NANCY WANG
NETWORK SECURITY
The identity problem: who did what? This identity problem is an elusive one, as Nancy points out with a question, asked and answered:“ If you were to ask your security teams who actually took an action against the system? Is it a human, is it a service account or is it an agent? They probably don’ t know or there’ s not 100 % certainty to that answer,” she says.
The reason is obvious and it comes down to permissions:“ Agents look like humans because they have all your permissions, but they also could look like a service account.”
In the quest to make the secure path the easiest path, industries must adopt the identity best practices with no standing privileges.
“ An agent that is overpermissioned with longstanding credentials is a risk because then they can do replay attacks over and over again,” Nancy says. This raises the question of designing security systems around these“ non-deterministic beings”. The sweet spot, Nancy says, in“ allowing them to be creative, to take reasoning, but also to apply essentially traditional construction sets in the form of SDKs” is to have“ controls that are predictable, but also you don’ t want to constrain the agents so much that they no longer have the productivity gains that got you excited in the first place”.
NANCY WANG
TITLE: CHIEF TECHNOLOGY OFFICER
COMPANY: 1PASSWORD INDUSTRY: CYBERSECURITY
LOCATION: SAN FRANCISCO, CALIFORNIA, US
Nancy brings deep expertise in AI, cybersecurity and enterprise technology, having scaled major security platforms and led engineering organisations at AWS, Rubrik and 1Password.
108 September 2026