Radio Logic

How does your body fight off millions of threats it has never seen before, without a single rulebook?
That question might hold the key to securing AI agents.

Anders Åskåsen sits down with Tom from FSP to explore a fresh way of thinking about identity: borrow from biology.

They dig into why role-based access keeps exploding, why we never solved least privilege even for simple service accounts, and why agents now run those same old problems millions of times faster.

Tom's big idea? Treat security like an immune system. Block the known-bad on sight. Slow down the suspicious. Give a human time to step in.

Plus the wild story of an AI agent that signed up for its own API token overnight and would not stop making phone calls.

If you own identity, security, or governance, press play.

What is Radio Logic?

Cybersecurity podcast Radio Logic delivers essential, no‑nonsense conversations with trusted experts on all things identity security. Hosted by Anders Askasen, SVP of Marketing at Radiant Logic and author of Cybersecurity Explained, the show draws on his 20+ years in security and digital identity to address today’s challenges.

00:00:00 - This is Radio Logic, the show about digital identities, the people behind it, the tech behind it, and in each episode we'll cover what works, what doesn't, and what's next. Let's dig into it.

00:00:29 - Welcome to Radio Logic, the monthly podcast where we break down identity into something that actually makes sense. I'm joined by Tom. Tom, you're from FSB. Tell me a little bit about yourself and welcome back to the podcast.

00:00:44 - Thank you. Well, FSP—we're a digital transformation, data and AI, and cybersecurity firm based in the UK but with offices all over the world. I've been in identity for too long to mention, both as a consultant with FSP and previously with other firms, and also on the other side of the fence as well—with Refinitiv and London Stock Exchange, so sitting on the other side owning the controls.

00:01:15 - Last time you were on the podcast, we heard of some of the battle scars that you got from complicated role-based access control (RBAC) projects where you had the role explosion and the proliferation of roles—more roles than there were humans and all the rest. I thought it's a good starting point to discuss because it is a pragmatic way of sort of encapsulating entitlements into something that is more abstracted away from the granular entitlements you can assign. You can audit that role, you can vet that it actually contains the right thing. But why are we always ending up with these problems with role explosions?

00:01:56 - So I guess RBAC as an idea is pretty ancient, right? I think if you're studying for CISSP and so on, you look back at some of these Department of Defense documents from, I guess, the 50s/60s—the real era of computing—where RBAC as a way of managing that proliferation of who has access to what in a very regulated environment was needed. And I guess with the right amount of effort, it can be made to work in a quite static environment with static people, static systems, and static projects. But as we start to pour accelerant on that and get more complicated, it just becomes really difficult to manage.

00:02:35 - Is that where we are right now? We're kind of in the shift from static authorization to more agile, more real-time, more policy-driven, more risk-based types of authorizations?

00:02:49 - I think we've been there for a while, and that failure to keep up—the static model of who should have access to what versus the dynamic reality of who actually needs access to what to do their job—and of course people finding ways around that in unexpected ways. You know, we're about to do that with non-human identities, right? Agents finding unexpected ways to get the thing that you asked them to do done in ways that we couldn't pre-state, couldn't pre-define that they needed this access to do that. And even if we did, part of the value of agency—whether that's in a human doing a job or agentic AI doing a job—is we don't know how they're going to solve the problem; we want them to just get on and do it. Equally, we can't give them so much access, just carte blanche access all areas, that if an attacker compromises that account or identity, they can misuse it in every which way.

00:03:47 - When I speak to customers, there's essentially three different patterns that are emerging on how Agentic AI is being deployed and how companies are testing the grounds out a little bit. You have that sort of "in the browser" type of agentic AI where you kind of give the keys to the kingdom, and that allows that in-browser experience (or even OpenCLAW, which is quite popular) to become useful; it can do stuff. The other pattern that I'm seeing is that sort of orchestration layer—the N8N, Zapier, Bedrock of the world—where it's kind of like Workflow 2.0. You and I have both battled workflow when it comes to joiner-mover-leaver processes and all the rest, but all of a sudden we have a non-deterministic AI agent that can make decisions in real-time. And then the third pattern is you develop something yourself and you need to think about all the security mechanisms. Is that how you see the world as well? And where do these problems start appearing? I can see that if you give access to everything to an in-browser type of agent, you set yourself up for at least an increase in attack surface.

