Radio Logic

🔐 Identity used to sit behind a firewall. Now it IS the perimeter.

In this episode of Radio Logic, Anders Åskåsen sits down with Simon Moffett, founder and analyst at The CyberHut, to unpack one of the biggest hidden costs in enterprise tech: identity debt. 💸

They dig into why old identity choices come back to bite, how shadow IT became shadow identity, why moving to the cloud didn't fix the mess, and where smart CISOs are moving their budget. If your identity layer is slowing the business down, this one is for you. 🎧

What is Radio Logic?

Cybersecurity podcast Radio Logic delivers essential, no‑nonsense conversations with trusted experts on all things identity security. Hosted by Anders Askasen, SVP of Marketing at Radiant Logic and author of Cybersecurity Explained, the show draws on his 20+ years in security and digital identity to address today’s challenges.

Anders Askasen:

This is Radio Logic, the show about digital identities, the people behind it, the tech behind it. And in each episode, we'll cover what works, what doesn't, and what's next. Let's dig into it. Is Anders Ascason, and I'm the senior vice president of marketing at Radio Logic. And with me today, I got Simon Moffett from the CyberHut.

Anders Askasen:

Simon, tell the audience who you are.

Simon Moffatt:

Hi, Anders. My name is Simon Moffett, founder and analyst at the CyberHut. Been fortunate to be in identity twenty five years, I guess, probably not dissimilar to yourself. Lots of change in that time, and the CyberHuts role really is to try and analyze all of the exciting vendors in the identity space, do your analysis, advisory, research reports, and try and try and make sense of this wonderful identity world we live

Anders Askasen:

in. And you do put out some really good research that that at least benefit me in my role. I I started out my career at at a university, and we had essentially two different networks there. One was a Unix based system based on on Solaris, and the other one was a Windows environment with eDirectory and Novell. Okay.

Anders Askasen:

And we did a migration from essentially the old ETC pass WD file where the users was just in one file with the passwords at that time, right, into NIS to have some kind of distributed identity. Very early stuff. Right? Mhmm. And then Sun released what they called NIST plus, which was a a pain in the in the behind.

Anders Askasen:

And then LDAP came and tried to solve all the problems that NIST plus was supposed to solve, but it did it better and it was standardized and it got wider adoption. But then we realized that that didn't really fly together with the the Windows world and and e directory, and and we kinda needed some kind of synchronization. But, essentially, what we were building up at that time was was all these different identity silos that today we referred to as technical debt. Yeah. And I'm I'm sure you have similar experiences.

Simon Moffatt:

Absolutely. Look. I think it's it's part and parcel of of technology adoption, evolution, that that you you start off with something with good intentions, the best technology available, the best understanding of the problem that you want to fix at the time, which is often your problem knowledge, I guess, evolves over time as well. If you start to deploy something or you understand the problem space better, you probably wouldn't necessarily select a particular technology in hindsight. But all organisations really, they make the best choices at the right time.

Simon Moffatt:

But unfortunately, technology didn't always move at the same pace as the business or as the consuming sort of users. So there's always a disconnect between sort of business and the user evolution and the technology evolution. You deploy things that doesn't necessarily keep pace, you have to integrate them, change them, configure them. So there's always that disconnect. And as always, there's disruptive technology evolving, constantly evolving.

Simon Moffatt:

You mentioned sort of different ways of doing stuff there. It's a little bit like you buy a brand new house and you paint the walls and it's brilliant, but then somebody else moves into the house and they paint on top of your paint and this gloss goes on top of gloss and do some filler, and so the house evolves and you end up with all of these underlying foundations, and they don't always get removed. They stay there, and you end up building on top of them. Think that's it's typical for many. I think identity today, it's gone through so many different iterations and evolutions of sort of version three of IdentityNow, I don't know, maybe even version four with AgenTic and AI.

