Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Saviynt: Identity Security as Business Enabler with EY's Ian Roy

Saviynt
08/17/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


day. Glad to be back with you, it's me, David Lee, of course, Enrique Serra, what's going on my man? Hey, David. Good to see you, man. Good to see you. It's been a little bit, man. It's been a while. It's been a while. Yes. Missed you, man. Me too. I know. I should move to Canada. And Simon too. I know. Where's Simon been? I don't know. So we have Ian Roy, head of cybersecurity at EY coming by to have a conversation. We're going to get into some stuff. We're going to talk about identity security, we're going to talk about where the industry is going. Stay tuned. You don't want to miss it. All right, Ian, welcome, man. Thank you. Thank you. Happy to be here. Excited. Yeah. Looking forward to the conversation. Yeah, it's going to be a good one. Yeah. Enrique, how are you doing, man? I'm good, man. I'm good. Great show. Yeah. Great show. Thank you for joining us. Thank you. Enrique. Anybody had any barbecue yet? I have not. I mean, you know, we're in Dallas. I had Indian food. Indian food in Dallas? I think it's inevitable, right? Hanging with the people that we hang out. Okay. That's true. But I'm just saying, you're in Dallas. And I had both. I had Indian food Monday night and pork chops last night. Okay. And they were both amazing. Yeah. So it was weird. So we went to a dinner last night and so we're in Dallas and we were talking about the different things on the menu. We're talking about different like barbecue sauces, things like that. So they had a Carolina barbecue on a Dallas menu, which is crazy. So all right. There's different kind of barbecue sauces for people that don't know, right? And like Carolina barbecue sauce is used like a vinegar based kind of sauce. But like in Texas, right, this is when you move to Texas, there's three things you get as soon as you get here. Right. You get your ID. You get your gun. And they tell you about barbecue sauce. All right. And so like Texas has their own type of barbecue sauce. So the fact that we're at a Texas restaurant and they allowed Carolina barbecue. I was like, I don't know who this chef is, but I don't know how they allowed this. Clearly. So anyway, it was just interesting. So I got to make sure I grab the barbecue. It wasn't. I don't really like the Carolina style barbecue sauce. Anyway, so it was just one of those things. But anyway, what do you guys think about the show so far? Very exciting. Yeah. It's amazing to see all the innovation that's happening around AI security and our clients need that. So it's amazing to see all the new development. So excited for solving the AI security problem for our clients. Yeah. How do you think that we've been watching this industry, right, for the last, you know, a couple of years kind of transformed from, you know, identity and IT administrations, identity security, right? We're going to come to IVIP in a second. Oh, my God. I know. I know. It came up a couple of... It did. It came up last night in the conversation. We're going to mess it up. But, like, this move to identity security and how we have to look at it now. I'm interested, Ayan, to get your take on how do you think we need to look at it now? Right? Because I think for the longest time, you know, we've kind of looked at identity more so not as an enabler, but more so like I said, cost-centered, it's a thing that we have to do. Yeah. But now I think it's different now. We kind of really have to start leaning it a little bit differently. So what's your take on that? Absolutely. No, I couldn't agree more. I've been working in this space for over 25 years, and back in the days, it was single sign-on, then we went to compliance, and now what is so exciting is identity security. And what I mean by that is if you look at what is happening around us now, a lot of nation-state actors are using AI to create more advanced threats and attacks, and the time to exploit is reducing in a big way. So what we are now trying to share with our clients and discuss with our clients is how to build the right defense in depth. And identity is a critical component, is a critical layer to build the right defense in depth. The one other data point I'll share with you, David, is we do a lot of shadow investigations. Post-breach, we go in and we look at how the threat actors exploited and the kill chain. Ninety percent of those attacks, we have seen lateral traversal, privilege escalation. And the countermeasure for that, again, comes back to identity. How do we secure our privileged, not just human IDs, but the non-human IDs as well? So identity is now in the forefront. We need more identity signals going to all our endpoint detection, into your SIEM security event monitoring. And that is a fundamental countermeasure now to deal with the advanced threats. Which is, no, and I agree a hundred percent, especially if you think about, for me it would be so obvious, if you think of the attack chain and the critical path being identity. I don't remember the last time I saw a breach or an attack which