
#192 Can AI be secure without Slowing People down
About this episode
As AI becomes part of everyday work, enterprises face a difficult challenge: how do you protect identities, devices, applications, and data without making employees less productive?
In this episode of XTraw AI, Raghu Banda speaks with Denis O’Shea, Founder and CEO of Mobile Mentor, about the changing security landscape, Zero Trust, passwordless identity, cloud-native workplaces, and why employee experience has become a critical part of enterprise security.
We also explore a provocative question: are employees really the weakest link—or are poorly designed technology experiences pushing them toward risky workarounds?
In this episode, we discuss:
- Why traditional security controls are struggling in an AI-enabled, hybrid workplace and what “secure by design” should mean today.
- How Zero Trust, passwordless identity, and cloud-native endpoint management can improve both security and employee productivity.
- Why AI adoption is ultimately an employee-experience challenge, and what enterprises must get right to turn AI investments into meaningful business value.
You can reach @ Denis O'Shea
My LinkedIn @ Raghu BandaWebsite @ XTrawAI
Get every episode summarized
Each time XTraw AI: Machine Learning and AI Applications publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
1,146 searchable segments. Every word is indexed and playable.
Full transcript
XTraw AI: Machine Learning and AI Applications — #192 Can AI be secure without Slowing People down. Machine-transcribed; use the interactive transcript above to jump the player to any line.
All right, welcome back to our extra AI podcast series. And today I'm gonna have a interesting conversation. I think we all know how there is a lot of AI and agents and everything going on. And today I want to go a bit more into when or how when AI meets zero trust. How do you secure the workforce without killing the productivity? Because this is where we keep seeing a lot of things happening. So with me is guest Mr. Dennis Oshar, founder and CEO of Mobile Mentor. Welcome on board Dennis. Thanks for a good last to be on your podcast. Thanks for having me as your guest. All right, so a bit of a background about Dennis. Dennis is a founder and CEO of Mobile Mentor with he has more than 20 years of experience. Dennis helps organizations navigate the transition to the cloud native zero trust, passwordless identity and AI enabled work.
His perspective is predominantly grounded in a practical question that every enterprise is now facing. How do we improve security without like creating so much of friction because that is what is happening now. I think and we will kind of touch base and go into some of these topics. But before we get there, Dennis, I would like to know your personal story or a professional story about how you ended up doing what you're doing now. Oh, thank you. I used to work for Nokia, the cell phone company for 15 years. I had a great run with them. And I had an episode where I had a major failure towards the end of my 15 years. I was working in Europe and Switzerland. And I was trying to sell the next generation of technology to one of the big mobile carriers. And they asked me a question I couldn't answer, which changed my career. They said, why should we buy this new technology off you when our customers are not using the technology
we bought over the last couple of years? And that forced some deep introspection and reflection to figure out what's going on with technology. And what I realized is that the technology was developing so fast, was getting way ahead of the customers. And this was with smartphone technology 23 years ago for smartphones are coming out. People were paying a thousand euro or a thousand dollars for a smartphone. And all they were doing was sending text messages and making voice calls. Because the technology wasn't mature enough yet. And people didn't know how to harness it. So I left Nokia. I founded this business, which was all about unpacking the value of the technology, making it more usable, helping organizations adopt and extract value from the technology. And so we started with smartphones way back 22 years ago. Now it is most of the work we're doing is with AI, platform, security platforms, and helping to deploy these technologies in a way that makes sense
and helping people get value out of them. And I guess we see the world through the lens of the end user. We always have. So everything we're doing is trying to reduce friction, provide more value to the end user. And that's even more important today than it probably was 22 years ago. Right. I think that is a great journey. I know we have different waves of innovation, whether it is with the internet revolution or then the mobile revolution, and the cloud revolution. And now we are getting into all this AI and agents. And this is getting a bit more interesting. Before I even get into this conversation, was there a particular customer experience or a defining moment that you realize that security and employee productivity could no longer be treated as two different conversations? Because this is where I know you're coming from that mobile world. But at the same time, and I understand
that you're talking more in the context of end users. So was there a defining moment that you could talk about? I there was actually there will have been many, but in particular, we do a lot of work in the healthcare space and helping healthcare providers go passwordless. And when we realized that actually passwordless is a beautiful example of getting better security and a better user experience. And then we explained to people that you've probably already living in a passwordless way with your smartphone. Because you look at it in a does face ID or touch ID on an Android, and it signs you into the OS and then the applications and maybe you have two factor for your bank account. But most of the things you're doing, your password less on a mobile device.
