Bojan Simic’s first day running security at a financial institution, he found an RSA token taped to the middle of a shared desk. Four people would roll their chairs back, read the code, and roll back to type it in. That moment started a career-long obsession with one question: how do you know who’s really on the other end? Today the answer is getting harder, because the thing on the other end increasingly isn’t a person at all.
In the premiere of Candid CISO Season 2, John Donovan sits down with Bojan, co-founder and CEO of HYPR and a FIDO Alliance board member, for a frank conversation about what happens when the CEO walks into Monday’s meeting demanding AI agents everywhere, and the CISO’s first thought is how to keep the company out of the headlines.
Inside this episode:
From passwords to probabilistic actors. How HYPR’s quest for “non-shareable credentials” led from fraud prevention to FIDO to a new problem: handing credentials to systems that won’t do the same thing twice.
The 4% problem. People know about roughly 4% of the permissions they hold. Their agents know about all of them.
Why deterministic controls break. Tell an agent it can’t send more than $5,000, and it may just send several smaller transfers instead. Bojan makes the case for control agility, not just control coverage.
Unintended consequences, big and small. A copilot that decided to email HR on an employee’s behalf, a single Salesforce tool that could delete a thousand records in a millisecond, and pen-testing agents that need a chaperone.
Evaluator agents and “human above the loop.” Why the future looks like agents watching agents, with people stepping in only when it matters, and why nobody reads those permission prompts anymore.
Data custody at machine speed. A global defense contractor, a French document, and an agent that wants to share it with a colleague in the U.S. Why enforcement has to happen at runtime.
The banking wake-up call. What happens to a bank’s moat when an agent can move your whole financial life in under an hour?
Who paves the road for agents? Bojan’s take on Jason Chan’s paved road concept, and why security teams need to lead from the front so marketing, finance, and sales can say yes safely.
The takeaway is practical: don’t reinvent the wheel, and keep the accountability model you already trust. If Bob’s agent does something it shouldn’t, it’s still Bob’s call to answer for.
This episode is sponsored by HYPR. Learn more at https://www.hypr.com/candidciso.
Join us live. The conversation continues at Candid CISO Live on Thursday, October 8th at Stanford, featuring Jason Chan, formerly of Netflix and the architect of the paved road, with Bojan joining us in the room.
Candid CISO is a Tout Media production.













