So yeah, really a pleasure to be here. We are a CIM provider in Switzerland. And of course, as a CIM provider, you primarily deal with external identities. And our hypothesis is really the next breach will most probably come not from the internal world, but from the external side. And this is a pure numbers game.
I mean, if we look at the ratio, normally, if I also look in the population of identities with our customers, normally in taking any insurance, any bank, for one employee, you have typically 100 plus external identities. External identities, of course, customers, B2B partners, or also then AI agents.
However, if you look at the budgets, often they are kind of inversed. So it is very much focused still on internal topics.
Of course, this is important. I mean, no question about that.
But still, I mean, it does not really reflect then also the scope of risk. But let's briefly look into the external identities. What kind of categories do we really have here? So first of all, B2C. So that's the classical CIM space. Customers logging into a banking portal, insurance portal, health portal, whatever you want.
Normally, the scale there is in the millions. Often overlooked are B2B partner portals. Very important in modern supply chains. And typically here, the scale is a bit lower, thousands to 100,000. The trust model here is then also contractually bound, often via federation. And you have some additional topics, like, for example, identity governments.
Also, how, for example, are permissions federated users then also removed from the system? So how are their permissions, which are normally much more invasive compared to a customer, really successfully removed? If you look at the regulation, I mean, you have some supply chain topics you have to cover here. So make sure that your supply chain always stays secure.
Then, of course, machine identities. We have also some customers which are in that field. And here you can have a scale from tens of millions. And here we are also fighting with some other challenges.
So, for example, having a huge series of devices using username, password for all the series of devices. 10,000 devices with the same credential combination. How do you find which one is broken or has been abused? The situation is a little bit involved. So more and more devices are supporting certificate-based authentication.
But still, I mean, this is a huge, massive potential attack surface as well. And now, of course, the fourth category, and this is still emerging, are AI agents. And this is one of the new challenges which we, I think, as an industry, have to deal with. So what are basically the attack patterns behind it? And let's also look here into some of the numbers which are publicly available. What still astonishes me in year 2026 is the Verizon Data Breacher Investigation Report.
Still, 80% of web-based attacks are based on stolen credentials. Although we have passkeys and all this cool technology, this is still the fact here.
No wonder, if you look at the ratio, 90% of the organizations have had at least some security breaches throughout the year. Basically, the Verizon Data Breach Investigation Report is only investigating real data breaches. So they investigated or analyzed more than 20,000 incidents. And with more than 12,000 real successful attacks. So these are really significant numbers here. And there's, of course, always a gray zone. It's illusory to think that all cases have been captured here.
The ratio, this 1 to 100 plus ratio, that's our own observation, if you speak to our customers. And now the agents, I mean, this is a completely new field. We don't know where this will lead you. But I will show you some concepts how we can also get this under control.
Now, how does such an attack of such an external-facing identity normally look like? And here, a typical approach is now that even if MFA is in place, I mean, attackers have shifted up in the stack. So the approach is to steal the cookies, to steal the tokens, to get access to a resource which they should not have access to. Classical approach is the adversary-in-the-middle attack. My marketing team teach me you should no longer say man-in-the-middle. So this is no longer politically contract. So formally known as man-in-the-middle attack.
So we all know, I mean, nowadays it's relatively easy to build a perfect-looking phishing website and tricking users on that site. What then happens, the request is perfectly forwarded to the real IDP. Real IDP validates the user, performs multi-factor authentication, and basically returns a cookie or an access token, whatever. The reverse proxy stores the cookie here, forwards the request to the user. There's no way for the victim to find out that something happened in between there. And basically then the victim's browser is accessing the app.
The IDP has done its job, so there's no failure on the IDP side. But the attacker, by replaying the cookie, basically has access to a resource where he should not have access to. You might say, hey, why is this still possible?
I mean, we have all the technologies and tools available. Yes, because they are not really deployed or broadly adopted.