And so a lot of the work we do is helping enable that experience on a Windows machine or a MacBook in a hospital environment or in a bank or in a retail environment. And so we love that example. And we really encourage people to go passwordless because passwords are the number one cause of breaches. We all know that. But also it's a delightful experience for the end user when they can use biometrics and not have to remember all these passwords and manage all these passwords. That is a perfect intersection of better security and better user experience. Beautiful, beautiful. I like the way you've put it, better security and better productivity. Yeah, before we die, yeah, let's reduce the friction, right? But before I dive into the actual topics, I have one of the question, I know there is this interesting question, right? I think you have a productively said that Gen Z employees could either get an organization hacked
or help them make millions. So where are we headed now? I know we see a bunch of companies, a bunch of tons of startups coming up. And I know there's a lot of Gen Z people starting a lot of these firms. And I think I have great admiration working with them, but also like you said, there is both good and bad of what's here. Yeah. I'll tell you what we've done. We did a global research study in 2022 and again in 24 and again in 26 to understand the relationship between people and technology and the workplace. And what we did the first one, Gen Z was a tiny group in the workplace. That was the group that entered the workplace during COVID. They didn't get on boarded properly because they were working remotely. It was all weird and they really didn't get set up for success. By 24, they were starting to show up in bigger numbers. Now in 2026, our most recent study,
Gen Z is quite large in the workplace. And we keep doing the research every two years. And by 2034, Gen Z would be the dominant cohort in the workforce. They'll be the largest group. All the baby boomers will be gone. A lot of my generation, I'm Gen X, will be gone, hopefully retired. And Gen Z will be the bosses. They will essentially be calling the shots. So we think the best way to predict the future is to understand Gen Z behavior now. Their preferences, their habits, their behaviors. And one of the things, there's a few things we know about Gen Z. Their habits are really interesting. They are the most likely to work around a company's security policies. They're the most likely generation to do the exact opposite to what we ask them to do in terms of using the right tools and following processes and structure. But they're also incredibly innovative and resourceful.
And they have the highest adoption of AI. And what we found in our research is AI adoption is inversely proportional to age. So older people are using AI in a very basic way, basically glorified search or writing emails. But the younger generation, oh my god, the way they're able to use AI and multiple AI tools and vibing agents that can work with other agents and create new things, it's extraordinary. So we think Gen Z is going to change the workforce. But because of their irreverence and their tendency to work around friction, they're also a liability. So what we conclude from all of this is the employer today, if you're an IT leadership or an in leadership, we think job number one is reduce friction so that people are using the right tools in the right way, securely,
because friction will force this generation to work around the company's security. And the evidence we have from the research is that Gen Z, about one or 52% of Gen Z think that the systems and applications provided by their work are too clunky. And they will go off and do other things. For example, use Gmail or use Dropbox or save things to insecure cloud locations because they just want to move fast and be creative. And so we think that that's what we said. Job number one is to not rebuild. Address the foundational issues that have lots of friction so that we can remove some of that friction and hopefully enable Gen Z to bring all their other skills to bear in a safe way in the environment. Beautiful. Beautiful. I completely echo your thoughts about what you're talking about. I think, yeah, I myself, I'm from Gen X generation as well.
I think I've started working during this, during a long time back. And you see the behaviors and how we work with these different generations and like I completely echo your thoughts on how things are moving at a very fast pace and how the creative mindsets of this newer generation of the Gen Z and how value they can adapt with these faster changing needs and how we can work with them. Yeah, yeah. Gen Z is super interesting as well because they don't understand security through the same lens that other generations do. And the reason for that is, you know, we talked about some of their demographics. Everyone knows the age of Gen Z. Not many people think about the psychographics and what shape their minds. And Gen Z was a generation who was in nappies crawling around the lounge when 9-11 happened. 9-11 happened. They're the last generation
have no recollection of 9-11. So while we were all dealing with the fallout from 9-11 and the security implications and the changes we saw in airport security and cyber security and all our lives were changed, Gen Z were oblivious to all of that. So they've grown up without the fear that we developed because of 9-11. And so they've read about it and they've heard about it and they've probably learned about it in school. But it was almost second hand. It was something that happened to other people in another era. So they don't see, they don't think about organizational security or organizational data in the way that we might like them to. They are hyper focused on privacy. US Gen Z, what do you care about more of your personal privacy or your company security? It's 80-20. 80% will say, I care about my personal privacy. And what's on social media? My kids shared and what are HR departments knows about
and all that. They don't care very much about company security. You ask the same question of the baby boomer generation. They're responsible grown up adults who live through 9-11 and all of that. They do understand security and they'll give it a higher rating, I think, about 60%. And they've got, they place less value on personal privacy because they didn't grow up in the digital era. They've learned digital skills later and they're not as worried about privacy breaches or data exfiltration. Right. That's a great point, I think you brought it up. Now with this, I think this is one period or one time or one era we are in, where we have like three or four generations working together at the same time. And now the way we deal with the AI works, the workplace dynamics of the threat landscapes
that are dealing with is going to be significantly different. And I could also say bigger, right? I think vast and we also see that. So in this kind of scenario, I know there are, now we come into the scenario about these AI deployments and we see that many of these deployments are failing to provide meaningful results. What is your thought like? Do you think are the organizations getting wrong about the technology selection or the business alignment or the employee adoption or so on and so forth? Or is it about managing this kind of different kind of generations and how they deal with this technology? Because now the way I see or the way one generation sees the security threats is going to be different from another generation, see the security threats. Is there, what's your take on that?
