The Hidden Security Risks of Agentic AI Moving Beyond Traditional Defenses
Security UnfilteredAugust 03, 2026
261
00:49:5291.3 MB

The Hidden Security Risks of Agentic AI Moving Beyond Traditional Defenses

Nudge Security: https://www.nudgesecurity.com/

LinkedIn: https://www.linkedin.com/in/russell-spitler/

In this episode, Joe chats with Russell Spitler from Nudge Security about the evolving landscape of AI, SaaS, and cybersecurity. They explore how rapid technological advancements are reshaping security challenges and solutions, especially with AI's increasing capabilities and integrations.

00:00 - Russell’s cybersecurity origin story and early influences

04:24 - The industry’s rapid expansion and current security workforce trends

08:05 - How organizations struggle to manage SaaS security and AI integrations

12:49 - The shared responsibility model in SaaS and AI platforms

19:13 - How Nudge secures AI and SaaS ecosystems through API and browser insights

22:39 - Challenges with agentic AI: delegation, access, and risk mitigation

24:34 - The rise of agentic AI capabilities and security implications

27:23 - The potential for AI to democratize security and development

32:08 - Future of security automation and behavioral engagement strategies

36:58 - Building secure, scalable AI security solutions compared to container security

41:17 - The next phase: automation, policy enforcement, and behavioral redirects

Joe: How's going, Russell? It's great to get you on the podcast. I know we've been talking about doing this thing for a while and you know, I I really appreciate you taking the time out of your busy schedule Russell Spitler: Yeah. Joe: to to come on the podcast. Russell Spitler: Good to finally be here. Love talking about security, so it's always a fun excuse to set aside some time for this. Joe: Yeah. Yeah, absolutely. I mean you're in you're in like minded company, you know. That's basically all I do now. Russell Spitler: It's it's funny, it's usually my kids who tell me to shut up when I start talking about security. So I gotta save it for the work hours. Joe: Yeah, no, I mean I I can't even like talk about it with with my wife really. Like she's she'll like turn on the podcast and be like, I don't understand a single thing that you said, like that entire time. You know, and Russell Spitler: Yeah. Joe: I'm like, Man, I I don't know I don't know what to tell you. I don't know how to break these things down even any simpler. 'Cause she's a Russell Spitler: Yeah. Joe: she's an early childhood teacher, right? So she's in a totally different like world. Russell Spitler: Well, we we need some early childhood development books for cybersecurity. I think the next generation would be well served. So maybe that's your next challenge, Joe. Joe: Yeah, right. Some good picture books. my three Russell Spitler: Yeah. Joe: year old always tries to like pull books off of my my bookshelf behind me and she's like obviously looking for pictures, you know, it's like, there's no pictures in there. Russell Spitler: That's a TCPIP stack. Ooh. Joe: Yeah. Yeah. Right. Well, Russell, you know, take me back to like how you got started in the in the space. You know, what does that look like for you? Like were you did you, you know, experience something and, you know, identify, hey, like cybersecurity is an area that I want to go down, or what does that path look like for you? Russell Spitler: You know, I was a child of the 90s. So I think the story of us who are working in cybersecurity who grew up in the 90s has a pretty similar background in ARC, which is IRC and AOL chat rooms and poking around on my computer and like just kind of trying to figure out how the whole thing worked. And that's probably what really got me kind of hooked into. The world of cybersecurity before I even really had that term available to me. And then it was an interesting sort of progression in college where where, you know, I started as a, I don't know, political science major or something. I wanted to learn about Croatia or I don't know what I was doing. But that ultimately ended up being an entree into taking some CS classes. And I was like, these are kind of easy. And I remember I was doing this a lot. And at that time there was no sort of formal computer security or you know really any security courses at all. And so I started doing my independent work in cybersecurity, notably in static analysis. So I was really interested in how A, vulnerabilities got into software and B, how you could find those vulnerabilities leveraging an IDE during development time. And so I built a static analysis engine as one of independent works during college and then when I got out of college, I want peek my head out and there's only a couple of companies doing that, so I got a job. Joe: Hmm. Yeah, it's fascinating how things have like changed seemingly like so rapidly. You know, like I graduated with my bachelor's in 2014, and I didn't I didn't intend on going down the security route or anything like that. But it was like just starting to pick up. You know, and that's not that long ago, like 12 years ago, you know, and now we're in a situation where it's like every company. has security roles. They all have, you know, deficiencies of some sort where they need to expand in their environment and whatnot. Like it's just crazy to see this industry kinda like get propped up so quickly. Russell Spitler: It's it's an interesting one. And I think like the educational aspect of this industry is a is a real challenge because you know, when you look around the industry and you see the people who are successful, it's all the curious types. It's the people who kind of like want to know how things work. It was probably the kids who like broke every electronic thing in their house when they were younger because they wanted to get chips out of the computer or whatever it was. that's the fate of my original Apple IIe. It's like, I'm getting the chips out in my Like, what are doing? This thing's broken now. It's like but with that, that sort of mindset, I think it's consistent. But like when you look at sort of what you need to educate somebody in a in a sort of academic environment, it's really tough because the landscape is so dynamic. And and it's hard to kind of get that place where you can learn the fundamentals without learning sort of the. the nuances of the day, but then if you don't learn the nuances of the day, the sort of, you know, availability of jobs becomes more difficult. And so there's a real balance that I I don't envy academic institutions for having to try to