Podcasts

Prefer to listen to your Identity news?  Click on the individual podcasts below or scroll further to browse all the newest podcasts to find what interests you.  Note – you won’t see the Identity Unlocked podcast in the newsfeed because our friend Vittorio has left us – but his voice and his insight are unrivaled even now, please listen and enjoy.

Identity at the Center
Hybrid Identity Protection
Identity Unlocked
  • #446 - Rethinking Identity for AI Agents with Rick Scot

    Rick Scot, Global CIO and CISO at Elevate Textiles, joins Jim and Jeff to talk about how he went from leading a data team to holding both the CIO and CISO seats at a global manufacturing company. Rick shares the moment that pulled him into security, how his tight-knit Charlotte cyber community shapes his thinking, and how he balances speed and control when the two roles pull in different directions. The conversation moves into identity for the age of AI agents: whether an agent is a human or non-human identity (Rick argues it's neither), who should own accountability when something goes wrong, and how session termination has to extend beyond turning off an account. Rick also digs into shadow AI, the real cost of tokens versus flat-rate licenses, and how he evaluates new identity technology against his organization's size and risk appetite. The episode closes with what excites and concerns him most about AI over the next three to five years, his advice for identity practitioners, and a lighter look at hobbies people wouldn't expect.Connect with Rick: https://www.linkedin.com/in/rickscot/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Intro and community shoutouts07:06 - Introducing Rick Scot, Global CIO and CISO at Elevate Textiles07:46 - How Rick got into cybersecurity09:22 - Charlotte's tight-knit cyber community11:18 - The moment that made security the focus13:06 - Balancing the CIO and CISO roles16:17 - What "Identity at the Center" means to Rick19:26 - Where to start when building an IAM program23:29 - Balancing risk and innovation with AI27:46 - Who should own accountability for an AI agent29:38 - A hierarchy for agent identities33:31 - Terminating access and sessions, not just accounts36:25 - Dealing with shadow AI41:37 - Standing up a governance process for new AI projects43:19 - Evaluating new identity technology and token costs48:51 - Training and governance around AI usage52:22 - Established vendors versus disruptive startups56:56 - Looking three to five years ahead1:00:20 - Advice for identity practitioners1:01:41 - Lightning round: hobbies and surprises1:08:40 - Closing and where to find RickIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Rick Scot, Elevate Textiles, CIO, CISO, identity and access management, IAM program, identity governance, AI agents, non-human identity, agentic identity, shadow AI, session management, offboarding, token costs, Charlotte cybersecurity community, identity leadership

  • #445 - Sponsor Spotlight - Twine Security

    Jim McDonald hosts this Sponsor Spotlight episode of Identity at the Center, made possible with support from Twine Security. Jim is joined by Benny Porat, co-founder and CEO of Twine Security and previously co-founder and CTO of Claroty. Benny shares how his cybersecurity background led him into identity and explains the concept of the "execution gap," the space where identity teams are accountable for outcomes but lack the full business context to act on their own. The conversation explores Twine Security's AI digital employee, Alex, and how it differs from traditional automation and RPA, where AI-driven execution fits best within identity operations today, and the balance between the parts of a task AI can handle easily versus the harder remaining work. Benny and Jim also dig into governance and trust, including why least privilege matters even more for AI agents and non-human identities, how organizations typically start with read-only access before expanding permissions, and how access reviews and recertification could evolve as AI takes on more of the process. They close with reflections on measuring success, how the identity practitioner's role changes as more execution shifts to AI, and a lighter round on what a personal AI digital employee might look like.Connect with Benny: https://www.linkedin.com/in/bennyporat/Learn more about Twine Security: https://www.twinesecurity.com/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at idacpodcast.com00:00 - Introduction and welcoming Benny Porat, co-founder and CEO of Twine Security00:52 - How Benny found his way into identity and access management02:21 - The origin of the name Twine03:28 - Defining the IAM execution gap05:53 - AI digital employees versus RPA and automation08:07 - Where AI digital employees are best suited today09:45 - Why AI is strong at eighty percent and what makes the rest difficult14:45 - Where a digital employee like Alex fits within identity operations18:43 - Trust, governance, and giving AI agents the right permissions21:42 - Applying least privilege to AI agents and non-human identities25:19 - How organizations start using Alex, from read-only to full execution30:27 - Rethinking the role of access reviews with AI involved33:14 - Measuring efficiency gains and revocation rate improvements36:00 - Addressing concerns about AI replacing IAM practitioners39:12 - How customers define and measure success44:15 - How the practitioner's day-to-day role changes with AI agents47:12 - Closing thoughts and where to learn more47:37 - Lighter note: imagining a personal AI digital employeeKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Benny Porat, Twine Security, Sponsor Spotlight, AI digital employee, Alex, identity and access management, IAM, execution gap, least privilege, access reviews, recertification, agentic AI, non-human identity, NHI, Claroty, IGA, PAM, governance, human in the loop