I think it's got a lot less to do with the choice of technology and a lot more to do with the underlying foundations and maturity of the organization. So the way I look at AI is, AI is amazing and is really accelerating some businesses. But it's also shining this great big spotlight on problems that should have been resolved or issues that should have been tackled in the past. And if they haven't been, AI is now magnifying those issues. So the best example is data security. So modern organizations who have their data in the cloud find it very easy to categorize the data, apply some kind of sensitivity labels and security. So that if you go and search for W2 in your company, you hopefully don't find W2s or if you search for offer letters or performance improvement plans or any sensitive information. Hopefully you don't find those because hopefully your company has done the groundwork
and secured the data and prevented oversharing of sensitive data assets. The companies that haven't done that work and still have data on hard drives or file shares and in different places all over the place, they're in trouble because they've got a problem now because the employee clever employees will know how to write a prompt. That's going to find something that's either embarrassing or create a privacy breach or a security breach. And then if people are able to upload company information into a public LLM, a large language model and attach a company document or a spreadsheet or something like that to get it analyzed, that information is now gone. It's out in a public LLM model. And so you've got a breach there. So there are many ways that things can go sideways when it comes to data security in the world of AI. And we believe that the organizations that were doing
this work before AI and laid a good foundation to get all their data consolidated, categorized, labeled, tagged, have some retention policies, deletion policies. They don't need to be super smart and complex. They just need to be there so that you've got the controls and you can dial things up or down depending on what data is now showing up in prompts and what data is being uploaded to LLMs because you're reporting should show that each month. So that's one problem, right? Just the data security. And other is what I call the plumbing. So when employees start building out lots of agents, they're going to be accessing applications and APIs and every agent becomes a software product that will need to have a lifecycle and lots of versions and have security policies wrapped around it and identity and controls and all of that. And that needs to be done well because if I develop an agent
in a company and it's talking to all these systems and other agents and then let's say I leave, now we've got an orphaned agent that nobody probably knows exactly how this thing was built of what it's doing and what passwords I used to access different APIs and different applications. It's going to be a brittle thing. But if the company has a mature process and a good DevOps capability and a way of doing this with service accounts and all the right structures, then if the creator of the agent leaves no big deal. The agent will keep on working and hopefully doesn't break. So those are just two examples of foundational maturity that will either accelerate or what happens in some cases we see your organization say, or CEO wants AI, we're told to get on with it, we've got 90 days, we roll it out and then they have a big problem and then they slam on the brakes and go, oh my god, we have to stop. Because now we realize our data is in the mess and now it's going to take us a year to fix up our data
or we had an agent go crazy and do this crazy thing over here because we didn't have any way of governing us. And that's a disaster. We have to slam on the brakes. Right, so these are two very important points of, I know which are very valid, which we all know about these things but again, you're stressing the importance of not only the data security, but also this agent security and how you interact with all these various different agents and how do you, whether you follow these particular policies and how good are your policies and how well are you maintaining these. And now we see with this, PANTIC era of adopting AI at a very frantic pace, we see that organizations are moving too quickly to deploy these AI assistants without even first addressing what kind of data
that you have shared, what kind of identity controls you are, what kind of devices you have. And on top of all that, your employees are they trained well enough? Or do you, what's your take on that? Meaning is that fair enough to say that since we are moving so fast or all these things taken care, or are we lagging at some particular, we're lagging very few organizations have a solid enough foundation to embrace AI at scale. But what we see is, some organizations are moving really slowly. We read about the headlines of all the rapid adoption, but I just was on one organization this morning that's moving incredibly slowly because they're still dealing with so much technical data. So many on-premise systems and manual processes,
literally from the last century, like the way they onboard a new employee, the way they set up a new device, the way they do all the things, it's the same way they were doing it 25, 30 years ago, has not changed. So their employees are now doing their own AI. It's basically bring your own adventure. And so the signing up for personal accounts and some are on Gemini and some are on Claude and some are on Copilot and some are on DeepSeek. And it's just Wild West, complete Wild West and chasing the next shiny object. And their data is all over the place and they have no visibility, no control, people are building agents in different ways because the employees are way ahead of the organizational leadership. They're way ahead. So guess what, this is going to end, not well, there's gonna be a problem, there's gonna be some kind of significant breach in that environment, I know it, sadly. Then there are other organizations that are going slow deliberately
