Season 1, Episode 10

Identity Security on the Frontlines: How McDonald’s Built a Scalable Strategy

What does it take to secure 2.2 million workforce identities across 95 markets, when the vast majority belong to franchisees and licensees? Recorded live at Identiverse, our co-hosts Roy and Rob sit down with George Roberts, Principal Architect for Identity and Access Management at McDonald’s, to find out. 

Over the past eight years, George has helped bring every McDonald’s market onto a single global workforce platform, supporting around 1,500 franchise organizations in the U.S. alone and enforcing security strategy in an environment with 100,000+ account turnovers a month. For frontline crews who prefer to keep their personal devices personal, his team built a creative MFA approach inspired by old-school spycraft. 

As George puts it: “It’s really, really hard at scale to have perfection, and if you try to achieve perfection, you’re not going to make any progress.” 

This conversation is packed with practical ideas for making Identity and Access Security strategy work at any scale, including for identities who work beyond the corporate laptop. 

Key takeaways include: 

  • How George’s team strikes the right balance between security and user experience, and helps leaders understand the trade-offs 
  • How partnering with the business on a global training rollout brought every market onto one platform and allowed McDonald’s to enforce universal policies and controls 
  • Where George sees Identity Security heading next, from verifiable credentials to continuous identity and AI agents 
George Roberts: [00:00:00] The biggest myth is that identity is easy. We have 2.2 million workforce users- Wow … across 95 markets worldwide. Rob Ainscough: It probably doesn’t get much bigger than that in terms of identity. George Roberts: About 93% of our workforce identity is not McDonald’s employees. One of the challenges, of course, is trying to balance ease of use and operation for our frontline workers with the needs of security. We’re kind of 50% security and protection and 50% business enablement. I think where we’re heading is to a state where every person owns their own identity. They’re gonna get verifiable credentials from a trusted entity that they can then present when the situation is needed. Roy Akerman: Identity isn’t just an operational problem, it’s a security one, and most teams are figuring out in real time. Rob Ainscough: This is the podcast where we reverse engineer the meaning of identity security, sharing candid conversations about the people building, [00:01:00] fixing, and rethinking identity security from the inside. Roy Akerman: I’m Roy Akerman. Rob Ainscough: And I’m Rob Ainscough. Roy Akerman: Let’s dive in. Rob Ainscough: Let’s do it. Hi, everyone. We’re here at Identiverse recording Identity Decoded with Roy and also today, George Roberts. Hi, George. George Roberts: Hi. Rob Ainscough: How are you doing? Glad to be George Roberts: here. I’m happy to be here. Rob Ainscough: Very good. Very good. So George works at McDonald’s 2.2 million identities you’re working with George Roberts: Yes, that’s our workforce identity Rob Ainscough: scope Wow. So tell us more about your job, what you do at McDonald’s, and how the heck you manage- … 2.2 million identities George Roberts: I’m the principal architect for identity and access at McDonald’s, and I, you know, work on the strategy and the technology and architecture for our workforce identity, and I help with the, um, standards and policies for identity and access across the board at McDonald’s. [00:02:00] We have a, a great team that, um, manages a really complex and complicated identity environment. Like you said, we have 2.2 million workforce users- Rob Ainscough: Wow … George Roberts: across 95 markets worldwide. Rob Ainscough: It probably doesn’t get much bigger than that in terms of George Roberts: identity Um, we’re, we’re pretty large. I think there may be a few that are bigger than us, but not too many. Rob Ainscough: There’s kind of this thing that I get as an ex practitioner. So the company I was at, 450,000 people, right? But there’s this kind of thing where, you know, at some stage, a big number is a big number, right? After, like maybe 10,000, probably can’t do that manually at that point. But 2.2 million, something else in terms of numbers there. And, and were all those employees, or were you managing different types of identities and different employee relationships in that? George Roberts: Yeah, so McDonald’s i- is mainly a franchisee and licensee organization, so about 93% of our workforce identity is not McDonald’s [00:03:00] employees. So 7% of our, our identities are corporate staff or market staff in the markets that McDonald’s operates, or restaurant staff in the restaurants that McDonald’s operates. But we largely, worldwide, we largely don’t operate restaurants ourselves. They’re mostly operated by franchisees or licensees. So I think we’re, I think we have, like, 23 markets that we operate the market, but even in those markets, they’re largely