Simon Moffatt:

So you have that sort of isolated point product LDAP thing, and then we had a bit of integrated middleware in the sort of early 2000s with your big suite platforms. Get the CDs and you install a platform of stuff, and that would take you a few days, I guess, to do. And that didn't integrate very well. And now clearly cloud changed things around SaaS and how we consume technology in a different way. So identity is no different, really.

Simon Moffatt:

Gone through these evolutions. It's changing. The foundations are still there. Yes, legacy, maybe being more sympathetic, we can call them classic technologies perhaps, traditional technologies. History will probably show some of those technologies to be worse than others and maybe some better than others.

Simon Moffatt:

But I think it's part and parcel of of technology evolution. I think identity, I think because it has now become so important, so critical, the emphasis is upon it. So it amplifies the weaknesses and maybe some of the poor choices we made in the past.

Anders Askasen:

And it causes that operational drag. Right? Because it's hard to introduce new applications. It's hard to introduce and innovate in that climate. Plus all these different legacy technologies, some of them are not even maintained any longer.

Anders Askasen:

And and they caused that Absolutely. Increase in in risk surface that I know sees us for a fact that they hate it. Right? But at the same same time, they're still struggling with this. And there's a difficulty in in in doing the work properly

Simon Moffatt:

Mhmm.

Anders Askasen:

By ripping out this stuff, this old legacy stuff, and putting something modern in place. And I I guess everybody thought that the you know, moving things to the cloud would change things, but in in essence, we're still keeping this on prem legacy debt, plus we have the cloud. So we're in a hybrid landscape where we need to tackle both environments. And like you said, with with the agentic AI and and and the fourth wave of of identity, we have that to consider as well. How are you even gonna tackle that?

Anders Askasen:

I

Simon Moffatt:

think first of all, it's a transition. Think moving to the cloud is a good example because I think everyone assumed the cloud would come along and you'd migrate to the cloud and it would take nine months, and you'd be done there, everything's in the cloud. Clearly, isn't the case. Most organizations have some sort of hybrid landscape. I think what's amplified is that if your identity world is still static, it is based on maybe on prem or classic technologies, there's a different set of requirements from the cloud, speed, elasticity, scalability, the ability to rapidly integrate.

Simon Moffatt:

You know, I can go online this afternoon and I can sign up to a SaaS accountancy platform, and it'd take me fifteen minutes. I may not even need a credit card, but if I did, that would be literally the only barrier to integrating. And then it would say, right, okay, let's point it to your corporate network and pull in some API stuff and connect, blah, blah, blah. You can't have your identity world then saying, well, it's gonna take two or three, four or five days to integrate this app. It's a

Anders Askasen:

very good But this is exactly also how this shadow IT problem emerges, right? Because it's so easy for the business just to engage with a new service that solves a business problem. So the agility is there, but then you introduce that risk and that attack surface exposure.

Simon Moffatt:

You have shadow IT, but you also have shadow identity. So that SAS example is a really good one because clearly the SAS app needs identities for it to work. And in the old world, you'd have an HR system and that would sync into a directory, and then you'd have connectors and protocols to sync the directory into downstream systems. Now, clearly the SaaS app, maybe you can do that relatively rapidly with SCIM or maybe federated provisioning with a SAML or OIDC token when it'll automatically create an account in this SaaS platform. But then what?

Simon Moffatt:

Is that account in the SaaS platform gonna get deprovisioned If I leave, or if I no longer need access to this accounting system, will it be removed? Will my access be cleaned? And honestly, very rarely does that happen. So you end with all these SaaS cloud systems, it's almost like a one way creation. The identities proliferate out, so you get identity sprawl, you get shadow identity.

Simon Moffatt:

Licensing costs go through the roof because you have identities in these SaaS and cloud systems, which are no longer needed, no longer used. They aren't deprovisioned from an authoritative source. You've got all of the mechanics of that sort of identity world, which when it was on prem was quite closely controlled, isn't, because it's proliferating further. You have identity sprawl, you have shadow identity, you have access permissions. And the ultimate thing is that it's costly.

