So, good morning, everyone. It's nine years since I'm working in identity, and it's the first time that I'm presenting here at EIC, so I wanted to do something out of my comfort zone, and here I am. I'm hoping we are having a good time together. And even last night, my dear colleague, she convinced me to not use any digital assistants today with me, so it will be great. My name is Caroline, and I'm deeply passionate about identity. Identity is at the heart of everything we do, personally and professionally.
In my daily work, I focus on positioning identity as a real business and security enabler. I'm trying to make sure that it's clearly understood within organizations, that it's effectively governed and also embedded with fit-for-purpose capabilities in organizations. I'm working for different kinds of clients, from assessments, I'm doing audits, and I'm doing implementation consulting projects. To share my passion now also with you, I want to take you on a personal journey. It starts with my car, with my old car, and we're ending with autonomous systems, information security, and identities.
This is my old, beloved car. It was really reliable, spacious, it had heating, air conditioning, and music, and it brought me everywhere safely.
So, at some point, the oil consumption started to rise, and the tires were out, and the rust of a 24-year-old car really spread out. Then I needed to decide for a new car. I had to take quite some decisions. It was about, do I want an SUV or a state car? Electric or combustion? And then there were all the security features, 360-degree camera, lane departure, warning. We have other topics like drowsiness detection. And then we have convenience, like heated seats or the better sound system.
So, you are wondering probably why I'm taking you through a journey with a car. Fair enough. The point is, I wanted a car, or I needed also one, and it should match my requirements and my standards for safety, security, and convenience.
So, I thought, let's imagine the world where I can customise my own car. And there's an organisation that can also build it for us. Just as cars have evolved from mechanical machines into software-defined products, also the production environments are changing from just automated lines into autonomous ecosystems. And with that, I was also asking myself, how does the organisation ensure that there's safety and security for the organisation itself, and in the end, for me as a customer? And before we answer that question completely, we will explore what an autonomous system is. It's not working.
That's not quite autonomous. Okay, great. So... There was one too far. Great.
Okay, the goal of an autonomous system is the independent development of a solution path for a specific task and adapt it to an optimised particular situation. The path is executed in an operational environment. You can view these systems from two perspectives, the external perspective, how it's interacting with other actors and how it perceives other actors, and you have an internal perspective, how it perceives, learns, collaborates, plans. It's using a knowledge base and topics like human-to-machine communication. Did you know there are six stages until full autonomy can be reached?
So it starts with level zero, no automation at all. There's some assistant function, then you have automation, and you're concluding with autonomy. In the end, an autonomous system is defined by four characteristics. You have perception and verification, learning and adaptation, planning and self-regulation, and process execution and collaboration.
Well, that leads me to the question also, do you know how autonomous the systems in your organisation are? I think it's quite an important answer to this question, because with autonomy also risks are arising. You have an attack surface that is expanding and your threat landscape completely reshapes. There's a shift because the systems are no longer technical components. And with that change of the risk landscape, there's also a deliberate security response required. Our imaginary company is taking information security really serious.
The ultimate goal is the absence of unacceptable security risk for the organisation and for me as a customer. So they have established an ISMS, risk management, and they are all managing their information assets. They are following the security goals of CIA and additional goals like authenticity, accountability and reliability. Due to the increasing usage of the autonomous system, also the scope of what the organisation needs to protect is now expanding.
Saying that, as autonomous systems represent real value to the organisation, they also should be treated as assets and need protection like any other as well. And here I want to highlight three aspects. Why an autonomous system is also an information asset. We have accountability because decisions must be traceable and compliant. They should be linked to a validated identity. We have trust because systems must reliably interact with each other. Autonomy only works when there's a trusted and secure authentication and communication. Decisions should be based on untempered information.
And then we are having safety because the systems are acting in a real physical world. Compromise and wrong decisions lead also to real-world damage. Saying that, without security, there's no safety. So accountability, trust and safety, they don't happen by accident. They are enabled across all organisational levels, strategically, tactically, operationally, from governance down to deep technical mechanisms. And across all these layers, there's always one question. Who or what is acting here? And it's where we bring identity in. Identity is a security control for organisations.
And at the same time, it's a primary target for attackers. This is why industry leaders and security reports are stating topics like compromised identities are used for internal phishing and lateral movement. 35% of cloud identities are accounted for valid account abuse. Attackers prioritise credential theft and account compromise and protect your identities. As consistent identity and access control shape one of the foundational pillars for cyber risk management. So we accept identities in the human context. And I'm seeing it in my daily work.
Companies are applying identity concepts to all kinds of different identities. Therefore, it should also apply to autonomous systems. Identity gives you then the foundation to make the autonomous system secure, trustworthy and accountable. And what happens if identity fails? To answer this question, we go back to our imaginary world. Imagine the production is fully working. Robot sensors, transportation vehicles, all are working together and everything is really as expected. Systems communicate, decisions are made and production continues. And then something changes.
