Zero Trust Identity & Continuous Verification
Combined Session
Thursday, May 21, 2026 14:30—15:30
Location: B 07-08
Log in to download presentations
Thursday, May 21, 2026 14:30—15:30
Location: B 07-08
Watch the video
Deutsche Telekom, being at the forefront of providing global digital access, sought to consolidate their IT infrastructure under the Zero Trust Architecture to continuously protect sensitive information. To address these challenges, Deutsche Telekom implemented NextLabs’ Zero Trust Data Security to unify data protection process for extensive user bases across all major platforms. Deutsche Telekom was able to adopt the zero-trust security architecture to automate and standardize security measures and implement a global ERP strategy with strict data access controls. Additionally, it enabled the Company to enhance cloud computing capabilities and ensures effective security measures by protecting against unauthorized access and data leakage, all while reducing costs with a no-code approach. These measures allow Deutsche Telekom to continuously protect sensitive data, implement field-level encryption, and enforce privacy policies, thereby strengthening data governance and standardizing data protection across the organization.
Takeaways:
- Automate access and protection of data using least privilege principle and classification to dynamically protect sensitive data regardless of where it is used or stored.
- Simplify management of data protection policies to prevent unauthorized access of restricted data.
- Simplified policy administration and management through a unified policy platform to respond to new cybersecurity requirements in real-time.
Watch the video
Traditional IAM systems validate access only at login and maintain that trust until a session expires—leaving organizations exposed when user state, credentials, or device posture changes in between. In a Zero Trust world, this model is no longer sufficient.
The Shared Signals Framework (SSF) and the Continuous Access Evaluation Profile (CAEP) introduce a standards-based, interoperable way to exchange real-time security events between identity providers and relying parties. This enables adaptive, continuous access evaluation aligned with modern Zero Trust principles.
This session breaks down the practical implementation of SSF and CAEP:
- Why conventional session-based access control falls short.
- How event types such as session revoked, credential change, assurance-level change, and session presented drive real-time enforcement.
- Architectural patterns for implementing SSF/CAEP in IAM systems.
- Key challenges (e.g., multi-tenant event routing, aud claim modeling, subject scoping) and strategies to overcome them.
- How SSF and CAEP enhance interoperability, reduce lock-in, and strengthen organizational security posture.
- Attendees will leave with a clear understanding of how to integrate SSF and CAEP into identity infrastructures and move toward a continuous, dynamic Zero Trust model.
Watch the video
In logistics, many drivers may only drive for us once. Maintaining personal profiles for this population is unreasonable, even unrealistic. Together with the business, we challenged standard IAM assumptions to gain visibility of thousands of shipments in our digital ecosystem.
This session walks through how we got there, the architecture behind it, and why this pattern might apply far beyond logistics.