
Things like identity management and threat intell…
Loading summary
A
Hello and welcome to statescoop's Priorities podcast. I'm Colin Wood, statescoop's editor. For this episode, I interviewed Kevin Green, who's the public sector chief cybersecurity technologist at Beyond Trust, a company that develops software for privileged access management and vulnerability management. We talk about frontier AI models, the fast moving target of patching cybersecurity vulnerabilities and perhaps unsurprisingly given his role, why he thinks privileges and access should play a larger role in organizations seeking to be more proactive in their cyber defense. But first, here are the top stories this week. One year after deadly floods in Texas Hill country, many regions are updating their warning systems, but adoption still remains uneven. 29 counties have signed agreements with the state, but in the state's more than 200 remaining counties, many communities still lack warning sirens, largely due to cost. Ralph Johnson, who has spent the last three and a half years as Washington State's chief information security officer, announced in a LinkedIn post on Friday that he'll step down from his role in September. Cybersecurity has never been just a job for me, johnson wrote. It has been a mission, a responsibility and a professional community that I care deeply about. Illinois Governor J.B. pritzker this week signed a bill into law that adds a new layer of oversight for developers of advanced AI systems operating in the state. The Artificial Intelligence Safety Measures act requires large AI developers to publicly disclose their safety and security practices, report significant AI safety incidents, and maintain internal compliance programs. Here's Kevin Green with Beyond Trust.
B
I'm the Chief Cyber Security Technologist at Beyond Trust. I support everything from go to market thought leadership, reach back into product engineering and really try to level set on how we align our capabilities to meet government needs. So that's my current role. I have extensive experience in the cyber, mainly around the beltway here in D.C. where I served as a computer scientist Program manager at Department of homeland security from 2012 to 2017. There I led research around software security. So software security is one of the things that is near and dear to my heart. So all these things we see around these frontier models and accelerated vulnerability detection are things that in back in 2014 I had planned in my program before our entire division was dismantled and no longer funding R and D. So that's one reason why I departed and went over to mitre. But I want to just circle back around the work that I was doing at DHS before. There was a mythos. You know, I had already had formulated something that was similar and I and I kind of leveraged the word from my good friend Mike Walker, who was running the Cyber Grand Challenge at darpa. I had already signed an MOU to ship some of the infrastructure over to one of my performers in Madison, Wisconsin called Mortgage Institute for Research, where the Software Assurance Marketplace was being held, was being funded. So I was really on the pathway of really trying to make some really outstanding, groundbreaking improvements in terms of how we develop and test software over security vulnerability. So fast forward to today, I see all this stuff playing out with frontier models and being able to have accelerated vulnerability detection really just jogs my memory of the, of the work that I was doing. Some of the things that I were doing was a little bit ahead of the curve at the time. Government wasn't really that fond of bug bounties. So I had major conversations with Casey Ellis, Katie Massouris, who you see now in the news talking about whole anthropic thing because at the time I really want to figure out a way how do we build a healthy ecosystem around the most critical open source software components that are being used in government? Because I think that was important. I mean government by and large is one of the biggest acquirer software, right? Because a lot of software development at the time wasn't being developed in house in the government. So I wanted to really try to have somewhat something that was forward leaning but also help, you know, reduce the attack surface of software. Now what we're seeing with all these more, you know, mature models from a vulnerability detection capability that we're seeing with these frontier models. So now the time to attack the window of exposure is, is, is really sliding, right? So we have to do a better job at really trying to elevate the importance of not only secure by design, but I call resiliency, right, building resiliency in software and figure out a way how do we reduce the overall attack service that we've seen with software. And then obviously from there I went on to mitre as I was mentioning, worked on mitre, ATT and CK research, which brings that threat informed defense approach which I think is so important. Now what we've seen with a lot of what adversaries are trying to do in terms of impact, our critical infrastructure impact state services that, you know, that are so critical to their different consumers and constituents in that particular state. So critical infrastructure becomes a very important role. So really just trying to, you know, blend all these things together and take my experience and help our customers in state and local really level set on the importance of what I call privilege disruption and being able to not allow adversary to convert their initial access into any meaningful control.
A
Right, yeah, thanks for that. The reason I asked is because it's just so highly relevant to the topics that we're going to be talking about today. And you recently had a opinion piece published on cyberscoop that touched on some of the things that you just referenced. For anyone who hasn't seen that, I want to take kind of the broad view first, just so people kind of understand where you're coming from on these issues and how you, you have, you have an interesting perspective on these things. So what is wrong as you see it, with the current paradigm with regard to cyber frameworks and cybersecurity policies?
