Artwork for podcast Security by Default
From Legacy to Modern PAM: A Migration Playbook with Erik Siebler
Episode 3831st August 2026 • Security by Default • Joseph Carson
00:00:00 00:47:32

Share Episode

Shownotes

Navigating the intricate landscape of identity security has evolved dramatically over the past two decades. Once characterized by a mere username and password, the contemporary environment demands that employees manage an astonishing array of digital identities—approximately one hundred per individual, not accounting for the emerging complexities introduced by agentic AI.

Joe Carson engages Erik Siebler, a seasoned professional with fifteen years of experience in Identity Governance Administration (IGA), Privileged Access Management (PAM), and authentication, to unravel the concept of 'legacy' within identity security. They delve into the defining attributes of legacy PAM systems, which are inherently infrastructure-bound, protocol-heavy, and tailored for a bygone era dominated by servers and routers. Erik elucidates the common pitfalls organizations encounter, particularly the tendency to misinterpret modern PAM solutions as mere expensive password managers, thus neglecting the essential integration of security into existing workflows to achieve frictionless access.

As the dialogue progresses, the focus shifts to the forefront of the identity security discussion: agentic AI. Erik articulates a nascent failure pattern in which one AI agent, denied access, may exploit another to circumvent restrictions, thereby complicating the landscape of privileged escalation. This new paradigm necessitates a reassessment of traditional security measures, as privilege escalation becomes increasingly relevant not only to attackers but also to the automated processes within organizations. The episode culminates in a practical migration playbook, emphasizing the importance of product selection, side-by-side rollouts, and key-user engagement, ultimately aiming to equip listeners with actionable insights for effectively transitioning from legacy PAM solutions to modern frameworks.

Takeaways:

  • The evolution of identity management has transitioned from simple usernames and passwords to managing nearly 100 digital identities per employee in modern organizations.
  • Legacy PAM systems are predominantly infrastructure-bound and protocol-heavy, failing to accommodate the needs of contemporary workflows and user experiences.
  • The advent of agentic AI introduces new challenges in privilege escalation, necessitating a reevaluation of traditional security measures and access controls.
  • Successful migration from legacy PAM systems requires a meticulous strategy, including product selection, user engagement, and the establishment of critical metrics to measure success.
  • Zero friction in user experience is as crucial as implementing zero trust principles, emphasizing seamless integration into existing workflows.
  • Organizations must acknowledge the technical debt associated with legacy systems and prioritize modernization to enable effective security in a hybrid and cloud-driven environment.

Transcripts

Speaker A:

Hello, everyone.

Speaker A:

Welcome back to another episode of the Security By Default podcast.

Speaker A:

I'm the host of the show, Joe Carson.

Speaker A:

It's a pleasure to be here and it's always my favorite time of my week, which is getting to have fun conversations with amazing people on really exciting topics.

Speaker A:

And the whole goal is to really allow us to kind of share our lessons and experience with you, to educate you, to help you on your path, on your future career, or to help you solve challenges that you might be having around the workplace and looking for solutions and ideas to really help make your world a similar, a safer place.

Speaker A:

So I'm really excited to welcome with an awesome person.

Speaker A:

So, Eric, welcome to the show.

Speaker A:

Hopefully, you know, I mean, if you can give the audience, because it's your first time on the episode, if you can give the audience a little bit of background, your origin story, how you got into the industry and a little bit about yourself.

Speaker B:

Yeah, perfect.

Speaker B:

Hi.

Speaker B:

Thank you for inviting me, Joe, and happy to talk with you about the topic today.

Speaker B:

And also to all the listeners out there, my name is Eric Siegpler, I'm based in Germany as well.

Speaker B:

Some of you might hear.

Speaker B:

Yeah.

Speaker B:

And I'm in for around 15 years in the industry now.

Speaker B:

I have an IT background, IT business systems.

Speaker B:

I did an MBA somewhere in the middle in cyber as well.

Speaker B:

But I was always focusing on digital identity after my major.

Speaker B:

So all of this in there, I started to do IGA projects, pen projects, authentication projects, and all the things which were coming over the last 15 years in this field.

Speaker B:

So, yeah, so I'm.

Speaker B:

That is my main thing.

Speaker A:

Yeah.

Speaker B:

And I also love to look into other security aspects.

Speaker B:

But yeah, my core knowledge is all.

Speaker A:

Around identity, which is today is probably one of the most important areas in security.

Speaker A:

In digitalization, it's always been sometimes a bit of how to get people productive and get them enabled and get them accessing the systems.

Speaker A:

That's been kind of the problem, that joiner lever mover kind of traditional scenario.

Speaker A:

But it has accelerated into so many different things, especially around APIs, cloud, mobile computing, you know, Internet services now all require some type of form of digital identity.

Speaker A:

So it has become one of the major pillars, I call it the connective tissue of our digital society.

Speaker A:

It's what brings everything together.

Speaker A:

Yeah.

Speaker B:

And with AI agents, that's just accelerating even more.

Speaker A:

Yeah, absolutely.

Speaker A:

I mean, I always remember, I always remember back when I started my career back in the early 90s.

Speaker A:

It shows how long I've been in the industry.

Speaker A:

Security then was, you know, identity was the key to the room and your username to log on to, whether it being a VMS system or basically a desktop or a unique system back in the day.

Speaker A:

And then of course accelerated.

Speaker A:

s, and then the early:

Speaker A:

If I fast forward to today, I'm looking at my system.

Speaker A:

I've probably got hundreds, if not thousand plus different identities.

Speaker A:

And that's all for APIs for different systems.

Speaker A:

I don't like to merge identities into having one identity that goes across so many systems.

Speaker A:

I prefer to keep every time I create a new account, I create a new identity, but I manage all of that.

Speaker A:

And it's challenging.

Speaker A:

But I think to your point, the acceleration, I think if we look at some of the analyst reports, the average identity now is in, you know, probably close to 100 per employee.

Speaker A:

You know, for every employee an organization has, it's upwards of close to a hundred identities.

Speaker A:

So I remember, you know, 10 years ago it was probably five to one, but with APIs, with agentic AI, with machine identities and service accounts that just exploded.

Speaker A:

So what do you think?

