Host: Hello everyone, we are back with our latest episode of ExtraMile by SecureITWorld featuring leading experts as they break down actionable approaches and tangible takeaways that matter the most in the tech world. I'm your host Rittika and for today's episode, we are going one on one with Itamar Apelblat, the Co-Founder and CEO of Token Security. The firm accelerates the secure adoption of agentic AI by discovering AI agents across an enterprise setup.
Our guest Itamar is a serial entrepreneur with more than 15 years of technical and leadership experience in cybersecurity. So, in this discussion, let's go behind the scenes from Itamar's role in unit 8200 to the boardroom, spotting invisibly agents, launching Enso, the future of identity and access management, and more. So great to have you here with us, Itamar, welcome!
Itamar: Yes. Great to be here. Thanks for the introduction.
Host: So you co-founded a fintech company, served in unit 8200 and now lead Token Security. How has your approach to cybersecurity leadership changed throughout your career span?
Itamar: Yes. So, I started in the 8200 unit and over there I was serving in the small team that was in charge of securing the data and network of the unit. So basically, the CISO of the unit, he was my manager, and I was a software engineer, and I was building stuff, building security product to a massive unit infrastructure that is also heavily targeted.
So how can you protect such a complex environment and also an engineering environment to keep involving? There's a lot of different engineers and security researchers that are doing their own stuff. How can you support them?
And I did that for 10 years. So I grew with that team that started as a small team, but then we saw what you can do and what we need to defend. And then we moved from a 20 team members to 200 and I grew to become an R&D group leader.So, I learned how to lead and build some really complex security solutions over the time. And think about it. I had unlimited resources to solve any problem that I wanted in the security space.So, I learned a lot over the time there. And the things that I learned, and I think that was the most fascinating for me, was about first prioritization. The security team should be business enablers.
So how can we help support the business move forward and understanding that we cannot solve all the problems in the infrastructure and the network. We have to prioritize and provide value to the entire organization. There is no any organization in the world that their entire mission is to protect themselves.
They have other missions. So how can we support those missions? Then after 10 years doing that, I wanted to do something a bit different.
I founded a company, co-founded it with someone who was one of the gurus of consumer's products. His name is Uri Levin. He was the founder of Waze, the navigation app Google acquired, and then had a lot of other companies in the consumer space.
And together we wanted to change the interaction between individuals and accountants. And that was an amazing ride for us because I moved from building a product to an organization that has to use my product to build something for the mass, for the entire population of a country. And they really don't have to use it, right?
So, we started to see how user experience is key in order to provide value to the end user. And the second thing that I learned over that time was how to make decisions that are data-driven. When you have such a high number of visitors, of interactions with your product, you have to make decisions that are based on data, on an A/B testing, and testing basically your hypothesis.
And all of those learnings, both from the 8200 and then also from my previous startup, really helped us build Token with the right foundations. On one hand, creating a very unique user experience for the customers, but at the other hand, also like solve a real pain security teams have, and it's just growing and not do something that is completely niche, but go after a big problem that people care about. And yeah, I'm very fortunate to have those two experiences.
Host: Indeed, an inspiring journey, I must say. Each chapter has shaped the leader you are today. Moving to the next question, what has building enterprise-grade security solutions taught you about balancing innovation with the practical needs of security teams?
Itamar: So, it was also an interesting journey. So first of all, you have to listen to your customers and listen is to hear what they say, but also look at what they do. And the first thing was for us, it was really, this was a new problem, didn't have visibility to their agents or in general, they didn't have controls for the non-human identities.
So the first thing was allowing the customers to have visibility, right? To have views where they can see all those agents, identities, and the risk that until today was almost ignored or overlooked. But then we found ourselves in a new problem.
They have a list of issues and another dashboard of a lot of problems, but they don't have the enough human resources, the political capital in order to solve themselves. And we move very quickly from, hey, let me just show you what issues do you have to let me automate and enforce your policies and auto-remediate the issues that you find. Moving from a place where you see all those red screens to a place where I can actually take back controls and enforce my point of view into my organization.