franchised. Like the US market here, we have around 14,000 restaurants and, you know, th- the vast majority of those, I think it’s o- over 90%, are franchised restaurants. Rob Ainscough: I guess from an identity perspective, difficult to manage that kind of fragmentation in terms of, well, what will I know about these franchisee employees? I guess you’ve got different franchisees with different standards for the data that they’ve got or might send you. Like, how have you [00:04:00] broken down that problem? How do you, how do you kind of get a foundation for who works in McDonald’s? George Roberts: It definitely is challenging a- and especially because of the fact that we are in so many markets, and many of those markets are licensee markets, so they’re, they’re a third party company that runs the entire McDonald’s brand in that market. You know, ideally we try to put ourselves in a position where we have a single source of truth for the, the users in that market. Even- Even if we don’t have, like, a direct HR integration because in the US we have around 1,500 franchise organizations that run those 14,000 restaurants, so we’re not gonna do 1,500 HR integrations. But we have what we call a workforce management platform that is used for scheduling and time clock that’s used across the board in all of the restaurants. And while it’s not a full-fledged HR system, so [00:05:00] we don’t have all of the attributes, we have enough attributes that we can, we can use that. Rob Ainscough: Must have been an amazing journey to get that, get to that kind of m- maturity, right? It must have taken years and years to get to that kind of level in terms of dealing with this problem, right? George Roberts: Yeah, it absolutely has. I mean, I’ve been working on the team for the last eight years, and we’ve grown tremendously in the last eight years. When I, when I started eight years ago, I think we only had about 33% of our markets on the global platform and only about 800,000 users. So over eight years we’ve, we’ve gotten all of the markets on and grown the, the, you know, user base significantly. It’s all Rob Ainscough: about building, building, building, slowly building it up. George Roberts: Yeah. You know, I’ll be the first one to tell you that we’re not there yet, right? There, there’s always more to do. We’re- It’s never Rob Ainscough: done. George Roberts: We’re, yeah, we’re going through a big modernization effort right now and, you know, every- everything that we change is all about, you know, progress over [00:06:00] perfection. You know, that’s, that’s one of my sort of mantras is progress over perfection. It’s really, really hard at scale to have perfection, and if you try to achieve perfection you’re not gonna make any progress. Roy Akerman: I mean, there’s so many fascinating questions to ask when you’re speaking about scale, when you’re speaking about the diversity of identities. One of the things that make me very curious is, like, frontline employees, right? Which is like a very different challenges, and again, cultures, countries, regulations, things like that. Can you Get us a little bit of that thing, like how, what, what’s the challenges around there? George Roberts: One of the challenges, of course, is, i- is trying to balance the ease of use and operation for our frontline workers with the needs of security. And, and I think that’s a, it’s a common balancing act that we face in identity, where we’re kind of 50% security and protection and 50% business enablement, [00:07:00] right? You know, I, I like to talk, you know, with our leadership within M- McDonald’s. We’re, we sit within McDonald’s global cybersecurity, so obviously our, we report up e- through the CISO, and his focus is all about risk reduction and, and security, and rightly so. We’re like one of the only teams within cybersecurity that isn’t 100% focused on risk reduction and, and security. And so it’s an interesting challenge to find that right balance of security and, and business enablement, and ease of use for, for the users. And so one of the big things that we run into a lot with frontline workers specifically is they’re usually not, at least in our circumstances, they’re usually not on devices that we can trust. We can’t require them to use their personal device for work purposes. Now, we can support it, right? We can offer them the option to use their device for [00:08:00] multi-factor. So we can offer them the ability to use pass keys and the ability to use, you know, MFA applications and things like that, but we can’t require it. So we always have to have some sort of least common denominator factors. Roy Akerman: Is it kind of like collide with some people’s aspirations to make a full separation between personal devices and their, I don’t know, workstation at work? Like, did you see people that says like, “No, I will not use this for, uh, I don’t know, like, uh, getting a text message,” or, “I will not install this authenticator app,” or something like that? George Roberts: Yeah, absolutely. We do have, we do have some people… And, and, you know, that’s their