B
I think what we're seeing is that the threat landscape is evolving at a very fast pace, even before the frontier models and what they're able to do, the capability that they possess. So I think by and large our culture here in the US has been very reactive, a reactive cybersecurity posture. So I'm always a proponent or a very strong advocate for being proactive in getting ahead of the attack life cycle, understanding how do we move further left and really build those early warning signs and signals that are so important. Like we know that threat actors are silently abusing our identity infrastructure. Right. Or privileged environment, so that silent identity abuse becomes very important. And we know that privilege is the fuel that drives the success of these campaigns with threat actors. So I've been really strongly advocating for moving further left. You know, with every cyber attack, there is a cyber story. There's a, there's a prologue. And the prologue are the structural conditions that exists in your environment, which I call privileged debt. Right, the privileged debt that exceeds a operational need to have within the environment. And over time, because of all the different things we see with cloud SaaS, AI infrastructure, privilege accumulates. Privileged debt accumulates over a period of time. And if we're not careful, we're seeing now the effects of these cyber attacks and their downstream impact on spending some of that debt that we've accrued in our environment. So I think for me is really trying to help our customers build that privilege disruption architecture that deny an adversary or threat actor from gaining that meaningful control, which is so important. So I think that's that pre proactive approach and then really trying to use that early warning telemetry to hunt for the signs of pre positioning persistence and privilege escalation that go silently abused across our infrastructure.
A
Right. I think you'd be hard pressed to find someone in state or local government who would disagree with you on those points? That all sounds good. And then what you usually find in practice is it's easier said than done. So with your experience dealing with customers and so forth, what are those sorts of challenges that you hear about or run up against sometimes in terms of trying to eliminate that privileged debt?
B
So I think one big part of it is not having the right set of capabilities. I don't want to really say tools, I want to say capabilities, solutions or the right architecture. I think because the threat landscape has moved so fast, I think a lot of technologies investments are no longer providing the visibility, it's no longer providing the biggest bang for our buck. So we're behind the power curve when we start talking about really trying to gain that total visibility across our entire identity estate. So we can see when privilege, that privilege creep happens, a privilege sprawl happens that allows for the debt to accumulate over a period of time. So having that full visibility across your humans, non human identities as well as your agentic AI environment becomes very important because you can't protect what you don't know about. And really using that to drive whether or not we are building systems that meet compliance, right? Every organization has some compliance baseline, some compliance mandate for building and implementing systems over time. You need to understand whether or not certain systems are being implemented or falling out of the baseline and whether or not people are conforming to the baseline. So I think that's a big part of it, the visibility across the entire DNA state. And the other is no matter what CISO I talk to across the different states, resource constraints become very important. So how do we use automation as a way to do some of the heavy lifting, but also focus on the things that matter the most? Right. We can't solve world hunger in a day. So I do think if we understand how to take more of a threat informed defense approach, then we can prioritize the things that matter most. And I think, you know, at some point I'm going to say this. I think, you know, I was at Critical Effects DC a couple of weeks ago and I made this comment. I think we're at a point now where we have to concede something. And I think initial access is the thing we have to concede. And reason why I say that is we know that there's MFA bypass, we know that there's AIUs and phishing. Like these things are cheap and commoditized, right? So we are seeing a lot of threats that are being successful from initial access standpoint. And I talked about the privileged Debt. But the problem we have is we have to shift our strategies, our design, our infrastructure to be able to disrupt that privilege. So even if initial access is successful from a threat actor perspective, we can allow them to convert that initial access for impact and progression. Because at the end of the day, most cyber attacks, no one sees the data leaving. Right. That exfiltration becomes very important. But I do believe that there's this choke point, right, where if you look at the MITRE attack lifecycle, it starts with persistence, privilege escalation and then lateral movement. If we build strong controls around that, I think we put ourselves in a better position to be resilient and start after capabilities and behaviors.
A
Right. And now you talked about things moving fast and today that means these frontier AI models to start with. I wanted to talk about those models and also how they've been jailbroken in recent weeks for. Well, they just have to do it.
B
Right.
A
If it's like, why do you climb the mountain? Because it's there. Right. I think that's probably what people would say. In any case, our audience has, I'd say, a range of technical ability. To start with, could you describe what it means to jailbreak an AI model and why that is of interest and concern to various parties?
