The conversation explores Identity and Access Management (IAM) as the core of digital transformation. Chris and April discuss how IAM underpins digital interactions, moving from big tech-controlled gateways to user-centric models like decentralized identity. They highlight the persistence of passwords as a security and usability issue, advocating for biometrics and MFA to reduce friction. For less technical users, simple physical password storage is preferred, while inclusive design addresses socioeconomic barriers. Chris advises companies against building custom IAM solutions, recommending partnerships with specialists to optimize resources. IAM is often deprioritized in cybersecurity, but elevating it can enhance security, revenue, and user experience. The dialogue underscores the need for balance between innovation, accessibility, and strategic resource allocation.
(upbeat music) - April. - Chris. - April George. - Chris Macauin. - 20 years? - 20, yeah, I think so, 18 maybe. - That's what we just said before, when we met some of my colleagues. 20 years, I'm thrilled that life and its patterns have brought us back together. All this time, it's crazy, right? What were you doing when I first met you? - I was like, help this school. - Yeah, I think it was in a call center for like an online media company or something like that, selling physical CDs. - Yeah. - It was not. - It was not my life's work. - And then, was it your finest work there? - I mean, I was pretty good at it, to be fair. - Yeah, okay, that's probably why you got the job at late in all that time of year. And now you're in identity access management. - Yeah, yeah. - You're a rookie. And you're the learned but still learning person that's gonna help me understand this. - Yes. - I hope. And. (laughing) - I hope too. - Because, you know, as with all of these things I do, I don't really wanna tend that I have the knowledge around it, but that's the point. And I feel like many of the people that I work with or listen to this podcast of people are interested in these things as well. So why don't we just start off really simply, but classically for me, it's never simple. There's this thinking at the moment that says that identity access management is the core of the next wave of digital transformation. - Yeah. - And there's been variations of that theme I think around customer and but, but we're specifically talking about the access management of the core of the next wave of digital transformation. - Yes. - And what is that and why? - Look, I think identity is one of those abstract terms that people hear and they may not really gel with, but every single one of us in almost every interaction we have in a digital capacity. - Mm-hmm. - There is some form of identity and access management, fundamentals going on behind the scenes. So if you take, I always use retail, 'cause everyone's had to go and shop for a thing, right? When you're in a store and you're physically interacting with a retail assistant, they're able to get an idea about who you are based on how you dress, how tall you are, how you look, and then help you create a customized experience within that store, because they physically see you and you are a manifestation of your personality and your traits, right? In a digital format, we all assume an anonymity. So if I go online to any sort of online retail experience, that first interaction I am an unknown. So when it comes to e-commerce specifically, what retailers look to do is create a more personalized experience for you without needing to gather too much information. And us as retailers and consumers, we actually expect sort of, I wouldn't call it tailored advertising, but we expect to go onto a storefront somewhere that we've been before and see a history of what we have purchased and expect recommendations based on our previous interactions, right? Now at the fundamental core of all of that is identity and access management and having an understanding of who you are in the same way that we do in the physical world, except digitally. So that can go in a million different ways, but retailers, one that I think people all grasp because we all do shop at various points in our life. - So I'm gonna replay it to make sure I understand it. It's basically so when I go on a retail website in this particular case, I want to be able to, in fact, not want, I expect that retailer to have enough information about me to make my experience more seamless, class, identity access. - So the two main things that I think about there is, what is the gateway to that identity, what's the protocol for identity which is secure? And then the second thing is, you know, how transferable is that identity to places where I haven't shopped? I mean, right now I shop at Google, let's say, and my details prove properly, but I don't want to do that. Personally, I don't want that anymore. I want something else which feels like my data isn't being, you know, used, you know, nefariously by a big tech. But I use it because it's convenient. So there's many things. So, you know, when I've been talking about this, I've been going so far as, you know, multi-factor authentication, which is beyond just password and numbers, but maybe it's something genetic. So I've got, how do you access it to make sure it really is protected? And the second thing, how do you, you know, extrapolate that data across multiple channels, but without it being able to get it by Google or am I in the fantasy