<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Aditi Shah — Writing on Identity &amp; Access</title>
    <link>https://helloaditi.au/writing</link>
    <atom:link href="https://helloaditi.au/writing/feed.xml" rel="self" type="application/rss+xml" />
    <description>Practitioner essays on IAM, privileged access, identity governance, Zero Trust, breach analysis and AI security — from 12+ years in regulated enterprise environments.</description>
    <language>en-AU</language>
    <managingEditor>adi.shah08@gmail.com (Aditi Shah)</managingEditor>
    <lastBuildDate>Tue, 26 May 2026 09:00:00 +1000</lastBuildDate>
    <item>
      <title>Scattered Spider and the Help Desk: How a Phone Call Took Down UK Retail</title>
      <link>https://helloaditi.au/writing/scattered-spider-help-desk-uk-retail</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/scattered-spider-help-desk-uk-retail</guid>
      <pubDate>Tue, 26 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[In 2025, a group of teenagers cost Marks & Spencer, Co-op and Harrods hundreds of millions — not with malware, but by phoning the IT help desk and asking for a password reset. An identity post-mortem.]]></description>
      <category>Incident Analysis</category>
      <category>Social Engineering</category>
      <category>Help Desk</category>
      <category>MFA</category>
    </item>
    <item>
      <title>AI Governance Through a Security Lens: Guardrails Before the Gold Rush</title>
      <link>https://helloaditi.au/writing/ai-governance-through-a-security-lens</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/ai-governance-through-a-security-lens</guid>
      <pubDate>Tue, 26 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[AI governance is being drafted as a legal and ethics exercise. Treat it as a security and identity problem instead — and NIST's AI RMF, ISO 42001 and the EU AI Act stop being paperwork and become a control program you can actually run.]]></description>
      <category>AI Governance</category>
      <category>Risk</category>
      <category>NIST AI RMF</category>
      <category>ISO 42001</category>
    </item>
    <item>
      <title>Securing Enterprise-Wide AI Adoption: Enablement Without the Blast Radius</title>
      <link>https://helloaditi.au/writing/securing-enterprise-wide-ai-adoption</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/securing-enterprise-wide-ai-adoption</guid>
      <pubDate>Tue, 26 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[The business is adopting AI faster than security can govern it. Here's how I'd scale AI across an enterprise without spawning a new generation of shadow IT, silent data leaks, and over-privileged agents.]]></description>
      <category>AI Security</category>
      <category>Enterprise AI</category>
      <category>Shadow AI</category>
      <category>Non-Human Identity</category>
    </item>
    <item>
      <title>Decommissioning Done Right: The Quiet Risk of What You Forget to Remove</title>
      <link>https://helloaditi.au/writing/decommissioning-done-right</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/decommissioning-done-right</guid>
      <pubDate>Mon, 25 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Orphaned accounts, dormant access, and forgotten leavers are the access nobody is watching — which is exactly why attackers love them. Decommissioning is a control, not an afterthought.]]></description>
      <category>Deprovisioning</category>
      <category>Orphaned Accounts</category>
      <category>Dormant Access</category>
      <category>Hygiene</category>
    </item>
    <item>
      <title>The Salesloft Drift Breach: When a Chatbot&#x27;s OAuth Token Owns Your Salesforce</title>
      <link>https://helloaditi.au/writing/salesloft-drift-oauth-breach-analysis</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/salesloft-drift-oauth-breach-analysis</guid>
      <pubDate>Sun, 24 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[In August 2025, attackers stole OAuth tokens from a marketing chatbot integration and walked into the Salesforce environments of 700+ companies — Cloudflare, Google, Zscaler and more. The non-human identity reckoning has arrived.]]></description>
      <category>Incident Analysis</category>
      <category>OAuth</category>
      <category>Non-Human Identity</category>
      <category>Supply Chain</category>
    </item>
    <item>
      <title>Identity Threat Detection and Response: Wiring Identity into the SOC</title>
      <link>https://helloaditi.au/writing/identity-threat-detection-and-response</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/identity-threat-detection-and-response</guid>
      <pubDate>Sat, 23 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Identity is now the primary attack vector, yet most SOCs still treat it as an afterthought. ITDR is about making identity signals first-class citizens in detection and response.]]></description>
      <category>ITDR</category>
      <category>SOC</category>
      <category>Threat Detection</category>
      <category>Identity Security</category>
    </item>
    <item>
      <title>16 Billion Credentials: What the Largest Leak Ever Really Tells Us</title>