didn't involve identity. So why do you think leaders and organizations, they don't embrace that? And identity is still seen as perhaps the stepchild of cybersecurity. Why are we not talking about that more? Or maybe they are. Do you think your clients are now perceiving the importance of identity and giving a different look at this? Absolutely, yes. And so Enrique, I'll share again a story. I was talking to a good friend of mine, he's the cyber leader at a private equity entity. And when we were having a conversation, he said, you know, I wish I did more identity growing up to become a CISO. And that was music to my ears. He grew up the ranks being an attack and pen tester, to building some of the most sophisticated cyber operations centers, SOC. He was one of the best architects that I've known for SIEM. And coming from someone like that and saying that I should have done more identity, and that was an eye-opener for me as well, because now a lot of cyber leaders are realizing the importance of identity, like to make zero trust really work, you need conditional access in addition to micro-segmentation. And that is, in my mind, a realization the industry is realizing, business leaders and cyber leaders are now realizing that identity is a critical countermeasure. And identity security really helps us build the right defense in depth. Without identity security, we cannot have AI security. And I love it because, well, knowing you, you work for EY, right? And you are in charge of a much broader scope than just identity, in cyber security. So having that context of the growth of importance, I think, and the advocacy on the topic. I hope we didn't have to talk so loud about this and the importance about this. But I think, as you're telling us, I think we see the tables turning a little bit. And identity not only having a seat at the table, as I think we spoke in other episodes, having the biggest seat as well. So to your point, CISOs having to have this knowledge about identity. But let me perhaps ask a few different angles on this, which is, how about the identity practitioner having to learn more about threat detection? They having to learn about this taxonomy of what an attack chain is and what this means to them. So do you think, do you see EY or yourself talking to your clients, also approaching identity teams having to learn this new skill in cyber? Absolutely, yes. Absolutely, yes. And Enrique, you bring up an excellent point. As identity practitioners, we have often thought about new hire, transfer, termination, authentication type of controls. What we now need to learn is, how do we integrate with the right data security tools? How do we integrate with our threat and vulnerability management tools? How do we do a better job of managing non-human IDs and integrating with operational technology OT security solutions? So that is very critical. A lot of our, as we work with our clients, it is very difficult to build the right security with just one product. So one of the things that we're talking to our clients right now is, how do we bring the ecosystem of our alliances? We're working with our alliances like Saviant and CrowdStrike, building the solutions, integrating the solutions. And that is so important. The other layer that we are very focused on, we have to, as identity practitioners, we also have to understand, what are the business trends? What is happening in the business? And hybrid is here to stay. NVIDIA is pushing GPUs on-prem. Hybrid is absolutely here to stay. How do we create a single pane of glass across different hyperscalers? How do we create a single pane of glass so we have more visibility into what's happening so that we can build the right defenses? Hybrid. It's interesting because we spoke about hybrid cloud for so long and having on-prem with SaaS and IaaS. Are you talking about hybrid in a sense of intelligence as well? The hybrid of human intelligence, artificial intelligence, and the combination of both? Absolutely. Absolutely. So I would say hybrid on-prem, in the cloud, multiple hyperscalers. So we are absolutely seeing that with our clients and that's primarily being driven by resiliency. We've seen some outages now. And humans in the loop is so critical right now. So we are using AI for our L1, L2 automation. And humans in the loop is so important to kind of drive the accuracy and the speed of cyber threat management. How do we make a shift from moving identity from like this cost center mentality to this enablement mentality? And outside of the solutions, but really driving this thought mindset of these leaders. So I want to dig into that example of the guy you were talking about saying, I wish I did more identity coming up. We've had this conversation a number of times of a lot of these leaders, a lot of the thing with identity, 80% of it is the tech. This other 20%, which is this big chasm they have to cross, is all the other stuff. And I was having a conversation about this last night. It's the horse trading, the talking to the application owners, getting your committee together, right? And really understanding across the business why this is so important and getting