So what the thing that we learned the most was, okay, hey, we need to listen to our customers, but we cannot just show them a list of problems. We have to help them move from point A to point B and solving those issues. And that was a mind switch that I think the industry itself is now taking for moving from more solutions that are security posture management to solutions that are also help you enforce and auto-remediate the issues that you're surfaced.
Host: Yeah, that's a really amazing take on innovation, Itamar. Thank you for that. On that note, let's move to the next one.
Token Security aims at discovering and securing AI agents across the enterprise. What are the biggest visibility gaps organizations face when adopting agentic AI?
Itamar: Look, agents are everywhere. When you map AI agents, there is no one place for you to look at and say, hi, this is all of my AI agents. There are in your cloud, in your SaaS applications.
Now every SaaS application itself becoming agentic and have their own agent suite. It's also running locally, you know, in every computer, employees can run their own agents and that creates a huge visibility issue that basically my entire infrastructure is moving into an agentic infrastructure and I need to have visibility to all of that, right? I think that the biggest issue today is all those local agents that are running an employee's computer because they're just the most, the easiest to adopt.
You don't need now a whole complicated bureaucratic processes to install an agent and start to help you personally to be a bit more effective and right now the enterprise is also trying to push AI agents because they understand basically that this transformative technology that if we won't use, we will just lose advantage, we will lose to our competitors, so we have to adopt it. So right now security teams are really reactive into this change and trying first gaining this visibility. I think that after I'm knowing about this agent, I still have some issues around understanding the utilization, the usage of the agent.
What's the purpose? What am I trying to achieve? What the agent is actually doing?
So looking at the agent intent and analyzing it, understanding what's the agent purpose and then looking at the activity and see that they're supporting it, right? Because we need to treat AI agents, another digital worker that we have in our organization. When I work for Token, I have an account and so for a human, I can just say, hey, does Itamar needs those access?
Yes or not? And is now the authentication, is Itamar or is it someone else? Now when we come to AI agents, I also want to see that the agent is doing what it's supposed to and it's connected to the application that are relevant to that mission.
And that's a bit of a different mind switch. So gaining visibility to that is very hard and that's what we are helping.
Host: That's really an eye-opening perspective on where the blind spots really lie. So let's proceed further. Could you share insights about Token Security's recent launch, Enso?
And how do you believe it will reshape identity security for modern enterprises?
I'll give you a small sideline story. So we were really inspired by the journey of our co-founders, Joe's brother, that was building a product, sometimes in our office, sometimes in other places, that was really successful and it was part of a revolution. So he built a company called Base44.
Just like Base44, you have other competitors like Lovable or Replit, that basically changed the experience of building a new application, that today and every person can build an application by interacting in a natural way and not necessarily need to understand how to write code or using more classic templates of website builders. And we really love that. And we were really also innovative in Token Security.
So we launched our MCP server about a year and a half ago. We were one of the first security vendors that allowed this type of interaction. And then we started to see how people are using our platform.
And we said to ourselves, hey, we have all this really strong data, right, of the agents, who are they connected, how they're being used. We have all those really strong APIs and capabilities, like removing agents, updating them, changing their permissions, all of those really strong controls. But what we started to see is that although we have really nice UI, our customers sometimes have very specific needs.
They want to do something that is also a bit different or use the data and do actions that we were never thinking about. So what we said is, hey, how can we build an app builder, just like Lovable and Base44 and Enso and Replit, but that lives inside of Token's platform and can leverage all of the data and the product capabilities. So the idea here is really moving outside of the UI boxes of the security vendor and allow you to create whatever boxes that you have, that you want, on top of the data.
Because I really believe that security solutions today, they are good as the data that they have. And if we have a lot of data and a strong set of capabilities and features, and allowing you to build on top of that, you are really limitless on the thing that you can do on top of it. And I do think it's a more innovative way of thinking of security solutions and understanding that large enterprises have a lot of unique use cases, unique processes.
