Identity Threat Detection & Response (ITDR) III
Combined Session
Friday, May 22, 2026 11:35—12:35
Location: A 05-06
Log in to download presentations
Friday, May 22, 2026 11:35—12:35
Location: A 05-06
Watch the video
Most privileged accounts live outside PAM, leaving attackers a clear path to privilege escalation. Despite widespread adoption of Privileged Access Management (PAM), the hard truth remains: most privileged identities still operate outside its reach. Traditional PAM solutions protect only a fraction of the attack surface, leaving Tiers 1 and 2—servers, applications, and workstations—largely exposed. The result is a sprawling, fragmented ecosystem of privileged accounts, endless secondary logins, and unmonitored access paths ripe for exploitation. The problem is intensifying: non-human identities (NHIs)—from service accounts and APIs to AI agents—most with privileged access, already outnumber human users.
This session exposes the hidden blind spots in today’s NHI & privileged access strategies and the operational realities behind “just-in-time” (JIT) access promises. Drawing on frontline lessons from leading Tesco’s IAM strategy and now advising global enterprises as Silverfort’s Chief Identity Security Advisor, Rob Ainscough shows will explore why only 10% of organizations fully complete their PAM projects and how complexity—not technology—is the primary barrier to success.
Attendees will learn how to extend protection beyond PAM, delivering continuous visibility and control across system tier and every identity type—including NHIs and AI Agents. In this session, Rob will share how to shift identity security from a reactive “firefighting” model to proactive “field control.” He will outline practical strategies, including:
- Recognizing when privileged access strategies are leaving the broader environment exposed.
- Building a unified identity defense that spans on-prem, cloud, and hybrid systems.
- Extending protection to non-human identities (service accounts, APIs, AI agents) before attackers do.
- Building the business case for executives who are blind to this hidden threat
- Communicating identity risks and wins effectively to executives to drive investment
The outcome is holistic, cost-effective coverage that eliminates standing privileges, contains lateral movement, and simplifies compliance with frameworks like NIST, PCI DSS, and NY DFS.
Join Rob to see how modern identity-tiered protection can turn privileged access chaos into control—and why every uncovered admin account remains an open door attackers won’t hesitate to exploit.
Watch the video
In the Harry Potter series, the Marauder’s Map reveals the whereabouts and true identities of everyone within Hogwarts, making it an invaluable tool for spotting intruders or identifying those with ill intentions.
Similarly, in cybersecurity, detecting signs of identity compromise within your network or infrastructure is critical to protecting your organization from breaches. This talk draws inspiration from the magical world of Harry Potter to explore how cybersecurity professionals can uncover hidden threats and signs of identity compromise. Just as the Marauder’s Map reveals individuals who shouldn’t be there, we’ll examine how to detect unusual behaviors, unauthorized access attempts, and subtle indicators that something is amiss.
Watch the video
Attackers increasingly bypass traditional security controls by exploiting legitimate identities, credentials, and authentication flows. From token replay and MFA fatigue to privilege escalation through trusted access paths, identity-based attacks are becoming the dominant path to compromise.
This panel explores how organizations can detect and respond to identity threats earlier by moving beyond traditional IAM controls toward a true ITDR capability. The discussion will examine how identity signals from authentication systems, endpoints, cloud platforms, and security monitoring tools can be combined to reveal subtle indicators of compromise that often go unnoticed.
Panelists will discuss practical approaches to identifying suspicious identity behavior, integrating identity telemetry into SOC workflows, and building detection capabilities across hybrid environments. The conversation will also explore real-world attack techniques and how organizations can move from identity visibility toward proactive identity defense.
Attendees will gain insight into how ITDR complements IAM, Zero Trust, and security operations and how organizations can start operationalizing identity-based threat detection today.