When Identity Becomes The Front Line Of Cybersecurity
The Business of CybersecurityMay 20, 2026
33
00:22:4020.76 MB

When Identity Becomes The Front Line Of Cybersecurity

What happens when the biggest cybersecurity weakness inside your organization isn’t your infrastructure, but the people using it every day?

In this episode of Business of Cybersecurity, I speak with David Cottingham, president of rf IDEAS, about why identity has become one of the most targeted attack surfaces in modern business. From phishing attacks powered by AI to the growing risks tied to compromised credentials, David explains why traditional password habits continue to expose organizations across healthcare, manufacturing, finance, and enterprise environments.

Our conversation looks at the uncomfortable reality that while businesses have spent years hardening infrastructure, attackers have shifted their attention toward human behavior. David shares why fully passwordless environments may still be out of reach for many organizations, but why the move toward stronger authentication methods, secure second factors, mobile credentials, passkeys, and biometric workflows is already reshaping how businesses think about trust and access.

We also discuss the growing tension between stronger security and employee productivity. From clinicians accessing patient records in hospitals to workers authenticating on factory floors, David explains why security tools only succeed when they fit naturally into real-world workflows. The episode also explores the convergence of physical and logical security, the dangers of outdated proximity cards, and how layered security strategies still matter in an age shaped by AI-driven threats.

Along the way, David shares what he’s hearing from organizations at industry events, why many leaders feel overwhelmed by identity decisions, and how companies can future-proof their authentication strategies without disrupting existing systems overnight.

If identity is now the new perimeter, how should organizations rethink trust before the next breach forces the conversation?

Useful Links

Please check the partners of the Tech Tech Talks Network

[00:00:00] So a huge thanks to Denodo for supporting the Tech Talks Network, helping us produce more than 60 interviews a month. And when it comes to trusted data products, it all starts with the right foundation. And trusted data products start with Denodo because they can help you create, manage and deliver business-ready data products faster with secure real-time access across all of your data sources.

[00:00:26] And you can learn more by simply visiting denodo.com. If Identity has quietly become the new front line in cybersecurity, why are so many organizations still relying on the same password habits that have already failed them for years?

[00:00:49] Well, today's conversation takes us right into that tension between risk, usability and real-world business outcomes. Because while headlines often focus on ransomware or infrastructure breaches, the reality is attackers are still increasingly walking through the front door using compromised credentials. They don't even have to think about breaking in through the back. So today I'm joined by David Cottingham.

[00:01:17] He's the president at RF Ideas. And they are a company focused on secure access and authentication across everything from healthcare environments to factory floors. And my guest spends his time helping organizations rethink how identity is managed at the edge. Whether that's through physical credentials, mobile access or smarter authentication workflows that actually fit into how people work.

[00:01:46] So today we will try and unpack why going fully passwordless still feels just out of reach for many businesses. But what a practical next step could look like. And why the shift from protecting networks to protecting identities is something that is playing out across every industry. And hopefully we'll also get time to get into the balance between tightening security measures and keeping employees productive.

[00:02:15] And not complaining to security teams for slowing their teams down. So if you've ever wondered where to start on that journey towards stronger authentication without creating friction, this conversation today should give you plenty to think about. So a big thank you to NordLayer for backing the podcast and supporting the kind of real world cyber security conversations that we need more of. Because as someone that records 65 plus interviews a month,

[00:02:45] I've personally seen a huge increase in browser based attacks over the past year, whether that be phishing, malicious extensions, account takeovers, the list is long. And it's all happening where people spend most of their time inside the browser. So NordLayer's new business browser that's built to address exactly that. It blocks malicious sites before they load.

[00:03:09] It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps. And it also helps you stay compliant by controlling access and enforcing policies without the need to rely on multiple disconnected tools. So for anyone listening that is thinking seriously about reducing risk in SaaS heavy environments, this feels like a smarter and more focused approach.

[00:03:37] And you can learn more about it by visiting nordlayer.com slash browser. But enough scene setting for me. Let me introduce you to my guest now. So a massive thank you for joining me on the podcast today. For everyone listening, hearing about you for the first time, can you tell them a little about who you are and what you do? Hi Neil, I'm David Cottingham. I'm the president of RF Ideas.

