Tag: Janani Nagarajan

  • Whisper Report: How can AI and behavioral analytics enhance identity security?

    Whisper Report: How can AI and behavioral analytics enhance identity security?

    Published to clients: February 17, 2026                                         ID: TBW2086

    Published to Whisper Club: February 17, 2026

    Analyst(s): Dr. Doreen Galli

    Abstract:

    “This Whisper Report investigates how AI and behavioral analytics enhances identity security. It highlights how organizations manage identity scale and emerging threats using behavioral baselines, anomaly detection, and contextual risk scoring. Researched at Identiverse held in Las Vegas, it incorporates quoted insights from Lumos’ Janani Nagarajan, GitGuardian’s Dwayne McDaniel, CyberSolve’s Ankush Kappor, Oasis’ Guy Feinberg, Simeio’s Octabio Lopez, Clarity Security’s James Davidson, Cubeless’ Treb Ryan, Apono’s Ofir Stein, Keeper Security’s Craig Lurey, Imprivata’s Diron Chain, and Panini’s Jim Harris.”

    As covered on Computer Talk Radio

    Target Audience Titles:

    • Chief Technology Officer, Chief Digital Officer,
    • Chief Data Officer, Chief Marketing Officer, Chief Content Officer
    • Head of AI and Machine Learning, Data Scientists
    • Product Managers, Content Managers

    Key Takeaways

    • AI is essential for managing identity scale and complexity in modern enterprises.
    • Behavioral analytics improves anomaly detection, risk scoring, and least‑privilege access decisions.
    • AI accelerates threat detection for human and machine identities at machine speed.

    How can AI and behavioral analytics enhance identity security?

    We took the most frequently asked and most urgent technology questions straight to the Technologists gathering at Identiverse 2025 held at Mandalay Bay in Las Vegas. This Whisper Report addresses the question regarding of how can AI and behavioral analytics enhance identity security?

    Motivation

    In short there are two big motivations driving the adoption of AI and behavioral analytics. First, as Lumos’ Janani Nagarajan reported, “It is really critical to know the difference that in identity where it becomes harder with tons and tons of applications tons and tons of identities including machine identities. Those people are accessing, in addition to the machines, they’re accessing the same apps and it becomes a tangled web of permissions entitlements. It really becomes complex to operate at human scale. You cannot throw in more people to solve this problem. And this is where AI and analytics plays a huge role in solving for identity.” In other words, the mere scale of the identity space in most organizations demands AI to effectively manage.

    The second reason to adoption AI and behavioral analytics in identity is because as Dwayne McDaniel of GitGuardian affirmed, “ ways to attack someone is to assume their identity and act on their behalf in a weird way this is especially true for machines.” Furthermore,  AI is being used against the identity space to steal someone’s identity – specifically as deep fakes. As CyberSolve’s Ankush Kappor argued, “AI is changing the scenario in a dramatic sense in two ways one the adversary now has a lot more options to play with deep fakes are a big problem where previously you could use facial parameters for authentication and so on so forth with deep fakes that is that is no longer the case so there’s a cause for concern right there that are existing control is now breaking down because of AI.” But facial IDs are not the only identity form let alone the only biometric identity under attack from AI. Kappor went on further to explain, “voice-based authentication is also under risk you’ve seen companies like ElevenLabs and the kind of  ease with which you can actually clone somebody’s voice a concern the last thing that I would like to really point out.”

    Example Use Cases in Identity

    Now that we understand why leveraging AI and behavioral analytics is important in the identity space, let’s dive into the use cases as depicted in Figure 1.

    1. Behavior Baselines

    A common starting point in behavioral analytics is to create an analyze a behavior graph. Oasis’ Guy Feinberg suggested, “We use AI to identify the baseline for the behavior of different identities so we can create this graph to show you the different anomalies. When there’s a threat actors utilizing this identity or a deviation from the business justification of the original identity the use that why we provision it for. AI is a way for us to identify faster with better accuracy uh and also it helps us kind of fingerprint different threat actors that target different type of non-human identities as their favorite factor.” This graph is then used as Simeio’s Octavio Lopez summarized, “What AI is going to be able to assist us practitioners with IM (Identity Management) is being able to make you get signal out of the noise that we see every day. Whether it’s like identities being able to figure out what roles they need to have or even just combing through all the statistical data that comes from all the systems ,AI is going to be really useful and being able to make our lives a lot easier.”