Attackers are not relying on sophisticated attack paths. A moment of trust is enough. A simple phishing mail and then the attacker is entering the network. From an attacker's perspective, our organisation is also really attractive. You have high-value customers, you have a connected environment and a really long supply chain because you're producing a car. And instead of causing immediate disruption now, attackers do something more powerful. They take over the identity of the system. So they can now operate within the organisation. They are acting as a trusted actor.
And the system, the environment is continuing to act as expected. But in reality, the attacker is having control. And this is what is called spoofing, the intentional impersonation of an authorised digital identity. So what happens if the attacker is now in our organisation? The attack impacts the autonomous itself, the technologies and the characteristics. It impacts actors in the environment. It impacts the protection goals of the organisation. And then it intrudes the car. And when the car is finalised, it can go also outside of the borders of the organisation.
So using a distrusted identity, the attacker interacts freely within the organisation without being recognised as malicious. This is having a huge impact on this information security controls. They access, manipulate and extract data. They influence decisions, they communicate and interact with other actors. And then it's not limited to one system. The entire ecosystem is affected. And the car is also in the end. Then intruded.
With that, the attacker can listen to my conversations. They can turn up the volume so that my ears are hurting. They can unlock the doors when I'm not there. So everyone can enter the car. And they can fully take over control of the car. Maybe in the end, they prevent that the brakes are not working anymore. And all of this simply because there was one identity which was no longer trustworthy. This shows once an identity is compromised, the core principles of information security are no longer guaranteed.
So now let's discover some of the topics to address the security for the organisation, the autonomous system and the car. Some things are staying the same. We still have holistic governance, we apply identity principles, and we manage the identity lifecycle. What changes is the scope. Because you now have to apply these principles to autonomous, non-deterministic systems. So what our organisation can do is build up their identity strategy to answer the question, what they want to achieve. Do you know what you want to achieve with your identity strategy?
So it's about defining goals and driving outcomes. An identity strategy is no silo. It should be aligned to every other strategy that is there, with IT, OT, AI. So you can position identity as a real business capability. And that's also what I'm seeing in my daily work in practice. Identity is not only a service anymore. It's really established as a business and security enabler. Then the era of autonomy is also reshaping ownership, responsibility and accountability. The question is, do you know your identity stakeholders? Who are taking the decisions in your organisation for identity?
Also here, what I'm seeing is that there are boards established that are dedicated for IAM to consolidate all the information that you're having. They're aligning on baselines, requirements for processes, architecture. And then you have a decision power behind it. Risk management is about understanding your threat landscape. What threats are you facing in your organisation? It's about spoofing, manipulation, man-in-the-middle attacks. And outside the organisation?
Well, the car requires a really long supply chain. And with that supply chain, other organisations have the idea of doing M&A activities. So what is happening with M&A?
Also here, identity is becoming a real consideration already in pre-acquisition integrations and then also in the integration part. It's not only about integrating one IT landscape with another anymore. The complexity is rising. When we talk about authorisation and authentication, we're talking also about just-in-time access. Permissions that are granted for specific tasks that are time-bound and automatically revoked. Permissions are based on parameters like sensitivity, context and risk. Whatever parameters you are having in your organisation.
Then it's about protecting and rotating your credentials. It's not sharing any credential and there should be an audit trail for it. And lastly, prepare your business continuum management. Know your downtime requirements and monitor identity behaviour. Because with that, you can ensure also later a response for identity-based attacks. So what does this mean for all of us? Autonomous systems, information security and identity are deeply connected. You can't address one without addressing the others.
When we want to get identity right, if we treat it as a true business capability, designed, governed and embedded across the enterprise, then it becomes something powerful. It becomes the enabler for accountability, safety and trust and the key to ensure information security in an autonomous world. And with my new car, I'm having a new digital assistant now in my life. And I'm really impressed by all the capabilities it's having, all enabled with the power of identity. So with that, thank you for being here with me today. Thank you. Questions from anyone in the room?
My main question is, tell us a little bit more about the car you picked. You're kind of missing the punchline from the whole... How much I paid?
No, just, you know, what is it? What did you get?
Oh, I think I'm not allowed, but it's... It's a secret what kind of car you drive? You didn't see it before? It was on there.
Well, I saw the old Volkswagen. It's quite autonomous, so I can... I'm able to not hold the wheel for like a minute or something and it's just keeping the line. It's amazing.
Okay, interesting. So try it out. So I think you got a US-based car, because you can't tell the Germans.
No, I think it's a German car. But whoever is in Turkey at one time, we can have a ride together. Sounds good. So we have, unless there are any questions, we have a break for about five minutes until the next session. So stay here or whatever you need to do, but be back in five minutes.