IDENTITY W
RLD
Melbourne
Melbourne · 17 March 2027 · Collins Square Events Centre

Agenda & Speakers

The programme

Australia's biggest dedicated IAM agenda.

Short, sharp and interactive: keynotes and case studies from practitioners, live panels you vote in, peer roundtables on the problems you name, and two hours of structured networking by design.

Identity World Sydney
Agenda

Wednesday 17 March 2027.

All times AEDT. Speaker lineup and agenda announcement coming November 2026. Sign up for the full lineup drop announcement below!

08:30

Registration Opens & Networking Breakfast

Networking
+

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

09:15

Welcome & Opening Remarks

Keynote
+

Kick off the day with a welcome from your MC and a look at what's ahead.

09:20

Opening Keynote: Authenticated. Trusted. Compromised.

Keynote
+

MFA can work exactly as intended and the account can still be compromised. Once a user has authenticated, attackers can target the session, token or browser state created afterwards and use it without going through the login process again.

This session looks at how one organisation is protecting access after authentication succeeds, how quickly stolen sessions can be identified and what has to happen when a trusted session suddenly becomes untrusted.

We'll cover:

  • Where session and token theft gets around controls that worked correctly at login
  • Which signals can show that an authenticated session has changed hands
  • How teams revoke access quickly without forcing every user through constant reauthentication
09:40

Keynote: Digital ID's Next Phase: What Private-Sector Adoption Means for Australian Organisations

Keynote
+

With Australia's Digital ID system now opening to the private sector under the Digital ID Act, organisations face a genuine strategic choice: become an accredited relying party, wait, or build alongside. This keynote unpacks where the rollout actually stands, the accreditation and cost realities of myID and the AGDIS, and how leading organisations are turning verified digital identity from a compliance obligation into a trust and onboarding advantage.

  • Where the private-sector rollout stands and what accreditation practically requires
  • How verified Digital ID reshapes customer onboarding, fraud reduction, and KYC
  • The commercial and privacy trade-offs of relying on a government-backed identity system
10:10

Panel Discussion: When Identity Goes Down: Getting the Business Back Online

Panel
+

Identity now sits in front of almost everything employees need to do. If a core identity platform is compromised or unavailable, recovering the rest of the business can depend on getting identity working first.

This panel looks at how organisations prepare for an identity outage or compromise, what needs to be recoverable first and whether their plans would actually work under pressure.

We'll discuss:

  • What has to come back first when the identity layer itself cannot be trusted
  • How organisations design break glass access, backup and clean recovery
  • How often identity recovery should be tested before an incident proves the plan wrong
10:40

How I Solved… Turning "Who You Are" Into "What You Can Do Right Now"

Case study
+

Authentication answers who someone is. It does not necessarily answer whether they should be allowed to perform a particular action against a particular resource at this moment.

This session looks at how organisations are moving away from access decisions buried inside applications and towards policies that can make more specific decisions based on identity, context and risk.

We'll cover:

  • Where roles and static permissions stop being specific enough
  • How access decisions can change based on the user, resource, action and current context
  • What it takes to apply consistent authorisation across applications, APIs and AI agents
10:55

Morning Tea & Networking

Break
+

Recharge with refreshments and structured networking with your peers.

11:25

Audience Activity

Workshop
+

A hands-on, interactive session working through a real identity and access scenario as a room. Details announced soon.

11:40

How I Solved… Mapping the Path From Standard User to Global Admin

Case study
+

One permission may look harmless. Several permissions connected across Active Directory, Entra, cloud platforms and applications can create a route to something far more powerful.

This session looks at how one organisation mapped those connections, found paths an attacker could use to move from an ordinary identity to critical access and decided which ones to remove first.

We'll cover:

  • How seemingly low risk permissions can combine into a serious access path
  • Which identity relationships traditional access reviews are most likely to miss
  • How teams prioritise remediation when hundreds of possible paths are uncovered
11:55

How I Solved… We Went Passwordless, So Where Are Attackers Getting In Now?

Case study
+

Passkeys and phishing resistant authentication make stealing a password far less useful. That does not mean every route into the account has disappeared.

This session looks at what happens after organisations strengthen the login and attackers start targeting weaker fallback methods, authenticator enrolment, new devices and account recovery instead.

We'll cover:

  • Which fallback routes can undo the protection gained from stronger authentication
  • How enrolment and recovery should change once passwords are no longer the main control
  • What organisations need to remove rather than simply adding another authentication method on top
12:10

Panel: Your Certificates Last 100 Days. Can You Automate Machine Identity Fast Enough?

Panel
+

From 15 March 2027, public TLS certificates max out at 100 days. That turns certificate renewal from an occasional operational task into a continuous automation problem and exposes the wider issue of how organisations discover, own and rotate machine identities at scale.

This panel looks at how organisations are automating certificates and other machine credentials before shorter lifetimes make manual processes unmanageable.

