This episode examines securing agent-driven access to third-party applications in enterprise environments. Hasan Imam of Obsidian Security, chief executive officer, joins theCUBE Research hosts John Furrier and Dave Vellante to preview the NYSE Wired Cybersecurity series at Black Hat. Imam discusses evolving security challenges posed by autonomous agents and application-to-application integrations, and frames implications for enterprise security architecture and controls. The conversation addresses artificial intelligence, autonomous agents and non-human identity, and considers agent governance, runtime enforcement and prevention strategies.
Key takeaways include Obsidian Security's $85 million Series D at a $1.1 billion valuation and rapid customer growth. Imam reports that more than 40 customers pay over $1 million annually and that over 65% of enterprise customers permit agents to access third-party application data. They emphasize agent governance and real-time runtime enforcement to prevent destructive actions while theCUBE hosts underscore the urgent need for prevention and immediate mitigation. Watch to learn practical factors to consider for enterprise security teams in identity security, cloud security and application security when deploying autonomous agents and AI.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Zero Trust Cyber Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Zero Trust Cyber Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Zero Trust Cyber Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Zero Trust Cyber Series. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Hasan Imam, Obsidian Security
This episode examines securing agent-driven access to third-party applications in enterprise environments. Hasan Imam of Obsidian Security, chief executive officer, joins theCUBE Research hosts John Furrier and Dave Vellante to preview the NYSE Wired Cybersecurity series at Black Hat. Imam discusses evolving security challenges posed by autonomous agents and application-to-application integrations, and frames implications for enterprise security architecture and controls. The conversation addresses artificial intelligence, autonomous agents and non-human identity, and considers agent governance, runtime enforcement and prevention strategies.
Key takeaways include Obsidian Security's $85 million Series D at a $1.1 billion valuation and rapid customer growth. Imam reports that more than 40 customers pay over $1 million annually and that over 65% of enterprise customers permit agents to access third-party application data. They emphasize agent governance and real-time runtime enforcement to prevent destructive actions while theCUBE hosts underscore the urgent need for prevention and immediate mitigation. Watch to learn practical factors to consider for enterprise security teams in identity security, cloud security and application security when deploying autonomous agents and AI.
This episode examines securing agent-driven access to third-party applications in enterprise environments. Hasan Imam of Obsidian Security, chief executive officer, joins theCUBE Research hosts John Furrier and Dave Vellante to preview the NYSE Wired Cybersecurity series at Black Hat. Imam discusses evolving security challenges posed by autonomous agents and application-to-application integrations, and frames implications for enterprise security architecture and controls. The conversation addresses artificial intelligence, autonomous agents and non-human iden...Read more
exploreKeep Exploring
What explains the company's $85 million funding round at a $1.1 billion post-money valuation?add
What is agent governance, and how does Obsidian provide governance and runtime enforcement to prevent non-human agents from making destructive changes in third-party applications?add
How has the shift from human-to-application access to application-to-application integrations and agent-based access (using OAuth tokens and API keys) changed enterprise security needs, and why is securing human identity alone no longer sufficient?add
What went wrong in the recent agent-related breaches at OpenAI, Hugging Face, and Anthropic, and how should enterprise security adapt to prevent and mitigate such attacks?add
>> Thank you. and talks about security is a great preview and also get the news out there Hasan Imam is here CEO, Obsidian Security congratulations on funding 85 million dollars series d congratulations a lot of action take us through the news what's it all about who's involved what's the use of funds what are you gonna do
Hasan Imam
>> john thank you for having me uh
Hasan Imam
>> so the raise of 85 million dollars at
Hasan Imam
>> a post money of 1 .1 billion valuation is on the back of two things. One, we have seen incredible growth among our largest customers. More than 14 customers are paying us a million dollars per year. More than 100 customers are paying us more than 100k per year. But second is what we have seen over the last one year. What we have seen is agents accessing data inside third -party applications. Across our enterprise customers, more than 65 % of our enterprise customers have given agents access to data inside third -party applications. That's where we live. The second thing that we are seeing is, methods like models starting to identify vulnerabilities inside of third -party applications faster than ever. And I think both of those things are great accelerators of Obsidian. And this funding is to drive the R &D investment as well as go -to -market investment to drive growth on the back of these accelerators.
John Furrier
>> The thing about agents right now is that you're starting to see reasoning come in as a different mechanism with the AI. So they're certainly doing a lot of good for the cyber defense but as you mentioned they're running wild they're touching resources they're touching storage they're touching memory they're doing work this is a huge issue and they're going to have identities and what i love about what you guys are doing is you have the non -human identity piece of it which comes into play when you start thinking about agents of course the humans will drive the agents but they're going to be free to run around and do things and then also you have the inbound agents cross -platform coming in explain the nuance of this because i think this is at the heart of the cyber challenge here because you don't know what you're going to, you don't know, but you've got to reason on it, act on it. It sounds chaotic, but what's your strategy? What are you guys doing? this is going to be a big growth for you guys. How are you going to tackle that?