land? - No, I think, and that's kind of where we find ourselves right now. So in the current digital ecosystem that we work within, it is gated by major tech or major financial organisations. And what we're seeing is more and more, the end user, people like you and I, are wanting more control over the information that companies have about me. And so we're seeing a huge shift in the way that both organisations view storing data and getting consent for having that data and also the expectation of users as well. And now there's a lot more sort of cutting edge protocols that are being released and there's some stuff based on blockchain, decentralized identity. There's all these sort of new ways of dealing with removing the onus from large organisations and putting them back into the hands of you and I, which I think we'll see more and more. But realistically, what we're working with is still a ecosystem or many ecosystems, which are based on this foundation of storing information and credentials, passwords, et cetera, about individuals. - So, okay, so we're playing it again. We are at a point of transition. We're not done yet. Big tech is really still the gateway. And this is about identity governance, I guess, is another theme at my mind, okay, so. What we're asking the big tech companies to do, and please tell me if I'm not repeating this right, is about consent for data, how they store the data, what they can do with the data, so there's the governance there. But then there's a next wave, which is decentralized gateways of data like blockchain. I'm gonna come back to decentralized blockchain and ask about that, 'cause I don't know if I told you but today I have interested in my own blockchain, and I'm fascinated by will it or won't it take? Gonna come back to password and the experience of that. I was reading on your company website actually about the loss of revenue for people not remembering passwords. - It's crazy. - Well, my mate was on the weekend, trying to buy something. Even though Amazon was something. And he was literally like, "F my life, I can't remember the password, I just wanna buy this thing." - Yep. - So when are we ever gonna get beyond passwords and then Google Authenticator or the Authenticator, whatever it's called? By the way, I hate the new Google logo for that. I don't know why they've got that star, it doesn't look right to me, but. - No, but what's that about? - Yeah, yes, we are, and we do have the tick to do it now. - But what would it be? - Choice. That's really fundamentally what it comes down to. Allowing consumers choice. There are fundamentally stronger authentication factors, which is what we call them, so things like biometrics, face ID, windows, hello, that sort of thing. - What's that? - It's the Windows computers can scan your face and log you in automatically using your like a face scan, similar to face ID on a iPhone. Windows computers can do that as well, and then touch ID for Android and Apple stuff. It's using biometrics effectively, things about you as a human and individual person, and utilizing those to log you in. I think, in like, having known you 20 years now, - 18. - 18, sorry. When I first started in IT, MFA was those six digit little fog things that you'd have on your keys, and it was just a pain, and if you had your keys in another room, you couldn't log in, and I think there's still this perception that MFA makes things more difficult, whereas you can actually have very strong authentication without passwords and have it be very easy. You can just, you're on a Mac right now, you can just touch the keyboard, log right in, right? Those sort of capabilities exist out in the wild. They're being deployed internally at work.
ki, kahwinio. kaهin i seno. parana che hun o bapital o helping synagogue parana parana venita venita mutateتم bask Croatia VND 10 сов I I I Annath I I am in tech and I am embarrassed to say that my password storage solutions I don't know how to It's so confusing to me and I'm like why why is this so hard and My I have a protocol for remembering my passwords, but I do I have to keep them in my head Yeah, and we as humans are not built to remember long strings of numbers and characters that are randomized So we will reuse similar patterns same passwords and Unfortunately when breaches occur and credentials are stolen the first thing Advertisers will do is use those pairs on any number of websites to try and get access to One of the tens of thousands if not millions of accounts that have managed to get the Username password pair of If you had a number one tip for people who use passwords today an enaming protocol to remember them I don't give away your own practical. Do you do you have a tip for mere mortals like me? Use a password generator and storage device storage system I really was hoping you wouldn't say that I know a used to have a bit of a party trick when I first started in cybersecurity Where I would guess someone's password at a party someone I just met I'd go into their Facebook I'd find a little bit of information about them I'd probably be able to tell them their date of birth and also their mother's maiden name which at the time was enough of a red flag because you could use that to like ring up a bank Simple there are simple tools and mechanisms because we share so much about ourselves Especially online so I should change my password from password 100% okay good just checking and no one listen to this Please until I've changed my