This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Bob Burke. Bob Burke is the Chief Information Security Officer at Beyond Identity, where he plays a key role in building and securing the company’s identity-first access management platform. He has over 20 years of experience in cybersecurity and engineering leadership and brings deep expertise in identity, cloud infrastructure, compliance, and protecting mission-critical SaaS systems.
Chapter Titles:
00:00 Introduction
10:07 What was the main threat back then?
13:30 Finding a Security Architect
15:24 What gaps cause MFA to go down?
18:00 You don’t know you’ve been breached
22:36 Should CISOs be part of IT?
30:31 Phishing Resistant Attacks
33:42 Beyond Identity
37:42 If your identity is compromised…
41:19 Hardware supply chain
47:45 More about Bob
Audio:
Important Links
Transcript
Manoj Tandon:
Hello everyone! This is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. We have another awesome guest today!
Before I tell you about him, please hit the Like and Subscribe button — we live in a world of algorithms, and we need to see a little love so we can keep bringing you this content.
Without further ado, I’d like to introduce our next guest. He’s been in the industry for over two decades — more than 20 years of experience. Bob Burke is the Chief Information Security Officer at Beyond Identity, where he’s helping build the company’s identity-first access management platform.
He brings deep expertise in identity, cloud infrastructure, compliance, and protecting mission-critical SaaS applications. Bob, thank you so much for joining us. I appreciate you being on the show.
Bob Burke:
My pleasure.
Manoj Tandon:
We always like to start off with a bit of background. How did you get into the cybersecurity world? Is that what you always wanted to do when you grew up?
Bob Burke:
No, not at all. Like most people of my generation, I probably wanted to be an astronaut—or a firefighter, or something like that. But like many security professionals, my background isn’t linear; it’s a bit eclectic.
I graduated with a degree in aerospace engineering with a focus on computational fluid dynamics, which seems like a strange start.
Manoj Tandon:
Not really—your host here did something similar!
Bob Burke:
See, there you go. I think data scientists and security professionals tend to have the most eclectic backgrounds. There’s a reason for that, and hopefully we’ll get into it later.
I started in aerospace engineering, then moved into grid computing—shifting from mathematical computation to software very quickly. That’s where my passion was.
Early in my career, I worked at a company called NetRake that was fundamentally building the first session border controllers and security gateways. It was revolutionizing telephony in the early 2000s, during the dot-com era. We were doing deep packet inspection, network engineering, and early embedded development—writing kernel modifications to enable new types of network capabilities.
That’s when I was first introduced to network engineering and network security, and I met some of the most brilliant people I’ve ever worked with. It shaped what I wanted to do.
After that, I took what I’d learned and joined a telecom company to push that technology further into the ecosystem. I did that for a few years, which was a lot of fun. Then I caught the startup bug—my partner calls it a character flaw because I’m drawn to startups, but it’s really a passion for building things.
One of my first startups focused on early authentication and access management for banking. This was back in 2007—well before FIDO or U2F, even before the iPhone. We worked with banks to build authentication and authorization layers using multifactor cards that tunneled into the home. You could tap a device in your house without sharing any banking information and perform multifactor authentication using IPsec and EPKI.
It was a bit ahead of its time. We proved the technology worked, but adoption was slow.
Manoj Tandon:
It wasn’t part of the cultural fabric yet.
Bob Burke:
Exactly. I can remember people telling us, “No one in their right mind is ever going to tap a device to log into anything.”
Manoj Tandon:
Well, they haven’t walked into a hospital recently, have they?
Bob Burke:
Right! Today, that’s all we do—authenticate and tap. That early work eventually led me deeper into identity.
After that, I worked with a VC firm helping bootstrap energy startups. I built engineering teams, set up technology, and got companies off the ground. One of my favorites focused on energy management—we’d help companies reduce energy spend by 8–10%, which could save millions.
That work introduced me to IoT. The first thing you deal with in IoT is device attestation, device security, and mutual authentication. That’s where I started understanding that devices are part of the security ecosystem—and that each device must have a strong identity.