because they're saying we know we haven't defined our use cases yet, we haven't secured our data yet, we don't have a way of rolling this out and measuring it yet, we don't have the plumbing in place to do agents at scale yet. So let us get these foundations in place. So we go slower first so that we can then go fast, knowing that we have a solid foundation to build on. I love that approach. So going slow today so we can go fast tomorrow and laying a good foundation down. And then of course there's organizations who are just charging ahead, just blistering speed, maybe because their industry demands it. And in particular we see SaaS companies who are developing a software product, the benefits for coders is enormous because they will write the code, develop the test harness, do the testing, write the documentation, do the product documentation as well,
do the releasing, release scheduling, it's amazing. So anyway, you can't say no if you're a software development shop, you just have to embrace it. If you're a publishing shop or producing marketing content, you have to sell organizations are going very different speeds for different reasons. But that is also going to be a problem, right? And it's because I think you've said some of these SaaS companies might be going too fast because they could develop fast. I think this is where the security aspects or identity access management, these are some of the things you might have not really looked into or you might have taken it because you've got to develop some of these things a much faster pace. So I want to get into this business problem, right? Even the business problem, I want the security friction, the technology ways and the work arounds because this is how you're trying to go at a faster pace
to maybe make the shortcuts so that I can reach these vast amounts of speeds at the faster pace. So here I have a question. So you often say that many business are only using a fraction of the technology capabilities they already pay for. Yeah. So why is that? Is that a licensing problem or is it a skills problem or is it like failure to connect the technology with the business outcomes? Is that, what do you think? I would say it's more of a leadership challenge. Organizations tend to accumulate too much technology. And I've been in this game a long time and almost all the companies I meet and where we do an assessment to understand their current technology stack. They've got too much technology. They've bought all these things over the years
that are partially deployed. And when we do these assessments, most of the work we do is in the Microsoft space. Microsoft 365, huge platform, lots of capability. Most organizations are only using between 40 and 50% of the capability because they've also got overlapping products maybe from VMware or CrowdStrike or Octa or other organizations. And they're probably using 40 or 50% of those. So you end up with a situation that's suboptimal because they're not using all the capabilities, not using all the automations and the integrations. And it gets quite complex and security is the worst. So the research now shows that large organizations have 52 different security tools. Why is that? And I've given this a lot of thought. And my conclusion here, I go is that we bought, collectively as a society, we bought all these security tools over the last 10 or 15 years
because we were under attack. We knew there were bad actors trying to break into our environments. Somebody comes knocking with this great new security tool and we go, oh yeah, I need that and I'll add that. And they add the next thing and add the next thing and you got 52 security tools and a huge security department and many of the tools have overlap. And they're often not well integrated because they're all built to be secure and be silos. They're not built to integrate very well with each other. And in the same way that I bet you Ukraine, the Ukraine Defense Forces have at least 52 missile defense systems right now. Because anybody who comes to them and says, hey, we can help defend your cities. They'll probably buy that technology because they're under attack. So I totally get it. When you're under attack, there's fear and you're going to buy the thing that is going to help you get out of trouble. Likewise, if we think about the next 10 years, what does the world look like? Well, I've got a bold prediction.
And my bold prediction is that most large organizations will end up with 52 AI tools. Why? It's not because of fear of being under attack. It's fear of missing out. It's formal. And it's hearing about what competitors or other organizations or collaborators or peers are doing. And people will just accumulate all these AI tools. And some of them will be well deployed, most not. They won't be fully deployed. They won't be fully integrated. They won't be fully harnessed. And so we're going to end up with the AI equivalent of the security situation we have today. Too many tools, partially deployed. And so a lot of the work I do, you know, and my role trying to help organizations, but strategy is, I say to them, let's pick one or two. One or two and make them your primary strategic platforms. And then let's go on a journey of simplification and consolidation.
