The presentation delves into the concept of Identity Resilience, emphasizing its critical role in the modern digital economy. This term, while also relevant in psychology, here refers to the security of digital identities in business operations. The speaker narrates a significant incident involving Ticketmaster, whereby a failure to secure identity data led to a major breach, emphasizing the consequences of inadequate identity protection. In this case, the leak of 560 million records, including 30 million concert ticket barcodes, highlighted severe lapses in security practices. The speaker underscores that such incidents demonstrate the necessity of securing digital identities to avoid dire business consequences. Furthermore, cybersecurity threats are evolving, with a notable shift towards malware-free and identity-focused attacks, requiring more comprehensive identity management strategies. In discussing the role of data in today's economy, the speaker notes that safeguarding digital identities is paramount. They point to trends like the integration of cyber insurance with identity management practices and the increasing relevance of identity-related policies in industries such as healthcare. Highlighting a joint industry responsibility for identity protection, the presentation underscores the importance of trusted digital identities in fueling the modern economy. Finally, the speaker calls for a collaborative approach to enhance the resilience of identity systems, stressing that such measures are essential practices that should be integral to organizational security frameworks.
Hi, good morning, everybody. Thank you for joining me this morning here. We will talk about Identity Resilience, as you can see, and how it is becoming a key element, a cornerstone for really operating in today's digital economy and operating under business growth. A few words about myself as the speaker today. I've been in this industry for more than 25 years. I've been in this event for many years, and I love it. And it's good to be here among friends. I am currently President and Chief Revenue Officer of iC Consult. We're one of the sponsors.
The world's, I would say, biggest independent IAM services provider. We live and breathe and eat and drink identities. We're good at it. I'm also the co-founder of Leading Cyber Ladies, which is a non-profit, a global movement that promotes women and diversity in cybersecurity.
Yeah, and it's a great pleasure to be here today and talk about Identity Resilience. Okay.
And so, Identity Resilience. One thing we won't talk about today is that type of Identity Resilience. Apparently, Identity Resilience is also a term in psychology. It talks about how resilient is your sense of identity when you are dealing with big changes, big challenges in life. And this is not this type of a conference. So we will not talk about this type of Identity Resilience. We will talk about other stuff. For example, we will talk about that lady. Who do you think she looks like? The cat looks like... Does it look familiar? Any ideas? I couldn't use the real image.
So I had to use something that AI generated for me. Does it look like anyone? It's not Elon Musk, right? Exactly. We will talk about Taylor Swift today. We don't talk about psychological problems. We will talk about Taylor Swift and how she is relevant for identity and security. So this is a nice diagram that shows the growth of identity data breaches and some of the bigger identity data breaches that have taken place. And you can see two very evident things. First of all, there is a growth trajectory.
Along the years, there are more and more and more breaches that involve large amounts of identities. And then another thing that you see in this diagram very quickly is there is a green arrow up in the top and it's directing you to the Ticketmaster breach where 560 million records were leaked, were stolen. And let's talk about what happened there. And that's how we start talking about Taylor Swift, by the way, if you didn't realize that yet. So Ticketmaster, like many other organizations, use a cloud service that is operated by Snowflake, a market leader in that space.
And there was a leakage of identities coming out from Snowflake. Basically, the post-mortem analysis discovered that an unencrypted list of username and password was found on one of the company's computers and in Jira tickets. And no MFA was enabled. So then Shiny Hunters, which is a very famous cybercrime organization, they were able to get their hands on this list, hack into some of the companies that were hosted on Snowflake. Ticketmaster was one of them. And initially what they did, they then published a list for sale, 1.3 terabyte of data, 560 million records on sale.
They asked 500K back then for that list. What happened next is that they actually discovered that within that list, they also had some additional information that was actually valued more. They had 30 million barcodes for concerts, tickets, basically.
And 170,000 of them were the ERA's tour tickets. And Ticketmaster in that point in time was already in trouble because their systems were not resilient enough and really crashed a lot during the ordering process. If you remember when Taylor Swift announced she's going on concert, the internet collapsed, the world collapsed, it's that important. And so there was already a class action being organized against Ticketmaster because the website couldn't handle the requests. And now 170,000 tickets are out there, the barcodes are out there. And that meant trouble for them.