navigate these days. Joe: Yeah. Yeah, that's that's like the real that's a real challenge, you know, even as someone that like might be looking to get, you know, like let's say a master's or a bachelor's degree or whatever. It's not like a normal topic, right? Like you are very hands-on. And if if you're not hands-on, it's probably not a very good program overall. Which, you know, when I was trying to get my masters, I was I started to like look for a school, I don't know, maybe twenty fifteen, twenty sixteen. And you know, there were there was like three schools that were Technical hands-on, you know, the rest of them were all, you know, in the books. And I'm sitting here like, okay, well, I'm interviewing for people, and they're all telling me I need hands-on experience, right? And like I need hands-on experience with like stuff that like, you know, my small little company can't provide, like Splunk or whatever it is. So my best option is to go the master's route and actually get the the hands-on experience. And you know, for me For me, I kind of need that like formal, you know, training kind of like where it's it's like, Hey, this is the plan, this is what we're working on, you know, that sort of thing. Because if you just leave me to my own, you know, devices, like it'll never get done basically. Russell Spitler: It's it's ironic to think of a master's degree as vocational training, but like that's that's ultimately, you know, what it ends up being, right? Which is Joe: Yeah. Russell Spitler: how do you get that hands-on experience. But you know, there's some programs that that I have a lot of appreciation for and some companies have kind of picked up on this, which is, you know, it's great to get interns for your SOC if you can align yourself with a local, you know, educational institute. And know a few of the big banks do that. There's a couple out of Arizona as well that do that. But those I I really have a lot of respect for, which is how do you balance out that sort of fundamentals with hey, they actually sat and like r you know, did some tier one tickets for three months over the summer, like, you know, that's a that's a feat of strength in its own. Joe: Right. Yeah, it's a totally different ball game when you you know, when when like the pressure is on and time matters and now you have to work through a problem live and you probably didn't know about the problem beforehand or anything, you know. th that's why I like always emphasize with people, hey, like you have to go into a help desk role. Like you have to, you know, get on the phone with an angry customer and figure out how to diffuse the situation and move through it, you know? Russell Spitler: Absolutely. I think those frontline experiences are always formative for for anybody, you know, entering any field to be fair, but particularly in this one where, you know, until you've actually had to set up a new employee's laptop, you really don't know what it means to set up a laptop. Joe: Right, right. That's a really good point. So what what was the problem in the marketplace that you discovered that kind of led you to going down the route of creating nudge security? Russell Spitler: So it was an interesting one. So so my first, you know, foray at out of college was in static analysis. And that was kind of in the early days of AppSec. And then I I moved to running the product and product management team at a company called Alien Vault, which is very much in the security analytics space, which was, you know, how do we detect people breaking into organizations? That got acquired by ATT and there goes my wall. That got acquired by ATT and While we were at ATT, I ended up inheriting a large MSSP practice. We had an MDR practice that we were running there at ATT. And we stepped on seeing the same sort of profile of security incidents, which was, you know, EDR is running great, you know, Zscaler and Palo Alto are running great. And the attacker logged into Salesforce and took all the data. And you're sitting there saying, okay. Like that's a sign. And then my co-founder and I kind of went and started talking around. And what we found was organizations just don't know what technology their employees are using anymore. And while I don't really know if I care if like, you know, developers using Postman. I don't know, maybe I do, maybe I don't, but there's more meaningful use of SAS than most organizations really have awareness of. And the Net impact of that means that your sort of corporate data in terms of your, you know, your IP, your source code, your financials, your customer data lists, all these things are getting propagated across that ecosystem. And the attackers are taking advantage of that. So we sat there saying, like, hey, if no company knows what technology their employees are using, then we've got like a massively underfunded aspect of security that we need to go take care of. So that was really the sort of you know, seed of what got us started in nudge. And to be fair. AI has just been an exponential, you know, increase in the rate of that sort of unmanaged adoption. And you know, today we're sitting in a situation where, you know, the exposure is not necessarily just uploading a customer list to a Dropbox account that you don't know about, but now it's literally like what happened at I think I'm not gonna say the name, a mid-sized bank in on the East Coast where like an employee put their you know, customer information into an unapproved AI tool and they had to file with the SEC as a result of it, right? These sort of implications of not knowing what tech your employees are using and not having a good handle on that have massively increased over the last couple of years. And and really excited that we started working on this problem before that sort of wave came. Joe: Hmm. Yeah, SaaS security is definitely a place that can use a lot of improvement, to be honest with you. You know, I I've focused on cloud security for probably the past, you know, nine years, eight, nine years at this point. And I think, you know, the old mentality was, the cloud security guys will will handle it, you know? But like it's such a different can of worms, honestly. You know, not only is it different, but the task at hand is so large that like it's it's just impossible to stay on top of. You know, like I was working for a large automotive manufacturer and you know, doing cloud security work in AWS, and my manager came to me and said, Hey, I need you to figure out what's going on in in Salesforce. Okay, that that's fine, right? But we have like seven different