This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Jasson Casey is the CEO & Co-Founder of Beyond Identity, the first and only identity security platform built to make identity-based attacks impossible. With 20+ years in security and networking, Jasson has built enterprise solutions that protect global organizations from credential-based threats.
Chapter Titles:
00:00 Intro
02:00 Our Guest
10:37 The Identity and Access Management field is crowded
16:11 How does your MFA know?
45:34 What does the future look like for AI?
49:48 Claude and Ceros
Audio:
Important Links
Transcript
Manoj Tandon: Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security, Security Confidential. We have another great guest today. Before I announce him, I’ve got to remind you—please hit the like and subscribe button. It helps us quite a bit and allows us to keep bringing you this great content.
So without further ado, I’d love to introduce to you Jasson Casey. He is the CEO of Beyond Identity. He had a colleague on here a couple of years ago, but his company is firmly in the zero trust arena, and they have some new announcements to make. We’re eager to hear about them.
As for Jasson, he’s been in the business for over 20+ years in security and networking. He’s built enterprise solutions that protect global organizations from credential-based threats.
So Jasson, thank you so much for being on the show. We’re looking forward to gaining some insights and knowledge from you. Thank you for being here.
Jasson Casey: Yeah, thanks for having me.
Manoj Tandon: So we love starting off with a little bit of your background. Introduce yourself—our audience might not know you. Give us a little bit of your dossier. How did you get into this space?
Jasson Casey: Sure. How did I get into this space? Let’s see. I’ve always been into building things. For some reason, I got fascinated with communication protocols in college, and I stumbled upon a job that helped me pay for school—writing software that used sockets and spoke to other software, basically building distributed systems.
I didn’t really understand it in that framework back then—it was more of a novice practitioner—but security problems reared their head almost immediately once you start doing protocol implementation.
That was back in 1999. I was doing what’s now called Voice over IP. It’s common today, but it was cutting-edge back then. We were implementing protocols from scratch—SIP, RTP, that sort of thing—and peering our network with other networks.
We had concerns like, “They’re on private address space, I’m on public address space,” and VoIP has this thing called a layer violation, where one protocol speaks deeply about layers three and four of another. The minute it crosses a NAT or firewall boundary, the protocol breaks. So how do you fix it?
There were also security concerns—VoIP gateways were like cash registers. If I hook them up to a peering point, anyone can disrupt them. So I got into designing specialized application-layer firewalls or gateways.
That took me on a journey building carrier-grade systems before hyperscalers. Then I got into hyperscale infrastructure, took time off to do a PhD in formal methods of distributed systems, moved to the East Coast running engineering for General Keith Alexander at IronNet, then moved to New York to run R&D for SecurityScorecard as CTO.
In 2019, I resigned to start my own business—but about a week later I ran into Jim Clark from Netscape, and he convinced me to join forces. That’s how Beyond Identity started.
Manoj Tandon: Fantastic. Netscape—wow. That’s evolution from Mozilla way back in the day.
Jasson Casey: Yeah. It’s an interesting background. Before Netscape, Jim was at Silicon Graphics. My first computer at work was actually an SGI Onyx running IRIX.
Manoj Tandon: I know it well. I used that myself a huge amount. I was in the CAD/CAM/CAE space at the time.
Jasson Casey: Yeah, my first job before networking was actually in geoscience—doing visualizations and simulations for extracting oil. I was figuring out how to fit massive models into commodity memory. That was my exposure to Silicon Graphics.
Manoj Tandon: What a small world. And Jim Clark—that’s a name I haven’t heard in ages. What was his drive? Just entrepreneurship, or was there a specific interest in zero trust?
Jasson Casey: His drive was entrepreneurship and user experience. At Silicon Graphics, it was about making supercomputing accessible. At Netscape, they invented SSL to enable secure transactions, but they punted on user authentication and said, “You figure it out.”
Years later, Jim built an authentication system for his yachts and homes. He wanted full automation—remote control via satellite. Instead of passwords, he used device-bound credentials via certificates.
I came at it from a security perspective. At SecurityScorecard, we had data showing three key predictors of breaches: use of password managers, MFA, and patching endpoints.
Jim’s system eliminated credentials entirely. Keys are bound to the device, never in memory, never transferable. Combine that with endpoint security posture, and you can answer three questions at authentication:
Who are you? What device are you on? Are you secure enough?
There’s no credential to steal, no phishing, no session hijacking. That was the founding insight of Beyond Identity.
Manoj Tandon: From a commercial perspective, identity and access management is crowded—Microsoft, Google, Okta, Ping. What was your design point entering that market?
Jasson Casey: In 2019, identity security wasn’t as hot as it is today. Our angle was simple: existing authentication was trivially breakable.
Ask any SOC what drives incidents—identity failures. And traditional MFA is a terrible user experience.
We offered something new: better security with less work and a better user experience.