right, right? Yep. Yeah. It’s their right to keep their private life private. You know, we, we run into challenges even with collecting an email address from users, you know, because we have to be very careful in how we state that to them. Like, we don’t wanna tell them, “Oh, we want your personal email address.” We tell them, “We want a non-McDonald’s email address,” right? Because we [00:09:00] don’t provide email addresses for all of our restaurant employees. The, the cost there is just tremendous. So We, we always have to be careful, like, ’cause people are like, “Well, why do you want my personal email address?” It’s like, well, we don’t. We just want you to give us an email address that we can send you email about work, and if you want to go out to Gmail or Hotmail or whate- it’s not Hotmail anymore, it’s Outlook. I’m old. Rob Ainscough: Is it? Yeah. George Roberts: Um, you know, if you wanna, if you wanna g- go out to Outlook or, or Gmail or Yahoo or AOL for, you know, w- anybody who wants to still use AOL. Is it still going? I think Roy Akerman: so. So, how do you authenticate them then, right? Like, uh, because th- you need to, uh, there is a personality and e- like, an entity beyond McDonald’s, right? But they’re coming to McDonald’s, they need to have a shared secret or something like that. Well, how do you deal with that without a device? George Roberts: Yeah, so we do provision an identity for them, obviously, and they’re gonna use, you know, a username and a password [00:10:00] as their primary factor. But when it comes to multi-factor, it is a struggle, it’s a challenge. Um, like I said, we do offer and encourage them to use a personal device if they have one for, you know, something like an SMS or a, or a MFA, a push notification MFA, or, or ideally, a passkey, but we can’t require it. And so we’ve solved that by building, uh, what we call our paper-based MFA, which is basically a, a, a printed sheet of, of codes, um, like old school spycraft that, that they can take with them, and it’s, it’s just a, a numeric sheet of codes, and when they go to authenticate and they’re prompted for MFA, the, the MFA system says, “Hey, give me code 72,” and they type in code 72, and then we know that they have that physical thing with them. You know, we can do things like, you know, set the, [00:11:00] the sheet to expire after a certain amount of time. Our managers in our restaurants can print new sheets for our crew people right in the restaurant. You know, so it’s, I mean, it’s not ideal. Nobody wants to carry around a piece of paper. I can’t count the number of times people have told me that they’ve washed them. W- you know, you put it in your back pocket wh- and then you go home after work and you throw your pants- They Roy Akerman: MFA on plastic, like. George Roberts: Yeah. But, you know, I mean, as a least common denominator, a way for somebody who really doesn’t want to use a device, it works pretty well. Rob Ainscough: It’s very much familiar from my experience, right? And I think it’s not just that you’re constrained on, on device and method, but, but also the requirements for them to be able to act as different almost personas in different circumstances. So for us, for example, there was them acting as a corp user, accessing their payroll, for example. Very different to them logging onto a till Sure right, in a shop or, or in a warehouse. And we had constraints [00:12:00] around what they could use in that setting. So, um, from a, a store’s perspective and a warehouse perspective, they were not allowed mobile phones in those scenarios, right? They just by policy weren’t allowed to use them for company policy, right? Just bad perception or, you know, whatever it was. Roy Akerman: So you went with paper as well? Rob Ainscough: So, so we went, we went, we went with plastic. Okay. We went with plastic, but we were, we were in a very similar space to you, right? How do I work around all of these constraints? And bear in mind, particularly when they’re operating as an operational colleague, the speed requirements, right? The simplicity requirements, the fact that people do forget things and lose things, and you still need them to operate your site, your store, your warehouse, whatever it is. You’re so boxed in on frontline worker. But remarkably, I think from a product perspective- It’s very underserved in the market, right? Everything’s almost aimed at someone sitting at a desk with a laptop. George Roberts: There are great [00:13:00] solutions out there that work well in a frontline worker situation. You know, you have FIDO keys a- and, and other things like that, but they’re costly, and they’re fine in the circumstance where maybe you have a factory worker where you don’t expect a lot of turnover. But in our case, you know, we’re in a restaurant, and we do have high turnover. You know, we often see new account turnover in the 100 to 120,000 accounts a month, right? And so, you know, if you’re, if you’re buying FIDO keys for them, you know, you’re gonna lose a lot of them. Rob Ainscough: Completely agree, and, and, you