Salesforce environments, right? Like it is massive. Yeah. The it it's massive. Russell Spitler: That you know about? Yeah. Joe: And I go in there and find out that we have more. And, you know, they're doing different things. They're connecting to different environments that we didn't we didn't know about, you know? Like all these things that increase our security posture significantly that the security team didn't even know. You know? And That's like not a typical thing necessarily when, you know, I have other projects to do, to be quite honest. Like typically that that amount of work, like I thought that I could handle it right off the bat. And I did fine with it in in terms of you know adjusting and being able to get up to speed on it. But you know, looking back on it, it's like, that amount of work, that literally goes towards like a headcount, you know, like that is someone else. Russell Spitler: It's it's I think cloud security is a great way to sort of frame the problem because AWS spent, you know, untold marketing dollars helping us understand the shared security model of of the cloud. But I think what is kind of lost in the sort of common risk profile of SaaS or the risk understanding of SaaS is that we have a similar shared responsibility model with every SaaS provider that we have, which is yeah. They're going to harden the infrastructure and the application as best they can. And they do a decent job, especially companies like Salesforce and Google and those guys. But then there's features in there that have security implications. And then there's integrations that have security implications. And then there's open integration points that, like, you know, it's kind of up to the person on the other side and you to make that decision. But those decisions are not centralized. They're not coming back to like, you know, one DevOps team pushing out into the cloud. It's literally every user of those SaaS platforms is part of the team that holds that responsibility for security on behalf of the customer of that platform. So, just as you said, in the Salesforce ecosystem, Salesforce has done a phenomenal job of adding in security visibility, security features, and they've got, I don't know. Is 30 years of features now of just like normal business use features that they've layered on top. And every single one of them has, you know, there was some product manager in a room saying, well, if the user does it, then it's their own responsibility for doing it, right? And like that was the judgment. But not all the time were those written down. Not every time was that put into the secure configuration guideline. And even when somebody like yourself gets. Handed that secure configuration guideline and seven instances of Salesforce. Now you need to reconcile best practices versus like actual use and figure out when the best practice is going to like prevent you from shipping tires to Guatemala next month or when it's actually going to reduce a hacker, you know, coming in and taking the customer data. And that's a non-trivial task. It's a lot of domain expertise. And more importantly, it's a lot of business context that you need to understand because every single one of these platforms is. Built to help alleviate some business process from you. And there's a whole lot of intertwining between what acceptable risk is, what secure configuration is, and you know, where you're gonna sort of accept that, where you need to lock it down, where you need to move something off, where you need to help a team just, hey, listen, we can't let you have Notion hooked into GitHub anymore because of XYZ consideration. Personally, I think Notion and GitHub is a fine combo, but just as a great example, right? Like those are the types of conversations that you need to have with the business. It's not just an easy kind of checkbox lockdown process. Joe: Yeah. That's a really good point. You know, and I I almost feel like I almost feel like SaaS security didn't really get its like attention that it was required. You know, because let's just say like eight years ago when I was getting into cloud security, SaaS security really wasn't talked about that much. You know, and when when I when I was getting my CCSP cert, Really all that they mentioned on it was, hey, you gotta be aware there's these things called SaaS apps. They have their own configuration, they have their own permissions. You need to be able to go in and audit it, you know, and and recommend different security controls on it, right? And they teach you the basics of the security standards and stuff like that. And it does a really good job of like, you know, putting you into basically any situation and knowing how to adjust it. But You know, back then, like there there was a focus on cloud security, and there still is a focus on cloud security. And then SaaS security like quickly became, you know, a thing, at least in my opinion, from my from my perspective, right? It it became a thing, and then quickly AI came into play and kind of trumped the attention that SaaS security was about to get, if that makes sense. Russell Spitler: I I think there's like an interesting thing, and I and I've had conversations for the last, you know, five, six years with people on this, is the SaaS is the how, not the what. And and when I sort of say that my like, you know, reframe that in my mind, it becomes a lot easier to talk about SaaS security because the problems that present itself that are challenges in SaaS security are the same problems that we've been working on for years, which is kind of. You know, identity governance, whose accounts where, how are they provisioned, how do I deprovision them, et cetera. There's sort of a data security aspect of like where does my data live? How can my data be accessed? What can access my data? there's now of course an AI governance, which is like what models are touching my data and like, you know, how you know, how nice are they when they touch it. and then there's sort of a a excuse me, a non-human identity, which kind of gets, you know. kind of somewhat meshed with that data security. But when you think about it there, the how of SAS as a delivery platform, or you know, frankly, I don't differentiate between like, you know, AI tools and SaaS applications. What's the difference? I log in at a website and they have some of my data, right? Like it's the same thing. under the hood, it's different, obviously, but but you know, the same practical profile. But that's the delivery mechanism. And the approaches that we've taken to solve those primary challenges, those