DiscoverIdentity Decoded | The Identity Security Podcast
Identity Decoded | The Identity Security Podcast
Claim Ownership

Identity Decoded | The Identity Security Podcast

Author: Silverfort

Subscribed: 2Played: 9
Share

Description

The only podcast where identity and security finally sit down together for a conversation that’s long overdue. Defining what Identity Security should look like is harder than it sounds, so let’s skip the buzzwords and vendor pitches and get straight to honest conversations with people like you doing the work. From the role identity plays in incident response to programmatically getting rid of AD tech debt or finally achieving least privilege, expect candid conversations about what's actually working, what's broken, and what's next. Tune in as leaders from every discipline unpack the tensions, tradeoffs, and lessons learned from building Identity Security programs in the real world. A Silverfort production hosted by Roy Akerman and Rob Ainscough, new episodes drop every two weeks.

10 Episodes
Reverse
In this episode of Identity Decoded, recorded live at Identiverse, hosts Roy Akerman and Rob Ainscough sit down with George Roberts, Principal Architect for Identity and Access at McDonald's, to talk about Identity Security at a scale few practitioners ever encounter. George manages 2.2 million workforce identities across 95 markets worldwide. The conversation covers how McDonald's built a single source of truth without 1,500 separate HR integrations, why frontline workers get a printed, paper-based MFA sheet as their "least common denominator" security factor, and George's long-term vision for verifiable credentials and distributed identity. They also dig into why identity teams get looped into new technology initiatives too late, and why George doesn't think AI or continuous identity are overhyped, just under-answered. 🎧 Episode Highlights [01:42] George's role as principal architect for identity and access at McDonald's, and what it takes to manage a workforce identity environment this complex. [02:47] Why 93% of McDonald's workforce identity isn't McDonald's employees, it’s the franchise and licensee model behind the numbers. [04:19] Solving fragmentation without 1,500 separate HR integrations, using a workforce management platform as a practical single source of truth. [06:38] Balancing ease of use and security for frontline workers who can't be required to use a personal device for MFA. [10:21] The paper-based MFA solution: a printed sheet of codes as the "least common denominator" authentication factor, washing machines included. [14:17] The long-term vision: verifiable credentials and distributed identity, where every person owns and presents their own identity. [20:07] How a global training-app rollout became the business driver that finally got every market onto a single identity platform. [23:50] Why identity teams need to be looped in early on any new technology initiative, not two weeks before it goes live. [28:20] Rapid-fire: identity's biggest myth ("it's easy"), the leadership mistake of picking pure security or pure business enablement, and the hard truth that vendors build for perfect customers who don't really exist. [33:39] The trend George says isn't overhyped, just under-answered: AI and continuous identity, and why the industry hasn't caught up yet. 🔑 Key Takeaways: Takeaway 1: Identity Security at scale isn't a technology problem, it's an organizational one. McDonald's got 100% of its markets onto a single identity platform not by pitching security, but by attaching identity to a business initiative that leadership already wanted. Takeaway 2: Security and business enablement aren't competing goals. George describes his team as "50% security and protection, 50% business enablement," and says the biggest mistake leaders make is assuming identity is purely one or the other. Takeaway 3: Perfect solutions don't scale to imperfect environments. High-turnover frontline workforces, unmanaged personal devices, and thousands of connected applications mean elegant, modern identity solutions like FIDO keys often aren't practical. Sometimes the right answer really is paper. 👤 Guest Spotlight: George Roberts, Principal Architect for Identity and Access, McDonald's George Roberts leads strategy, technology, and architecture for workforce identity at McDonald's, along with the standards and policies for identity and access across the company. Over his eight years on the team, he's helped grow the company's global identity platform from roughly a third of McDonald's markets and 800,000 users to full coverage across 95 markets and 2.2 million workforce identities. George sits within McDonald's global cybersecurity organization, where he works to balance security requirements with the practical realities of a high-turnover, largely device-unmanaged frontline workforce. In this episode, he shares how McDonald's built that scale, and where he sees identity heading next. Stay connected https://www.silverfort.com https://www.linkedin.com/in/sirtwist https://www.linkedin.com/in/rob-ainscough https://www.linkedin.com/in/roy-akerman
