Rogério Rondini, an IT professional specialized in identity and access management, discusses the critical importance of integrating identity threat detection and response (ITDR) into organizational strategies to combat growing cyber threats. He highlights the evolution of identity as the new security perimeter, with identity attacks accelerating in pace and sophistication. Emphasizing that traditional identity management silos—privileged accounts, workforce, and consumer identity—should not remain isolated, Rondini advocates for a cohesive strategy that merges these domains, learning from financial sectors' success in fraud prevention to combat identity threats. He proposes a comprehensive ITDR framework which involves collaboration across cybersecurity, identity, and forensics domains, under the leadership and accountability of a Chief Information Security Officer (CISO). Rondini underscores that ITDR should encompass strategy, governance, and operations, incorporating adaptive capabilities such as lifecycle management, risk profiling, detection, and alert management, all within a multi-layered, defense-in-depth approach.
My name is Rogério Rondini. I'm from Brazil, living in the Netherlands. I'm going to talk about ITDR, a call to action. I hope at the end of the presentation you understand what I'm talking about when I say a call to action, because a lot of actions have been taken recently to block identity attacks.
But yeah, there is still some work to do. As I said, I'm from Brazil, moving to the Netherlands about eight years ago. I've been working in IT for 25 years and the last 15 years in identity and access management. I think everybody has heard about identity as the new security perimeter or identity as the security perimeter. We have been saying this mantra in the last five years, so we say it so many times that the bad actors listen to it and then they decide to attack identity systems. That's the situation where we are now. To give some numbers, this came from the PwC Trusted Insights 2025.
You see the attack surfaces are expanding rapidly and now we have generative AI in the picture. The respondents say that 67% of the concerns are related to gen AI. Cloud technology is on top. On the other hand, we also see the number of concern or the threat concerns compared to how organizations feel they are prepared is quite different. So we see cloud-related threats. 42% of the respondents are concerned but only 34% feel they are prepared to respond and so on. Identity attacks are occurring at unprecedented speed. We see a number of supply chain breaches increasing, about 15%.
You see a high number, like about 8% of credentials being stolen and they are selling credentials in the market at a very cheaper price. The fraud related to identity are also growing fast and now we still have a new actor there, the synthetic ID, which is related to AI faking identity when onboarding and creating a bank account, for example. And on the other side, we also see a huge number of incidents or data breaches related to non-human identity. And then it's growing, it's growing over time. So we are taking actions to block identity attack but it keeps growing.
On the other hand, we see in the trust insight from PwC that organizations understand the cybersecurity and identity and access management is a part of the digital transformation when they come to customer trust, brand integrity and this kind of thing. So this is the situation that we are facing now. But before diving to the topic about the ITDR specifically, I wanted to discuss a little bit about what I call the three classic identity and access management domains problem. So we see this everywhere. So basically, this is how we have been working and implemented identity and access management.
We split it over the years in three different domains. We have privileged account, workforce, access management and consumer identity. And the thing is, at the beginning, this was a natural path forward, right? So we start with workforce a while, 20 years ago, 25 years ago, then privileged account. And then suddenly we learned that identity is important for the business to drive business growth. And then we created the acronym for consumer identity, citizen identity. But also within the organization, it in fact create silos, right?
So we don't see consumer identity teams talking to workforce identity team and privileged identity and vice versa. So we have this siloed and fragmented within organization. And when it comes to ITDR, identity threats, detection and response, we frequently get the question, where should we put ITDR? So in which of these domains? So the first answer that came in, so this is of course a privileged identity, it's a PUN related. And then some organizations move to the PUN domain to implement identity threat detection response capabilities.
But then, so we also have workforce identity because we have employees assessing a cloud environment. We have employees and we privilege the access and we needed to understand which group these people are assigned to and then everything. So it could be a workforce identity. So then why not to understand, to introduce ITDR as part of the workforce in the privileged domain. So it's a combination of both domain. And then we say, well, okay, so then it's fine. So if identity threat is a workforce related and privileged access related, it means we are good with consumer identity, right?
And that's not really true because in consumer identity, in a consumer side, we have been implemented fraud prevention. So the consumer identity is good in prevent fraud or detect fraud. Mainly financial service implemented this for years, right? So then the question is, what's the difference between fraud prevention and identity threat detection, right? If most of the time fraud also starts with an identity threat or an identity attack, right? But how financial services implemented fraud. So can we learn from financial services and fraud prevention and apply this to ITDR?
So that's the question. So what if instead of talking about siloed identity and access management domain, we don't just combine these domains and look at the required capability to prevent identity attack. So why not eliminate the obstacle between traditional EON domains and focus on the capability itself, right? What can we learn from financial service and apply to ITDR? So based on this idea, we came up with a framework for ITDR. So this is more on a strategic level on how we implement ITDR. So in terms of this strategy, and then it starts with one thing that we have been calling out.