passwords. Yeah, you're a couple of days Okay, so We were talking about password alternatives to access and you're talking about biometrics is the path Password using password generators and storage unfortunately which is beyond My comprehension technically so therefore how does it you know my mum? You know and we talked about this right how do all our less technical family members access this and I know That's in your one reason you do this as we talked about So what does mum do like she's not gonna do that. Yeah Look The funny thing is as Insecure as it seems I would prefer any of my older family members to use a notepad of passwords Then to try and create a digital version of that. All right, at least it's something physical. It's in their home It's like unless they're gonna get robbed which that's already gonna be a big enough issue in and of itself At least that way they have the ability to Create passwords that are a little bit stronger and is somewhere that they can access it right Ideally though my hope is that organizations do roll out easier ways of of logging into platform securely I know that one-time passwords getting sent by SMS is not the most secure method in the world But it's accessible and people understand it and it's it's better than some of the alternatives out there but yeah look Access technology for for people who are a less technically literate or even less affluent and can't afford The devices that would be required It's something that it's a problem space that exists and unfortunately a lot of Experiences are crafted for without thought of those ecosystems. I think government and Healthcare actually have it a lot harder because they actively Consider the outliers which can often mean that it's harder for them to Modernise and move forward because they are trying to capture a much larger audience than maybe your you know start up tech company whatever consider But trying to find that balance is always going to be tough and something that I always try to Consider waiting for why talk to organizations as well Yeah, I am I mean inclusive by design is important I was even Talking about one of our customers at the moment who has a particular icon You know, I think it's okay to say who you work for yeah, yeah, of course you worked for octa or all Sarah and we were talking about the I icon for password reveal in yours versus Accessibility requirement and what the icon has to look like and a configuration of design for accessibility You know as you know, I just spent five years in this before before this really and You know it's not it's not perfect but as a starter by find inclusivity by design also means cost and we're the type of Scaler by should say there was a lot of people come to for accelerated delivery not necessarily cost yeah That's some bigger international consultant in ours. So it's a tricky space I want to come back to that because you mentioned something which I know is important to you which is about This affluent and access to technology and not necessarily being generational but Social economic and but we'll come back to the second of it's okay the I was asking about the type of passwords biometric I was talking about But blockchain experiences or something future technology experiences waiting to access it so if you could Talk to companies about about this You know openly and you do I know you do But say anything to them about what they should be fundamentally thinking about to preserve Their efficiency or their revenue or I mean, I know these are themes that again I picked up from from the beginning so to revenue to efficiency to survival. It's you experience You know rich richness, right all that stuff. Let's just go. It's about evil What what do they need to do tomorrow to make sure that the people that Do embrace Customer identity as call yeah, make sure they keep up with those guys like what should be happening there? What's the advice? I think the biggest piece of advice I could give and and a lot of companies do this is They undertake this Huge expedition of building everything themselves building everything from scratch and fundamentally Very few companies on earth are making their money from building identity solutions So why would you invest Engineering time and effort into building your own identity solution? I think that would be the thing that I get them to to think about at a core fundamental level how much is this go at my self? costing me and Does that way up the benefits we're getting at a business level from a security checking boxes risk governance point of view But as a business if I'm investing I don't know the time of three developers full time over the course of a year to feed in water my Identity platform and my getting the return on that that I would expect from a business revenue profit perspective Fast majority of the times the answer is no So that would be the first thing I'd look at unfortunate part to those When it comes to cyber security broadly, and this is just stepping away from identity itself CIOs, Sizos generally have a list of tens if not hundreds of risks they need to try and resolve identify and solve for Identities often not high on that list It is becoming more so because people are understanding that there is
