We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
In this interview from Black Hat 2026, Sinan Eren, co-founder and chief executive officer of Opnova, joins theCUBE's Krista Case to discuss how Opnova is closing the identity governance "last mile" gap, fresh off winning Black Hat's Startup Spotlight Competition. Eren explains how disconnected legacy applications, from AS/400 mainframes to green-screen terminals, have long evaded modern identity governance and administration platforms, leaving compliance gaps that traditionally took system integrators months and millions of dollars to close. He details how Op...Read more
exploreKeep Exploring
What customer challenge did you see that Opnova aims to address?add
What are the main drivers for adopting/implementing identity governance and administration (IGA) platforms, especially in financial services?add
What benefits does a governance platform that enforces quarterly user access reviews and strict SLAs for account creation, deletion, and entitlement changes provide?add
How do you handle onboarding applications that don't have existing connectors or integrations, and how long does that process take?add
>> Welcome back to theCUBE. This is our live coverage of Black Hat 2026. I'm Krista Case. We have a really exciting segment for you right now because we're sitting down with Sinan Eren, the founder and CEO of Opnova. And Sinan, Opnova just won the Black Hat Startup Spotlight Competition for both the US and the global. So congratulations and welcome to theCUBE.
Sinan Eren
>> Thank you, Krista.Pleased to be here.
Krista Case
>> Absolutely.
Sinan Eren
>> We're delighted. It was quite a surprise, but we're happy to take it.
Krista Case
>> Absolutely. It's a great day, huh?
Sinan Eren
>> Yeah, indeed.
Krista Case
>> Well, again, we're happy to sit down with you fresh off that. So thank you for taking the time. So we had a chance to catch up before we went live here. And I understand that Opnova is solving some longstanding kind of challenges with identity governance platforms. What I find interesting, Sinan, is this is a technology that's been around for a long time. but there's still a lot of applications that fall outside of the scope and the kind of oversight of traditional identity governance platforms. So maybe you can talk a little bit, start there, kind of what's the customer challenge that you saw there that you helped to create Opnova to address?
Sinan Eren
>> Yeah, this is also known as the last mile integration challenge or disconnected applications. a typical US bank for example will have hundreds if not thousands of applications. And some of these will be in -house, hybrid, legacy. Some of them will still be AS/400 mainframes and green screen, blue screen terminals. You don't get these granular APIs or modern protocols like SCIM, so it's not easy to integrate, right? Traditionally, you brought in a system integrator, a global system integrator, and then they will build custom connectors. It will take six months to onboard a single application. It's very costly, takes a lot of time. And by the time you are $3 million, $5 million out, you only covered 20, 30%. That's been the main challenge for customers.
Krista Case
>> That makes sense. You're addressing both the time and the cost component of integrating these applications into the identity governance fabric. So I guess, why has this remained such a persistent challenge that customers have struggled to address? So I understand how Opnova is addressing it, but why is it still a persistent challenge these days? Why haven't customers been able to already integrate these applications into those platforms?
Sinan Eren
>> Right, it is really challenging, technically challenging, but another thing is that these platforms might not always have the flexibility to, for example, navigate a complex interface, right? They might depend on flat files, they might depend on CSV, some sort of a file format that is designed for them to consume, and not all this long tail of applications support, they do not provide. and in financial services especially, the vendors themselves, the ISVs might not even care. Governance is not their concern. But any organization that might have failed an audit will know painfully well that this long tail of disconnected applications is where the real risk lies. It's been a challenging development over the last 15 plus years, but it still remains an unsolved problem. That's why we started Opnova.
Krista Case
>> That makes sense. And Sinan, you talked about risk, right? And so far, we've been talking a lot about costs and complexities, but naturally, there's a significant element of risk here if these applications exist outside of these identity governance platforms. What do you think has changed from a customer perspective, such that they may be less willing to accept that risk as a cost of doing business these days? I have to imagine you're getting a lot of momentum because you did just win this Startup Spotlight Competition here at Black Hat. But if you could elaborate on what's changing such that customers are recognizing that they need to take action.
Sinan Eren
>> That's right. a main driver is basically compliance, right? If you are a financial services, a public company that's governed by Sarbanes-Oxley, every quarter you need to do account recertification. you have to essentially have the business units and their managers approve or disapprove all these entitlements and permissions that's been longstanding with these employees, right? Before IGA platforms, it was quite the wild, wild west, but IGA platforms with the governance laws like SOX put in place, they started to go after this challenge. However, not being able to consume and connect and integrate with these applications kept it very limited, right? So if an organization fails an audit because of a disconnected application, that's the main driver. The second most important driver, SLAs. You are onboarding a new banker, a loan officer, it might take weeks if not months to get them all the applications and the permissions there. So main is to be compliant, to be able to do account certification in a timely, quarterly manner. Second is to have better efficiency ratios to deliver access on time.
