Episode 139 · Enterprise · 31 min

The weakest link has a login

Okta's argument is that the corporate perimeter dissolved the moment a cleaning contractor got a password to the payroll system. Ben Goodman's case: the headline breaches of the last five years ran through third-party credentials nobody in HR was tracking — and the only fix is to govern every non-employee identity, from freelancers to AI agents, with the same rigour as a full-time employee.

BG
Ben Goodman
Regional leader, Asia-Pacific & Japan, Okta · with Vishal Krishna
The weakest link has a login — episode thumbnail
31:14
Said in this episode
▶ 11:42
7,500
Tool sets Okta integrates out of the box
Goodman's figure for how many applications the platform connects to without custom work — the concrete form of what he calls neutrality.
▶ 0:15
1 trillion
Cyberattacks on India projected by 2033
Vishal's opening figure, attributed to a report he says is available online, rising to roughly 17 trillion a year by 2050 — a host-cited projection, not an Okta number.
▶ 17:50
99%
Share of a transaction an AI agent can run alone
His rule for agentic commerce: AI handles almost the whole process, but the transaction step must be authorised by a human through a push notification or Face ID.
▶ 14:00
5 years
How long third-party credentials have driven the big breaches
He dates the shift to the last five years of large incidents — Sony, Optus in Australia and several in India — where compromised third-party credentials were the main driver.
▶ 26:31
10 → 100
Startup headcount versus vendors it must manage
Vishal's example, which Goodman accepts: a ten-member team can easily be working with a hundred different vendors and freelancers on day one.
The brief

The argument in sixty seconds

Goodman's claim is that identity has quietly become the whole of security, because everything that used to mark a perimeter has gone. Okta's heritage was connecting employees to Salesforce and Workday; after the Auth0 acquisition it also signs you up to consumer services like OpenAI, and it now supports roughly 7,500 tools out of the box — a number he treats as a productivity argument rather than a boast, since a CIO who cannot say yes quickly to the tools a 10x engineer wants will lose the engineer. The sharper argument is about who else is already inside. The big breaches of the last five years, he says — Sony, Optus in Australia, several in India — ran through compromised third-party credentials: a cleaning company with access to payroll, a law firm, a marketing agency, all provisioned with usernames that never sat in the HR system, were never revoked, and eventually got shared. His conclusion is uncomfortable for most enterprises: every identity, employee or not, needs joiner-mover-leaver governance and privileged-access controls. The same logic now extends to AI agents — let one run 99% of an insurance upgrade if you like, but the transaction itself must step up to a human with a push to the phone or a Face ID check, and an AI service that skips that step is one you should not be using. Underneath it all sits the gap he wants closed: identity still has no pervasive industry standard, which is why nobody can say when they are secure enough.

Worth your time if you are

CIOs whose vendor list is longer than their headcount
Security leads who can name every employee but not every contractor
Ten-person startups already working with a hundred freelancers
Product teams weighing passwordless against one more OTP
Episode map

Where the conversation travels

Every block is a chapter, coloured by what it's about. Click any of it to jump straight to that minute on YouTube.

