Yeah, so good afternoon and let us start the engines, right? So, I assume everybody will agree that Formula One is an amazing sport and it's a kind of ultimate fusion of elite driver skills, innovation, data, statistics, but also speed. If we look at the different stages during a Formula One weekend, there are some of them.
So, let's start with the qualifying, where the teams need to collect and get a lot of data to do the right things at the right time and be ahead of the others to reach the pole position. At the start, everything needs to run fast, smooth and secure. And last but not least, during the race, it's all about continuous monitoring to do the right things at the right time, like a pit stop or a strategy change.
And for sure, the teams want to become better, win trophies, championships, and instead of having a limited view in their small side mirrors, they want to reach the next level and have a clear view in front of them. So, McLaren and Mercedes-Benz moved this year to the next level with a partnership with Okta.
And today, I would like to take you to the next level. So, let's talk about end-to-end unified identity security with Okta. My name is Arkady Skowczynski. I'm a Principal Product Acceleration Specialist at Okta. Safe harbour, so they are not getting in trouble. Safe harbour too. Okta is the world's largest independent and vendor-neutral identity company, and our mission is just to free everyone to safely use any technology. Identity is security and has become the new parameter. Gone are these days where a kind of secure firewall was enough to keep the bad guys out, right?
In today's evolving threat landscape, identity is really the key to the kingdom. And these stats here paint a sobering picture.
So, more than 80% of all data breaches come from identity attacks. In 2023, nearly 1.9 billion session cookies were stolen from the top fortune customers. Stealing a session cookie, literally moving through networks with an alarming ease. It takes around 290 days to really detect someone was breached, and we see a more than 180% increase of attacks today than a year ago. In addition to this, we have a kind of identity sprawl.
So, the cloud explosion, the fragmentation of different technology stacks makes it very, very hard to control everything on top of the complexity. And we need to shift our thinking, and we need to have answers and solutions for this. The good thing is we at Okta have to write answers and solutions for the different stages for the security. Before authentication, to have a kind of privileged, least privileged access. During authentication, to secure authenticate. But also after the authentication, to standardize the threat and response mechanism.
So, our Okta platform is really the foundation of a truly comprehensive approach to identity security. Because first, we have an end-to-end protection, from the left to the right, before, during and after authentication. We are capable of doing the secure identity orchestration, and we have an amazing and seamless integration as number three.
So, all of this is running on top of an enterprise-grade platform, with 99.99% uptime, no downtime, and billions of logins every month. So, each of our products is excellent in itself, but together, they are really spectacular.
So, let's dig a little bit deeper into the first stage. So, before authentication, with our qualifying, and start here with identity security posture management.
So, with our ISPM tool, we are able to detect identity risk across your complete tech stack, give our end-users and administrators a kind of end-to-end visibility dashboard, and a day-one task remediation. So, think about a day-one task remediation dashboard, our qualifying.
And, as we can't protect what we can't see, we are also taking care of your non-human identities. So, all the service accounts, API tokens, secrets, machine-to-machine, all this is possible within our ISPM solution and before the authentication. By combining this ISPM solution with our privileged access management tool, we are able to mitigate risk, means that we are able to add the service accounts in our centralized catalog, give permissions and change ownerships, and have a one-stop shop visibility for our admins to really secure our service accounts.
Last but not least, it's all about centralized management and determining least privileged access controls with an IGA solution. So, we want to automate and customize our join-and-move-a-lever scenario in a low-code or even no-code environment. Give the people the right permissions, they need to continue working on day one, day zero, etc.
Okay, as seeing is believing, I want to just quickly introduce and showcase you our latest flagship identity security posture management, how the tool is looking like. Okay, this is the ISPM dashboard, we are capable of syncing and getting a lot of data, doing the time range, so we have a lot of dashboards, MFA, top trends and risk, you see admins accounts, admin user accounts, we are capable of zooming in, identifying high-risk accounts with a lot of details, which permissions are assigned, based on which attributes, which admin accounts are unused and which admin accounts are at risk.
So, we have all of our active accounts, we have a login MFA dashboard, and as mentioned, we are also taking care of our non-human service accounts that are all customized and controlled by ISPM. In the issues tab, one-stop shop of all the issues, no MFA for global admin accounts, so maximum visibility, so we are able to be proactive, to be in a pole position, and to fulfill all the controls like NIST, SOCKS2, etc.
So, this was quite awesome, so we made it during the qualifying, and now we are ready to go. So, this was quite awesome, so we made it during the qualifying, we are in the pole position, so now let's continue with the start, securing authentication with solutions and products like Okta Device Access and Okta Fastpass.