all those things done to actually build the program. And now when we look at this, the business gets it, identity isn't everything. And we can say that it's an enabler. How do we work with the rest of our industry? How do we help our practitioners do that, right? And then say, okay, well, it's an enabler. So then how do we enable the business, right? How do we work with the rest of our peers to go, well, go enable the business? And how do we get the business to look at it like that? Yeah. So excellent question. So I'm going to, this is when I start dating myself. So about 25 years ago, I was working for an automotive company. So when you were five. And in the automotive company, they were the market leaders in all segments with the exception of the new first time car buyers. So what this automotive company decided to do was they wanted to launch a new brand to get the first time car buyers to start buying this brand. And so they, back then, I had an eight month timeline to get WebSingles sign on, on to those web properties. And they came to us and said, the business came to us and said, we are going to launch the portal for this new brand in eight weeks at the New York Auto Show. So we either get security done in eight weeks, and my traditional SDLC was eight months, or I'm going to go without security. So that was my alternative. And I worked with IT infrastructure to kind of enable the business. So I kind of started doing this way back in my career. And I have always taken that philosophy to our clients. As a cyber practitioner, my job is to enable the business to perform their transactions securely. One other client story that I'll kind of share with you. And this became real to me when the CFO of a cruise line, one of our clients, went to the board and said, we are going to add a billion dollar of revenue using our digital channels. So this is a cruise line that is going through a digital transformation. And one of the big challenges for us was to create that omni-channel experience, the ship shore experience for the customers. And what became real for me was, we have to enable the technology to meet the business need so that the CFO could go back to the board and say, yep, we have generated a billion dollar in incremental revenue. So I have lots of these examples, a life sciences example, where researchers and scientists are working on drug research and bringing drug to market. What we need to do from a cyber perspective is, how can we enable these researchers to come into the environment more securely and create a frictionless, seamless experience? I was looking at your answer and listening to the examples you gave, which are basically CIAM, customer IAM, two of them CIAM, one extended workforce. I had this hypothesis. When we think about identity, not as a cost center, but as a value generating type of business, it is hard to think outside of CIAM, because CIAM, yes, you put a dollar, you get more clients, revenue. But I like the last example, which you gave is researchers or external employees or non-employees accessing this, the less friction they have to do that, it also enables business. Absolutely. I think those are great examples. And my hypothesis is, is there anything outside of customer, outside of the either B2B or B2C type of more workforce focus that we could think of making identity more as a cost center? Yeah, there's the risk avoidance and the cost avoidance of user provisioning, for example, the efficiency of getting access. Do you see other examples perhaps in your career, 25 plus years? By the way, I remember Web SSO, oh my God, that brought me back, web access management. Do you see other examples there are perhaps workforce that are not just, oh, this is good, it's saving me money, but no, it's making me money, which I think it's an interesting difference. Yeah, so Enrique, the one other, so I was with our chief economist a few months back and he was talking about the macroeconomic trends right now. So if you look at our clients and their businesses today, they're dealing with supply chain disruption. They're dealing with the impact of tariffs. And what does that mean? They are going to different suppliers in different countries. Our clients are going through more transactions than they have ever done before. We are seeing an increase in M&A activity. That is another area where identity plays a critical role. This is where we are enabling the business. How do we onboard hundreds and thousands of users so that they have a seamless experience? The last thing you want is parent entity and acquired entity having two different identity systems. So we have such an important critical role, again, to enable the business to get seamless access, the right level of security, and without identity, without the right identity, technologies, the processes, and the right team, the people, process, technology, and the right level of data, it is very difficult to enable business. No, I love it because how many times we were talking to clients, even prospects, and they asked us, I said, no, I like the idea. Please help me to talk to the business in a way that we can justify this. So I think those