Identity Threat Detection & Response (ITDR) II
Combined Session
Wednesday, May 20, 2026 15:35—16:35
Location: B 07-08
Wednesday, May 20, 2026 15:35—16:35
Location: B 07-08
Watch the video
Whether human, non-human, or agentic, identities have become the dominant control plane - and attack surface - of modern digital infrastructures. Yet our visibility into who actually has access to what remains fragmented across IGA, PAM, CIEM, and SaaS environments, resulting in persistent over-entitlement and hidden risks. In the age of AI, this gap becomes critical: Access can be exploited at machine speed, while IAM architectures often still rely on static models, periodic reviews, and incomplete context. Identity Visibility and Intelligence Platforms (IVIPs) have emerged as an architectural response to these real-world challenges, introducing a dedicated layer for continuously aggregating, correlating, and analyzing identity and access data across the Identity Fabric. Drawing on practical observations from the field, this session examines why identity transparency has remained elusive despite mature IAM controls - and why continuous identity visibility and intelligence are increasingly foundational for risk-adaptive access, identity threat detection, and true least privilege in AI-driven environments.
Watch the video
Customer, partner, and machine identities are now the largest unmanaged attack surface.
Cybersecurity strategies were traditionally built around employees, devices, and internal networks. But today, organisations manage far more external identities than workforce identities - including customers, partners, APIs, services, and AI agents. In many cases, the ratio already exceeds 1:100.
Yet security architectures still focus primarily on workforce IAM. This session explores why external identities are becoming the new cyber resilience frontier, how identity-driven attacks are evolving, and why organisations must adopt an Identity First Security approach to secure digital ecosystems.
Watch the video
Insider risk is no longer a niche security problem, it’s a governance challenge at the core of every organization. As businesses evolve toward hybrid operations and data-driven collaboration, the real question is not who has access, but how identities reflect trust, accountability, and intent.
This session explores how Identity and Access Management (IAM) programs can evolve into a foundation of insider risk management, not by adding more surveillance, but by embedding behavioral, ethical, and operational context into identity governance itself.
We’ll look at how identity becomes the language of trust across the enterprise:
• From provisioning to prediction — understanding the signals of privilege misuse and entitlement drift before they become incidents;
• From compliance to culture — turning access policies into expressions of organizational values and accountability;
• From detection to decision-making — using identity-centric risk insights to inform hiring, offboarding, and third-party engagement decisions.
Drawing on cases from finance, healthcare, and the public sector, we’ll demonstrate how organizations can use IAM not just to prevent incidents, but to strengthen their human trust architecture.
The result: a model of identity-driven insider risk management that aligns regulatory compliance with sustainable resilience, proving that trust can be engineered as deliberately as access itself.
Attendees will leave able to:
- Read IAM telemetry signals from existing IGA and PAM data that predict insider incidents earlier than detection tooling.
- Apply a four-node decision tree to test identity-based monitoring against EU proportionality requirements before deployment.
- Translate one identity maturity gap into a defensible annual loss range, anchored in published industry data.