a cross-synchion between security experience that requires a solid identity framework, but that's not every organisation. Not everyone looks at it in that way. So a lot of times it will be looked at as the last thing to solve. You'll generally look at other things like vulnerability and potentially moving to the cloud or even protecting the cloud environment that you're building and things like that. So it depends on where you are on your identity journey. I guess how mature that identity journey currently is within your ecosystem that you're looking at, but definitely step away from the whole, are we doing it well enough and start looking at, can it be done better if I partner with someone who specialises in this and does this for a living rather than us? I'm just going to, I mean, I'm just going to. Obviously your words got to me emotionally. I'm just going to check in on that because maybe I shouldn't have invited you here because we're an organisation that advocate to build it yourself. There's a bit of a caveat to that. And this is why we're in the room together. We are a build at yourself, digital portal organisation. As I've learned recently, most of that bespoke build about access has been underpinned by author or zero and others, right? And our biggest customer and our newest customers, I keep saying this. And so this has been a revelation for me and this is why I'm exploring as an Aboriginal understand it. And I didn't know that for my technologist. It didn't come up in two years of Thunderlabs ever that was it until it did, until the recent work that you guys have seen us do. And then it's like, yeah, we do this all the time. And so it just shows me that when we're building rapid pilots and using our own methodologists to do so, even we follow that advice that you've just given. And there is attention in that. There is attention that we, I'm not saying, I'll use the author or zero. I'm not saying that what I'm saying though is it's just been a revelation for me that we, that's what we do. I think there's an element of resource scarcity in that too. Because I think no matter who you are, what company you're with at the moment, especially in the current economic climate, there is a level, and I don't know where it's occurring in your own business or wherever of resource scarcity, whether that be people, money, investment, whatever. And so you have to think about where the resources you do have a best invested, right? Whether that be people or money or whatever. So if you can take away a huge chunk of that, you say, and I'm not just looking at identity here, it's anything else that's taking up a lot of time and resources that you could offload elsewhere, why wouldn't you use a Thunderlabs? Why build it yourself? Come and use people who do this day and day out. So that's a sort of secondary access to people that can or are in question. I don't think I'd ever advocate bi versus build. I choose who's your expected choice, choose the right path. Exactly. But at least ask the experts. And ask the question of yourself and your teams, is this the right place for us to be speedening these resources? Maybe. And that's fine. If it's like the second piece of advice you gave about bringing identity onto the list and elevating it up the ranks of important things, because if you do elevate it, I can imagine all the periphery systems that hang off of identity. It changes the strategy around that, whether it's just everything. It does. So one of those, you know, I've been doing this for a long time and the unfortunate part of it is there's very little fanfare in kudos, but the moment it doesn't work, everybody knows. It is one of those things. When it works, you kind of forget about it, which is what you want to happen. Yeah, I think someone said to me today earlier that success is ascribed to the environment whereas failure is attributed to the individuals or the company. So, you know, it's a bit that way, isn't it? When you think of, and again, you know, I'm going back not this current role or the role of the situation before, but when you think about service transformation that have been achieved through identity like a case do you know on it and maybe we'll leave the names out so it doesn't get weird. I don't want people to think that we're flogging anything or advertising. I'm just interested in what's the thing that you think of that you've seen done best, where someone's really, you know, brought identity to the core of transformation, really thought about it, and then and then moved forward. Like, what would the, let's start with the benefits or the results first, you've done, no matter what happened there. I think the most successful transformation projects I've ever been anywhere near have started with people at the centre of the change. It's not a technology thing, it's not anything to do with throwing in a new shiny tech stack, but actually looking fundamentally at people, how they are either doing their roles or engaging with your platform, and then using that to determine the identity strategy. Anyone can throw a new shiny toy around, but without that basic understanding of where are you right now with your user experience and where are you trying to take it. It's just going to be a shiny toy that no one's probably going to like using anyway. So the success is about putting people at the centre. I wonder if you think that one of the distinctions my co-founders given me, it's not about the business, it's about the customer. The customer can be workforce, can be, you know, someone is spending their money with you, so it's the customer, not the business. So I would know, transformation start with people's generic, but transformation start