B
So I think that's a good question. It's the ability to persuade AI to do something against safety. Alignment. Right. So every AI has some alignment for safety. So it's the ability to persuade the AI to take another priority over the right priority. I call it convince me bug. I came up with the term called convince me bug because essentially you're convincing the model to do something that the alignment is not designed to do. And I've made several arguments that jailbreak is going to happen. That's part of innovating, that's part of making mistakes. That's part of trying to be on the cutting edge of technology. But what we can allow is for if an AI model or if someone's able to jailbreak a AI frontier model, we can't allow them to, to inherit the execution authority to be operationally dangerous. So it goes back, you know, this common theme about privileged debt, that execution authority is what allows a threat actor to do malicious thing and do things that can operationally impact our environment, disrupt our environment. So I do think jailbreak, while it's going to happen, right. And I think now what we've seen with Anthropic is they came out with jailbreak assessment framework and a lot of people are now complaining that it's is affecting their performance. Is affecting the quality of using these models to the point you really can't do anything is and is what it's doing is every time a security function or something is being triggered, it forces them back down to a, to the Opus 4.0, 4.8 model. So at some point are we going to innovate? Are we going to use our lessons learned around really controlling what these agents can do, these AI can do? I think that's the most important thing. Understanding the footprint, the scope in which these frontier models have across our environments, across infrastructure. And I think no one sounds like a broken record, but I do think it comes back to that visibility and understanding how we provision AI. What are the touch points from a design perspective that we are allowing these frontier models and these agentic models to touch within our environments? And are we controlling the scope of these connections? Whether it's API, whatever the case may be, whatever integrations, are we controlling that and having that visibility to understand when a model is doing something that it's not supposed to do? So we can really reduce that blast radius that's so important.
A
Right? Do you think there is an upshot for state and local governments with regard to whether you have a powerful AI model that's been jailbroken or just the threat of that always being on the table? What does that mean for state and local governments?
B
I think the threat is always there. Even with the anthropic assessment framework for, for jailbreaking, I do think that is there. I mean, two things I always say is undefeated, right? Misconfiguration is a human error. So we've seen that across my 30 plus years in IT and cyber. So we can safely assume that there's going to be another class of jailbreak attempts that will happen that goes outside of the existing framework. So with that being said, I do think it's important to. If you're going to do and adopt these models in your environment, it's important to understand the debt that these models sit on top of because downstream we know the fact if a user, a malicious user, is able to implement some type of jailbreak and get the agent to do something that goes against this alignment, the first thing it tries to do is look for the execution authority to do it right. So I think if we can control that, pay that debt down, I think state and local agencies will have a more safer way to roll out AI. At the end of the day, I always say, even with AI, you need to have a safe, reliable, trustworthy policy that governs how you implement AI within your environment. So I think that's important to really kind of help state agencies not lose focus of that policy, that governance model, so that you can understand how you can implement technology and how it affects your environment.
A
What is privilege disruption?
B
To me, it's, you know, I was waiting for the new cyber strategy to come out back in November, December, and, and it talked about shaping adversary behaviors. And I was like, what, what, what other way to shape adversary behavior is to cut off the field that drives their, their campaigns? Right. And to me, the way to do that is to disrupt privilege. Right? Since you're not allowing them to convert whatever initial access they have in your environment, whatever foothold you have in your environment, you're not allowing them to gain that privilege access. Right. Because that's the fuel that drives their cyber attacks. And what we're seeing is when you're able to shape average shape behavior, you impose costs, uncertainty, and risk to the operations. So we never want to stop cyber attacks, but I do think if we raise the level of effort to make it a little harder by using the choke point that I talked about earlier, to cut off the fuel, right, so that we can disrupt their potential access. And we have to, again, we have to assume that there is some identity abuse that's happening in your environment. And the other thing I want to make point of is because the environment has evolved, the threat environments have evolved so much identity is not where the risk is. Privilege is where the risk is. So identity alone has no risk. Privilege gives the identity of risk. So building that privilege disruption infrastructure across your endpoints, across infrastructure, across your applications become very important. And as you build that privilege disruption infrastructure, you'll be in a better position to, to defend forward, protect forward, and, and build that resiliency against threat actor capabilities. So I think that's very important to kind of help our state and local agencies, the ones that we work with, the CISOs that I work with, in really shaping that and understanding what that means from a strategy standpoint and have an effective way to implement that. So they have the confidence in implementing the newer technologies like AI without having the fear of wondering, you know, the agent chaos that happens that we were seeing now I call it agent chaos that we're seeing now with some of these agents being misconfigured and just, just feeding off the privilege that, that, that they are allowed to inherit over a period of time.
A
Right. Do you think it's as. Not, not simple exactly, but is it, is it as, as limited to privilege, the solution? Are there other aspects of Security frameworks and security practices that need to be remediated to put the good guys on a better footing.