Krista Case
>> That makes a lot of sense. And Sinan, I understand based on our conversation before we went on air that you're not asking customers to kind of rip and replace their existing tools and infrastructure, which I think is really important because obviously customers have already made those investments and it's already integrated into their processes. So can you talk to how you're complementary would be the first part, and then also maybe how you're integrating in a way that doesn't further add complexity to a cybersecurity tool chain that already has many tools and is admittedly a bit fragile.
Sinan Eren
>> That's right, that's right. Right, so that's one of the main reasons. There's so much tooling out there, there's so much fragmentation. We've been talking about platformization for many years now. From the first day, our thesis, we wrote a thesis document. Once we identified the problem, we're going to be a better together solution. We're not going to say, rip and replace. We're not saying that your IGA platform is from the on -prem era or from the cloud era. Now it's AI native. This is not our narrative. This is a typical Silicon Valley narrative. This is the old adage, this is how you build companies, for disruption, right? I think that playbook has run its course. We are here to complement and enhance the existing tooling that you have. And I think that's easier for CISOs, the owners of workforce identity, the program managers to understand and agree. And we get almost always a POC if we engage a customer and are able to tell our story. Almost always they get the case.
Krista Case
>> And is that sort of, I guess, the golden ticket there and why it's resonating with CISOs?
Sinan Eren
>> Yeah, lowering the TCO for this governance platform to meet the requirements to deliver what it was meant to do, right? To provide quarterly user access reviews, to have a strict SLA about account creation, deletion, entitlement addition and removal. These are under strict SLAs, and usually, disconnected applications fall outside of that. So, CISOs love it two ways. Brings down the TCO, brings them back into compliance, improves their SLA, and if the IT service desk team is involved, they love that the MTTR, meantime to resolution is also significantly improved through this.
Krista Case
>> Absolutely.And that time to implementation, I think is one important piece of the conversation. You were talking a few minutes ago, Sinan, about how you're potentially replacing some of this work that, a customer would typically have to go through a systems integrator and there's time and cost that's associated with that. I'm wondering what's changing in terms of why you're seeing customers can no longer accept that time and that cost. I'm assuming it's largely driven by the fact that they have to respond more quickly in this kind of agentic AI era that we've been hearing so much about at the show, but I'd love to get what you're hearing from customers.
Sinan Eren
>> That's right, actually I didn't answer that part of your question. Thanks for reminding me. So we're trying to build something that's self -serve. Essentially, we call it imitation learning, or learning from video demonstrations of a particular workflow. So let's say you don't have a connection, you don't have any integration to a particular financial app, right? What happens usually is that your IGA will open a ticket, and that ticket will be resolved by a service desk employee manually clicking through an admin interface, right? Or running something on the console, or some green screen application, we model by recording that entire process. From that we generate a standard operating procedure in plain language. And we support actually multiple different languages. We're also in the market in Japan. There's a Japanese version. Obviously you generate an English text. And then any IAM engineer practitioner can easily read, approve, and push it to production. As simple as that. What is typically a six-month process for a GSI to build a custom connector, it could be done under six hours. So we onboard applications on a daily basis, not monthly, not yearly.
Krista Case
>> That's fantastic.
Sinan Eren
>> That makes it super easy. UX, that's the answer. User experience, speed to delivery, that's why people want to give it a try.
Krista Case
>> Especially as security teams these days are trying to do so much more with less, they're trying to really stretch their time. I can imagine that really is going far. So we're hearing a lot about how vendors are integrating AI as part of their solutions. And what I'm trying to do is really peel the onion back to understand how AI is actually being implemented in security solutions, and then what are some of the tangible outcomes that customers are able to achieve as a result of that AI. So can you walk us through how you're using AI in your solution and how it's solving some of these issues that we've been talking about related to IGA that previously were very time intensive and expensive to address.
Sinan Eren
>> That's right, so we are what is called a computer use model specialist. These are essentially multimodal LLMs, right? They can look at screenshots, short and long form videos, and they can have screen understanding. They have a generalized understanding of what a UI looks like, what's a scroll bar, what's a button, where's a label, where do you type, where's an input field, and not just browsers. So that's one of our main differentiations we can do that for an AS/400 terminal, right? We're completely agnostic. If a human can interact with the application, we can learn from that interaction and repeat it. So our specialty in AI is computer-use AI. That's at the core of our agent. Of course, now, the moment you build this technology, the moment in the early days with the design partners you show it, the first question is like, oh, how about determinism? How about hallucinations? How about the exceptional unhappy paths from the typical execution, the parts that we haven't maybe demonstrated. So in order to solve that, even in the early days, we worked backwards from the objections that we were going to get, and we built a caching layer. That's kind of our secret sauce. So as long as the caching layer, meaning you're still on the happy path, we don't need to do an inference call, we don't need to invoke AI, right? Because we have seen this so many times, you repeat the same action. AI is very useful, inference is very useful, when there's a deviation from the happy path, that there's an exception, there's some sort of a slowdown or the application crashes, then you ask the model, okay, what's the next big step? And then you kind of bring it back to the happy path, guess what, and then you continue with the same recorded replay kind of execution. That's what we found out to be the most effective way of using AI.
Krista Case
>> And so there's this engagement between the human and the AI. I know we hear a lot about human in the loop.
