Showing posts with label keeper security. Show all posts
Showing posts with label keeper security. Show all posts

Wednesday, May 20, 2026

The Identity Crisis Your Security Team Didn't See Coming

 

The Identity Crisis Your Security Team Didn't See Coming

ByDarren Guccione,

Forbes Councils Member.

May 20, 2026, 07:00am EDT

Darren Guccione, CEO and cofounder, Keeper Security.



For decades, identity security meant one thing: protecting the humans who access your systems. You issued credentials, enforced passwords, deployed multifactor authentication and moved on.

That model made sense when the identities you were managing were tied to a real person.

That world no longer exists. AI has redefined what an identity is, and most enterprises are nowhere near catching up.

AI agents don’t wait for instructions from a human to act. Rather, they operate autonomously and around the clock to execute transactions, access sensitive systems or interact with external applications.

Every agent requires credentials and access rights to function. Where a large organization might manage tens of thousands of human identities, the number of non-human identities (NHIs) can scale far beyond and outnumber the human workforce across an enterprise ecosystem.

At RSAC 2026, Cisco President and Chief Product Officer Jeetu Patel said it frankly: When identities operate at machine speed, traditional security models break. AI agents require a new model for establishing trust, not just a retooled version of the old model.

The Scale Problem Is The Easy Part​

The harder problem is behavioral. NHIs act nothing like human identities, and organizations that govern them the same way are creating exposure they may not recognize until it's too late.

Human accounts have a person behind them, someone who can be questioned, suspended or fired. NHIs, on the other hand, are frequently created on demand by developers or automated processes, with no centralized oversight and no clear owner.

They also don't map onto legacy privileged access management models designed around human behavior. For example, an employee logging in to an unusual system at 3:00 a.m. triggers alerts, while an AI agent doing the same thing looks routine—until it becomes a breach.

The risk is not hypothetical. When AI agent social network Moltbook launched, a misconfigured database exposed roughly 1.5 million API authentication tokens within days. Researchers from Wiz found that anyone with those tokens could impersonate or take control of agents that had access to internal systems like Slack and email.

In many enterprise environments, machines and NHIs already outnumber human users 92-to-1, according to my company's survey of 109 cybersecurity professionals conducted on-site at RSA Conference 2026. That's 92 entry points for every one that requires compromising a human.

The broader industry is struggling to keep pace. The same survey found that only 28% of organizations have full visibility into NHIs across cloud, on-premises and SaaS environments. More than 40% had already experienced a security incident involving non-human identities or credentials in the past year. Another 32% weren't sure whether one had occurred—a detection gap that is itself a problem.

These are solvable problems, but most aren’t solving them fast enough. Security governance for NHIs needs to move faster, because AI deployment certainly isn't slowing down.

Where To Start​

Most security teams know they have an NHI problem. Fewer know where to begin solving it.

The answer starts with visibility: Get a full accounting of your NHIs. Most organizations have a surprisingly poor picture of how many exist, who created them and what they can access. Without this visibility, everything else is just guesswork.

Once you have visibility, the next step is to apply least-privilege access to NHIs with more discipline than you would normally apply to humans. AI agents accumulate permissions over time, often far beyond what any single task requires. Reducing that footprint and automating enforcement will limit the damage when something goes wrong.

Move away from standing permissions toward a least-privilege model with just-in-time access. Agents shouldn't hold 24/7 access to systems they use occasionally any more than employees should. Dynamic, task-specific access is harder to exploit and easier to audit.

Finally, track down dormant identities. Abandoned service accounts and unused API keys don't disappear but sit quietly with whatever access they were originally granted. These "zombie" identities represent risk with zero operational value. Decommissioning them needs to be a standard practice, not a once-a-year cleanup project.

Conclusion ​

NHI security is not an IT hygiene issue. It sits at the intersection of data security, regulatory compliance and operational risk. Every AI agent your organization deploys is an identity with access to real systems.

The identity perimeter has already expanded beyond what most organizations are prepared to govern. The question is no longer whether to build a framework for NHIs. It's whether your organization will do it before or after a breach forces the issue.



Tuesday, January 30, 2024

NEW INC. MAGAZINE COLUMN FROM HOWARD TULLMAN

 

Talk Is Cheap--And Not All That Useful

In a world where everyone has a megaphone, doing is the best way to get through the noise.