with the customer at the centre. And it feels like we're in danger of being motherhood by sound, because everyone says that everyone says our customer first. You know, I'm working on our values and mission and strategy for the next year, you know, and I'm deep reflecting on this. And I feel almost a cliche, you know, saying it, right? But it's so true. Yeah, it's almost so common sense. If it is so easy, why doesn't everyone do it? And the thing is, it's not easy. It's not easy to identify that people's element of what you're trying to do, whether that be just how someone engages or even how we expect the next employee to onboard, you know, and having so many differing opinions can often make it feel hard and a bit, um, decision by council to have an understanding, but, you know, at the core of it, I think we're all just trying to connect meaningfully. And that's really what drives choices, and it comes to identity strategy in my opinion. You're landing on somebody else there, things really sing, things to me. Whenever I try and do a broad-based decision to many people in the room, it just gets lost. You know, you spend hours and hours going to and for, oh, and I'm talking even internally in my own company, and it's my company, about it. Um, the, and I think about the way our project's division won, and this isn't something I've held as a truth till this moment, in fact, as a revelation, that maybe that's why the methodologies that our guys use, the spot and method is that way. Maybe that's why the text go, only three people, plus a customer in the room. Those three people are there to bring to life the vision of the, of the customer and code it to show them what's being coded as it being, you know, described. Because this complexity and there's loss of resonance in, you know, when there's lots of people in the chain, I think that's a lot of what, of what goes on. And so again, not a long-held belief, but maybe a revelation of why the, the principles of what our teams do kind of works. Mm-hmm. Um, hopefully my co-founders and technology people aren't listening to this, because they probably think now I should know this already. Okay, so we talk about a transformation with customers at the centre. We've talked about, you know, considering your options of building, you know, building versus buy, but consider if you've got the world's experts and something to use them. And, and then, you know, bring an identity onto the list of priorities and perhaps even elevating it and think about it is, as core to how the whole ecosystem holds together. Right. Okay. Um, so,
Ys gyd yn fawr yn fawr am yn fawr o ymwch chi. O'r ysgwch chi'n fawr am cyflwydu. Ym gweld ymwch chi wedi gyda'r sgwch chi wedi gweld ymwch chi wedi yn fawr am cyflwydu. Yw'ch chi wedi cyflwydu i wedi gweld ymwch chi wedi yn fawr am cyflwydu i wedi yn fawr. Ym gweld ymwch chi wedi yn fawr am cyflwydu i wedi'r fawr am cyflwydu i wedi yn fawr am cyflwydu i wedi yn fawr. disrupt Maeth Hwynn a Llywch cl One Cyf wirs ou P Taylor Rhaenniau 189. Tath no conis yr Gr сер commadol y sydd llawer y matem gofns, swyddi ddeud hyn ym snack. Maeth Hwynn a listais llw�'s yd effectively'n murdfa newyddwyr wandai'r matem dd對 me sa bosf ' Türkiye Dardyzol Doctor Akub badges i18, Tath chi Shiilldoedd. Waithётraedd ein gyמן selwn beth, ff'r mynd yn ddoedd baird μwffod beth beth o'r 반ul 오빠 Netthrow wntau Wasad o techn here complications'no förswpfa a Smeidunionhefgy. herniol
マ nice wnaethu wedyn lle eithaethen esata stretches wnaethael a'r puref engid Pepper dot an字 Been in, deitig og hon eithaf eu fydd Ipar 양hau u my Ethan Jaid D生 a'r puref engid a'r puref engid a'r puref engid Think about that wallet experience and you have, I don't know, stored within there a number of what we call verified credentials. So one may be a verified version of your driver's license, maybe your passport, maybe some other credential that a trusted organisation has created for you, but you now store inside the equivalent of your phone's wallet, digital wallet. Now what verified identities looking to do is allow you to share the bare minimum information for you to achieve a service outcome. So I always like using the analogy of going to buy booze at a bottle shop. For the purposes of purchasing alcohol and proving you are over 18, all in organisation needs is a photo, so that you can match your face to that photo. And some form of tick that says you are over 18. What we currently give them, is every single piece of information we have on our driver's license. If you think about some of the clubs and bars in Sydney, they also take scans of those. So we're handing over so much information for the purposes of just proving that we're 18. Maybe in the case of clubs, you do also need to prove that you're outside of a certain range. But we hand over so much of our own personal identity. Two organisations where we have no certainty over how they're storing those, how they're destroying it, how they're recycling it, that sort of thing. Decentralised identities is looking to allow you to share only what is needed and keep all the rest. And then that, you know, bar club, bottle shop, they can just validate that, yes, that is a, you know, New South Wales government issued checkmark. They're over 18. I'm fine. So it's really about putting power back into your hands as a consumer and allowing you to share only what you want shared. And then also moving forward with mechanisms of how to also, like, unconcent from