01Cold open: a trillion attacks a year 0:00 Vishal opens on a projection he has read — more than a trillion cyberattacks on India by 2033, and perhaps seventeen trillion a year by 2050 — and lands on his premise that security begins where identity begins. 02The world's identity company 1:29 Goodman defines Okta as the layer that connects people to technology safely: a heritage of moving companies onto Salesforce and Workday, extended to consumer sign-ups at services like OpenAI, and now business-to-business authentication too. 03Loyalty points are currency 2:48 Airline miles buy flights and hotels, so they deserve bank-grade protection — which pushes multi-brand groups towards brand federation, one login per customer, and passwordless Face ID instead of the OTP that quietly drives churn. 04The digital supply chain cuts both ways 6:18 His anchoring claim for retail and healthcare: your digital supply chain is either the strongest or the weakest link in the business, because one third-party supplier with lower standards and system access imports their risk into you. 05The extended workforce nobody onboarded 7:50 Fuelers, cabin cleaners, legal firms and marketing agencies are not employees but touch critical infrastructure daily, so companies route their access through an identity platform and a zero-trust posture that checks device, network and authentication together. 06Why tool sprawl broke identity 9:38 Vishal describes the friction of pushing AI-made work into client networks, and Goodman points to generative AI democratising creative tools — Adobe, Canva, Figma — which leaves CIOs with more vendors to standardise against than ever. 07Neutrality, and 7,500 tools out of the box 11:28 Neutrality is defined as the ability to integrate any tool set rapidly under one set of policies — a talent question as much as a security one, when one hire grew up on Microsoft, another on Google and another on Zoho. 08Breaches came through the cleaning company 13:45 The large breaches of the past five years traced back to compromised third-party credentials created outside the HR system, never revoked, quietly shared — standing privileges that CIOs did not know existed because the decisions were made in legal and marketing. 09AI runs 99%; you sign the last 1% 16:02 On AI sales agents and automated insurance upgrades, Goodman argues the model is step-up authorisation — the agent does almost all of it, the human authenticates the transaction, and services that skip that check should not be trusted. 10There is no edge any more 18:51 Asked about security at the edge, he says the edge has gone: you are a verified credential that presents different attributes for work, contracting or an insurance purchase, and deepfakes are forcing the industry to keep hardening those factors. 11The standard that does not exist yet 21:24 Okta's new identity profiling standard, announced with the OpenID Foundation and industry peers, targets three gaps — nobody can tell when they are secure enough, cross-sector and cross-border collaboration stalls, and cyber students do not know what to skill up to. 12Startups should start on identity 24:13 Okta's heritage is the startup market, and the pitch is self-service sign-up on both workforce and customer identity from day one, so a small team can say yes fast to new tools while keeping one consistent policy. 13Cricket, fencing and one household rule 26:44 The former cricketer and cyclist has traded both for the gym, and imposes a single rule on his two children — one team sport and one individual sport, for collaboration and personal excellence respectively. 14Risky Business, and learning broad 28:20 He reads fewer books and more articles, follows the Australian podcasts Risky Business and The Contrarians, and closes with advice for a world without an AI rulebook: learn ten different things, and learn how to learn quickly.
Takeaways

Ideas to carry out of this hour

01

There is no edge left to defend

Asked where edge security is heading, Goodman rejects the frame outright — there is no edge any more. What remains is a credential that says who you are and keeps re-verifying itself, presenting different attributes depending on the transaction: almost nothing to log into work, proof of age and income to buy an insurance policy, an active record for healthcare. Security stops being a boundary you draw around systems and becomes a question of which attributes you are willing to release, to whom, for how long.

02

Your weakest security policy is your vendor's

The anchoring claim for any enterprise: the digital supply chain is either the strongest or the weakest link in the business. You can deploy the best security vendors with best-practice configurations and still import risk the moment a third-party supplier, legal firm or agency with looser standards is handed access to your systems. The design goal he sets is not to lock those partners out — that kills collaboration and productivity — but to extend the same phishing-resistant controls onto devices you do not own.

03

The breach came in through the cleaning company

Looking at the large breaches of the last five years — Sony, Optus in Australia, several in India — Goodman says the common driver was compromised third-party credentials. The mechanism is mundane: a company needs to give a contractor access, creates a username and password outside the HR system, forgets it exists; the person changes jobs, hands the login to a colleague, and a shared credential now sits on a critical system. CIOs were unaware because those decisions were made in legal or marketing, not technology.

04

Manage every identity as if it were an employee

The corrective is a single governance standard applied to everyone. Full-time employee, contractor or business partner, each identity needs proper joiner-mover-leaver handling, privileged-access controls and device checks — the things enterprises already do for staff via the HR system and nobody does for the extended workforce. At an airline that extended workforce is the fuelers and the cabin cleaners; in healthcare it is a long tail of people who touch critical assets every day and appear on no payroll.

05

Neutrality is a talent argument, not a philosophy

Okta supports roughly 7,500 tool sets out of the box, and Goodman frames that number as productivity rather than plumbing. Generative AI has democratised creative work — Adobe, Canva and Figma now sit inside firms that used to outsource it — so a CIO faces more vendors to standardise against, not fewer. Meanwhile new hires arrive fluent in whichever stack they grew up on: Microsoft at their parents' office, Google at university, Zoho in India. Neutrality is the ability to say yes to all of it quickly while enforcing one policy.

06

Let AI run 99% — never the transaction

AI can automate the work that used to take a team of humans, like moving a customer from a lower to a higher insurance tier. Goodman's line is that the last step cannot be delegated: at the point of transaction the system must step up and authenticate the human — a push to the phone, a Face ID prompt — so an agent can never move money or personal data on your behalf unchallenged. He turns it into a buying signal: an AI service without step-up authorisation is one you should not be using.

07

Loyalty points are currency; protect them like a bank

An airline is not just a booking system — it holds passport data and loyalty balances that buy flights and hotels, which makes them currency deserving bank-grade protection. That pushes multi-brand groups towards brand federation: keep the brands independent in market, but give the customer one identity and one login across all of them. The commercial argument is churn — one bad experience, whether a password reset loop or a data leak, is easy to cause and very hard to recover from.