      <link>https://helloaditi.au/writing/sixteen-billion-credentials-leak-analysis</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/sixteen-billion-credentials-leak-analysis</guid>
      <pubDate>Fri, 22 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Mid-2025 brought reports of more than 16 billion exposed login credentials. The headline number is almost beside the point — the real story is the credential economy quietly feeding every other breach.]]></description>
      <category>Incident Analysis</category>
      <category>Credentials</category>
      <category>Passwordless</category>
      <category>MFA Fatigue</category>
    </item>
    <item>
      <title>One Missing MFA: The Change Healthcare Breach and the Cost of a Single Control Gap</title>
      <link>https://helloaditi.au/writing/change-healthcare-one-missing-mfa</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/change-healthcare-one-missing-mfa</guid>
      <pubDate>Wed, 20 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[The largest healthcare data breach ever recorded — around 192.7 million people — traced back to one remote-access portal without multi-factor authentication. A study in how a single identity gap becomes a national crisis.]]></description>
      <category>Incident Analysis</category>
      <category>MFA</category>
      <category>Healthcare</category>
      <category>Blast Radius</category>
    </item>
    <item>
      <title>Birthright Access vs. Least Privilege: Resolving the Onboarding Tension</title>
      <link>https://helloaditi.au/writing/birthright-access-vs-least-privilege</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/birthright-access-vs-least-privilege</guid>
      <pubDate>Tue, 19 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Generous birthright access makes day-one productive and least privilege impossible. Stingy birthright protects you and floods the help desk. Here is how I square the circle.]]></description>
      <category>Birthright Access</category>
      <category>Least Privilege</category>
      <category>Onboarding</category>
      <category>IAM</category>
    </item>
    <item>
      <title>Governing Non-Human Identities: The Population Nobody Owns</title>
      <link>https://helloaditi.au/writing/governing-non-human-identities</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/governing-non-human-identities</guid>
      <pubDate>Tue, 12 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Service accounts, API keys, tokens, and workload identities now outnumber human users many times over — and they are governed a fraction as well. That gap is the next big breach class.]]></description>
      <category>Non-Human Identity</category>
      <category>Service Accounts</category>
      <category>Secrets</category>
      <category>Machine Identity</category>
    </item>
    <item>
      <title>Separation of Duties at Scale: Catching Toxic Combinations Before Auditors Do</title>
      <link>https://helloaditi.au/writing/separation-of-duties-at-scale</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/separation-of-duties-at-scale</guid>
      <pubDate>Tue, 05 May 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[SoD is easy to state and brutally hard to enforce across hundreds of applications. The trick is detecting toxic entitlement combinations continuously, not at audit time.]]></description>
      <category>Segregation of Duties</category>
      <category>SoD</category>
      <category>Risk</category>
      <category>IGA</category>
    </item>
    <item>
      <title>Migrating PAM Without Downtime: A Field Guide for Regulated Enterprises</title>
      <link>https://helloaditi.au/writing/migrating-pam-without-downtime</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/migrating-pam-without-downtime</guid>
      <pubDate>Tue, 28 Apr 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Replacing a privileged access platform means touching the credentials that run the business. Here is the staged approach I use to migrate without breaking production or failing an audit mid-flight.]]></description>
      <category>PAM</category>
      <category>Migration</category>
      <category>Privileged Access</category>
      <category>Programme Delivery</category>
    </item>
    <item>
      <title>The Essential Eight Meets Identity</title>
      <link>https://helloaditi.au/writing/essential-eight-meets-identity</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/essential-eight-meets-identity</guid>
      <pubDate>Tue, 21 Apr 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[The ACSC's Essential Eight is framed around endpoints and applications, but four of the eight live or die on identity controls. Here is how I map them.]]></description>
      <category>Essential Eight</category>
      <category>ACSC</category>
      <category>Identity</category>
      <category>Hardening</category>
    </item>
    <item>
      <title>Zero Trust Is an Identity Problem</title>
      <link>https://helloaditi.au/writing/zero-trust-is-an-identity-problem</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/zero-trust-is-an-identity-problem</guid>