    2.      Unused Access

    One popular signal noise AI is great at identifying is that of unused access. Per Clarity Security’s James Davidson, “Governance is all about understanding who has access to what and is it appropriate the behavioral analytics is how that access that exists is being used so one of the mistakes people make is you know you have a company you’re operating all the time you’re creating new access to solve problems but you’re not keeping track of that access that you created and then you’re not keeping track of how that access is being used so we’ve started incorporating behavioral analytics things like have you even logged intothe software if you’re not logging in then maybe you don’t need it.” A useful example was provided by Lumos’ Janani Nagarajan. “’Hey I see sales have access to these CRM apps which is great but I see these three people not using them. Can you make sure that you put them back to the pool and maybe you know give them at least a warning that they’re not using it?’ That that means your least privilege access stays intact. The security risks are driven down but your productivity is not compromised.” Imagine that. In one step you not only improve your security by reducing unused access but potentially reduce your software licensing fees.

    3.      Unusual Access

    While it is important to identify unused access, unusual access is also critical to monitor. CyberSolve’s Ankush Kappor proposed, “looking in data looking at usage patterns of uh users to come up with risk scores and then determine which usage patterns are more risky for example if you normally access a certain application from certain locations in the US and one fine day connections start coming in you know uh from Asia that’ll trip up a few flags and then that analytics can prompt you for a higher level of authentication.”

    4.      User Experience

    One use case end users can really get behind was brought up by Treb Ryan of Cubeless. “What I think what we really use AI for is to come up with answers in integrations that they’re transparent to the user so when they get in it just works.” As Apono’s Ofir Stein expanded on, “few that we already did for example user experience we provide list privilege with AI agent that help you to get access to what you need only what you need in the platform this is actually take the least privilege approach into the day-to-day.” Finally for those not enjoying those pesky challenge questions, CyberSolve’s Ankush Kappor shares the AI modernized version. “previously systems were limited to a hard hard-coded set of questions that the user could answer for example to validate you know which school I went to and so on but if AI can be enriched with more aspects of my personality and privacy concerns are taken care of  – then there is a vast variety of questions that can be asked of me that probably only I can answer and answer in a certain way.”

    Fortunately, the benefits of monitoring identity and access information go beyond the identity space. In fact, as Keeper Security’s Craig Lurey contends what he appreciates most about AI in Identity is, “the ability to monitor and detect threats in regards to privilege sessions. So if you’re connecting to like a database or a Linux server or Windows server or something like that it’ll actually monitor the interactions.  It will look for any high-risk type of actions and look for any malicious activity and so it does this all zero knowledge. The customer posts what we call the keeper gateway and it allows them to monitor this activity. It’ll automatically lock and kill the session if it detects any suspicious activity and then the administrator can then go back and review what took place and there’s an AI analysis um that actually summarizes the whole transaction and lets them know what happened and it’s a really perfect application of AI for threat detection.” Identity is critical to enabling threat detection and an identity solution enhanced with behavioral data and analytics is just simply better.

    A common area of concern within enterprise security is always all those edge devices and endpoints. Fortunately, Imprivata’s Diron Chain has you covered. “We are able to take machine learning and AI functionality embedded within our system single sign on multifactor authentication and shared endpoint access to make sure that we understand who did what when on what machine. And the visibility in and around that allows the organization to get a lot smarter in terms of operational efficiency utilization. Taking analytics powered by AI to look for pattern anomalies. Ways in which they can analyze big data in a way that is actionable.”