00:05:21 - Absolutely. And yeah, you reminded me I have a machine at home—I've been traveling this week—running what was called OpenCLAW a week or two ago. So that needs to be removed from a few permissions, I think. I think it can only talk to me on WhatsApp, which is fine. Just rewinding somewhat: we're talking about agentic AI and the difficulty of understanding what access they need, what's appropriate, and containing it, which is really hard. But you know, we never solved this problem when the service accounts and the workflows were deterministic, right? We didn't really apply least privilege. We could have known for most service accounts in the last 20 years: what does this service account do, what does it connect to, what does it need to do, how often does it do it? We could have had that kind of "activity bill of materials" and said "right, applying least privilege and even just-in-time—it gets these things at these times." But of course doing that and defining that ahead of time and providing that from the vendor to the organizations deploying these tools was hard and it wasn't done. So far too often we saw "just give it domain admin, then it works." And now we're taking that workflow concept and we bolt in an agent, so instead of having that static "if-then-else" type of condition to steer the workflow, we have a non-deterministic agent that, you know, with 87% probability, thinks this is the best approach to do this activity.

00:06:54 - Yeah, so really what we're doing with non-human identities now is bringing the same problems that we haven't really solved for humans and the access they need throughout their lifecycle, and running it millions of times faster at much greater scale. Depending whose stats you look at, the ratio of non-human identities to human identities in the average organization was already 40, 80, 100 to one. And that's before we bring agentic AI in. The whole benefit there is that you, as an individual, might have dozens of agents going off, inheriting certain delegated permissions from you and doing stuff across the business to make you more effective. So we can't do any kind of static pre-definition of what these agents can have access to—it just won't scale.

00:07:43 - So how do we solve it? Well, this goes back to my pre-cyber life as a researcher in bio-inspired algorithms. My research was around immune systems. If you look at biological systems and how they solve this problem of "I can't pre-state the problem, I don't know what all the pathogens are going to look like, and they evolve thousands of times faster than me"—what's the lifecycle of a bacteria? 20 minutes? Our generation time as humans might be 20 years, and your immune cells are several days. But we're not overrun; we're here. So we've solved the problem enough to stay alive. And it's that change over time: we are able to adapt to "danger signals." We're able to keep a baseline of things that are definitely bad and are always blocked immediately at the edge. If the agent starts trying to connect to things we've said "absolutely not," it's compromised—kill it. If it starts doing things that are kind of questionable—and again, this is where we need the higher-level understanding of "what is the intent of this agent, what should it be doing?" If it's supposed to be booking flights for me and it starts trying to inventory all the users in the business, that looks kind of "attacker-ish," so we need to shut it down. But again, it's really difficult because we need to have this kind of library, just like our immune systems have a library of "these are bad things; if you see them, shut down immediately." And then that understanding and observability of context—"something funny is going on here; it's not already a known bad, but it doesn't look great"—so let's raise the defenses a little bit, start to slow the agent down. We've learned some of these lessons on the internet; if you think about early worms and the defenses put in—"if we start to see this behavior, it might be legitimate email traffic, but if it looks suspicious, we just slow it down." That's enough time for a human to jump in the loop and go "this is bad, kill it" or "actually no, this is just a big email being sent out."

00:10:04 - It seems like you're making a lot of analogies with how nature works—how bacteria are kind of ephemeral, and that resonates with agents who are here and now and need just-in-time access and then disappear or chain up with other agents. It becomes a mesh of access that is hard to observe and hard to untangle. How should you even think about and approach that?