Speaker A:

One of the things that I'd like to, you know, because identity's evolved over the years and we've seen many evolutions and you know, one of the things is that organizations, you know, have a lot of legacy, they have a lot of old technology.

Speaker A:

What is for you when you see legacy, what is legacy in digital identity?

Speaker A:

What some of the ways that organization is it very much on premise, you know, traditional methods of managing the environments.

Speaker A:

Is that what you see as legacy?

Speaker B:

Yeah.

Speaker B:

So I'm.

Speaker A:

Yeah.

Speaker B:

I mean the identity world is broad.

Speaker B:

Yeah.

Speaker B:

But if you look into it, legacy is really all this, let's say fairly standard APIs use cases, you design it once and then.

Speaker B:

Yeah, it stays the same more or less for quite a while.

Speaker A:

Yeah.

Speaker B:

And then you might tweak it a bit on the way.

Speaker B:

Yeah, you have a typical joiner mover lever that works, maybe an internal and an external.

Speaker B:

That's it.

Speaker B:

That and around this you shaped all your processes, but that's not there anymore.

Speaker B:

Yeah, that's exactly as you said, it's evolving.

Speaker B:

You have far more machine to machine authentication which you want to secure, where you don't want to use just a client ID and secret or you want to have it also not just a hurdle.

Speaker B:

Yeah.

Speaker B:

I think legacy is you have a username, you have a password, you have A maybe mfa, but often a complicated one on the way.

Speaker B:

Nobody knows when to use it.

Speaker B:

You need to enter it at every step.

Speaker B:

Everyone is complaining.

Speaker B:

So at a certain time they will disable MFA.

Speaker B:

I mean that is what we did 10 years ago because people said it's not working.

Speaker B:

And I think that is a big shift also to legacy is how to make this modern and how to make it easy for the user so that they might not even see it in the background.

Speaker B:

And then they are more than happy to use it so that we got rid of just making more, more stuff somewhere in the middle, which they complain about, but rather making it smoother for them and at the same time more secure.

Speaker B:

Yeah, so I think in the authentication bits and pieces, that is for example passkeys or all these things around it, Federation passkeys when you're working on Windows, Windows, hello for business, they smile into the camera once and then all.

Speaker B:

I mean there's also outside of Windows you have this with Mac.

Speaker B:

You can use this also with Linux to a certain extent.

Speaker B:

Yeah.

Speaker B:

But just that they don't feel the authentication and authorization hurdle anymore.

Speaker B:

I think that is in the authentication context the move which we didn't do 10, 15 years ago, that was just about how do I get a plain MFA token somewhere and the process that they are compliant or that they, they are more secure.

Speaker B:

But everybody thought about is that also helping the end users?

Speaker B:

Yeah, I think that is an identity.

Speaker B:

Generally one of the big changes from legacy and towards where we moved as an industry.

Speaker A:

Yeah, absolutely.

Speaker A:

I always think, you know, when we look at those concepts is it's really getting to where it's frictionless.

Speaker A:

We talk about zero trust, but I always think about zero friction as one of the most important things is where security shouldn't be an additional check that a user has to do.

Speaker A:

It should be something the more we move it into the background, the more it is seamless, the more users want to use it because it takes away additional steps that we would otherwise have to do or have to remember.

Speaker A:

It makes their lives much easier.

Speaker A:

And that's.

Speaker A:

I think that's one of the very unique things about digital identity is that while, you know, it's.

Speaker A:

It's something that when you help users, you know, it's good for enabling them to be productive.

Speaker A:

But it's also something you can heavily use for security when you see, you know, I think one of the great things is that when users be able to use pass keys or biometrics types of authentication.

Speaker A:

What's some of the things, what's the challenges that prevents organizations from moving forward for those.

Speaker A:

And also legacy was very much focused on the human.

Speaker A:

It was human users.

Speaker B:

Exactly.

Speaker A:

It was for us types of people.

Speaker A:

And the big change has been where it was integrations, APIs, then application service accounts and of course agentic AI agents.

Speaker A:

What's some of the things that prevents organizations from moving forward that it really gives them challenges?

Speaker B:

Yeah.

Speaker B:

Often it's again, we cannot do it.

Speaker B:

Our technical debt, often a word which is often used now cannot support it.

Speaker B:

It's too complicated.

Speaker B:

I don't have budget for it and all these things.

Speaker B:

So we see it often especially in huge organizations.

Speaker B:

So I mainly work with huge organizations around the world, not smaller companies.

Speaker B:

So I always say a small client for me is a thousand plus identities.

Speaker B:

Yeah.

Speaker B:

And others might argue that's already huge.

Speaker B:

Yeah.

Speaker B:

So.

Speaker B:

But if you look at this kind of organizations, they had so many things growing over the years.

Speaker B:

And I think that's not just an identity problem.

Speaker B:

It's generally a problem for them, for modernization that all this legacy is still around.

Speaker B:

And then if you change something and it destroys a business critical process on the way, they will just turn it on again in the old way.

Speaker B:

The business must continue.

Speaker A:

And that backwards, backwards compatibility is always one of the.

Speaker A:

It's always one of the challenges because you know, you put so much effort into making it more secure and more modern.

Speaker A:

But to support the legacy, you had to support the old methods.

Speaker A:

And that's sometimes, you know, it kind of negates the purpose of actually installing in modern stuff.

Speaker B:

So.

Speaker B:

Yeah.

Speaker B:

And then, I mean, if we then look into the main topic of our talk today, privilege access management.

Speaker B:

So these identities which you should secure even more because I mean, we all know attackers try to get in there with the less effort.

Speaker B:

Yeah.

Speaker B:

And if they get a privileged account perfect.

Speaker B:

Then they don't need to hack anymore because they have everything after it.

Speaker B:

Yeah.

Speaker B:

And when we look into this.

Speaker B:

Yeah.

Speaker B:

It is there the same.

Speaker B:

Yeah.

Speaker B:

So it is.

Speaker A:

We saw it that some organizations, what I found is that, you know, when they're doing a digital identity project, I think sometimes it's more important to even sometimes start with the privileged accounts and the privileged identities because of, you know, the danger and the risk that they have have and making sure you've got the right security controls in place.

