Identity is a business priority

Q: What lessons from your roles across consulting and enterprise cybersecurity are proving most valuable in your current position as Field Chief Technology Officer of Saviynt?

A: A key lesson has been the importance of long-term strategic thinking.

 Organisations should not focus solely on the implementation of a technology stack but also consider broader variables such as market position, industry conditions, and cyber and compliance risks. This ensures that identity services better serve the organisation’s competitive position.

Planning for ongoing execution and expansion of identity services is equally important. Traditional and AI powered accelerators can reduce the cost and complexity of implementing identity controls across the organisation. Essentially, success requires a partnering mindset among system integrators, technology vendors and client advocates.

Q: Your career has spanned the UK and Australia. How have different markets shaped your perspective of digital identity and cyber resilience?

A: Working across international markets has given me experience in differentiating risk quantification against identity threat vectors and in mitigating them through cyber resilience investments. I saw increasing regulatory compliance requirements backed by government penalties.

In contrast, Australia’s approach – most recently highlighted by developments such as the Australian Prudential Regulation Authority (APRA) AI risk management letter – identifies market gaps but does not achieve the same level of supervisory intensity on AI adoption.

Q: Many boards still view identity management as an IT issue. Why should CEOs and directors see it as a core business priority?

A: It is both a business imperative and regulatory requirement, with non-compliance carrying reputational risk for both leaders and organisations.

The castle and moat security model is no longer effective; the perimeter is now the user. Modern data breaches often happen not through external attacks but because a hacker gained access to the network using the legitimate username and password of an employee or non-human account.

For the board, we are seeing general data protection regulation (GDPR) strength laws from China’s Cybersecurity Law (CSL) and Data Security Law (DSL), which can impose penalties of up to five percent of turnover, as well as Australia’s recent Privacy Act amendments, which introduce stricter enforcement including risks of criminal penalties related to doxxing and individual lawsuits.

As data moves across boundaries, a central identity platform tags access based on country of origin. Without this, organisations could be forced to build expensive, isolated data centres in every country, impacting regional profitability.

Q: As businesses adopt AI rapidly, how is it changing the identity security conversation?

A: Within our identity platform, we have been building AI capabilities to deliver broader, faster outcomes to clients who invest in Saviynt.

This includes our identity security posture management (ISPM) capability, which can discover and categorise risks across Software-as-a-Service (SaaS) environments.

We have also developed AI powered capabilities that can discover AI agents across major platforms including Amazon Web Services (AWS) Bedrock, Microsoft Copilot Studio, Google Vertex AI, Salesforce Agentforce and ServiceNow AI Agent. They help articulate risk, produce audit reports, and remediate issues through governance and provisioning controls within the same platform.

We even have an industry first real-time identity authorisation agent sitting between agents and application programming interfaces (APIs). This validates changes in intent and can block Agentic AI access immediately or route it for human approval.

Q: Over the next three years, which technologies will most transform identity governance?

A: As a broad theme, we expect a shift from reactive compliance to proactive, real-time security.

Standards such as model context protocol (MCP) are becoming universal as the background interfaces governing how agents interact with enterprise data. This will enable faster AI agent control and reduce the privilege creep, where agents inherit the permissions of their creators.

AI is also finally automating legacy access review processes within identity governance. Low or high risk behaviour is being identified by machine learning modules, enabling faster approval or revocation than in the past.

Q: And what advice would you offer to rapidly growing emerging markets seeking to modernise digital identity frameworks?

A: Learning from the approaches of other markets, success for fast growing companies depends not only on inclusion but velocity too.

A shift towards decentralised services using emerging technologies such as MCP servers, over legacy perimeter based identity models, allows for greater business agility and rapid adoption.

It is also important to automate employee joiner-mover-leaver cycles and apply the same identity controls to B2B and contractor identities as to the workforce, as these are often the weakest links in identity security.

Share.

Comments are closed.