00:10:36 - So how do we actually take those biological ideas and turn them into things we can use in computing? Looking at different timeframes: there are things that are known bad. If the agent starts running this piece of code or connecting to these kinds of things... but you need to define it? Absolutely. But these are things that we've already learned. This is like your innate immune system: if the bacteria has these molecules on its surface, it's known bad and killed immediately. We don't need to learn what it's going to do—it's just gone. And we already have that; all of those behavioral signatures in our endpoint detection tools today. Obviously, that's going to have to develop over time. In the next couple of years, we're probably going to see agentic AI used to carry out an attack—it'll be a much clearer story with less hype. We will see that agentic AI has been compromised, has run within an organization, has had access to assets that it legitimately should have had access to, and then did something it wasn't supposed to do.

00:12:02 - But it boils back to the statement that in order for an agent to actually do some good, you kind of need to give it access to execute. Is it a ticking time bomb? Are we giving away too much access? Are we still in that transitory state where we experiment and try to figure out where the boundaries are?

00:12:41 - Definitely. And the way we learn where those boundaries are—that balance between agency to do good and agency that went too far—is by pre-stating some hard boundaries. For a lot of organizations, the first time they realized their internal data governance was a little too loose was when the techies got a look at Delve in Office and could see who has access to everything and what files the CEO has been opening. Then when Copilot came along and had access to all that information and was able to use it really fast, there was a realization that data governance needs to be reigned in. Equally, as we start to deploy agentic AI, we're going to realize there are limits to what we should give it by default. It's probably okay for Claude to talk to me on WhatsApp, but probably not to have free access to my WhatsApp to send whatever it decides to anyone in my address book. That could get embarrassing!

00:14:15 - Have you dared give your credit card number to OpenCLAW?

00:14:18 - It does not have credit card numbers! But you can see the attraction of why people are taking a very "laissez-faire" approach because it's cool. I saw a video the other day—you don't know what's real anymore—but the guy said "OpenCLAW is ringing me because overnight it signed up for a Twilio API token and decided to start making phone calls and it won't stop."

00:14:46 - And I guess with the deep fakes you can generate, you can literally tune into a minute clip on YouTube, grab that voice, and clone it at a quality where people can't tell the difference.

00:15:11 - Yeah, and while we've made great improvements in authentication and proving "it really is me," we then get to the hard problem of "what should I be allowed to do now that you're sure of that?" A lot of the biometrics we thought were solved are now back on the table because of deep fakes. The crypto that works with public-private key pairs is safe for now, but who knows with quantum improvements? We're working with clients on post-quantum crypto and thinking about their certificate estates. Again, this is back to an asset management problem: do you know where your certificates are and how they're used?

00:16:09 - Exactly. These are all topics that, at least from a Radiant Logic perspective, we always talk about: the "three identity problem." You need to treat them as first-class identities, but they're governed slightly differently and portray different risks. Agentic identities are more ephemeral; machine identities are more static (API keys, SSH certificates); and human identities, which we thought were solved, have new challenges.

00:16:53 - Definitely. And thinking about those buckets: old-school deterministic service accounts will still be around, and we can give them just enough access. Then you've got agentic AI working towards a goal, where dynamic risk assessment requires contextual information. Then there's the third category: agentic AI doing stuff on behalf of a human and inheriting those credentials. That must be something the CISO is losing sleep over—delegating access to an agent to use your calendar or email. Quite often, the protocols don't have the granularity we need yet for that kind of delegation.

00:19:04 - So how do we move forward? If I assume the role of a CISO and I have a mandate from the board to push out more AI for operational efficiency, but I see the risks, what would you advise me to do?

00:19:42 - I think going back to that immune metaphor: we don't know all the bad things ahead of time, but we know some. We can put in tiers of boundaries—some things are just never allowed. Some things we learn as a community—like antivirus signatures, but for heuristics. And some we learn the hard way through forensics. There's a lot to learn from how biology spent billions of years and billions of tries solving this problem where the problem can't be pre-stated. We have to learn what's bad and what's good and then adapt to it.

00:20:47 - Tom, thank you for joining the podcast. It's always a pleasure hearing how you see the analogies with nature. Security is a layered problem, and that's the only way to preempt some of these attacks. I can see that Tom might be up for some more "scars" moving forward in this fast-moving space! Tom, thank you for coming.

00:21:26 - It's a pleasure. Thanks for listening to Logic. Subscribe now wherever you get your podcasts.