Enterprise Identity Forum 2026

The next Enterprise Identity Forum is taking place on 30 September at The National Theatre on the South Bank, London, running from 4.00 - 9.00pm.

Senior representatives of leading organisations who have already confirmed their attendance include

  • Head of IAM, Global Energy Major
  • Director, Cyber Resilience Centre
  • IAM Leads from three management consultancies
  • CISO, Global Energy Trader
  • IAM Lead, Global Mineral Trader
  • IAM Strategist, Global Media and Entertainment
  • Country Manager UK & Ireland, Global Identity Technology Company
  • Principal Security Engineer, Major Financial Trader
  • Group CISO, Global Investor
  • Security Architect, Security Technology Start-up
  • Global Head of IAM, Global Human Resources Solutions 
  • IAM Lead, Global Logistics
  • Head of IAM, Global Insurance Company
  • Head of Enterprise Identity, UK Defence Corporation

Agenda

FROM 15:45 PM to 16:00 PM

Arrivals and Refreshments

FROM 16:00 PM to 16:10 PM

Introduction and Welcome

Keynote Presentations

caroline r professional photo 1

Caroline Rivett

Cyber, Risk and Technology Consultant

FROM 16:10 PM to 17:10 PM

Facilitator: Caroline Rivett, Convenor, Enterprise Identity Forum

Caroline introduces the Enterprise Identity Forum. We then move to our two keynote speeches. We have two leading names from the world of security and identity discussing some of the most challenging strategic identity concerns. 

rob black

Rob Black

Director, Global Institute of Cyber Deception

FROM 16:10 PM to 16:40 PM

Guess Who? What Happens to Identity When You Don't Know Where Reality Starts?

Rob Black, Director, Global Institute of Cyber Deception

In the world of espionage, a false identity once required little more than a convincing story, a pair of glasses and a fake moustache.

Today, technology has made deception infinitely more sophisticated, scalable and difficult to detect. Alongside the growing influence of disinformation and digitally manufactured narratives, organisations now face a future where non-human identities move through networks, participate in conversations, influence decisions and potentially earn trust.

In this emerging age of synthetic reality, traditional assumptions about identity, authenticity and trust are being fundamentally challenged. What is left of identity when we can’t verify? How do we redefine trust when appearances, voices, behaviours and even personalities can be generated on demand? And perhaps most importantly, what comes next?

Because if we can no longer be certain who, or what, we are interacting with, we may need to rethink some of the most fundamental assumptions underpinning cybersecurity, society and reality itself.

mathew ettelaie1

Matt Ettelaie

Director, Cyber Risk & Testing, KPMG

FROM 16:40 PM to 17:10 PM

When Identities Attack: How Hackers Become You and Your Machines

Matt Ettelaie, Director, Cyber Risk & Testing, KPMG

What if the most dangerous identity in your organisation isn’t a person? What if it’s a machine, a service account, an API key or, increasingly, an AI agent; with more access than any employee could ever have?

 

As Director of the KPMG Ethical Hacking team, I spend my time thinking like an attacker: finding the paths into organisations that defenders hope don’t exist. Increasingly, those paths lead through identity.

 

In this presentation, I’ll take you behind the scenes of modern cyber attacks, using examples of our work and case studies; showing how hackers exploit both human and non-human identities to “get in, move around, escalate privileges” and ultimately achieve their objectives.

 

We’ll explore the techniques behind compromising human identity, from phishing and social engineering to deep fakes and session hijacking. We’ll also look at the rapidly expanding world of machine identities: service accounts, secrets, APIs, workloads, bots and AI agents; and why these can become an attacker’s most valuable asset.

 

The uncomfortable reality is that attackers don’t always need to break security controls and find vulnerabilities. Often we simply become an identity you already trust.

FROM 17:10 PM to 17:25 PM

Networking and Refreshments Break

Panel Sessions

1583852029725

Bruce McVicar

Head of Identity and Access Management, Wella

1541078746925

John Williams

Lead IAM Strategy Architect, Flutter Group

kalpana

Kalpana Iyer

Director, Cyber Security Advisory, KPMG

FROM 17:25 PM to 17:55 PM

Inventory Management for Agents and Non-human workloads

Every Agent and Non-Human workload should have an identity. However, can traditional approaches, including scanning and detection based approaches be sufficient for achieving this end goal? Given that the experience of securing Service Accounts in the past has been hit and miss, is there a different approach we can pursue to ensure that Agents and Non-human workloads can be brought under the remit of IAM controls, starting from registration, access control and effective lifecycle management? Is effective Inventory Management on its own sufficient or emerging capabilities like Intent Detection, Scope based actions and Skills as relevant and important? Our panel will discuss. 