And simplify today's tech stack, which is usually a long list of technologies, simplify it down to a much shorter list than three years or five years or now. And go on this transformation and squeeze a lot of value out of one or two strategic platforms, such as the Microsoft one, and use all the automations and all the integrations. And make it work for you. Get 70% of the value instead of 45%. And make it work for you. And turn off all the noise around it, all the overlapping products, and get your team up really skilled up so they become the experts. And they know how to find the automations. And all the smarts and the technology platform. Right, right. Beautiful. I think it's great that you brought that point about 52 plus security tools, each of many of the companies or many big corporations using. And of course, there will be definitely 50 plus AI tools or even more, I've also heard about a statistic people
saying that use cases, I think even there are 200 plus use cases, every company wants to already work on. But we don't even know which one you want to really. Yeah, so that that number is already staggeringly high. Yeah. Now, I want to take this conversation a bit more deeper. I know you're there are a lot of these traditional security concern controls are concerns they're failing with this model, modern knowledge workers, I would say, right, because there are quite a lot of things, especially when employees, so you have a task at hand that you have to confirm that, are you do complete that task at hand. You earlier mentioned that there are a number of tools. I think you can have some of these tools that are homegrown or some of these tools which are well set up in your environment. But there are some things employees
might easily, they can turn to their personal devices or they can turn to some unauthorized applications or maybe to public AI tools to complete their work. Is that happening quite a bit? Quite a lot. Is it? You see in your experience, why that is happening? Is it because of the competition that we are in? Do you want to talk to that? I think people are always looking for ways to work smarter. We all try to hire smart resourceful people. And so they will be smart and there will be resourceful and find ways to get the job done. If that means using some unsanctioned AI tool or just their own free or even paid AI tool, they're going to use that. Unless we give them really good tools at work. If we give them good tools like in my company, we give everybody co-pilot.
And under co-pilot you can then access all the cloud models, the Sonnet and Opa and the Chatchee PT models and everything is grounded in Microsoft 365. So that's how we want people to work. What we don't want to do is have a personal deep seek account, our personal Gemini account and start using those for our work data or customer data. That's a no-no. But they would do that if we did not give them access to co-pilot and cloud and Chatchee PT as the primary tools. But I think that's the first thing. It's giving people a happy path. Where we say, these are the tools we want you to use and we've invested in making them secure. And we can support them, we can give you assistance. This is the happy path. And if that doesn't exist, they will find other ways. They will go off the reservation so fast because we've hired smart, resourceful people. So I think this is the right time to pivot into this topic of how do we build a secure
and a productive AI enabled workspace. I think you've already mentioned that how organizations should start thinking about. So maybe could you go a bit more deeper and kind of explain, what does this secured by design actually look like in the year of 2026, across identity, across endpoint management, the data governance and so on and so forth? So, regular, I'm going to share a story if that's okay about the mistakes we made. Because we got this wrong. And that has been quite instrumental to reflect on the mistakes we made and then figure out how we can help our customers. So when we started with AI, we moved early because we were a technology services company. And we deployed AI to most of our people. And then we got in a bit of trouble because we realized we had not defined our use cases properly. So we didn't know who we should have given AI to and what order. Then we realized we hadn't secured our data.
That was a second problem. And when we did a search, we found we had 33,000 sensitive data assets that were overshared across the organization. So like a spreadsheet that was shared the whole organization or work documents or whatever. And the third thing was we found that we were all reasonably competent using AI in the browser. We were really, really poor at using AI in Excel and Word and PowerPoint. And in the embedded applications, we were really bad. And then the fourth thing was we didn't have any agents because we didn't know where to start. We just didn't have a clue where to start with agents and we hadn't done the groundwork and we didn't have any API access into our CRM system, our finance system, the systems of matter that had the important data. And then the last thing was we had no way of measuring our success with AI. So when the board asked, how's it going?
Giving AI to all these people and paying all the licenses, what's happening? How's it going? We couldn't answer the question. And so if I had to choose between giving it to everybody because it's amazing or saying, we're gonna pull it all back because it's no good, we had no way of knowing because we couldn't measure anything. So we then called those, those are our five problems to find in the use cases, secure in the data, teaching people how to use it properly, building the agents and having an ROI framework. And so they became the five work streams we now use to help our customers get ready and do AI well and be successful. Beautiful. I think you brought one very interesting aspect. Right? I think there are this securing the data. Yes. Like with this 33,000 plus access points, where if you cannot, though it's an example, I think that's how things are happening. You have an open worksheet, which is shared across different teams.