Simon Moffatt:

It costs cash because you have identity everywhere, not to mention you've got the identity sprawl there. So you have shadow identity, but you then have lots of identity debt within that that original classic on prem world there. You have multiple directories, you're gonna have shadow systems, you can have manual systems that are not even connected to these provisioning and deprovisioning flows. So there's a lot of there's a lot of mechanics in there which doesn't get the visibility and the attention it needs. And you mentioned the word drag there, that's a really good word, because it slows the business down.

Simon Moffatt:

It stops them from making

Anders Askasen:

It hinders teams from innovating as well.

Simon Moffatt:

Teams from innovating, partnerships, you know, most organisations have a whole cohort of supply chain, business partnerships, federated relationships. If you can't share information to the people you need to share it with, that drags on innovation, it drags on productivity, it drags on morale actually as well, it's something which isn't often talked about. So if the systems aren't fit for purpose, the business starts to feel that in its way it responds to competition, agility, getting services out of the door, compliance pressures as well, regulatory pressures.

Anders Askasen:

I was just about to say with with all the new initiatives in the European Union, for example, with with NIS two and DORA that impacts financial services and critical infrastructure, there's a lot of impact it has on identity. And and and, you know, you see the same thing in The US with with similar initiatives that also targets critical infrastructure.

Simon Moffatt:

100%. These regulations are not simple. You know? It's it's not ten ten steps that you don't. These are complicated, difficult things to understand, be implement, and then continually implement.

Simon Moffatt:

It's not a one off thing. You know? You're in a regulated industry with any of those pieces of regulation, you will have to continually be making sure they are being applied. And it's not easy.

Anders Askasen:

It's not easy because there's often there's several different regulations that are overlapping or even conflicting at times as well.

Simon Moffatt:

Conflicting, changing, and some of these things may require you to implement a control, which may take you three, six, nine months to implement, and then you have to report against this. And then, as I say, you may then have another system which comes on board, which alters your compliance landscape or alters the risk posture. So it's a constant flux, ultimately. I think having a strong, continuously adaptive identity infrastructure is critical, because the world isn't static, and your identity world shouldn't be static. And you really need to look at where that debt is, where it's located, and how it's really impacting the business.

Anders Askasen:

And when we opened this conversation, told you about some of my sort of historical sins, if you will, where we we we just try to synchronize two different environments and how that was a challenge, right, and to support a joiner mover lever initiative. But imagine large scale enterprises that go through mergers and acquisitions and and divestitures. Yeah. Yeah. That, you know, they they acquire a company, and and that company comes with its own set of sins that have built up over years.

Anders Askasen:

Is there a good way of tackling this? And, obviously, that's a biased question because we believe that we have the answer to that. Yeah. But it's it's a real problem, and and and it's it's something that you really need to consider when you're engaging in those type of activities.

Simon Moffatt:

Well, you're absolutely correct. You have to tackle it. I think what's perhaps happened in the past is is some of these problems either have not been acknowledged or have been acknowledged and they're not solved. And I think now, because identity is this this this fulcrum of risk, security, compliance, business enablement, allowing the business to do more, suddenly identity has become the main sort of budget release, if you like. So all of that budget that used to be spent on firewalls and data centers and all of that physical stuff, which doesn't really it doesn't really exist anymore.

Simon Moffatt:

A lot of that budget is being transferred into different areas, things like zero trust, SASE, continuous identity, identity posture management, and other.

Anders Askasen:

And and that's because the perimeter has really changed. Right?

Simon Moffatt:

It has changed.

Anders Askasen:

It's no longer that moated, if that's even a word, but moated environment a physical boundary with firewalls, that's no longer the case, right?

Simon Moffatt:

No, but I think the awareness has improved though. So within the business themselves, they realise that spending in these isolated ways, it wasn't delivering security, and equally wasn't delivering business productivity. So it's a long term thing, it's an evolutionary thing. So you have zero trust, an example there, like that's this different way of handling this all parameterized aspect. So that's now a well known concept, everyone understands it, so the budget alters.

