Transcript
It simply cannot keep up with pervasive privileges and the sheer velocity of AI growth. This moment requires more than just an update. It requires a fundamental category shift. Hello, Impact. I am so happy to be with you guys today. It's amazing to be here in Austin and to see so many familiar faces. Thank you for spending time with us. Now, I want to start with something that on the surface feels very familiar, but when you really look at it, it has completely changed. And I'm talking about privilege. For a long time, we have thought about privilege in a very specific, very narrow way. In fact, privilege belonged to a small group of people, IT administrators, who held the keys to the kingdom. That was the original problem that Pam was built to solve, and CyberArk solved it better than anyone else. But here is the reality we have to face. That world no longer exists. In every modern enterprise, every single user can become privileged based on the data, the SaaS applications they can access. Privilege has been democratized, but not in a way that makes us safer. Today, your developers are pushing code directly into production. Your cloud operations, well, they are managing infrastructure from a single console. Your data scientists are running models against your company's most sensitive and proprietary customer data. And now, business users, just like me, we are living inside SaaS applications that holds the crown jewels of your information. These are all high-risk identities that can impact entire systems with a single keystroke. Yet, despite this reality, only 22% of organizations attribute privilege to every human identity. This is a massive disconnect. It means that for 78% of organizations, true identity security is only being applied to a tiny subset of users. Human privileges are pervasive. It is uncontrolled, and it is an open door for attackers. This disconnect creates what we call the privilege-exposure gap, where privilege lives today and where security is actually applied. Now, there are three primary reasons why this gap continues to widen. First, we are suffering from fragmented visibility. Traditional tools were built for a static world. They provide limited insight across modern workloads and cloud-native identities. This is what we call identity debt. It's hidden in plain sight, accumulating interest every day you don't address it. Second, we have a problem with persistent risk. We are still relying on static, always-on privileges. In a modern environment, standing privileges should be the exception, yet somehow they've become the default. This creates a permanent attack surface, allowing adversaries to exploit that standing access whenever they choose. And finally, there's complexity in our tools. Traditional systems require heavy, manual deployments that can slow down your teams. This forces business leaders to make an impossible choice between security and velocity. When you combine these factors, overprivileged and dormant access accumulate rapidly. The attacker can use these trusted paths without triggering alerts. Risk and cost compound over time, and this gap is only growing larger. So we have to be honest with ourselves as an industry. The existing model is broken. It simply cannot keep up with pervasive privileges and the sheer velocity of AI growth. This moment requires more than just an update. It requires a fundamental category shift. We have to redefine how we deliver privileged security across the entire enterprise. We cannot just iterate. For too long, the industry has accepted a two-tier system, high-grade security for the few and basic authentication for the many. But attackers don't care about our internal definitions. They care about access. Meeting this moment means moving beyond the silos of the past to build a system that treats every identity as a privileged identity by default. We must be willing to disrupt ourselves to meet the needs of the AI enterprise. And it is with that spirit that I am incredibly proud to introduce our next generation of human identity security, IDERA Modern Privilege Access Management. IDERA sets a new standard for PAM. By eliminating standing privileges and extending dynamic privilege controls to all users, we are democratizing privilege controls. And this will help ensure that all identities are secured, not just managed. We are building this on three core pillars, full discovery to eliminate blind spots, dynamic privilege access to extend controls to every identity and modern target, and radical simplicity to make security a force multiplier. Now, let's take a look at this first pillar of discovery. But this is not discovery as we have known it, not a static inventory, not a one-time scan. This is continuous AI-driven discovery. Understanding where privilege exists across the enterprise, across users, across cloud environments, across SaaS applications, but more importantly, understanding context. How these identities behave, what they access, and where they introduce risk. We are introducing the remediation agent where visibility finally meets automated action. The goal is to replace your blind spots with continuous visibility and AI-driven analytics that surface and remediate identity risk across the entire enterprise. This agent is a true game changer. It analyzes your specific tenant account onboarding patterns to predict and recommend the best controls for every discovered account. This is the find it, fix it capability the industry has been waiting for. The remediation agent acts as a force multiplier for your team. It can reduce your onboarding cycle time by up to 66%. We're talking about moving from a 21-day, manual, fragmented process down to just seven days. And we do this all with a human-in-the-loop philosophy. Every AI recommendation includes a competent score and the specific onboarding reasoning so your team remains in control while moving at light speed. Now to show you exactly how we turn visibility into action, let's look at how Ideara's AI remediation agent tackles the massive scale of unmanaged accounts across your enterprise. Every organization is buried under identity debt. For a security admin, the Ideara Risk Management Dashboard maps that debt, revealing a high-risk baseline of unmanaged admins and exposed secrets that grow faster than we can secure them. We can't fix it all at once, so we prioritize. By identifying our top five hotspots, we see the structural risks that matter most, like orphaned users with privileged access and compromised shared app credentials. But we don't stop at visibility. We use Cora AI to turn these insights into a plan. We simply ask Cora to secure our most privileged accounts, providing instant visibility into the exposure, and remediation is now automated for built-in and service accounts. The AI agent does the heavy lifting, and provides context and onboarding accounts in bulk. This is Pam at the speed of business. For personal privileged accounts, we remove the risk entirely. We move users from permanent standing access to zero standing privilege, so access only exists when the work is actually happening. The result? We've shifted the needle. Our risk score is trending down because we've neutralized the exposures that