Maintaining Identity Security on a Breaking Internet
Tuesday, November 10, 2026, 3:45 PM - 4:10 PM

We have a problem with the “A” in the infosec triad of confidentiality, integrity, and availability. After a string of global outages caused by a handful of chokepoints on the wider internet over the past two years, it is clear that we can no longer assume that the internet backplane for SaaS-based identity will be as robust as needed for critical security workloads. The move to SaaS-first identity security models has been the trend for over a decade, and will likely continue broadly — but practitioners everywhere must be prepared to architect for the inevitable next disruption. If you work in or around federal environments, you already understand what it means to operate when connectivity isn’t guaranteed. DDIL — Denied, Degraded, Intermittent, or Limited — is the operational reality that defense and intelligence programs have built against for years. The enterprise world is only now catching up to that discipline. In this talk, Jon Lehtinen will describe how organizations can architect their identity security solutions to provide robust authentication, authorization, and compliance even when the connection to authoritative sources is denied, degraded, intermittent, or limited. Attendees will leave with concrete architectural patterns, deployment considerations, and a clear mapping to frameworks like NIST CSF 2.0, DORA, and CMMC — so that when the next major internet degradation hits, your organization stays productive, synchronized, and secure.
Aria
MGM National Harbor Hotel
101 MGM National Ave
Oxon Hill, MD 20745
United States
Session