Endpoint Security
,
Events
,
Governance & Risk Management
Device Authority’s Antill on Secure-by-Design and Continuous Authentication
Many IoT devices, such as those in industrial or remote environments, were never designed with modern authentication in mind and often use default credentials – or none at all – making them easy targets for attackers. Even when certificates are used for authentication, Darron Antill, CEO of Device Authority, pointed out that frequent expiration and limited visibility into device status create operational and security risks over time.
See Also: How Generative AI Enables Solo Cybercriminals
Addressing security at scale, Antill recommends a secure-by-design approach, including implementing zero trust principles to continuously authenticate and authorize devices throughout their life cycle. Automation, he said, is key: Human administrators cannot manage the millions of devices expected to populate modern enterprises, especially as these devices stay in service far longer than traditional IT assets.
“Never trust anything inside or outside your perimeter. Always verify anything and everything trying to connect to your systems,” Antill said.
In this video interview with Information Security Media Group at RSAC Conference 2025, Antill also discussed:
- THe emergence of identity as foundational to the IoT space;
- Why organizations must adopt new approaches that account for both human and non-human actors;
- The importance of embedding cryptographic techniques and secure-by-design thinking from the beginning.
Antill has expertise in IoT cybersecurity, enterprise software, SaaS, and IT and security-driven businesses. Under his leadership, he has raised over $70 million in funding, including a landmark investment from Goldman Sachs – then the second-largest private investment outside of Facebook.