  • Why Less Than 20% of Ransomware Victims Ever Pay with Marc Jason Grens, President of Chaintrax

    This episode features Marc Jason Grens, President of Chaintrax. Marc has led Chaintrax for twelve years, growing it from a compliance and anti-money-laundering firm in cash-to-crypto services into a licensed blockchain forensics practice after entering the ransomware payment business in 2017. He has since advised on more than 4,000 incidents. In this episode, Marc explains why ransomware victims decide to pay, why that payment can violate US sanctions law if it isn't vetted first, and why tracking the money afterward is how law enforcement works to recover it. This episode makes the case that paying a ransom is only the beginning of a compliance and recovery process, not the end of one. Guest Bio Marc Grens is the President of Chaintrax,  which has been providing cutting-edge financial, technological, and consulting services for the payments and incident response industry for the last 12 years. He is a serial entrepreneur with more than 15 years of experience in the investment industry. Prior to Chaintrax, Marc held senior positions at Charles Schwab, HighTower Advisors, and Alpha Strategies. He received his M.B.A. from the Kellstadt Graduate School of Business at DePaul University in 2010, and a B.A. from Illinois State University. Marc is an active angel investor and serves on multiple advisory boards of companies in the Chicago tech community. Sponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more. Links Connect with Marc on LinkedIn Connect with Sean on LinkedIn Connect with Jeff on LinkedIn Don't miss future episodes Learn more about Semperis HIP Conference 26 is coming to Nashville, September 8–10, 2026. Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments. If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

  • #444 - August 2026 Mailbag

    Jeff and Jim open with the unavoidable topic of AI agents and the tension between enabling innovation and governing agent permissions, then run through a packed fall conference schedule. The August mailbag pulls questions from Singapore, Toronto, Prague, Johannesburg, Helsinki, and Seoul. They discuss when externalized authorization makes sense, why passkey recovery can become the weak link in phishing-resistant authentication, what EU digital identity wallets may mean for enterprises, how continuous access evaluation changes the meaning of terminating access, and how to build resilience around a centralized identity provider without creating a second full-scale IdP. The episode closes with a lighter question: if every IAM product needed a giant warning label, what should it say?Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:10 - Welcome and have we talked about AI too much?01:32 - Governing AI agents without becoming the progress prevention department03:50 - Fall conference season and IDPro04:40 - Cybersecurity Summits in Chicago and Atlanta06:40 - SailPoint Navigate, InfoSec World, FIDO Authenticate, and Identiverse DC10:40 - 3D printing, challenge coins, and superfan status11:56 - August mailbag begins12:19 - Singapore: Is externalized authorization ready for mainstream IAM?20:30 - Toronto: Passkeys, account recovery, and help desk social engineering25:55 - Prague: What should enterprises do about EU digital identity wallets?31:44 - Johannesburg: Continuous session revocation and what “terminate access” really means38:04 - Helsinki: Designing identity resilience around a centralized IdP45:23 - Seoul: What warning label should every IAM product have?48:26 - Wrap-up and how to send future mailbag questionsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, August 2026 mailbag, externalized authorization, authorization, policy-based access control, passkeys, account recovery, phishing-resistant authentication, identity verification, EU digital identity wallet, continuous access evaluation, shared signals, session revocation, token revocation, identity resilience, identity provider, disaster recovery, business continuity, AI agents, agentic identity, IDPro, FIDO Authenticate, Identiverse DC, InfoSec World, SailPoint Navigate

  • #443 - Ghosts in the Machine with John Huyette and Omer Arshed

    Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments.5 Laws of AI Risk: https://www.linkedin.com/feed/update/urn:li:activity:7487942457075257344/Connect with John: https://www.linkedin.com/in/john-huyette-1373906/Connect with Omer: https://www.linkedin.com/in/omerarshed/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00 Introduction, 3D printing, and conference updates06:58 Introducing John Huyette and Omer Arshed07:52 John’s path from technology risk to AI risk12:11 Omer’s identity origin story13:43 The five laws for managing AI risk18:00 What “ghosts in the machine” means for identity20:17 Governability and ownership of AI identities25:17 Do you know what has access to what?29:43 Applying decades of IAM lessons to AI32:35 Lineage and integrity35:20 Building an AI bill of materials37:12 Trust boundaries and external data38:36 Prompt injection and untrusted content42:48 Applying zero trust principles to AI agents47:26 Authority containment49:56 PAM, least privilege, and just-in-time agent access56:22 Human impact and accountability58:41 Is agentic AI really a new identity problem?01:02:35 Starting with lower-risk AI use cases01:04:21 Where organizations should start01:05:07 Shadow AI and zombie accounts01:07:09 What excuses would an AI give during an access review?01:12:20 Wrap-upKeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.