Speaker A:

Sometimes I also like to think that look at as what, you know, break it down into services.

Speaker A:

So let's do it end to end services.

Speaker A:

And then it becomes very repeatable.

Speaker A:

It makes it much easier to deploy because you're doing it end to end.

Speaker A:

What's some of the things, you know what, what, what's some of the controls that you would put in place for privileged accounts?

Speaker A:

What's, what's some of the protection that you recommend?

Speaker B:

And I mean privilege account when you started in the past, we all know it, we have seen it.

Speaker B:

You have somewhere a username and a password stored in a script somewhere and that was their privileged account management.

Speaker B:

Yeah, I think everyone who is long enough in the industry has been somewhere at a client in an organization where you saw such a kind of script, which is terrible at the end.

Speaker B:

No control, you cannot do anything.

Speaker B:

And then you might have maybe usernames or passwords which are even the same and stuff like this.

Speaker B:

Or you keep the default username password on routers and stuff like this.

Speaker B:

Yeah, I remember I have colleagues which are pen testers.

Speaker B:

They came into a network and on the main routers they just kept admin admin or whatever they.

Speaker B:

And what was there as a default?

Speaker B:

Yeah, and I mean if you see all of it, that was how it all started and then you realized you need to manage this properly.

Speaker B:

So.

Speaker B:

And I think one of the first things was discovery in the pen this world and then also password rotation traditional thing.

Speaker B:

That is how it all more or less started.

Speaker B:

Yeah.

Speaker B:

And this in a fairly on prem.

Speaker B:

Infrastructure heavy way.

Speaker B:

So I mean if, and that is if you look to legacy PEM or older pem, however you wanted to say it, it was very, very much infrastructure focused because that was still the core.

Speaker B:

You had servers, network switches, databases, all these things.

Speaker B:

And I think that is also a key when you're seeing putting controls in there and why it stopped.

Speaker B:

Then you come to a certain point where they cannot go forward anymore because they still tied around us.

Speaker B:

But the world has changed a lot over the last 15 years.

Speaker B:

We don't talk that often anymore about VMs or we talk about microservices.

Speaker B:

We said it APIs and we are not talking about agentic yet.

Speaker B:

So I mean this is really the thing.

Speaker B:

We started with discovery password rotation.

Speaker B:

Then at a certain time we started session recording to do audit controls.

Speaker B:

And then maybe if you wanted to do it more advanced, you started to do session stopping.

Speaker B:

If they didn't delete all or whatsoever.

Speaker B:

Yeah, what controls?

Speaker B:

And I think that is a little bit how it evolved.

Speaker B:

And the controls then started to come more and more and more, but always still focused on infrastructure at the beginning.

Speaker A:

Yeah, yeah, that's, I think that's, I think that's a big key thing.

Speaker A:

The Difference between modern and legacy is that legacy was very much that infra it was your, your, your on premise traditional legacy infrastructure.

Speaker A:

It was your routers, your switches, your servers that was around.

Speaker A:

It was firewall access.

Speaker A:

It was things that you could touch and physically control.

Speaker A:

And as you mentioned, as well as organizations, I think it was probably what kind of evolved was to move to bring your own device in cloud computing and especially I also found that a lot of those legacy infrastructures, they failed to be able to break down the end user or the business side of it as well.

Speaker A:

It was very much focused at IT infrastructure.

Speaker A:

They've already struggled to get beyond the IT infrastructure into the end user to get them.

Speaker A:

Sometimes they may have put a password manager there and just okay, let's stop and let's leave it at that.

Speaker A:

And rather than bringing it into vaulting and including it as part of the entire, you know, identity security kind of service.

Speaker A:

What's.

Speaker A:

So you know, if you're looking at that traditional side of things, what's some of the more modern, you know, what do you see as modern?

Speaker A:

What's you know, have you moved forward?

Speaker A:

Let's say an organization that's starting, let's say they have nothing today.

Speaker A:

Where would they start and what would modern look like?

Speaker A:

What would be some of the capabilities?

Speaker B:

Yeah, I mean if you look at the end PEM we put in place to secure their privileged accounts.

Speaker B:

But if you are completely starting from scratch, I think nobody has its own data center anymore, nobody has its own VMS anymore.

Speaker B:

They just take microservices from wherever or SaaS services, all of this.

Speaker B:

So we don't have this traditional layout more or less disappears with the big cloud computing or also if you use local providers.

Speaker B:

Yeah, I mean it starts to disappear more and more.

Speaker B:

And that is the key I think also for pem that also the identities, the privileged identities are changing.

Speaker B:

Yeah, you don't have necessarily an root user anymore since if you don't control the infrastructure layer anymore, a Linux system, then you don't have an root user anymore.

Speaker B:

Do you still have for your db, do you still have your DB Admin?

Speaker B:

Yeah, whichever DB you're using, maybe not even this anymore.

Speaker B:

And this is I think the big change so modern is probably the infrastructure disappeared or it got abstracted into a layer which you can now consume.

Speaker B:

Yeah, I just get a website, I just get a blob storage somewhere.

Speaker B:

I just get a network layer in the middle and the rest I don't care about it anymore, so to say.

Speaker B:

Yeah, so and I think that is a big difference from a legacy environment towards a modern.

Speaker B:

But, but I mean the reality is and that is all big organizations, especially it's hybrid, they have everything they still have on prem, they still have cloud and then it starts to get even more complex.

Speaker B:

So I think if you start greenfield with a new corporation which starts really with nothing, I think they have a far easier life than all the bigger organizations still having.

Speaker B:

All coming back to the initial thing technical debt which is often used now with all the things which are still flying around.

Speaker A:

Absolutely.

Speaker A:

So they have to have something that's a hybrid that works for still works for the old legacy IT infrastructure traditional.

Speaker A:

So there has to be some way to plug in a modern PAM solution into that old infrastructure.

Speaker A:

But at the same time meet the use cases for DevOps environments, for cloud SaaS applications and so forth.

Speaker A:

So it has to be able to handle all of those use cases.

Speaker A:

Is this where do you see PAM platforms as the kind of the way forward?

Speaker A:

Is that something or.

Speaker A:

Or PAM services?

Speaker A:

PAM is a service that would be consumed from the cloud.