examples are just a great way to illustrate that, a blueprint, if you will, to have those kinds of conversations. Yeah, but I think it's also like we have to shift, and I say we as an industry, right? The practitioners in general, we have to shift the mindset of how we approach all, right? In the conversation I had last night, I was talking with a customer, and they were talking about they're excited to get started on their journey, things like that. And the guy, he was just asking me all these questions. How do we do this? How do we do this? How do we do this? And I finally had to say, dude, technology is not the answer to everything, right? Like, you know, like, well, and if we do this, how are we going to get audit to agree to do this? And I was like, you go talk to them and ask them. Yeah, yeah. Right? Like, well, but they always did this in their old school. And I was like, then you have to go ask them and say, well, you did it this way before. If I show it to you this way, well, they're never going to accept that. Then you've got to go figure out and come up with a compromise. Like, we have to get past this, like, technology is going to make it better. Technology is going to make it better. Technology is going to make it better. It's not always going to make it better. And maybe there is an answer. But also the answer is going to them and saying, hey, listen, I know that this is what you're used to. And this is your process. And this is what you want. So now let's have a conversation and get to why is it that you want something a specific way? Yeah. OK, so you know that your process is X, Y, Z. And this is what you want. Right. And you're you're you're telling me to do something that I feel is inefficient. But this is what you're saying to do. OK, well, I can sit here and we can we can butt heads all day long or I can go. We're teammates. We work with the same company. At the end of the day, like we want the same thing. So let me figure out why is it that you want this and then show you that, hey, this is what you want. But I'm showing you that I can get you to the same result just in a different way. And it's more efficient. I was like, these are things this is identity all day long. And that's the one thing that I think we we've lost in the industry is that we forget that so much part of this is you've got to get involved with the business and talk to them. And some of it needs to be changing your process. Some of it needs to be changing the technology. And one of the things that I told this customer at the end of the day is like, this is how you need to measure this, right? Yeah, when you look at it, you should be doing you should be tweaking on both sides. Right. And neither side should ever tweak too much. If you're tweaking the business process too much, you're wrong. If you're tweaking the technology too much, you're wrong. But you should never be sitting there and going, well, the technology to solve everything. And you should never be saying, well, the business absolutely has to change. Those are right. It should be a mixture of both. Right. And, you know, for those of us who are musicians, stuff like that or whatever. It's like when you're on a mixing board, right? You're trying to get the perfect mix and balance. I'm going to raise the treble up just a little bit. Now I'm going to pull down a bit like you're constantly trying to find that perfect mix and blend. And I think in the industry we lost that. Right. And I'm always going to be critical of us first in the industry. This is we live and breathe this. Right. It's our job to be in this and helping our customers and reminding them. It doesn't matter if we're on the vendor side, the practitioner side, wherever. Right. Yeah. We have to do that because they look to us to go, hey, what are these answers? And it's sometimes calling them out and not telling them what they want to hear like, oh, OK, we'll do this. No, no, no, no, no. Like, hey, you got to go do some work. So you're going to go have to talk to the audit team. You're going to go have to talk to your application owners. And yes, you're going to have to spend some hours. And yes, maybe our technology will or some technology that will make it better, make it easier. Yes. Maybe a consulting company will come in and do some work for you. But like you still have to do some work as well. Right. And I think those are some of the things that we have to get back to, because I think that what we're going to see over the next really three years with where we are with technology and how the opportunity that AI presents. Right. And I want to be very clear when I say that, because it's, you know, there's all this buzz around AI and what it can be and what it can do. But it is very clear the opportunity that's presented and how it's allowing us to change the way we operate. Right. And so that opportunity is going to give us this ability to completely change the way a lot of people work and how we address a lot of these problems. And that's not something that we can ignore. Right. Absolutely. So I think leaning into that and giving our customers the ability to go like there's things that there's