What happens after an AI agent presents valid credentials and enters your business systems?
In this episode of The Business of Cybersecurity, I speak with Spencer Young, Senior Vice President of International Markets at Delinea, about why authenticating an AI agent is only the beginning of the security challenge.

Spencer has spent 34 years in IT and around half that time in cybersecurity. His experience covers secure software development, vulnerability testing, application protection, data security, and identity security.
Our conversation begins with the changing economics of cybercrime. Spencer says attackers increasingly prefer stealing or compromising legitimate credentials because logging in can be cheaper, faster, and easier than forcing a route through network defenses. He estimates that over three quarters of attacks involve a compromised credential somewhere in the chain.
AI agents add speed and scale to identity risk. They can access applications, databases, financial systems, development tools, and infrastructure while performing dozens of actions during a single session.
The danger is not limited to an agent being denied access. An agent may be fully authenticated and possess valid permissions while taking an action the organization never intended.
Spencer offers the example of a finance agent created to support payment processes. Hidden or manipulated instructions could cause it to change payment profiles and redirect money while appearing to operate as an authorized identity.
This is why Delinea is focusing on runtime authorization. Rather than approving an agent once and allowing every subsequent action, the approach evaluates each proposed tool call, database query, or SSH command before it runs. The action can be allowed, blocked, or referred to a person for approval.
We also discuss how least privilege applies to autonomous systems. Spencer recommends providing credentials only at the moment an agent needs them, limiting access to the specific task, and revoking those privileges immediately afterward. The agent never needs to see or retain the credential.
The research figures Spencer shares reveal a concerning difference between confidence and control. He says 80% to 85% of respondents feel confident in their ability to discover nonhuman identities, while only 30% validate nonhuman identity use and AI activity in real time.
Delinea now works with over 9,000 organizations, including over 60% of the Fortune 100. Spencer says regulated industries frequently demonstrate greater identity security maturity because external requirements encourage continuous controls rather than reactive incident response.
However, technology cannot decide an organization’s risk appetite. People must define what the agent is expected to do, which actions require approval, where it must stop, and who is accountable when something goes wrong.
Could your organization detect a properly authenticated AI agent taking an inappropriate action before that action executes? Listen to the episode and share your thoughts with me.
Useful LInks
Learn more about Delinea

[00:00:00] The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And Denodo applies guardrails across your entire data estate. By aligning your company's data infrastructure under one system, these guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more.
[00:00:33] What if an AI agent has valid credentials but uses them to take action that nobody intended? Yeah, it's the stuff of nightmares right there. And my guest today is Spencer Young. He's the Senior Vice President of International Markets over at Delinea. And he joins me here on The Business of Cybersecurity today to explain why connecting securely is only the beginning.
[00:01:01] Because attackers, well, they increasingly prefer logging in with compromised identities, which is so much easier than forcing their way through a network perimeter. And it's autonomous agents that can amplify authorization gaps and do so at machine speed. So my guest today will explain why every database query, tool, call and command might need approval before execution.
[00:01:31] And he will also discuss how short-lived credentials reduce exposure and why legitimate access never actually guarantees safe behavior. So if you're interested in joining me in exploring the confidence gap, I think you're going to love this one today. And we'll also mention Delinea's research that found that 80 to 85 percent of respondents felt that they were genuinely able to discover non-human identities.
[00:02:00] And only 30 percent were able to validate their activity in real time. This is a gap that deserves every CISO's attention. And with that scene perfectly set, let me introduce you to my guest right now. So thank you for joining me on the podcast today. Can you tell everyone listening a little about who you are and what you do? Hi, thanks, Neil. So I'm Spencer Young. I'm the Senior Vice President at Delinea of our international markets.
[00:02:27] So I look after our EMEA and APAC regions. I've been with the company for just shy of five years now. It's coming up to the end of my fifth year. Been in IT for about 34 years, which is always painful to say when you realize how old I actually am. But I've been in cyber probably for about half of that time. I started in secure software development. So I was leading teams that were building secure applications for things like financial trading systems, patient record systems for the NHS.