Sinan Eren
>> That's the human in the loop controls, right. Yeah, absolutely.
Krista Case
>> So where do you think humans are going to add the most value and expertise in this process? As we think about maybe the next 12 months or so, what are some of the areas that humans are going to really bring to bear that expertise to complement?
Sinan Eren
>> The macro picture, the system level thinking is going to be critical, right? Trying to understand what's the right investment to make, where to start, what to prioritize. These are of course, very subjective organizational matters. There's a lot of tacit knowledge in every organization. So we are still going to have to bring it all together. AI cannot understand if there's not enough context. So we're still going to be in charge of how these things are designed, how do they operate, where to start, where to prioritize. So there's a lot of work to do. Of course, at the same time, we'll be chaperones. Whenever there's a human in the loop call, because hey, I lost my way, I'm out of the happy path, what's the next best step? So we'll be in line. and on the line and in the line some way, controlling these agents.
Krista Case
>> Absolutely.
Sinan Eren
>> Yeah.
Krista Case
>> So Sinan, I definitely understand, from an enterprise compliance and risk perspective, why it's important to get these applications underneath the identity governance umbrella. If we think about the security team, how does their day -to -day change, what benefits do they receive if they're able to use Opnova to then extend identity governance to some of these applications that have typically been left out.
Sinan Eren
>> I can give you an example from a banking customer. So in their case, they did not want to outsource these manual tickets that are generated by the governance system, because there's no connector, they're not able to automate it. So they were manual tickets. They had two options, either to do it themselves, basically go create accounts, delete accounts, disable, remove entitlements, and do of course the account certification process all manually, or outsource it to the business unit. That was the other option, right? Application owners. When they decided that it was really out of control, the CIO was very much against this, so guess what, the security team had to resolve tickets. They have a leaderboard about who resolves more tickets. It's not their job, it's not the most creative way of using their, the most efficient way of using their time. So we took that away, we took away 15 ,000 tickets in the first year, fully automated, what used to be manually done by the security team. It's a small team, even though at a larger bank setting. Yes. That's the biggest benefit to teams. 15 ,000. Take the mundane out of the equation.
Krista Case
>> Absolutely, and it's a great use for AI, going back to that piece of the conversation. So Sinan, as you mentioned, you won the Global Startup Spotlight Competition. I'm really interested in that competition because I feel like it's an indication of where we're heading, technologically speaking, as an industry. As you looked around at some of your peers in the Global Startup Spotlight Competition, were there any kind of common threads that you saw amongst the participants? Any kind of takeaways from the competition that we might think about, again, based on where we're heading as an industry with these new solutions that are being developed?
Sinan Eren
>> Yeah, I give them a ton of credit. They were all delightful, wonderful people, products, amazing teams behind these products and companies. What I noticed is that there was a deliberate attempt to build something AI -native, it's a loaded word. where everything is cloud native, now we're AI native. What I mean by that is that it's not a bolt-on. It's not a bot that answers questions from the stored documentation or the data sets. No, really, at the core, there's a use case that is supported and enhanced and made better by AI. So in our case, that's computer use, connecting and disconnecting applications. In some cases, it's deception. In some cases, it's about SOC workflows, just to learn them like we do and then repeat them once there's an incident, once there's an alert. So think of it as the reimagining of SOAR with AI at the core, right? So there's a lot of that on the floor, especially in the competition stage. I was really impressed. AI, not bolt-on, but really built around and at the core.
Krista Case
>> Yeah, it's the bolt-on versus AI native is really interesting. I guess, what are some of the true AI native capabilities that you think we're going to need as an industry over the next 12 months? Or maybe where are we going to start to see customers begin to adopt some of these AI native capabilities? Are there kind of pockets of the security stack that you think are most critical there?
Sinan Eren
>> The most obvious is AppSec. I mean, it's already, like, we're generating so much code now through vibe coding and other means. Of course, you know, the code review process, the audit, the pen test, it makes a ton of sense. I think that's an easy, that's a low-hanging fruit, right? Next, of course, is going to be, that's our category, is the repetitive, the mundane, whether these are tickets that are meant for service desk, but the security folks have to deal with that. These are patching, triaging misconfiguration vulnerabilities. All of those are definitely going to be the next phase of AI agents coming in and doing autonomous work with proper guardrails, with human in the loop. But yeah, we started with generating tons of code, so securing the same code with AI makes a ton of sense. That's phase one. Phase two, definitely work itself.
Krista Case
>> If we're generating code at machine speed, we need to protect it at machine speed too.
Sinan Eren
>> That's right.Makes a lot of sense.
Krista Case
>> Well Sinan, congratulations again to you and the Opnova team. Thank you so much for taking some time to sit down with us here at theCUBE. Again, hot off your victory here at the Global Startup Spotlight Competition at Black Hat. So thanks again.
Sinan Eren
>> Thank you, pleasure talking to you.
Krista Case
>> And thank you so much for joining. Stick around, we'll be back in just a few minutes with a couple more segments here live at Black Hat 2026.