Dean Watson

UK Solutions Manager, Infinigate UK&I

Identity has become the new security perimeter. Attackers no longer need sophisticated exploits – they simply log in. That shift makes Identity Access Management (IAM) one of the most critical components of any modern cybersecurity strategy. 

Since 2020, identity-driven breaches have surged. High-profile incidents across retail, finance, and government show that even well-resourced organisations struggle to defend against identity-based attacks. The takeaway is clear: if identity isn’t secured, nothing else is. 

What should a modern IAM strategy deliver?

IAM isn’t a single tool; it’s a coordinated set of capabilities: 

  • Complete visibility: Integrate across cloud, on-prem, and legacy systems to create a single source of truth. 
  • Real-time detection: Continuously analyse identity behavior to spot anomalies early. 
  • Actionable insight: Deliver clear, prioritised alerts that enable fast response.  

Detection is the real differentiator. The faster you identify abnormal behaviour, the faster you can contain risk.

What does suspicious identity activity look like?

Focus on anomalies, not signatures. Common indicators include: 

  • “Impossible travel” between login locations 
  • Sudden changes in IP address or device 
  • Activity outside normal working hours 
  • Unusual spikes in service account behaviour

These signals often expose compromised credentials before a full breach unfolds. 

How do you strengthen security without adding friction?

Risk-Based Authentication (RBA) provides a practical answer. It adapts security controls based on context and risk: 

  • UEBA (User and Entity Behaviour Analytics): Builds behavioral baselines and flags deviations 
  • Conditional Access: Triggers step-up authentication when risk thresholds are exceeded 
  • FIDO2 passkeys: Replace passwords with phishing-resistant authentication 

Together, these approaches reduce noise, improve user experience, and significantly cut attack success rates.

What does IAM-as-a-service look like in practice? 

As organisations face skills shortages and rising threats, demand for managed IAM services continues to grow. A strong offering should include: 

  • MFA or passwordless authentication (FIDO2) 
  • Policy-driven access control 
  • Identity coverage for both users and machine identities 
  • AI-driven risk analysis 
  • Workflow automation and lifecycle management 

Continuous optimisation is essential to stay ahead of evolving threats. 

How should organisations and partners approach implementation? 

Start by securing your own environment. In a world of supply chain attacks, your security posture directly impacts your customers. 

Next, standardise your identity stack. Many organisations consolidate around platforms like Microsoft Entra ID, supported by complementary technologies. 

Finally, prioritise onboarding. A structured, low-disruption rollout ensures business continuity and builds long-term trust. 

The bottom line 

IAM is no longer just a control layer, it’s the foundation of modern cybersecurity. Organisations that adopt an identity-first approach will lead in resilience, reduce risk, and stay ahead of today’s most effective attack methods.