About this session
Mathieu Roy and Francois Lepire, both IAM architects at Indigo Consulting, present a four-pillar maturity model for deploying identity and access management: governance, privileged access management (PAM), identity governance and administration (IGA), and customer identity and access management (CIAM). For each pillar they map three maturity levels, from writing a first normative framework and defining basic account lifecycles to automated, cross-system controls like segregation of duties and correlated per-user risk profiles. Recurring warnings include not buying a PAM tool before defining a strategy, since organizations often over-license CyberArk or BeyondTrust relative to real capacity, covering non-human and vendor accounts that are frequently overlooked yet carry high privilege, weak native reporting in PAM tools for audit evidence, and maintaining a properly protected but not over-engineered break-glass account for outages. On IGA they flag account correlation across applications with inconsistent identifiers as the most time-consuming, hardest-to-automate task, and caution against promising full automation or fast role-based access rollout in environments with over 100 applications. They close on CIAM, weighing SMS and email MFA's convenience against phishing and SIM-swap risk depending on the population's exposure.
Key takeaways
- Write a strategy and a first normative framework before buying a PAM tool; organizations that skip this routinely over-license products like CyberArk or BeyondTrust relative to what they actually use.
- Inventory and cover non-human, service, test and vendor accounts explicitly; these are frequently overlooked yet often carry high privilege with weak passwords or hardcoded credentials.
- Keep a break-glass emergency account genuinely usable in a crisis; over-protecting it with too many approval steps defeats its purpose the day systems are actually down.
- Budget real time for account correlation across applications with inconsistent identifiers; this is the slowest, least automatable part of an IGA rollout and audits will scrutinize uncorrelated accounts specifically.
- Scope role-based access and certification campaigns to critical systems first rather than promising full automation across 100+ applications in a few months; manual, well-scoped certification is a legitimate low-maturity starting point.
Speakers

Mathieu is a graduated Engineer and IAM leader with over 20 years of experience. Mathieu brings extensive knowledge of IAM, IGA, and PAM projects, as well as a proven track record of success in leading large-scale security and governance… Read moreRead less
Mathieu is a graduated Engineer and IAM leader with over 20 years of experience. Mathieu brings extensive knowledge of IAM, IGA, and PAM projects, as well as a proven track record of success in leading large-scale security and governance initiatives. In one of his previous roles as Director of Governance and Security Architecture at iA Financial Services, Mathieu managed tier-one projects, including the writing and implementation of a normative security framework aligned with NIST and Cobit Framewok. After this, he led a multidisciplinary IAM team to successfully deliver three main project axes: EIAM, HPAM, and CIAM. Furthermore, Mathieu redesigned the mode of service delivery and operations, resulting in increased efficiency and effectiveness.

A long-time contributor to IAM, François has worked in the various roles of IAM teams. From technician, to analyst, advisor, product owner and today, as principal architect, François has tangible experience of what the reality of each position is… Read moreRead less
A long-time contributor to IAM, François has worked in the various roles of IAM teams. From technician, to analyst, advisor, product owner and today, as principal architect, François has tangible experience of what the reality of each position is. This gives him an unparalleled perspective and experience, allowing him to brilliantly measure the impacts of governance decisions relating to the normative framework. Whether for optimizations, product management, detailed or reference architectures, François is an undeniable asset that can allow you to benefit from a trusted actor committed to your success. François specializes in roadmap development, detailed and reference architecture, as well as the deployment of PAM, IGA and CIAM solutions.