matter most. Moving from identity debt to a hardened posture. Finally, we ensure that debt doesn't crawl back. Continuous governance keeps the environment secure long after the initial cleanup. The shift from manual discovery to automated remediation, empowering you to not only find risk, but to fix it. Now, I love hearing from our customers and how the innovation we're driving is helping them every day. So let's take a listen to Brian. Identity is, I really think, the place to be, and you've gotta get that right to enable the business. How do we change that paradigm where we can reliably leverage AI to solve our problems at speed much, much faster? And again, some of the remediation solutions are some of the things I've been looking for. We're sort of at a balancing point. Too fast, and we're not gonna think things through all the way. Too slow, and the whole industry and the whole capability set that we're trying to secure is gonna get away from us. We need reliable, repeatable solutions that are at speed. I think more and more high-quality platform solutions are really important. Palo Alto has a lot of best of breed that they bring to the table. It's the same innovation we've counted on for many years. Going forward, as part of a very, very state-of-the-art Palo Alto network family. Now, from discovery, we move on to controls, and this is where the biggest shift happens. We move away from where identity is static and the idea that access should exist permanently, and towards a model to have access exist only when it's needed. This is dynamic privilege, and it's delivered through a combination of models. Zero standing privilege, just-in-time access, and contextual enforcement. Now, zero standing privilege means exactly what it sounds like. There are no permanent permissions, no standing access. Nothing exists unless it's required. Even if the compromise happens and the credential is taken over by an attacker, there is no entitlement for them to use and leverage laterally, and that changes everything. Because if permanent entitlement does not exist, it cannot be exploited. For scenarios where access is required temporarily, we use just-in-time access. Permissions are granted for a specific task, for a specific duration, and then removed immediately after. And the key here is updating and extending this model so that it's not just for traditional environments, it's for modern environments. That includes zero standing privilege and access for managed Kubernetes, and enter ID groups, helping customers bring dynamic privileges to systems that have become central to modern operations. It also means shifting PAM left with Terraform and CLI-based automations that allow customers to embed privilege controls into deployment workflows instead of layering them in after the fact. And privilege controls are not just for IT administrators anymore. We are extending true security to all human users. Whether it's a developer, a data scientist, a business user, we are providing seamless privilege session management for the web applications where your most sensitive data lives. We are shifting from a workforce state of static standing privilege to a secure dynamic state of just-in-time access. Now, to show you how this transformation impacts the daily experience of an employee, let's walk through a day in the life of a platform engineer operating in a world of zero standing privilege. Alex is a platform engineer, and his day begins from a trusted foundation. His workstation, secured by Cortex, Idera Endpoint Privilege Manager, and Prisma Secure Browser. If Cortex identifies a threat, it triggers EPM to impose a stricter policy posture to neutralize risk. Alex starts with zero standing privilege. Because of his role in the Project Phoenix production deployment, the platform has already paved the path for the infrastructure and applications he needs. This isn't manual policy creation. It's deployed as code via Terraform. Security is baked in the pipeline. This allows him to jump straight into the mission. First, he needs to push an updated Intune policy for devices that are part of the project. Alex gets scoped, just-in-time access to Intune, and his privileges expire at the end of the session. Next, Alex needs to monitor the health of Project Phoenix using ZSP for SaaS applications to access the Chronosphere dashboard. He identifies a latency alert on the production cluster. Alex has the necessary visibility to diagnose the root cause without standing privileges. To resolve the problem, he uses the IDsec CLI to gain native access to the production cluster to remediate it, all with zero standing privilege. Finally, the CISO's view. The command center is the high-definition proof of our zero-trust strategy. We see the full story, not just Alex's ZSP access, but the activity of our machine and AI identities as well. The Phoenix production rollout is a success. The audit trail is complete, and the attack surface has been reduced. By shifting from static permissions to dynamic session-based access, we've empowered Alex to move at the speed of business without leaving an open door for attackers. Now, just as importantly as what we do is how we deliver it. With Idera, we have completely reimagined the user experience through a unified command center. It provides real-time insights from workforce users and vendors to service accounts and AI agents. Now, it doesn't just show you identities. It shows you exactly how they connect to your systems, the privileges that they hold, and the risk they pose. But this is more than just a dashboard. It's an entirely new way of working. By implementing a unified policy model with guided, outcome-driven workflows, we've fundamentally reduced the overhead of operating PAM at scale through self-service deployment. From the command center, your security teams can finally monitor identity posture in real-time, enforce policy, and investigate incidents from a single, unified console. The PAM you know and love is finally ready for the future with Idera. Everything we've discussed today, from discovery, the dynamic access, the radical simplicity, it all leads to a very different outcome for your organization. First and foremost, you eliminate standing access by ensuring that no identity holds access longer than necessary, you remove the permanent attack surface that adversaries rely on. You reduce lateral movement. When sessions are contained, monitored, and bound by just-in-time controls, an attacker who gains a foothold has nowhere to go. But perhaps most importantly, you can extend privileged controls across the entire workforce. We are moving beyond the era where high-grade security was reserved for a small elite. Every single identity has access that matters. Because as we have seen, that is exactly where the risk lives. When you address that risk in a way that is dynamic, contextual, and simple to operate, you do more than just add a new tool. You fundamentally change the security posture of the entire organization. You move from a reactive state of identity debt to a proactive state of active security. Adira, Amon, and Pam enables us to close the exposure gap. This is the end of the always-on era and the beginning of a resilient AI enterprise.