So that's, on a nutshell, what Enso was trying to solve. Then we saw that it's also helping us to develop new features faster because we're using Enso as a tool for prototyping, for showing and shipping features very quickly to our customers and see their engagement, having this A/B testing mindset that we talked about before and see what hits more and what hits less, and then develop those concepts into greater features and stronger solutions. And I'm really excited about Enso and now we're seeing that also other companies are trying to build something similar, which is always a good sign that you're doing something right.
Host: Yeah, it's truly fascinating to know how Enso is solving the specific needs of enterprises. So next up, what are the most significant risks caused by unmanaged AI agents operating across cloud, SaaS and enterprise environments and how does token security address them?
Itamar: We need to treat, as we talked before, agents as a new digital welcome. Now, it's different than our human employees because a human employee can take a limited number of actions, right? Like, he can interact with the resource and then move back.
An agent is also autonomous and automated, so it's in a machine scale. So we now need to think about all of the risks that we have of a digital, classic digital worker, a human, but that also can iterate much faster and interact with resources in a much larger scale and can automate all of those things. So, it's almost a mix of the risks that humans have and the risks that machine identity has all in one.
That I have a non-deterministic app that pursues a goal, that's going after to achieve that goal and do whatever it takes to do that, that creates fundamental risks. So some people say that an AI agent is a bit like, so a coding agent is like a junior developer today. I think that it's already became much more smarter than the junior, you know, like developer, but it's someone that's like a thousand junior developers, right?
So by the likelihood of having mistakes, of taking actions that are fundamentally wrong or that a human has common sense, sometimes the agents don't, right? So how can we prevent that from happening? So basically the way that it translated is agents, it has today a lot more access than what they need to do, that they have privileged escalation capabilities.
So they can leverage some vulnerabilities on permissions and can take actions that were not meant to do. There's prompt injection. And I think also the life cycle of the agent right now is one of the things that people are really missing.
When an employee is joining the company, we have a join or move or leave processes where he joins the company, we update their permissions, they're moving between teams, we're changing that. They leave, we're removing their access. We need to do the same for AI agents and keep validating it.
But the issue with AI agents is the ratio between that and humans is growing very faster. So we're talking about a hundred to one. And when that happens, you cannot do the same manual or semi-automated workflows that you did before to a much larger population, right?
So we see that as a big risk on managing the life cycle of the agents. We see today a lot of orphan, unmanaged, or there's no owner. And basically the doomsday, we're already seeing it today, that agents are escaping some of their permission, finding ways to move between entities in order to achieve their goal, faking things and doing some really unique activities in order to get to their target.
And I think that an attacker will compromise the agent, right, or fool the agent to take some actions that were not part of the original plan. So that's a big pain.
Host: Yeah, absolutely. And I just wanted to know how token security is addressing such concerns.
Itamar: Yeah. So we start with visibility. You have to see these agents that are, as we said, are in a lot of different areas in my infrastructure and keep changing all the time.
But after that, what we are doing is looking at the agent ownership that we assign automatically, the consumptions, who is using these agents, what actions are they doing, how the agent is being invoked. Basically, when you think about agent risk, it's based on the level of autonomy I give the agent, does it need my proof to take actions or not, how it's being invoked, and then also the level of access, what the agent can interact with. That's an identity problem.
So at Token, what we did was really analyzing not only the agent, but the different identities and access that the agent has in the target applications. We're looking at the activity and then we say, hey, this agent meant to send a dashboard once a week to the entire leadership team about our focus thing in sales activity. Why does it need to have right access to our sales force?
It doesn't. It only needs to read those type of objects. So how can we now update the access of the agent based on the purpose?
And that's basically the core goal of the solution is not only giving a visibility, but then restrict what the agent can do, where it can do based on the intent of the agent and also auto-mediate and take actions in an automated way when the agent is doing the wrong things, basically.