Speaker A:

Would that be something that you would consider modern way that it can still plug it back into the legacy infrastructure?

Speaker B:

I mean there the answer is probably it depends if you just put in PEM solution in the cloud, is it in modern?

Speaker B:

Probably not.

Speaker B:

I mean it comes with the integrations and all the functionality which that solution brings.

Speaker B:

And then at the end for me it doesn't matter if you hosted SSS solution on prem or wheresoever.

Speaker B:

It's about the integrations with such a PEM solution which are important.

Speaker B:

Can you natively integrate?

Speaker B:

And that is I think a nice example which I had with a client once is when you look to the traditional way like a legacy PEM solution works, you natively integrated it in RTP or SSH and all those things and it didn't need to an administrator didn't necessarily see that the PEM solution was in the middle because it all worked with the native protocols.

Speaker B:

But if you look to the modern world and then you have now the new admin which for example, just on an AWS portal, an Azure portal or on a cloud portal, they just use the browser and they're an old fashioned legacy tool which goes via RDP or whatsoever that feels like a friction for them.

Speaker B:

So these administrators don't want to see a friction, they might want to use it as much as possible, as easy as possible.

Speaker B:

And if you then put something in the middle again like a legacy PEM solution and that's something I've seen often is you use a legacy PEM solution which is just using, let's say, infrastructure protocols to make it more easy or simplified towards a cloud portal, then these users might not feel that well, because they say, I cannot use my native browser experience.

Speaker B:

What are you doing now?

Speaker B:

And I want to log in, but I don't know the password of my administrative user on the cloud.

Speaker B:

So what they are then asking at a certain time is, can I just retrieve my password from a pen solution?

Speaker B:

Then they retrieve the password from the pen solution and enter it manually on their cloud provider and then they, they can use it natively.

Speaker B:

So then you use your PEM solution only as a really expensive password manager, so to say.

Speaker B:

Yeah.

Speaker B:

And you lose all the other controls.

Speaker B:

And so I think for me, legacy and modern PEM solution is not about a deployment method.

Speaker B:

It is for me about the integration such a solution can provide to make it for everyone easy to consume and again, as frictionless as possible.

Speaker B:

That's not just for the end users, but also for all the administrator.

Speaker B:

Yeah.

Speaker A:

So it sounds like one of the big key steps is one is discovery across all of the environments that you operate in.

Speaker A:

And then the second part is then interoperability integration between the existing infrastructure that you're using for the business, that it should fit seamlessly into that, into the native experience.

Speaker A:

So being able to find everything and be able to bring it in.

Speaker A:

I was using metaphor all in the past.

Speaker A:

Is that so it's like you're buying a car, but you don't want to have to build the roads just for that car.

Speaker A:

You want to be able to get a car that works in the existing roads that you drive on, rather than having to recreate everything again.

Speaker A:

And it should be also natively used to the cars that you're used to driving.

Speaker A:

It should fit into that same experience.

Speaker A:

What's the next steps?

Speaker A:

Integration.

Speaker A:

Interoperability is key, discovery is key.

Speaker A:

What would be the next phase after that?

Speaker A:

Is there things that, you know, there's a lot of regulations and compliance that does require.

Speaker A:

So, you know, auditability.

Speaker A:

Is that something that would also be important here?

Speaker B:

Yeah, and I think that is highly dependent on the industry.

Speaker B:

There are certain industries.

Speaker B:

I mean, if you look to finance and banking, that is one of the core features.

Speaker B:

Yeah.

Speaker B:

If someone does something on a payment terminal or where they can control certain transactions, I mean, their auditability is the key.

Speaker B:

I see certain industries where this might not be the.

Speaker B:

I mean, everyone wants it, but maybe to an extent where it's not so important.

Speaker B:

Yeah.

Speaker B:

Because they don't have this high pressure.

Speaker B:

So I think auditability is yes a key thing.

Speaker B:

It's also detection of course but to which extent that highly depends on the.

Speaker B:

On the industry.

Speaker B:

The clients is working.

Speaker B:

The clients are working on and yeah, there I see.

Speaker B:

I think finance is one of the more extreme parts.

Speaker B:

Yeah.

Speaker B:

Whereas maybe in certain trading it is not so important.

Speaker B:

I once had a client that was interesting.

Speaker B:

It was a retailer and we did their general retailing an improvement to secure all their processes in a retailer.

Speaker B:

And they said at the end our shops around the world or that was just around Germany, they are independent for up to two weeks.

Speaker B:

So even if my central service is down and all of it they can continue where is the need that I do so much more things to make it more secure and so on.

Speaker B:

Because they are independent.

Speaker B:

Yeah.

Speaker B:

They can continue working.

Speaker A:

So so kind of very unique use case, you know that it's almost like they can.

Speaker A:

They can operate offline for a period of time before it needs to be kind of resynced internally.

Speaker A:

So that.

Speaker A:

So you know I do see a lot of.

Speaker A:

Kind of some of the regulatory sides, you know the PCI is you know is definitely one on the.

Speaker A:

In the payments and financial side.

Speaker A:

And then there's you know the SOC1 and SOC2 which tend to also does have a lot of kind of push for commerce.

Speaker A:

So as we kind of you know trans.

Speaker A:

And let's talk about one big disruption we're seeing in the industry which is around AI and agentic AI.

Speaker A:

How is that changing how privileged access management works and how do you see it need to evolve?

Speaker A:

What's the changes that Pam needs to make to be able to operate in an agentic world.

Speaker B:

Yeah.

Speaker B:

And if I would have the perfect answer to this, I think I wouldn't sit here anymore and would be now a billionaire somewhere and sitting on an island because I like feel think that is everyone asking themselves right now.

Speaker A:

Yeah.

Speaker B:

And I think there again the as we see it generally in identity and in Pam with agentic.

Speaker B:

The speed of it.

Speaker B:

Yeah.

Speaker B:

The also the way how they operate is just extreme.

Speaker B:

Yeah.

Speaker B:

And I think the difference there especially in pen is when you see how agents are working and trying to abuse access from other agents which we never saw like this before.

Speaker B:

Yeah.

Speaker B:

Maybe from an attacker.

Speaker B:

Yes.

Speaker B:

They tried to go through the attack lane but when you now you had a service account and the service account had the.

