As enterprises accelerate their digital transformation journeys, a critical security gap has emerged that traditional controls like SSO and MFA simply can’t address: the growing chaos of unmanaged identities, orphaned accounts, and sprawling privileges across hybrid environments. Rita Gurevich, Founder and CEO of SPHERE, has been witnessing this evolution firsthand since founding her company in 2010, originally as a consulting firm born from the lessons learned during the Lehman Brothers bankruptcy. What started as a “clean-up company” helping organizations untangle their technology assets has evolved into a mission to establish “Identity Hygiene” as a foundational security layer.
In this exclusive VMblog Q&A, Gurevich explains why the explosive growth of non-human identities�now outnumbering human identities 82 to 1�represents one of the biggest blind spots for modern security teams and boards. She reveals how SPHERE’s approach to “upstream hygiene” is helping enterprises safely navigate Active Directory modernization, maximize their PAM investments, and transform compliance from effort-based point-in-time assessments to evidence-driven continuous monitoring. With fresh Series B funding from Edison Partners and Forgepoint Capital, Gurevich shares her vision for making identity hygiene as standard as vulnerability management while addressing the next generation of challenges from M&A consolidation to agentic AI automation.
++
VMblog: SPHERE has been operating since 2010, which gives you a unique long-term perspective on identity security evolution. What originally drove you to found SPHERE, and how has your vision for “identity hygiene” evolved as enterprises have moved from on-premises to hybrid and cloud-first environments?
Rita Gurevich: I founded SPHERE in 2010, originally as a consulting firm. I got the idea actually during the Lehman Brothers bankruptcy, where I worked at the time and was tasked with helping split apart the technology stack for the different entities that bought pieces of the business. What I uncovered was alarming: no inventory of assets, no ownership, and no understanding of what was in use and tons of garbage everything. It was the ultimate lesson in bad housekeeping and inspired me to start what I called a “clean-up company.”
As we helped clients “clean up”, we kept coming across the same identity problems again and again-privileged access sprawl, stale accounts, ghost users-and manual methods weren’t enough. We began automating our work, which evolved into SPHEREboard and the concept of Identity Hygiene: continuously finding, fixing, and monitoring risks.
Over the years, as enterprises moved from on-prem to hybrid and cloud-first environments, identity became the new perimeter and the need for Identity Hygiene shifted from a nice-to-have’ to a have-to-have. That original vision only expanded: hygiene is no longer a one-time project across a few sensitive systems, but a foundational layer of security that keeps organizations resilient in today’s dynamic environments.
VMblog: You’ve positioned identity hygiene as the “missing security layer” that enterprises need to make Zero Trust initiatives truly effective. Can you explain what identity hygiene means in practical terms, and why traditional security controls like SSO and MFA aren’t sufficient on their own?
Gurevich: Identity Hygiene means exactly what it sounds like: ensuring every identity is surfaced, properly owned, secured, and clean (meaning its properly following all key controls). In practice, hygiene activities can be removing orphaned accounts, flattening nested groups, right-sizing entitlements, rotating passwords and monitoring drift.
Identity Hygiene is about keeping your identity environment clean and secure-much like brushing your teeth, but for your identities. It means knowing every identity (human and non-human), verifying its legitimacy, understanding what it has access to and its level of privilege, and ensuring it has only the access it truly needs and is properly protected. What some people often misunderstand is that hygiene, especially identity hygiene, is not one-time exercise. We’re working hard to educate the community on not just how to achieve it, but why. Going back to brushing your teeth; you don’t do it simply because it’s part of your morning routine. You brush your teeth to prevent cavities. That’s a shift – thinking about hygiene in the context of intent and urgency.
Traditional controls like SSO and MFA are critical, but insufficient. They answer “who are you?” and “can you authenticate?” but not “should you still have this access?” Without hygiene, you’re putting strong locks on a house filled with open windows. Zero Trust only works if the underlying identity estate is clean.
VMblog: One of the most compelling points in your messaging is the rise of “ghost” and service accounts-non-human identities that often bypass human-centric security controls. What makes these accounts such a significant blind spot for organizations, and what should boards be asking their security teams about non-human identity management?
Gurevich: Ghost accounts, service accounts, SSH keys, tokens-these non-human identities (NHIs) don’t follow the same rules as employees. They don’t go on vacation, don’t reset their passwords unless told to, and rarely expire. Yet they often hold some of the highest privileges in the enterprise. Many are forgotten, misclassified, or owned by teams that no longer exist. That makes them perfect hiding spots for attackers and huge blind spots for defenders.
Boards should be asking their CISOs:
- Do we have a complete inventory of non-human identities?
- How many are privileged, orphaned, or over-privileged?
- What’s our ownership, rotation, and ongoing validation policy?
