Okay, thank you all. So you'll be pleased to know this is a brief 20-minute presentation. I'll be talking a little bit about the current challenges and stepping forward into modern identity, okay? So we're not going to overwhelm you with the full-blown end story. I'm going to try and take you on a journey in your head from where you are today to what tomorrow looks like in a stable fashion, okay? Because everyone's been talking about AI. Did anyone see my colleague Larry Chinsky on stage during the keynote, other than the people who work for him?
Okay, yeah, about eating stones, about using glue to keep cheese on pizza, okay? Bear that in mind. So I'll start by simply saying this, because in the industry, it really winds me up when people say, and we vendors have been guilty of this, when we start saying that identity is the new perimeter. It's not the new perimeter. Identity has always been the perimeter. We're just wising up to it because we're running out of options, okay? Identity underpins absolutely everything in security, especially in a stateless cloud world, especially in an automated world, okay?
Now, who's familiar with this website, Information is Beautiful? Anyone seen this website before? Highly recommend it. You'll all get a copy of this presentation, so you can click through the links yourself. This is a way, this is a website that visualizes statistics, and what I've got here is a screenshot of some of the breaches, okay? I hope nobody in this room is working for any of these organizations.
If so, I apologize. We'll adapt it later, but this is pretty self-explanatory, okay? The yellow ones are the ones that are more interesting, size of the circle, size of the breach.
So, I zoomed out, okay? That's 2010 in this timeline that goes from the bottom upwards, okay? I won't state the obvious. You can probably see the trend for yourself, okay? September 2025 is at the top of the screen, which is what this is zoomed in. I think the point here is clear, okay? But what I would draw your attention to is what were the key topics at the conferences we were attending at those times, okay?
Big data, BYOD, virtualization, that's cool, isn't it? RBAC, ABAC, which should we be doing, et cetera, and so on, to now a hyper automated AI world. Throughout this journey, we've been tackling many different challenges. Throughout this journey, we've been pushing things to the cloud, we've started doing things with on-premise in, I would argue, the 90s. Virtualization became a thing, then we started consuming platforms, AWS, Microsoft, Google, et cetera. Does anyone here not have more than one platform in their organization?
So, nobody has got zero platforms, nobody's got one platform. We've all got multiple platforms, okay? Good.
So, we all get this, okay? We're all at this space so far.
These are, at OneIdentity, the big ticket trends that we look at when we try and solve the business problems that our customers encounter in identity security, okay? I won't bore you with the specifics of them, there are a couple I'm going to cherry pick, but things like cyber insurance and OT stand out for different reasons.
OT, in many cases, carries a risk to life. OT, of course, meaning operational technology, typical utility space. All of these have regulations around them, even AI, okay? Especially OT, IEC 62443, for the geeks in the room, okay? Ransomware's now AI enabled, of course it is, why wouldn't it be, okay? But there's something clear here that I want to draw your attention to, okay? There's something that all of these have in common, okay?
AI, non-human identity, DevOps, compliance, and what we're trying to do with our skills and resources. Can anyone tell me what these things have in common? I'll give you a clue, it's on the slide. Sorry? Identity. Accountability, okay? Seems obvious now that I've said it, but I put to you, okay, in our DevOps tool chains, and I'm not going to bother asking for a show of hands, because if you have not got a DevOps tool chain, you just haven't discovered that you have, okay? All right?
So, all of these exist in our organizations in some form or another, okay? All of them carry accountability, and I will say this, nobody's going to take an AI to court, okay? That's not a thing.
So, when we start answering to our investors, and the vendors are the same, we're the same as well, okay? Tell me, what are we doing with AI?
We go, I don't know. We go, okay, well, I want an AI strategy, go and get me an AI strategy.
So, we go and look at where we can invest in AI and what business processes we can wrap AI around and what value we can get out of it, and then we go back and go, this is what we're doing with AI. The business problem that we're trying to solve comes after the fact, not before. Does that resonate with anyone? You know?
So, I would argue, don't do that, okay? Again, stating the obvious. But I warned you, we're going to start with where we are. Our skills and resources, our people, you, okay, are the ones accountable, okay? Because we're human. All of these must have a human owner, period. That's not because compliance says. It's not even because common sense says. It's because that's where chaos begins. If there is no owner, it is, by definition, already in a state of chaos, okay?