So the CISO must have a seat on the board. This is what PwC has been emphasizing recently. And there was a question to Martin about who should drive the ITDR. So in our point of view, this is a CISO responsibility. So the identity threat, right? CISO responsibility. So the identity and access management should be part of the CISO responsibility within another organization. And in terms of capabilities, so when we say a four pillars capability-based approach, it means we need to look at the core capabilities on each domain.
Let's say identity domain, cybersecurity domain, and eventually forensics domain. And build an entire program and the process to tackle identity threat, identity attacks. So basically the framework that we are proposing combines identity baseline. So you need to have an identity foundation, identity baseline that supports identity security, right? So usually we say, oh, during the time orchestration are focused on consumer identity because it's required a user experience.
But that's not true anymore because during the time orchestration also helps privilege the account and workforce and employee account to protect and to detect online immediately what's happening, right? And take the proper decision. So there are several capabilities that we introduce as a foundation. Lifecycle management, credential, events logging, authorization, access control, just-in-time provision, step-up authentication, and adaptive authentication. So these are the capabilities.
We can include some more capabilities, but these are the foundation to implement identity and access management regardless of the type of identity you want to protect. On the risk management, also contextual risk and fraud profiling. Treat Intel is important to understand the risk and to support the detection response. Detection and alert management, integration with SOC, and case management, identity use case. So introduce identity in the cybersecurity use case and also the response mechanism, so automated playbook and everything. This all combined in one framework, in one program.
So when you look to identity threat or to implement ITDR in our organization, we feel that it should not come from one specific tool or one specific identity domain, but it should be a combination of these four elements integrating identity cybersecurity security in one main goal. To give an example, how we could apply this framework, right? So as I was mentioning about the fraud detection prevention financial service, this is a typical one approach that some financial service organizations use to prevent and detect fraud. It's called defense in depth approach.
So basically defense in depth approach is a layered approach. It means if one layer is bypassed, there will be another layer to protect and to prevent the attack, to prevent the fraud. Why not apply the framework that was mentioned before on a similar approach, but not for fraud prevention, but to detect identity threat detection response. So basically this is the same idea. So we have a layered approach and we introduce the capability module into this framework. So basically we have strategy governance and operation. CISO should take the responsibility for this entire program.
We need to define a policies operating module, to create an operating module and combine all this required capability. Then there's the second layer, which will be more tied to the identity foundation, where we introduce, we need to understand that the identity taxonomy applied to our organization. What kind of identity are we trying to protect? What is the risk incurred to this identity? Is it the consumer identity or is it employee or is it a B2B? What kind of identity we have in our organization? There's a lot of new use cases. For example, you probably have heard about the gig economy.
So how do you deal with freelancers and people that are coming and going to your organization all the time? So we need to understand the identity that we are trying to protect and the risk imposed to each one of this identity. In terms of authentication, so I mentioned about journey time orchestration and risk-based authentication. These are typical use cases or this typical capability that we apply in consumer identity, but it also should be applied to a B2B use case, to a workforce use case. And why not to privilege the access use case?
Of course, for service accounts, we might not request MFA, but it's still the journey time orchestration, the risk-based authentication apply to this service account authentication flow. And what action do you take when you identify any risk? Other layers, detection, alert handling. So basically, we layered this defense in depth, applying the framework, the four pillars framework, including identity foundation, cybersecurity integration, SOC, and everything. So basically, coming to the conclusion, in our perspective, so ITDR is not about another tool or technology.
So you might have good tools, you have vendors provide the tools that you can use, but there is no silver bullet. So there is no one tool will solve all the problem.
And again, this is what I wanted to emphasize. So it's not one identity and access management domain specific problem. So it cross all identity domains and it cross all cybersecurity in general. It cannot be tackled by only identity and access management team. So this is basically the outcome or why the title, a call to action, because we really see the need of integration between identity and access management teams and the cybersecurity team.
And yeah, so it's a combination of security tooling, human process and best practice. And it's required capabilities from all domains. We need to learn and apply financial service experience in fraud prevention to identity threat in all levels. And maybe the most important demands of holistic view from the CISO, with CISO taking the responsibility. So someone within organization needs to be accountable, need to be responsible for the identity threat or for identity security in general. And we need to learn it should come from, as we see, from the CISO, from the CISO in the organization.
Even though you have a specific teams and groups within the organization, but there must be a holistic view from the CISO, take the responsibility and apply financial service experience to identity threat in the organization. But there must be a holistic view from the CISO, taking the responsibility on the identity and access management program and applying the ITDR capabilities. So this was a presentation. So thank you. Thank you very much, Matteo.
See All Locations
See All Locations