Enterprise Identity Forum 2026
The next Enterprise Identity Forum is taking place on 30 September at The National Theatre on the South Bank, London, running from 4.00 - 9.00pm.
Senior representatives of leading organisations who have already confirmed their attendance include
- Head of IAM, Global Energy Major
- Director, Cyber Resilience Centre
- IAM Leads from three management consultancies
- CISO, Global Energy Trader
- IAM Lead, Global Mineral Trader
- IAM Strategist, Global Media and Entertainment
- Country Manager UK & Ireland, Global Identity Technology Company
- Principal Security Engineer, Major Financial Trader
- Group CISO, Global Investor
- Security Architect, Security Technology Start-up
- Global Head of IAM, Global Human Resources Solutions
- IAM Lead, Global Logistics
- Head of IAM, Global Insurance Company
- Head of Enterprise Identity, UK Defence Corporation
Agenda
FROM 15:45 PM to 16:00 PM
Arrivals and Refreshments
FROM 16:00 PM to 16:10 PM
Introduction and Welcome
Keynote Presentations

Caroline Rivett
Cyber, Risk and Technology Consultant
FROM 16:10 PM to 17:10 PM
Facilitator: Caroline Rivett, Convenor, Enterprise Identity Forum
Caroline introduces the Enterprise Identity Forum. We then move to our two keynote speeches. We have two leading names from the world of security and identity discussing some of the most challenging strategic identity concerns.

Rob Black
Director, Global Institute of Cyber Deception
FROM 16:10 PM to 16:40 PM
Guess Who? What Happens to Identity When You Don't Know Where Reality Starts?
Rob Black, Director, Global Institute of Cyber Deception
In the world of espionage, a false identity once required little more than a convincing story, a pair of glasses and a fake moustache.
Today, technology has made deception infinitely more sophisticated, scalable and difficult to detect. Alongside the growing influence of disinformation and digitally manufactured narratives, organisations now face a future where non-human identities move through networks, participate in conversations, influence decisions and potentially earn trust.
In this emerging age of synthetic reality, traditional assumptions about identity, authenticity and trust are being fundamentally challenged. What is left of identity when we can’t verify? How do we redefine trust when appearances, voices, behaviours and even personalities can be generated on demand? And perhaps most importantly, what comes next?
Because if we can no longer be certain who, or what, we are interacting with, we may need to rethink some of the most fundamental assumptions underpinning cybersecurity, society and reality itself.

Matt Ettelaie
Director, Cyber Risk & Testing, KPMG
FROM 16:40 PM to 17:10 PM
When Identities Attack: How Hackers Become You and Your Machines
Matt Ettelaie, Director, Cyber Risk & Testing, KPMG
What if the most dangerous identity in your organisation isn’t a person? What if it’s a machine, a service account, an API key or, increasingly, an AI agent; with more access than any employee could ever have?
As Director of the KPMG Ethical Hacking team, I spend my time thinking like an attacker: finding the paths into organisations that defenders hope don’t exist. Increasingly, those paths lead through identity.
In this presentation, I’ll take you behind the scenes of modern cyber attacks, using examples of our work and case studies; showing how hackers exploit both human and non-human identities to “get in, move around, escalate privileges” and ultimately achieve their objectives.
We’ll explore the techniques behind compromising human identity, from phishing and social engineering to deep fakes and session hijacking. We’ll also look at the rapidly expanding world of machine identities: service accounts, secrets, APIs, workloads, bots and AI agents; and why these can become an attacker’s most valuable asset.
The uncomfortable reality is that attackers don’t always need to break security controls and find vulnerabilities. Often we simply become an identity you already trust.
FROM 17:10 PM to 17:25 PM
Networking and Refreshments Break
Panel Sessions