So, there's at least one place to start. Now, let's zoom out a bit and look at the business, okay? We can talk about risk reduction. We can talk about operational excellence, which, you know, big surprise, we're going to. It's in the title, okay? And compliance.
So, let me ask you, which one of these do you want? I'm going to wait the entire rest of the 15 minutes for an answer if I have to, which one do you want? Or do you want none of them? That's a valid answer as well. All of them? You want all of them? Yeah? Why? Seriously? Let's start at the beginning. Why do we want these? Because you're told to. Yeah? Perfectly valid answer. That's why I want them as well. Speaking as the vendor, okay? I want these as well because I have to, okay?
Now, I would argue, as an investor or as a business owner, what I want is the one in the middle. What I must have is the risk management and the compliance because those are not choices. Operational excellence is, okay? The one in the middle is a choice, okay?
So, on the path to modern identity security, this is a choice you must make. The choice is either you want this or you don't. And therein lies the principle of what is the business problem you're trying to solve because when you peel back the layers of the onion, it's going to fall either side of this, okay?
Now, if I pick on compliance for a second, okay? Is anyone's organization only beholden to one compliance framework? It's a stupid question, isn't it? I'm very aware it is, okay? There's always going to be multiples.
So, your baseline must have, your baseline you're being told to is already complex before you even start because these are driving complexity, okay? Let me take a leaf out of Larry's book and make light of this for a second, okay? This is a European conference, okay? If you've not heard of NIST2 or DORA, like, I don't know what to tell you, okay? I can quote from them for you, but SOX takes us out of Europe for a second, okay? The reason I want to show you this is because of these guys, okay? The whole Enron scandal, okay?
The whole idea of securing money laundering, one of the reasons why accounts payable and accounts receivable are things that we care about, okay? Did you know that the congressional votes to pass this act of law, which is still publicly readable, okay? The only people who voted no, three of them, okay? Nine people who weren't there unanimously yes. Going to war in Iraq?
Nah, 60-40. Legalising marijuana? This absolute must-happen, easy decision, okay? For a Sarbanes-Oxley breach, okay, the CISO gets more jail time than second-degree murder. Did you know that? More jail time than murder. Beware the CISO if you're out of SOX compliance because it's cheaper for him to kill someone. Fact. Look it up, okay? Incidentally, the only crime I'm aware of that you get more jail time for is airline piracy, but don't tell them.
Now, it's no surprise that something like Sarbanes-Oxley, and many other compliance frameworks as well, require not just a single piece of identity security control, okay? They need IGA, PAM, Access Management, ITDR, okay? The whole SIEM process. You need all of them per compliance framework. The advantage is that many of them overlap. If you're ISO 2701 certified, you've done the majority that you need for the rest of them anyway. I'd call out NIS2 and DORA, okay? Bringing it back to Europe for a second, okay? Article 34 in NIS2 basically says you get a fine if you breach these two articles.
So, guess what? Compliance officer does exactly what I did. What do those articles say? Don't care about the rest because the rest don't carry a fine. And it's all about cybersecurity policies, the usual suspects. You must have MFA, you must have policy solicitor, and the other thing.
Okay, fine. Reporting obligations. 24-hour reporting obligation. 72-hour investigation obligation.
One month, complete, full disclosure. Exactly every single thing that happened in that incident and a remediation plan. Are you confident you can do that in a month? Are you confident that you can categorize all of the indicators of compromise within 24 hours of being notified? Okay. Many would say no. Some would say yes, and then encounter difficulties. There are enablers to that. DORA is a very interesting one as well. There are many documents that make up DORA. Of the 1774 document, okay, Article 21 talks about privilege access management. It's an act of law in the finance space.
It goes so far as to say if a privileged user, if Alan Radford, or alan.radford at oneidentity.com, if I want privilege access, high-risk access to something, I must have a separate account assigned in order to have that access. If I elevate alan.radford at oneidentity.com directly, I'm breaking the law. That has some very important ramifications, not just, hey, look, we must be compliant. As a vendor, if we design our solution so that your just-in-time elevation is elevating the user directly, it's illegal to use our software, right?
It feels like stating the obvious, but it's not so obvious unless you go and look, okay? So compliance, I put to you, is front and center of a modern cybersecurity strategy.
Now, this is something for you to take away. This is a value map, okay? There's capabilities on here. This is like a sort of zoned-in on identity piece, if you will, okay? How many of you got Active Directory? I was going to say, if no hands went up, that'd be weird, okay? Now put your hand up if you want Active Directory.