In episode two of this two-part series of Identity Decoded, hosts Roy Akerman and Rob Ainscough continue their conversation with Aaron Turner — this time tracing a surprising parallel between drug cartels and ransomware groups. Aaron was assigned to the US Department of Justice after 9/11 and spent 18 months working with DEA Special Operations Division under Steve Murphy and Javier Peña — the real-life figures behind Netflix's Narcos. He breaks down why both types of criminal organizations are, at their core, transnational, economically rational actors that rely on stolen or assumed identities to operate. The conversation moves from Pablo Escobar's "plata o plomo" model of corrupting trust, to franchise-style scaling that lets sophisticated attackers hide inside the noise of less-skilled affiliates, to Aaron's later work at Idaho National Lab building some of the first cyber-physical attack simulators — and what that taught him about identity segmentation across IT and OT environments. 🎧 Episode Highlights ●[00:02:00] Aaron's near-miss legal career — dropping out of law school after witnessing partners commit fraud, and how that background led to a lawful-intercept role at Microsoft. ●[00:02:54] Post-9/11, Aaron is reassigned to the Department of Justice embedded with DEA Special Operations Division under Steve Murphy and Javier Peña. ●[00:04:13] Shared traits: both cartels and ransomware groups diversify revenue streams and act as rational, opportunistic economic actors. ●[00:04:42] "Plata o plomo" — Pablo Escobar's money-or-a-bullet model, and how both cartels and ransomware operators use stolen or assumed identities to run their operations. ●[00:07:45] The franchise model — how scaling out affiliates creates more noise for sophisticated attackers to hide inside, and why low-governance safe havens matter to both types of criminal enterprise. ●[00:11:06] Founding some of the first cyber-physical attack simulators at Idaho National Lab to explore the boundary between cyber and OT. Work that reinforced the importance of segmenting identities across IT/OT boundaries and exposed the rise of nation-state "bounty" incentives for crossing them. ●[00:15:58] How specialization inside criminal enterprises mirrors the way any growing company divides labor over time. ●[00:17:00] Why growing up in a high-trust, low-risk environment makes people more susceptible to phishing — and how lived experience shapes a defender's instincts. 🔑 Key Takeaways: ●Drug cartels and ransomware groups are structurally similar: both are transnational, economically rational actors that rely on stolen or assumed identities and operate out of low-governance jurisdictions where they're insulated from law enforcement. ●Franchise-style scaling doesn't just grow a criminal enterprise's revenue — it multiplies the noise defenders have to sift through, letting the most sophisticated actors hide their "sniper" attacks inside a flood of low-skill, low-success attempts. ●The most profitable position in either type of network isn't at the edges — it's whoever controls the "last mile." For the cartels, that was the Mexican plazas; for ransomware, it's whoever holds the decryption key. Disrupting that specific choke point matters more than chasing every actor in the chain. 👤 Guest Spotlight Aaron Turner, IANS Faculty Aaron Turner has spent over 30 years in the security industry, starting as an early penetration tester in the 1990s before joining Microsoft, where he spent eight years working across Active Directory, SQL Server, Windows Mobile, and Xbox Live. Early in his Microsoft career, he helped rebuild a national identity platform for Venezuela on NT4 — a project that led Bill Gates to personally recognize him with a "gold star" award in 1999, one of the company's most selective honors at the time. That recognition gave Aaron the freedom to work across some of Microsoft's most foundational identity and security projects during the internet's early enterprise era. He has since founded his own company and continues to research and speak on Identity Security, attacker tradecraft, and the long-term consequences of decisions made in Active Directory's earliest design days. Stay connected https://www.silverfort.com https://www.linkedin.com/in/aaronrturner https://www.linkedin.com/in/rob-ainscough https://www.linkedin.com/in/roy-akerman