You might think that it is secure, but sometimes access doesn't need to be given to everybody in the organization. It depends on the use case and the work level, the things. And the other important point that you also mentioned is about embedding AI into these applications, which were already natively built. Correct. Because new applications, you know how to, how you are, how you are, AI is built on top of that. Yeah. Native applications, how do you use this embedded AI? Yeah. So do you, this is where, I think these are some great points that you've brought. So for me, now, do you want to expand a bit on how that, I know this embedded AI piece is going to be getting much more interesting. And now when we talk about security or embedding security into this, how do you foresee that is first question?
I think maybe the second question I want to go into the million dollar question or the extra question, but what's that let you answer that then we can. So how I see this play out will be, it will start with identity and access management. And when new employees join the organization, when they join a mature organization, we'll talk about mature organizations first. When they join a mature organization, their details will be set up in the HR system. That's the point of intake and the starting point. They will be an automated process from the HR system to create the user's account, which will have a whole bunch of predetermined attributes. So depending on your role, there'll be certain applications you get on birthright on day one, access to specific resources, certain security policies, certain permissions, maybe some subscriptions, you need to be signed up to maybe some hardware peripherals, extra screens and stuff like that.
All of that should follow the role. So a role based bundle of hardware, software, applications, permissions, policies, subscriptions. And those permissions and policies should then be inherited for all the work the person does. So the groups they belong to, that's going to be super important. So using dynamic groups. So if you belong to group A and the people in group A are allowed to access your finance system, but not your CRM and people in group B can access the CRM, but not the finance system, following the hierarchy of the groups, so that if you now go and build an agent, your agent shouldn't hurt the security policies that have been attributed to your role from day one. So let's say if you were in sales, if you were allowed to access the CRM system, but not the finance system, your agent would be able to access the CRM system and pull that data, but not look up the company's financials. And taking that right down to the tasks and the API calls,
so you're going to have a certain API call, your agent might be talking to another agent or uploading information or fetching information or accessing third party systems. There will be a hierarchy where everything will flow down from the original definition of the user's role, policies, permissions. And then mature organizations will be able to go in and do an access review and say, let's have a look at RIGU's account and see what's the accessing. Is it appropriate? Are we following zero trust principles? And as you know, the zero trust principles are just in time. So giving you access to the thing you need for the time you need it, not indefinitely, and least privileged access. So that if your agent needs to access a system to retrieve some information, well, that would be an authentication event that happens for that specific request in that specific moment. Not keeping that door open indefinitely for all data, but your agent requested a certain file or information.
And there's an authentication request to see. Is RIGU still a valid employee? Yes. Is he in good standing? Yes. Is he on a Wi-Fi? We recognize yes. Is his device managed? Yes. Can his credentials be found on the dark web? No. Is he in the country where we normally expect him to work? Yes. OK. Now allow you to log in, retrieve the information you need from that API call, and then terminate that call or that session. About that does is it follows zero trust in a way that we, the other third principle in zero trust is we assume breach. We assume breach. And so we're looking to minimize the blast radius. So if that agent gets compromised or that data gets leaked whatever, we want to minimize the damage. So if that agent got hijacked or if it went rogue, which is very topical this week, if that agent went rogue, the damage it could do is hopefully limited because we're using just
and time access and least privileged access to all the resources around it. So we have the least amount of damage. It's something. Beautiful. I think I like the way you have explained it right from the onboarding of a new employee to how things should be set up in the system and how the access is provided and then for the agent packages. Yeah. Access packages and other things. I know it took a lot for me to get to this point, but I would like to now come into this interesting question, which I term it as the million dollar question of the billion dollar question. It's not going to win a million dollars today. Do I have a chance? So I know there's so much of competition out there. There's so many technology deployment providers out there. How do you differentiate yourself or your mobile mentor in this space when you're helping an organization move beyond their deployment
and extract this miserable business outcomes I love the question. Thank you. Look, we're primarily a Microsoft partner. They have 400,000 partners, 400,000. Yeah, that's the reason. Yeah. And so it's very easy to be nobody. And when I started this business, I was in New Zealand. So basically the second last rock before the end of the the end of the earth. So we were nobody far, far away and impossible to get Microsoft's attention for anything. So I gave my team a challenge about 12 years ago. I said, what if we aim to become the best in the world at one narrow thing? We picked this one Microsoft technology and we picked Intune, which is a platform for managing all our devices and applications and all that. And it was quite an immature technology back then. But we made a bet and we said, what if we become the experts on that platform, that technology, we grow as the technology grows and we partner with Microsoft and we're
aimed to become the best in the world at that one thing, which means we're going to say no to everything else. We're just going to do that one thing and be super narrow, hyper focused. So Anish and Anish. And then five or six years later, we won global partner of the year for the work we were doing with that. And we really got noticed by Microsoft. And then they started introducing us to their biggest customers. So we've got the biggest health care customer in the world. We got the biggest education customer in the world with a million devices and a whole bunch of amazing customers. And then I got invited onto the Microsoft advisory board for that product line. And that then led us to other things, identity and AI and security and other things over the last, you know, over the years. So I would say the thing that makes us different is very deep knowledge of a very specific set of technologies. We're not all things to all people.
