Skip to main content
Spotify for Podcasters
The Week in Identity

The Week in Identity

By The Cyber Hut

"The Week in Identity" is focused on providing a weekly analyst briefing on the latest identity and access management news events, funding rounds, conference updates and more. Identity is now foundational for all employee, consumer and device based security and usability projects and is changing rapidly. Hosts Simon Moffatt (Founder at The Cyber Hut) and David Mahdi (ex-Gartner Analyst and CISO Advisor) provide impartial analyst comment and opinion on some of the most exciting trends within the IAM landscape.

For more information on The Cyber Hut visit www.thecyberhut.com/
Available on
Google Podcasts Logo
Spotify Logo
Currently playing episode

E29 - Identity Mesh and Identity Fabric / Heliview IAM Conference Review / Cyber + Identity Mashup / People, Process and Technology / IAM Threat Reports

The Week in IdentityMay 26, 2023

00:00
44:42
E29 - Identity Mesh and Identity Fabric / Heliview IAM Conference Review / Cyber + Identity Mashup / People, Process and Technology / IAM Threat Reports

E29 - Identity Mesh and Identity Fabric / Heliview IAM Conference Review / Cyber + Identity Mashup / People, Process and Technology / IAM Threat Reports

This week Simon and David review the recent Heliview IAM Conference that took place in the Netherlands. The main topic for the day was the rise of the identity fabric (or mesh) and how this can enable the modern organisation with a range of agile IAM components that supports both business and security use cases. Simon presented a keynote on the future of IAM - using some research from The Cyber Hut focusing on where IAM may look like in 2028 and beyond...

They also discussed the need for people, process and technology integration, in order to map the existing IAM landscape to future investment and metrics.

They finish off by discussing the rise in cyber threat reports that have emerged in the past month that all have a very strong reliance on IAM - and why ITDR is a process not a product.

Cyber Threat Reports:

Joint Cyber Advisory: People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection CISA Advisory: Hunting Russian Intelligence “Snake” Malware Permiso Security: Unmasking GUI-Vil - Financially Motivated Cloud Threat Actor



May 26, 202344:42
E28 - The RSA 2023 Episode - Passkeys / MFA / Adversary in the Middle / Collaboration / Standards

E28 - The RSA 2023 Episode - Passkeys / MFA / Adversary in the Middle / Collaboration / Standards

This week Simon and David review the recent RSA Conference that occurred at the end of April over in San Francisco. From the generic meta-patterns at the conference covering themes such as collaboration, standards, multi-cloud and technology integration, through to more IAM focused conversations covering MFA, passkeys and authentication attacks. Are passkeys now here to stay? What will help adoption? Will attacks on passkeys start to increase along with usage rates? Will attacks against existing MFA forms including SIM swap, MFA fatigue and social engineering be a compelling event to improve adoption?

May 11, 202354:26
E27 - RadiantLogic & Brainwave / New Styra CEO / Auth0 OpenFGA project / Chief Identity Officers / AuthZ as part of ZT

E27 - RadiantLogic & Brainwave / New Styra CEO / Auth0 OpenFGA project / Chief Identity Officers / AuthZ as part of ZT

This week Simon and David tackle a range of news items including: Radiant Logic completing the acquisition of IGA vendor Brainwave; Authorization vendor Styra getting a new CEO and Auth0 (by Okta) releasing v1.0 of a new open source authorization project called OpenFGA. They also tackle the question of whether we need to see Chief Identity Officers in the board room and how zero trust is essentially driving the demand for authorization platforms.

Apr 21, 202345:22
E26 - Interview with Alex Bovee from ConductorOne

E26 - Interview with Alex Bovee from ConductorOne

In this week's episode, Simon and David are joined by Alex Bovee the CEO of https://www.conductorone.com/ - a next generation identity security and IGA provider. They cover a range of topics including the adoption of cloud services and the impact on security, the cloud shared security model, the left shifting of identity risk from being detection focused to preventative, reducing access reviews to focus on exceptions only, how the security world is taking on more IAM capabilities and knowledge and the introduction of a new open source project called Baton - to extract and manage identity data.

Mar 31, 202343:41
E25 - Gartner IAM USA Review / ITDR / Identity Orchestration / Identity First Security

E25 - Gartner IAM USA Review / ITDR / Identity Orchestration / Identity First Security

In this episode Simon and David review the recent Gartner IAM conference held in Grapevine Texas. Is Identity Orchestration on the rise and how will that impact the complex identity infrastructure of the modern enterprise? What role does security now play within IAM and how will that impact metrics, persona and integration? Is this the year of Identity Threat Detection and Response? And what is becoming of Zero Trust and how it relates to identity?