know, incredibly expensive and difficult to deal with those situations of forgotten or lost, let alone joiners and leavers and all that kind of thing. Yeah, Roy Akerman: I, I think this, this complexity and, uh, traditional… It’s not a traditional solution. I, I think it’s plausible, right? I, I, as an attacker, I’m thinking about how can I brute force that? How can I d- run an MFA, uh, bombing attack on MFA on plastic or, sorry, QR on [00:14:00] plastic, or, like, MFA as a Spycraft table, I don’t know, Russian cipher, whatever. And, and I think that it brings us to things that we spoke about last night in our IDU dinner, the Identity Underground Dinner, which is, uh, I think is one of your forward-thinking gigs about distributed identity, correct? George Roberts: Yeah, I mean, you know, long term, I, I, I think where we’re heading is to a, a state where the… every person owns their own identity, and they’re gonna get verifiable credentials from a trusted entity like a bank or a government that they can then present when the situation is, is needed. And so in- instead of us having to mint new credentials for every person who needs to interact with our enterprise, we can, you know, have a system of record that, that, you know, that they, they’re there, but we don’t have to have credentials that they use to [00:15:00] authenticate to us. They, they present Their verified credentials, we verify that they’re still active and that they’re coming from a trusted entity, and we use that to verify who they are, and then we apply the appropriate authorization and, and access controls, et cetera, because we’ve now verified, “Hey, this is John Smith,” instead of us having to take on the burden of trying to verify that ourselves. Roy Akerman: For example, like, you know, I’m using digital signatures, right? And some European countries are trying to make sure that I am who I am, so there’s a, a certificate authority, right, that I’m reaching out to. I need to notarize a request with my passport and everything. Someone needs to see me physically, and then they will, you know, provide w- with a certificate that have, you know, like, uh, the entire life cycle and things like that. H- how does this… I- is it different from distributed identity? George Roberts: Yeah, so in that case, there are various scenarios like with governments and with things like what you were talking [00:16:00] about, where the burden of proof is a lot higher, right? And so when you have gone through that burden of proof, you’ve provided the documentation that’s necessary, that is an ideal situation for that entity, whoever you provided that proof to, to issue you a verifiable credential, right? Because they’ve done the work and the due diligence to verify that you are who you say you are. And then from that point on, once they’ve issued you that credential, you can then present that credential to anyone who’s willing to accept it, and the person who is accepting it can verify it against the, the original issuer to say, “Hey, is this credential valid? And if the person is presenting this to me, it, can I trust that they are who they say they are?” Rob Ainscough: And I guess you’ve got an interesting kind of chicken and egg situation here of, you know, is it about, ’cause you’ve kind of got, I guess, a two-sided marketplace, right? People [00:17:00] supporting the acceptance of them, and supporting the issuance of them. And how do you see it? Because it’s, it’s still nascent, right? It’s still early days for this journey. I think it’s exactly the right journey for us to think about. But, you know, is it more about, you know, people pushing to want to use that stuff, or is it more about, you know, platforms being available for them to leverage? George Roberts: I hate to cop out and say- Rob Ainscough: Both. George Roberts: What? Rob Ainscough: Or neither. George Roberts: And, and, and some of my colleagues will, will laugh when they hear this, but it depends. But, no, I mean, it, it’s, I think it’s both, to be honest with you. It’s a little bit of both, right? You need to have enough o- of, of a- Yeah … availability of users who have been issued credentials and can get them in a fairly straightforward and easy manner. Before you will start to get people to accept them. But you’re not going to get people who want to go [00:18:00] collect their verifiable credentials if there’s nothing they can do with them. So you almost have to have a partnership between some early adopters, both from the issuance and the acceptance side. And I think we’re starting to see some of that with mobile driver’s licenses here in the US where you have states that are moving to issue mobile driver’s licenses, and you have scenarios that those licenses can be used, right? And, and I think they’ve recognized that, hey, we can’t roll this out without at least having some reason to get it. But once you start to have that initial implementation out there, and you start to have people have these credentials, then it becomes more relevant for other organizations to start to go, “Oh, well, hey, 20% of my customers