      <pubDate>Tue, 07 Apr 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Strip away the marketing and Zero Trust reduces to a single discipline: making access decisions per-request, based on verified identity and context. Everything else is plumbing.]]></description>
      <category>Zero Trust</category>
      <category>Identity</category>
      <category>Architecture</category>
      <category>Access Control</category>
    </item>
    <item>
      <title>Measuring IAM Maturity: Metrics Executives Actually Understand</title>
      <link>https://helloaditi.au/writing/measuring-iam-maturity</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/measuring-iam-maturity</guid>
      <pubDate>Tue, 31 Mar 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Boards don't fund 'better identity governance.' They fund measurable risk reduction. Here is the capability model and the handful of metrics I use to make the case.]]></description>
      <category>IAM Strategy</category>
      <category>Metrics</category>
      <category>Maturity Model</category>
      <category>Leadership</category>
    </item>
    <item>
      <title>SailPoint IdentityIQ: Taming the Aggregation-to-Provisioning Pipeline</title>
      <link>https://helloaditi.au/writing/sailpoint-aggregation-to-provisioning</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/sailpoint-aggregation-to-provisioning</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[IdentityIQ is powerful and unforgiving. Most production pain traces back to the same handful of misunderstandings about how aggregation, correlation, and provisioning actually fit together.]]></description>
      <category>SailPoint</category>
      <category>IdentityIQ</category>
      <category>Provisioning</category>
      <category>IGA</category>
    </item>
    <item>
      <title>Role Mining That Doesn&#x27;t Collapse Under Its Own Weight</title>
      <link>https://helloaditi.au/writing/role-mining-that-doesnt-collapse</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/role-mining-that-doesnt-collapse</guid>
      <pubDate>Tue, 10 Mar 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Role-based access control promises order and usually delivers a role explosion nobody can maintain. Here is a pragmatic model that survives contact with reality.]]></description>
      <category>RBAC</category>
      <category>Role Engineering</category>
      <category>IGA</category>
      <category>Access Models</category>
    </item>
    <item>
      <title>Privileged Access Management Beyond the Vault</title>
      <link>https://helloaditi.au/writing/pam-beyond-the-vault</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/pam-beyond-the-vault</guid>
      <pubDate>Thu, 26 Feb 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Most organisations buy a PAM tool, vault some passwords, and declare victory. The vault is the easy 20%. The governance is where the risk actually lives.]]></description>
      <category>PAM</category>
      <category>Privileged Access</category>
      <category>Just-in-Time</category>
      <category>Zero Standing Privilege</category>
    </item>
    <item>
      <title>Access Certifications Without the Rubber-Stamp</title>
      <link>https://helloaditi.au/writing/access-certifications-without-rubber-stamping</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/access-certifications-without-rubber-stamping</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Quarterly access reviews where managers approve everything in ninety seconds are theatre. Here is how to design certifications that actually remove access.]]></description>
      <category>Access Reviews</category>
      <category>IGA</category>
      <category>Governance</category>
      <category>Least Privilege</category>
    </item>
    <item>
      <title>CPS 234 for IAM Teams: What APRA Actually Wants to See</title>
      <link>https://helloaditi.au/writing/cps-234-for-iam-teams</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/cps-234-for-iam-teams</guid>
      <pubDate>Thu, 29 Jan 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[APRA's information security standard is written for boards, but most of its weight lands on identity teams. Here is how I translate CPS 234 into controls an assessor can tick off.]]></description>
      <category>CPS 234</category>
      <category>Compliance</category>
      <category>IAM</category>
      <category>APRA</category>
    </item>
    <item>
      <title>Designing a Joiner-Mover-Leaver Process That Survives an Audit</title>
      <link>https://helloaditi.au/writing/joiner-mover-leaver-that-survives-an-audit</link>
      <guid isPermaLink="true">https://helloaditi.au/writing/joiner-mover-leaver-that-survives-an-audit</guid>
      <pubDate>Wed, 14 Jan 2026 09:00:00 +1000</pubDate>
      <description><![CDATA[Most JML programs look tidy on a slide and fall apart at the leaver stage. Here is the operating model I use to make identity lifecycle defensible rather than decorative.]]></description>
      <category>IAM</category>
      <category>Identity Lifecycle</category>
      <category>SailPoint</category>
      <category>Governance</category>
    </item>
  </channel>
</rss>
