Early-bird Discount
expires in
Register Now

Agenda

Identity Threat Detection & Response (ITDR)

Identity Threat Detection & Response (ITDR)

Combined Session
Wednesday, May 20, 2026 14:30—15:30
Location: B 07-08
Log in to download presentations

From IAM to ITDR: Building Identity Threat Detection and Response for Real-World Resilience [Intermediate]
14:30—14:50

Watch the video

 

Identity Threat Detection and Response (ITDR) has quickly emerged as the next frontier of identity security. As attackers increasingly exploit legitimate credentials, tokens, and federated trust paths, traditional IAM controls, even those within mature Zero Trust frameworks, often fail to detect subtle identity misuse until it’s too late.

In this session, Hutch will use his experience at a large global bank to explore how organizations can extend their IAM foundations into a true identity security operations capability, blending signals from IAM, EDR, SIEM, and cloud platforms to identify and respond to identity-based threats in real time. Attendees will learn how to recognize early indicators of compromise within authentication, authorization, and privilege escalation flows and how to operationalize ITDR without waiting for a major vendor or product release.

Drawing on real-world scenarios and implementation lessons, Hutch will outline a practical roadmap for detecting and containing identity attacks before they evolve into full-scale breaches.

Key Takeaways

  • Understand what Identity Threat Detection and Response (ITDR) is and how it complements IAM, IGA, and Zero Trust programs.
  • Learn the critical telemetry sources and detection logic required to identify identity abuse across cloud and hybrid environments.
  • Explore a reference architecture for integrating ITDR into existing SOC workflows and incident response playbooks.
  • See real-world attack paths and detections, including MFA fatigue, token replay, and conditional access bypass attempts.
  • Gain a practical maturity roadmap for moving from identity visibility to proactive identity defense.
Steve Hutchinson
Director of Security Architecture
Mitsubishi Bank of Tokyo
Steve “Hutch” Hutchinson is the Director of Security Architecture at MUFG. After cutting his teeth in C/C++ software development and network engineering, Hutch spent a decade as an...
AI and Identity: The Next Frontier in Access Intelligence and Anomaly Detection [Introductory]
14:50—15:10
 
Allan Foster
Chief Evangelist
Identity Evangelist
Allan Foster helped build ForgeRock into a multinational identity software vendor culminating with its listing on the NYSE in Sept 2021. Allan’s deep technical knowledge was well used in all...
Almost Human: How to Protect Machine Identities [Intermediate]
15:10—15:30

Watch the video

 

Not every machine identity is human, and not every machine identity is AI. What about protecting the machines that already exist in your environment? This includes service accounts, enterprise applications, and all the other names they have today.

This session will examine how to protect these identities in a modern environment, make attacks visible, and respond to attacks that are already underway. This demo-packed session will show how simple attacks against service accounts in Active Directory and app registrations in Entra ID can be.

It will also show how attackers can live persistently in your environment, steal data, and act like a normal business application.

Tim Wolf
Senior Solution Architect
Semperis
My mission is protecting identities. Currently at Semperis, I ensure the resilience of Active Directory and Entra ID. My background includes years as a Microsoft PFE, implementing Zero Trust and...
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.