ways that you can address problems that you just you couldn't even imagine doing before. Yes. Right. Yes. So a couple of thoughts, David, that come to mind. And you brought up some excellent points. And by the way, my daughters are in orchestra. So your music, I know how you play together. We've got to talk more about music in this episode. Yes. Yes. They're violinists. And so to your point, like how the orchestra comes together is so important. And as I think about your point around engaging the business, we often in cyber get into our technical jargon. Yep. We talk about kill chain, indicators of compromise, and we lose business at that point when we start using that language. Very much. What we need to really focus on is talking in business terms. What is the business impact? What is the business risk tolerance? Because we have to partner with the business to design the right process. To your point, we have to design the right end state process. And with AI, we actually have an opportunity to do that. We have an opportunity to rethink how we have historically done things and how we should be leveraging AI in our future state process. And it should really be a partnership with business to get the right level of security. And business should be in the discussion signing off on the risk tolerance because we are not doing things to them. We are doing it with them. Right. So that is so important. Great point, David. I think going back to balance, it's almost like we're balancing three things. The two that they brought up, which I think 100%, it's solid advice, which is the technology and the processes. They're fine-tuning those two things. And the third one, which is we've got to talk the same language. Yes. If we're too deep into the weeds of what identity, proficiency, and OAuth 2.0, we lost the audience here. Yes. We saw at Gartner how much they're pushing the idea of outcome-driven metrics. So having leaders talking more on this sense of business language of, hey, let's talk about the outcome. Let's talk more about the problem we're solving versus the tool, and balancing those three things. Do you agree? It makes sense that, number one, I love the rule of three, but also it's easy to remember. Yes. And it's the process, it's the tools, but also the language we use. I think good stuff we're coming up. Absolutely, absolutely. And that is the other part that we have to unlearn. Like, you know, I would love to talk about Spiffy and SAML and OAuth 2.0, but that's where we geek out, but not with the business, right? So, yeah, couldn't agree more, Enrique. Music, no. What's your favorite band? U2. U2? Yeah. Okay. All right. And they have stayed a band together. And I think that the power of the team in identity, the power of the team in cyber, it is so important. Perseverance. I can think of a few identity vendors that they just persevered, and perhaps they thrived because of that. I can think of Birdjam, another band like that. So, of all the grunge bands, is Birdjam the best band of that era? I don't think they were, but they just stay longer. Yeah. Are they still the same band? I don't know. I think they changed drummers, but mostly... Yeah, yeah. Eddie Vedder? Is that the... Eddie Vedder is the singer. Okay. See, I know a little bit. I don't know a lot. I know. It's not my genre. R&B. Not my thing. Is it? Yeah, and so... I'm learning classical music. I am developing a bigger appreciation for classical music now, because the girls are playing violin. Right. So, yeah. How many girls do you have? Two. Two daughters, yeah. Both play violin? Thirteen and eleven, yeah. Wow. Both in the orchestra, yeah. That's awesome. So, I enjoy watching them and hearing them. Yeah. So, you're playing with them? No, not yet. It's a tough instrument to learn. That's what I've realized. It is the most difficult. Yeah, there's no frets. No, I really admire it. What is that? Technically, right, there's a fret on a violin, isn't it? No, no, it's fretless. Oh, it is fretless? Yeah. So, you've got to go, wee-wee, and... It takes a lot of practice. Okay. That's what I'm learning, yeah. But, yeah, the longevity of what we do in Identity II and in cybersecurity companies, they say, no, we know who we are. How many times at Gartner I spoke with startups and vendors, and they say, tell me who you are. And not all of them, they have that answer at the tip of the tongue. It's, no, we do this, the AI. So, and we started with that question, AI, in this conference here. Yes, I think it's changed the way we work. It's changing the way we'll protect. It's changing the way attacks are being constructed as well. However, too many noise, isn't it, Ian? And how do we even come out with, perhaps, recommendations or suggestions to filter out the noise from the good stuff? Yeah. What do you think? So, Enrique, a couple of thoughts, and going back to the three points, three S's. So, I have started using that in my client discussions. Design for speed, design for scale, and design smarter systems. Speed, scale, smart. So, going back to the days of human identity and smaller population, now we are dealing with a higher volume of identities. So, the need for