 

EXPERT OPINION BY HOWARD TULLMAN, GENERAL MANAGING PARTNER, G2T3V AND CHICAGO HIGH TECH INVESTORS@HOWARDTULLMAN1

JAN 30, 2024

 

I had an early morning breakfast recently with the CEO of a Chicago tech company who's so focused on his business and constantly in motion that he makes me feel like a slacker. He said he had spent a few hours over the weekend building a new gaming computer for his 16-year old son and that it had been more challenging and time-consuming than he had expected because he was having his son do most of the work so that he would develop his own skills and dexterity. He mentioned that one of the critical cables turned out to be defective so that the fully built system wouldn't work at first. But they kept at it, did some troubleshooting, eventually found the problem, and replaced the bad connection. Knowing him as I do, I can just imagine the steam shooting out of his ears. Patience isn't his long suit. Perseverance, on the other hand, is one of his amazing strengths, which he hopes to pass on to his kids.

Foolishly, I asked him why he didn't simply buy the kid the best gaming computer out there since he could certainly afford it.  Besides, the companies selling these high-end machines had whole teams doing quality assurance to make sure they worked right out of the box. He shrugged and said two interesting things: first, as you'd expect from a genius computer geek, the one they ultimately built was better and faster than anything on the market; and second, the whole point of the exercise was that he was building the new machine not just for his son, but with his son, and helping him in the process as well. It was both a teaching opportunity, a shared moment, and an important bonding experience.

These days millions of parents are impatient, at a loss, tongue-tied, and finding it harder and harder to effectively engage their own kids, not to mention their younger team members at work, in substantive conversations about so many critical things:  ethics, politics, trust, antisemitism, money. These are things that matter now, and which will matter even more in their futures. The message and the lesson that I took away from my breakfast chat is that the most successful strategy today isn't: (1) trying to share your "truth" with your kids or lecture your employees on something or (2) throwing up your hands in frustration and ending the discussion entirely.01:23

It's more about showing them, through your actions, what's important, what matters, and why.

Don't expect anyone to listen to your sage advice and speeches and ignore your example. Observation, at a time when everyone's a videographer, is far more convincing and relevant than conversation. There's tremendous untapped power in the simple act of showing up, sharing experiences, and demonstrating that you sincerely care about the outcome.  What you do often speaks so loudly that there's no need to hear what you say. Find time in your busy life to pitch in, to drive your kids to their next game or activity, and to stick around to show them that you're interested.

We're at a critical juncture in our country.  None of us -- whether we're building a business, raising a family, or trying our best to do both -- can afford to tune out and shut down. Or allow the pains of the recent past and the disappointments we're feeling with our institutions, organizations, governments, and even fellow citizens immobilize us, or lead us to believe that our efforts are hopeless.

It's easy to lose hope as we watch feckless and foolish former football coaches like Alabama Senator Tommy Tuberville threaten our military and make fools of the rules and the leaders in Congress. It's depressing to watch the border crisis and the lack of more aid to Ukraine continue to cost lives every day while the MAGA hypocrites in the House block bipartisan relief bills and bend their knees to the demands of the Orange Monster -- a deviant just found liable for $83.3 million in damages in a defamation case in New York.

And it's easy to become discouraged when we see our creaky and antiquated court systems unable to fully deal with many obvious crimes, lies, and attacks on our democracy, as well as with their perpetrators. But we shouldn't accept for a moment that there's nothing we, as parents, business builders, and concerned citizens, can do to set the right examples for our kids and team members. Saying won't make it so, but doing can take us a long way. Actions still speak louder than words.

Small steps and gestures can start the ball rolling. The key to getting things done is to overcome the pervasive inertia and angst and put yourself out there by doing something. Whether it's a DIY project at home or joining some community action committee at your church or synagogue or raising funds for your firm's favorite charity. There's plenty that needs to be done and nothing that dissipates the languor and lethargy as effectively as the satisfaction of working together as a team to complete even simple chores and short projects. Step by step, brick by brick, and task by task, the real objective is to restore and rebuild business and personal connections at every level, which will eventually form the new foundation for fair, full and honest communication. You'll hear far more compliments than complaints because those who are pulling the oars don't have time to rock the boat.

Your kids and newer employees may be hesitant at first to buy into the process and be convinced that it's authentic and sincere. That's expected, because we're all still suffering from Trump's destructive and cynical attacks on integrity, sincerity, and trust. But, in fairly short order, they'll catch on and surprise you with their interest, commitment, and enthusiasm.

