Early-bird Discount
expires in
Register Now

Agenda

Zero Trust Identity & Continuous Verification

Zero Trust Identity & Continuous Verification

Combined Session
Thursday, May 21, 2026 15:35—16:35
Location: B 07-08

PANEL: Zero Trust - A decade In
15:35—15:55

Watch the video

 

Zero Trust has evolved from a provocative architectural concept into a foundational strategy guiding enterprise security programs worldwide. Built on the principle of "never trust, always verify," the model assumes that no user, device, or workload should be granted implicit access based on network location alone, and that every request must be continuously authenticated, authorized, and validated against contextual signals. This panel brings together analysts and architects who have spent the last ten years looking at Zero Trust across different environments, ranging from regulated financial institutions to global manufacturing and public sector organizations. Panelists will share candid reflections on what initially drew organizations to Zero Trust, how their understanding of the model has matured over successive iterations, and where the gap between vendor marketing and operational reality has been widest.

The conversation will include the recurring challenges customers have faced along the way, such as IAM modernization, fragmented telemetry across cloud and on-premises estates, legacy applications that resist modern policy enforcement, segmentation strategies that stall at the network layer, and the organizational change required to align security, identity, and infrastructure teams around a shared model. Panelists will also discuss the practical solutions that have proven durable, such as identity-centric policy engines, phishing-resistant authentication, microsegmentation grounded in workload identity, continuous access evaluation, and the growing role of unified policy frameworks that bridge human, machine, and increasingly agentic identities. The session is intended as a retrospective rather than a forward-looking roadmap, offering a clearer picture of what a mature Zero Trust program looks like in practice and what still remains unresolved.

 

Katryna Dow
CEO & Founder
Meeco
Katryna Dow is the founder and CEO of Meeco; a personal data platform that enables people to securely exchange data via the API-of-Me with the people and organisations they trust ...
Allan Foster
Chief Evangelist
Identity Evangelist
Allan Foster helped build ForgeRock into a multinational identity software vendor culminating with its listing on the NYSE in Sept 2021. Allan’s deep technical knowledge was well used in all...
Sebastian Rohr
Member
IDPro
While Sebastian has been known as author of multiple articles, reviews and essays on all kinds of Identity and Security topics, he has more recently made a name for himself as being the...
John Tolbert
Director Cybersecurity Research
KuppingerCole Analysts
John Tolbert is Director Cybersecurity Research of KuppingerCole, Inc (US). As Lead Analyst, John covers a number of different research areas, outlined below. John also advises cybersecurity and...
Rethinking Accounts for a Continuous Age [Advanced]
15:55—16:15

Watch the video

 

Continuous, or 'event-driven', identity offers a wealth of benefits.  With the shared signals framework we can finally enable single log-out; facilitate zero standing privilege; improve fraud detection and resilience; better integrate with digital identity credentials; and optimise the user experience.  And the pace and responsiveness of a continuous architecture is crucial in responding to the needs of non-human and agentic identity.

To maximise the potential of continuous identity, however, we need to rethink some fundamentals, starting with the very concept of an 'account'.  In a continuous world, user accounts can - and arguably *should* - be ephemeral.  Adopting ephemeral accounts can significantly improve security, compliance, privacy and user experience. It's a big change, but now is the time to consider it.

Join Andrew for this thought-provoking exploration of the potential of dynamic, ephemeral accounts: re-imagining our fundamental identity architecture to meet the demands of a new internet.

Andrew Hindle
Founder & CEO
Hindle Consulting
Andrew is an independent consultant focusing on digital identity, privacy, cyber security, and corporate governance. He is the Identiverse Conference Chair, serves as a non-executive member of the...
Identity is Not Enough: Enforcing "Proven Intent" via Session Isolation and Context-Aware AI [Advanced]
16:15—16:35

Watch the video

 

The cybersecurity industry spends billions on Identity Threat Detection (ITDR) and PAM, yet we cannot stop a compromised administrator or a coerced insider from executing malicious actions once they have valid access. The failure is architectural: we verify who the user is, but once they log in, they have direct technical access to the target system, leaving us blind to their intent until it’s too late.


This session introduces Pre-Execution Governance, a new architectural standard that bridges the gap between Just-in-Time (JIT) Access and real-time execution. We will demonstrate how to fundamentally decouple the user from the application by terminating their session in a remote, isolated browser. The user interacts only with a visual stream - effectively preventing any malware or exploit from physically reaching the target infrastructure.


We will then show how this isolation layer enables deep, real-time oversight:
- Contextual Matching: Using deterministic AI to compare live user actions (clicks, queries) against the specific "Reason for Access" declared in their JIT request - blocking valid credentials from performing invalid tasks (e.g., a "Restart Service" ticket cannot execute a database dump).
- Dynamic Peer Verification: Moving beyond static rules, the system automatically triggers the 4-Eyes Principle (via mobile push) only when the live action contradicts the approved JIT context.
- Exploit Immunity: How separating the user interface from code execution renders application vulnerabilities irrelevant.

Ivan Klimek
CEO & Founder
Excalibur
Ivan Klimek is the CEO and founder of Excalibur, a Slovak Cybersecurity vendor democratising Privileged Access Management (PAM). Under his hands-on leadership Excalibur was able to win &...
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.