
Loading summary
Commercial Narrator
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block. Or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check responses set up required compatibility and availability various 18/2
Duracell Advertiser
are all batteries the same? That's like asking if all soccer players are the same. Take Messi, the most decorated player ever. Is there any other player who has achieved that? No, just him. Now take Duracell. Is there any other battery with power boost ingredients inside? No, just Duracell. Remember, goats only trust goats because they're built different and Messi only trusts Duracell.
Commercial Narrator
Foreign.
Brian (Host)
Technologies Home of the Digital Executive Podcast do you work in emerging tech? Working on something innovative? Maybe an entrepreneur? Apply to be a guest at www.corazon.com brand welcome to the Digital Executive. Today's guest is Jeffrey Mattson. Jeffrey Manson is a serial entrepreneur and globally recognized cybersecurity and AI executive with decades of experience building market defining companies and technologies that protect the world's most critical systems. He is currently the CEO of Secure Auth, a premier identity company securing customer identity, workforce identity, agentic identity, continuous risk monitoring and presence authority for the world's leading Enterprises. Founded in 2005, Secure Auth protects millions of identities every day for top federal agencies, the largest financial institutions, healthcare organizations and global retailers. Well, good afternoon Jeff. Welcome to the show.
Jeffrey Mattson (Guest)
Well, thank you Brian. Happy to be here.
Brian (Host)
Absolutely my friend. I appreciate it. Hailing out of Los Altos, California, I'm in Kansas City and I just appreciate you making the time today. I know sometimes it's hard to get on these different calendars these days. We talked about things being short right brevity and podcasts and all that, but I just really appreciate that. So Jeff, if you don't mind, I'm going to jump right into your first question. You've built and led companies across network engineering, enterprise security, AI, native threat detection, and now identity spanning giants like Juniper and Huawei, all the way to ventures you founded from scratch. What's the through line in that career arc and what drew you to take the CEO role of Secure Auth at this particular moment in the market?
Jeffrey Mattson (Guest)
Well, thank you Brian. Yeah, the throughline has always been really the same question. It's different layers of the stack. It's who's allowed to do something and what can they actually do at the moment they try to do it? And so when we talk about network security and networking, it describes where you can go on the network, where you can go in an enterprise, where you can go in the cloud. Whereas identity is the discipline of describing who you are and what you're allowed to do. And so putting those two things together, we have this modern approach to identity which says wherever you go in the network, at any point, we need to figure out who you are. And at that moment, when you try to do something, if you're allowed to do it. This is called the principle of zero trust. It's the idea of not saying, oh, okay, we've let you into our network past our firewall. Now you can go wherever you want. We're saying often bad guys do get into our network, and we have to assume we're breached at all times, assume that we've been compromised, and we have to have protections at every point in the network, at every layer. The reason I came to Secure auth, though, is because they're on the very cutting edge of solving one of the most difficult problems we've ever faced in security as a result of by means of using zero trust principles. And that revolutionary change is. Well, I'll just put it in perspective. At Secure Auth, we have financial institutions which have hundreds of thousands of employees, and we've gotten them to the point where they can all log in to work without having to memorize a password. We've gotten to the point in the technology where we've gotten beyond passwords. We use passkeys and biometrics and other things. And we also have completely eliminated, at the same time, the possibility of them being phished, of having a phishing attack. We reach this point where we've basically secured the employee access experience. These customers say, all right, you've secured our employees. But now for every employee, employees are actually just a small number of the entities that we need to secure, because now we have these agentic AI processes running through our environment. And so AI agents, they're like ghost employees. They're like a new workforce that can be ten hundred, a thousand times the size of the original workforce. And they are, you know, we're used to having to secure humans, and humans have accountability, and humans know that they'll be punished if they do things that they, you know, they shouldn't. Agents do not have that accountability. You know, there's actually no real way to punish a. An agent in any meaningful form. Humans, they're slowed down by what we call biological friction, which is they can only do things so quickly. So I have the right to delete entries in a database and if I had enough time, I could delete the entire database. Well, an agent can delete an entire database in less than a minute. So they don't have biological friction, they don't have biological accountability, but they have the power of automated processes. They don't have identities in any traditional sense. And on top of that there, as we saw in the recent news in the last two weeks, you know, Anthropic had to withdraw one of its agents because it was easily jailbroken. And there's been a lot of discussion about the fact that it's impossible to stop tail breaking, it's impossible to stop prompt injection, it's impossible to actually make a model completely secure. You can take some steps to mitigate it, but you can't make it secure. And even if you do make it secure, it can still do unpredictable things. It's a stochastic process. It's not deterministic. So this is basically the sum of all fears in the identity and networking space is having these AI agents as delightful and powerful as they are having them running around the enterprise, accessing database, accessing sensitive information, doing transactions. It's, you know, quite a bit of risk and it's, it's very difficult, a challenge to solve. So I thought Secure Auth has been in the business for 20 years and has this very broad portfolio. They have, you know, a strong base of customers and in finance and health care and energy, defense and large retail. So very good customer base to work with to solve this problem with, and a very good base of technology to do it. But they're also the right size that they can move quickly. So I think I've made the right choice. I think we've been pulled into a lot of opportunities and we're at the cutting edge of this very exciting time in security.