now have these. Maybe it’s worth me taking a look at how can I incorporate this into [00:19:00] my workflow.” And then eventually, as more and more people get them, you’ll start to see that become the primary, and, and hopefully it will just accelerate from there. Roy Akerman: I think that we- early on we, we, we discussed about, you know, how do you enable business, right? And we spoke a little before the show about what do you need in order to adopt a new technology, right? It needs to be accepted, what you said, like 80% of the market, something like that, because you need to actually address so many markets. Right. And I want to transition a second, like the discussion from enabling the business and the connectivity to maybe one or two ways that you see, uh, like when you’re using identity to reduce the risk to the business or like to play the security part of the CISO, as, as you said. Because I guess that if the system will be down because of technical issues, they will wake up the CISO anyway if he responsible for this as well. But from the security aspects, like anti-threats and things like that. George Roberts: You know, a couple of key things come to mind right away. Up until, you know, five years ago or so, I, I think I had mentioned that, you know, we only had about [00:20:00] 33% of our markets that were using our global identity platform, and we thankfully were able to partner with the business. They wanted to roll out a, a training application globally and, and we were like, “That’s great, but we’re only rolled out to about 33% of the market.” So And you’ll have to come along for the ride and help us push this. But once we were able to roll that out, that business enablement activity now allows us to be able to set policies and to be able to secure all of the users the same way. Because those other 66% of the markets that were not on our platform before, they still had identity needs, but we didn’t have any visibility into them or how they were operating, and so we didn’t have the ability to incorporate them into our security plans, into our, uh, you know, our, our obser- observability levels- It’s a false bridge et cetera. Rob Ainscough: Yeah, exactly. George Roberts: Yeah. And, and, like, we had no idea, like, how [00:21:00] secure they were. Now, with everything all coming through a single platform, we have visibility over it, and we can ensure that we’re, you know, applying the right security principles, the right policies, and getting the data into the f- to the hands of the people who need it and the systems that need it in order to be able to make those decisions, like our SOC. Rob Ainscough: Spookily similar to my experience, right? How did we- We are George Roberts: all one, man. Rob Ainscough: We’re all one. How, how did, how did, how did we get to a point where we, um, gave everyone a Tesco.com, uh, account? Well, because there was an ERP coming in that meant they needed single sign-on, and we needed to protect it So it was a business enabler that led to us securing the business better because it gave us a surface, a reason, a driver, a deadline, and buy-in across the business to make it happen George Roberts: But the thing that’s interesting is you would never get there if you proposed to the business that it would be more [00:22:00] secure- That is what I wanted to say. Of course … to give everybody an ID. Rob Ainscough: And, and I think it comes back to one of those key things where, where exactly, ’cause we constantly say, you know, “This is a board level concern. Identity- Yeah … is a board level concern.” But we gotta anchor in things the business really cares about, and I think there’s been such a drive, particularly for frontline workers, but generally around, um, the digitalization of the frontline, right? And the need to make that easier, more efficient, more effective at the front end, so ultimately you make more money. Roy Akerman: Yeah, yeah. It seems like s- simple principle of psychology, right? Like, uh, what will you invest in more? Prevent something bad from happening or letting something good happen, right? Business enablement, growth or whatever. That, that’s kind of like, I think, th- that’s a right way to play it. I, I heard about… I think 90% of my discussions over here were exactly the opposite, how the business does not appreciate security and will see this as like a burden, and like, uh, the, the, uh, the hardships are trans- translating security value into business value in so many cases. So [00:23:00] that, that’s plausible. And I think that in very large, I mean, super large, extra large, extra, extra, extra large systems are there, I mean, there’s no other way. If things will not play right together, even if it takes a lot of time, if the business will not be connected with… Uh, I mean, identity enables the business, and security is an application on top of that kind of like path. Many of it will not be re- built like that Seems that, you know, like, there’s no other way. There’s one thing to say, right? Rob Ainscough: Yeah, no, I think almost that, that scale that you’re