Simon Moffatt:

So to make Zero Trust work, you need to have a strong identity foundation, which includes the identity data aspect, profiles, policies, permissions, and the runtime aspect. You need context. You need to be integrating identity into more systems. So the awareness, I think, to fix these problems is much higher than used

Anders Askasen:

to be. So would you agree with me if I state that well, I, I think that it's it's a matter of maturity that you need to do this in a certain order. You need to start at the identity layer and clean that up and make sure you unified everything into a coherent layer of identity data that you can then feed higher up the value chain. Would you agree with that that it is a journey?

Simon Moffatt:

It it is a journey. A 100% is a journey. And I I think it's important to realize that there are many systems now rely upon identity, and they make assumptions upon identity. And those assumptions are often quite implicit. So by this, I mean, if you have a, say, data encryption platform, for example, and to gain access to a decrypted piece of data, you need to have an assertion, an IDC token, and some claims and some permissions, etcetera, etcetera.

Simon Moffatt:

The data system is making assumptions that that token is valid, it's been issued correctly, it has the correct identity information within there, that the Simon in the ID token is a real person, it's being biometric verified. It's not going to do those checks again. It's relying on the data presented within the tokens and within the identity ecosystem. So suddenly, you can also have this almost cascading level of risk or a proliferation of risk, because those assumptions are across a whole host of different integrated systems. So your cloud, your SaaS, data, network, endpoints, and other.

Simon Moffatt:

They're all relying on identity, and they assume identity is working effectively. They're assuming the offboarding process happens instantaneously. They assume the tokens being issued are valid, and the people within the tokens are, you know, real people. There's So a lot of implicit and explicit assumptions made on identity. And if your identity world is littered with debt, is littered with stale accounts, ghost accounts, redundant accounts, etcetera, those assumptions suddenly start to fall down.

Simon Moffatt:

And and that that becomes a productivity blocker, it becomes a security risk, compliance risk, and all of those other sort of more secondary issues, I think. And it's I think the reliance on identity working effectively has never been as high, really, because it is now really critical to the security stuff and the productivity.

Anders Askasen:

And it has to do with the fact that the perimeter is now changed to identity, and that's the key of everything. But I I was talking about sins that I've committed in the past. And and and and when we introduced these synchronization, there were differences in how we manage the onboarding and the offboarding and put it specifically the offboarding. So we so there was some need to leave certain accounts in one system, and, you know, some of it was manual work. Some of it was scripted work, and and there was really no coherency of how to deal with some of the offboarding problems.

Simon Moffatt:

And Yeah.

Anders Askasen:

And and and, obviously, that introduced a lot of risk Mhmm. Because there was accounts that you can log in and and you can you can act as a normal user. But if you know your way around the system, you can quickly maneuver and and do these lateral movements of gaining more access. And and obviously, with that technical depth, if you don't tackle it

Simon Moffatt:

Yeah.

Anders Askasen:

It's gonna be a problem. Right?

Simon Moffatt:

Yeah. Yeah. 100%. And it's there's there's there's a few things to unpick here, though. Think one is is the visibility aspect.

Simon Moffatt:

The bad guys, they always fall between the cracks. And by this, they will leverage ghost accounts, excess permissions, systems that aren't being logged, systems that have manual deprovisioning or even provisioning mechanisms, because there's no eyeballs on that stuff. So they can operate, they can maneuver, they can try things without risk of being captured and caught, because there's no monitoring or there's no visibility around, okay, well, this guy left the HR system six months ago, his account is still in whatever, active directory, whatever. Nobody knows. Nobody cares.

Simon Moffatt:

So there's huge disconnect. But I mean, practically and pragmatically, there's licensing costs here, there's costs to the business of not doing the basic stuff of deprovisioning people.

Anders Askasen:

But it's also that sort of evolution or maturity journey that you go through as an enterprise where you unify your identities, you make sure you have that cleansed and in sync with what it should be, the single source of truth. But once you have that, like to your point, you can apply that additional observation layer and actually detect and monitor and more acutely actually do something about the problems when they're being observed or when they're being detected. And I think that's the holy grail of identity governance, if you will, where you can detect the problems and do something about it and actually improve the posture and reduce the attack surface.