identity challenges, those data challenges, those non-human identity, the posture and configuration challenges are just aggravated when they are delivered through that SaaS stack. And that becomes the sort of reframing that I think really helps people kind of map their risk register to the SaaS in AI security problem, which is this is a delivery technology. This means that we have some new opportunities in order to how we tackle those problems. And we have some new challenges in terms of how those problems need to be thought about. And it's the same mapping that we went through when we went to kind of the early days of cloud security, which was we had a whole bunch of stuff in our data centers. And our first approach was let's sit, you know, ship a bunch of Citrix firewalls up into AWS. And like, you know, you probably didn't have to get your hands dirty with that. But like I remember looking at architecture diagrams with like massive load balancers and citric firewalls and like dozens of instances before it hits the app. And like six months later, people are like, yeah, well, I can just turn all the ports off. Like I don't need to, you know, I don't need to do this anymore. Right. and and it was a big mindset shift when when we started to map those controls to what the environment looks like. But in a similar way, SaaS security is the how. And then the what that we're solving is is a lot of the sort of traditional challenges that we've been dealing with for years. Joe: You want agentic AI and these different models to be able to access your data because you want to make it more readily available, more easily available to your teams to make them more efficient and whatnot. And you want the AI to be able to perform actions on it, you know, in different situations, hopefully with a lot of visibility around it. But then the data security aspect of it comes into play, and it's like, well. Maybe the AI shouldn't see this data, but how do we control it from seeing, you know, everything or control it from not seeing this amount of data, but seeing everything else, you know, or what whatever that looks like. We're now kind of like going into that area, right? And same thing you know, with SaaS security. Because like we're seeing, you know, Salesforce spin up different like Salesforce agents and all these other vendors doing the same thing. I I wonder Because y you know, I I see a lot of these challenges with my customers right now, right? Where they're trying to use these features, they're trying to use these capabilities, but they're nervous about the data aspect of it, of everything else that's flowing into this platform. Russell Spitler: It's it's a you know, I think whenever there's sort of a new technology, I think it's really important to kind of look at the fundamental rules that we've learned in terms of the challenges that we're facing. And then start to ask what's changed now with this technology? And and particularly when you're thinking about AI and data security, you know, our are sort of, you know, tried and true rules is like only provision access for, you know, the data sets that you. Think are appropriate and, you know, only allow them to access those data sets. The place where we've gotten a little bit lax is probably the better word than lazy because it's impossible to keep up, is is we've kind of given we have taken advantage of the fact that the software that we provisioned access for is deterministic. So in the previous generation, you know, there were 14 queries that this particular app would run against my database. And I didn't quite right size the entitlements for those 14 queries, but like, you know, it was pretty close. And like it was a circle and it was a square that was a little bit bigger, and it's fine, right? The reality with AI is we have non-deterministic software on the other side. And we have something that, you know, now kind of acts like a, you know, mid-level employee. I used to say it was a high school intern, but now it's pretty good. And they're gonna like take advantage of all the access they have. And you know, when a user asks a question of that agent or that agent has an objective that it's trying to achieve, it's going to use every resource that's available to it. And it's not one that's going to sort of say, Hey, can I touch the cookies on the table? It's going to wait until it hits a wall before it stops. And that's very different dynamics than what we've dealt with in the past. And I think that puts a much finer focus on how we need to think about. The constraints that we put on top of these platforms. But the biggest challenge that I see today is across the board, the agentic identity model is one that is a delegated model, not one that is a provision model. And what I mean by that is, with the exception of perhaps agents that you've running in your AWS environment, you explicitly provision a particular IAM profile or something for it to access. Most agents are things that you know, a lot of us run them on our desktops, a lot of us run them in Agent Force and Copilot and, you know, actually very popular is access like Zapier and Tines, like those are big agentic platforms, but you might not think that. And what they've done is essentially said, I already have a workflow in Tines. And if I just like put in this new block in that workflow and I give it a little brain, it'll be a hell of a lot better at achieving its task. But what it's done is delegated the access that it's always had, but now given it the sort of autonomy to be able to go really exploit that access as fully as possible. And those are the big challenges that I kind of see today is like the identity model that we've given these agents is really not that sort of fine grained control that most organizations are expecting those agents to operate under. And they have a lot more dynamic behavior than what we've had to deal with. past, which sort of really exploits that disconnect in a in a meaningful way. Joe: Hmm. Yeah, it's like the capabilities of agentic AI and just AI overall rapidly expanded and grew, you know, from like like what you said. Like it used to be a non threat, a non issue, a high school, you know, admin, quote unquote, to now it's mid level where you know you do actually have quite a bit of access. You do actually have of quite a bit of knowledge. of you know things that can go wrong and things that can go right and all that sort of thing. Right. And really like the new attack plane is like let's just break into someone's, you know, agent control plane. If we can get to the thing that's