Speaker B:

The proper access control in place and it called a service there and they got it denied and it was a.

Speaker B:

Denied done.

Speaker B:

Yeah.

Speaker B:

An agent doesn't stop there Anymore an agent then starts.

Speaker B:

Okay, but I know this other agent which might have the access.

Speaker B:

So I just try to force that this agent does what I wanted to do right now.

Speaker A:

Yeah.

Speaker B:

So when we now look into this, the privileged escalation.

Speaker B:

Yeah.

Speaker B:

As we said it from attackers is now not an attacker anymore.

Speaker B:

It might be your business process internally.

Speaker B:

Your machines which.

Speaker B:

Or doing this.

Speaker B:

Yeah.

Speaker B:

And this is I think a really big change in the, in the.

Speaker B:

For the PEM world.

Speaker B:

Besides all the other things with agentic.

Speaker B:

Yeah.

Speaker B:

How do you control this now?

Speaker A:

Yeah.

Speaker B:

If you have maybe your agent and you have it properly controlled, but it can reach out to others and they are just willingly say, oh yes my friend, I do this for you, then you need to see again, okay, where's now the control where stops.

Speaker B:

And I think that is for privilege.

Speaker B:

One of the main changes.

Speaker B:

Yeah.

Speaker B:

Besides all the other open points, what is the answer there?

Speaker B:

I don't know it yet.

Speaker A:

Yeah, it's like AI agents are now becoming, you know, really, really smart social engineer, social engineering, other agents.

Speaker A:

And I agree and one of you know is it's really important that kind of.

Speaker A:

We understand one is the discovery which becomes key in agenda GI as well because it's really hard to understand what's the context, what's the outcomes or what skill is that agent specifically, you know, know been asked to do and you know, does it have the ability to.

Speaker A:

To break out off the guardrails that's been put in place by going and you know, getting other agents that has the access to.

Speaker A:

To.

Speaker A:

To give it over just like you know, and attackers doing social engineering today.

Speaker A:

So it's going to be interesting to see.

Speaker A:

I think one of, one of the most important parts here is that when you're designing agentic AI in the context, you know, one is.

Speaker A:

Is getting what's, you know, how do we keep the human in the loop some way to make sure that we have the oversight.

Speaker A:

I think we're moving to.

Speaker A:

We are moving to an autonomous agent.

Speaker A:

But oversight becomes really important from a human aspect.

Speaker A:

The ability to stop it in its tracks, you know, like a halt button or a pause button so that the agent itself, you know, will not try to continue.

Speaker A:

And also making sure that it doesn't abuse.

Speaker A:

Because I think that's one of the big differences that humans, we do have ethical, you know, and questions.

Speaker A:

We have context where we can go and say is this the right thing to do?

Speaker A:

How can I do it in a more legal, proper business process way.

Speaker A:

But agents don't have those kind of Guidelines or ethics.

Speaker A:

They're task driven, they're outcome driven.

Speaker A:

I need to meet this goal, this is what I've been asked to do.

Speaker A:

And I'm going to try everything in my power that isn't on the exception list or exclusion list in order to achieve that.

Speaker A:

And that does create a lot of very disruptive challenges for the identity specifically PAM industry.

Speaker B:

Yeah.

Speaker B:

And that is then internally as a business.

Speaker B:

Yeah.

Speaker B:

There might be not external attackers involved yet because they just do it on their own and do then whatever they think they need to do.

Speaker B:

But if you then see that an external attacker might get the chance to leverage such an agency for his target to compromise you, to get data from you, whatever they wanted to do, it's getting even more complicated.

Speaker B:

Yeah.

Speaker B:

I mean there are so many texts which is not pen related necessarily.

Speaker B:

How we can still abuse agents or AI right now with white written commands and then PDF as a simple way which you might open or which you enter there or stuff that you put in an email.

Speaker B:

So it is a completely new way of, of I think that attackers are using it for offensive security to be faster, but also to leverage maybe existing agents inside an ecosystem to get to their target.

Speaker A:

Yeah, absolutely.

Speaker A:

And so if of an organization, let's say, you know, and you've, you've done many of these in the past, let's say they, they, they are stuck at that, you know, legacy PAM environment today and they do want to be able to manage more than just human users and they want to, you know, they have this hybrid environment already and they're trying to managing it with, you know, kind of in a legacy way.

Speaker A:

What's the path if they do want to migrate to something more modern, what's the first step?

Speaker A:

You know, what do you recommend?

Speaker A:

You know, let's say they're, they're looking at their business today.

Speaker A:

They're having less of their own internal IT infrastructure, but they're still stuck in a legacy PAM infrastructure and they want to leverage it more for, you know, SaaS, model for cloud, for workloads that's running in the cloud.

Speaker A:

They've got maybe hybrid workforce as well, working with a lot of third parties.

Speaker A:

What's the steps to migrate?

Speaker A:

What's some of the things that they need to start with?

Speaker B:

Yeah, so I think at first you need to see what is the product you wanted to use because you probably don't develop it on your own.

Speaker B:

I mean, with white coding many things are possible nowadays, but I wouldn't recommend this necessarily for such things.

Speaker B:

So I still see even with all of the changes happening there that you still use a product out there on the market.

Speaker B:

So I think the first, first thing is check what product you wanted to use, what product fulfills your requirements.

Speaker B:

Is it the same window?

Speaker B:

Is it another window that.

Speaker B:

It depends.

Speaker B:

So I think the product selection is one of the first steps you need to do based on your use cases you're seeing right now.

Speaker B:

And then if you found this out, it is a key to find either your own good people or a good partner supporting you on this journey to really make it as frictionless as possible.

Speaker B:

Because if you're touching a pencil system when you're then migrating it, it's often key processes, administrators everywhere in your business best case.

Speaker B:

So if you migrate something into a new solution, you also migrate a legacy into it because you want to have one new pillar which can do also all the old stuff, but also the new stuff.

Speaker B:

So you need to make sure that the migration happens as smoothly as possible.

Speaker B:

And for this you need to have a good team, either of your own people if, if inclined, or if a company has their own people or a good partner.

Speaker B:

I mean that's the business where I am in.