Simon Moffatt:

Yeah. I think that's fine. I think it's you know, identity used to be quite linear. You go through a set of steps and you finish those steps and then that would be completed. Whereas now, because identity is so central, it has to be more reflexive.

Simon Moffatt:

It has to adapt to external threats. It has to adapt to what the business needs, because ultimately, identity is there to serve the business. So if suddenly the business needs to launch a new application, build a new app, spin up some infrastructure, consume a SaaS app into a merger, into an acquisition, supply chain, not touched on supply chain, but that has huge ramifications if your identity layer is not working effectively. So the identity world needs to respond to those external events. So how does it do that?

Simon Moffatt:

Well, it needs to listen. It needs to be able to be aware of, okay, we need to change our identity world, whether it's an identity, an account, an application, a policy. You need to be changing these things really more dynamically. So you need to be able to listen and observe what's happening within the business, within the security and threat world, and then be able to implement that change effectively, whether it's changing a permission, increasing monitoring, adding in more context during a policy enforcement decision. So you need to be able to listen, act, and then respond.

Simon Moffatt:

I think in in that siloed legacy world of of sort of linear identity, which is fragile, quite static sort of processes, that's really hard to do and time consuming and and inefficient.

Anders Askasen:

It is. And and to to your point there, that's that's what we're trying to do with the Radio one platform. We we we unify identities to make sure that we have that signal source of truth. We apply that observation layer to detect these anomalies, these these threats, these incidents, and then allow to act. And and one of the the recent additions to the platform is to support shared signal framework where we can actually send the signal to, you know, our friends in the industry, whether they're Okta or CrowdStrike or or you name it, to shut down and and make sure that you secure immediately if something happens.

Anders Askasen:

And I think that's super powerful. But we see legacy depth of dealing with that as you know, it's both an operational tactical problem. It's a strategic problem. But as a CISO and to wrap up, how do you actually go and get funding to support some of these initiatives? Anything you can recommend there?

Simon Moffatt:

Always, funding's always an issue. I think it's always around identifying where where your core weaknesses are. You know, you wanna you wanna improve your system strategically. So ultimately, it's not necessarily about spending more or raising budget, but about spending effectively. So there's no point spending on on legacy firewalls or data centers if that's not improving the business journey or the business outcome.

Simon Moffatt:

So always be thinking of the business outcomes. And often, it's a case of transferring budget to the most productive and impactful areas of technology. And you mentioned zero trust earlier, identity is a key foundational part of zero trust. So you sort start to see the budget changing and shifting and being spent more within the identity world about improving the data, improving monitoring, delivering strong authentication. You mentioned shared signals there to look at encountering external threats.

Simon Moffatt:

So it's often a case of just transferring budget, which allows your identity world to be more efficient, more dynamic, more responsive. And actually, once you do that, you often find a lot of this stuff comes for free. And by that, I mean, the fact that if your identity world is working effectively, you see a massive reduction in license costs, for example, you see a massive improvement in employee onboarding productivity. So there's sort of cost savings emerge everywhere by getting identity right. So it's a little bit like your health, know, you invest in your health, it rewards you in multiple areas.

Simon Moffatt:

I think that's exactly the same for identity. But like always, understand your ecosystem, understand your identity world to get started. Know, where is by real high risk, where is the death? Where is identity helping? And more importantly, where is it hindering the business?

Simon Moffatt:

Where is it slowing things down? Where is it stopping the business from doing what the business needs to do? They're always good places to start.

Anders Askasen:

I think these these are all very wise recommendations, Simon. Thank you so much for having the conversation. It's it's always a pleasure, and looking forward to next time.

Simon Moffatt:

That's all. Thank you for having me. Always good chatting.

Anders Askasen:

Thanks for listening to Radio Logic. Subscribe now wherever you get your podcasts.