Hasan Imam
>> That's such a great question, right? So we talk a lot about agent governance. And what we mean by agent governance is how the agents are set up, who created the agents, what type of privileges these agents were given and what applications these agents have access to. But once the agents have access to the applications, then we are in runtime. The agents are interacting with a non -human identity inside the third -party application to be able to act on data. And this is where Obsidian is unique because once you give an agent the ability to modify data, an agent could add to the data, delete the data, write new data, delete a table, delete a database, delete an instance. The granularity of control required to be able to control what the agents can do inside a third-party application via non-human identity, that's where we shine. So our ability to not only provide governance of the agents but also runtime enforcement where we can prevent catastrophic actions inside third-party applications is a unique capability.
John Furrier
>> I want to dig into the runtime governance in a second because there's tension between the adoption and risk management. But first, answer the question that people might ask you or ask us, why is this a new category? What's different in security with this dynamic of agents touching resources? You were just explaining that. Explain why it's a new category. I'm sure you get this all the time, but why is it a new category?
Hasan Imam
>> Yeah. So think about it in the following way, right? So 30 years ago, when Salesforce got started, Workday got started, 15 years ago, Snowflake; Databricks got started. We really focused on how humans were accessing these applications. Companies like Okta figured out how to do identity and access management, Zscaler was doing zero trust into these applications. What happened is over the last 10 years, we started getting more value by connecting one application with another application. Salesforce connecting with Slack, Microsoft connecting with Salesforce. So you have all these applications talking to each other, but at any point in time in an enterprise, a large third -party application like Microsoft or Salesforce would be interacting with hundreds, if not thousands, of other third -party applications. So this already was a very significant problem in terms of how do you monitor the communication between two third -party applications that happens outside of your corporate perimeter. So it's not visible to Zscaler. It's not visible to Palo Alto Networks. Now what's happening is that that same mechanism is being utilized by agents, right? So agents are going through that same mechanism of OAuth token and API keys to access data inside of third -party applications. So we have a fundamental shift in terms of the access mechanism, the identity that's accessing it. And this is the reason we are looking at a problem that is far larger than securing the human identity.
John Furrier
>> it's so relevant because we grew up in the cloud era where APIs were great. You connect to an API, you're good. Now, with the rise of MCP, A2A, you're starting to see delegation and relationships between applications. You just pointed out multiple applications talking to each other. That's a deeper connection. Explain that innovation, adoption tension from the governance, because, we see success formula where governance has to get done. Great. But that's just the beginning. Talk about the tension between the adoption side of it and the risk management side, because I think this is where you guys are shining, where, hey, I could take a little bit of governance, nail that, but let's put it into action.
Hasan Imam
>> Yeah, I think that if you look at the large platforms, The reason they are platforms is because they're allowing thousands of applications to connect to them and pull data and get work done. And for an enterprise to drive productivity, they have to allow applications to talk to each other. They have to allow autonomous agents to access data inside third -party applications. So adoption is very significant and it is increasing, When we looked at data about a year ago, we saw that agentic access into third -party applications was growing at 16x year over year. Application to application integrations are growing at more than 2x year over year. But as a risk area, we have largely ignored it because we have been of the mindset that if we protect human access, we were protecting non -human access that is part and parcel to the application to application and agent to application. So yes, this is probably one of the largest blind spots for enterprises, the CISOs and the CIOs. And we find ourselves in the middle of solving for this. And we believe that this is going to be one of the more significant problems we will be solving in security over the next few years.
John Furrier
>> You mentioned the investment is going to go towards R&D. Do you envision a couple of years out that the same security and governance layers will look a lot like identity security but for non-human identity? What does that AI native architecture look like from your perspective?
Hasan Imam
>> Yeah, I don't think so. The reason I don't think so is because it is a lot easier to think about how we can centralize authentication of humans versus agents that are living in different departments, in different silos, different third party platforms. You could have local agents, you could have agents in the public cloud, right? So it's a lot more decentralized in nature. So I think that ultimately, we believe that you have to control what the agents can do inside of third-party applications. And so, our viewpoint is that there is going to be, you know, MCP servers and gateways that are being adopted by enterprises around the world. And we sit alongside those gateways and MCP servers and provide the intelligence to be able to ensure that we control what the agents can do inside of applications. Because, see, if we take the mechanism of like, we want to reduce agentic access, we want to reduce agentic privilege, that will fundamentally go against the goal of driving innovation and productivity, because you want to give agents access, you want to give agents privilege so that they can actually go figure things out. So if you're doing that, you have to control what the agents can do, from an action perspective, from a runtime perspective.