[00:04:04] And we deliver a series of identity solution for our customers, primarily leveraging ID cards or RF credentials. That can take the form of a physical card or increasingly a mobile credential. And everything we're about is helping our customers automate workflows by leveraging that credential to help them go about their work in a secure, efficient way.

[00:04:31] Well, it's a pleasure to have you join me today, especially because we're talking at a time where everyone is having conversations around agents, agentic AI, digital identities. And I think it has thrown the topic of identities right back into the mix, right into the spotlight as well. And passwords, they've been known as a weak point for years for us humans, yet they do remain deeply embedded inside business systems.

[00:04:59] We're starting to see pass keys more often now in our personal lives. So for organizations, though, where should they realistically begin if going fully passwordless is still out of reach? It's somewhere we're all heading towards. It feels within touching distance. But what does this mean for organizations? Yeah, you're absolutely right. Passwords still are firmly embedded in processes throughout businesses.

[00:05:26] And what we talk about is helping customers get on a journey to more secure authentication. And that typically right now means adding a second factor. And adding a second factor can be, you know, a physical credential, mobile credential. We're all familiar with things like two-factor authentication, receiving a text pin.

[00:05:50] But in a lot of business settings, that's just a really cumbersome, inefficient way to do it. So we encourage people to just get on that journey to start. And you've spoken about identity becoming the new attack surface for a long time now. And as I said, it's now going mainstream. So what would you say is driving that shift away from infrastructure? And why are attackers finding credentials such an effective and possibly easy entry point today?

[00:06:19] Yeah, you're right. I think it is moving a bit away from infrastructure because there's been so much emphasis on hardening infrastructure over the last maybe decade. I've been in this space for 25 years now. And I think identity or passwords are becoming a more common threat vector because it involves people, right?

[00:06:44] And people continue to be one of those points that can be exploited. And tools like AI is allowing attackers to write even more compelling phishing messages that, you know, the long ago days, five years ago, where you would get this clumsily written phishing message that you could quickly identify and discard, I think are gone.

[00:07:10] You can now, with these AI tools, attackers can write very, very compelling messages that look extremely authentic. And that allows for phishing and account takeover and passwords being compromised in a way that some, you know, just continue to grow and grow. And I was watching an episode of The Pit recently and the cyber security risks and it going down in healthcare was playing the scene out.

[00:07:39] What I took away from that more than anything was how it has entered the mainstream now. So when you look across industries like healthcare, manufacturing and finance, how does that move from network security to identity first security? How does that actually play out in real world environments for people listening? Well, I'm a big fan of that show as well.

[00:08:00] So I think the way it is moving is, I guess if I understand your question, you know, what's changing or how is that moving from passwords to other forms or leveraging additional forms of identity? Yeah, that's right. And we talk about here at RFID is we talk about the password problem.

[00:08:21] And when we say that, what we refer to are the bad habits that come from reuse of passwords, shared passwords, and processes that are put in place in front of people that almost encourage them to avoid good processes.

[00:08:43] So if you are constantly asking someone to log in again and again and again using a long form password, they're going to find ways to circumvent that or at least avoid doing that as often as they do.

[00:08:56] So the way we help customers address that at RFID is our wave ID products allow you to simply tap a credential to a reader or leverage, begin to leverage pass keys and get people into those workflows more efficiently in a way. Then authentication just becomes this seamless thing that doesn't slow them down. You mentioned the medical space.

[00:09:22] We've had a lot of success in the medical space of helping clinicians automate that authentication workflow. So instead of walking in to a clinical setting, turning their back to a patient, fumbling with a password, clinicians that use our solution are simply tapping their identity to one of our devices and immediately accessing that record and engaging with the patient. So you get better patient interaction.

[00:09:49] You still have a secure interaction for the clinician with that data. And they're more satisfied because they're not typing passwords all day long. And I think many organizations are layering on multi-factor authentication, trying to do the right thing. But of course, not all second factors are equal. There are a few vulnerabilities in some of those too. So what should leaders be thinking about when choosing that right approach for their workforce and for their organization?