We still say no to a lot of requests. But when it comes to working in the Microsoft area and anything to do with endpoints, security, AI, we say yes, yes, that's our wheelhouse, that's our thing. And then when we work with customers, we can help them deploy the technology, and can build the technology for them and hand it over to them. Or we can say, we'll build it and we'll manage it for you. We'll just give you a man of service. Everybody else does that. OK, there are 400,000 partners who can build us or just manage it. We found this amazing white space in the middle, this untapped market opportunity, where there are organizations who want to learn the technology. And they want to internalize that knowledge. And they want a partner to come in and design it with them for their requirements, build it with them, hands on keyboards, doing the work every week, and then help them become the experts. And that has become our fastest growing service over the last few years.
We call it mentoring, which is very close to our brand. And everything we do has a bit of mentoring in it. So we like to learn the technology from Microsoft, being on these advisory boards, and we're now part of their elite engineering team. We get to learn all this new technology and see what's coming. We then get to share that with our customers, help them deploy it, and extract good value from it. So our operating model is very different to most managed service providers or professional service companies where in there with our customers, hands on keyboard, doing the work, but making them the experts. Beautiful. I like the focus step coach. Really great talking with you. I would like to have a couple more questions before we end the conversation. I know we have, there's a lot more organizations are growing at a faster pace. Workplace is increasingly, it is being shaped
with this different AI agents, AI technologies, cloud native platforms, and like you briefly talked about, the passwordless identity, other so on and so forth. One of those most important actions a business or a technology leader should take during the next 12 months, or what do you foresee in the next one to two years? Oh, I foresee three huge problems in front of us right now. Data security, we talked about that. That's going to be a huge and persistent problem. The next new problem is going to be the mushroom cloud of agents in organizations. It's going to go, you've got everybody developing agents are going to be all over the place accessing all this data and working autonomously. And so managing all those, knowing where they are, what they're doing, what applications are calling, what APIs, what version, the security policies, so managing agents into end as the lifecycle management.
That's a huge problem that needs to be managed and that's huge. The third thing is going to be spend management. So AI is very shifting from free to paid and then the paid model is going from a flat fee to a consumption. So it'll be a flat fee and a consumption charge. So if you look at Anthropic or Cloram or Microsoft, the way they're charging, there's a flat fee for your co-polish or whatever and then there's going to be core work on top of that and core work is a consumption-based charge and you'll buy credits, which will have a relationship with tokens, but it won't be one to one. It'll be much more confusing than that. And tokens and credits would have a relationship with dollars, but it won't be simple. So people are going to have to make sense of this in the new economy of AI. And if organizations have three or five or 52 AI products that have some flat rate charging, some consumption-based charging, some based on API calls,
it's very quickly going to get very complex. And organizations will need to learn how to manage all this complexity and all these charges and make sense of the tokens and the credits. Excuse me. So the three big things, data management, agent management, spin management. That's what I think would be the three big headaches that we need to resolve in the foreseeable. Yes, yes. I completely agree. The task that you have put across the data management is going to be really, really important and mushrooming of too many agents. And with that, I think the spend management for the organizations, the IT budgets, the spend, I think that's going to mushroom like a crazy. Yeah, yeah. Fun times. Fun times. So yeah, one other question before we go to the last one,
I think how do you feel the employee experience changes in this context? Because now there is a lot of, we see a lot more, what I say is that, do you believe that this employee experience will become almost invisible and frictionless or will employees encounter a lot more controls as these AI-related risks will increase? Because there are two sides of the coin, right? I think do you think the employees will have even more ease of use or these regulations and the risks with the security? Maybe two to three years down the lane. You know, that's a great question. I asked that question of our research data, because we had the research data in 22, 24, and 20, 26, and I ran a prompt and I said, look at the research data only and predict the future