So, we are capable of securing the first vulnerable touchpoint, the device login, with a phishing-resistant authenticator. On top of this, once the user is successfully authenticated strong, we are capable of upcoming tools like device-bound single sign-on, by securing a token on the device and leveraging this one to achieve a kind of seamless and secure user experience while accessing the applications or the Okta dashboard, because everyone will agree that basic MFA is not good enough anymore, and we need a phishing-resistant multi-factor authentication nowadays.
Demo two, the power of Okta Device Access and Okta Fastpass. So, we will authenticate strong with a phishing-resistant solution and to leverage device-bound single sign-on to have an amazing and seamless user experience.
So, this user will log in with his password and a strong factor with a FIDO2 token on the device. We are providing several factors. We will pick a FIDO key, type in the PIN, put the finger on the FIDO key, and I'm logged in.
Now, with features like device-bound SSO, we are leveraging the secure token and have a seamless, secure access to the Okta dashboard across different browsers, to different applications, and also to the admin dashboard. So, a really secure, smooth, and cool user experience.
So, we made it through our first corner. We are leading the race, but it's going to be a long run, and we need to continue doing, as mentioned, the right things at the right time. With solutions like Identity Threat Protection with Okta AI.
So, with our solution we've implemented, we have a solution that's laser-focused on securing identities in real-time, not only at log-in, but throughout the entire session. So, it's all about continuous monitoring and detecting and responding. A little bit more in detail, how things are coming together with ITP, from the left to the right.
Step one, it's all about ingesting the signals. When a user is interacting to applications with Okta, we are collecting the different signals and detections with our own Okta Verify solution. In addition to this, we have the capability of the power of the shared signals framework within the OpenID Foundation, where we are actively participating in, and we are getting additional signals from security vendors like CrowdStrike, Jump, Zscaler, Cloudflare, and many, many more.
Then, we are converting these signals into context and leveraging our big policy framework to evaluate the context against our different applications and global authentication policies, and then are able to do the pre-orchestrated actions like universal lockout to terminate active sessions across all devices altogether for different cloud applications, or prompting the user for an additional MFA, or sending a notification to the SOC team and starting workflows to cutting permissions and putting the users into quarantine groups.
For all of this, we have a nice observability with reports, dashboards, et cetera, and we are capable of giving feedback in our pipelines so that the GenAI models are growing. The last demo, and to sum this up with our identity fabric, is Identity Threat Protection with Okta AI, where we are getting live signals from a security vendor, Jump, and once a signal or risk is detected, we will terminate all the different sessions across all the devices together and secure our identities in real time.
So, on the left side of the house, we have our Okta dashboard with all the applications, and we have a device enrolled into Jump Security Cloud. Devices are green, all good.
Now, as users are sometimes doing multitasking or getting phishing mails, I'm simulating here a malware link, clicking on this chiclet and getting this message. Jump immediately detects the signals, sending these high-risk signals via the Shared Signals Framework to Okta, and we are cutting the permissions and terminating the sessions across all devices for the Okta dashboard, for the cloud applications, but also on our device for our Apple ID that was federated with Okta as the identity provider.
So, one thing remains for sure. To get security right, we really have to get identity right to achieve our start-finish win. And to reach the next level of your security journey, Okta is the only identity security platform you will ever need.
So, feel free to follow me and reach out to us, visit us at our booth, and thank you for your time. Okay, questions anyone? Thanks for your presentation. Just a quick question on the various feature and modules of the product presented. Just to have an indication whether all of this is actually readily available out there. Okay.
And then, towards the end, you talked about observability and getting all the signals from various different feeds or various different other systems. I assume that you'd need a certain level of integration with all these elements to have the demo presented working, correct?
Yeah, so the demo was based on an integration with a security provider like Jamf. But as mentioned, we are capable of ingesting our own signals with our Okta Verify agents.
So, when there's a session context or device session context change, we are capable of detecting movements through different networks. When a device state is changing, but this demo is specific with the Jamf, so getting low, medium, or high risk signals, for sure we need to have an integration with security vendors like here Jamf, CrowdStrike, Zscaler, and you need to have the solution on the other side of the house for sure.
But as mentioned, we have a lot of so-called first-party detections or first-party signals that we can leverage and do it via our continuous evaluation protocol and do the magic stuff like universal lockout or pre-orchestrated workflows. Right, and very last follow-up question. All these actions that follow like the exceeding of a threshold or like bridging the policy are pre-configured or are these stuff that you can actually configure yourself as an end user?
Yeah, good question. So you can configure the powerful actions based on your use case, so there's no need to do every time a kind of universal lockout, kicking the user out. You can design your own no-code or low-code pre-orchestrated workflow and maybe just send out a notification because there was a minor change. So we have powerful authentication policies, but also entity risk policy where you can granularly define how do you want to react when a certain threat was detected.
Okay, if you don't have any further questions from the audience, thank you very much, Arkadiusz. Thank you.