08

Identity's missing standard costs three things

There is no pervasive identity standard across industries and companies, and Goodman argues the absence causes three specific harms: organisations cannot tell when they are secure enough, public-private and cross-border collaboration stays hard, and cyber security students do not know what to skill up towards. Okta's answer, announced with the OpenID Foundation and industry peers, is a common identity profile — the ambition being that you could one day choose vendors, or countries, by whether they comply.

The numbers, drawn

What the episode measures

Every figure below was said on air — timestamps included, caveats kept.

Conversation share

portion of the hour spent on each theme
SaaS & enterprise · 28%Data & digitisation · 20%AI & machine learning · 16%Regulation & policy · 13%Product strategy · 9%Sales, GTM & growth · 6%
SaaS & enterprise28%
Data & digitisation20%
AI & machine learning16%
Regulation & policy13%
Product strategy9%
Sales, GTM & growth6%
Computed from the chapter map of this episode.

The attack curve the episode opens on

cyberattacks a year (trillions)
India, by 20331India, by 205017
Host's opening figures, attributed to a report he says is available online — an order-of-magnitude projection, not Okta data, and not revisited in the conversation.▶ 0:15
Worth keeping

Lines that stay

Your digital supply chain is either the strongest or the weakest link in your business.

— Ben Goodman ▶ 7:11

We have to manage every identity as if it's an employee in the company — the right joiner-mover-leaver, the right governance, the right privileged access controls.

— Ben Goodman ▶ 15:47

Even though AI will do 99% of the process, that bit which is the transaction is always validated by you as a human being with the right credentials.

— Ben Goodman ▶ 17:50

I don't think there's an edge any more.

— Ben Goodman ▶ 19:08

Learn broad, know how to go deep. In a world where you don't know what the next iteration of business is, knowing how to learn new stuff rapidly is the most valuable skill set.

— Ben Goodman ▶ 30:18
Clips that travel

Short on time? Start here

Security leads who track employees but not contractors

The weakest link is someone else's login

The digital supply chain argument in full, plus the extended workforce — fuelers, cleaners, agencies — and why zero trust is the answer to devices you don't own.

7:05 → 9:38 · 3 min ▶ Watch clip
CIOs who have never counted their non-employee accounts

Breaches came in through the cleaning company

How shared, untracked third-party credentials became standing privileges on critical systems — and why nobody in technology knew.

13:45 → 16:02 · 2 min ▶ Watch clip
Teams shipping AI agents that touch money

AI does 99%; you authorise the last 1%

Step-up authorisation as the design pattern for agentic commerce, and as a test for which AI services deserve your data.

16:02 → 18:51 · 3 min ▶ Watch clip
Anyone still drawing a network perimeter

There is no edge, only credentials

The dissolution of the edge, deepfakes forcing better factors, and the case for one verified credential with situational disclosure.

18:51 → 21:24 · 3 min ▶ Watch clip
Founders juggling more freelancers than employees

Why a ten-person startup needs identity on day one

Okta's startup heritage, self-service workforce and customer identity, and the argument that saying yes fast is a security feature.

24:13 → 26:44 · 3 min ▶ Watch clip
Glossary

The jargon, unpacked

Workforce vs customer identity
The two halves of Okta's business — logging your own staff and contractors into internal tools, versus signing up and authenticating the customers of the product you sell.
Zero trust
A security approach that verifies every request on its own merits — device, network, authentication and authorisation — instead of trusting anything because it sits inside the corporate network.
Extended workforce
Everyone who works with a company without being on its payroll — contractors, agencies, suppliers, an airline's fuelers and cabin cleaners — and who rarely appears in the HR system that governs access.
Standing privileges
Access rights that remain active long after the reason for granting them has gone, typically because the account was created outside HR and nobody owns revoking it.
Joiner-mover-leaver
The lifecycle discipline of granting, changing and removing access as a person joins, changes role or leaves — the control Goodman wants applied to non-employees too.
Credential stuffing
Attacking an account by replaying username and password pairs leaked from some other breach, on the assumption people reuse them.
Brand federation
Letting a group with several consumer brands keep them independent in market while tying them to a single customer identity and one login, so experience and security policy stay consistent.
Step-up authorisation
Interrupting an automated flow at the moment that matters — a payment, a policy change — to re-verify the human via a phone push or Face ID before it completes.
Connections

If this resonated, go here next

Full transcript

The whole conversation, searchable

122 segments

Auto-generated captions, lightly cleaned. Click a timestamp to open that moment on YouTube.