And that came also with a bigger request for a ransom, which was 2 million at that point in time. Their trouble and their problems didn't end there because what happened later, they also got another class action about this situation, this problem, this breach. And this was 5 million, the class action against them, because there were complaints about how Ticketmaster handled it. Apparently the breach took place in April, it was discovered in May. The regulatory disclosure of the breach happened in June, but the customers were informed only in July. So there was a lot of kind of...
There were complaints about how it was managed. And as a result, Ticketmaster is now dealing with a class action against them in the value of 5 million.
So, yeah, that's a case of identity breach goes wrong, and you can see how the money piles up in fines and how it becomes a business issue for a company like Ticketmaster. And one thing that comes very clear from those kind of stories is that identities are becoming a mission-critical item for companies. If we think about today's modern economy, how we do banking, how we do e-commerce, how we travel, digital identities enable that. And those digital identities must be trusted and they must be secured and protected. Without that, our modern economy will collapse.
It's that important, it's that core to how things operate today. You remember the graph I showed you earlier with the identity breach attacks? This is another view that says something very, very similar. So this is an interesting report that came from CrowdStrike, right? And CrowdStrike are really focused on devices and XDRs. And they're actually showing here a very clear dynamic in which malware-free attacks are on the growth, right? From some kind of a minority, now it's becoming the majority. And they're basically talking about identity-based attacks as a key element here.
And how there's a specific focus on social engineering in a way to bypass multi-factor authentication mechanisms. And I just love this quote here, hackers don't break in, they log in when it comes to an identity breach.
So, yes, we see a shift in the type of attacks that are taking place. And more and more are becoming malware-free, not malware-based, and identity-focused attacks. Now let's talk about Gen-AI and specifically the use case. We talked about social engineering, let's talk about spear-phishing now. Because spear-phishing are sophisticated, directed, focused attacks at specific individuals.
And there was this very interesting kind of experiment where human experts in social engineering and spear-phishing were put against Gen-AI capabilities and also mixed capabilities, Gen-AI and humans operating spear-phishing attacks. And as you can see, Gen-AI is doing damn well in spear-phishing attacks. And that's a concern, right? That's a concern because we can get good results on spear-phishing leveraging AI capabilities. It costs less and you can operate it at scale. So good results at scale with a lower cost, that's a very good business. The only negative part, it's illegal, right?
But if it was a legit business, yeah, that's good, you know? It doesn't cost you much, you get good results and you can operate at scale. So that was the part where I kind of get to scare you because we are in the cybersecurity business, there needs to be some scaring element here. Now let's talk about what's happening next and how our industry is changing, how things are shifting now. And this is always a good place to look at.
And if traditionally the IAM capabilities were more in the protect domain of NIST, with automation and IGA solutions, and then things are really more focused on that element, we now see a shift in how the industry, how the landscape is looking. And a very good example would be, open the door, step outside, look at the expo area, you will see all that variety of companies that are now covering multiple use cases.
And like, for example, posture management for identities, which is all about this continuous monitoring of how the identities of the organization are doing, are there any vulnerabilities in that space? Then we have the identity threat protection, which is really monitoring if something happened, do we have a breach and how do we act to a breach? And the all element of identity recovery, if something goes wrong, how do we recover? How do we assure that level of resiliency? Rolling rollbacks from backups and removing any kind of malicious configuration.
So we really see the whole kind of range of the NIST domains being now covered also with our industry, with identity industry, and so many companies are now kind of forming and are gaining success by covering the whole spectrum of controls that are needed. So that's really interesting. And we cannot ignore cyber insurance, right? If you need to get prepared for the day that something happens, cyber insurance is also a key element in that preparation and in being resilient. And also there we see a shift towards identity, an inclusion of identity elements in cyber security.
So for example, if we look at the qualification process and kind of checklists that cyber insurance companies will go through, we now see more and more identity related topics included. For example, privileged access and controls of administrator accounts, single sign-on and multifactor authentication, everything around hygiene of users and on-boarding and off-boarding. So that's becoming really like a holistic part, a standard part of cyber security policies and a way to qualify for them.