controlling all the agents, we can get in to anything in your environment. Russell Spitler: Well, and not trying to give anyone any ideas right now, but like, you know, platforms like Replit and Lovable and you know, all of those things that have these sort of, you know, quickly coded applications that then were given OAuth grants and ability to provision identities and access various, you know, data sets. Like that is just a a, you know, gold mine in terms of access into environments. And that's that's largely the pattern. We've seen, you know, in the last couple of major breaches, the clue breach, the the Salesforce, drift, excuse me, I don't want to say Salesforce, the drift breach that compromised Salesforce, data resident in Salesforce. but drift and clue were were both those cases. And even the Vercell app was a similar profile where, you know, an attacker was able to compromise the secrets related to an OAuth client. And so then was able to extensibly make API calls on behalf of that OAuth client, which customers had used to provision OAuth grants across Salesforce ecosystems, and they stole that information out of it. When we start to think about those types of attacks, this is just the tip of the iceberg because that is a that is a very opportunistic target for somebody who's looking for escalating their access into an environment. And particularly if I can just go down the supply chain until I find the person with front door open, grab their OAuth grant, start working the way up the chain. It's it's a meaningful progression and one that we've seen a few times. Joe: Yeah. Yeah. That is that's a scary thing, right? Because AI is at a really capable place right now where you can build really cool stuff and quickly, you know, turn it around into like a a you know customer bought and sold, you know, product, right? And that opens the door to a lot of people that used to, you know, be gated by okay, I have to either know how to d be a developer or I have to hire a developer or I have to do X, Y, and Z to, you know, do all these different things and connect it into the different platforms and whatnot. You know, like I I'm in security. I've been in security for, you know, 12 plus years. And like I didn't know a lot of this stuff. Like I'm building like, you know, my my my side, you know, pet project is like building an app that can, you know, grade Pokemon cards, right? Like From just taking a picture of them and give me an accurate like grade estimate. I thought it would be really cool to do something like that. Well, 95% of what it's doing, I never would have thought about that. Like that's gated knowledge. Not that I couldn't gain it, but it's gated in terms of like, okay, either I gotta learn it or I gotta hire someone that has it. Well, now I can pay $100 to Claude and Claude's working it out for me. Maybe right or wrong, it'll more than likely. accomplish the task at the end of the day, but whether it does it securely is a whole other whole other can of worms. Russell Spitler: It's it's a it's a scary can of worms, to be fair. And and that's not to say that I don't think that Claude can develop secure code, but the bigger question is, as we all well know, is there's a lot of steps along the way, regardless of whether the code is great, like you know, you deploy it on a server and you forget to, you know, close the admin portal, like you know, like That has some implications. Like, you know, you hard code your passwords in there. That has some implications. There's a lot of these pieces of the puzzle that may or may not be viewed as essential steps for accomplishing the objective you've given the model. And certainly there's a lot of platforms. And you know, I was pleased to see last time I was messing around on Replit, like they did do a little bit of a security analysis of the code that was being run. I don't or at least they said it on screen, I assume they were doing. You know, and and those those considerations are starting to creep in, but there's a lot of frankly, just tribal knowledge in the security community that sometimes gets codified, sometimes does not. And certainly as we look at an explosion of apps, and especially apps like kind of maintained by a non-technical audience, there's a lot of places where like those security trade-offs might not be front and center. And or well understood. And and those are, you know, easy to find examples of, especially on Twitter. There's always that like, I vibe coded an app and I didn't realize I left my like private stripe token in there. And, you know, like all this kind of inane stuff, which the models will get over after a while. But then there's the more serious vulnerabilities. And those I think will probably be resonant for a long time. And the architectural level disconnects, which will be even more Challenging for for organizations to try to deal with. Joe: Yeah, that I mean it's turning into an opportunity for like posture management, you know, at at various levels of AI, you know, which you know, personally, like I was familiar with Nudge as like the SaaS platform, right? And then I learned that you guys were pivoting, or maybe not even pivoting, adding in AI capabilities to better secure it, right? And you know, to me I always felt like that was a natural pivot versus even another company, you know, starting from scratch, going into the the AI space, AI security space, and trying to build it, you know, from the ground up. I always felt like, you know, the the SAS platforms would be better positioned technically, you know, from that technical perspective to be able to address these problems, you know, up front in a quicker, more efficient way. Is that Is that accurate, do you think? and it's probably like a self serving question, right? Like cause obviously Russell Spitler: I yeah. Joe: you'd probably say yes no matter what, but Russell Spitler: Yeah. The the answer is obviously yes from my biased point of view. But but the thing I would sort of stick take a step back, and I think we can do an objective yes as well is, you know, there's the empty room problem, which is if all of these AI tools came out and they all had pre proprietary protocols and you know they were all closed ecosystems and they couldn't interact with the rest of the internet, then they'd be pretty useless, right? Like, I mean, that was the first version of ChatGPT, right? Like I could ask it questions and it couldn't really do anything. I couldn't even look at web pages, right? Like, you know, it was kind of cool, but like it wasn't really a business tool. But the reality is, is