This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The Journey to Zero Trust starts with Secure Identityabstract

Download resources

About this session

An Okta business value manager with a decade in identity (Accenture, director of cybersecurity at Aldo, now Okta, plus teaching at HEC) sets out to demystify zero trust and argue that identity is the practical place to start. He traces the term to NIST's definition of no implicit trust and continual verification, notes the same idea appears as complete mediation in a 1975 design-principles paper, and lists what zero trust is not: not a product, not something you buy from Okta or Zscaler, and never finished. He sketches an identity-centric architecture where the identity platform provisions users, applies adaptive and step-up authentication from network, device and behaviour signals, and exchanges data with SIEM, MDM, CASB and cloud platforms. The core of the talk is a five-stage maturity model with concrete problems and benefits at each level: consolidating directory sprawl and deploying MFA for compliance or insurance; single sign-on and automated provisioning; work-from-anywhere policies and access reviews; protecting legacy apps and streamlining M&A; and finally passwordless access without VPN. He closes with IBM breach-cost data and common obstacles, then takes questions on COVID-era acceleration, service authentication, APIs and adoption in Quebec.

Identity powers cyber resilience, and acts as the basis for the secure adoption of modern IT innovations, and for the pursuit of digital transformation initiatives that are essential for business competitiveness. Identity is the core of a Zero Trust strategy: With the perimeter moving to the identity layer, people become the critical component of the Zero Trust ecosystem.

Key takeaways

  • Zero trust is people, process and technology; buying an identity or network product does not make you zero trust.
  • Start with identity because it is the glue between users, devices, SaaS, on-premise apps and cloud platforms, and it feeds signals to the SIEM.
  • Do not skip maturity stages: consolidate directories and roll out MFA and SSO before attempting adaptive policies, RBAC or passwordless.
  • Sell each step with a tangible benefit such as fewer help-desk password resets, avoided compliance fines, lower insurance premiums or faster M&A onboarding.
  • Reduce MFA fatigue by using context (network, device, behaviour) to prompt only when risk warrants it, and reserve step-up factors for critical apps.

Speakers

Louis Migault
Louis Migault
Senior Business Value Manager · Okta
Louis started his identity journey back at Accenture when he worked on the first deployment of ForgeRock for a major customer. From there, he improved his acumen in Identity Management by helping multiple clients deploy complex solutions. He then… Read moreRead less

Louis started his identity journey back at Accenture when he worked on the first deployment of ForgeRock for a major customer. From there, he improved his acumen in Identity Management by helping multiple clients deploy complex solutions. He then made the jump on the customer side by joining The Aldo Group where he was responsible to build and a team of exceptional individuals. Finally, he wanted to do the "trifactor" (consultant, customer and software vendor) and joined Okta where his role is to help guide future customers on how to sell Identity internally.

Resources

Tags

More from GoSec 2022

Also from Louis Migault

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.