Great to be here. We've heard so many interesting presentations today. We've seen some James Bond theme. We've just heard wars of AI versus AI. And I will provide you with a bit of a backdrop to it. A bit of the history of identity access management and the future of it.
So, if you're wondering why there are two people on the slide and only one person on stage, unfortunately, my colleague, Max, had to call in sick today. So, I'm gonna be winging his slides.
So, please stay with me if some of them might take a little longer. So, with that, let's dive right into it. Identity access management has been with us as a species since the dawn of time. It has been, and it still is, a survival mechanism. Who belongs to the tribe and who doesn't? Who is enemy and who is friend? Most of the times, it worked.
Otherwise, we wouldn't be here. But history told us, not always.
However, identity access management always served the same purpose. That the right individuals access the right resources at the right time for the right reasons.
So, we still do that, as we've always done, by authentication. Who are you? By authorization, what are you allowed to do? And we govern the identities through policies, processes, controls, and technology.
And, of course, we manage our privileged permissions tightly. However, today, identity access management is more important than ever.
We, and so we've learned in the previous presentation as well, have to protect our species. We have to protect it from the machines. I see I'm a bit tough on the jokes here today. We'll get warmed up to that.
All right, but seriously, I mean, we see cyber threats on the rise. And not only if you're in the same profession as me, but everyone sees it. More phishing emails, and so on and so forth.
Also, we see increased adoption of cloud and hybrid environments. On top of that comes more and more regulatory pressure. Especially in banking, at least so I feel, it's becoming more and more. And I could tell you a story about it or two, but that's for another time.
So, but where does identity access management begin? Where does it, where do its origins lay? When did we evolve from just sniffing each other to identify friend or enemy, to something like Okta, for example?
Well, identity access management was already needed in the Middle Ages. To see who can come into my castle and who can't. Or at least one way or the other.
So, some of the very first ways of identity access management were soldiers, where apparently some rather foul-mouthed French guards were protecting the castle, for those of you who know Monty Python. And I wonder if that could still be applied today.
Well, sometimes in customer service, I feel it definitely does. But if we look into the technology age, the first origins of identity access management started in 1961 at the MIT. They actually came up with a project at the MIT that was called CTSS, the Compatible Time Sharing System. And the CTSS allowed multiple users to use a single computer and its computing power at separate time slots, so to speak. It kind of reminds me of when I had my first, or when our family had the first computer and I had to share it with my sister and my parents.
To ensure that users keep their files and processes private in the CTSS, each user account was protected by a password. The implementation back then was rather simple because all of these passwords were written in a plain text file, and you guessed it, this file was also called passwords. Passwords dot D-I-R, to be precise. So it came as it had to. A couple of years later, we saw the first vulnerability disclosure, so to speak, right? When an engineer made a joke and printed out this plain text file. Which again shows that the best people in security are those that do it for fun, right?
Because they're bored, because they just want to test the system. Does it work the way it works? Just blow a whistle into the phone and see if you can use it for free. Technology, of course, developed. It developed even further, and along came mainframes and the need for local user directories. This time with encrypted passwords. A little further down the road, in 1999, Microsoft, or people at Microsoft, and we all know who you are, David Thompson and team, built Active Directory, the Active Directory, AD, to adopt the principles from the novel directory service.
It was built in LDAP, Kerberos, and DNS, and it was supposed to be the identity solution for Windows 2000 release and the enterprise networking for the next decade. Well, we all know how this story went on.
Yeah, it didn't work out that well. So still to this day, 90% of the enterprises rely on Active Directory, which is being exploited for malicious purposes left and right. So what to do? Fast forward.
In 2010, the cloud revolution started. It was more of an explosion, and it went from, well, from this to this, yeah, and it only took about 10 years. And all of a sudden, everyone and everything, and I mean everything, was in the cloud. Apps moved outside, users went remote, and identity became the new firewall. Let me say that again. Identity became the new firewall. Identity as a service providers emerged, services like Okta and MS Entry ID and others, and MFA became non-negotiable. If you're still relying on a single password nowadays, even back then, you're just not secure.
With employees working from everywhere and working in a very young company, I can tell you what that means, working from home, from the train, from the coffee shop, from the beach, from everywhere, the location becomes a secondary factor. So it doesn't matter anymore where the people are, it matters who they are and what they are doing and whether that makes sense. So never trust, always verify became the new standard. Which brings us to how does identity access management look today?