 

Facilitator: Bruce McVicar, Head of identity and Access Management, Wella
John Willams,
Lead IAM Strategy Architect, Flutter Entertainment
Kalpana Iyer, Director, Cyber Security Advisory, KPMG

1517453032585

Matt Walls

Principal Security Engineer, LSEG (London Stock Exchange Group)

sheena gor

Sheena Gor

Cyber Security Engineer, ID & Access, LGC

FROM 17:55 PM to 18:25 PM

Forget New IAM Tools - How Do You Make the Most of What You've Got?

Tough times call for tougher measures. The IT landscape is rapidly changing within organisations with the adoption of AI throwing newer challenges in an already tough budget outlook. There has been an explosion of products that purport to address each and every niche use case, however budgets are limited and capability to execute is a further constraint. Sweating the assets is not just a good practice, but a necessity. Our panel of practitioners will iterate on whether it is still possible to get more from existing enterprise investments in IAM and the tactical approaches required to extend the horizon for reinvestment. 


Facilitator: Matt Walls, Principal Security Engineer, London Stock Exchange Group

Sheena Gor, Cyber Security Engineer, ID and Access, LGC
Final panellist TBC

FROM 18:25 PM to 18:40 PM

Networking and Refreshments Break

1719851232390

Manoj Kumar

CEO - Pax Identity

1517453032585

Matt Walls

Principal Security Engineer, LSEG (London Stock Exchange Group)

paul mackie

Paul Mackie

Group CISO, Fern Trading

FROM 17:55 PM to 18:25 PM

Identity Management in Multi-Cloud Environments

Organisations have deliberately adopted a multi-cloud strategy to address regulatory and data sovereignty requirements among others. As workloads started moving to the cloud, the scramble to implement access controls across cloud based infrastructure and services were taking root, just as a more fundamental question was being asked. Is there a need to build a core capability stack for effective controls across multi-cloud environments? The cost and feasibility of deploying and maintaining bespoke access control frameworks for each hyperscaler will be prohibitive. Our panel will discuss what this core access control capability stack looks and feels like and how do we go about deploying it. 

 

Facilitator: Manoj Kumar,
Matt Walls, Principal Security Engineer, London Stock Exchange Group
Paul Mackie, Group CISO, Fern Trading
Nico Corrarello, Systems Engineer, Infisical

FROM 19:10 PM to 19:30 PM

Bowl food and Drinks are Served

The event has a relaxed flow between the conference and networking areas and participants can bring their food and drink into sessions.

Solutions Spotlight Sessions

FROM 19:30 PM to 20:30 PM

In these informal sessions a practitioner presents a common identity challenge and a solutions provider presents how they would solve this issue.

kalpana

Kalpana Iyer

Director, Cyber Security Advisory, KPMG

profile pic

Dan Moss

EMEA Technical Partner Manager, Delinea

FROM 19:30 PM to 20:30 PM

IAM Solution Spotlight 1: Using PAM to Control High Risk Business Transactions

This session explores the critical distinction between technical privilege (system-level access) and business privilege (functional access within applications). Should similar approaches be taken to controlling these or are they two separate domains? Does conflating the two mean additional and unmanaged risk and complexity?


Kalpana Iyer, Director, Cyber Security Advisory, KPMG

Dan Moss, EMEA Technical Partner Manager, Delinea

1583852029725

Bruce McVicar

Head of Identity and Access Management, Wella

1719851232390

Manoj Kumar

CEO - Pax Identity

FROM 19:30 PM to 20:30 PM

IAM Solution Spotlight 2: Making IGA Entitlements Understandable

How many times do we see roles and entitlements with poorly defined entitlements? Coherent Entitlement and Role Descriptions are important for governance hygiene. Importantly, it underpins the effectiveness of access reviews, role compositions and enforcement of least privilege.

Bruce McVicar, Head of identity and Access Management, Wella
Manoj Kumar, CEO, Pax Identity

FROM 20:30 PM to 21:00 PM

Networking and Drinks