Mar 24, 202347:20
E24 - Interview with 1Kosmos CEO Hemen Vimadalal

E24 - Interview with 1Kosmos CEO Hemen Vimadalal

This week we hear from a special guest as Simon has a great conversation with 1Kosmos CEO Hemen Vimadalal.  They start off at the beginning...going back to 2003/4 when Hemen helped setup identity certification and role management startup Vaau - which later became Sun Role Manager, then Oracle Identity Analytics.  From there Hemen continued on the entrepreneurial journey to setup Simeio Solutions - a 1000 strong identity advisory and managed services player, before moving on to setup 1Kosmos - a software vendor aiming to tackle the usability and security dilemma by linking identity proofing to passwordless authentication.  An insightful discussion that covered identity governance and administration, trust boundaries, the rise of different identity personas, data breaches, privacy and identity based authentication.

Mar 10, 202338:31
E23 - UK eCrime Review ChatGPT / Authomize OpenITDR / Identity Threat Assessment Framework / Identity Visibility - Radiant Logic & Ermetic
Mar 06, 202327:35
E22 - CyberArk 2022 Results / PAM-lite / Microsoft Entra / Workload Identities / Okta + Plaid

E22 - CyberArk 2022 Results / PAM-lite / Microsoft Entra / Workload Identities / Okta + Plaid

This week Simon and David take a look at two of the giants in the IAM space - CyberArk and Microsoft.  Are Microsoft emerging as the dominant cloud service provider in the identity space? What were CyberArk's latest results telling us? Who are Plaid and why have they partnered with Okta?  What is becoming of the workload identity space?

Feb 17, 202353:18
E21 - Saviynt Raise $205M / Radiant Logic to acquire Brainwave GRC / SiberX Toronto / Future of Cyber Manchester
Feb 03, 202345:17
E20 - Strata.io Series B $26M / Home Depot Consent Breach / Fave Biometric Poll Result / Identity Based Authentication / IAM Maturity Assessments

E20 - Strata.io Series B $26M / Home Depot Consent Breach / Fave Biometric Poll Result / Identity Based Authentication / IAM Maturity Assessments

This week Simon and David discuss a $26 million series B round for identity orchestration vendor Strata.io. What is identity orchestration, why is it a problem today and how can it be handled within the enterprise?  What is IDQL and what are recipes?  A discussion on a recent consent breach at Home Depot in Canada saw the Canadian Privacy Commissioner got involved. They also review a recent poll covering our favourite biometric, which spawned a discussion around identity based authentication (see 1Kosmos and keyless.io for more on that).  They also delved into the world of IAM maturity assessments...



Jan 27, 202347:06
E19 - The Regulation Episode / Guest interview with Kristian Alsing / NIS-D / NIST 800-63-4 / PSD2-SCA / GDPR

E19 - The Regulation Episode / Guest interview with Kristian Alsing / NIS-D / NIST 800-63-4 / PSD2-SCA / GDPR

Welcome to the first episode of 2023! After a short festive break, Simon and David are back to bring you the latest industry analyst views on a range of different identity and access management topics.  This week, they have a special guest: Kristian Alsing - a Senior Cyber Security and Business Resilience Executive - with 20 years experience working for the likes of Accenture and Deloitte.  Kristian recently wrote a great guest article for The Cyber Hut on NIS-2. In this episode the guys cover a range of topics relating to regulation and the role of IAM - covering critical infrastructure, the ever increasing supply chain and the rise of destructive attacks in waiting!

Jan 20, 202353:47
E18 - 2022 Year in Review Quiz

E18 - 2022 Year in Review Quiz

As the end of 2022 is on the horizon, Simon and David run through a festive quiz roulette, hitting some of the key topics of interest from the past 12 months including..


Favourite conference of 2022 Favourite identity buzz word IAM acronym / topic that will die in 2023 Biggest IAM surprise in 2022 Most interesting IAM startup / category IAM acronym / topic that will come alive in 2023

Huge shout out to a range of vendors including...HYPR, Aserto, 1Kosmos, Indykite, PlainID, Axiomatics, Styra, Sonrai, Ermetic, Strata, SecureKey, SDO, Gen, ForgeRock, Ping, Okta, Cyberark, Sailpoint, Auth0, tru.id, SGNL, 3Edges, Keyfactor and many more.


Have a great festive period and we'll see you in 2023!!

Dec 23, 202244:05
E17 - Poll Results - Where does IAM report in your org? / Cyber & identity security hiring and firing / Microsoft Entra review

E17 - Poll Results - Where does IAM report in your org? / Cyber & identity security hiring and firing / Microsoft Entra review

In this week's cold and snowy episode, Simon and David review a recent The Cyber Hut poll asking the question around where does IAM report into within your organisation?  What about consumer identity and privacy?  Also...do we need a new role - the Chief Identity Officer?  How can the reporting lines impact the hiring and firing of IAM and cyber security personnel?  And a brief look at the re-branded Microsoft identity capabilities known as Entra.

