Melbourne Identity, Authentication & Access Management Summit 2025
Secure the future of secure access and join industry experts for hands-on sessions and insights on identity management, authentication, and passwordless security solutions.
Check out last year's event

Join us at the Identity, Authentication, and Access Management Summit to explore the future of secure access.
In September, we're bringing together security experts, IT leaders, and industry innovators to enhance identity management and authentication.
Discover best practices for managing identities, streamlining sign-on processes, and balancing user experience with security. Dive into how AI is shaping access management and the move towards passwordless authentication. Engage in interactive sessions, real-world case studies, panel discussions, and debates to stay ahead of the latest trends.
Key Themes:
- Identity Management Future Trends
- Zero Trust Implementation
- Managing Compromised Credentials
- Streamlining Sign-On Processes
- Enhancing Authentication Methods
- Balancing User Experience and Security
- AI in Access Management
- Passwordless Authentication
Who Should Attend?
Security professionals, IT leaders, identity and access management specialists, and anyone eager to improve their understanding of secure access and network with industry peers.
Don't miss this chance for a day of learning, innovation, and collaboration.
Our Speakers
Agenda
This session explores how to align access policies with actual business risk, avoid “control fatigue,” and build workflows that people actually follow. Drawing on experience leading technology controls and governance at AIA Australia, Luke Ma will share practical approaches to make identity governance effective, sustainable, and embraced across the enterprise
- Enterprise identity governance challenges, past, present, and emerging ones
- Avoiding control fatigue by focusing on the highest-impact safeguards
- Building practical workflows that teams willingly follow
- Measuring success and iterating without adding unnecessary complexity
The number of non-human identities, from AI agents to service accounts and automation scripts, now far exceeds human users in many environments. But these identities often lack clear ownership, lifecycle management, or access controls. In this session, we’ll unpack why they’ve become one of the most overlooked and risky parts of modern identity programs.You’ll learn how to:
- Identify and inventory non-human identities across your environment
- Set lifecycle, ownership, and access policies that actually stick
- Reduce risk by securing tokens, automation credentials, and embedded secrets
Identity-based threats are still the most common cause of breaches but in 2025, they’re harder to spot and faster to spread. It’s not just about stopping bad logins anymore; attackers are hijacking sessions, abusing tokens, and blending in with legitimate users.
In this panel, security and IAM leaders share how they’re spotting identity misuse early, what behaviours and signals actually help, and how they’re speeding up response without burning out their teams.
We’ll cover:
- What teams are watching for now – The signals, behaviours, and patterns helping catch identity misuse early
- How response is evolving – What’s working for fast containment, smarter investigation, and reducing manual effort
- Where IAM and detection need to connect – Making sure identity systems and security teams work together, not in silos
When budgets tighten, identity security often gets pushed into the “necessary cost” bucket, a compliance checkbox that’s essential but not seen as value-generating. In this session, I’ll share how we flipped that perception and built an identity strategy that not only reduced risk but actively drove productivity and efficiency across the enterprise.
You’ll learn how we:
- Reframed identity security as a performance driver, shifting the conversation from cost and compliance to measurable business value
- Unlocked efficiency gains through automation, AI-driven access decisions, and streamlined governance
- Make a compelling business case with the metrics and language that resonate in a budget-constrained environment
In this innovative session, attendees will be faced with a series of scenarios that they may face in their roles. Attendees will discuss the possible courses of action with their peers to consider the ramifications of each option before logging their own course of action.
Results will be tallied and analysed by our session facilitator and results will impact the way the group moves through the activity.
Will we collectively choose the right course of action?
As deepfake audio becomes more realistic and easier to generate, voice authentication systems are being put to the test. In this session, the Director of Speech Science at Redenlab shares real-world cases where deepfake voice was used or detected and the hard lessons they reveal.
Drawing on research and implementation experience across speech science, healthcare, and AI, this talk explores how speech models are being subverted, what detection techniques are showing promise, and how IAM and security leaders can future-proof voice-based authentication strategies.
We’ll cover:
- Where deepfake voice attacks are already landing – Real examples of compromise attempts and what they expose about current system weaknesses.
- How to build detection and resilience into voice auth – Techniques to identify synthetic speech, build layered defences, and flag anomalies early.