[00:10:17] Yeah, I think they should be thinking about security, obviously, right? We're talking security here. But making sure that it is a secure credential that will be used and leveraged and that it's a modern credential.

[00:10:32] So, you know, the industry of physical cards and physical identity has a long history of continuing to leverage legacy technologies such as proximity cards that are easily cloned. Right. You can find countless how-to videos and even devices that will assist you in cloning that. And now you've compromised that identity card that's used in one of those secure workflows.

[00:11:00] So we encourage people, yes, get a second factor, but make sure it is a secure second factor and one that will be easily leveraged. So if you were using Crocs cards before, move to one of the more secure variants to make sure that you don't have a credential that can be easily cloned. And there is often tension between tightening security and maintaining productivity.

[00:11:26] So a question on behalf of business leaders out there, how can businesses introduce those stronger identity controls that we're talking about here, but without creating friction for employees or slowing operations down where IT suddenly gets accused of being a blocker rather than a business enabler again? And we've done so much positive work over the last few years, but how do you continue that? Because it is a tough balance sometimes. It is a tough balance.

[00:11:52] So what we encourage our customers to do is, you know, engage that workforce that's going to be part of this, right? Don't shove down an edict that feels like you don't understand how I go about my work. So understand what that workflow looks like, take that into account, and then find ways while still maintaining security to easily insert that into the flow. That's why, you know, again, I go back to this, right?

[00:12:21] Whether it's using RF or we also increasingly are seeing biometrics enter the workflow space, that ease of use of a credential that is still secure is vital. Because if you don't think about that workflow and you don't do it in a way that can be efficiently adopted by the users, you're going to have great resistance and people are going to find ways to work around it. So look at the workflow. How does a secure credential go into that?

[00:12:51] And then make sure that the users can repeat over and over again, use that as they go about their day. And with technologies like everything from smart cards to mobile credentials and even proximity-based access evolving so quickly right now, I'm curious, how do you see authentication methods changing over the next few years? And anything organizations or leaders listening should be preparing for now? How do you see this continuing to evolve?

[00:13:20] Well, it is certainly a rapidly evolving space. And, you know, I think the way this leader should be thinking about it is begin to walk, if you're not there already, walk on this journey of moving towards more secure credential types. And so that, you know, the industry is absolutely moving towards pass keys, you know, away from some of the other legacy types.

[00:13:45] So you can, if that's too far of a leap, pick a technology that will allow you to go on your journey. So in RFID's case, we make a lot of multi-technology readers or devices where you can read a legacy credential, but you've got a future proof and a ready device that can also move to that next secure credential type.

[00:14:09] So put in place things that you can ease into leveraging the current credential and then move towards more secure credential types. So just build it out, think about it in a roadmap sort of a way, knowing that, you know, it's likely your building physical access system may require a legacy credential type for quite some time, right? Maybe you don't own the building, so you can't control the physical access system.

[00:14:37] So you maybe have to carry around a prox card while you're leveraging that next technology in the workflow, getting access to information or securely retrieving a document. So think about that as a roadmap. And for any leader listening who is concerned about breaches tied to identity misuse, because it is a growing threat there, what is the most overlooked step that they should take, do you think, to better reduce risk before it turns into a real incident?

[00:15:07] There's a big focus on proactive approaches to security rather than reactive. Any advice here? I think it's layers. You know, I think that has always been true, right? Like I said, I've been in this space a long time, and layers continue to be one of your best lines of defense. No one is saying, you know, we're talking a lot about passwords here this morning. No one is saying go back, roll back to simple passwords, right? So make sure you have all of these pieces in place.

[00:15:34] Have your network security buttoned down with appropriate tools there, right? Make sure you're using anti-phishing solutions at the edge. And then continue to train and also drive your teams towards more secure credential types. So still complex passwords at the core, network security at the edge and layered throughout. But then also adding a secure credential on top of that,

[00:16:02] that is easy and efficient to use is where you need to go. And before you join me on the podcast today, I was having a quick look on your LinkedIn page for the organization. And I could see you guys spend a lot of time on the road, a lot of different conferences. I'm curious, if you would put all those conversations into a big melting pot, any kind of trending conversations that people are coming and asking to you for help with? What are people talking about there out on the show floors?