[00:02:56] And then I moved into code vulnerability testing tools and then application and data security before I landed at Delinea in identity. So and I think in reality, like so many cyber practitioners, I quite like the adversarial nature of what we do. And so many folks, certainly at Delinea and the people that, you know, my peer group, I think a lot of us feel that way. So it's a great space to be in and one that's obviously changing very rapidly around us right now.
[00:03:24] Well, I appreciate you taking the time to sit down with me today and dig a little bit deeper on identity, which has become the new security perimeter. And despite that, attackers seem to be focusing less on breaking in and more on simply logging in. So how have you seen the threats, threat landscape change over the last couple of years? And why are identities now the easiest way into an organization? It's a great start point question, Neil. Thank you.
[00:03:52] I think what's changed over the last couple of years is that hackers and bad actors realized fairly early on, actually, that it's now easier, less expensive and faster to gain access to systems through compromising legitimate credentials rather than trying to brute force a way in. You know, the fact that, you know, bad actors and we forget this sometimes they monetize on data. Right. And that's ultimately what they're after, whether that's to extort or disrupt.
[00:04:20] But I do think the economics of the attacks have changed for sure. You know, they don't need to exploit the perimeter and spend time and money trying to do that if they can get legitimate access into systems. And I think, you know, and I know we're going to talk more about it in this session. You know, the recent breaches in things like HivingFace and OpenAI and Anthropic and Meta are showing really how AI is making those attacks even faster and more sophisticated than they've ever been.
[00:04:48] And yet, you're right, identity, even over the last couple of years, has maintained and still is the main way in. I mean, it's still over three quarters of the attacks that will involve some form of compromised credential along the way. Yeah. And just to throw into the mix here, AI agents, they're creating a whole new category of digital identities. And I must admit, as an ex-IT guy, it does make me a little nervous.
[00:05:15] Individuals, entire teams and an entire organization are creating hundreds, if not thousands of these agents. So what new risks do they introduce? Why is securing an AI agent fundamentally different from, let's say, securing a human user? Yeah. I think it's, first of all, I don't think the agents themselves introduce new security risks, per se. But what they do is they instrument those risks that are already there.
[00:05:41] And they can do that at a speed and a scale that we have just never contemplated or seen before. I think that that's the main difference in terms of the business issues that get created for companies and government organizations when they think about securing a gentick. I mean, if we think about it in terms of your question around how it differs from a human, human has a pretty defined role.
[00:06:03] Right. And for those of us in the identity security space, we tend to think of in the early days, the first sort of roles that we would secure would be those IT administrators. You know, the ones that had access to the keys to the kingdom, they had access to all the systems, all the databases, all the applications. And then you had certain privileged business users. So board level kind of folks, senior people that would have access to things. And then along came machines. So servers would get access to systems and you'd want to make sure that you secure those.
[00:06:31] I think the difference with a gentick is that whilst that role, you know, what they are designed and set up to do is quite defined. They can use legitimate access that they're given to take the wrong actions at machine speed. Good example is, you know, a finance agent, for example, that a finance team would set up to help them with their payment systems could, for example, have hidden instructions put into by the agent or to the agent to change the payment profiles and start moving money around.
[00:07:01] Places where it shouldn't move money. So I think and doing that all the while as if it is a fully authorized identity doing exactly what it's supposed to do. I think that's one of the differences. And whilst through our own research, for example, at least 80 to 85 percent of the companies we talk to say they're very confident in their ability to discover non-human identities. Only 30 percent of them actually validate non-human identity usage and AI activity in real time.
[00:07:30] And that that's the real key to it is the is being able to watch what that agent or any identity, frankly, does in real time. It's the difference, that difference between authenticating something, whether it's a human or a non-human or an authentic agent or a model. Authenticating them once is just not enough. We've got to be able to effectively authenticate. Think of it this way. Authenticate it with every single action that it's taking.