in 2034 based on the trends we can see in the data. This is looking at like a couple of million data points. And some of the predictions were really, really interesting and some were really obvious, but one of them was, you know, will be completely passwordless, which is great. We've been banging on about that for years. We have to get rid of passwords. They were a great invention in 1961, 1961, that's 65 years ago. We're still relying, imagine if your home was still using the same security you had 65 years ago. Anyway, it's nuts, but, you know, so many organizations still rely on passwords. And that's one, they will go away and security will become largely invisible was one of the other predictions. We love that. So the more we can have embedded security that's aligned to the role and you're onboarding right from day one and inheriting a set of policies, permissions, profiles and all that,
it should become invisible. And you should be able to work on your devices, plural, multiple devices, some might be owned by work, some might be personal, but in a way that it's almost irrelevant who owns the device because the data is secure wherever we go, we're not signing in with passwords, we're using biometrics and conditional access policies and real-time authentication. All our software updates and software patching is automated and invisible. So there's the patching for the device, the operating system, the firmware, the drivers, all the third party applications, that's all automated. So we're not getting these annoying notifications that we have to shut everything down and do a restart. You know, we want that process to be silent and invisible and we see that a lot of the security interventions will be silent as well. If there is a known vulnerability that it will get repaired or remediated silently without the user even being aware of it.
So we do think that a lot of security controls that are very visible in our face today and annoying and give us friction will become silent and invisible in the future. You're just that. Super happy about that. But it requires a ton of work. It won't happen if we are not investing in that. You know, we have to make the investment to go passwordless and then we can tell our employees, what would he do? We're now passwordless and you can forget about, you know, password vault or saving all those pesky passwords you had in the past and now we're going to stop and knowing you to restart your machine. It's going to do the patches automatically while you're sleeping or whatever. So we're removing friction from the end user experience. It's going to get better. That's great. I think that's great to know that. I think you're coming from that background. The end user experience will increase tremendously. At the same time having these AI controls
that will help propel the, so the risks are minimized and the risks and the controls are put in the background. So that we can still, the end users will still have the experience and a much more, smoother experience. Yeah. Correct. And we'll be secure by design. Like we will set up the user's role to have the right policies and profiles and belong to the right groups and access the right applications from day zero. And then we might modify a group or permissions or some of the policies and all the people in that group or in that role will inherit those new changes. So it'll be dynamic, but silent and invisible. Great. Yeah, I love chatting with you. I learned a lot before I let you go. Any closing remarks where you could, if the audience would learn to more, would want to learn more about you or mobile mentor or your latest research and perspectives.
How do they reach out? Thank you. Firstly, the company name is mobile mentor today. The company name very soon will just be mentor. We're going through a rebrand. And my name is Dennis O'Shea. Dennis with one in and over post review SGA. I'm on LinkedIn only. I'm not on any other social platforms. Just LinkedIn so you can find me easily or you can find the company mobile mentor today, mentor tomorrow. And yeah, thank you for the opportunity to be on your podcast. Ragu, I really enjoyed it. You asked some killer questions. You got deep into my head. So I really appreciate that. Thanks. Thanks for your time and I love the conversation. Thank you. Thank you, Dennis, for joining us on Extra AI and for sharing such a practical perspective on what it really takes to build a secure, productive AI enabled workplace. Today's conversation reminded us that AI adoption
is not just about deploying more technology. It is about getting identity, security, endpoint management, zero trust, and most importantly, the employee experience right. And to everyone listening, thank you for spending your time with us. If you enjoyed this conversation, follow Extra AI and stay tuned for more discussions with leaders shaping the future of AI, enterprise technology, and business. This is Ragu Banda signing off. Keep extracting the raw AI conversations and happy predicting the future with Extra.
More episodes
More from XTraw AI: Machine Learning and AI Applications

#191 The Quality Layer for the Agentic Coding Era with OrangePro AI
XTraw AI: Machine Learning and AI Applications

#190 Reclaiming the Internet in the Age of AI
XTraw AI: Machine Learning and AI Applications

#189 From Search to Agentic Answers with You.com
XTraw AI: Machine Learning and AI Applications

#188 July 2026 -The Month AI Agents Crossed the line from Answers to Action
XTraw AI: Machine Learning and AI Applications