Early-bird Discount
expires in
Register Now

Agenda

Identity for Industry 4.0 (IoT, OT & Smart Infrastructure)

Identity for Industry 4.0 (IoT, OT & Smart Infrastructure)

Combined Session
Wednesday, May 20, 2026 14:30—15:30
Location: B 09
Log in to download presentations

Maintaining OT and Worker Identity Security in Disrupted, Degraded, Intermittent, and Low-Bandwidth (DDIL) Environments [Advanced]
14:30—14:50

Watch the video

 

In military operations, solving for reliable security at the tactical edge requires identity systems to remain responsive and operational in disrupted, degraded, intermittent, and low-bandwidth (DDIL) scenarios. Identity systems must continue to operate the same in theater whether or not connectivity to the home base is available. However, one does not need to be in the military to recognize the potential value of replicating these deployment patterns for OT. A DDIL-capable identity architecture ensures robust industrial operations and security regardless the connectivity status of the factory floor. In this talk Jon Lehtinen will walk through the components, architecture, use cases, and operation of a DDIL identity system to show how solving for DDIL scenarios can keep your staff, OT, and IT functional even if you lose the connection to the outside world.

Jon Lehtinen
General Manager
UberEther
Jon Lehtinen has 20 years of experience practicing identity security in large corporations like General Electric and Thomson Reuters, as well as within IAM security vendors such as Okta. He builds...
Beyond Compliance: Identity Architecture for Industry 4.0 under NIS2 and the CRA
14:50—15:10

Watch the video

 

European regulation is changing the identity design brief for Industry 4.0. In manufacturing, identity can no longer stop at workforce access or remote supplier access. NIS2 raises expectations for cyber risk management, reporting, and supply-chain security across 18 critical sectors, while the Cyber Resilience Act requires products with digital elements to be secure by default and maintained through their expected support period, with reporting obligations starting on 11 September 2026 and the main obligations applying from 11 December 2027.

This session explains why factories now need four identity planes: workforce, third-party, machine, and product. It shows how that shift changes the way organizations handle machine and gateway identity, product lifecycle trust, and the evidence needed for governance and incident response. Rather than treating NIS2 and the CRA as compliance checklists, the session turns them into a practical identity architecture problem for operations, suppliers, machines, and connected products.

Attendees will leave with:

  • a clear model for separating workforce, third-party, machine, and product identities in a factory environment
  • a practical view of how CRA changes product lifecycle identity, from secure defaults to updates and support periods
  • a concrete understanding of how NIS2 shifts identity from access alone to evidence, review, and accountability after incidents or supplier activity
Guillaume Teixeron
Senior Analyst
KuppingerCole Analysts
Guillaume Teixeron is a Senior Analyst at KuppingerCole Analysts, focusing on cybersecurity, digital identity, and software engineering excellence. His background covers identity and access...
Beyond the Bearer Token: Veridian for IoT, OT & Smart Infrastructure
15:10—15:30

Watch the video

 

Industry 4.0 is moving faster than the identity layer underneath it. Sensors, robots, autonomous vehicles and AI agents now make decisions across organisational borders in real time - yet most still authenticate with vendor PKI, OAuth bearer tokens, or device certificates that cannot rotate, cannot prove provenance, and cannot survive a quantum break. The result is a trust gap at the very edge where Industry 4.0 actually has to work.
This talk introduces the missing layer. KERI gives every device and agent a self-certifying, post-quantum-ready identifier. ACDCs carry verifiable credentials with full chain-of-authority provenance. The GLEIF vLEI anchors that chain in a globally interoperable root of legal-entity identity. Drawing on Veridian's production deployments and complaint GLEIF vLEI tooling, the session shows how this stack lands on real Industry 4.0 problems - device onboarding, OT command authority and cross-operator interoperability - verifiable in milliseconds, with no bilateral integrations.

Thomas Mayfield
Head of Decentralized Trust and Identity Solutions
Cardano Foundation
Thomas A. Mayfield is the Head of Decentralized Trust and Identity Solutions at the Cardano Foundation and holds a BSc. Honours Degree in Computer Security and Digital Forensics. Thomas is...
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.