In episode one of this two-part series of Identity Decoded, hosts Roy Akerman and Rob Ainscough sit down with Aaron Turner, who spent eight years at Microsoft during the founding of Active Directory — starting as a support engineer and later working on Active Directory, SQL Server, Windows Mobile, and Xbox Live. Aaron takes listeners back to the mid-'90s mindset that shaped Active Directory's design: a mission to "kill Novell" and sell more Windows and Office licenses, not to build a security boundary. The conversation traces how that original trade-off — deployment speed over security — led to decades of "identity debt," why LSASS (designed in 1998) has become a favorite target in modern ransomware-as-a-service kill chains, and what the NSA's declassified account of removing Russian actors from the US Treasury reveals about identity segmentation done right (and wrong). 🎧 Episode Highlights [00:02:00] Aaron's origin story: getting into computers after watching WarGames, early penetration testing, and landing a bilingual, Novell-experienced role at Microsoft. [00:04:00] The Venezuela story: building a countrywide identity platform on NT4, and how that trip led to Bill Gates personally awarding Aaron a "gold star" in 1999. [00:07:00] Why Active Directory's original mission statement was to "steal Novell's lunch money," not build a product with security in mind from the start — and the resulting tension between deployment speed and security. [00:11:00] The mismatch at the heart of Active Directory: enterprise-grade authentication, handed to teams without enterprise-grade security operations. [00:15:00] The economics of identity debt: roughly $250 billion spent on firewalls since 1999, versus an estimated 2% of that on identity. [00:18:48] The LSASS problem — why a process designed in 1998 to run for a week at most now caches years of credentials, and how that fuels modern ransomware-as-a-service kill chains. [00:22:20] Aaron's practical playbook: turn on success logging, visualize authentication traffic with tools like Gravwell, and eliminate legacy protocol dependencies (like clear-text LDAP) one server at a time. [00:24:25] The NSA's declassified account of removing Russian actors from the US Treasury — how attackers moved across five separate identity planes (on-prem AD, AD FS, Entra, Okta, Duo) to stay hidden, and why simplifying your identity stack matters more than adding another layer. 🔑 Key Takeaways: Takeaway 1: Active Directory was never designed as a security boundary — it was built to sell more Windows and Office licenses, and decades of security assumptions have been built on top of an infrastructure tool, not a security system. Takeaway 2: The industry's massive underinvestment in identity relative to firewalls (an estimated $250B vs. ~2% of that on identity) has created a structural "identity debt" that most enterprises can't simply modernize their way out of — many will have to invest in shoring up legacy infrastructure rather than fully replacing it. Takeaway 3: Adding more identity providers doesn't reduce risk if it adds more places for attackers to hide — as seen in the NSA's Treasury case study, simplifying and consolidating your identity stack is often more effective than layering on additional cloud identity tools. 👤 Guest Spotlight Aaron Turner, IANS Faculty Aaron Turner has spent over 30 years in the security industry, starting as an early penetration tester in the 1990s before joining Microsoft, where he spent eight years working across Active Directory, SQL Server, Windows Mobile, and Xbox Live. Early in his Microsoft career, he helped rebuild a national identity platform for Venezuela on NT4 — a project that led Bill Gates to personally recognize him with a "gold star" award in 1999, one of the company's most selective honors at the time. That recognition gave Aaron the freedom to work across some of Microsoft's most foundational identity and security projects during the internet's early enterprise era. He has since founded his own company and continues to research and speak on Identity Security, attacker tradecraft, and the long-term consequences of decisions made in Active Directory's earliest design days. Stay connected https://www.silverfort.com https://www.linkedin.com/in/aaronrturner https://www.linkedin.com/in/rob-ainscough https://www.linkedin.com/in/roy-akerman
