This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The Evolution of Identity Trust from IT Security to Business Enabler

Download resources

About this session

Loren Russon, who leads product for Ping Identity after 25 years in identity, argues that identity security is shifting from an IT cost center to a business enabler, and questions the trend toward trust nothing, verify everything. Using an online game modeled on the prisoner's dilemma (The Evolution of Trust, by game developer Nicky Case, heard here as Nikki Kay), he shows that reciprocal cooperation, not blanket distrust, wins out over repeated interactions when both sides communicate clearly. He maps how digital trust is built at scale: verified documents such as a driver's license can expose around 150 usable data relationships, giving roughly 99 percent match confidence; behavioral and device signals build a risk profile; and liveness or voice checks add a layer once a person moves from unknown to known. He walks through Ping's adaptive trust architecture, detect, authenticate, direct and orchestrate, across an airline's 45-plus authentication roles, and shares two case studies where bot detection alone stopped 98 percent of a credential-stuffing attack on a retailer and, tuned over weeks, 97 percent of new-account fraud at a ground-transportation company.

Identity is no longer just an IT security issue but a key business enabler as businesses work to delight their consumers, partners, and employees with frictionless user experiences that also improve the security of access to the data and resources IT works to protect.
We all know security is a choice people make, and if we make it difficult, people will not choose it. But if we make security seamless and put control of what personal information can be shared, we can build trust over time and in the end get to know more about our users as we recognize them each time we engage with them.
In this session, I’ll introduce how you can establish trust through decentralized identity, leverage threat detection and mitigation tools to seamlessly engage users, and balance frictionless experience and security by implementing an adaptive trust model for governing access entitlements.

Key takeaways

  • Favor reciprocal, verify-and-respond policies over blanket 'trust nothing' defaults; in the game-theory model Russon cites, reciprocal cooperation outperformed constant distrust across repeated interactions.
  • Layer identity signals rather than relying on one check: combine document verification, device and behavioral telemetry, and liveness or voice checks to move a user from unknown to known.
  • Start fraud reduction with bot detection before adding heavier controls; one retailer case study blocked about 98% of a credential-stuffing attack from that step alone.
  • Design authentication flows per role, not one-size-fits-all; the airline example needed 45-plus distinct flows for pilots, gate agents and tarmac staff.
  • Move authorization beyond simple allow/deny toward directed responses (step-up authentication, added approval) so risky but legitimate transactions get friction instead of an outright block.

Speakers

Loren Russon
Loren Russon
SVP of Product & Technology · Ping Identity

Senior Vice President at Ping Identity, brings over two decades of experience in identity and access management, driving innovation in security solutions that protect millions worldwide.

Resources

Tags

More from GoSec 2024

Also from Loren Russon

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.