[00:16:31] I think people are asking for help kind of sorting out what can feel like a very overwhelming and complex set of decisions. So we help our RFIDs, we help our customers every single day kind of sort that out. You know, we have people say, okay, I need to automate workflow on the factory floor because I'm really concerned about who's kicking off that process at an HMI panel, but I don't know where to start.

[00:16:56] So we're helping them kind of walk through understanding what they have in place today and then helping them sort out what can be a daunting, you know, set of terms and technologies. So we're walking them through everything from base technologies all the way to pass keys and where the industry is going in terms of standards. So we help our customers sort that out every single day.

[00:17:24] And that's, you know, you ask about what I'm hearing. It's also this convergence of physical security and logical security that's continuing to slowly march towards from that door entry all the way into the office suite. And we've talked a lot around defining the problem and the solution that you guys are offering here. But with everything you're focusing on throughout this year, is there anything that particularly excites you?

[00:17:49] Because, yes, there's a lot of scary headlines out there, but there's also a lot of opportunities to stop this stuff for good, right? Yeah, I think, you know, you talked about some of the AI technologies. And I know that people maybe say, wow, that's an overused term. But I think that organizations, I'm excited to see how organizations are going to continue to use some of these tools to begin to make even smarter, you know, kind of zero trust decisions.

[00:18:18] And we play a role in that at the very edge of that authentication stream. So from the moment someone presents a credential to one of our devices, we're part of beginning to understand who did that, when did they do that, was it a proper credential presented?

[00:18:36] So I think all of these tools, while there are many of them that are being used to threaten our enterprises, can also be used to very logically identify who is attempting to access information. And I think our industry is going to be able to leverage a lot of those things all the way from the edge into the core to make sure we're making smart decisions about who is truly accessing that information.

[00:19:01] And do they have the right to do so at the appropriate time, location and access level? Well, thank you so much for sitting down with me today and bringing all this to life. And as business and technologies inevitably begin to change, for anyone listening that are not just looking at improving their security, but also maybe partnering with you, working with you, or just finding out more about how to turn trust into more productivity. Where would you like me to point everyone listening?

[00:19:31] They can easily start out at RFideas.com and they'll find information, not just about our products, but also case studies and examples of how we have helped our customers solve the password problem, work on identity at the edge. And they'll also see examples of all the industry solutions we've worked with from securely retrieved documents to logical access into critical business applications to workflow automation on shop floor.

[00:20:01] So that's a great place to start. Well, so much we covered today from how to balance cyber risk, innovation and business outcomes, all that align with other conversations that we're continuously having on breaches, AI driven risk, and so much more. I'd love people listening to check out everything that you've just mentioned there. I'll put links on the show notes, make it nice and easy, but more than anything, just thank you for sitting down with me and sharing your story. Really appreciate your time today. Thank you, Neil. Great speaking with you.

[00:20:33] One of the things that stood out to me in that conversation with David today was just how much of this comes down to behavior as much as technology. Yet we can talk about zero trust, multi-factor authentication, and past keys all day long. But if the experience doesn't naturally fit into someone's workflow, it simply won't stick. And I think this is where the real challenge lies.

[00:21:00] Because leaders are challenged with designing security that people will actually want to use, or almost make it feel seamless so they don't feel any friction. And this is where I think there's a bigger shift happening here, because identity is no longer a small piece of the security puzzle. It is now becoming the foundation that everything else sits on.

[00:21:23] And as AI continues to make phishing and social engineering more convincing, that focus is only going to intensify. So if you want to learn more about how RF Ideas is helping organizations tackle the so-called password problem, and rethink authentication at the edge, I'll include links on the show notes. And you can visit me at techtalksnetwork.com.

[00:21:50] There's a blog post for every episode, and the links to the guest and everything that they mention too. So please, explore their work and take a look at some of the real-world case studies there. But as always, more than anything, I just want to hear your perspective. Are passwords still embedded in your organization more than you'd like? Or are you already moving towards a passwordless future? Let me know your thoughts. We'll continue this conversation together.

[00:22:18] So pop over techtalksnetwork.com. Other than that, I'll be back again bright and early tomorrow morning. Speak with you then.