Dec 16, 202239:23
E16 - HYPR $25M Series C / US DoD Zero Trust Reference Architecture / Would You Pay for Privacy?

E16 - HYPR $25M Series C / US DoD Zero Trust Reference Architecture / Would You Pay for Privacy?

This week Simon and David bring you another dose of analyst insight and opinion on the world of identity and access management.  This week they discuss how HYPR received a $25 million funding round to rid the world of passwords; a discussion around how identity is now foundational for zero trust - and how the US DoD released a reference architecture for zero trust and what that means for identity - and an interesting poll result, on the question "Would you pay for privacy?".


Dec 01, 202240:05
E15 - AKeyless $65 million funding / ForgeRock launch cloud IGA / Future Identity in London / Mobile Authentication - biometrics & privacy

E15 - AKeyless $65 million funding / ForgeRock launch cloud IGA / Future Identity in London / Mobile Authentication - biometrics & privacy

This week Simon and David discuss a funding round for secrets management startup Akeyless who this week announced a $65 million funding round.  The need for secrets, machine identities and service credential management is on the rise and Akeyless are aiming to securely automate this area.  IAM platform player ForgeRock also announced this week, they were launching a cloud based identity governance and administration (IGA) service.  The world of IGA has been dominated by on-prem solutions.  Can ForgeRock make a difference?  They round out this weeks chat, with a review of the Future Identity two day festival that happened in London this week.  Simon hosted a panel on mobile authentication - launching a riff on biometrics, privacy, identity based authentication and more...

Nov 18, 202235:31
E14 - Whitehall IDM London / AI+ML & Automation / IGA / Machine Identity / Identity Business Cases / Identity for Zero Trust

E14 - Whitehall IDM London / AI+ML & Automation / IGA / Machine Identity / Identity Business Cases / Identity for Zero Trust

This week Simon and David met up face to face at the Whitehall IDM Conference in London.  This one day event covered a host of topics, case studies and vendor pitches.  Simon and David pick out the best and most interesting aspects focused on the rise of AI+ML in authentication and IGA - asking the question is identity becoming a big data problem?  They discuss the emergence of machine and service identities - what it is, who will own it and how it works.  They cover cyber insurance the ever growing need to articulate the business case for IAM and how identity for zero trust architectures is for small and large organisations alike.

Nov 11, 202246:19
E13 - ForgeRock acquisition by Thoma Bravo / Authenticate 2022 Review / Twitter Verified

E13 - ForgeRock acquisition by Thoma Bravo / Authenticate 2022 Review / Twitter Verified

After a short break, Simon and David return to discuss the recent $2.3 billion acquisition of ForgeRock by Thoma Bravo and the effect that may have on the broader IAM market - with Thoma Bravo already recently completing the acquisition of Ping Identity.  They also cover the recent Authenticate 2022 conference and how can we improve MFA adoption?  An emerging vulnerability in asymmetric challenge response authentication and passkeys also make an appearance...

Nov 04, 202240:20
E12 - IAM Deployment Models Continued... / Oort.io receives $15M Series A ITDR / ICConsult acquires Kapstone consultancy
Oct 07, 202236:21
E11 - Identity Deployment Model Definitions: OnPrem - IaaS - PaaS - SaaS - Managed Service / Definitions & Assessment / CIAM Signals / AI-ML in Identity Poll

E11 - Identity Deployment Model Definitions: OnPrem - IaaS - PaaS - SaaS - Managed Service / Definitions & Assessment / CIAM Signals / AI-ML in Identity Poll

This week Simon and David discussed the ever growing question around identity and access management deployment models that arose from Simon's recent trip to the Identit.eu consumer identity event in Belguim.  What are the options?  How do practitioners decide between the vast array of choices from private cloud and on-prem through to SaaS.  Do they really just need a managed service if a SaaS offering becomes too hard to customize or perhaps can't connect to on-premises data? They also check in at the mid-point of the latest The Cyber Hut poll that is running - seeing where AI/ML will have the biggest benefit in the IAM industry...

Sep 30, 202235:20
E10 - Uber MFA Breach Discussion / Authentication / Why Are We Not Using Passwordless?

E10 - Uber MFA Breach Discussion / Authentication / Why Are We Not Using Passwordless?

This week Simon and David do a deep dive riff on that old age chestnut...authentication!  Uber has recently been in the news regarding a data breach...one seemingly executed by using an MFA Bombing attack technique.  Could it have been stopped?  What options are available?  They then discuss a recent LinkedIn poll run by The Cyber Hut asking why are we not using passwordless authentication....tune into hear the midweek poll results.