operating at, as you go through that kind of a transformation, it really does drive a lot of diff- disciplines around automation, ’cause you can’t do it at scale without it, right? Around how you’re building that, that platform and those capabilities that you need to serve that audience puts a lot of pressure on that system to, to get it right and to scale it. George Roberts: You know, I think one of the key things too is that it’s really important for the rest [00:24:00] of your technology organization to see you as the identity org- as the identity team. Because historically, w- what we’ve seen is that identity often is the last team to be engaged when there is a new effort going on. Yeah. And we really need to be one of the first ones, because the decisions that are made around how a system is implemented, how a system is secured, how the role management is done, how it can plug into the environment, and how they can be successful in rolling it out, are critical. And when you get brought in two weeks before the go live date, like, “Oh, hey, maybe we should figure out how to do this SSO thing,” you know, it’s, it’s a recipe for disaster. And it does happen. You know, and so that’s, you know, one of the key things that I’ve, you know, that is part of my [00:25:00] job, is to make sure that we’re plugged into the rest of the organization in such a way that they know who to come talk to when they’re, when they’re looking at standing up some, something new. Rob Ainscough: I always thought as well, just to add to your point, ’cause I think it is so important, right, is what capabilities can I bring for you, right? So I always thought, you know, of course, I can offer you an account with single sign-on and protection, blah, blah, blah. I can offer you a simplified version of that for operational use cases where you don’t wanna be putting in your full email address and password, but also I can offer it for you if you’ve bought a system or if you built it in-house and you use the custom stuff. Tick, tick, tick, tick, tick, and here’s the capabilities I can offer you. And almost having that menu ready for them to use and leverage in that scenario once they know who the right person to talk to. Roy Akerman: You spoke about, you know, sometimes identity people are brought last to deal with a new situation. And Frontier AI and Mythos [00:26:00] and this entire hype about AI weaponized attacks, where did they find you? Who knocked on your door? Did they ask for, for, for answers from you? Who was it? I mean, it came from the security team, it comes from… George Roberts: It’s such a challenging time now, right? Because- On the one hand, I, I welcome it because it really does give us a huge arsenal of tools to really make things better. But like any good thing, bad people can make it do bad things. And so, yeah, I mean, I think it’s gonna be a race for a while to patch as many things as we can and, and hope that we can outlast the ones who are trying to, to, you know, get past them. I mean, any good enterprise does. We have the, you know, the typical set of, you know, processes and, and, [00:27:00] and pipeline tools, and code reviews, and y- y- you know, all the SAST and DAST tooling and, uh, all of that stuff, right? And we have a really great red team within our cybersecurity organization that bangs away against stuff and finds stuff all the time, which, you know, it’s so funny because y- you, you know, sometimes leaders are like, “Oh my God, look at all of this bad stuff the red team found.” And I’m like, “Oh my God, look at all of the bad stuff the red team found.” “This is awesome,” Roy Akerman: right? That’s the way. But without opening the conversation, I’ll just say that we know that Mitos and other, uh, models actually love identity, right? Because the way that they read us humans is through this awkward trust relationships that we have among each other, right? We cannot operate without trust. And I would imagine that if, if, if there will be sarcasm with models and others, they will look at us like, “Oh, do you trust this? I mean, this is what you need in order to let us pass?” Okay, be it. So, I [00:28:00] mean, maybe in a couple of months we’ll meet again and we’ll speak about the role of identity as the last resort or the front line against those models, and I think that hopefully the complexity of your environment will make the, the, the model go to the loop of death of whatever because it’s really hard. But, like, out of the 2 million, where, where, where, where am I starting? Yeah. It’s a good segue to our last part, which is the rapid fire question. The, the Rob Ainscough: dreaded Roy Akerman: rapid fire questions. Yeah, this is where you’re using the fine Brit accent in order to bring- … a little bit of, uh, sarcasm George Roberts: to the party. Yeah, and I, I was prepped in advance, and I have no idea what I’m gonna answer for any Roy Akerman: of these, so. Of course, yeah. We were… And it- we overem- you with, uh, little quizzes. It’s a surprise Rob Ainscough: for everyone. George Roberts: It’s a surprise for everyone. Yeah. Yeah. Rob