IAM as a security discipline has evolved significantly over the past 25 years, from authenticating and authorizing a few hundred employees protected by a virtual private network to a massive number of accounts and identities mixing employees, business partners, customers, devices and things, privileged and non-privileged, human and non-human accounts, all of them exposed through a public network (The Internet), putting not only IAM systems but Identities at the centre of organizations' security landscape.
As a result, user identities and identity systems became the focal point of attacks in more than 80% of all cyber threats. The growth of non-human identities has also caused a significant increase in identity-based attacks. Equally important, the fraud landscape is rapidly advancing. Fraudster tactics are becoming increasingly sophisticated, and with GenAI evolving rapidly, the number of frauds related to identity theft, account takeover and synthetic IDs has growth significantly.
With a deeper look at the many breaches, frauds and identity-based attacks reported in the last few years, they all have things in common: lack of MFA or strong authentication mechanism, stolen credentials, unprotected legacy applications, outdated identity life cycle and onboarding process, immature governance, lack of visibility with no or poor monitoring systems, failing in quickly detect an attack, weak response plans, and more, regardless the type of identity or identity system.
Given the current scenario, why are we still segregating the IAM discipline in three domains WIAM, PAM and CIAM as if we still had only employees, customers and privileged accounts, and why governance (IGA) is mostly or only related to Workforce?
In this thought-provoking session, we will discuss the current scenario and propose a new strategy focusing on capabilities rather than on the IAM domains to remove the barriers between these traditional IAM domains and to join-forces with Cyber security to support organisations on their Identity Fabric implementation journey.