- What security teams need to prepare for next – The future of synthetic voice, risks to high-stakes workflows, and how to stay ahead of attacker innovation.
Some of the most dangerous identity risks are the ones no one’s looking for — old permissions, forgotten accounts, and invisible access paths that build up over time. In this session, I’ll walk through how we used AI to uncover and fix these risks across our environment.
You’ll learn how we:
- Found hidden access paths and unused permissions that weren’t being monitored
- Identified gaps traditional audits and reviews tend to miss
- Turned those insights into action with risk-driven clean-up workflows
AI agents, synthetic users, and machine identities are becoming part of daily operations but most IAM strategies weren’t built to handle them. In this panel, security and identity leaders will explore what happens when your users aren’t human, your workflows are autonomous, and your policies can’t keep up.
We’ll unpack the new risks AI introduces, how teams are adapting identity controls, and what needs to change in how we govern access and identity going forward.
- How to handle machine and agent identities: What’s working to manage authentication, permissions, and lifecycle for non-human actors
- Where current IAM approaches break down: Firsthand challenges teams are facing as AI scales across infrastructure
- What to change now: Tools, policies, and cross-team strategies that help you stay in control as AI reshapes the identity landscape
Delegates will chose from a list of pertinent peer-to-peer discussion topics focussing on evolving and emerging trends, techniques and technologies
Put your cloud security knowledge to the test in this fast-paced quiz covering real-world threats, key concepts, and emerging trends. Compete for bragging rights—and a $300 travel voucher—as the top scorer takes the crown.
At Downer, identity is more than an access layer, it’s the foundation of their security strategy. In this session, you’ll hear how the IAM team is leading real change across a complex mix of cloud and on-prem environments.
From structuring teams for delivery to embedding identity into broader risk and operational priorities, this is a practical look at what it takes to move beyond policy and build a scalable, outcome-driven identity programme that earns buy-in and delivers results.
We’ll cover:
- What identity-centric security looks like at Downer – How controls, visibility, and risk reduction are delivered in day-to-day operations.
- How Downer structures and leads IAM at scale – Team design, platform coverage, and delivery across hybrid infrastructure.
- Where identity delivers the most impact – How we connect IAM strategy to compliance, operational priorities, and business risk.
The digital identity landscape has entered a new phase, one where threat actors no longer need technical expertise to launch sophisticated attacks. Thanks to a booming ecosystem of syntheticmedia tools, face swaps and deepfakes have become commoditized. Today, over 120 active face-swap kits and 100,000+ injection permutations fuel a rising tide of synthetic identity fraud. And worse still, the human eye is no longer a reliable filter: even seasoned professionals now struggle to distinguish real from fake.
Traditional verification and authentication systems, built for a different era, are being outpaced. This session explores how a science-led approach to liveness detection is enabling organisationsto regain the upper hand.
- What makes modern deepfakes so dangerous—and why most detection systems fail
- How layered liveness detection thwarts synthetic identities in production environments
- How to build frictionless, scalable verification and authentication experiences without sacrificing assurance
- Lessons from real-world attacks and a roadmap to resilient, adaptive identity security
Some IAM challenges just don’t have clean answers but the choices your team makes can define your entire security posture.
In this interactive session, we’ll vote, debate, and challenge five of the most divisive identity decisions facing organisations in 2025. Each one will be explored through live multiple-choice questions designed to split the room and surface the real trade-offs teams are making today.
You’ll leave with a sharper view of where others stand and what strategies are actually working.
We’ll explore questions like:
- Who should really own IAM — security, IT, or the business?
- How much friction is acceptable in customer identity before it hurts the business?
- Should IAM be centralised, or is federated identity the only way to scale?
- Where are modern identity architectures failing silently?
- Should identity systems block risky behaviour or just alert and log it?
Past Speaker Highlights
Who Attends?
Chief Information Security Officer
Chief IAM Officer
Chief Identity Engineer
Head of KYC
Head of Risk and Compliance
Head of Financial Crime
Head of Privacy
Head of Identity Governance
Head of Cybersecurity Platform
Head of Cybersecurity
Head of IAM
Head of Access Control
Head of PAM
Cyber GRC Director
CIAM Director
Digital ID Manager
Workforce Identity Lifecycle Manager
Digital Product Manager
Fraud Risk Manager
Authentication Manager
Cybersecurity Engineering Manager
Cybersecurity Architecture Manager
Our event sponsors







Past Sponsors
Event Location
Metropolis Events

Frequently Asked Questions
Get In Touch
Contact our event team for any enquiry

Danny Perry
For sponsorship opportunities.

Lili Munar
For guest and attendee enquiries.

Ben Turner
For speaking opportunities & content enquiries.

Taylor Stanyon
For event-related enquiries.