scale is so important. The human IDs, non-human IDs, I talked about speed. What is the way zero-day exploits were leveraged in attacks, the time to exploit is shrinking rapidly. So, that speed is so important. As we design systems, as we think about identity for the future, we need to design for speed, which is fundamental. We need to make our systems more intelligent. So, for me, again, the fact that we have started building more intelligence and more AI into our identity systems is very exciting. And for me, that is where the innovation is going to happen, like a lot of good innovation. And most of our Alliance partners who are thinking along those lines, who are embedding speed, scale, intelligence into their innovation journey, are absolutely going to be the winners at this point. That's very good. Because I think everybody is a little bit afraid of bubble scenarios. We saw the bubble of web. Because there was a lot of good stuff happening at that point and a lot of garbage. So, I can imagine with AI, a lot of real good, revolutionary, innovative stuff. And a lot of, man, you don't know what you're doing. It's a bunch of people in Brazil typing things and selling that as AI. And we saw examples, real companies, no, our AI was a bunch of guys just typing in the back end. So, I think a lot of leaders are a little bit, okay, I know I need to be fast, but I'm super cautious about making the wrong call here. Yeah. And, Enrique, I mean, some of us have been in the identity space for several years now, or decades, I should say. And if you think of... It's just years. It's just years. Thank you. And way back when we started talking about access, certification, SOX compliance, we enabled more rubber stamping. That was the year 2000. That wasn't real security in my mind. So, the fact that we are really talking about identity security now, for me, that couldn't be more exciting because I get excited talking about building a secure and more trusted working world. So, for me, identity security is here to help us get there. Yeah. Do you remember what Sachin said about the certification campaigns? I think, man, this is brilliant. And not because I was CEO, but he said something about certification campaigns. So, if you're running a certification campaign and you're removing 5%, 2% of entitlements, you're doing compliance. Yes. Now, if you're doing this and now you have a recommendation, you're removing 60%, 7% of entitlements, you're doing security. Yes. Wow. That's kind of brilliant. Absolutely. Zero standing privileges. Just-in-time access. Yeah. Shrinking the tax interface. Yeah. So important. Yeah. All right. I'm on the other for that. I don't believe in access reviews at all, but that's a different conversation. I will say this. I agree with you. I like where we're going from just the identity security standpoint of it, right? I want to see identity get to the point where we're less about the compliance aspect of it and the administrative aspect of it and more about looking at identity from a true like risk perspective, like here's all this access, here are all these things. What does it mean? Right? What does it mean for this account and these accesses and these privileges within my organization? Right? Yeah. David has access to these cloud accounts, these privileges. So what does that mean? Right? Cool. David accesses this 35 times a day. Is that good? Is that bad? Right? He has access to this much data. To start having these kind of intelligent conversations around the type of risk that this brings to the organization. Yeah. This has been awesome. We're going to wrap up with a couple of things. I want to get back to IVIP because this came up at dinner last night and we could not figure out. So somebody went to the session and was like, yeah, they came up with this new acronym at Gartner IVIP. And we made the joke, yeah, because all Gartner analysts get their bonuses based on if they come up with an acronym and it sticks. What does it stand for? What is it? Because I remember we talked about it at Snippers. What is it? IVIP is? Identity Visibility and Intelligent Platforms. Okay. All right. It's a hoax. Analysts don't get paid by the acronym, I can attest. But I did call one of my old good friends at Gartner and say, hey, what is this about? So I did ask them and what was interesting, I didn't see from that angle because we talk about ISPM as well, Identity Security Posture Management. And so my question was more about what's the interaction or an intersection of both? And the way they describe, no, visibility, it crosses security. There are things we can do, for example, with IVIP, which includes, for example, license management. So are you overusing licenses? So that has nothing to do with security. So okay, I can see that. And as a reporting dashboard of visibility, it includes other things that are not security. While security posture management, it's mostly focused on reducing attack surface and improving your posture in security. So I think I was satisfied for now, but I say I want to go deeper and maybe another episode on this. Hey, because I could see that kind of going back to like the enablement