We may not believe that we have the necessary strength as individuals to turn things around, but even when strength fails, there is always perseverance. And beyond perseverance, there remains hope. When hope doesn't seem sufficient to the task, there's love. And love never fails. Make sure your kids know this each and every day. No child should ever have to wonder if his parents love him.

Wednesday, May 24, 2023

WGN RADIO WITH LISA DENT AND HOWARD TULLMAN

 

(from left to right) Howard Tullman with U.S. ambassador to Japan and former Chicago Mayor Rahm Emanuel (photo courtesy of Howard Tullman)

Howard Tullman, general managing partner for G2T3V, LLC and for the Chicago High Tech Investors, LLC, joins Lisa Dent to talk about how college commencement speeches have changed over time, why they are meant to inspire graduates entering the workforce, and how some protests sometimes threaten free speech. Also, Tullman talks about a recent trip to Japan he took with former Chicago Mayor Rahm Emanuel, who is now U.S. ambassador for that region. This conversation with Howard Tullman is sponsored by Career Vision.

LISTEN TO THE SHOW HERE


Tuesday, May 16, 2023

NEW INC. MAGAZINE COLUMN BY HOWARD TULLMAN

 

Fraud Protection Is So Easy. Why Won't We Do It?

You can take these very simple steps to protect yourself, or be like lots of tech companies and keep doing the same dumb things that lead to losses.

 

BY HOWARD TULLMAN, GENERAL MANAGING PARTNER, G2T3V AND CHICAGO HIGH TECH INVESTORS@TULLMAN

 

I have come to believe, sadly, that it's impossible to convince the vast majority of digital consumers that they should take the few simple steps, and invest the embarrassingly modest amount of dollars needed, to protect the security and confidentiality of their passwords. You can explain things to people repeatedly, but the simple truth is that you can't understand things for them. If only we could learn what's important before it's too late, we'd be far ahead of the game. Prevention rather than cure. It's so much smarter and cheaper to avoid the pothole entirely than to get a great deal on a tow truck or a new tire.

But instead of preemptive actions, we're lazy, we're sloppy, and far too many of us continue to use the same short, stupid, and easily solvable passwords repeatedly across multiple applications on our phones and PCs. This creates continuing and growing risks of losses, which can be many times the amount of the costs of avoidance through basic preventative actions. When you're dying of thirst, it's too late to start digging your well.

There are simple, cost-effective solutions for password and secrets management available from firms, like Keeper Security, that do a first-class job of password protection. But it's far harder than you'd expect to convince people to invest the one-time effort needed to protect their identity and most valuable assets. We're apparently all willing to invest far more in trying to secure something good or advantageous than we are in trying to keep something bad from happening. And, amazingly, it doesn't get much better or easier to get consumers to make such a move even after they've been hacked -- whether they know it or not.

You'd think, if there was any substantial group of easily targeted and prospective adopters for security solutions like these, that major tech companies, consulting and accounting firms, government agencies, and their employees would be high on the list, but, here again, it's a matter of the shoemaker's kids and large-scale IT departments generally do a horrible job of patrolling and securing their own environments and enforcing consistent security measures on their own teams.

But what's struck me lately is an entirely separate set of exposures that relate -- with apologies to Capitol One -- to exactly "what's in your wallet" and what would happen if it was lost or stolen in a theft or carjacking. Even the best password plans won't really help you much in this situation, but a couple of simple steps and about 15 minutes of your time can make a huge difference.

I know that we see hundreds of ads every week online or on the tube about how quickly and easily we can shut down or replace a lost card, but here's a flash: All the contact numbers and URLs that you need to reach and tell the many issuers that your cards have gone astray are on the cards, which are in your wallet which -- in a case like this -- you no longer have in your possession. It's a lot like trying to use "Find My Phone" app when it's your phone that's missing and that's where the app resides.

Worse yet, if you asked yourself and answered honestly, you'd admit that you really have little or no idea of exactly what credit cards, debit cards, access badges, medical alert info, insurance stuff, licenses, and other stuff are stuffed in your wallet or purse at the moment-- and absolutely no idea of who or how or where you'd go to cut off, cancel, or replace these items.  

So, here's what I would suggest to save yourself a great deal of grief and a lot of running around trying to track down and contact all these various parties when the problem arises. And, by the way, while this is certainly a phygital solution from the age of bricks and mortar, you can use the Keeper Security Vault application on your phone to quickly and easily digitally store all the images I’m talking about below securely on your cellphone and have them instantly available to you there in the event of a lost wallet.