Speaker B:

But to find a way forward, plan it properly and then execute it.

Speaker B:

And I think the steps are there.

Speaker B:

Find your new product, get the new product in place, and then work on the migration plan, which is identifying your users, identifying your targets you're using and identifying the use cases and then plan how can I migrate them one to one or not do.

Speaker B:

I might maybe not need to migrate certain use cases because you're used in the legacy world.

Speaker B:

You worked on workarounds which you don't want to migrate necessarily.

Speaker B:

I think that's the most critical part in such a migration.

Speaker B:

Users are for short systems are for sure.

Speaker B:

That doesn't change much with a migration.

Speaker B:

But the use cases, because certain use cases might work far easier than in the past.

Speaker B:

Some other use cases you don't want to migrate anymore.

Speaker B:

And what I've also seen often in such migrations is that there were use cases you were not even aware as a central pen provider for your organization, because they were just used for something which then was never documented.

Speaker B:

And then they will come at a certain point when they are on the new solution saying oh, I cannot use it this way anymore.

Speaker B:

Do something.

Speaker B:

And then it starts to get interesting.

Speaker B:

So I think to sum it up, find a good product, get it up and then do the migration plan.

Speaker B:

Plan properly with all the parties involved.

Speaker B:

And at the end it's a.

Speaker B:

It can only Work well, if you have the product, they are the good product.

Speaker B:

You have the client fully dedicated to it and then either their own people or a partner.

Speaker B:

And this as a triangular force, so to say to get it forward and then push it forward.

Speaker B:

Yeah, because there will be obstacles on the venue.

Speaker B:

I mean we had.

Speaker B:

We did many migrations and, and we successfully finished all of them.

Speaker B:

But some were bumpy and others not so bumpy.

Speaker B:

So it's I think just a normal way.

Speaker A:

Yeah, absolutely.

Speaker A:

A lot of lessons along the way when you're doing the evaluation.

Speaker A:

What's some of the criteria they recommend from a product?

Speaker A:

Selection criteria.

Speaker A:

What's some of your due diligence that you can do beforehand choosing it for the client?

Speaker A:

What some of the criteria is.

Speaker A:

It's, you know, is it going to the analyst reports and just choosing the one to the most right or most top or is it looking at what's the kind of capabilities of the client as well?

Speaker A:

Do they have in.

Speaker A:

In house people that's understandable.

Speaker A:

Do they have something in place already?

Speaker A:

What's some of the kind of criteria that you look at when.

Speaker A:

During the selection phase.

Speaker B:

Yeah, and.

Speaker B:

And most.

Speaker B:

When we are, when we are supporting this.

Speaker B:

I mean often I personally still think it is analysts because they are supposed to be no neutral and have their framework.

Speaker B:

It's always easier to follow those.

Speaker B:

I mean if you have a good relationship.

Speaker B:

There's also my personal opinion which I share in sometimes.

Speaker B:

But I mean this is not something you can write in any report why you chose this and this product.

Speaker B:

Because Eric said it.

Speaker B:

Yeah.

Speaker B:

So I think the core is still that you have as qualitative as possible and things which are not just feelings.

Speaker A:

Yeah.

Speaker B:

So.

Speaker B:

And that I think analyst reports is always good to say.

Speaker B:

Look, they are mentioned there.

Speaker B:

These have already this and this reputation.

Speaker B:

Some analysts check them and yeah, please go forward with it.

Speaker B:

So in most cases I see it that we are choosing some top players or niche players out of an analyst report and then going forward with them having a long list, then starting to check them further and then going down to a short list and then you come to a project that is certain time.

Speaker B:

And then of course which is still a main thing often is then the price at the end.

Speaker B:

Yeah.

Speaker B:

So you can have the best product but if it is the most expensive and nobody can pay it, then often also clients will think at a certain time that's not working.

Speaker B:

Yeah.

Speaker A:

It has to support the business, not be the business.

Speaker B:

Yeah, exactly.

Speaker A:

Yeah.

Speaker A:

That's ultimately, ultimately gets to.

Speaker A:

Is.

Speaker A:

Is that, you know, in the end I also look at it as well as the, you know, complexity also becomes a massive factor and.

Speaker A:

And sometimes usability as well is that, you know.

Speaker A:

So I think it gets to your point is what's important as well is that it should be able to fit into the business's existing processes rather than change the business as well.

Speaker A:

You want people to be able to meet and become frictionless and move it into the background as much as possible.

Speaker A:

How important is it to involve the users, those who's going to be using the solution during that phase?

Speaker A:

When do you start engaging with them?

Speaker B:

So we recommend usually to start fairly early with key users so that you get at least during.

Speaker B:

Often depending on the size, you cannot do it in a big bang.

Speaker B:

Often you need to do it waived approach for such a migration from towards new.

Speaker B:

And we then see that we often start with maybe the IT department or the security department, the identity department.

Speaker B:

Depending how big the organization is.

Speaker B:

They can be the first testers, they understand it better.

Speaker B:

And then you go further.

Speaker B:

But then I think, think you cannot involve everyone.

Speaker B:

That's just not possible for most organizations.

Speaker B:

So you start with some key users and I think this is the key.

Speaker B:

Then coming to key users again to find the proper one which are covering most or the majority of your workforce which are using it or the user group and then getting their feedback and using it.

Speaker B:

But what you will also see, and I think that is normal with change, you will meet at a certain time users of your solution which just say I don't like it because it looks different.

Speaker B:

Different.

Speaker B:

Because with every change, even if you stay inside the same vendor and modernizing it to the latest stick.

Speaker B:

Yeah.

Speaker B:

The button might change from top right to bottom left or whatsoever.

Speaker B:

It might be only minor.

Speaker B:

And they will say there's the button not there anymore.

Speaker B:

I don't like it.

Speaker B:

Yeah, so you need to.

Speaker B:

I think then when you take their feedback, you also need to put a lot of work into the qualification.

Speaker B:

And is it an opinion?

Speaker B:

Is it really a breaking stuff which is there?

Speaker B:

And that is.

Speaker B:

I think the human factor in such a migration is still huge, but you cannot manage it one by one.

Speaker B:

So you need to start to formally find some proofs.

Speaker B:

And then at a certain time also start now we migrate it and let's see what comes afterwards.