B
I think privilege to me, has to elevate as a critical component of cyber defense. Now, if we look at zero trust, identity has always been a key, key part of that, as well as data protection. So I think there are other security control considerations that have to be part of really defending and building a holistic cyber infrastructure that can defend against what we're seeing with the evolution of these cyber attacks. Now, threat actors are using, or could use these frontier models to accelerate the exploitation of vulnerabilities. Right. So is really understanding you can't patch everything. Right. But I do think there is this notion of what I call privileged path dependent CVEs, meaning if exploited, it lands directly on a privileged plane. We have to be able to prioritize those and fix those fast, because I think those are the ones that's going to give a threat actor the foothold to do something operationally dangerous in the environment. So we have our work cut out for us. And I do think that privilege is a central component in building an effective cyber defense and a cyber deterrence framework, but also the basic visibility and having a very, very robust zero trust infrastructure and investment in that. I don't think zero trust should go away, but I do think it should be tightly integrated with a more privilege centric approach, because I do think that's the battleground. Well, identity is a battleground. I think the real war is where privilege lives within environments.
A
That was Kevin Green with Beyond Trust. A big thanks to Kevin for taking the time to share his perspective with our audience. That's it for this episode. The Priorities podcast is a production of Scoop News Group in Washington dc. Production work is done by Carlin Fisher. I'm Colin Wood. Thanks for listening.
Priorities Podcast – StateScoop
Episode: Is ‘privilege debt’ creating cyber risk in your organization?
Guest: Kevin Green, Chief Cybersecurity Technologist, BeyondTrust
Host: Colin Wood
Release Date: July 8, 2026
This episode explores the notion of "privilege debt" and its growing impact on cybersecurity risk within organizations, particularly for state and local governments. Colin Wood interviews Kevin Green, a seasoned cybersecurity leader, about the phenomenon of accumulated privileges, the evolving landscape of AI vulnerabilities, and proactive defense strategies. The discussion also covers recent incidents of AI jailbreaks, operational challenges in privilege management, and why privilege must become the focal point of modern cyber defense.
[01:53–05:53]
Notable quote:
"So all these things we see around these frontier models and accelerated vulnerability detection are things that in back in 2014 I had planned in my program before our entire division was dismantled..."
— Kevin Green, [02:32]
[06:30–08:33]
Notable quote:
“With every cyber attack, there is a cyber story. There's a, there's a prologue. And the prologue are the structural conditions that exist in your environment, which I call privileged debt.”
— Kevin Green, [07:30]
[09:00–12:00]
Notable quote:
“We can't solve world hunger in a day. So I do think if we understand how to take more of a threat informed defense approach, then we can prioritize the things that matter most.”
— Kevin Green, [10:30]
“At a point now where we have to concede something. And I think initial access is the thing we have to concede.”
— Kevin Green, [10:56]
[12:00–15:18]
Notable quote:
“Every AI has some alignment for safety. So it's the ability to persuade the AI to take another priority over the right priority. I call it convince me bug...at some point are we going to innovate?”
— Kevin Green, [12:45]
[15:18–17:11]
Notable quote:
“At the end of the day, I always say, even with AI, you need to have a safe, reliable, trustworthy policy that governs how you implement AI within your environment.”
— Kevin Green, [16:44]
[17:11–19:37]
Notable quote:
“Identity is not where the risk is. Privilege is where the risk is. So identity alone has no risk. Privilege gives the identity of risk.”
— Kevin Green, [18:47]
[19:37–21:40]
Notable quote:
“I don't think zero trust should go away, but I do think it should be tightly integrated with a more privilege centric approach, because I do think that's the battleground. Well, identity is a battleground. I think the real war is where privilege lives within environments.”
— Kevin Green, [21:25]
| Timestamp | Topic | |------------|------------------------------------------------------| | 01:53 | Kevin Green’s background and history in cybersecurity| | 06:30 | Defining privilege debt and the pitfalls of reactivity| | 09:00 | Challenges in eliminating privilege debt (visibility, compliance, resources)| | 12:00 | Frontier AI models and AI jailbreaking risks | | 15:18 | Implications for state & local governments | | 17:11 | What is privilege disruption? | | 19:37 | Holistic security—beyond privilege disruption | | 21:25 | Final thoughts on privilege as the new battleground |
Kevin Green’s approach is pragmatic and urgent, focusing on elevating privilege management to front-and-center within cybersecurity strategies. His key message: while new technologies (especially AI) and attack techniques are continually evolving, organizations must proactively address privilege accumulation and establish proactive, governance-driven defense frameworks. Visibility, automation, and robust policy are essential, and privilege disruption must be prioritized to truly mitigate operational cyber risk—especially in the public sector landscape.