
Building a Common Operating Model Between Identity & Security Teams | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 15:25
[BLUF] The speaker argues that identity is the critical control plane for modern security, yet organizations fail to secure it by prioritizing uptime over control and treating identity and security as separate domains. 0:35
Key Takeaways:
• The speaker highlights a non-traditional background in sales within the identity and security space, noting early migrations from NT4/NDS to Active Directory and the frequent neglect of environment cleanup 0:00.
• Identity is the central control plane and primary vector for modern breaches, but organizations often optimize for system uptime rather than security control, creating a persistent gap 0:35.
• Security and identity teams often operate in silos with conflicting mandates—security seeks to eliminate risk while identity ensures availability—leading to misaligned metrics and unresolved tech debt 0:41.
• Effective defense requires shifting from event-based monitoring to attack path management, fostering collaboration between teams, and establishing shared metrics like attack paths eliminated 1:20.
Closing statement: Bridging the gap between identity and security through shared visibility, attack path management, and unified metrics is essential to closing the control gap and mitigating modern threats.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So, I'm kind of a unique twist today. I'm not a traditional practitioner. I'm going to go ahead and admit and let you guys throw stuff at me. I was in sales for a long time. Uh, and the gray hair on the side of my head isn't just from selling. It's cuz I had made the weird decision to spend that entire time between identity and security. Uh, even before that space really existed. Uh, if you remember NT4 and NDS, my early projects were doing migrations from those onto AD. Uh, and even back then trying to beg people to clean up their environments before bringing them over. and most people said no. So that's why we're here. I tried to stop it. Uh so I you know this identity is the control plane. Uh it's central to modern breaches. Uh you know we optimize for uptime. We're not focused on contr…