And then also I found this really nice statistic that talks about companies that are investing in policies that include identity coverage. And we really see that the vast majority have identity related incidents covered in their cyber security policies. And it's very clear that some of the industries that are very exposed to individuals, for example, healthcare, is kind of really leading the charts when it comes to that. And as like last final words, I want to talk about joint responsibility.
When it comes to being resilient and deploying controls and choosing the right solutions, there's always a lot of focus on the companies themselves, on our customers. But the responsibility is not just on the organizations that need to protect themselves, their employees or their consumers. I see that as a joint responsibility that we have as an industry. So even if we look at more traditional IGA vendors, vendors in our space, they need to have identity resilience in mind as they design solutions. It also needs to be in mind for policymakers and governments and auditors.
It's not just about the end organization that they need to deal with an attack. It's all of us as an industry, it's all of us as an economy. Because again, going back to one of the earlier statements, digital identities, trusted digital identities, they do fuel the modern economy. And so I will pause here because I did want to leave a few minutes for a Q&A.
Well, thank you very much. A round of applause for Hilda Merle, please.
And again, a quick reminder, if you have a question, please raise your hand and we will give you the microphone. Ladies and gentlemen, Mike Small. Thank you very much, Hilda, for that great talk.
Now, resilience is about being able to recover as well as being able to protect against. And it is certainly the case that increasingly the threat actors attack the identity stores. And if you're left without your identity systems, you're basically in a difficult situation. So what is your considerations? What are your thoughts about recovery? I think that, well, first of all, it is part of a very kind of, let's call it the best practice. I love how Nis positioned things because it makes it a clear part of an approach and a best practice. So recovery is a basic element.
It's a basic element in other things that we do in life, right? And there's no reason why it wouldn't be a basic element and the basic control that you want to deploy for identities. And the more we treat identities as a critical infrastructure, the crown jewel for the organisation that needs protection, then you put the whole holistic approach around it, which should include recovery. I haven't seen many recovery companies here, I have to say, although I know there are a few and there are more and more of them being formed. But maybe that's for your next year sponsorships.
Let's make sure that they get also a good representation here. Yes, thank you.
Well, it was interesting because if you followed the US news, you will have heard all the stories about Rubio and communication. And people talked about that as being, oh, well, it's all right, it's encrypted, but it's actually a failure of provisioning, a failure of control of identity. I think there are also some other failures around.
Yes, there are more. So that's an interesting thing that people don't think about when it comes to, shall we say, just communications issues. Yes. Thank you. Thank you. I always love your insights, Mike. Any further questions? Anything from our virtual audience, perhaps? And in the meantime, may I ask a question of my own, please? So is this just another endless chain of risks we have to worry about and invest? Or can it be turned into a more positive view on this whole problem? Can it be an enabler for anything new and nice and profitable?
I'll tell you how I see it, because it might not be the exact kind of answer to what you asked, but I think that we are, with everything that is happening around us and how digital businesses are constructed right now, we are in a pivotal moment where the risk landscape is changing. And with identities becoming such a key element in how we operate, how we live as individuals and how we operate. And as business says, the risk landscape does change, and it is pivotal, and it doesn't happen that often that things change in a way that...
Yes, identities were there always, right? We had usernames, we had passwords. But it was always there. But with how the world is changing, how economies are changing and how interconnectivity is happening and cloud access and everything, that risk that was always there becomes center stage to our risk register and how we handle things and how we manage things. And so...
And it's pivotal and it's unique, because in our world, a lot of things change a lot, but seeing something that was always there becoming that bigger for getting so much attention, getting so many attacks not being directed there, and like hackers log in, they don't... You know, it's pivotal and it's important, and you can see also how the whole industry is shifting around it and the regulations, the best practices are shifting around it, because I think it is pivotal and it is important.
Okay, well, I think those were the great closing words for this presentation. Thank you very much again. Thank you. Thank you all for coming.
See All Locations
See All Locations