Zero Trust Identity & Continuous Verification
Combined Session
Thursday, May 21, 2026 15:35—16:35
Location: B 07-08
Thursday, May 21, 2026 15:35—16:35
Location: B 07-08
Watch the video
Zero Trust has evolved from a provocative architectural concept into a foundational strategy guiding enterprise security programs worldwide. Built on the principle of "never trust, always verify," the model assumes that no user, device, or workload should be granted implicit access based on network location alone, and that every request must be continuously authenticated, authorized, and validated against contextual signals. This panel brings together analysts and architects who have spent the last ten years looking at Zero Trust across different environments, ranging from regulated financial institutions to global manufacturing and public sector organizations. Panelists will share candid reflections on what initially drew organizations to Zero Trust, how their understanding of the model has matured over successive iterations, and where the gap between vendor marketing and operational reality has been widest.
The conversation will include the recurring challenges customers have faced along the way, such as IAM modernization, fragmented telemetry across cloud and on-premises estates, legacy applications that resist modern policy enforcement, segmentation strategies that stall at the network layer, and the organizational change required to align security, identity, and infrastructure teams around a shared model. Panelists will also discuss the practical solutions that have proven durable, such as identity-centric policy engines, phishing-resistant authentication, microsegmentation grounded in workload identity, continuous access evaluation, and the growing role of unified policy frameworks that bridge human, machine, and increasingly agentic identities. The session is intended as a retrospective rather than a forward-looking roadmap, offering a clearer picture of what a mature Zero Trust program looks like in practice and what still remains unresolved.
Watch the video
Continuous, or 'event-driven', identity offers a wealth of benefits. With the shared signals framework we can finally enable single log-out; facilitate zero standing privilege; improve fraud detection and resilience; better integrate with digital identity credentials; and optimise the user experience. And the pace and responsiveness of a continuous architecture is crucial in responding to the needs of non-human and agentic identity.
To maximise the potential of continuous identity, however, we need to rethink some fundamentals, starting with the very concept of an 'account'. In a continuous world, user accounts can - and arguably *should* - be ephemeral. Adopting ephemeral accounts can significantly improve security, compliance, privacy and user experience. It's a big change, but now is the time to consider it.
Join Andrew for this thought-provoking exploration of the potential of dynamic, ephemeral accounts: re-imagining our fundamental identity architecture to meet the demands of a new internet.
Watch the video
The cybersecurity industry spends billions on Identity Threat Detection (ITDR) and PAM, yet we cannot stop a compromised administrator or a coerced insider from executing malicious actions once they have valid access. The failure is architectural: we verify who the user is, but once they log in, they have direct technical access to the target system, leaving us blind to their intent until it’s too late.
This session introduces Pre-Execution Governance, a new architectural standard that bridges the gap between Just-in-Time (JIT) Access and real-time execution. We will demonstrate how to fundamentally decouple the user from the application by terminating their session in a remote, isolated browser. The user interacts only with a visual stream - effectively preventing any malware or exploit from physically reaching the target infrastructure.
We will then show how this isolation layer enables deep, real-time oversight:
- Contextual Matching: Using deterministic AI to compare live user actions (clicks, queries) against the specific "Reason for Access" declared in their JIT request - blocking valid credentials from performing invalid tasks (e.g., a "Restart Service" ticket cannot execute a database dump).
- Dynamic Peer Verification: Moving beyond static rules, the system automatically triggers the 4-Eyes Principle (via mobile push) only when the live action contradicts the approved JIT context.
- Exploit Immunity: How separating the user interface from code execution renders application vulnerabilities irrelevant.