these tools are most effective when they can interoperate with your data ecosystem. And the reality is people's modern data ecosystem is SaaS based. You know, your source code lives in GitHub, your customers live in Salesforce, you know, your finances live in Net suite, whatever it might be, the reality is your data lives in that SaaS ecosystem. And so AI naturally has massive integrations into that existing business ecosystem that is driving so many of these companies out there. And so when we look at AI coming into the market, first of all, from a technical profile, it looks like every other SaaS application out there, right? There's an authentication. I sign in with Google, I use SSO, I use a username and password. I get in there, I start clicking OAuth grants, I generate API keys, and I do some stuff with data, and some of them even store data for me, right? Like all that, like if you just describe that, you know, in abstract, that sounds like Airtable, that sounds like Notion, that sounds like you know, GitHub, that sounds like everything else out there. And when you think about, okay, now how do I secure AI? How do I govern AI? How do I sort of control the use of AI? There is the direct interactions you have. With ChatGPT. And then there's sort of the indirect interactions that, you know, Anthropic or ChatGPT has on behalf of that user with the rest of your ecosystem. And this is the piece of the puzzle that I think a lot of people are just starting to wrap their heads around. This is when I hook Anthropic up to HubSpot and I ask Anthropic, hey, you know, how many new customers did we talk to yesterday? What it's doing is it's taking that query. Giving it to a model that's running in some data center somewhere, you know, drinking all the water or whatever we're worried about these days. And then it's making, you know, a TLS connection from that data center over to HubSpot's data center using the OAuth protocols to exchange and secure, you know, the delegated authority that I've given it. And that data is going directly from HubSpot back to Anthropics data center. It's chunking it away and then it's giving me the response, right? A lot of people's, you know, sort of initial guess. Is like, well, it's it's a native tool on your desktop. So it must be like reaching out to HubSpot from your desktop and reaching out to Claude from your desktop, and all of that stuff is being munged locally and then presented to you. But this isn't really how these products work. And that's the big shift that a lot of people need to make because the first sort of foray that we took out there when we started talking about AI, and like you see this in the first generation of companies, is like, Here's a new deal P a web proxy that's like AI native, right? And like we we know how to look at AI protocols and know when you're querying AI. But that's not really the sort of major concern these days. The major concern these days is who's that employee? Who's giving it access? Who's delegating that authority to talk to other services on its behalf? How can I disrupt that delegation of authority? How can I control what access we're provisioning it? It's a little less about, you know, can I sit there and be a traffic cop, especially when you can't sit on the side of the highway. between AWS and and anthropic. Joe: Hmm. You know, can can you talk a little bit about how how it's achieving that, how it's able to get that visibility. because like there's a lot of moving pieces with it, you know, like this isn't a normal I I don't know. I I just try to think of other integration points for other domains of security, right? Like it's it's like the endpoint or the browser, you're doing a proxy for the network traffic, you know, all those sorts of things. But AI and agentic AI touch basically everything now, right? I mean, basically every avenue that you would have secured, you kind of have to have visibility into those different avenues or those pathways, right? How how is Nudge addressing those different pathways? Like for instance, you know, the browser. Right, like I could just go to the browser, pull up Claude or Chat GPT, and I'm interacting with it and now it's creating different things on my behalf and whatnot and connecting it all up. Where where are those integration points to get that holistic view? Russell Spitler: Yeah. So so two probably different steps here. The first is you need to know what's out there before you can make any progress. Because you know, you can go, as you said, like, you know, let's go waste three months securing Claude and then you go and find out that half your employees are using open AI. Like what did you did you reduce risk or not? Right. so having that visibility is is basics one on one. And and the way that we've approached visibility is is kind of a side channel attack. be fair, which is we kind of recognize that the sort of traditional network control plane and the sort of traditional kind of endpoint, they have their limitations, which is, you know, I need to be in line and I need to observe the activity before I can report on it. And we've all been through kind of like, you know, sassy rollouts that take 18 months and like you get almost done and you're kind of patting yourself on the back and saying, I'm not going to work on this ever again. And Then you got to wait and actually see what happens. So we we tried to take a different approach. And what we recognize is there's one design pattern that every AI and SaaS provider has, which is as soon as you register for an account, the first thing that's going happen is that provider is going to try to drive product usage. It is their economic motivation to get you to use the tool more. And the only way to communicate with you that's universal is email. So what we do is we tap into the enterprise email stream. And we look back as far back in history as we can, and we will piece together all these little minute signals. It might be like, hey, you have a pull request review in GitHub. Hey, you're out of you know, tokens on anthropic, or you know, here's a usage warning and notion. All of these things we can piece together and we can use that to identify what accounts which employees have across what applications. And that detail comes back in, you know, about an hour. And I can give you a dashboard that shows you with high confidence exactly what's out there, what instances are being used, like those Salesforce instances you're talking about before. Here's the other three that you didn't even know about, right? you know, which ones are free, which ones are