Brian (Host)
Thank you. Really appreciate that. You certainly went through a bit here, obviously talking about what a network is, the path you traverse, your identity, who you are, what you're allowed to do, and as you really plainly put, zero trust environment. And those principles are something that we have to live by. And that's what Secure Auth does. And you mentioned today being one of the most challenging times because you went into the threats and just some of the nuances with agentic AI. Right. You talked about agents and having no biological friction or accountability. But there's a lot of times these agents are able to taken control of and just making a Real tough environment for CISOs and CEOs like yourself to kind of manage. So I appreciate that. Jeff, you described identity as evolving from a static login check into a live, continuously updated map of relationships and authority. What broke down in the traditional IAM model and why is that shift happening so rapidly right now?
Jeffrey Mattson (Guest)
Well, you can think of it. It's an excellent question. And you can think of it the same way as we've evolved from having this concept of a single firewall that protects your internal network from the external big dangerous Internet. You know, that was an adequate concept at one point, but it's only a single point of protection. And in the same way you're used to logging into different things and in fact now you actually log in your identity. Your logins are used hundreds of times a day. Often you go to the supermarket now and you use an ID to log into their customer rewards program. Same thing happens when you go to the gas station. The problem with this approach is that your identity is not really static. You could log into a system and you could be running for quite a while and you could have your account taken over by a bad actor and that bad actor could then use your authority to do whatever they wanted to do. And this is very common way that attacks are done. In fact, there is a class of threat actors. There's a business called the access brokers. And access brokers, all they do is they will get you into someone's network. They will, they will penetrate that first hop, they will get you authenticated. They can find credentials on the dark web. It's easy to, if I forget my password, I always just buy it off the dark web for less than a dollar. They can also do things like SIM swapping. They will go to a mobile phone store in the suburbs and they will bribe, wheedle and control and threaten sometimes even employees to change the, the SIM assignment of a phone so that your SMS will be received by them and they can use that as a way to get in. So getting past that initial authentication is, is not that difficult. You know what, what identity is turning into is more of a set of continuous checks to make sure you actually are who you say you are and to make sure your intentions are good. And so I think we're moving away from this concept of static identity more towards this continuous authentication, continuous authority and more from the idea of, of access. Just being able to get into something to intent to figuring out what you're trying to do. And are you allowed to do that? And this becomes extremely important with you Know once again with agentic AI, because as we mentioned, these agents, their identity, their intentions could change at any time. A model that you've been using for quite a while because they're unpredictable, it could suddenly start misbehaving, it could do something it's not supposed to. And it could also be hacked by a bad actor very easily through prompt injection, for instance. So these continuous checks and continually monitoring the, you know, the identity of the actor and the intention, they become paramount.
Brian (Host)
Thank you, appreciate that. There's just so much going on here. And you talked about, you and I both worked in this environment where firewalls were the main security. It's a thing of the past now. They only looked at the perimeter security basically. But now that's why zero trust. And you've heard this zero trust architecture, all these terms are being used because we need to rethink how we do security. And you talked about that. Because hackers easily social engineer their way. If they can't scrape credentials somewhere, they'll definitely use social engineering just to get into that first level level of authentication.
