Keeper Security’s Darren Guccione on Governing Agentic Identity
The emergence of non-human identities within enterprises has reached a remarkable tipping point, now outpacing the number of human identities. According to Darren Guccione, the CEO and co-founder of Keeper Security, traditional legacy access tools, which were originally designed primarily for human users, are increasingly ineffective when it comes to tracking, verifying, and governing these non-human identities (NHIs). This critical issue was brought to light by Guccione in a statement made prior to the opening of the Black Hat 2026 conference, a significant annual event for cybersecurity professionals.
Guccione emphasized that many privileged access tools were initially crafted for IT administrators who managed human logins, thus overlooking the realities of modern enterprises where non-human entities now dominate. These entities include automated systems that run Continuous Integration/Continuous Delivery (CI/CD) pipelines, execute services in cloud environments, manage Kubernetes clusters, and handle various tasks without human intervention. The rapid expansion of NHIs has exposed a detrimental gap in security, leading to reduced visibility and control for security teams, which is central to the annual discussions at Black Hat.
To address these challenges, Guccione proposed a unified identity governance platform that integrates robust monitoring and tracking capabilities for all identities, both human and non-human. This platform should operate on the principle of recording sessions and managing profiles in a cohesive manner, eliminating the inefficiencies of a fragmented system comprised of disparate tools.
“The speed at which the NHIs proliferated into the enterprise is far greater at the pace of the enterprise’s ability to defend against and govern them,” Guccione remarked. This statement captures the urgency required to adapt cybersecurity frameworks to fit the realities of today’s technology landscape.
In a video interview with Information Security Media Group (ISMG), which preceded the Black Hat USA 2026 event, Guccione delved deeper into several pivotal subjects. He highlighted the inadequacies of privileged access tools that were created with typical IT departments in mind, which struggle against the growth of multi-cloud non-human identities. He underscored that the limitation of these tools results from their inability to effectively manage the complexities of modern-day cloud environments, which are increasingly populated by automated services.
In addition to discussing the need for enhanced identity governance, Guccione also raised important points about cybersecurity funding. He advocated for the idea that cybersecurity initiatives should not solely rest in the hands of Chief Information Security Officers (CISOs) but instead need to be regarded as board-mandated priorities. This shift, he argues, is crucial for developing an effective overall strategy against emerging threats.
Furthermore, Guccione stressed the importance of quantum-resistant encryption, especially in light of new threats posed by artificial intelligence. As cybercriminals become increasingly sophisticated, utilizing advanced technologies to breach security systems, adopting encryption that is resistant to quantum computing attacks becomes essential for safeguarding sensitive information.
Guccione, who leads strategy, product innovation, and global growth initiatives for Keeper Security, brings over 25 years of extensive experience in technology and cybersecurity to the conversation. With his background, having previously co-founded Callpod and OnlyWire, he provides valuable insights into the challenges and necessary advancements in cybersecurity.
In conclusion, as enterprises continue to adapt to a landscape dominated by non-human identities, the dialogue initiated by thought leaders like Darren Guccione becomes crucial. The focus on developing a unified governance platform alongside the implementation of cutting-edge encryption technologies will be instrumental in navigating the increasingly complex cyber threat environment.
