Identity Decoded | The Identity Security Podcast
The only podcast where identity and security finally sit down together for a conversation that’s long overdue. Defining what Identity Security should look like is harder than it sounds, so let’s skip the buzzwords and vendor pitches and get straight to honest conversations with people like you doing the work. From the role identity plays in incident response to programmatically getting rid of AD tech debt or finally achieving least privilege, expect candid conversations about what's actually working, what's broken, and what's next. Tune in as leaders from every discipline unpack the tensions, tradeoffs, and lessons learned from buil...
Identity Security on the Frontlines: How McDonald’s Built a Scalable Strategy
In this episode of Identity Decoded, recorded live at Identiverse, hosts Roy Akerman and Rob Ainscough sit down with George Roberts, Principal Architect for Identity and Access at McDonald's, to talk about Identity Security at a scale few practitioners ever encounter. George manages 2.2 million workforce identities across 95 markets worldwide. The conversation covers how McDonald's built a single source of truth without 1,500 separate HR integrations, why frontline workers get a printed, paper-based MFA sheet as their "least common denominator" security factor, and George's long-term vision for verifiable credentials and distributed identity. They also dig into why identity teams get looped...
How Ransomware Groups Run the Cartel Playbook: Inside the DEA with Aaron Turner
In episode two of this two-part series of Identity Decoded, hosts Roy Akerman and Rob Ainscough continue their conversation with Aaron Turner — this time tracing a surprising parallel between drug cartels and ransomware groups. Aaron was assigned to the US Department of Justice after 9/11 and spent 18 months working with DEA Special Operations Division under Steve Murphy and Javier Peña — the real-life figures behind Netflix's Narcos. He breaks down why both types of criminal organizations are, at their core, transnational, economically rational actors that rely on stolen or assumed identities to operate. The conversation moves from Pablo Escobar's "plata o plo...
Inside Active Directory's Origin Story: Aaron Turner on Microsoft's "Kill Novell" Mission
In episode one of this two-part series of Identity Decoded, hosts Roy Akerman and Rob Ainscough sit down with Aaron Turner, who spent eight years at Microsoft during the founding of Active Directory — starting as a support engineer and later working on Active Directory, SQL Server, Windows Mobile, and Xbox Live. Aaron takes listeners back to the mid-'90s mindset that shaped Active Directory's design: a mission to "kill Novell" and sell more Windows and Office licenses, not to build a security boundary. The conversation traces how that original trade-off — deployment speed over security — led to decades of "identity debt,"...
Winning in securing agentic identity: Start with one team, one use case
In this episode of Identity Decoded, recorded live from Identiverse, hosts Roy and Rob sit down with Sean O'Dell to unpack one of the most talked-about — and least understood — challenges in Identity Security today: agentic identity. Sean shares how his background across healthcare, entertainment (including a stint reverse-engineering an authorization system at The Walt Disney Company), and engineering shaped his product-first approach to identity and access management. The conversation dives into why identity must be a "first directive" baked into agents at creation, the difference between agent identifiers and agent identities, the lack of standards across providers, and Sean's prac...
The Four Ps and a Balance Sheet: Why Eve Maler Says Identity Needs a Product Mindset
Eve Maler co-invented SAML, served as CTO of ForgeRock, and spent years as a Forrester security and risk analyst before founding Venn Factory, where she helps executive teams turn identity from hidden plumbing into a business advantage. Recorded live at Identiverse, this episode of Identity Decoded finds Eve joining Roy Akerman and Rob Ainscough to unpack the ideas behind her new book, Mastering Digital Identity: From Risk to Revenue. The conversation traces how identity work quietly grew into "an elaborate patchwork of workarounds," why treating identity like a product (not a ticket queue) raises the ceiling on what it...
Beyond the vault: Why AI agents force us to rethink Privileged Access Management (PAM)
Rohit Agnihotri has spent nearly two decades helping organizations rethink identity, building and leading IAM programs and advising executives on strategy. He's also the founder and host of the widely listened to Identity Navigator podcast. In this episode of Identity Decoded, he joins Roy Akerman and Rob Ainscough to make the case that traditional, vaulting-first privileged access management is dead, and to unpack what's replacing it. Rohit walks through why the old "vault everything" model breaks down under the sheer volume of machine identities, why standing privileges are one of the biggest attack vectors in the enterprise, and why...
Attackers are only as powerful as their permissions: Identity Security lessons from inside Mandiant
Episode Summary:
Chris Linklater from Mandiant has spent his career helping organizations respond to cyber incidents, recover from breaches, and strengthen their security foundations. In this episode of Identity Decoded, he joins Roy Akerman and Rob Ainscough to unpack why identity has become one of the most common paths attackers use to gain access, move laterally, and exfiltrate data. Drawing from real-world incident response engagements, Chris explains why organizations often focus too narrowly on privileged accounts while overlooking the risks posed by everyday users, delegated permissions, and poorly governed group memberships. Together, they explore the growing importance...
From IT support to security's core: General Motors' identity story
Andrew Cameron has over two decades at General Motors watching identity evolve from an IT function to the core of enterprise security. In this episode, he shares about that journey and explains why GM now treats identity as the control plane across an incredibly complex environment that includes factories, legacy OT systems, and robots on the plant floor. Andrew gets into the real tension between governing access upfront versus controlling it in real time, and why a one-time login event is never really enough. He and the hosts give a refreshingly grounded take on the difference between identity sitting...
What happens when a well-intentioned AI agent goes rogue ft. Susanne Senoff
Is “identity is the new perimeter” more of a marketing slogan than a real security strategy? In this episode, Roy Akerman and Rob Ainscough sit down with Susanne Senoff from Conga to discuss how AI agents are starting to behave more like threat actors, and why traditional ideas like “perimeter” and “zero trust” are becoming harder to define. Susanne shares firsthand experience, including an AI agent that wrote reverse proxy scripts and triggered a high-severity cloud alert, showing why security hygiene, understanding critical assets, and monitoring behavior matter more than static privileges or tier-zero boundaries. Together, they explore how IAM needs to...
Mythos, AI-powered attacks and the security reckoning ft. Sree Ashokkumar
Mythos changed the rules of security. Again.
In this episode, Roy and Rob sit down with Sree Ashokkumar, VP of Cybersecurity at Interactive Brokers, to talk about what happens when frontier AI models like Mythos start exposing foundational weaknesses in identity and collapsing the security controls we've relied on for years.
Mythos has quickly become one of the biggest conversations in cybersecurity, and for good reason. Sree shares what he's hearing from peers who've seen it in action: breaking out of hypervisors, chaining exploits in minutes, and forcing CISOs to rethink everything from vulnerability management...