John Furrier
>> You know, we were joking on theCUBE a couple weeks ago around the cloud native world, observability. A lot of the same things are popping up, traceability, lineage. You're starting to see that kind of microservices -like thing, but it's different. And I want to ask you this because I think it's interesting. One narrative that's been popular or that's been evolving is, okay, you can have a lot of agents out there running around, but who's the root human behind it, right? So there seems to be a discussion around, okay those agents belong to him they belong to her this seems to be kind of like this human association so how do you view that because that ties the identity of a human to maybe a fleet of agents an agent a rogue agent a good agent so as you have these agents running around doing things doing work working in the same way people think which is we're seeing happen this seems to be like you own your agents and there's almost an accountability trace, right. Just putting that out there to get your thoughts, because this seems to be the formula for people, the way they're thinking about it, that you can use some identity management for the non-human machines or agents with the human.
Hasan Imam
>> Yeah. Yeah. No, that's a great question, John. So there's definitely human association, right? So you, I, we could be creating an agent and delegate, our privilege to the agent, right? That's one mode of how agents come about. But we also see workflows being created that are agentic workflows that are not necessarily tied to a particular agent, but were created to be able to solve for a particular problem within the enterprise. Then agents could be creating agents, right? So that's also possible. That's also very much possible. Actually, that's what we expect from autonomous agents. So it is important to understand human identity. So if you think about our roots, if you go back four or five years ago, we understand human identity inside third -party applications better than anybody else. It's actually interesting, right? I think that understanding laid the foundation for us to understand non -human identity. And the non -human identity became very relevant when we tried to solve the application -to -application problem. Now the combination of understanding of human identity and non -human identity and the mechanism for how applications talk to each other, which is the same mechanism agents would be using to talk to applications. The combination of these things gives us the moat to be able to solve this problem better than anybody else.
John Furrier
>> I love the problem you're solving around the applications because definitely that's happening more than we're seeing. You mentioned earlier runtime governance is a big part of what you guys do. that brings up to me i love that term because it's real time talk about the speed and velocity of what's changing how that's impacted your customer base obviously the Fortune 100 you have a lot of those customers big names what's it like for them what's their world like how is the speed and velocity of the needs of course the data volumes growing exponentially what's that look like? How has that changed?
Hasan Imam
>> Yeah, so if you just think about what happened with OpenAI Hugging Face or Anthropic agents going and breaching three enterprises, there are two things that are true. One is that there was a misconfiguration with the testing environment that allowed the agents to escape and then the second thing was the agent was able to leverage a weak password to be able to break into an enterprise so one these problems actually exist in third -party applications broadly when we look at our enterprise customers, what we have seen is that more than 75 % of customers have an admin that doesn't have MFA enabled. Almost all the customers will have some level of access to a third -party application. So these problems need to be resolved and our perspective is that we have to provide capabilities for enterprises to autonomously or in an agentic way go and address these things because these are such large -scale problems. Now, the second thing is that when we think about runtime, the concept of detection and response, where we or someone else detects something and then SOC responds to it and humans in the SOC go through the processes to be able to respond to it, that just doesn't work in the agentic world, right, so agents move in seconds maybe milliseconds right, so the way we are thinking about this problem is uh you know we in our space when we detect something we also provide the ability to do real -time mitigation as well as provide prevention capabilities but all of it is geared towards being able to solve these challenges or attacks that might get through the blast radius in seconds or minutes, not necessarily in hours. And I think you will see this trend across all different categories of security, which is the provider that detects it also has to resolve it and prevent it. You know, it is not going to be OK for it to be detected and then subsequently responded to by another party, hours or days later. That's just not an acceptable answer in security anymore.
John Furrier
>> Hasan, great to have you on. That's great insight. And that's the future. You got more integration, more capabilities, runtime, real time, got to go faster, do more. That's the new normal. Congratulations on the funding. Have a great Black Hat. Thanks for coming in from California to New York. Really appreciate it. And congratulations. We'll see you soon.
Hasan Imam
>> Thank you, John. Thank you for having me.
John Furrier
>> Okay. I'm John Furrier with theCUBE here at theCUBE's NYSE studio, the NYSE Wired program. This is a cybersecurity series. Agents will be doing a lot more. This is what's changing in the world. The script has flipped. It's almost inverted. Companies are doing more. Their categories are expanding. And again, new capabilities are emerging. The autonomous agents will be out there doing the work the way we think. And that's the future of AI. Thanks for watching. Thank you.