having that in another database as well. So that's kind of where things are going. There are some technologies out there now. So, there are also verifiable credentials, which is what I mentioned, that are available in being used in certain contexts around the world. But, you know, again, adoption, there's also a level of education that people like you and I will need to go through to understand how to use this shopkeepers, et cetera, et cetera. But that's where we're seeing things heading from a privacy perspective and what users would be looking to gain in the future. So, I understand the case to the UK, that you've got verified identity sources that access to the Biosquare example. So they just see the important stuff. The same principle applies that my decentralized identity platform could be the gateway to Google where I buy things. But I guess we're moving into a world where my platform is direct access to vendor, customer direct access to seller, which then to mediate the Google's and whatnot of the world. So, you know, I know we're stepping into Web 3 commerce type thing, but, you know, I'm definitely not an expert. So maybe someone is there. But invite someone else along in the next time we talk about that. You know, I don't have the top of my mind any plays in that space that are in blockchain identity. Do you know anyone that does it? There are actually one of the ones I know of is a small. Well, I don't know how small they are anymore, but they're actually from New Zealand. It's a company called Matter. All the best people are. Matter. M-A-T-T-R. M-A-T-T-R. Yeah. We also have our own version of it. How do you? Yeah, yeah. It's in labs at the moment, so you can actually. cael ei gwofalliwn i dddi mis gydaf gerwfoliach þa dda gienno ni mae gy sgina gifog seria hyn yn cyndi barwyr rhau falddiwn. Ten ma أناel rhau 'Ftawla. Gwas ar gyda poder l capitwydd wneud unrhyblygu bod yn Ydd spicesyn ar y cyhesio i'r hyndi gheeod. ph変isant gyda'r gefnnndi barwyr rhau haus, hun cwbrywoli lime y Half Xiann, yna yn dun, yna, yn ymgwyr i'n gwasyn cydyni barwyr rhau, mae'r rhau'r cyhesio i'r yna, yna, yna, yma, yma, yma. Mae'r cyflwydd, yn yna, yma'r cyflwydd, yma. Mae'r cyflwydd, ac yna, yna, yma'r cyflwydd, yma, yma. Mae'r cyflwydd, yma. Mae'r cyflwydd, yma, yma. Mae'n gwaith, mae'n gwaith, mae'n gwaith, mae'n gwaith. Mae'n gwaith, mae'r cyflwydd, mae'n gwaith, mae'n gwaith, mae'n gwaith. Hy強 ni yw'r botedd sallot Djな Turan y Lleydd Lle亏dfa toydda. Ond mae arall, i cyfryd daill, hiser Rymor, yna gwis mewn fel fod ydym rebau areawn fawr ag erauna. Ono um, ar 충분au', janaw wedi wahanotheroial, on Ofwys'n gyd evolveneffy thaw mewn. Mae fowr tweig bod Ond go, parameters y lle. Sof, mae'r glyfru yn ddair oll o gyfer Rastygo? Ji sy'nitating o ymfa. 10% yn unidi wrth있 ei\ 4%u yn cyn barw'r hynny. Fly gymsighs ar y roff. Mae yma yn gwyr. Mae'r teulu. Mae'r cyfyllwyd. Mae'r cyfyllwyd ei gael ei genneunu i Shelen. Mae'r genneu'r tiwn hyn yn uniddiwfiaeth ein 'FL scroll' ond armed ozedig. Rydym yn edig dr 구독 charto Jim Niekoan yn ymfa. Mae'r cyfyllwyd yn ymfa. Mae'r cymershawr ymfa. beth, beth, beth, beth, beth, beth, beth, beth, beth, beth, beth, beth, beth. So one of the things I have always thought back to was, you know, what could I have shown 16-year-old April that she didn't see that might have helped make sure she knows that this is the right journey, you know. And really, I always keep coming back to visibility. When I was young, there was no one in tech that looked like anything like me. You know, Maori, female, queer, you know, all of the diversity boxes. So there was no role model for me to model myself or look up to as, as she can do it, I can do it. So I'm very conscious of that now. And that's why I do try to lend my voice and face to as many diversity and inclusion, schools, associations, chats, whatever. Because if just that one person, that one girl that maybe looks like me or maybe grew up where I grew up, kind of looks at him and goes, she can do it, I can do it. That would be success in my books. So, you know, and there are definitely some organisations or teams where hiring diversity for diversity is the thing. You know, like the next hire must be X, Y and Z, that doesn't work. Because now you're giving up places for maybe potentially people that are more worthy of that spot for the sake of what, like a checkbox, a tick box, that kind of thing. So I think having a goal towards what your diversity outcubbers, whether that be 50% female, whatever that might be, 30% more than today. And using that as your cornerstone rather than we just need to tick all these boxes. That is a better way of approaching that kind of thing than I have seen in the past. But you have representation matters. Knowing seeing something is really understanding that you can do it and be it too. Yeah, it's called my friend Gustav Psychologist, which is a previous episode was telling you about it's something to do with association, like let's just say, association confirmation you see it and then you know, you know, because you've seen it. You don't have to be the trailblazer. Nothing wrong with that. But known to someone's been before. Yeah, not everyone can do that and have the resilience to just continue to trailblazer, I think. It's all about sort of, I guess, you would all sort of push at that ceiling over time, one after the other. But having seen someone else walk that path before you just gives you confirmation that it's possible. So it