Yeah, see? Me either. I've started encountering customers that really put a smile on my face because they use phrases like, and I quote, Active Directory is dead in my organization. Would anyone be able to say that? No? AD is messy. It's legacy, and it's messy, okay? So in some elements here, and you'd have already encountered this yourselves, you're putting a Band-Aid on a symptom rather than addressing the problem, okay? And this identity picture is not just about identity frameworks. It's about the platforms that you're all using.
So as you can appreciate, this diagram could get complicated quite quickly. The reason I'm giving it to you as a takeaway is that if you've invested in elevation on endpoint, or in what you're doing about third-party access, or wherever you're investing in your risk controls, if you start mapping out to parallel complementary controls, you get more out of the original investment than you would have otherwise, okay?
And this is one path to operational excellence, because the organizations that have moved away from AD are actually realizing that the pain of keeping Active Directory clean is much easier when there isn't one at all, okay? Now, let me show you something real-world. So this is from a real-world scenario, okay?
Now, anyone who's lived and breathed in the identity space will recognize some of these metrics, okay? It takes me time to provision a user. It takes me time to do an incident response. It takes me time to find and investigate and assign ownership. NHI is a real itch to scratch here, okay? Some organizations will actually go through whole investigations.
Some customers would go, well, actually, what I did was I stopped provisioning in Active Directory completely in order to get a grip on what's being created, or to put another way, stop the leak, clean up the mess first before fixing the leak, okay? So we're all familiar with what these metrics mean, okay? This organization did something very, very simple.
They focused on these metrics, they set targets for these metrics, and they not just achieved those targets, they exceeded them, and then reduced the overall manual overhead, which they were able to draw a direct line of sight to revenue, okay? 99.18%. I have to go and double-check this, okay?
Now, what do you think was the secret to this success? Does anyone want to guess? I'm getting stern looks from the organizers, so I'm running out of time, so silence is your friend. Anyone want to guess? I'll give you a clue. It wasn't AI. Yeah? Who was expecting me to say AI? Yeah? All they did, and this will make you laugh, and this will make you laugh, all they did was bridge AD. That's the one thing they did, and that was the result. I put to you, when you look at operational excellence, that's a place to start. You don't necessarily need AI, okay?
And for the benefit of my colleagues in the room, yes, One Identity has AI solutions, okay? But my point here is this. Don't throw AI into your environment because someone told you so. It will help, but in a very specific way. These metrics can be made much, much stronger if you start relying on this kind of terminology in AI. You'll notice that none of them are actions. You're not relying on AI to do these things. You're relying on AI to educate them, increasing the value of the decision that is ultimately being made, okay?
That is your stepping stone from what you're already doing with existing risk management controls and enriching them. Once you've got that foundation, then you can start getting clever, because guess what? Then you've got it under control, okay?
Now, I'm going to finish up by putting a bit of a tinfoil hat on, okay? Because there's only one logical conclusion to these paths that we're on, and I'll use the phrase digital immune system, okay? All of the threat actors out there, okay, they are investing in AI. You are part of their supply chain. We saw at the start of the presentation that supply chain is growing. You are part of the supply chain, because as Mike Humby once quoted back 2010-ish, data is the new oil.
Again, not new, it's the old oil, okay? Data carries value, and you are part of that supply chain, whether you like it or not, which means the only logical conclusion to the road that we're all on is an always-on, live, real-time digital immune system behaving much like the immune system of a human body, where it never, ever switches off and is under constant attack, okay? That is the world you are in now, okay?
And there are some steps here within the last 20 minutes that can help you reinforce and be ready for that future world, because the future world will be more real for you when you realise, okay? So, many summaries. I won't read bullet points to you. At the end of the day, think in terms of, what am I doing with compliance? What am I doing with risk management? How do I bring operational excellence to the foreground in trying to solve these challenges? Because if I'm not focused on how that transpires into business value, I'm just burning money, okay?
And that's really the point I wanted to get across to you today. So, you can always reach out to me. I'm sure I've generated more, I'm sure you've got more questions now than you've walked in with, okay? And that's a good thing.
So, I don't know which booth we're at, but we're somewhere at the front. You'll have seen us, One Identity, okay? You can reach out to me directly. I'm alan.radford at oneidentity.com, LinkedIn, what have you. We may or may not have time for questions. ANAÏS We'll let you know. But thank you so much. ALAN Thank you. ANAÏS Thanks. Yeah.