here, the classification of privilege, and then therefore updating the policies constantly. We really wanna get to a place where access for privileged identities and access for all identities, as this applies to all, is really a more dynamic access decision rather than this, deterministic decision based on a one set policy. And so this is really an evolution that will come from a few different components. It's adopting a more mature, zero standing privilege policy across the organization, which is an ongoing effort from most organizations. It's applying this privilege spectrum concept and it's really working with your with your identity products to figure out, you know, how do we mature, in this journey to where we are making dynamic access decisions and really continuously monitoring the deep risk and blast radius of our identities. Okay. Thank you so much, Theo. That makes complete sense. What's And now moving on to Anupam. What's one practical step organizations can take to start moving in this direction? Yeah. I do agree with what Theo mentioned. Right? Discovery and and moving the capability dynamic. So the step one is to discovery. Go find every account service key, AI agent that touches your system. Most organizations have done this, have never done this fully, which is exactly why the spectrum feels theoretical to them. Once you see everything, you finally have something to actually place on it. Step two is dynamic. The spectrum only works if an identity can move along. So if you find everything through discovery, but still lock each identity into one fixed setting forever, you're back to the binary. Dynamic is what turned the spectrum into a from a concept into something that actually runs in day to day basis within enterprises. Thank you. So I think those are two great takeaways. First, obviously, change the mindset, then make that actionable. So if there's one question we hope you take back to your organization, it's not simply, is this identity privileged? It's, how privileged is it? And are we applying the right controls for that level of risk? If any of this resonated or you have initiatives underway around privileged access, zero standing privilege, nonhuman identities, or AI, we'd love to continue the conversation. Feel free to schedule some time with one of our experts. Theo, Anupam, thank you both so much for the conversation today, and thank you to everybody who joined us.