[00:07:58] Is it actually authorized and approved to go and access that system at that time? And what was it originally designed to do? You know, agents have intent embedded within them, right? The humans say this is what we want you to do for us. And agents obviously want to please us and they'll go and do the action that we've asked them to do. And they have no guardrails set with how they go about and do that. I mean, the hugging face breach was a great example of that. The agent actually didn't do anything wrong. It did what it said it was.
[00:08:28] It did what it was asked to do. And it wasn't given the guardrails to prevent it from accessing the systems that it chose to access to complete the task. And one of the reasons I was excited to get you on the podcast today is having read how Delineo recently introduced runtime authorization for AI agents. So rather than simply controlling who or what gets access, you're now evaluating every action that an AI agent takes.
[00:08:55] So for people listening, tell me a little bit more about why that shift from authentication to authorization is so important. I think it comes back to what we've just been talking about. It's that authentication is typically that one-time process. And that one-time process will absolutely be able to answer who or what connected to something. What it does after it's had done that connection is the piece that's the missing component of it.
[00:09:23] And what runtime authorization does is it determines whether every proposed action, so before the agent's going to do anything or any human for that matter. We have customers that have runtime authorization in place for their human identities as well as for machine and for agentic.
[00:09:40] And so it then, as I said, makes sure that we are preventing access at each action that it's trying to take rather than just saying it has the credential, it is able to access everything that that particular identity is able to do. I mean, a single agent session, it comes back to this thing we were talking about earlier about the speed with which agents can use above an IT administrator or a human. A single agent session can involve dozens of tool calls to different things with different task profiles.
[00:10:09] So you have to block each action or you have to elevate the privilege on each of those actions at an individual basis. And I think, you know, the way that we think about it quite uniquely as a company right now is we almost, we take away the notion of any standing privilege or access to the credential that typically a human would use to get access to things. And we inject the credential at the point that the agent is about to get access to the thing it's going to get access to.
[00:10:39] As soon as it's done that action, we remove it and revoke it and the agent never sees it. So if the agent's compromised in any way by a bad actor or a hacker, they're not going to be able to find the credential or the password that was associated with that agent. And I think that to me is the real value, certainly with all the current conversations we're having with our current customers, our prospective customers and the industry.
[00:11:05] You know, any industry event you're going to right now, Neil, I know, you know, this is the topic of conversation in terms of how people secure it. And customers are, and companies and even tech companies, we're all at different varying levels of maturity with how we think about securing AI and how we think about using it.
[00:11:22] To my mind, if the only thing an enterprise did or a government department did was ensure runtime authorization for the agents, I think that goes a significant way to solving that. You know, how do we work out what it's doing and make sure that it does what it's supposed to do and not step out of line? I think that's probably the most significant impact that that could have on any company right now. And something else we often hear of is least privileged, especially in cybersecurity.
[00:11:51] So what does least privilege actually look like when we're now dealing with autonomous AI agents that are making decisions at machine speed? Anything you'd like to add on that to? Yeah, first of all, as you just said, first of all, you have to be able to secure them at machine speed. And that's been a big shift in the market. As I said earlier, you know, when Delineo was first created as a company, you know, our main focus was on securing, you know, highly privileged individual humans.
[00:12:20] And they work at human pace. With autonomous agents, as I said earlier, the best way to enforce least privilege or zero standing privilege or whatever other acronym the industry wants to come up with, and we're good at doing that. We love our acronyms is to just make sure that, as I said earlier, those credentials are injected just in time, scoped to the task that the agent's been asked to do. And then they're revoked as soon as that task is completed. But at the end of the day, it still is.
[00:12:47] And Art Gillard, our CEO, was interviewed, I think, this week, and he made the commentary around it is still beholden on human beings to define the policy and the risk boundaries of those agents around the controls. We can provide, and technologies like us can provide, the controls that enforce those things automatically and do that at machine speed. But it is still beholden on humans. Humans are still the most important factor in this around it's us that set the boundaries. We set the task for the agent.
