Enterprise IAM Modernization: Cloud, Federation & Integration
Combined Session
Friday, May 22, 2026 10:30—11:30
Location: B 07-08
Log in to download presentations
Friday, May 22, 2026 10:30—11:30
Location: B 07-08
Watch the video
Identity & Access Management has stepped into the spotlight, now entering the center of modern cybersecurity. With identity being one of the organization’s most valuable and most targeted assets, IAM has evolved into a foundational pillar of enterprise protection and the organization’s overall security posture. No longer confined to IT operations, IAM has become a strategic enabler, providing compliance, business enablement, and security.
Yet in many enterprises, IAM still operates on one side while Cybersecurity sits on the other. The result is an ambiguous, sometimes strained relationship between two disciplines that ultimately pursue the same goal.
In this talk, Charlene (Senior Advisor at KuppingerCole) and Lisa (IAM Competence Owner at Fressnapf/Maxizoo) explore that identities have become a dominant attack vector and a decisive point of failure in today’s cyber kill chain. We examine how proactive IAM controls and reactive security controls are meant to complement one another, and why this might break down in practice.
We highlight organizational blind spots, silos, and ownership gaps that hinder collaboration more than any technical challenge ever could. Finally, we provide concrete ideas on how IAM and Security can form a long-lasting, productive, and meaningful alliance: through shared strategy, shared metrics, and a shared understanding that identity is the new enterprise perimeter.
Watch the video
Zero Trust is often described as a target architecture, but in large enterprises it must be realized through concrete steps that deliver security improvements today while enabling future trust models. At BASF, identity is used as the central control plane to drive this transformation.
In this session, Cyber Security Enterprise Architect Keno Torfs shares BASF’s journey from a traditional, binary IAM model toward a risk‑based Identity and Access Management (IAM) architecture built on Microsoft Entra ID. By introducing Authentication Assurance Levels (AAL) and linking application risk to enforceable authentication strength, BASF established a pragmatic foundation where security scales with risk while usability is preserved for low‑risk access.
Building on this foundation, the presentation looks beyond authentication to the next stages of BASF’s Risk based IAM roadmap. It explores how passwordless authentication, identity assurance, and emerging concepts such as decentralized identities and verifiable credentials can further reduce implicit trust, simplify access decisions, and enable new trust relationships across enterprise and ecosystem boundaries.
Attendees will gain insight into how a global industrial enterprise turns Zero Trust from theory into an evolving, scalable identity platform, connecting delivered results with a clear vision for what comes next.
Watch the video
Most organizations describe an Identity Fabric as an architectural ambition: connect the right platforms, integrate the right services, and enable the business. Then reality hits: responsibilities are split across IAM, Security, IT operations, HR, application teams, and external providers. Controls become ambiguous, work gets duplicated, and decisions slow down.
Instead of looking at tools, we are looking at the organization: This talk introduces a holistic IAM Target Operating Model that treats the Identity Fabric as one coherent system of capabilities, responsibilities, and operational services. It adds a third lens that is usually missing: the people & organization lens. Beyond “who owns what,” we make visible which skill profiles are required, how they translate into roles, and how that becomes a pragmatic view on candidates, sourcing options, and headcount planning.
You will learn how to build a multi view TOM of the Identity Fabric:
- task view across different dimensions,
- shared responsibility view across internal and external parties, and
- role and skill view that allows staffing the model with real people.
The result is an operating model that is actionable for leadership, usable for audit and provider management, and concrete enough to guide hiring and team design - no matter which size the company has.