Later, I participated in W3C’s verifiable credentials work—back when everyone was talking about self-sovereign identity. One of the first industry-wide implementations was through a company called Coupon Media. We provided age-restricted offers across 50,000 convenience stores using verifiable credentials. That involved integrating third-party identity proofing solutions.
Over time, I’d gone from network security to device security, authentication, and now identity proofing. Eventually, that journey led me to Beyond Identity.
Throughout all of it, I kept asking: Why isn’t security part of the original product ideation? Too often, it’s treated as operational overhead instead of being embedded into design.
Manoj Tandon:
That’s true. Those early banking systems—mainframes, Unix, big IBM racks—weren’t designed with security in mind. They were designed for transaction throughput and reliability.
Bob Burke:
Exactly. And that lack of early security focus meant that later, even deploying proper solutions could save tens of millions in cybersecurity insurance costs.
Manoj Tandon:
Back then, were nation-state actors a concern? Or was credential theft the main threat?
Bob Burke:
Credential theft, primarily. Nation-state threats weren’t really part of the mainstream conversation yet. Most attacks targeted high-value banking customers. So we built strong network and authentication backbones for secure remote banking.
Manoj Tandon:
You’ve seen the industry evolve dramatically. How did Windows and Active Directory change the landscape—for better or worse?
Bob Burke:
It was a good thing in terms of productivity, but like most productivity tools, it came with trade-offs. Active Directory drives enormous IT value, but it’s also a major source of security threats. Legacy AD deployments often have deep-rooted vulnerabilities, making lateral movement easy once attackers get in.
Manoj Tandon:
What’s your advice to organizations in that position?
Bob Burke:
Focus on security architecture. Don’t get distracted by flashy AI tools. Take legacy systems seriously. Shift from detection to prevention wherever possible. That architectural vision is the only way to stay sane in today’s threat landscape.
Manoj Tandon:
Finding great security architects is tough. They must understand both business and technology, and there’s no real certification that guarantees that skill.
Bob Burke:
Exactly. Architecture defines your attack surface. It’s not a one-time project—it’s a continuous journey. Look at MFA as an example. Many MFA solutions deployed a few years ago were great then, but they target a five-year-old threat landscape.
Today, bypassing MFA is trivial—thanks to phishing-as-a-service, malware-as-a-service, and AI. Legacy MFA methods like OTPs, SMS, or magic links are easily phishable.
Manoj Tandon:
So what caused MFA effectiveness to decline?
Bob Burke:
The landscape changed. Years ago, attacking MFA required technical sophistication and infrastructure. Now, anyone can buy phishing kits like EvilProxy or Tycoon2FA for a few hundred dollars. The threat ecosystem has industrialized.
Manoj Tandon:
And executives often think, “We haven’t been breached, so we must be fine.”
Bob Burke:
Exactly. Absence of evidence isn’t evidence of absence. Just because you haven’t seen an attack doesn’t mean your program is sufficient—it just means you haven’t been noticed yet.
Manoj Tandon:
That disconnect between business and cybersecurity teams is still a huge problem.
Bob Burke:
Yes. Security leaders must express security in business terms—how it enables and protects the company’s mission. Otherwise, they’ll always be seen as an operational cost center.
Manoj Tandon:
That’s a great point.
Bob Burke:
Compliance is another area where this is changing. Years ago, customers rarely asked about compliance. Now, it’s table stakes. If your product isn’t compliant—and can’t help enhance your customer’s compliance posture—you’re out of the running.
Manoj Tandon:
Agreed. And what’s your view on where CISOs sit within the organization?
Bob Burke:
Ideally, the CISO should be independent of IT. In many companies, though, IT still rolls up under the CISO. Larger organizations need CISOs who are independent actors with a clear vision of how security enables business.
Manoj Tandon:
You’ve also used the term “MFA apocalypse.” What do you mean by that?
Bob Burke:
Our marketing team coined that phrase. The idea is simple—we got complacent. First-generation MFA solutions worked against the threats of the day, but the landscape has changed. Today, MFA must be phishing-resistant.