I mean, it is improving. But still, I mean, for example, passkeys, they were introduced in 2018, 2019. So the UF standards or FIDO standards, it's still not widely deployed. Even if I talk to prospects or customers, we often have controversial discussions around that. But how would you mitigate that? So the first mitigation here is definitely passkeys.
I mean, FIDO 2 has been designed to be phishing resistant. So FIDO authentication would fail here.
But, of course, let's say Google Authenticator, TOTP-based authentication slips through here. Then here, and I think this is really something which should be addressed now.
Really, the session harvesting, that's the topic most organizations should focus on now. We have also, there are also some more advanced APT-level attacks out there.
Basically, attacking the IDP itself. So they are known as Colton-SAML, Silver-SAML attacks.
Here, basically, the IDP is attacked. And even the credentials are stolen here, or the private key is extracted from the IDP. Which is then a completely different level of an attack surface. This forged IDP is then really able to issue cryptographically correctly signed assertions to the victim. And so there were known attacks. So SolarWinds in 2020. Peach Sandstorm, that's an attacker network, most probably funded by the Iranian government. Which is really focusing on identity-level attacks. So they don't approach the infrastructure, it's really on identity level.
Combination of various attack patterns, starting with password spraying. And ending up then with extraction of signing keys here.
Anyway, I mean, it's not hopeless, as I will show in the next couple of slides. But one thing we should reflect, why do these traditional approaches that were deployed for the workforce, why do they fail when it comes to external identities? So for the workforce, I mean, you have a known finite user population. You know your user population. You have a corporate device, typically, you know what kind of devices you have out there. You have often also the network context. You have an admin-controlled onboarding process. You have tolerance for friction.
Hey, it's a job. Your employer tells you what to do. You have to follow the procedures there. Identities are provisioned by HR lifecycle. And sessions are, in most cases, at human speed. But with external identities, I mean, those concepts, they no longer work. So normally you have millions of customers onboarded by a variety of processes, often self-registered. And if the processes are too friction, too error-prone, or impose too much friction, you will lose customers. And they will go to the competition. So that's one of the challenges.
Then you have a consumer device, any kind of network which is being used. Self-registration at scale, also here. User experience is a key success factor because friction means lost revenue here in this case. Often also the identity outlives the customer. So customers may have churned, but you have still identities lying around, in particular also in the B2B case. And if the external identity or the user is using an AI agent on his behalf, I mean, you have to operate at machine speed. That's also completely different compared to the traditional workforce.
Now, yeah, so I think these are enough arguments to say, yeah, so, yeah, the workforce IMO is just designed for another purpose. And that's why it doesn't fit.
Now, how should we focus now or how should we approach this identity-driven attack? So when I started my career in IT, we were really mainly focusing on network breaches. And basically, yeah, you had to improve your firewall. You had to add stateful inspection and so on. And then you could keep the bad guys out. It was still focused on a perimeter.
Now, basically, the security of credentials is everything. And I will show you now then the concepts how the security of those credentials can be improved. Attackers are now focusing to steal the credentials after authentication because they are always following the easiest path. And so they don't try to break MFA. So it's much easier to steal the token or the cookie. And you don't have any perimeter to breach because you are operating on the application layer. The agent topic is really emerging. I think there we have still some challenges ahead. Probably I will talk more about that next year.
So, yeah, with perimeter security, I mean, conceptually, it's assumed the attacker is outside. But with identity-first security, you really have to assume the attacker has already stolen the token or the cookie. So how are we going to defend ourselves in such a scenario?
Now, let's look at how we can conceptually and architecturally approach this. Today, we have, in most cases, federated architecture. So we have an IDP and you have your integrated applications. User is redirected upon for success to the IDP. There you have MFA deployed. And basically the user is redirected back to the app and starts using the app. So whatever happens later on the IDP is kind of out of scope for the application. And that's obviously also something that the OpenID Connect Foundation has recognized and has now implemented.