In this episode of Identity Decoded, recorded live from Identiverse, hosts Roy and Rob sit down with Sean O'Dell to unpack one of the most talked-about — and least understood — challenges in Identity Security today: agentic identity. Sean shares how his background across healthcare, entertainment (including a stint reverse-engineering an authorization system at The Walt Disney Company), and engineering shaped his product-first approach to identity and access management. The conversation dives into why identity must be a "first directive" baked into agents at creation, the difference between agent identifiers and agent identities, the lack of standards across providers, and Sean's practical advice for security teams overwhelmed by agentic adoption: pick one team, one use case, and deliver one verified agentic identity before trying to scale. They also cover AI security hype, the legal and liability questions raised by LLM decision-making, and why "IGA is the answer to all your questions" might be identity's biggest myth. 🎧 Episode Highlights [01:29] Sean's background: from healthcare and retail to reverse-engineering an authorization system at The Walt Disney Company. [02:49] Why identity and access management is "the most intellectually complex space" and why companies increasingly want product-minded, business-fluent practitioners over narrow technical specialists. [05:42] Identity’s role in building the agentic AI revolution. [7:15] Sean's framework for why a stable identifier at birth matters even as an agent's role evolves. [12:15] The missing standard: fragmented approaches to agent identifiers (JWT, SPIFFE, WIMSE, or proprietary means) [20:10] Sean's practical starting point for overwhelmed teams: pick one team, one use case, and deliver one verified agentic identity before trying to scale. [32:23] Rapid-fire round: identity myths, leadership mistakes, hard truths, and the most overhyped trend in the space right now (spoiler: AI security). 🔑 Key Takeaways: ● Takeaway 1: Identity has to be designed into agents at the moment of creation. Provenance and verification are needed at birth. ● Takeaway 2: Don't try to solve agentic identity all at once. Pick one team and one use case, get a single verified agentic identity right, and use that pattern to scale. Trying to build a perfect, overarching framework up front leads to paralysis. ● Takeaway 3: The industry's biggest current gap isn't identifiers. It's authorization and consent: knowing that an agent is only calling what it's supposed to call, and who's liable when an LLM-driven decision goes wrong. 👤 Guest Spotlight: Sean O'Dell, Distinguished Engineer at CVS Health Sean O'Dell leads identity and access management, consumer identity, and agentic identity/access security at CVS Health. His path into identity spans healthcare, logistics, and engineering, with an early career highlight reverse-engineering an authorization system at The Walt Disney Company. Known for a product-first, business-fluent approach to IAM, Sean is a vocal advocate for baking identity into agentic systems from the moment of creation rather than retrofitting security after the fact. He's active in the Identity Underground community and speaks regularly at industry events. In this episode, he brings a practical take on how practitioners can start solving agentic identity today rather than waiting for perfect standards. Stay Connected: ● https://www.silverfort.com ●https://linkedin.com/in/rob-ainscough ● https://www.linkedin.com/in/roy-akerman
Eve Maler co-invented SAML, served as CTO of ForgeRock, and spent years as a Forrester security and risk analyst before founding Venn Factory, where she helps executive teams turn identity from hidden plumbing into a business advantage. Recorded live at Identiverse, this episode of Identity Decoded finds Eve joining Roy Akerman and Rob Ainscough to unpack the ideas behind her new book, Mastering Digital Identity: From Risk to Revenue. The conversation traces how identity work quietly grew into "an elaborate patchwork of workarounds," why treating identity like a product (not a ticket queue) raises the ceiling on what it can achieve, and why zero standing privilege is less about removing access than about making it just as seamless to grant. Eve introduces her four Ps framework, protection, personalization, payment, and people, plus the hidden fifth P of productivity, and makes the case for an "identity data balance sheet" that finally puts a value on the data identity teams protect. The discussion closes with a look ahead to agentic AI, board-level metrics like mean time to contain, and a rapid-fire round on Identity Security's most persistent myths. Key Topics 1. Why identity hits a ceiling when it's only managed as infrastructure, tickets, or incidents 2. How vaults quietly