paid, you know, which users are accessing it. And that comes back immediately. But that's one data point. And that's a strong data point that gives you historical, that gives you sort of off network. There's a lot of advantages of it, but it's not the only way to get visibility. The second one is really, and this really kind of emphasizes the the employee centric focus that we have. And I'll I'll circle back to that in a second. But the other one is we do sit in that browser and we'll, you know, install into Chrome, Brave, you know, Edge, Dia, Atlas, you know, the browser, everything that's out there is Fierry Firefox. And when you pop open that browser, we'll know who you are. And we can observe the interactions that you're having with these websites alongside the network traffic that that website is generating. And there's a critical detail there for kind of the technical audience out there is like the modern architecture, and particularly for AI apps, is increasingly, you know, it used to be sort of like public cloud and pass was the architecture, but now it's increasingly SaaS on SAS, like super base and like, you know, Okta or excuse me, auth zero and like. All of these little microservices that you can embed into your app that make it super easy to get a very functional capability very fast. And so when you're sitting at that network level, even at the endpoint, all of a sudden you're seeing, you know, I have like 15 browser tabs open. That probably means about 300 network connections that are going off my laptop right now. And it's really hard to piece back together, these 15 are from, you know, you know, Salesforce.com. Or these 15 are related to that interaction that user just took. On this particular tab. So sitting in that browser allows us to kind of associate that user action with the actual network inspection. And of course, we can analyze the data that's going into that user interaction, which gives us a really rich spot. And then the final piece of the puzzle, which is probably the most variable, is the actual administrative APIs of the AI or the SaaS providers. And there are some platforms which are very mature, and I think Salesforce certainly deserves its credit for being a very mature API. All the administrative actions, all the details, everything's available through that API. Anthropic also has a very mature API. You gotta pay through the nose to get access to it. But like, you know, it's got a great set of capabilities and it's enterprise compliance API. And we hook into the APIs of these providers to get that next level of introspection. How are they configured? You know, what other non-human identities might be, you know, configured within there? Are there web hooks pushing data out? Are there external contractors provisioned in there? And we get all of those additional details to kind of wrap it together. So now we have three unique vantage points. We have that sort of, you know, side channel visibility into what accounts are out there. We can use that to start to bootstrap what we're actually going to observe. what we're actually gonna observe as they're interacting with the application. And then we can relate that to what data we're actually seeing from those vendor APIs, which again is highly variable depending on the vendor. And that gives you a very comprehensive picture of not only what people are using, but also how they're using it and where you have, you know, things that you can do to meaningfully reduce your risk. And that gives you a really strong picture as you go forward. The one other thing that I would sort of comment as we think about that picture is exactly where how you kind of frame the question, which is when we think about AI and all the various places it touches and what it can do, you're absolutely correct. It it starts to look a lot more like an employee than a piece of software. And that's a big piece of the puzzle. Joe: what's maybe the next phase of this AI journey or explosion that we're seeing right now in the marketplace? You know, because thinking back twelve months ago. You know, agentic AI was kind of like very new. You know, I think the first time I heard about it might have been last May, last April, you know, right around that time frame. And now it's like everything that everyone is talking about. And it's a huge security risk. And you know, it's definitely a challenge from a security perspective to like stay on top of it. What what do you think the next iteration or evolution of the space is and you know, maybe how is Nudge thinking ahead and preparing for that to deliver, you know, enhanced security capabilities to your customers. Russell Spitler: Yeah. So so I think there's really two pieces of that. One is we're seeing a massive acceleration explosion of sort of the risk surface related to employees using technology. So where in the past we used to quote something like 30 OAuth grants per employee that has quickly rose like dramatically increased to about 88 per employee that we see. And now instead of about 16 that had data access, there's about 33 that have data access. So it's doubled the exposure of technology that's accessing corporate data on behalf of each one of your employees. And that's average per employee. That's not saying you have 88 OAuth grants in your organization. If you have a thousand employees, that's 88,000. So the scale of this is one where we've really reframed our mindset. Which is we've always provided the capabilities of like, hey, if you really want to go dig in and investigate an oil with grant, I'll give you all the detail in the world to go make that risk assessment. And I used to do that a lot. I would go in a customer site and kind of like walk through it with somebody and it take me about 15 minutes to get it done. I was pretty good at it and like seen a lot. You know, for somebody who probably doesn't have as much practice, it's 20 to 30 minutes. But now you multiply 30 minutes or 20 minutes, if you want to be optimistic, by eighty-eight, thousand, it's still more time than you got. If you want to go home and see your kids, right? So what we did was we we repositioned that and we said, okay, well, let's if AI causes problem, can we use AI to solve this problem? Right. And so we recently introduced an agent that we trained on all the best practices we know about how to analyze that OAuth grant in context. So we look at the context of the user, we look at the context of the technology, is like this is an app that's being used, is it approved? Has it had a TPRM process gone through? Like, does it have its posture