Identité sécurisée, entreprise protégée.
Download resourcesAbout this session
Mike Berthold, senior solutions architect at Okta, makes the case that identity is now the primary attack surface: over 80 percent of breaches involve identity, detection still takes roughly 292 days on average, and identity-based attacks rose about 200 percent in a year. He walks through four common attack types. Credential stuffing has moved from noisy bursts to slow trickling and password spraying to stay under detection thresholds, fed by an underground economy that validates and resells breached credential lists. Info-stealer malware harvests both passwords and session cookies at scale, which argues for device-bound identity and shorter, risk-scaled session lifetimes. Adversary-in-the-middle phishing kits, sold as a service for roughly 120 to 250 dollars, proxy real bank login pages convincingly, countered by phishing-resistant, domain-bound MFA, brand monitoring and user education. Voice-based social engineering targets help desks and depends entirely on process discipline rather than technology. A long audience Q&A covers passwordless rollout, email as an identifier, passkeys as an emerging standard, and applying the same four-vector framework to non-human and ephemeral identities.
Dans le paysage numérique actuel, l'identité est la pierre angulaire de toute stratégie de sécurité efficace. Cette présentation, intitulée "Identité Sécurisée - Tout Sécurisé", explore le principe fondamental selon lequel une identité bien protégée est synonyme de sécurité omniprésente. Nous analyserons comment une gestion robuste des identités et des accès (IAM) ne se limite pas à protéger les utilisateurs, mais étend sa portée à l'ensemble de votre infrastructure, de vos données et de vos applications critiques. Nous aborderons les défis courants, les meilleures pratiques et les technologies émergentes pour établir un cadre d'identité résilient. Les participants découvriront des stratégies concrètes pour renforcer leur posture de sécurité globale en maîtrisant la complexité de la gestion des identités dans un environnement en constante évolution. Rejoignez-nous pour comprendre pourquoi ce concept n'est pas seulement un slogan, mais une réalité essentielle pour l'avenir de la cybersécurité.
Key takeaways
- Assume credential stuffing is already low and slow (trickling, spraying) rather than loud bursts; monitor for anomalous login patterns, not just volume spikes.
- Bind sessions to device identity and set risk-scaled session lifetimes (short for high-value actions like money transfers) to blunt stolen-cookie attacks from info-stealer malware.
- Deploy phishing-resistant, domain-bound MFA so a proxy site that looks identical to the real one cannot capture a valid second factor.
- Treat account verification and user authentication as separate problems; do not let a security question become the weak link that resets a strong MFA factor.
- For non-human and service identities, prioritize least-privilege access and short-lived, expiring credentials over permanent service-account passwords.
Speakers

Mike is a Senior Solutions Architect based in Montreal, Canada. He covers the Okta Platform (Workforce Identity and Customer Identity) as well as Auth0 as part of Okta’s Office of the Field CTO (OFCTO) Presales team. He works with his colleagues to… Read moreRead less
Mike is a Senior Solutions Architect based in Montreal, Canada. He covers the Okta Platform (Workforce Identity and Customer Identity) as well as Auth0 as part of Okta’s Office of the Field CTO (OFCTO) Presales team. He works with his colleagues to build deep relationships with Okta customers in North America, help design successful outcomes and ensure the smooth planning, deployment, and ongoing use of Okta's solutions. Mike has been working in Identity for over 20 years and holds several certifications, including CISSP and Okta Certified Technical Architect (OCTA).
