I wanted to expand to this based on conversations I've had over past 4-5 months as part of a research report coming out soon from The Cyber Hut on ITDR - what it is and why it's important now. The last thing I want to do however, is create more confusion and definitions! In order to avoid that I want to break down the term bit by bit.
An opinion piece analysing the potential acquisition of ForgeRock by private equity firm Thoma Bravo.
IAM 2 Identity & Access Management Industry Analysis Map We track a range of established and emerging vendors in the global identity and access management ecosystem. Established vendors provide us with meta-knowledge regarding market dynamics, funding, customer budget maturity and stable use cases.  We also track more emerging technologies that relate to IAM in order to […]
Authentication Design & Management 1 Day Masterclass or7 Hours Self Paced Video The Why:  To provide a virtual workshop for industry leaders, practitioners and consultants looking to develop authentication systems for both B2E, B2C and IoT/Machine ecosystems. For Who:  Your Current Role: Information leader, CISO, identity architect, security architect, CIO, digital consultant Pre-Reqs: Infrastructure understanding, digital concepts, […]
Based on the Amazon Book The CIAM Market and Technology overview course is based on the best selling book “Consumer Identity & Access Management: Design Fundamentals”. Released 2021 A business focused Industry first book on consumer identity Kindle & Paperback Digital copy available for free when buying course Purchase on Amazon Consumer Identity & Access […]
An introduction to just in time, next generation authorization vendor sgnl.ai
Over a 4 week period I asked the preferred deployment model option for four key identity and access management services: consumer identity, workforce access management, identity governance and administration and privileged access management. The results where subtle and nuanced.

Passwordless authentication is often described as improving both the usability and security aspects of both the employee and customer identity journeys. Many approaches to passwordless have emerged over the last 5 years - including hardware, software, biometric and standards based initiatives.

In November 2021, The Cyber Hut released a 61 page buyer guide for passwordless authentication, describing the vendor capabilities, requirements, integration options, B2E and B2C use cases and planning recommendations for migration.

A brief snapshot of questions to consider, when engaging software based solution providers in this space is described here.

Our latest LinkedIn poll on September 27th was focused on understanding the role and impact of artificial intelligence and machine learning (AI/ML) technology on the general identity and access management industry.
Security starts when authentication ends. It's a line I have used a few times over the years as it is one I actually quite believe in. In an era where firewalls are derided as being pretty toothless in the fight against omnipresent complex cyber attacks - and the concept of trusted networks quite rightly become obsolete in the world of "zero trust" - it always seemed odd to me, to put such a large emphasis on stringent authentication services. Clearly authentication is hugely important don't misunderstand, but my point really was that authentication (even with a strong MFA component) becomes less relevant if a) it is not continuous and b) not part of a more holistic approach focused on the access control of services, data and APIs.