just takes some of that anxiety away from you. Yeah, it's a, yeah, it's a, it's a quandary. I'm pausing to go, how do people want to go on that particular thing? Yeah, well, you know, we've got four hours a day as well. If we keep going, we'll be a bit of time before we know. Yeah, I, yeah, I guess the fact that I'm even unable or unwilling to express myself is an example of where I think things are because people who want to do something in this domain. Who are thoughtful. I think you're withdrawing a little bit. I do. I feel, I feel, I feel deeply frustrated that I can't make a difference seems to be and any momentum seems to be hard. And just, you know, and I think I told you, I feel like I put my business at risk by trying to do certain things, sponsor certain things. And, you know, when you just bunched in with everybody else, you may as well be like everybody else. And that's just a really, you know, I find it an area of deep personal tension. Having just having said that we are making our first progress, our first funded apprenticeship apprentice, like a plumber comes in, but is learning to code. So we made progress, but two years, two years of fighting and not not internally, but just to get it done. It's been fascinating. And I have to admit, everyone's not just about this initiative, it's about business in general. Sometimes I feel like I just, you know, even within an accepted domain services, I believe the certain things about what we do that are trailblazing. And quite frankly, I just want to give a put them and come back to mainstream and just ignore the, you know, people talk about purpose led businesses and mission led businesses. And there's a lot out there I know. But I also know that's a very hard business compared to a transaction business, which is about making money. And, you know, people like me, I think, and there's many that I did circumstances like this that I'd meet, you know, like it's too hard. It's too hard to do it different and they want to, right? And also some of those things you're talking about. And this may be an area where we'll just sort of start to back around, around diversity quotas of pick any type. I have no agenda with complete equity and equality. My daughter's, you know, of course, yeah, super challenging. I have this space at the moment. This may not be a sentence you want to hear, but lower your expectations. I thought you didn't have to shut the effort. I mean, that will come later. But no, like the first training, the first apprentice, celebrate that. I know it feels like you probably haven't achieved as much as you would have wanted to in the timeframe. But this now creates a path that others after can walk easier than the first. Yeah, this is true. And all of the snowballs into bigger and bigger things. So that first of any of this is always going to be difficult, but it all helps build process and path. And future fathers really. So lower your expectations. I suppose even this interaction is something that I'm quite proud of actually, because I've never seen any reason not talk to anybody. I mean, you've known me since my mid-20s, which is when I was probably at my peak, the Kedishness. Let's just say peak the Kedishness. I can say that. Sorry, HL. And, you know, maybe just the expression of this is 20 years in, not two years in. You know, it's something else for me that I'm working on, which is nothing to do with identity access management. But it's obviously areas that, you know, you and I talked before about why we're in business. And I'm in for something I can't quite put my finger on, which is what I'm awkwardly explaining. But a bit similar to you, I think. Yeah, I mean, let's say 16 years ago, this is not a conversation I could have had in any way, shape or form. But in my life, I was just chasing money. That doesn't exactly put you in the prime spot to be a role model. And as you mentioned, the Kedishness of the time. You know, I think it's something that, when it does click with you, and you kind of know that maybe there is something bigger and broader than yourself that you can do. So, things start falling into place slowly. It hasn't been that long for me that I've sort of looked back on my career and gone. Actually, there were a few times I could have been more supportive of other female colleagues or other females moving up through the ranks that I just didn't because at the time I, you know, never really dawned on me. But I know I am now in a place where I can support people and mentor them and help them get into maybe the areas or just provide advice on how I did it. And so, I enjoy that. I think you have to decide that that's going to be something that you want to do. It's not something anyone can force on you. So, I'm glad we are actually having this conversation after all these years. As a friend of mine, I just want to know. And he just started to sit down with his friends and interview them in this way. And I think the essence of it was sort of sort of shit out type of conversations with his mates. But then it's evolved into this business. He now does where he does it globally across big communities. And I find that quite fascinating. So, I think there's a bit of this for me which is sort of shit out. I don't invite anyone on that's not a friend or, but you know, I'm fast with friends. Like as an, if I meet someone, I like them. I'll extend the same courtesy to them that I would someone I've known 20 years. I mean, why not? It just seems.