Host: Yeah, that's a really practical approach to address the risks of unmanaged AI agents. So here's our next question. What motivated Token Security to integrate with the Anthropic’s Cloud Compliance API and what challenges does it solve for enterprises?
Itamar: Yeah, so one of the most adopted agentic technology today is cloud. And basically we see today that the enterprise adopting the agent is adopting cloud in a lot of different ways. You see individuals that are using their own cloud account and you see that also the enterprise using cloud enterprise accounts and have license.
The idea with this integration is to pull some data about the agents that are managed and are governed through cloud and add more controls and context into them. So think about it that they have agents. I still want to understand which tools are they using, how they're interacting with different resources.
So we pull some of the data from cloud, but some of the data from the target applications the agent is connected to, and then start to take actions, whether it's in your managed solution, the cloud or on the applications that it's connected to and the identities it's leveraging. But the idea here is that we understand that cloud is one of the solutions that enterprise are running to adopt and to use. And we have to connect also to that in order to add more visibility, more strengths and controls.
And our entire concept is to have one centralized place to control and to have visibility and to enforce your policies across all different agents. Some of them managing cloud, but other managing a local environment or in other SaaS solutions or running in your production environment. So you want to have visibility to all of them.
But for sure, cloud enterprise is an important piece in that puzzle.
Host: Yeah, that I can say that is a solid and beneficial integration, Itamar. So let's go ahead. Token security was recognized in Gartner's 2026 Hype Cycle for Digital Identity under workload identity management.
Indeed a huge achievement. Looking ahead, how do you see AI agents and non-human identities reshaping the future of identity and access management?
Itamar: Yeah, I think that a lot of the fundamentals. So when we think about identity security, it started in the mid-90s with solutions like Novell and Active Directory and then expanded into PAM, CyberArk and CellPoint and IGA solutions. They were all very human-centric in a world where most of the identities were managed.
Most of the organization access was in the on-premise environment. And then there was this shift of moving to cloud and you saw Okta and other solutions. Now we're in the next transformation.
AI agents are a digital workforce that we have to take into consideration that could run on behalf of a person or to have their own identities, their own missions and tasks. And right now what we see is that those concepts that we were building for the past 30 years just don't scale when it comes to AI agents. Because now we're talking about an enterprise that has a thousand more, like a thousand times more identities than they have before.
They have millions of more interactions than the humans because they don't sleep. They just pursue a goal, right? And take actions continuously and multiple steps.
So basically the entire way for us to think about identity lifecycle, about compliance, think about access review. That was a process that was done very manually before. I don't think that it scales when it comes to thousands or a hundred times more agents and identities that we have before.
So we need to rethink about some of those concepts that we were building for a while and see how in a world where we have way more non-human identities than AI agents, how do we still control it in an effective way and not just overlooking it? Because at the end of the day, identity-based attacks is the number one reason for any attack and breaches. And even now that we see different stories around AI agents that became a rogue and created a unique, complicated attack, they were all leveraging identities, right?
So the core foundations of securing those identities is still our number one priority. But we need to understand how to do that differently now that we have so many new identities in this world with this world characteristics, right?
Host: That clearly signifies where the identity and access management are headed. So here we come to the end, Itamar. This has been an insightful conversation indeed.
Thank you for joining us here and making the time. From the discipline of Unit 8200 to building a company that's transforming how enterprises trust their AI agents, your perspective offers a glimpse into where identity security is headed next. Thank you so much.
Itamar: Thank you. It was a pleasure.
Host: And that brings to the end of today's conversation. We also extend appreciation to our audience for joining us to this exclusive episode of ExtraMile by SecureITWorld. Conversations like this aim to highlight the voices of enterprise leaders and AI pioneers.
We'll be back soon with a leader from another top technology organization making a difference. Until then, keep learning and keep exploring.
Explore Our Other Insightful Interview:


