    7.      Identity Theft

    Targeting the heart of the problem in identity theft, adding hehavioral AI can make all the difference. For human identity theft, Git Guardian’s Dwayne McDaniel offered up this viewpoint. “how do I know I can trust this person well if I haven’t described a specific set of things I’m allowed to do and I only ever do those things thumbs up i get a good score. If I all of a sudden start doing weird things it’s like wait a minute you don’t seem trustworthy anymore but that takes actual contextual analysis the fact I detect identity theft.” But detecting identity theft isn’t only for human identities, McDaniel went on to further explain the benefits to machine identity. “can this machine get into the system and retrieve this data under certain circumstances that’s completely normal operation how it’s going to do its work otherwise but now it’s starting to look up other database tables now it’s starting to do other things in that data source that it’s not supposed to do there’s no way a human can keep up with that level of analysis. AI on the other hand can at machine speed and alert someone to raise a flag say wait a minute something right something’s gone wrong in system so I actually see a pretty bright future for this particular use case with AI.” Please denote that he said at machine speed. As we covered in Conference Whispers: Black Hat 2019, threats can execute a complete ransomware attack for years in under 30 minutes. Expecting someone on call to get the alert, get online and stop something that fast is simply not reasonable.

    Final Word of Advice

    AI is a new fun tool that many like to find an excuse to use to play with it. Panini’s Jim Harris offered some very wise advice, “Don’t reinvent the wheel but how can we incorporate those solutions such as things that come from Fiserv and other companies that are in that space to leverage our capabilities with theirs to deliver a whole solution for a customer.” In other words – clients should schedule an inquiry, let’s check what is available on the market that fits your specific needs. You might just save yourself a lot of time and money.

    Related playlists & References

    1. Whisper Report: How can organizations implement zero-trust security without disrupting user experience?
    2. Conference Whispers: Identiverse 2025
    3. Conference Whispers: Identiverse
    4. ElevenLabs
    5. Conference Whispers: Black Hat 2019
    6. Whisper Report: How can organizations implement zero-trust security without disrupting user experience?
    7. Whisper Report: What are the latest advancements in decentralized identity and verifiable credentials?
    8. Whisper Report: How can AI and behavioral analytics enhance identity security?

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    Downloading, re-uploading, or redistributing this file is not permitted under any license.


    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, Whisper Club, and One Change a Month, Vegas Convention Library; Leading Professionals, Real Questions, Real Time, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: How can organizations implement zero-trust security without disrupting user experience?

    Whisper Report: How can organizations implement zero-trust security without disrupting user experience?

    Published to clients: July 23, 2025                               ID: TBW2084

    Published to Readers: July 24, 2025

    Published to Email Whispers: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    ABSTRACT:

    “Organizations can implement zero-trust security without disrupting user experience by prioritizing frictionless authentication, especially biometrics, and enforcing least-privilege access through dynamic policies. Understanding user context and behavior enables informed decisions that preserve continuity. Self-service access tools reduce delays, while streamlined verification processes minimize frustration. With thoughtful planning and clear communication, zero trust can enhance both security and usability, ensuring users access only what they need—when they need it—without unnecessary barriers. This report includes insights from executives and technologists at CyberSolve, Lumos, Imprivata, Simeio, Panani, Keyless, Oasis, Apono, Omada, and Cubeless, quoted throughout the discussion.”

    Target Audience Titles:

    • Chief Information Security Officer, Chief Technology Officer, Chief Digital Officer, Chief Information Officer
    • Chief Product Officer, Chief Experience Officer
    • IAM engineers, Security Architects, DevSecOps Engineers, UX Designers, IT Ops Managers, Application Security Architects

    Key Takeaways

    • Use biometric authentication to streamline access and reduce friction for users.
    • Apply least-privilege policies with dynamic adjustments to maintain secure, appropriate access.
    • Enable self-service access changes to minimize delays and improve user experience.
    • Understand user context and behavior to make informed, non-disruptive security decisions.

    How can organizations implement zero-trust security without disrupting user experience?

    We took the most frequently asked and most urgent technology questions straight to the Technologists gathering at Identiverse 2025 held at Mandalay Bay in Las Vegas. This Whisper Report addresses the question regarding how can organizations implement zero-trust security without disrupting user experience?