So in today's world, when we look at identity access management, it is not enough to just look at authorization and authentication concepts. We have to keep in mind the different environments like cloud, multi-cloud, on-prem, and the shared responsibility models of cloud and its providers. So at a conference in 2025, apparently you can not make a presentation without mentioning AI. So this is us mentioning AI here.
So yes, AI and machine learning are huge drivers for IAM today with just-in-time access and adaptive authentication models. From a regulatory and a compliance side, and this is where I kind of specialize in, we have to keep topics like GDPR, the upcoming CIA, current regulations like DORA and NIST too in mind. But we're also being guided by best practice frameworks like NIST that guides us in digital identity. To put it simply, if you're working on a new security strategy or just want to upgrade your posture, IAM should be at the core of what you're doing.
You have to keep it in mind at all times. After all, it's one of the main three pillars of each security initiative, right? You have the identity, you have the assets, and you have the data.
So, let me take you on a little journey to what the future of identity access management might look like. Let's look into the crystal ball and see what's in stock for us. So the future of identity access management will give rise to decentralized and password-less identity. In the future, identity access management will be a new paradigm for identity access management. It will be organized around the individual, around the single user. That means goodbye giant server deciding who is worthy of gaining access, and welcome digital identity.
It's going to be more like the user identifying themselves, right? Think about when you travel and you enter a new country, yeah, you present your passport at the port of origin. That's how it's gonna look like.
Of course, passwords will be replaced by passkeys, and I mean, thank God for that, because who wanted to remember their 16-digit passwords anyway? On top of that, identity access management will get smart.
Now, finally, he's talking about AI, you think, but I still leave that to others at this conference. So, while identity access management was a bouncer in 2010, solely checking access, it will evolve into a behavioral analyst in the future, a behavioral analyst with security skills.
So, in the near future, IAM will no longer be a tool. It will be more like a nervous system. Modern systems can sense risk. They adjust trust in real time, and they orchestrate the entire identity flow throughout your ecosystem. It's not about logging in anymore. It's about knowing, adapting, and then acting. Which brings me to the conclusion.
So, let me wrap up what I told you today in four main takeaways. The zero-trust principle, never trust, always verify. We had it on the slide, is here to stay. It will only become more and more important with the increasing complexity of today's identity world. To support this, AI-based solutions will drive the zero-trust principle by accelerating the speed of which zero-trust-based decisions will be made for authentication and authorization. Humans should no longer be needed in the future access model. Only maybe for high-privileged access.
Thanks to cloud and the increasing decentralization of infrastructure, also identity access management will become more decentralized. No more crown jewels, on-prem active directories, but a decentralized network of IAM systems, each communicating with each other and managing their turf will be the future. And all of that without ever having to worry about passwords anymore, right?
Passkeys, MFA, biometrics, FIDO2 will drive the password into its well-deserved place in hell. And whenever I still receive those emails, I should update my password every 90 days, then they can go right there as well. From a finance perspective, we can tell you the compliance with regulations will depend more and more on your identity access management. We see it in DORA, we see it in NIST 2 and other regulations, that there's increasing focus on a well-working, up-to-standard identity access management system.
And with that come full audit log capabilities, meaning everything must be fully transparent and documented. So to end this keynote on a high note is it deserves a well-working and future-proof IAM setup is and will always be your key business enabler. New projects with new tech coming up, identity access management has you covered. Additional business locations in new countries with different locations, and that's a future scenario, right? No worries, IAM is flexible, fast and efficient in managing local needs and in line with your framework.
So if you think you can, so if you think about how can security support the business, always have a well-functioning and future-proof identity access management and an IAM setup in place. I think I've said identity access management a hundred times now. So and with that, I would like to thank you. We're happy to connect here at the conference or via LinkedIn. Me and my partner Max couldn't make it today, unfortunately. And I hope to speak to some of you about the topics that I just mentioned. Thank you. Some excellent points, I'm so glad you made it here today.
Thank you so much for soldiering through that presentation on your own. Thank you.
But yeah, it was really valuable content. I hope that you guys enjoyed it as much as I did. One thing I wanted to ask you was what identity-centric signals are most effective in dynamically adjusting access in a zero-trust architecture? I wouldn't know. Okay. I just wondered whether you had a top of mind. We have another question from the audience is, what about the future of PAM systems? Is it not easy, it's not so easy or even desirable to give up on account repositories in this area?
Yeah, I mean, PAM has always been an interesting topic and always been very challenging for everyone, right? So I think the main principle still remain, right? We need to tighten the security there and always keep an eye on them.
Well, the way you do it is basically based on your preference. Okay, well, please give it up for Jillian Szpartko. Thank you. Thank you. Thank you. Thank you. Thank you.