Jeffrey Mattson (Guest)
Absolutely.
Brian (Host)
So appreciate that. And talking about that static identity versus continuous identity, I think it's really important. So Jeff, Secure Auth's platform includes biometric continuous identity assurance and real time risk evaluation rather than a one time authentication check. Why is that architectural shift so significant and what threats does it defeat that perimeter based or session based model simply cannot.
Jeffrey Mattson (Guest)
Yeah, well, what we've seen is there, you know, there's two traditional threats that have bedeviled enterprises that are overcome by weaker authentication warms, you know, so just using passwords, passwords are just inherently insecure. People either use overly simple passwords and they repeat passwords. And so if you actually, you know, steal one, you have what's called keys of the kingdom. And then administrators can try to make very complex passwords. We have financial companies that, that you know, mandate 16 digit passwords with all kinds of arbitrary rules associated with them. And not only is it tedious for the employees, they have to pound them in several times a day. You can't use a password manager with the, you know, VDI with a virtual desktop, for instance, so they have to manually enter these, but they end up often storing them insecurely, writing them down, you know, on paper, or storing them somewhere on their, in their environment that makes it easy for them to be stolen. So we have a lot more factors that we can use to really eliminate passwords and come up with very strong authentication. And they generally tend to use biometric capabilities that are available through PCs and Macs and mobile devices. You know, they can recognize your face, for instance, or your fingerprint. And they also generally have hardware support to store credentials securely in a way that they can't be stolen. And we call this passkeys. A lot of people see requests to use passkeys pop up and I don't think we've done a great job as an industry explaining to end users actually what they are. But that's been the one failure in the rollout of passkey is that the great success has been, you know, we're basically combining that biometric authentication of your device with the device itself. You know, the fact that you're accessing, you're accessing a device that is associated with your identity and using strong cryptography to, you know, verify that you are who you say you are. So that's been a huge advance in the field for humans accessing networks. Now a session can always be overtaken by a man in the middle attacker or by someone else taking over an account. And that's why they need to be monitored continuously and challenged continuously. What we do is we use behavioral profiling to see if a user is behaving in a way that's suspicious. And if they are, then we may ask them to re authenticate, we may send them some challenges and introducing risk where a bad actor could actually be hijacking an account. But we think we've advanced quite a bit in, in that respect. Now of course, all this changes with agents because they don't have bio, there's no biometrics associated with agents. Agents are not living creatures. They don't have fingerprints or faces. So you know, we, we do need a new paradigm for that. But then new paradigm, as you see from what happened with Anthropic last week, is, you know, this concept of non US citizens not being able to access the most advanced model that Anthropic offers due to export controls. And the only way for Anthropic to deal with that was to shut off all access to their models because there is no way to, to determine whether an end user was a foreign national or not. And you know, I think what that's arguing, what that's veering us towards is more of a KYC model, more of a know your customer model as we see in the finance industry, in which this strong authentication will be an important part of being able to use a model. Right? So if you want to access a very powerful model, you'll need some level of certification, maybe citizenship, but maybe it's Also that you're, you know, if you're, if you're looking at doing biological research, that you are actually a legitimate researcher and you're not someone who is trying to, you know, engineer some sort of bio terrorist attack. And so you, so you see this, this human based strong authentication will probably dovetail with, with agentic AI at some point soon.
Brian (Host)
Thank you, really appreciate that, lot to unpack there. But at the end of the day we all know this passwords are inherently secure. As you talked about challenges of people, especially admins, we've all been there trying to manage these complex passwords that they're using every day and people start to create shortcuts. So it's kind of crazy. But you did highlight some things around pass keys. I think you're right. There should be some better education, better integration. But that biometric identity of a device that's owned by you is very helpful to thwart threats. Of course. But we all know that man in the middle scenario, we've all been there, we've seen how those work. So I really appreciate that. And Jeff, the last question of the day. As agentic AI continues to mature and the boundary between human action and machine action blurs further, where do you see identity security in let's say five years? And what does Secure auth need to get right today to be the company that defines that future?