Speaker A:

During this migration kind of phase, is both solutions operating side by side or is it like just that switch over, like you end the day you turned one off and you moved to the other.

Speaker A:

How long do you recommend keeping both side by side during that migration phase.

Speaker B:

Yeah.

Speaker B:

Often we have them side by side for a while because that comes back to the.

Speaker B:

We don't want to disrupt any services.

Speaker B:

That is for most of our clients.

Speaker B:

When you're changing something of a running system which is integrated in their day to day task think about they have whatever business they are in and they have a critical incident to whichever reason and they need to access their infrastructure, their database.

Speaker B:

They are.

Speaker B:

When we are looking more to the legacy things.

Speaker B:

Yeah.

Speaker B:

And they cannot access it because the PEM solution is not working in the new way.

Speaker B:

And then they might lose millions of dollars because they.

Speaker B:

Yeah.

Speaker B:

There's something happening in their business.

Speaker B:

Yeah.

Speaker B:

This cannot happen.

Speaker B:

So you need to make it as as easy as possible to.

Speaker B:

To that they don't.

Speaker B:

How shall I say it now the best way so that they are not interrupted in their daily processes.

Speaker B:

Yeah.

Speaker B:

Because for them it's just a change.

Speaker B:

They might not even understand why we are doing it.

Speaker B:

This in the.

Speaker B:

In the background.

Speaker B:

Yeah.

Speaker B:

So there we put it side by side and then we.

Speaker B:

We start to make it enable them with some.

Speaker B:

A lot of details around it.

Speaker B:

Yeah.

Speaker B:

That they can use both solutions at the same time.

Speaker B:

Then you can say please use the new solution.

Speaker B:

Start using it for your day to day task.

Speaker B:

If you come to a point where you cannot use it anymore because there is a bug or something works differently.

Speaker B:

You can always switch back to the old solution so that you can continue the way as you did before.

Speaker B:

That we don't break your business on that is the key.

Speaker B:

So have them side by side.

Speaker B:

Encourage them to use the new solution.

Speaker B:

If they found a bug, write it down, go immediately back to the old solution, continue your time and we will fix it with the next iteration.

Speaker B:

And I think this is the key to have both system at the same time.

Speaker B:

Let the users know they can still use the old way if it's not working.

Speaker B:

But also encourage them to use the new way because that is a downfall of this approach.

Speaker B:

Some might say.

Speaker B:

Say I don't care.

Speaker B:

I use just the old way.

Speaker B:

Further they will never finish this project.

Speaker B:

I keep on my old version and continue.

Speaker B:

So that is then the key make sure that they also move to it and that.

Speaker B:

Yeah.

Speaker A:

So.

Speaker A:

So what's.

Speaker A:

What's some of the key metrics that you.

Speaker A:

You.

Speaker A:

You know.

Speaker A:

Of course you know in that migration phase you're probably looking at you know activity from users login.

Speaker A:

You know that they're logging into the new solution and using it.

Speaker A:

If you find you know handful of users that have never logged in you probably that's a flag to, you know, that they either didn't get the communication or they're just stuck in a method of the old way.

Speaker A:

What's some of the key metrics that you look at?

Speaker A:

What would be some during a migration itself?

Speaker B:

Yeah, it's a usage of the platform.

Speaker B:

Yeah.

Speaker B:

So I mean generally I think as you said, I mean you can see how many connections, concurrent sessions are running, how many users are logging in.

Speaker B:

And I think that's the key and that should go upwards during a migration.

Speaker B:

You turn more waves on and then you should see more and more there and on the same time it should reduce all the other.

Speaker B:

The usage.

Speaker B:

Yeah.

Speaker B:

They might be less traffic going through the system, less session recordings and so on.

Speaker B:

And I think that is the key that you see that the usage goes up and the other side down.

Speaker B:

The thing is how granular you can do it depends how much time you have for it and how much people you have.

Speaker B:

But usually in such projects they are already fairly busy with actually migrating all of it.

Speaker B:

So they don't have the time to look into so many statistics and so many data into.

Speaker B:

So I think it's more a trend you're looking into and the feeling and then often also something's not changing who, who, who shouts out the loudest in the business of the, of a company.

Speaker B:

But there again that doesn't necessarily mean that's the most breaking buck on the way.

Speaker B:

Yeah.

Speaker B:

So that is then again the between metrics reality and normal politics in such organization find a way there and is there easy answer this metric again, unfortunately no.

Speaker B:

I think it's in a good feeling of, of the enterprise itself, of their client base together with the project team to find a good balance there.

Speaker B:

Yeah.

Speaker A:

To.

Speaker B:

To get it done.

Speaker B:

Yeah.

Speaker A:

And what's, how important is it, you know, for organizations today?

Speaker A:

Let's say, you know, they're looking at cloud and they're looking at gentic AI.

Speaker A:

How important is it for them to try to, you know, to move faster?

Speaker A:

Is it something that they can keep delaying and stay on legacy, you know, for the foreseeable future?

Speaker A:

Will they end up having to end up with two solutions to manage both?

Speaker A:

How important is it for them to make a decision, you know, to, to already start thinking about migrating?

Speaker A:

What would be the trigger?

Speaker B:

I think that is again twofold.

Speaker B:

I think the experts inside organizations see it and they want to move it forward and they want to push it so they see the demand and they want to push it even further.

Speaker B:

I think right now, even in the let's say more worldwide economic situation which is not just growing everywhere where you see that they save more budgets and all this.

Speaker B:

The issue is often do they get the budget for such a project because you might get maybe savings on the way, but you always, always have an initial invest at the beginning.

Speaker B:

Yeah.

Speaker B:

Where you have maybe for short term two products running at the same time or you have a project costs at least for someone doing it.

Speaker B:

So you need to have an initial investment which you need to do.

Speaker B:

And getting the budget, that is still something I see often as a constraint.

Speaker B:

Even though maybe the people know that they need to do it.

Speaker B:

The pressure knows that the business knows it.

Speaker B:

But getting this into the proper business case inside the often IT department, I mean it's still the reality that security sits most of the time still in the IT department and not somewhere else.

Speaker B:

That is the biggest issue.

