Header image

Session 2.8d Update: Do you Know Who - and What - Can Act Across the Mission?

Tracks
Wednesday, November 18, 2026
4:00 PM - 5:00 PM
Nicholls Theatre

Presentation Outline

Every mission now depends on actors that never log in. Service accounts, workload identities, API keys, machine certificates, automations and AI‑enabled agents authenticate, retrieve data, invoke services and execute processes across Defence environments continuously and at machine speed. These non‑human actors inherit the access landscape already in place — and operate far faster than governance processes built around periodic human review. Identity has therefore become a cyber‑risk and mission‑assurance issue rather than an administrative one. Severity in a cyber event is no longer determined by initial access, but by the exposure already available to the actor: its standing privileges, reachable systems, delegated authority, and the tools, APIs and workflows it can invoke. This exposure persists even when every account, credential and access decision is technically valid. This session introduces composed capability — what an actor can actually accomplish once identity, credential, access, privilege, tools, APIs, data and connected systems are combined. The most consequential exposure now forms in the seams between individually bounded systems, where identity is asserted in one, a token issued by another, an API invoked by a third and a workflow triggered in a fourth. No single owner governs the composed path, and revocation rarely propagates across all boundaries. The session closes with a common operating model — Govern, Identify, Protect, Detect, Respond, Recover — to ensure every actor capable of acting on behalf of the mission is known, governed, monitored, revocable and evidenced.


Speaker

Agenda Item Image
Mr Frankie Briguglio
Federal CTO
Sailpoint

Biography

Frank Briguglio, CISSP, is a global cybersecurity strategist with over 30 years of experience delivering identity‑centric security programs for defence and government. As Federal CTO and Global Public Sector Strategist, he works closely with Five Eyes partners — including Australian Defence and national security agencies — to strengthen mission assurance through modern identity governance, credentialing, and Zero Trust. Frank’s expertise spans FICAM, PKI, NIST frameworks, and high‑assurance access management. He served as Lead Architect for the U.S. Department of Homeland Security’s Continuous Diagnostics and Mitigation (CDM) program, one of the world’s largest identity‑driven cyber initiatives, providing lessons directly applicable to Defence’s Zero Trust and digital modernisation efforts.

He represents SailPoint in the NIST NCCoE Zero Trust Architecture collaboration, contributing to standards and reference designs that support coalition interoperability and secure information sharing across Defence networks. A frequent speaker at MILCIS and other defence cyber forums, Frank delivers practical insights on identity governance, dynamic authorization, and credential assurance — foundational capabilities for secure, resilient, and sovereign Defence operations.
loading