Jeffrey Mattson (Guest)
Well that's a great question and I think for the people in the identity space think that this is a great time to be alive because you know, Identity used to be sort of what my kid would call an NPC non playing character in the security world. It's, it's, you know, it's necessarily something that's necessary but the hot area is responding to actual hacks and you know, incidents for instance, and, and going after bad guys. Whereas Identity is just bedrock platform on which other security is built. But now Identity has, you know, what they call, you know, main character energy. It is a, the fundamentally the anchor for securing Gentex. And I think five to 10 years from now, you know, even sooner, you will see a revolution in software and in the workforce where the majority of work is being done with a collaboration between humans and swarms and networks of agents. Just as we went from monolithic applications to microservice distributed applications, from on prem to cloud, I think you'll see a vast distributed network of agentic AI serving human needs. And right at the center point of that will be this identity based zero trust architecture where every single interaction, every action taken between one agent and another or between a human and agent will have to be carefully authorized, verified and examined for risk. And that is the future of security. I think we have an opportunity, it's almost a clean slate. We have an opportunity to, to do this right. Security has always tried to catch up with other technology trends and there's always tech debt associated with, with getting security involved. But I think we can be involved from the beginning in this new revolution where we can come up with a, a secure zero trust layer that will sit between the agents and allow them to seamlessly interoperate with each other, allow this technology to progress very quickly. As I said, it's wonderful, it's delightful, it's powerful, but we need some way to, to control it. And in order to keep it from exploding in complexity, that, that way of controlling it needs to be a completely separate concern. And so I think it's a great time for us to use zero trust based identity principles to, to address that concern.
Brian (Host)
Thank you. 100% agree with you there. Zero trust is where it's at today. It just has to. And you talked a lot through those examples of why that can happen. But people are definitely saying this time and age is really interesting and exciting time. But as you said, the security world is a little bit chaotic. This landscape with all these threats layered with agentic AI as an example. You also did mention the future must hold a strong collaboration between human machine as we're going to see where tasks are handed off from agent to agent, agent to human. In some cases all those handoffs will need to be validated along the way. And I thought that was interesting. So thank you and Jeff, it was such a pleasure having you on today and I look forward to speaking with you real soon.
Jeffrey Mattson (Guest)
Thank you Brian, it's been a real pleasure.
Brian (Host)
Bye for now.
The Digital Executive – Episode 1278
Geoffrey Mattson: Death of the Password – Why Zero Trust Is the Future of Security
Date: July 3, 2026
Host: Brian, Coruzant Technologies
Guest: Geoffrey Mattson, CEO of SecureAuth
This episode explores the rapid evolution of digital identity security amid the growing influence of agentic AI in enterprises. Geoffrey Mattson, CEO of SecureAuth, discusses the demise of password-based security, the rise of zero trust architecture, and the new challenges brought by AI agents operating alongside or on behalf of humans. The conversation moves through shifts in authentication models, the importance of continuous identity assurance, and what it will take to define the future of security as humans and AI increasingly collaborate.
[02:48]
Notable quote:
“Humans, they're slowed down by what we call biological friction...An agent can delete an entire database in less than a minute. They don't have identities in any traditional sense.”
— Geoffrey Mattson [05:38]
[07:46 – 11:47]
Notable quote:
“We're moving away from this concept of static identity more towards...continuous authentication, continuous authority...and figuring out what you're trying to do, and are you allowed to do that?”
— Geoffrey Mattson [09:57]
[12:46 – 16:58]
Notable quote:
“Passwords are just inherently insecure...but that biometric authentication of your device that's owned by you is very helpful to thwart threats.”
— Geoffrey Mattson [13:23]
[17:51 – 20:17]
Notable quote:
“As we went from monolithic applications to microservice distributed applications...you’ll see a vast distributed network of agentic AI serving human needs. Right at the center...will be this identity-based zero trust architecture.”
— Geoffrey Mattson [18:31]
Mattson’s tone balances technical insight with urgent pragmatism. He is candid about industry shortcomings (“failure in the rollout of passkeys”), optimistic about new opportunities, and precise in his explanations—making often complex subjects accessible without oversimplification.
This episode is essential for CISOs, technology leaders, and anyone curious about enterprise security’s future. Mattson explains why zero trust is non-negotiable in an AI-powered world, how continuous authentication beats traditional models, and what it will take to keep identity—and by extension, all digital interactions—secure as the boundaries between humans and machines continue to blur.