Ainscough: That’s good. Very good. All right, so we’re gonna start with a myth. What’s one identity or security myth? George Roberts: I’m gonna look at this from the business perspective. Rob Ainscough: Sure. George Roberts: And the, the biggest myth is that identity is easy. Right? Roy Akerman: But just provision a username. George Roberts: I mean- Give it the Roy Akerman: password … George Roberts: like, how hard can it [00:29:00] be to let somebody log in? Like, h- I, I, I mean, I get it. Obviously, you know, they don’t, they don’t know the ins and outs of, of how complicated things are. But yeah, I mean, it’s It’s a h- it’s a hard thing to do to explain to people who are not familiar with identity why identity is so hard. Because at its core, identity really isn’t that hard. In abstract, when you, when you talk about identity concepts, it f- it shouldn’t be that hard. It’s everything else that you have to plug into- It’s their fault … and where you, and where you get the data from, and what the data looks like, and all of that stuff that makes identity hard, right? So in a green field, perfect sunny day situation, identity really isn’t that hard. Roy Akerman: I mean, when somebody will ask you, like, “Why is it so hard?” Like, just tell them how many applications do you have there that you need to connect the identity. And it’s not the hundreds, right? George Roberts: [00:30:00] No, it’s in the thousands. So question number two, can you tell me one thing that Rob Ainscough: identity or security leaders get wrong? George Roberts: Security leaders, I’m gonna g- I’m gonna kinda call back to what I said before where we have a 50% security mandate or protection mandate and a 50% business enablement and, and UI, UX mandate. Security leaders often get wrong that we are a security-only function. And business leaders often get wrong that we are a business enablement only function. You know, that’s something that we have to navigate and, and educate them on, and find the right balance. And sometimes the balance isn’t 50/50. Sometimes it is leaning more towards security, and sometimes it is leaning more towards the business. But leaders need to understand what those trade-offs are, and so that’s our job, to make sure that they understand what the trade-offs and the impacts are [00:31:00] if you choose not to go 50/50. Rob Ainscough: That’s George Roberts: very important. Right? Because if, if you don’t, somebody’s not gonna be happy. And if they’re not gonna be happy, it’s not… It shouldn’t be me telling them that they’re not happy. It should be my leaders telling the other leader that they’re not gonna be happy. Rob Ainscough: At least tell them both why they’re both not happy. George Roberts: Right. Exactly. Hey, if every- … if, if everybody’s not happy, then we all win, right? Isn’t that how that works? Rob Ainscough: That’s how you get funding. That’s right. Um, right. Excellent. So third one, a hard truth. Tell me one hard truth about identity. George Roberts: Vendors build things for perfect customers. You know, I’m just thinking about the breadth of users that we have, and you come someplace like Identiverse, and you talk to vendors and they’re like, “Everybody should be doing passkeys. And every- you know, everybody should be doing this, and you should be doing agentic AI, and here’s how you should solve these problems.” And it’s like, it’s like, “Man, I’ve got so many other problems to solve before [00:32:00] I can solve those, and there’s no way I can get all of my users on passkeys,” not in the current state of things, right? I don’t blame or begrudge the vendors that, right? Because it, I understand that you have to build for modern, current things. Yeah. But the reality is, the hard truth is, that most of us who are in enterprises that have been around for more than two years have really messy, complicated environments. And, and as much as we would love to come in and just slap something new on there and say, “This is the way it is,” we just can’t do it. And, and so that’s my hard truth. Roy Akerman: So you’re saying I’m not your ideal customer profile, right? George Roberts: Well, like, and, and honestly, you know, those of us who work in sort of corporate on the enterprise side, we [00:33:00] have a little bit of an ivory tower syndrome sometimes because we’re lucky. We have company provided devices, and we have laptops, and we are using all of the latest and greatest in modern stuff. And it’s hard sometimes to remember that that isn’t the same everywhere. Rob Ainscough: Coming back to our frontline worker example, what about the 70-year-old who doesn’t have a mobile phone? George Roberts: Yeah, exactly. Rob Ainscough: What about that person? What are we doing about them? George Roberts: Yeah. Rob Ainscough: That’s the question. George Roberts: We’re, we’re printing them a, a paper based MFA- We are is what we’re printing them, right? We Rob Ainscough: are. We are. We’re giving them a scratch card. So the final quick fire question is, one overhyped trend in identity? George Roberts: There’s two themes to the