1. Inventory your wallet or purse.

Throw away the four-year-old business card from the guy at the Omaha airport you never called. Dump the hardware store receipt for the touch-up paint you bought and never used. Recycle the expired proof of insurance cards for the cars you sold years ago. Do you really need to carry your voter's registration card anymore? You get the idea.

2. Copy the cards and store the information in a couple of places.

Put all the cards that are still current and in use neatly on the glass of your printer, copier, or whatever (or use your camera) and make copies of the front and back. This shouldn't be more than a page or two. Make a few copies of the pages. Put the date you created the pages on each page as a reminder of how current your backup plan is.

3. Take an extra 5 minutes to write the contact phone numbers on the images of the front of the cards.

A lot of the critical info -- sometimes even the card numbers themselves -- isn't on the front of the cards, which is why you need to copy both sides. But to save time and confusion, I also find the number to call and write that number for each card on the face image of the cards on your compilation pages so it's handy when you need it.

4. Do the same thing for your significant other and make sure you each have copies of both lists stored in a safe place.

This may take a little discussion, but again, it's worth doing and it's a good way for both of you to review, rehearse, and understand what the necessary notification steps are in the case of any lost cards.

Pat yourself on the back(s) and hope you never need these lists. But remember that the frequency of these problems is constantly increasing and the costs of not being prepared and equipped to quickly deal with them are also growing. It's so much easier to anticipate these things than to try to fix them after the fact. And, while the past is past, it's never too late to change the future.

Wednesday, May 15, 2019

Chicago cybersecurity firm expanding as companies seek protection from hackers


Chicago cybersecurity firm expanding as companies seek protection from hackers



Darren Guccione, CEO and co-founder of cybersecurity firm Keeper Security, said demand from small- to medium-sized business is driving Keeper's growth. (Keeper Security)


Top of Form
Cybersecurity firm Keeper Security is set to triple its employee count in Chicago and move to a bigger office space later this summer, as demand grows for software that protects businesses from hackers.
The Chicago-based company launched in 2011 offering a password manager for consumers. Five years later, it rolled out a similar product for businesses that helped ensure employees’ passwords were strong and that their information had not been hacked.
Demand for that product among small- to medium-sized businesses is driving Keeper’s growth, said CEO and co-founder Darren Guccione.
“They need a cybersecurity platform that protects their businesses against a password-related security breach,” Guccione said. Small- and medium-sized businesses “are the ones being attacked the most because they tend to lack IT infrastructure and IT staff.”
Keeper has about 150 full-time employees worldwide, about 60 of whom are in its Chicago headquarters. It also has offices in California and Ireland. Guccione said he expects headcount in Chicago to increase to about 190 in the next six months.
The company is moving its West Loop headquarters to a space in the building next door that is roughly three times larger than its current office and has an option to expand, Guccione said.
Keeper’s Chicago employees work mainly in sales, marketing and customer service. Its software engineers work mostly out of the California office.

Password-security company boosting space, tripling local staff


Password-security company boosting space, tripling local staff
Keeper, which got its start with consumers, is getting a boost from the B2B market. 



Keeper Security’s move into the corporate market appears to be paying off.
The password-security software company is moving into larger space in Greektown and plans to triple its headcount in Chicago, hiring 130 people here by year-end. 
The company outgrew its space at 850 W. Jackson Blvd., so it’s moving next door to 820 W. Jackson, where it leased 16,000 square feet, with an option for another 5,000.
Keeper was founded in 2011 as a consumer product, but it’s getting a boost from the corporate market. Headcount doubled last year, says CEO Darren Guccione.
Keeper has 145 employees, including 60 in Chicago. The rest are in Northern California, where its technology team is based, and Cork, Ireland.
Most of the new hires in Chicago will be in enterprise sales. Guccione says Keeper has nearly 7,000 corporate customers, mostly small and midsize businesses.
“Keeper Security, like many password managers, gained popularity in the consumer space and is now jumping to the enterprise market," said Karl Sigler, threat intelligence manager at Trustwave, a Chicago-based computer-security company. "This makes sense because passwords are not only some of the most sought-after pieces of data when thieves attack, weak passwords are often the reason why a breach occurs in the first place."
The password-security industry is heating up. SolarWinds, an IT software maker based in Austin, Texas, recently bought Canadian password-security manger Passportal for an undisclosed price. 

Total Pageviews

GOOGLE ANALYTICS

Blog Archive