The security events of SSF security signal framework, which enables IDPs to send security signals towards the integrated application. That's a key concept to implement continuous adaptive trust in a federated world.
I mean, otherwise, there's no direct connectivity. The standards, they work as a publisher subscribe model. So basically, the apps can subscribe to events. And then basically, yeah, they are notified and they can then act on those signals. There are two categories of signals. So they are the continuous adaption and evolution protocol is focusing on session events. And the risk model is then on top of this focusing on account-based security signals.
Like, for example, a stolen credential popping up in a data breach then. And so this is getting bidirectional. So the IDP is then no longer passive after the login.
Now, how do we integrate that? So the challenge here, I would say these standards, they are still emerging. So some IDPs have implemented it. But the big challenge is how do you enable your apps to deal with that? And this leads me to the picture in the middle. So one approach here is to do it via an identity proxy, which sits between the user and the app. So then basically, just the identity proxy has to implement these standards. And you don't have to touch the application.
Of course, in such a scenario, all the requests need to go through the identity proxy. So that he sees, for example, if a session cookie is seen twice from two different IPs. Or if something strange on the device fingerprint is happening during a session. So that's an integration scenario. If this is not possible for whatever reason, then it's good to work with at least very short session lifetimes. Very short token validity timelines to do regular token rotation. Or to implement TPOP. So that's the proof of possession of the key.
So here you have signed a search where you have an additional level of security that the originator of the token is in possession of a private key. That's basically a good fallback pattern if one of the other tools is not possible for whatever reason.
Now, what are the design principles behind that? So in this new world, identity is becoming the control plane. So you should focus really on the identity level to really ensure the security on that. Regardless of how the network location, network segregation is actually achieved. External identity should be treated as a first class citizen. It's a much wider attack surface and it should really be treated accordingly. And also in particular for external identities, also user experience always has to be kept in mind. Trust needs to be continuous, not just binary during the authentication.
So it has to be continuously evaluated. And then the intent, and this is now really already targeting the AI agent space. So that the intent must be verifiable. And so this architecture should also then contain mechanisms for transaction confirmation. Where you can basically have humans in the loop to confirm. And basically compliance is then just an outcome.
And not, let's say, a natural outcome when you apply those principles. So for quite some years we have told the customers.
Yeah, you have to choose either custom experience or cyber resilience. There's always a tension, but with the new technologies around pass keys, password authentication. I think this is no longer the truth. So here we can really fulfill both requirements on the same level.
Now, moving forward, how would you build such a thing? I have to accelerate a bit. I have still three minutes on that screen, sorry. I was looking on that.
Okay, I will accelerate a little bit. What are the architectural layers? One layer is the identity channel. Then basically you have to cope with all those channels in your architecture. Then you have the identity security layer. That's actually where the whole risk evaluation, everything is happening. But you basically have to cover those topics here. And the governance and the lifecycle is then basically the monitoring of your identity security layer. And as I said, the regulatory compliance is then kind of a natural outcome if you apply those principles to your architecture.
So I will go through this a little bit quicker then. So what should you apply then? So passwordless is no longer a UX feature. It is a key element to avoid the demonstrated man-in-the-middle attacks. And transaction confirmation is not just session authentication. It is an important element to then basically balance and also the new agent use cases. And identity continuities across device life cycles here are also the mechanism with passkey synchronization, for example, are in place and are giving us a good baseline.
Now, what is your key takeaway? And maybe I would like to give you three questions that you could take away.
Also, look at your own organization. And these are three key questions. What is the ratio of your external identities compared to the workforce? Do you even know it? And what is your security investment ratio then aligned with that? Can you detect a compromised external identity within minutes? Yes or no? And does your identity architecture have a defined position of how to deal with AI agent credential? Is it a blind spot? These are all interesting questions. And I would be very pleased if you would discuss this on our booth. It's number 10 out there.
So, yeah, looking forward to some more interesting discussions. Thank you very much.