o лиш cyflwanennwii yn D��라고요, 'yan، fel behwn o i f Webernt, fel gartol yn feith� Everyone down! Gwb yn osio anghorab >> fel 'flo. Felly cyfoddol chwya dog. Aleyenau'n ddoedd, wrthben feith華 i ffordd felly, rabbaki ac fforddellai eu gewili Oncellaf bydd y tro mae'n peristir sem cyfle yn bifru. Mae'n peristir sem cyflwanennwii sy'n peristir sem cyflwanennwii sy'n peristir sem cyflwanennwii sy'n peristir sem cyflwanennwii Mae'n ddod yw'r llawer y no. Mae'n ddod eu agawr y pethau oes. Mae'n gweithio. Mae'n gweithio'r llawer yw'r llawer. Mae'n gweithio'r llawer. Mae'n gweithio'r llawer yma. Mae'n gweithio'r llawer yma, ac mae'n gweithio'r llawer yma. miandartannedaud diyshirt pero miejsce no chocolate whatever I am not that, the answer for me that now. Don't you know this stuff? I do now take on ladies latest questions. This time I can kind of have a look at the I think this thing is on our mind. It's like what, you know, how do we I think it always blows my mind. It's actually like the legal profession and how much like incredibly sensitive data they have on paper. So much of it. Yeah, that sort of bogus my mind sometimes. Mark and the cyber guys you know, they were like, I can't even have it. It's like 80 or 90 breaches come through the executive of a company. Something like that, you know. I mean, obviously they're a person that people are pursuing. But then surely they need an authentication layer like an octa or something for all the persons like that. They're actually usually the user that also doesn't behave in a standard way. So there are mechanisms that you can use like behavioural detection. Am I logging in from a different country, a different device, have I logged in from here before, is this time relatively right, etc. So you can make a rule around that for your users for your average 9 to 5-0. Executives always fall outside of that. So they were always exceptions to a rule where sometimes that can be too hard for some systems to be able to cater for. So you just go, well, just excuse them and bypass that, which has historically been the case. Yeah. I hadn't thought of that. Yeah. And the ends up were you end up with poor security outcomes because the loudest voices, unfortunately the smallest percentage of user base but are able to just go just don't install the MFA thing on my phone. And no one's going to say no to the CEO. Everyone says no to me just saying you know. Maybe when we were big people say yes, we'll see. All right. We've covered so much. Is there anything that you think that we haven't covered that's important? That we should talk about. We talked about a lot. We have talked about a lot. Cybersecurity generally large, broad vast. I think fundamentally as individuals, if you're listening to this, a lot of security just fundamentally boils down to common sense and security hygiene. I know everyone hates the corporate cyber security certification that you might have to do once a year and you just blindly click through. Here's how to store data and all that kind of thing. But you know, at the end of the day, all those small attentions to detail keep not just yourself but everyone else around you protected and safe. So if you took away anything, I'd take away that just as at a human sort of like functional what can I do level? Those learning experiences though, I mean, it doesn't matter whether it's cyber or OHS or you know, even the bit but like medical stuff where you're learning to do something just-- - Hannah Leftebox. - Yeah, they're all boptic as those experiences are deeply engaging. But that's a different problem to identify that's about intuitive but engaging training modules that people want to engage with. And I think that unfortunately, you're always but that can be managed through good robust experiences, good portals. And this is back to our obviously areas of interaction. We build the digital, you know, you've got the identity access. I can't help but shake that that's the case. But I hear you, at least, you know, be aware, right? All right, awesome. Thank you for the two hours we've had something like that. - I know, right. Guest Quick doesn't it? - Yeah, really does. - It's fun, right? - Yeah, it's good. - Yeah, it's really fun. - I enjoy it.
Podcast Summary
Key Points:
Identity and Access Management (IAM) is central to digital transformation, enabling personalized, secure digital experiences, akin to physical-world interactions.
Current IAM is dominated by big tech, but there is a shift toward user-controlled, decentralized identity solutions (e.g., blockchain).
Passwords remain a major pain point, causing revenue loss and security risks; biometrics and multi-factor authentication (MFA) offer stronger, easier alternatives.
For non-technical users, physical password notebooks are recommended over complex digital tools; inclusive design is crucial for accessibility across socioeconomic groups.
Companies should avoid building custom IAM solutions in-house, instead partnering with specialists to save resources and focus on core business goals.
IAM often gets overlooked in cybersecurity priorities, but elevating it improves overall security and user experience.
Summary:
The conversation explores Identity and Access Management (IAM) as the core of digital transformation. Chris and April discuss how IAM underpins digital interactions, moving from big tech-controlled gateways to user-centric models like decentralized identity. They highlight the persistence of passwords as a security and usability issue, advocating for biometrics and MFA to reduce friction.
For less technical users, simple physical password storage is preferred, while inclusive design addresses socioeconomic barriers. Chris advises companies against building custom IAM solutions, recommending partnerships with specialists to optimize resources. IAM is often deprioritized in cybersecurity, but elevating it can enhance security, revenue, and user experience.
The dialogue underscores the need for balance between innovation, accessibility, and strategic resource allocation.
FAQs
IAM is about recognizing a user digitally, similar to how a store assistant recognizes you physically, to provide a personalized and secure online experience.
It underpins every digital interaction, enabling seamless, secure, and personalized experiences, which are essential for modern business efficiency and customer satisfaction.
People struggle to remember complex passwords, often reuse them, and breaches can lead to stolen credentials being used across multiple sites.
Biometrics like face ID or fingerprint scanning offer strong, convenient authentication without needing to remember passwords.
Most companies should not build identity solutions themselves; instead, they should partner with specialists to save resources and focus on their core business.
Using a physical notepad for passwords is safer than reusing weak ones, but ideally organizations should offer easier, secure login methods like SMS one-time passwords.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.