[00:13:17] We should also be setting the boundaries that it's able to go stay within and what it cannot do much more clearly than we've been doing today. And, of course, what we're talking about is nothing new here. We've already seen incidents where stolen credentials, synthetic identities, and authorization gaps have been chained together into successful attacks. So we've seen examples of this already.
[00:13:42] And for people listening, what lessons should security leaders take from these kind of breaches that we've already seen? And where are organizations still possibly leaving themselves exposed from what you're seeing? Well, I think that comes back to the fact that with those breaches that you mentioned, it was all predicated on that one-time authentication. I am an agent and I wish to do this.
[00:14:10] I'm given the credentials and the authorization to go and do anything from there onwards and be ungoverned. And I think those successful attacks that have combined together have always started from legitimate credentials that it was given. And then it's able to get excessive privileges as it goes through that process and it uses gaps in how organizations control their logging capabilities, etc.
[00:14:35] And the key point really is that that legitimate access doesn't mean that it's safe access. Security teams must make sure that they validate continuously what that identity is doing, whether it's an authentic agent or a human. It actually shouldn't matter. It really shouldn't.
[00:14:54] But again, so many companies that we help and that other identity vendors in our space help companies do is we help them reduce exposure through things like long-lived credentials that have just been sitting in systems for so long. The agents will find those. If it helps them to complete the task they've been given or it speeds up their ability to complete that task, they'll go and look in those places and they'll utilize it. That's not them doing anything wrong or bad or very deliberate. It's just them completing that task.
[00:15:24] So again, it comes back to that one-time authorization does not secure an agent working at that type of pace and velocity. And a quick look online revealed that Delinean currently works with more than 9,000 organizations, including 60% of the Fortune 100.
[00:15:44] So I'm curious, looking across that kind of customer base and that kind of scale, what is it that's separating organizations that are successfully managing identity risk from those that are constantly just firefighting and reacting to the latest? That's a great question.
[00:16:59] The uptick in investments from the retail industry over the last 18 months was a direct result of the ransomware attacks on four or five of the major retailers in Europe that took place, I think, around a year ago. And now we're seeing the retail industry is becoming actually very mature with how it's thinking about the way that it secures all manner of identities.
[00:17:21] But it still comes back to that thing we started at, which is their focus is on ensuring that any identity cannot get access to the data on which it will want to monetize on. And I think that's what separates the most mature from those that are catching up. There's certainly industries that are catching up, for sure. But I think they're not facing fewer threats.
[00:17:45] They've just turned identity security from getting away from an incident response kind of point of view on it to more of a continuous risk management discipline that they're making sure that, again, their governance is constant on the identities that are in their organizations. And, of course, AI is helping defenders automate their security operations. But on the flip side of this, it also gives attackers new capabilities.
[00:18:12] So as this AI arms race of sorts continues, where do you think the human expertise remains indispensable? And where should organizations get more comfortable letting AI take the lead? I appreciate that question. It's almost an episode entirely on its own. But any takeaways around that? Well, I think it comes back to what we said earlier. It's people. It's human beings that define the intent of that agent and the policy around it and the accountability.
[00:18:40] The AI is not accountable in of itself. Yeah. And what the AI will do will handle the speed and the scale and consistent enforcement. It's people that define the intent and the policy. And I think the governance piece of it has to establish boundaries around, certainly in the first instance, what high risk actions would be rather than needing manual approval for every use case that an agent is going to want to invoke. The controls have to be automated.
[00:19:09] They have to be contextually aware. And as I keep saying, and I'm probably becoming like a broken record, they have to be enforced in real time, constantly. They have to. And companies are going to need to, as I said, the AI in of itself is never going to be held accountable. It's the company. They have to remain accountable for the systems that they build and what they deploy.
[00:19:30] And simply, you know, coming back to the AI did it is not going to be a get out of jail free for any company if there's a breach or bad things happen.
[00:19:43] And if we do have a CIO or a CISO listening who knows that AI agents are about to become part of their workforce, if not this year, early next year, what are the first three practical steps they should be taking right now to ensure that they can govern, monitor and control those identities before they become tomorrow's biggest security threat? It feels like it's a great opportunity to build the foundations now. But where would you advise that they start? It is.