discussion. I just think in general, and we'll kind of close with this, going back to making an enabler, I think we have to kind of retrain how we, again, when I say we, us as practitioners, how we see ourselves in the business and get out of us putting ourselves in that hole of like, we just do this, right? And nerding out on our little technical things. And when we come to the table, being able to do things and asking those questions around, hey, as a business, what drives you every day? What's your P&L? Right? Talking to them in their language. And so things like license management or things like that, or whatever, like realizing that we've got to be able to understand what we can bring to the table and that can help them succeed at what they do. And I think AI is going to help with that because instead of being threatened by like, hey, now AI allows even a business to come up with apps and things like that. I think what it will do would be interesting is that now it can kind of be that translator for us where a lot of us, we sit there in our technical, like we want to talk about spiffy, all this stuff, whatever. Well, they don't know that, but now they can just say, you know what I want? I want an app and here's the things that I want to do. And then AI can just kind of make it and then we can go, oh, that's what you want? Well, okay, to do that, you really need this is whatever and don't deploy that app yet because there's a whole bunch of stuff we need to do on the backside. But now all of a sudden, right? Like, cool, we can make this happen for you. Let's do some stuff over here that we need to do. Don't worry about it. We're going to make it a little bit more secure, add something to here. But now we know what you want business and we can help you get there faster, more securely. Right? There's this kind of real conversation happening where we know what it is you're wanting. And now we just kind of have this translation layer, right? I don't know. I just, I feel like we can kind of get closer to that where it's like, now we're truly helping and working with the business and like, I think AI can help us get there. Absolutely. And David, one other point I will highlight, because this is how I make friends in the business. AI can actually help me bend the cost curve for doing identity and cyber. So it can absolutely help me from an affordability standpoint. Our businesses have a big agenda to build more affordable, and affordability is a big priority for our clients. And using AI, we can absolutely bend the cost curve. So I talk a lot to my clients and CISOs and cyber leaders and identity leaders. And we need to hold ourselves accountable. We need to be given what is happening around us. And this is back to my three A's, accountable, adaptable, and agile. So agility, adaptability, and accountability. We need to hold each other accountable. I'll use that to make more friends. Yes. No, Ian, it's been great. Thank you for coming. Thank you for sharing this with us. I love the conclusion we got here together of the product process, the language. And I'm very grateful. I think the audience would appreciate that as well. Thank you for having me. This was awesome. Appreciate it. Thank you, man. Thank you. All right. That was good. That was really good, man. Man. Ian Roy. Ian. Uno. Two violinists. That's pretty awesome. Without frets. Without frets. Here's why I thought they had frets. Because of the strings. Like I just assumed there would be frets there or whatever. Super difficult as identity in cyber, people like to say. It's difficult. I had a surprise for you, though. I picked up acoustic guitar. Good for you. Yeah. Technically, I've been playing for a while. Yeah. I'll tell you off camera. It's a long story. But I started playing again. Nice. Yeah. You know, working on how to build up my calluses again. You know. I'm holding myself back here not to jump into advice mode. And speaking of good advice, what Ian said on the three things, well, I think we came on that conclusion of the balance. Yeah. Right? The balance. And I like your analogy. Well, I'm an analogy guy. But how you're mixing things up so it's a good level of product, the process, the language. That was something that I was always very self-conscious about. Even in the natural sense of language, like the Portuguese and English being a second language and how AI can help me polish this in a way that my colleagues would clearly understand. Yeah. I was thinking about that too in the language side of AI could help us in identity to rewrite and polish this the way the business can understand. I was thinking about that. I was going to be huge. Right. Yeah. And I like his, I like the three S's. Right? That too. Yeah. So it was the, let me see if I can remember them. It was the speed, scale, and smart. Right? Yes. Always got to keep a supplement. Stick to the threes. I love the rule of threes. It's easy to remember. And no, it was a very good entertaining, but also I learned a lot. Always learn. Did you learn? Always learn a lot, man. I'm always learning. It's hard not to. We get the great guests, man. It's always the guests. Never me. So. Let's do it.