NIST defines phishing resistance as authentication that cryptographically binds the origin server to the authenticator. In other words, the destination you’re logging into must be cryptographically tied to information stored securely on your device. That makes interception virtually impossible.
Legacy MFA solutions—SMS, OTPs, push notifications—don’t meet that bar. They’re easy to phish and intercept through reverse proxy attacks.
Manoj Tandon:
That makes sense. So tell us what Beyond Identity does.
Bob Burke:
Beyond Identity is an access management solution built from the ground up to eliminate identity threats. We secure every stage of the identity journey: device, access, and collaboration.
Our platform binds the user identity to the device identity, verifying both through cryptographic attestation. The result is phishing-resistant, passwordless authentication that’s secure by design and compliant by design.
We move identity threats from detection to prevention—blocking lateral movement and eliminating credential theft.
Manoj Tandon:
Are biometrics part of this?
Bob Burke:
Yes—passwordless and phishing-resistant by default. You couldn’t force a password into our system if you tried.
Manoj Tandon:
And you can guarantee authentication is coming from the right hardware device, independent of manufacturer?
Bob Burke:
Exactly. We use secure enclaves and TPMs to establish trusted device credentials. This also enables hardware supply-chain management—you can trace the entire lifecycle of a device credential back to its origin.
Manoj Tandon:
That’s impressive. Are you expanding into asset identification or management?
Bob Burke:
Not exactly. We’re not an asset-management company, but we do offer Device360, which gives visibility into device identity and posture. You need a certain amount of asset context to manage identity threats effectively.
Manoj Tandon:
And affordability? Are you focused on enterprise or SMB as well?
Bob Burke:
Both. Our platform is secure by design, but simple to use and administer. We serve Fortune 50 enterprises and small-to-medium businesses alike. We were FedRAMP Moderate certified earlier this year and already have customers on our GovCloud platform.
Manoj Tandon:
It sounds like you’re set up for success—and probably a great exit down the road!
Bob Burke:
(Laughs) Every startup hopes for that, but for us, it’s about changing the world for the better. Our CEO and founding team share that vision. The exit will come—but the goal is to build something transformative first.
Manoj Tandon:
That’s the entrepreneurial spirit. Before we wrap up, where can people find you?
Bob Burke:
You can find us at beyondidentity.com. We’re also on YouTube—just search for “Beyond Identity.” Come see us at Black Hat as well! We can do proofs-of-concept in days. Our next-generation solution was built for today’s identity threat landscape—not the one from five years ago.
Manoj Tandon:
Fantastic. Bob, thank you so much for joining us. You’re always welcome back.
Bob Burke:
Thank you, Manoj. It’s been a great conversation.
Read more about Bob on his LinkedIn
Check out the vCISO bot we created
Check out the other episodes in Season 17:
Ep. 0 Jon DiMaggio – Tracking Cyber Criminals
Ep. 1 John Carse – Why Your Browser Is Your Biggest Risk
Ep. 2 Alex Sharpe – Is Your Job Safe From AI?
Ep. 3 Chuck Brooks – Thinking Beyond the Checkbox
Ep. 4 Henrik Parkkinen – Adapting to AI & Rethinking What We Protect
Ep. 5 Alex Sharpe – Are AI Models Being Trained with Lies?
Ep. 6 Santosh Kaveti – Disaster Recovery Isn’t Optional
Ep. 7 Bob Burke – Think MFA is Enough? Think Again.
Ep. 8 Ed Gaudet – The Biggest Mistakes in Healthcare Security
Ep. 9 Husam Shbib – The Hacker’s Playbook
Ep. 10 Shayla Treadwell – The Psychology Behind Cyber Resilience
About Bob Burke

Bob Burke is the Chief Information Security Officer at Beyond Identity, where he has helped shape the company’s security-first identity and access management platform.
With 20+ years in cybersecurity and engineering leadership, Bob brings deep expertise in identity, cloud infrastructure, compliance and securing critical SaaS systems.
He has recently helped the team at Beyond Identity achieve a record mark by getting FedRamp certified in less than 6 months.
About Us
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