Manoj Tandon: Are you not bound to the device though?
Jasson Casey: You’re bound to an enrolled device—not necessarily your personal device. Enrollment is cryptographic, and policy determines access.
Manoj Tandon: What about someone traveling, using a business center computer?
Jasson Casey: Most customers don’t want that allowed. But we support unmanaged devices. Enrollment is flexible, but access is policy-driven.
Traditional systems restrict enrollment. We allow open enrollment but restrict usage. That gives better visibility and control.
Manoj Tandon: What about geo-fencing in traditional MFA?
Jasson Casey: That’s probabilistic. You’re guessing. MFA can’t tell if it’s responding to a legitimate request or a man-in-the-middle.
Device-bound authentication can. It’s deterministic.
Manoj Tandon: Couldn’t I spoof device identifiers?
Jasson Casey: Those aren’t part of the auth model. It’s cryptographic device binding. Single-device MFA eliminates phishing and session hijacking entirely.
Manoj Tandon: So you’re essentially adding a layer before SSO?
Jasson Casey: Exactly. Think of us as an intrusion prevention system for identity. We plug into Okta or Entra. Deployment can take 30 minutes.
Manoj Tandon: What changes for the user?
Jasson Casey: Instead of passwords and MFA, they might use biometrics or a PIN. Then they’re in. Faster and more secure.
Manoj Tandon: So you’re enhancing, not replacing identity systems.
Jasson Casey: Correct. Over 80% of SOC tickets are identity failures. We eliminate the root causes.
Manoj Tandon: What size organizations do you target?
Jasson Casey: Primarily enterprise and mid-market, but about 10% are startups with 50–100 people.
Manoj Tandon: Let’s talk about your new product.
Jasson Casey: It’s called Ceros—for agentic coding security.
Every company is under pressure to go AI-native. We see three groups:
- Wait-and-see
- Move fast, ignore risk
- Block AI due to governance
We help the last two.
Ceros is like a virtual machine for AI agents. It launches tools like Claude Code inside a controlled identity and security context.
We monitor:
- AI usage (shadow AI)
- Data flows
- Tool usage
- Permissions
We provide governance without slowing developers down.
Manoj Tandon: With tools like Claude Mythos, how much can you really control?
Jasson Casey: These systems aren’t magic. They’re structured loops—context, tokens, tool execution.
The LLM doesn’t act—the agent does. If you control the agent boundary, you control behavior.
You can apply deterministic verification to probabilistic systems. Formal methods can validate outputs.
Manoj Tandon: That’s fascinating—it reminds me of aerospace modeling.
Jasson Casey: Exactly. These are math systems. Not magic.
Manoj Tandon: Where is AI going?
Jasson Casey: Massive transformation. Entire roles will disappear. Business structures will change.
We’re already replacing expensive SaaS tools with AI-driven workflows.
Token cost will become a major budget line—like salaries.
It’s changing everything—from engineering to farming to aviation.
Manoj Tandon: We’re seeing that too—AI is replacing entire financial functions.
Jasson Casey: Same here. We built financial systems in hours that used to take teams.
It’s a new world.
Manoj Tandon: Anything you want to plug?
Jasson Casey: If you’re using Claude Code and care about security, try Ceros at beyondidentity.ai. There’s a free tier. It gives visibility and governance without slowing developers down.
Manoj Tandon: This was a fantastic conversation. We’d love to dive deeper next time.
Jasson Casey: Thanks for having me. I clearly enjoy talking about this stuff.
Manoj Tandon: You do—and we appreciate it. Don’t be a stranger.
Jasson Casey: Will do. Thanks.
Manoj Tandon: Thank you. Take care.
Read more about Jasson on his LinkedIn
Learn More about Ceros on their website
Check out the vCISO bot we created
Check out the other episodes in Season 19:
Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities
Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?
Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity
Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat
Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?
Ep. 5 Murphy John – The Future of Decentralized Data
Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now
Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern
Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis
Ep. 9 David B. Cross – The Future of Cyber Threats
Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft
About Jasson Casey

Jasson Casey currently serves as Chief Executive Officer and Co-Founder at Beyond Identity, where he’s built an identity security platform for enterprises to make identity-based attacks impossible.
Jasson has 20+ years of experience delivering security and networking products to all markets and customer types, including global enterprises and carriers. He served as CTO at Security Scorecard, Fellow in CyberSecurity with the Center for Strategic and International Studies (CSIS), and as Advisor to IronNet CyberSecurity, a security startup founded by Gen. (Ret) Keith Alexander.
Prior to Beyond Identity, Jasson was VP of Engineering at IronNet CyberSecurity and oversaw development of the vendor’s revolutionary collective intelligence platform and pioneered new approaches to total network observability, including limitless wire rate packet capture with truly elastic retention abilities.
Read more about Jasson on Kitcaster
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