become "elaborate patchworks of workarounds," and what zero standing privilege really requires 3. Treating identity like a product: leadership alignment workshops, lighthouse customers, and building organizational FOMO 4. The Four Ps of identity, and the hidden fifth P nobody names 5. Metrics that win over the board: mean time to contain, accountable action results, and the identity data balance sheet 6. What agentic AI means for human-in-the-loop UX and "ask me" policies 🎧Episode Highlights [01:17]: Eve's path from co-inventing SAML to CTO of ForgeRock to founding Venn Factory [02:10]: Inside the new book: turning identity from risk into revenue [03:29]: The archeological dig — mapping where identity responsibility actually lives in organizations [07:11]: The vault confession — "I don't have a vault, I have an elaborate patchwork of workarounds" [09:22]: Zero standing privilege, Touch ID, and why easier access enables less access [13:01]: Human-in-the-loop as a UX challenge for agentic AI, and the "ask me" policy [16:17]: The hidden fifth P — productivity — and why it changes the board conversation [18:22]: Running a leadership alignment workshop from scratch [21:38]: Building FOMO with a lighthouse customer and "irresistible" identity strategy [26:05]: Designing metrics: mean time to contain and accountable action results for agentic failures [30:25]: The identity data balance sheet — putting a value on identity data [33:08]: The Four Ps: protection, personalization, payment, and people [35:09]: Rapid-fire round: identity myths, hard truths, and the most over-hyped term in the industry 🔑 Key Takeaways: ●Managing identity as infrastructure puts a ceiling on it. Treating identity purely as tickets or incidents caps how much value it can deliver, and the gap often shows up as poor user experience, what Eve calls a "UX vulnerability." Getting past that ceiling means adopting a product owner's mindset and aiming for "no compromises" outcomes rather than trade-offs between security and experience. ●Zero standing privilege isn't really about removing access, it's about granting it seamlessly. When access is hard to get, people build workarounds that quietly become permanent, which is how vaults turn into "elaborate patchworks." The bigger unlock is making access as fast and frictionless to grant as it is to revoke, the same dynamic that took phone-lock adoption from roughly 50% to 99% once Touch ID made unlocking effortless. ●Boards respond to metrics that pair risk with value, not process counts. Counting reviews or approvals proves activity, not security. Eve points to measures like mean time to contain for agentic failures and "accountable action results," alongside an "identity data balance sheet" that identifies who actually benefits from each piece of identity data, making it possible to argue for both new investment and cutting what nobody needs. ●There's a hidden fifth P behind identity's four Ps. Protection, personalization, payment, and people map to risk-facing, market-facing, transaction-facing, and human-facing needs, but there's an unnamed fifth P, productivity, that quietly ties them together. It's usually the human-facing part of identity, the one most under-invested in, that determines whether all the rest actually works. 👤 Guest Spotlight: Eve Maler Eve Maler is the founder and president of Venn Factory, where she helps executive teams turn digital identity from hidden plumbing into a business advantage, reducing fraud and account takeover risk, boosting signup and checkout conversion, accelerating delivery for product teams, and giving customers new ways to share and protect their personal data. Over the last thirty years she has co-developed standards-based frameworks used in business systems worldwide, including XML, SAML for outsourced authentication, and UMA for individual control over data sharing. She has provided expert testimony on API security to the US Health and Human Services agency and advised the UK Open Banking initiative on technology adoption. Drawing on her background as a former Forrester Research security and risk analyst and former CTO of ForgeRock, Eve helps organizations move beyond tool debates and reactive fixes to build irresistible identity strategies. She is the author of Mastering Digital Identity: From Risk to Revenue (April 2026), which reframes identity as a board-level business imperative and shows organizations how to design, own, and operationalize it as a profitable strategic capability. Stay Connected: ●https://www.silverfort.com ●https://linkedin.com/in/rob-ainscough ●https://www.linkedin.com/in/roy-akerman ●https://vennfactory.com
loading
Comments