Sep 23, 202249:40
E9 - Gartner Security & Risk Management London / Outcome Driven Metrics for Cyber & Identity / International Identity Day

E9 - Gartner Security & Risk Management London / Outcome Driven Metrics for Cyber & Identity / International Identity Day

In episode 9, Simon and David briefly discuss the International Identity Day that is being promoted on Sept 16 - that aims to include, protect and empower citizens globally in the pursuit for having government issued identities for all.  Simon attended the Gartner SRM conference this week in London, where there was a left-shifting of identity into the app-sec and network-sec worlds, as well as a detailed discussion on outcome driven metrics - and making sure the business know how their cyber and IAM investments are doing. 

Sep 16, 202230:55
E8 - Gartner Identity & Access Management Las Vegas 2022 Review / Cloud / CIEM / ITDR / Identity Security / Trust / Hype Cycle

E8 - Gartner Identity & Access Management Las Vegas 2022 Review / Cloud / CIEM / ITDR / Identity Security / Trust / Hype Cycle

This week Simon and David reviewed the recent Gartner IAM event held in Las Vegas.  One of the larger annual industry events dedicated purely to the identity and access management space, it is of course, broad and varied, covering a range of established and emerging trends and technologies within the identity space.  In this episode they covered the role of the identity hype cycle, how cloud identity is big, complex and here to stay, the importance of outcome related communications and management of IAM and how we're all gravitating towards identity centric security.

Sep 02, 202237:20
E7 - A Breaches Episode - covering Twilio, Cloudflare and Cisco
Aug 12, 202240:10
E6 - The Privacy Play by Samsung and Apple / Ping Identity acquisition by Thoma Bravo
Aug 05, 202229:18
E5 - OneWelcome acquisition by Thales / Transmit partnership with Microsoft

E5 - OneWelcome acquisition by Thales / Transmit partnership with Microsoft

This week Simon and David discuss the recent acquisition of European identity and access management for B2E and B2C OneWelcome by French giants Thales.  This week also saw an interesting partnership between passwordless authentication startup Transmit Security and global heavy weights Microsoft - with Transmit bolting into their Azure AD B2C offering.

Jul 15, 202225:11
E4 - Blog review: 1Kosmos, Ubisecure, Trulioo / Palo Alto Unit 42 Cloud Threats / Ping + Microsoft + Workday / Cyolo.io Series B funding

E4 - Blog review: 1Kosmos, Ubisecure, Trulioo / Palo Alto Unit 42 Cloud Threats / Ping + Microsoft + Workday / Cyolo.io Series B funding

This week Simon (David's on holiday!) took a quick peek at some interesting blog entries that appeared.  Ubisecure provided some insight into hybrid cloud deployments, 1Kosmos told us more about "Identity Based Authentication" as a pillar of zero trust and Trulioo discussed how risk assessment should be a part of identity onboarding.  In other news Ping Identity announced a partnership with Microsoft and Workday to work on a profile for verifiable credentials and JWT and identity based access control startup Cyolo.io announced a $60 million series B round.  Finally an April article by Palo Alto's Unit 42 on cloud based threats also caught Simon's eye.

Jul 04, 202223:53
E3 - Identiverse 2022 / Infosec Europe 2022 / Identity for the Hybrid Cloud / Immutable Who & What / Behaviour Management / Proofing + Authentication become One?

E3 - Identiverse 2022 / Infosec Europe 2022 / Identity for the Hybrid Cloud / Immutable Who & What / Behaviour Management / Proofing + Authentication become One?

In this episode, Simon and David review the recent Identiverse conference from Denver and the Infosec Europe event that happened simultaneously in London.  They cover the rise of identity for the hybrid cloud, how authentication and proofing are becoming one, the use of blockchain technology to provide an immutable record of the who and the what and how employees are our first firewall of defence.



Jun 24, 202227:17
E2 - RSA 2022 Review / Machine Identities / Cloud Native Security / Cyber Insurance / Business Outcomes

E2 - RSA 2022 Review / Machine Identities / Cloud Native Security / Cyber Insurance / Business Outcomes

This week Simon and David discuss the recent RSA 2022 conference in San Francisco, and how the topics of identity and access management filtered into areas such as Machine Identity, the rise of Cloud Native Security solutions, how the world of Cyber Insurance is evolving and how vendors, providers and conferences...must start to align security solutions back to business outcomes if they are to provide real long term value. 

Jun 17, 202223:50
E1 - Intro / Gartner London IAM / CIAM / ITDR / Privacy

E1 - Intro / Gartner London IAM / CIAM / ITDR / Privacy

Episode 1 - Hosts Simon Moffatt and David Mahdi launch the brand new podcast "The Week in Identity", focused on providing a weekly briefing on the latest and greatest identity and access management news events, funding rounds, conference updates and more. This week, they discuss the Gartner London IAM event, the rise of consumer identity, how privacy is a new differentiator and how Identity Threat Detection and Response is on the rise.

Jun 04, 202226:57