Speaker B:

They are stopping them from migrating it and then they might stuck with maybe some different solution.

Speaker B:

Or in the cloud they use security control.

Speaker B:

It's natively built into each cloud vendor, but it's not unified anymore.

Speaker B:

It's not a central dashboard anymore.

Speaker B:

So then you start to separate it again and then lose also certain capability to detect and properly manage it.

Speaker A:

Yeah, you end up with many silo solutions and no central visibility, which increases risk and it makes challenges.

Speaker A:

I think also some of the things as well is that I think in the world we live in today is that Pam has become somewhat democratized as well, is that if you go back five or 10 years ago, there may be only a few options that organizations could choose from.

Speaker A:

But today there's much more choices.

Speaker A:

So there's a lot more.

Speaker A:

And those more modern solutions have evolved a lot from what it was five, 10 years ago.

Speaker B:

Yeah, but also the old solution has.

Speaker B:

So I think it's an interesting mix right now.

Speaker A:

Yeah.

Speaker B:

Also old vendors have evolved, new came in.

Speaker B:

So it's interesting.

Speaker B:

And as you said, it's definitely far more options for people or for organizations to adapt whatever is the best for them.

Speaker B:

Yeah, and that's not the easy answer as usual.

Speaker B:

So you need to see where I'm loading.

Speaker B:

And I mean we see organizations when they are really just everything on one big vendor from a cloud platform, nothing else going back to this then maybe all the stuff inside this platform is enough.

Speaker B:

Yeah, but this is fairly little companies coming back to the initial question, greenfield companies versus all the hybrid environments where it's not like this.

Speaker B:

But if you start again just fresh, then you might not need need to think about dedicated tools.

Speaker B:

You just use what is in there but it is not.

Speaker B:

Yeah, that might be for a new startup case, but not for from enterprises.

Speaker B:

Yeah.

Speaker A:

So question.

Speaker A:

I mean this world moves so fast.

Speaker A:

Even I'm always looking for information, trying to stay up to date, looking at different talks and industry experts.

Speaker A:

How do you stay up to date?

Speaker A:

What's some of the resources that you use is there?

Speaker A:

You know, what's your method for learning and staying up to date with the latest?

Speaker B:

Yeah, that's as you said, the challenge right now in the information flood, you can get everywhere.

Speaker B:

I still use a couple of websites which you can use to get general input.

Speaker B:

And I still love to talk with other experts I know in the industry to see what they are doing, what the day recently go to conferences to listen to talks, podcasts, to see what it is.

Speaker B:

But I still also personally love to touch it on my own.

Speaker B:

Yeah, and nice slides is good, but I still love to have something running on my side, playing around with it, see how it's really working and then also feeling oh that's cool, this and now this and this or they look, what is this?

Speaker B:

So I think it is a keep of still reading but also keeping keep open and do something on your own.

Speaker B:

That's how I do it in the end.

Speaker B:

Yeah.

Speaker B:

So a mix out of everything, but still you will miss things.

Speaker B:

So the best is exchange with other experts, other folks listening to them, see what earned here, what they did.

Speaker B:

So podcasts like yours for example.

Speaker B:

Yeah.

Speaker B:

And I think that is really the key where you can do it the fastest.

Speaker A:

Yeah, absolutely.

Speaker A:

It's similar to my methods as well as you know, I try to stay connected with the community as much as possible, you know, with some of my peers like yourself and like Ian Glaser and Hutch and Alan.

Speaker A:

And there's so many amazing industry experts out there that have such a wealth of kind of industry experience and also kind of really can also visionaries as well.

Speaker A:

So going to conferences like the Kapucha Cool EIC or going to a denti verse really allows me to get a kind of really good overview into where the industry's going and what's the challenges and how some of the ideas and methods that they're solving those moving forward.

Speaker A:

So it was always great to stay connected.

Speaker A:

But I also, I love taking things for a test drive as well.

Speaker A:

I love getting my hands on things and you know, understanding and clicking around and trying to figure out, okay, this is how I did it before and what's changed and trying to uncover it, look in the background, you know, Tick the hood up and seeing.

Speaker A:

Okay, where has things changed and what protocols are being used.

Speaker B:

So where the magic happens?

Speaker B:

Is it real magic or is it the same?

Speaker A:

Is it, is it the same engine?

Speaker A:

Nothing's changed.

Speaker A:

You've got the latest car and you open up then you just got like a two, a two cylinder old diesel engine.

Speaker B:

Yeah, it's nothing with electrical whatsoever.

Speaker A:

Yeah.

Speaker A:

So yeah, you plug it in but you know, there's nothing, nothing happening at all of the.

Speaker A:

They're still using the old method.

Speaker A:

If the audience does have follow up questions, what's the best way for them to reach out, connect with you they do want to follow up with later?

Speaker B:

I think the easiest is go to LinkedIn.

Speaker B:

There you can find me and that is where you can reach out and then we can find proper channels afterwards.

Speaker B:

Fantastic.

Speaker B:

To have communications or go through you.

Speaker B:

Most of them might know you maybe or at least have contacts to you and go through.

Speaker B:

Jodi has also my contact details.

Speaker A:

Absolutely.

Speaker A:

We'll definitely make sure in the show notes I'll put a link to your LinkedIn as well so the audience can find you very easily.

Speaker A:

So Eric, it's been for fantastic having you on and it's always really great to hear some of the best practices and your lessons and experiences and really kind of where Pam is becoming from a legacy perspective, where it's going to in the future.

Speaker A:

Also some of the best practices and plans for migration.

Speaker A:

So definitely if you are planning a privilege access management or digital identity migration, definitely reach out to Eric.

Speaker A:

He can definitely take you on that journey to being successful and take you on the path to, to getting into modern solutions.

Speaker A:

So absolutely.

Speaker A:

So Eric, great having you on the show.

Speaker A:

So for everyone, this is the Security by Default podcast.

Speaker A:

I'm the host of the show, Joe Carson.

Speaker A:

Tune in every two weeks for latest episodes, new guests, new topics and the whole goal here is to really get clarity through the chaos in the world we live in and to help you on your career and journey in cybersecurity.

Speaker A:

So stay safe, take care and thank you and goodbye.

Links

Chapters

Video

More from YouTube