We'll discuss:

  • How organisations discover certificates, keys and machine credentials they did not know they had
  • What needs to be automated across issuance, renewal, rotation and revocation
  • How teams deal with ownership gaps and prevent expired or forgotten credentials from becoming outages or security exposures
12:40

Peer Roundtables

Networking
+

Small-group, discussion-based sessions where you'll work through real identity and access challenges with peers in similar roles. Roundtable topics will be announced soon.

13:30

Lunch & Networking

Break
+

Enjoy a complimentary lunch while connecting with fellow attendees.

14:20

QuickFire Quiz: Test Your Knowledge Against Your Peers

Workshop
+

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights (and a travel voucher) as the top scorer takes the crown.

14:35

How I Solved: Locking Down Social Engineering in Identity Recovery

Case study
+

Strong authentication does not help if an attacker can persuade a service desk to reset MFA, enrol a new device or recover an account.

This session looks at how organisations are tightening the human side of identity recovery and what evidence should be required before somebody is given control of an account again.

We'll discuss:

  • How organisations prove someone is really who they claim to be when normal authentication is unavailable
  • Which recovery and enrolment processes create the biggest gaps
  • Where service desks should be allowed to make the call and when a request should be stopped or escalated
14:50

Keynote: Getting Rid of Permanent Admin for Good

Keynote
+

Permanent privileged access is convenient, but it also means powerful permissions are sitting there whether somebody needs them or not.

This session looks at what it takes to replace standing access with temporary privilege, how organisations handle emergency and overnight access and what happens when security controls meet the reality of administrators and developers trying to do their jobs.

We'll cover:

  • Which privileged roles can realistically move to temporary access
  • How approval, emergency access and on call work once permanent admin rights disappear
  • What broke during the change and where standing privilege still proved difficult to remove
15:10

Think Tank: Three Identity Providers, Hundreds of Legacy Apps. What Would You Keep If You Started Again?

Fireside
+

Large identity environments rarely look the way anyone would design them today. Years of mergers, platform changes, legacy applications and point solutions leave organisations running multiple identity providers, directories and authentication methods at the same time.

This think tank puts that reality to the room, panelists and audience together, to work through what should actually be removed, replaced or tolerated if organisations had the chance to simplify the identity environment now.

Questions we'll cover:

  • If you were designing your identity environment from scratch today, what would you keep and what would you refuse to rebuild?
  • Which identity providers, directories or authentication methods are you maintaining today mostly out of habit rather than necessity?
  • What's one legacy application everyone agrees needs to be modernised, wrapped or retired, but nobody has actually touched?
  • Where does consolidation genuinely reduce risk and cost, and where is it just movement without real benefit?
  • How do you sequence identity simplification so it delivers value along the way, rather than becoming another multi-year transformation that never finishes?
15:40

Closing Remarks & Prize Draw

Keynote
+

Wrap-up of the day's key takeaways, and your chance to win some epic prizes.

15:45

Networking Drinks Hour

Networking
+

Unwind with your peers for a couple of drinks on us!

16:45

Event Closed

Networking
+

See you at Identity World New York on May 6, 2027.

Session formats

Five ways the room works.

Short, sharp and interactive by design. No slide-after-slide days.

Keynote

Solo stage time from a practitioner or an invited expert, framing where the discipline is heading.

20 to 30 minutes
Panel

Three or four leaders comparing programmes directly, moderated to stay concrete rather than abstract.

30 minutes
Roundtable

Small-group peer discussion on a single named problem, with no audience and no slides.

50 minutes
1-2-1 Meetings

Curated, opted-in meetings between practitioners and the partners they choose to meet, scheduled around the programme so nobody misses a session.

15 minutes each
Networking

Two hours of the day given to breakfast, lunch and drinks by design, so the conversations started in the room carry on outside it.

Two hours across the day
Past speakers

Learn from the best in the business.

Global perspectives on identity and digital trust featuring localised experts and region-specific, tailored agendas curated by IAM leaders facing the same challenges as you.

Abhi Banerjee
Abhi Banerjee
VP IAM Security Platforms and Operations
Dr. Nader Nassar
Dr. Nader Nassar
Director Engineering: Cybersecurity and IAM
Galo Vaca
Galo Vaca
CISO
Harsh Rasik Busa
Harsh Rasik Busa
Chief Information Security Officer
Hemangini Tandel
Hemangini Tandel
Head of Identity
Igor Aleksenitser
Igor Aleksenitser
Head of IT Security
James Kay
James Kay
Assistant Director-General, Standards, Technical Advice and Research
Madhuri Nandi
Madhuri Nandi
Head of Security
Miguel Carrasco
Miguel Carrasco
Managing Director and Senior Partner
Sanchita Bajaj
Sanchita Bajaj
Privacy, Authentication and Identity Experience Design Director
Tharaka Perera
Tharaka Perera
Head of Information Security
Vanessa Gale
Vanessa Gale
Head of Identity & Access Management
Wednesday 17 March 2027 · Collins Square Events Centre

Don't miss Australia's biggest IAM event.