    What is the desired user experience?

    At the end of the day, the goal is, as Imprivata’s Diron Chai put it, “authentication and visibility and control to making sure that you know the right people are accessing the data whether remotely or within the organization in terms of their role and their functionality and then be a being able to understand who’s in the system when and why that all ladders up to a zero-trust architecture that we’re able to bring forth in a full architecture.”  Reaching this goal won’t be easy but as Simeio’s Octavio Lopez emphasized, “There’s a lot of communication that needs to happen and that’s something that we help a lot of our customers with.” A lot of communication and planning with the customers’ experience kept in mind. Here are five suggestions attendees at Identiverse offered also depicted in Figure 1.

    Five suggestions when implementing zero trust.
1. go frictionless, 
2. understand context
3. understand behavior
4. use self service
5 leverage dynamic policies

    1. Go Frictionless with Bio

    One common suggestions to deploy biometric based identity and access management solution. As Panani’s Jim Harris suggested, “make the authentication of your customer as frictionless as possible a one-time identity verification process establishes that customer in the future they present a simple credential match their biometric information to the information stored in the credential that they own and control making it a very frictionless fast way to authenticate with your customer.” And this is something Alex Jones from Keyless can also agree with! “going to pitch biometrics this is the fastest way to prove who you are effectively implementing zero trust.”

    2. Understand User Context

    Guy Feinberg at Oasis suggests that understanding the user context is the winning approach. He started by simply asking “Are you familiar with the scream test?” For those of you not familiar, one not uncommon method in IT to understand how a resource, in this case an identity, is used by disconnecting or unplugging the resource and see who screams. Feinberg went on to further explain, “when you want to understand what’s this identity is used for so what you do you decommission it and just see who’s at the open space is screaming that something is broke. We do we help you construct all the context around the consumption of that identity so you can see the full picture before you’re taking actions so you’ll have informed actions deciding do we need this type of identity now uh should we change the permission should we decommissioning it completely all without disrupting the workforce and making sure that business continuity stays on and nothing is disrupted aspects of this.”

    3. Understand User behaviour

    Beyond the context of what the user is using, Imprivata’s Diron Chai recommends also understanding the how and the when. “ Being able to inject simple multifactor authentication into the environment at the local level also being able to track the behavior of credentials of people accessing  like Windows endpoints as an example or mobile devices and be able to have the analytics to show utilization of the endpoint but also who what when was accessed within that session.”

    4. Use Self-Service

    To maintain the best user experience, Apono’s Ofir Stein recommends getting the human out of the loop. “you keep the user experience by allowing self-serve in your organization to provide access changes combine these two and you actually provide zero trust to all of the resources.”

    5. Leverage Dynamic Policies

    Omada’s Craig Ramsay highlighted the potential behind dynamic policies. “By using dynamic and continuous policies to make sure that their access is appropriate and it’s always at that level of least privilege and then it’s granted, when they join the organization, and as they move around the organization, and it stays appropriate.” It’s always nice when your privileges keep up with organizational changes – without human intervention or manual configuration.

    In Conclusion

    As Cubeless’ Treb Ryan concluded, “I find zero trust has greatly enhanced our user experiences and greatly made my job easier in the old days where there’s systems where you had to figure out which networks could connect or who would have access to what particular piece it was a nightmare.”

    Finally Lumos’s Janani Nagarajan reminded all, “not just in the networking layer not just in the app layer but a critical layer for us is identities because that’s where the workforce the humans the employees the contractors the vendors your customers are actually interacting with the apps.” Identities is the key to minimizing friction for the users in zero trust. If your organization is implementing a zero trust architecture and want to ensure you are on the right track, remember to book an inquiry. 

    Related playlists & References

    1. Whisper Report: How can organizations implement zero-trust security without disrupting user experience?
    2. Conference Whispers: Identiverse 2025
    3. Conference Whispers: Identiverse
    4. Conference Whispers: Identiverse 2024

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, Whisper Club, The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.