TechForge

February 3, 2026

Identity security and device trust are becoming the focus for enterprise leaders trying to reduce the risk of credential-based attacks.

Ahead of Cyber Security & Cloud Expo Global, Darren James, Senior Product Manager at Specops Software, shared his take on why traditional security investments often fail to stop modern data breaches.

Organisations are spending more on cyber security than ever before, yet reports of data breaches appear almost daily. These incidents often stem from compromised credentials or social engineering.Headshot of Darren James, Senior Product Manager at Specops Software.

James notes that despite these investments, the expected results are missing. His upcoming presentation at the expo, ‘How I Met Your Access Breach,’ riffs on a popular sitcom to examine what can be learned from these failures to improve protection without hurting the user experience. In his version of the story, the “blue French horn” represents the recurring warning signs that organisations frequently miss until it is too late.

Addressing the gaps that lead to an access breach

The modern workplace has moved away from the traditional model where employees swiped into a secure building and used managed desktops. Today, business relies on dynamic practices, often involving uncontrolled environments and unmanaged devices like personal smartphones or public networks. Many employees are also resistant to enrolling their private hardware in invasive mobile device management (MDM) solutions due to privacy concerns.

This creates a challenge for CISOs who must balance business functionality with budget constraints. James explains that “we can’t afford to buy everyone who accesses our systems a corporate smart phone.”

James argues that, in 2026, the security perimeter has moved to the device itself. However, he suggests there is a middle ground where “you can make sure every device meets your security posture, allows the users to fix any issues themselves, and respects the users privacy at the same time.”

Currently, many security teams are hesitant to block access based on device health. James attributes this to the fact that “if they block access on every non-compliant or unmanaged device using the basic options in their IdP – or the compliance options in their MDM – then at best it’s a horrible experience for the users, at worst the business will just stop functioning.”

Consequently, many teams “dial back their policies to reduce the amount of friction, and this undoubtedly leaves gaps in the company’s zero-trust architecture that can be exploited.”

Why device trust is the last line of defence

The rise of AI-driven attacks has made this more urgent. Attackers are now using AI to generate nearly infinite credential variants and fake identities, including voice and video, that can bypass standard identity and access management checks.

When credentials can be stolen or brute-forced and session tokens can be commoditised by “evil AI,” the device remains the only element that cannot be easily replicated. James explains that “the combination of a strong user authentication that is bound to a verified device that meets the company’s posture requirements, is the only thing that can protect you.”

This approach to device trust must be smooth for the user and work across all devices, including those not owned by the company. James highlights that “it’s got to be smooth, it must be secure, it must work across all devices – including ones you might not own – and it must promote self-service.”

Compliance is also driving this change. Regulations such as NIS2 and DORA are now active in the UK and Europe.

Zero-trust is specifically mentioned in NIS2 and NCSC guidance. However, achieving strict compliance across different identity providers (IDPs) and devices is difficult. James notes that “you end up leaving gaps and inconsistencies between different user groups.” Attackers look for these gaps and have already adapted.

Privacy also remains a major hurdle for the workforce. Employees are often understandably worried about their personal devices being monitored by their employer. James points out that “it’s their personal device, that they paid for with their money, why should I leave its fate in the hands of my employer… who watches the watcher?” This issue also applies to contractors who may already have their devices enrolled in a different MDM solution.

A true zero-trust model is built on the idea that a security breach has either already occurred or is inevitable. Because a device’s security status can change many times a day, checking it only at the time of login is insufficient.

James argues that “the posture of a device should be checked frequently throughout the session, so if that device becomes vulnerable action can be taken – ideally by the user – without having to contact the service desk.” If a breach does occur, containing it and having a secure recovery process is vital for getting the user back to work quickly.

The difficulty in setting a single policy for device trust lies in the variety of IDPs, MDMs, and device types in use. James notes that “what works for one might cause all sorts of problems for another, and this really is the crux of the problem.”

Many security policies assume a stable environment, but workforce access is rarely stable. James observes that “most access failures don’t occur because one control is weak, they happen because one control failed and nothing else was there to compensate.”

To conclude, James advises that organisations should build an access system rather than a single gate, then “failures can be absorbed, rather than be the cause of a breach.”

Specops Software is a key sponsor of this year’s Cyber Security & Cloud Expo Global in London on 4-5 February 2026. Be sure to check out Darren James’ day two presentation and swing by Specops Software’s booth at stand #75 to hear more directly from the company’s experts.

Banner for Cyber Security & Cloud Expo by TechEx events.

Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.

Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Author

  • Ryan Daws

    Ryan Daws is a senior editor at TechForge Media with over a decade of experience in weaving narratives and dissecting complex topics. His articles and interviews with industry leaders have earned him recognition as a key tech influencer from numerous organisations. Under his leadership, publications have been praised by analyst firms for their excellence and performance. Connect with him on X, Mastodon, Bluesky, Threads, and/or LinkedIn.

    View all posts

About the Author

Senior Editor

Ryan Daws is a senior editor at TechForge Media with over a decade of experience in weaving narratives and dissecting complex topics. His articles and interviews with industry leaders have earned him recognition as a key tech influencer from numerous organisations. Under his leadership, publications have been praised by analyst firms for their excellence and performance. Connect with him on X, Mastodon, Bluesky, Threads, and/or LinkedIn.

Related

August 24, 2026

August 11, 2026

August 10, 2026

August 5, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12371 view(s)
11427 view(s)
7693 view(s)
5372 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)