Bruce McVicar
Head of Identity and Access Management, Wella

John Williams
Lead IAM Strategy Architect, Flutter Group

Kalpana Iyer
Director, Cyber Security Advisory, KPMG
FROM 17:25 PM to 17:55 PM
Inventory Management for Agents and Non-human workloads
Every Agent and Non-Human workload should have an identity. However, can traditional approaches, including scanning and detection based approaches be sufficient for achieving this end goal? Given that the experience of securing Service Accounts in the past has been hit and miss, is there a different approach we can pursue to ensure that Agents and Non-human workloads can be brought under the remit of IAM controls, starting from registration, access control and effective lifecycle management? Is effective Inventory Management on its own sufficient or emerging capabilities like Intent Detection, Scope based actions and Skills as relevant and important? Our panel will discuss.
Facilitator: Bruce McVicar, Head of identity and Access Management, Wella
John Willams, Lead IAM Strategy Architect, Flutter Entertainment
Kalpana Iyer, Director, Cyber Security Advisory, KPMG

Matt Walls
Principal Security Engineer, LSEG (London Stock Exchange Group)

Sheena Gor
Cyber Security Engineer, ID & Access, LGC
FROM 17:55 PM to 18:25 PM
Forget New IAM Tools - How Do You Make the Most of What You've Got?
Facilitator: Matt Walls, Principal Security Engineer, London Stock Exchange Group
Sheena Gor, Cyber Security Engineer, ID and Access, LGC
Final panellist TBC
FROM 18:25 PM to 18:40 PM
Networking and Refreshments Break

Manoj Kumar
CEO - Pax Identity

Matt Walls
Principal Security Engineer, LSEG (London Stock Exchange Group)

Paul Mackie
Group CISO, Fern Trading
FROM 17:55 PM to 18:25 PM
Identity Management in Multi-Cloud Environments
Organisations have deliberately adopted a multi-cloud strategy to address regulatory and data sovereignty requirements among others. As workloads started moving to the cloud, the scramble to implement access controls across cloud based infrastructure and services were taking root, just as a more fundamental question was being asked. Is there a need to build a core capability stack for effective controls across multi-cloud environments? The cost and feasibility of deploying and maintaining bespoke access control frameworks for each hyperscaler will be prohibitive. Our panel will discuss what this core access control capability stack looks and feels like and how do we go about deploying it.
Facilitator: Manoj Kumar,
Matt Walls, Principal Security Engineer, London Stock Exchange Group
Paul Mackie, Group CISO, Fern Trading
Nico Corrarello, Systems Engineer, Infisical
FROM 19:10 PM to 19:30 PM
Bowl food and Drinks are Served
The event has a relaxed flow between the conference and networking areas and participants can bring their food and drink into sessions.
Solutions Spotlight Sessions
FROM 19:30 PM to 20:30 PM
In these informal sessions a practitioner presents a common identity challenge and a solutions provider presents how they would solve this issue.

Kalpana Iyer
Director, Cyber Security Advisory, KPMG

Dan Moss
EMEA Technical Partner Manager, Delinea
FROM 19:30 PM to 20:30 PM
IAM Solution Spotlight 1: Using PAM to Control High Risk Business Transactions
This session explores the critical distinction between technical privilege (system-level access) and business privilege (functional access within applications). Should similar approaches be taken to controlling these or are they two separate domains? Does conflating the two mean additional and unmanaged risk and complexity?
Kalpana Iyer, Director, Cyber Security Advisory, KPMG
Dan Moss, EMEA Technical Partner Manager, Delinea

Bruce McVicar
Head of Identity and Access Management, Wella

Manoj Kumar
CEO - Pax Identity
FROM 19:30 PM to 20:30 PM
IAM Solution Spotlight 2: Making IGA Entitlements Understandable
How many times do we see roles and entitlements with poorly defined entitlements? Coherent Entitlement and Role Descriptions are important for governance hygiene. Importantly, it underpins the effectiveness of access reviews, role compositions and enforcement of least privilege.
Bruce McVicar, Head of identity and Access Management, Wella
Manoj Kumar, CEO, Pax Identity
