Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Mexico's RFC waiver means for identity verification in banking

In April 2026, Mexican President Claudia Sheinbaum announced that individuals will no longer need a Federal Taxpayer Registry (RFC) number to open an N2 or N3 bank account. As the country continues its transition to cashless payments, this move has the potential to bring more than 32 million unbanked, informal workers into the financial system. But it doesn’t come without risk.

Why Rabobank made the switch to Identity Manager

Danny van Onna, senior product owner of IAM at Rabobank, and his team made the switch to Identity Manager by One Identity, and they’re not looking back. Hear him walk through what’s worked, what’s impressed and why they’re excited for the Identity Manager 10.0 update.

DPDPA Series Part 2: Security & Access Control (Live DPDP Webinar)

DPDP Act Stage 2 webinar moved beyond the fundamentals of India’s DPDP Act and focused on the practical side of implementation. The session explored the technical, operational, and governance layers organizations need to operationalize compliance at scale. Key highlights from the session: If you're leading privacy, security, compliance, or engineering initiatives, this session provides actionable guidance to help translate DPDP requirements into executable systems and processes.

SSO for AI Agents: The Identity Gap No One is Talking About

Single Sign-On (SSO) means fewer password headaches, faster access, and better security for human users. But the same cannot be said for AI agents. SSO, a core part of Identity and Access Management (IAM), which was initially built for humans, can no longer be used for AI agents. For humans, it was quite simple - just log in once, and authenticate across connected apps. However, when an AI agent tries to authenticate the same way, the traditional access model breaks fast.

SSO Access Governance: How Enterprises Control, Monitor & Secure Identity at Scale

One compromised login should never unlock an entire enterprise environment. Yet that is exactly the risk many organizations face when Single Sign-On is implemented without governance controls. While SSO simplifies authentication and improves user experience, it also concentrates access into a single identity layer that attackers actively target. That is why enterprises are investing in SSO access governance to bring structure, visibility, and accountability into identity management.

What Is the IAM Maturity Model? A Complete Guide

Most organizations do not fail IAM because they chose the wrong technology. They fail because identity controls evolve unevenly across the environment. MFA may protect workforce users but not contractors. Provisioning may be automated for SaaS applications while privileged accounts are still managed manually. Access reviews may exist on paper but lack enforcement, visibility, or accountability.

What is Remote Device Management? RDM Guide

The shift from traditional office setups to remote and hybrid work has changed how IT teams operate. Employees are no longer working from a single location. They use laptops, smartphones, tablets, and even rugged devices across homes, offices, and field environments. Managing all of this securely is not simple. IT teams now have to balance speed, security, and support without physical access to devices. When something breaks, they cannot walk up to a desk and fix it.

Workforce verification and privacy: How to manage data retention, vendor risk, and compliance

For many security teams, the 2023 MGM Resorts cyberattack was a wake-up call. A single vishing attack exploited weak identity assurance in help desk workflows and disrupted casino and hotel operations for days, causing hundreds of millions in losses and reputational damage. The breach revealed a disconcerting new reality: Just one compromised employee account can enable attackers to bypass the entire security perimeter, regardless of an organization’s size or security budget.

What SPIFFE Answers for Workload Identity and What It Doesn't

On workload identity, a spec the industry has already started building around, and what the next layer looks like. I don't have a better answer than SPIFFE (Secure Production Identity Framework for Everyone) for workload identity, and that's where I want to start, because what follows is going to sound like I do.

How Persona supports age verification and privacy online

Addressing these potentially competing priorities is difficult with today’s technology, and it's an active area of work for government agencies and private organizations alike. But we think there’s a potential path forward if regulations and organizations limit what you have to share, who you have to share data with, and how your data can be used.