PodParley PodParley

Autonomous Identity Governance With Paul Querna

Can multi-factor authentication really “solve” security, or are attackers already two steps ahead? In this episode of The Secure Developer, we sit down with Paul Querna, CTO and co-founder at ConductorOne, to unpack the evolving landscape between authentication and authorisation. In our conversation, Paul delves into the difference between authorisation and authentication, why authorisation issues have only been solved for organisations that invest properly, and why that progress has pushed attackers toward session theft and abusing standing privilege.

Episode 170 of the The Secure Developer podcast, hosted by Paul Querna, Danny Allan, titled "Autonomous Identity Governance With Paul Querna" was published on September 23, 2025 and runs 31 minutes.

September 23, 2025 ·31m · The Secure Developer

0:00 / 0:00

Can multi-factor authentication really “solve” security, or are attackers already two steps ahead? In this episode of The Secure Developer, we sit down with Paul Querna, CTO and co-founder at ConductorOne, to unpack the evolving landscape between authentication and authorisation. In our conversation, Paul delves into the difference between authorisation and authentication, why authorisation issues have only been solved for organisations that invest properly, and why that progress has pushed attackers toward session theft and abusing standing privilege.

Episode Summary

Can multi-factor authentication really “solve” security, or are attackers already two steps ahead? In this episode of The Secure Developer, we sit down with Paul Querna, CTO and co-founder at ConductorOne, to unpack the evolving landscape between authentication and authorisation. In our conversation, Paul delves into the difference between authorisation and authentication, why authorisation issues have only been solved for organisations that invest properly, and why that progress has pushed attackers toward session theft and abusing standing privilege.

Show Notes

In this episode of The Secure Developer, host Danny Allan sits down with Paul Querna, CTO and co-founder of ConductorOne, to discuss the evolving landscape of identity and access management (IAM). The conversation begins by challenging the traditional assumption that multi-factor authentication (MFA) is a complete solution, with Paul explaining that while authentication is "solved-ish," attackers are now moving to steal sessions and exploit authorization weaknesses. He shares his journey into the identity space, which began with a realization that old security models based on firewalls and network-based trust were fundamentally broken.

The discussion delves into the critical concept of least privilege, a core pillar of the zero-trust movement. Paul highlights that standing privilege—where employees accumulate access rights over time—is a significant risk that attackers are increasingly targeting, as evidenced by reports like the Verizon Data Breach Investigations Report. This is even more critical with the rise of AI, where agents could potentially have overly broad access to sensitive data. They explore the idea of just-in-time authorization and dynamic access control, where privileges are granted for a specific use case and then revoked, a more mature approach to security.

Paul and Danny then tackle the provocative topic of using AI to control authorization. While they agree that AI-driven decisions are necessary to maintain user experience and business speed, they acknowledge that culturally, we are not yet ready to fully trust AI with such critical governance decisions. They discuss how AI could act as an orchestrator, making recommendations for low-risk entitlements while high-risk ones remain policy-controlled. Paul also touches on the complexity of this new world, with non-human identities, personal productivity agents, and the need for new standards like extensions to OAuth. The episode concludes with Paul sharing his biggest worries and hopes for the future. He is concerned about the speed of AI adoption outpacing security preparedness, but is excited by the potential for AI to automate away human toil, empowering IAM and security teams to focus on strategic, high-impact work that truly secures the organization.

Links

Follow Us

The Secure World Foundation Podcast Secure World Foundation This podcast features content produced by the Secure World Foundation (SWF), an endowed, private operating foundation that promotes cooperative solutions for space sustainability and the peaceful uses of outer space. The Foundation acts as a research body, convener and facilitator to promote key space security, and other related topics, and to examine their influence on governance and international development. The Secure Woman Podcast Your Lifestylist Im your Lifestylist,Welcome to the Secure Woman podcast. Where I talk about the tools to elevating your thinking, move pass past trauma and we talk about healing is a journey. Our conversations are geared towards help women master their emotions and manifest their dream life, we are moving full throttle pass the pain. This podcast is for those looking to WIN past the pain. Support this podcast: https://podcasters.spotify.com/pod/show/yourlifestylist/support Secure the Future Dave Maasland Secure the Future is een maandelijkse podcast over digitale beveiliging. Met CISO’s, voor CISO’s. Over hoe we vandaag beschermen om morgen veiliger te zijn.Ik ben Dave Maasland en in de Secure the Future podcast ga ik in gesprek met vooraanstaande securityleiders in ons land. Je leert als CISO hoe vakcollega’s naar dit vak kijken, juist in deze tijd. Hoe gaan we om met de huidige ransomwarecrisis? Hoe bereiden we ons voor op dreigingen in de toekomst? Hoe begin je in het CISO-vak? En hoe zet je een sterk securityframework neer?Kortom: het is tijd om CISO’s in Nederland met elkaar te verbinden en meer kennis uit te wisselen. Natuurlijk ga ik ook met hen in gesprek over wie ze zijn als mens en hoe ze hier zijn gekomen.Luister daarom elke maand naar de Secure the Future podcast dé podcast over digitale beveiliging met CISO’s, voor CISO’s. The Reezy London Podcast The Reezy London Podcast Diving into the mind of Reezy London on his quest to secure financial longevity, happiness, & his interests in today’s world
URL copied to clipboard!