For every human being inside your organization, there are 82 others you've never onboarded, never reviewed, and probably can't see — machines, service accounts, tokens, API keys, workloads, and now AI agents. 82 to 1.
I opened this episode with that statistic. My guest's response: it's conservative. Inside a large financial institution, she puts the real ratio at four to eight times higher.
The attack surface didn't grow. It went invisible. This conversation is about making it visible again.
In The Chair
Shobha Jagathpal — formerly Managing Director leading cyber and risk functions at Morgan Stanley, with nearly 25 years across security, engineering, architecture, identity, cryptography, and cloud, built at Walmart, RSA, Oracle, Accenture, and Wipro. Co-chair of the OpenSSF Public Policy Committee, working directly on US and EU legislation around SBOM and SLSA. A mentor of women into the field through InfoSec Girls and WiCyS.
THE BRIEF — 3 Things Worth Your Time
1. You're governing humans while the risk moved to machines. 88% of organizations still define "privileged user" as a human — even though 42% of machine identities already hold privileged or sensitive access. Headcount stays flat; the machine-identity population compounds. The hardest to even find? OAuth tokens quietly granted to SaaS tools — "shadow SaaS" that lives at API-to-API trust and never shows up in a network scan. So what: If your privileged-access program only counts people, you're auditing a shrinking fraction of your real exposure.
2. Traditional IAM assumes a train on a track. Agents drive off-road.
Her analogy: classic IAM is a train on rails — you know the start, the path, the destination. The answer is binary: can this identity read file X, yes or no? An AI agent knows only the source and the destination, then figures out its own route. Probabilistic, not deterministic — and you may lack the visibility to trace how it got from A to B. So what: The question security has leaned on for decades — is this allowed? — no longer describes what an autonomous agent actually does.
3. Treat AI agents like high-risk human contractors. The bridge between governance (ISO 42001 gives you the control plane) and enforcement (identity gives you the data plane): scope tightly, forbid long-lived sessions, limit context, and demand the five-why’s — who did what, when, where, how — traceable across infra and app layers. So what: Governance frameworks tell you what good looks like; only the identity layer actually enforces it on an agent in motion.
Also in this episode
- The first 90 days: build an identity inventory, then kill hard-coded credentials and rotate secrets — the two moves with disproportionate return
- The supply chain has turned from accidentally buggy to deliberately weaponized — 454,000+ malicious open-source packages in 2025, including a self-replicating worm
- Why a 200-question vendor questionnaire is no longer good enough, and where SBOMs genuinely reduce risk vs. compliance theatre
- The EU Cyber Resilience Act (Dec 2027) and India's DPDP rules — why "wait and see" isn't an option for Asia-based leaders serving global firms
- The one board metric that unlocks budget: mean time to contain an unmanaged identity exposure
One line worth stealing
"Identity is no longer just an access problem. It's becoming the nervous system of the digital world." — Shobha Jagathpal
Watch the full conversation
The full episode goes deep on supply-chain risk, SBOMs, board metrics, regulation, and a rapid-fire round — including her pick for the one metric she'd delete forever.
▶ Watch on YouTube: https://youtu.be/UgkAIR45Ghk
Join the conversation
Her first 90-day move is simply an identity inventory — knowing what exists. So here is my question to you: if you ran that inventory tomorrow, how confident are you that you'd find every non-human identity with privileged access?
💬 Add your take here
Before you go
If this is your kind of thing, you have the super-power to write to ‘[email protected]’ with a security, privacy, or technology leader (or enthusiast) you would want to see in the chair. I read every one.
— Ashish | CISO Chair™