sort of locked down? And we take all of that context, you know, hey, does this user need access to this app? Is the data it's giving it access to appropriate? All of those factors go into play. And then our agent will assess that and it'll say, hey, listen, I need more information from that end user. And if that's the case, we'll actually reach out to that end user. The agent will and get more information and then improve its analysis. And then it'll come up with a recommendation of like, yeah, we should allow this. Or We should revoke this. And so we now have something that what used to take 20 to 30 minutes in a conversation now is a closed loop and will happen within 15 seconds of that OAuth grant coming into the environment. And so when you're thinking about that sort of onslaught of non human identities and those OAuth grants that you now need to go take care of, we now have an agent that will just take care of that for you. So that's an A an idea in a way that we're sort of taking AI to deal with this sort of modern ecosystem. Like it's really valuable to be able to. Take that knowledge, put it into an agent and deliver it on top of our platform with access to all the data that we have to operate effectively. And so I think that's going to be the first step of many as we go forward of instead of somebody coming and running the program with the tools and the facilities that we have within our platform, rather set up your policies within our platform and let the program be run for you. And we'll just bug you when we need more input or exceptions, or there's an edge case in your policy that we want to clarify. Joe: That's interesting. That's I mean it's there's so many different like methods of solving this problem, you know, and like everyone's kind of doing it a different way, but that sounds like you know, a really efficient way of approaching it. You know, I I think about like container security overall, right? And when people first started to, you know, look look into it and actually actually begin providing like products for it. we saw maybe the first iterations of it was hey, here's this secured image for your environment. Run this, deploy this, you know, and and use that in your environment going forward. And then the way that you described it, it kind of makes me think about how we started approaching the container security problem, right? Of okay, these things are, you know, insecure. Let's build a secure image that everyone can use and build their containers off of. And it it was great, but it's not very scalable at the same time, which I don't think would be the same problem from the AI agentic AI side. Right, I don't think that that would be a problem. Like we saw with container security, where it's like, okay, it's great 8 a.m. Well, by noon there was a vulnerability in this package. Now what? I have to re push this container with this thing that you updated, hopefully. It turns into a a bigger, you know, workflow issue. Right. and with with a gentic AI, it's interesting that we're we're kind of taken a similar approach, but that scaling problem seems to be mitigated because you're solving the problem at the root core and you're not really relying on people necessarily to like let's say, you know, use that image of an of what an agent looks like. You know, you're kind of solving it at the core of the actual solution and then moving forward with it. Russell Spitler: Well, and and even to kind of you know build on that a little bit more, you know, that that agentic piece is is an important accelerator. But Joe: Mm. Russell Spitler: really the end goal is how do I get that user to not grant the OAuth grant I don't want them to grant, and to like only grant ones that are gonna go flow through and say, okay. it's an important backstop. And that's really kind of the next piece of the product that we have, which is those in-browser engagements. So, you know, you go to OpenAI and you read blog posts about LLM creation, no problem. You go to sign in or prompt, I'll pop up in the browser, take over the screen and say, hey, listen, Anthropic is the preferred provider here. Click this button and I'll get you to the private instance that we are hosting for Anthropic. And those types of behavioral redirects make it so that the right path is the easy path. And that's really where you start to see a scaling solution to this problem, where if we can head off that behavioral challenge in the in the first place, then we can reduce the amount of work. It's still going to be a massive amount of work, and I'm glad we have agents to help with, but we can get to a place where we can start to drive people to the places we want them to go, make it easier for them to do that. And especially in a dynamic world like we're living in. something that can automate those engagements and deal with those at scale is is a critical piece of the puzzle. And that's that's a really kind of exciting piece of how we view the solution to this problem end up being, which is we're gonna change the behavior of employees. We're not gonna do that through more training. We got to sit there with them and get them to the right place when they're making those decisions. Joe: Hmm. Yeah, it makes a lot of sense, honestly. Well, you know, Russell, we're we're right at the top of our time here, un unfortunately. but it's been a great conversation. I really enjoyed, you know, kind of picking your brain and hearing, you know, what made you go down this path, you know, initially, right? Like what made you wanna start nudge and go this route with it? Like it was a great great conversation. Russell Spitler: Well, Joe, thanks for having me. I appreciate the time today and and always love talking about this stuff. So thanks a lot. Joe: Yeah, absolutely. Well, before I let you go, how about you tell my audience where they could find you if they wanted to connect with you and where they could find Nudge if they wanted to learn more? Russell Spitler: Yeah, absolutely. So always available on LinkedIn. So Russ Spittler at LinkedIn, you'll you'll find me. And then certainly on Nudge, nudge security.com. And we are eager to chat with you about the problems that we're seeing and see if we can help you out. Joe: Awesome. Well, thanks everyone for listening or watching this episode. I'll be sure to add all of the links that Russ mentioned in the description of this episode. Be sure to go and check it out. It's pretty pretty awesome solution. I like it a lot. and that's you know why I wanted to partner with Nudge. So thanks everyone. I hope you enjoyed this episode.