conference this year. It’s AI and agents and continuous, you know, identity. Those, those are the two trends. I don’t think either one of them is overhyped. I just think we don’t have answers for either one of them yet. Continuous identity is maybe a little bit easier. There are some standards, and there’s [00:34:00] some… It’s, it’s a little bit further, but there’s still a lot of open questions. There’s still a lot of vendors that don’t support it yet that I would love to see support it. But those vendors probably have questions like, “Hey, how, how do we solve this problem with, with continuous identity?” But AI, to me, I don’t think it’s overhyped, but I think it’s… There, there aren’t a lot of answers yet. And so what often happens at Identiverse and at other conferences is you, one year you get, “Oh my God, this is, this is a problem. This… Oh, we gotta solve this.” A- but there’s no answers, and that’s fine. Roy Akerman: I know what you’re going to say. And, and- And the other year you’re George Roberts: getting- And, and then the next year you come back and it’s like, “Okay, we have all of these solutions to these problems.” And I think that’s kinda where we’re at right now, right? I- is, like, yes, is AI and agent security and, and identity related topics huge? Uh, absolutely. I mean, like anything related to AI, it has gone so fast. [00:35:00] The, the trajectory of how fast people are implementing it without the right guardrails is a little frightening. Um, m- but I don’t know that we have the right answers to solve that yet, and we can’t tell the business, “No, you can’t use these tools.” So we’re kind of between a rock and a hard place right now. Hopefully we, a bunch of people come away from this conference with, with an understanding that like, “Hey, we gotta spend the next year solving this problem.” Roy Akerman: It’s like a hype cycle that goes- Right … so quick. George Roberts: Right. Roy Akerman: Right? So that, you know, you think that you solve it, but then, you know, like the problem grows like 10 times or exponentially. So I have another last question if I may. Last last question. I get a George Roberts: bonus? Roy Akerman: So any epip- I’ll give you, I can, like, uh, extra fries. Okay. Any epiphan- epiphany moment, any kind of like enlightenments that you got when you heard, I don’t know, a metaphor, uh, at the beginning of [00:36:00] solution, something that was, like somebody said on stage or something in this conference so far? George Roberts: You know, honestly, I mean, I think continuous identity for me, like it wasn’t new. Like I… It wasn’t something that I hadn’t heard of before. I’ve obviously talked to, you know, many of the folks who are working on the standard and have, have seen sessions about it in past years. But I was at a meeting with some folks and saw some architecture, proposed architecture diagrams of like kind of how you could do some of the continuous identity in, in a, like in a real way. Like, hey, how could you actually implement this and, and, and, you know, have a, a real world example of how to do it? And I think in the past I kind of thought- Yeah, that’s a great idea. I’m not quite sure how we would do it or whether or not it’s something we could do at this point. Like Roy Akerman: zero trusts. George Roberts: Yeah. You know? Yeah, and [00:37:00] I’m, I’m kinda coming away from this with some ideas around, you know, maybe we can’t solve everything at once, but progress over perfection. We may be able to have some cases where we can put these principles and these capabilities into use, and then e- over time, as, you know, vendors start to support it more, we can light up more capabilities on that. But I think I want to have us be ready to, to take those, to take that on when the vendors are ready to support it, versus having to then scramble and be like, “Oh, look, everybody’s supporting it now. Oh, great. Now I gotta go.” Roy Akerman: I think that that’s a, that’s a great take, and that’s encouraging. I wonder if, like, in the job descriptions in, like, senior levels in McDonald’s, that, like, checking for optimism and patience, like- sounds exactly the opposite of what I can bring. Yeah. And with that, George, we know that you are super busy. We know that tons of vendors went after you. Thanks for choosing to [00:38:00] join us, to Identity Decoded, being super transparent, sharing with all the creative ideas, like, around frontline workers, sharing about this crazy, interesting, uh, you know, complexity that you have in the business. And we hope that the next following days in the conference will be even greater. Thanks for the time. Rob Ainscough: Yeah, absolutely. I appreciate the invite. Thanks, guys. That’s it for this episode of Identity Decoded. Roy Akerman: If this conversation changed anything that you thought about identity security, share it with someone who’s working through the same challenges. Rob Ainscough: And don’t forget to follow the show so you don’t miss what’s next.

Identity Decoded

with Roy Akerman & Rob Ainscough

Subscribe so you never miss a new episode.