Home
Field notes on identity security

Writing on identity & access.

Practitioner essays from the trenches of enterprise IAM — privileged access, identity governance, Zero Trust, and the controls that keep regulated organisations audit-ready. No vendor fluff; just what works.

01
26 May 2026·3 min read

Scattered Spider and the Help Desk: How a Phone Call Took Down UK Retail

In 2025, a group of teenagers cost Marks & Spencer, Co-op and Harrods hundreds of millions — not with malware, but by phoning the IT help desk and asking for a password reset. An identity post-mortem.

Incident AnalysisSocial EngineeringHelp Desk
02
26 May 2026·4 min read

AI Governance Through a Security Lens: Guardrails Before the Gold Rush

AI governance is being drafted as a legal and ethics exercise. Treat it as a security and identity problem instead — and NIST's AI RMF, ISO 42001 and the EU AI Act stop being paperwork and become a control program you can actually run.

AI GovernanceRiskNIST AI RMF
03
26 May 2026·5 min read

Securing Enterprise-Wide AI Adoption: Enablement Without the Blast Radius

The business is adopting AI faster than security can govern it. Here's how I'd scale AI across an enterprise without spawning a new generation of shadow IT, silent data leaks, and over-privileged agents.

AI SecurityEnterprise AIShadow AI
04
25 May 2026·2 min read

Decommissioning Done Right: The Quiet Risk of What You Forget to Remove

Orphaned accounts, dormant access, and forgotten leavers are the access nobody is watching — which is exactly why attackers love them. Decommissioning is a control, not an afterthought.

DeprovisioningOrphaned AccountsDormant Access
05
24 May 2026·4 min read

The Salesloft Drift Breach: When a Chatbot's OAuth Token Owns Your Salesforce

In August 2025, attackers stole OAuth tokens from a marketing chatbot integration and walked into the Salesforce environments of 700+ companies — Cloudflare, Google, Zscaler and more. The non-human identity reckoning has arrived.

Incident AnalysisOAuthNon-Human Identity
06
23 May 2026·3 min read

Identity Threat Detection and Response: Wiring Identity into the SOC

Identity is now the primary attack vector, yet most SOCs still treat it as an afterthought. ITDR is about making identity signals first-class citizens in detection and response.

ITDRSOCThreat Detection
07
22 May 2026·4 min read

16 Billion Credentials: What the Largest Leak Ever Really Tells Us

Mid-2025 brought reports of more than 16 billion exposed login credentials. The headline number is almost beside the point — the real story is the credential economy quietly feeding every other breach.

Incident AnalysisCredentialsPasswordless
08
20 May 2026·4 min read

One Missing MFA: The Change Healthcare Breach and the Cost of a Single Control Gap

The largest healthcare data breach ever recorded — around 192.7 million people — traced back to one remote-access portal without multi-factor authentication. A study in how a single identity gap becomes a national crisis.

Incident AnalysisMFAHealthcare
09
19 May 2026·3 min read

Birthright Access vs. Least Privilege: Resolving the Onboarding Tension

Generous birthright access makes day-one productive and least privilege impossible. Stingy birthright protects you and floods the help desk. Here is how I square the circle.

Birthright AccessLeast PrivilegeOnboarding
10
12 May 2026·3 min read

Governing Non-Human Identities: The Population Nobody Owns

Service accounts, API keys, tokens, and workload identities now outnumber human users many times over — and they are governed a fraction as well. That gap is the next big breach class.

Non-Human IdentityService AccountsSecrets
11
5 May 2026·3 min read

Separation of Duties at Scale: Catching Toxic Combinations Before Auditors Do

SoD is easy to state and brutally hard to enforce across hundreds of applications. The trick is detecting toxic entitlement combinations continuously, not at audit time.

Segregation of DutiesSoDRisk
12
28 Apr 2026·3 min read

Migrating PAM Without Downtime: A Field Guide for Regulated Enterprises

Replacing a privileged access platform means touching the credentials that run the business. Here is the staged approach I use to migrate without breaking production or failing an audit mid-flight.

PAMMigrationPrivileged Access
13
21 Apr 2026·2 min read

The Essential Eight Meets Identity

The ACSC's Essential Eight is framed around endpoints and applications, but four of the eight live or die on identity controls. Here is how I map them.

Essential EightACSCIdentity
14
7 Apr 2026·3 min read

Zero Trust Is an Identity Problem

Strip away the marketing and Zero Trust reduces to a single discipline: making access decisions per-request, based on verified identity and context. Everything else is plumbing.

Zero TrustIdentityArchitecture
15
31 Mar 2026·3 min read

Measuring IAM Maturity: Metrics Executives Actually Understand

Boards don't fund 'better identity governance.' They fund measurable risk reduction. Here is the capability model and the handful of metrics I use to make the case.

IAM StrategyMetricsMaturity Model
16
24 Mar 2026·3 min read

SailPoint IdentityIQ: Taming the Aggregation-to-Provisioning Pipeline

IdentityIQ is powerful and unforgiving. Most production pain traces back to the same handful of misunderstandings about how aggregation, correlation, and provisioning actually fit together.

SailPointIdentityIQProvisioning
17
10 Mar 2026·3 min read

Role Mining That Doesn't Collapse Under Its Own Weight

Role-based access control promises order and usually delivers a role explosion nobody can maintain. Here is a pragmatic model that survives contact with reality.

RBACRole EngineeringIGA
18
26 Feb 2026·3 min read

Privileged Access Management Beyond the Vault

Most organisations buy a PAM tool, vault some passwords, and declare victory. The vault is the easy 20%. The governance is where the risk actually lives.

PAMPrivileged AccessJust-in-Time
19
11 Feb 2026·2 min read

Access Certifications Without the Rubber-Stamp

Quarterly access reviews where managers approve everything in ninety seconds are theatre. Here is how to design certifications that actually remove access.

Access ReviewsIGAGovernance
20
29 Jan 2026·3 min read

CPS 234 for IAM Teams: What APRA Actually Wants to See

APRA's information security standard is written for boards, but most of its weight lands on identity teams. Here is how I translate CPS 234 into controls an assessor can tick off.

CPS 234ComplianceIAM
21
14 Jan 2026·3 min read

Designing a Joiner-Mover-Leaver Process That Survives an Audit

Most JML programs look tidy on a slide and fall apart at the leaver stage. Here is the operating model I use to make identity lifecycle defensible rather than decorative.

IAMIdentity LifecycleSailPoint