TL;DR

  • 90% of post-breach investigations show lateral traversal and privilege escalation, making identity security the critical countermeasure against advanced threats leveraging AI
  • Identity practitioners must balance three elements: technology solutions, process optimization, and business-focused language that emphasizes outcomes over technical jargon
  • AI enables organizations to bend the cost curve for identity operations while serving as a translation layer between technical teams and business stakeholders
  • Identity has evolved from a compliance function to a foundational security layer essential for zero trust, AI security, and defense-in-depth strategies
  • Leaders must embrace accountability, adaptability, and agility to position identity as a business enabler rather than a cost center

Identity Security's Evolution from Compliance to Defense

Ian Roy, Head of Cybersecurity at EY, traces the transformation of identity from single sign-on and compliance functions to a critical security layer. With over 25 years in the space, Roy emphasizes that 90% of post-breach investigations reveal lateral traversal and privilege escalation as key attack vectors — making identity security the essential countermeasure. Nation-state actors are leveraging AI to create more sophisticated threats with reduced time-to-exploit, requiring organizations to build defense-in-depth strategies with identity at the core. The conversation highlights how identity signals must flow into endpoint detection and SIEM platforms to enable effective threat response. Roy shares that even seasoned CISOs who built their careers in penetration testing and SOC operations now recognize they should have invested more deeply in identity earlier in their careers.

Balancing Technology, Process, and Business Language

The discussion emphasizes that technology alone cannot solve identity challenges — practitioners must balance technical solutions with process redesign and business engagement. Roy stresses the importance of speaking in business terms rather than technical jargon, focusing on business impact and risk tolerance instead of kill chains and indicators of compromise. The hosts introduce a framework of three balanced elements: technology implementation, process optimization, and shared language with business stakeholders. Organizations must avoid over-tweaking either technology or business processes; the right approach involves adjusting both sides to find the optimal mix. Roy advocates for outcome-driven metrics and partnership with business units to design end-state processes that leverage AI capabilities while maintaining appropriate security controls.

AI as Cost Enabler and Business Accelerator

Roy positions AI as a transformative force that can bend the cost curve for identity and cybersecurity operations while enabling business agility. He introduces his framework of three A's: accountability, adaptability, and agility — principles that identity leaders must embrace to deliver value. AI creates opportunities to rethink historical processes and design more efficient workflows that reduce operational costs while improving security posture. The technology can serve as a translation layer between technical teams and business stakeholders, allowing business users to articulate requirements in plain language while security teams ensure proper controls. Roy emphasizes that affordability is a top priority for clients, and AI-driven identity solutions can help organizations achieve both security objectives and cost reduction simultaneously.

Chapters

0:00 - Introduction and Welcome
3:29 - Identity Security Evolution
7:25 - Identity Leadership Challenges
16:30 - Business Enablement Framework
21:12 - Speaking Business Language
30:30 - IVIP and Visibility Platforms
32:14 - AI as Business Enabler
35:14 - Closing Thoughts

Key Quotes

4:16 "Ninety percent of those attacks, we have seen lateral traversal, privilege escalation. And the countermeasure for that, again, comes back to identity."
5:45 "I was talking to a good friend of mine, he's the cyber leader at a private equity entity. And when we were having a conversation, he said, you know, I wish I did more identity growing up to become a CISO."
6:42 "Without identity security, we cannot have AI security."
21:38 "We often in cyber get into our technical jargon. We talk about kill chain, indicators of compromise, and we lose business at that point when we start using that language."
34:04 "AI can actually help me bend the cost curve for doing identity and cyber. So it can absolutely help me from an affordability standpoint."

FAQ

Why is identity security more critical now than in previous years?

Nation-state actors are using AI to create more advanced threats with reduced time-to-exploit. Identity security provides the essential defense layer because 90% of breaches involve lateral traversal and privilege escalation. Without proper identity controls, organizations cannot implement effective zero trust architectures or AI security measures.

How should identity teams communicate with business stakeholders?

Identity practitioners should avoid technical jargon like kill chains and OAuth 2.0 when speaking with business leaders. Instead, focus on business impact, risk tolerance, and outcome-driven metrics. Partner with business units to understand their priorities and speak their language, positioning identity as an enabler rather than a technical obstacle.


Categories:
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Zero Trust
  • AI & Machine Learning
  • Security Operations
  • Executive Briefing
  • Best Practices
  • Identity Security
  • Zero Trust Architecture
  • AI in Cybersecurity
  • Breach Investigation
  • Privilege Escalation
  • Business Enablement
  • Identity Governance
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Saviynt: Identity Security as Business Enabler with EY's Ian Roy

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Oct
                        08

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        10/08/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 10/08/2026
                          12:00 PM
                          10/08/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version