The internet was built as borderless infrastructure, but identity systems now sit at the center of geopolitical power. When authentication fails, business, payments, healthcare, and government services stop, making sovereignty an operational risk, not merely a political debate.
Based on discussions with 25 CISOs across finance, government, and critical infrastructure, this session explores a new reality: security leaders are no longer primarily worried about passwords, but about legal control, service continuity, and who ultimately controls identity interactions.
As regulations such as the Digital Operational Resilience Act (DORA), the NIS2 Directive, and the evolution of the eIDAS Regulation raise the bar, identity is shifting from an IT function to regulated infrastructure.
The next decade will not be defined by user experience alone, but by assurance and by one defining question: who is truly in control?