[00:20:11] And actually, you know, our advice has really been born out of all of the customer conversations that we've had. This is with our current customers, you know, in terms of how we because we hope we're going to help them first. And I think the first three things that we're seeing that the most mature companies are doing are, first of all, they're saying, OK, we need to control the sensitive actions first. Right. We need to identify those systems that could cause material harm if they were breached. We need to make sure that every attempt on access is evaluated before the agent executes anything.
[00:20:39] So, as I said earlier, define, stop it from doing it prior rather than working out what it's done after. The next part of it is, as we've actually been talking about for the last 25 minutes or so, is make sure that you only give the agents access when they need it. Limit it to very specific tasks and then remove that access as soon as it's done. Don't give it what we would call in the industry standing privilege to continue to work in the systems that it's had access to.
[00:21:05] And then last but not least, it comes down to setting the ownership and accountability, defining the agent specific policies that you need to do. That's where I think companies are not right now spending the level of time and energy on in terms of bringing humans into the really high risk decisions that agent would want to take. Retaining an action level record showing who did what, what it did, why it did it.
[00:21:32] It's that ownership and accountability that I think is the third piece that we're certainly already seeing across the most mature companies working with AI. I think that is a thought-provoking moment to end on. But before I let you go, where's the best place for people listening to find you or your team online, find out more information about anything we talked about today around Delinear, the recent releases, etc.? Where should they go? The very best place is our website, which is very simple.
[00:22:02] It is www.delinear.com. And my LinkedIn page, I think I'm the only Spencer Young, fortunately, on LinkedIn, which does help. You know, I curse my parents for the name, but it helps. But so, yeah, my LinkedIn page is there. And as you'll see in the biography, what we try and do is, whilst we've spent a lot of time, you know, on this session talking about the technology of it, one of the things a lot of our customers are worried about is the budget implications of all of this.
[00:22:28] You know, how do they show value and how do we as cybersecurity vendors help them to get the right budget allocations in the right places to see the right kind of returns? And so we tend to do a lot of that. You know, that's something I've been focusing very heavily on since I got into cyber rather than that. I love the technology. As I said, I love the adversarial parts of what we do. Fundamentally, companies are running businesses and governments are trying to secure citizens.
[00:22:54] We do spend a lot of time trying to help them work out where they should be investing first and why and then building the business cases for that. So some of that you'll find on the LinkedIn page as well. But it's been a real pleasure to spend some time with you, Neil. Thank you. I appreciate it. Thank you. I love chatting around how securing how an AI agent connects is no longer enough. A very clear message there. We do need control over what it does once it's inside.
[00:23:21] So I'll include links to everything you mentioned, the website, your LinkedIn, the company's LinkedIn and some information around the runtime authorization for AI agents we discussed as well. I'd love people to feedback. Have a look in the show notes. Have a look around. Let me know your thoughts, your experiences. But more than anything, thank you for your time today and bringing all this to life. Really appreciate it. Thank you, Neil. Thank you. Really appreciate it. I think Spencer's warning is simple.
[00:23:47] Legitimate access does not guarantee a safe action. An AI agent might be properly authenticated, remain within broad permissions, but still move money, query sensitive data or execute a command that nobody intended. And security has to follow the action, not stop at the login screen. And I think his practical plan begins with identifying systems where misuse could cause material harm.
[00:24:18] And then evaluating access before execution, granting temporary permission for specific tasks and keeping a record of who did what and why. It's the humans that must define these policies, these boundaries, ownership and moments when approval is required. So a massive thank you to my guests for joining me today. And remember, you can find out more at delinear.com. Connect with my guest on LinkedIn.
[00:24:45] And before I let you go, I'm going to leave you with a question. Could your security team explain every single action that is taken by an AI agent inside your organization today? How they answer that or how you answer that might determine if you need to go a little deeper on this. So as always, techtalksnetwork.com. Let me know your thoughts and experiences. And I'll return again real soon with another guest. Thanks for listening. Bye for now.