Without these questions, leadership is missing one of the biggest systemic risks in their environment. More and more CISOs are talking about bringing visibility to these accounts and automating the clean-up process, making what was once invisible now manageable, auditable, and secure.
VMblog: Many enterprises are struggling with Active Directory and Entra ID technical debt accumulated over years of organic growth. What are the biggest risks you see when organizations try to modernize their identity stores, and how does SPHEREboard help them navigate this transformation safely?
Gurevich: The biggest risk in cleaning up Active Directory or Entra ID is that it’s like rewiring an old building-you don’t always know what you’ll break. Years of organic growth create nested groups, circular memberships, stale permissions, and forgotten service accounts, all with hidden operational dependencies. Move too aggressively and you risk breaking workflows, disrupting production systems, or duplicating risk in a new platform.
SPHEREboard provides a safe on-ramp by delivering intelligent discovery, classification, and simulation. Before you remediate, you see exactly what’s tied to each account, entitlement, or group. The platform then prioritizes risky configurations and automates clean-up-so organizations can modernize their identity stores with confidence, speed, and minimal disruption.
VMblog: Your platform works closely with PAM solutions like CyberArk. Can you walk us through why “upstream hygiene” is critical before implementing PAM, and how organizations can avoid the trap of simply vaulting stale or high-risk accounts without proper remediation?
Gurevich: There’s a big difference between vaulting an account and actually protecting that account. Vaulting can create a superficial sense of security-it’s fairly easy to do-but it doesn’t stop someone from sharing the password on a sticky note or a bad actor from compromising those credentials. True protection requires more: you have to rotate the password regularly, set up ongoing safeguards, and make sure the process doesn’t break anything in the environment.
That’s why discovery and analysis must come before PAM. You first need to know what the account is, what access it has, whether it really needs those privileges, and which applications or systems depend on it. Without this, you risk vaulting ghost, stale, or misconfigured accounts-clutter that only obscures the real high-risk accounts you need to focus on.
SPHEREboard automates this arduous process of discovery, ownership assignment, and remediation-what is referred to as upstream hygiene. By removing the noise and cleaning up the identity estate, organizations can ensure that PAM doesn’t become just a vault full of clutter but instead a vault filled with clean, governed, and truly protected accounts. This approach not only maximizes PAM’s value but also provides clarity around where the real risks lie.
VMblog: You advocate for “proving compliance with evidence, not effort.” With regulations like SEC cybersecurity disclosure rules and evolving NIST frameworks, how does continuous identity hygiene help organizations move beyond point-in-time assessments to truly auditable controls?
Gurevich: Too many compliance programs still run on point-in-time audits, where armies of analysts pull spreadsheets and screenshots. That’s unsustainable under SEC disclosure rules and evolving frameworks like NIST CSF 2.0.
Continuous identity hygiene gives organizations evidence they can trust: audit-ready reports, live dashboards, and trackable remediation progress. Instead of proving compliance with effort, they prove it with data-making compliance both lighter and stronger.
VMblog: Mergers and acquisitions create massive identity consolidation challenges. Based on your experience, what’s your recommended playbook for organizations to baseline, merge, and remediate two companies’ identity estates without disrupting operations-and what role should the board play in mandating this process?
Gurevich: M&A is where identity chaos shows up in its worst form: duplicate accounts, conflicting entitlements, and inherited technical debt. Step one is always discovery-building a complete inventory of all accounts, human and non-human, privileged and standard, across both entities. From there, you can baseline what exists, identify what’s risky or redundant, align ownership, and apply consistent policies.
The next step is to normalize and merge entitlements in a staged, simulation-driven way, ensuring you don’t break workflows or disrupt operations. Remediation should then be done continuously, so integration progresses safely without grinding the business to a halt.
The board should play a very active role here. Identity consolidation must be a mandated step in the M&A playbook, not an afterthought. Without it, the financial synergies of a deal can be undermined by inherited cyber risk and compliance gaps. With it, organizations can merge cleanly, confidently, and securely.
VMblog: Looking ahead, with your recent Series B funding from Edison Partners and Forgepoint Capital, what’s your vision for how identity hygiene will evolve? What emerging trends should security leaders be preparing for, and how is SPHERE positioning itself to address the next generation of identity challenges?
Gurevich: With our investments, we’re scaling SPHERE to meet the next generation of identity challenges. The trends we see coming:
- Explosion of non-human identities (many have seen this stat – NHIs now outnumber human identities by a factor of 82 to 1).
- Agentic AI in security, automating not just detection but decision-making.
- Convergence of hygiene and intelligence, where continuous cleanup feeds real-time risk models.
SPHERE is positioning itself as the Identity Intelligence layer: the foundation that makes every other control-PAM, IGA, CMDB, Zero Trust-smarter and more effective. The goal is simple: to make identity hygiene as standard and expected as patching or vulnerability management.
##






