Dan Kaplan

Director of Content Marketing

About Author

Dan Kaplan is the friendly neighborhood content marketing leader at Aembit. Based in New York but operating remotely, he tells stories about agentic identity, workload identity, and cybersecurity that are meant to educate, inspire and, if he’s lucky, even entertain. Before joining Aembit, Dan held a similar role at Google Cloud, following stints at Siemplify and Trustwave, where he led content initiatives. He planted his roots in cybersecurity as a reporter and editor at SC Media. When he’s not conjuring content, he can usually be found watching sports, advocating for farm animals, or listening to paranormal stories as he falls asleep. Don’t ask.

Expertise

  • Cybersecurity
  • Identity and access management
  • Non-human identity
  • Workload identity and access management
  • AI agent identity and security
  • Cloud security
  • Security operations
  • Threat detection and response
  • Cybersecurity journalism
  • Content strategy
  • Editorial strategy

Education

  • Bachelor’s degree in journalism, Syracuse University, S.I. Newhouse School of Public Communications

Articles by Dan Kaplan

An exercise ended with frontier models inside a platform’s production systems, exposing a hard truth about what agents can do with credentials that systems trust.
Compare 10 identity security vendors for AI agents, including where each fits and what buyers should examine before choosing.
As AI moves from chat windows to enterprise systems, data leakage becomes an identity and access problem.
The response to the Canvas breach revealed how much modern institutions still depend on long-lived credentials, shared trust layers, and persistent access between systems.
Workforce and customer agents may rely on similar identity infrastructure, but the trust models, access patterns, and security risks behind them differ significantly.
Static access rules fail in dynamic MCP environments. Context-based access control evaluates identity, context and resources in real time.
Secrets managers store credentials but can’t close the access gaps that multicloud workloads and AI agents create. Five alternatives can.
Non-human identities outnumber human users 144 to 1, yet most security programs overlook them. The OWASP NHI Top 10 maps the risks.
Hardcoded credentials and shared tokens give attackers ongoing access. Dynamic authorization replaces them with real-time decisions.
Two layers protect cloud-native apps: Workload IAM secures machine identity and API security inspects request traffic. Most teams need both.
An agent behaved like a true insider threat. Unmanaged API keys made those mistakes devastatingly consequential. Both can be true at the same time.
Modern infrastructure depends on keys: encryption and access. They’re not the same, and treating them the same quietly introduces risk.