Program Sikkerhetsfestivalen 2026

Identity

Spring Cleaning: How AI Took Out a Decade of Identity Debt?

Tirsdag 5 · Kulturhuset Banken, Expedisjon

EnglishHigh-level 40 min

Stian Angvik

Stian Angvik

Cyber Security Engineer, NBIM

Stian Angvik is a Cyber Security Engineer on the Digital Identity team at NBIM. He combines exceptional communication skills with a proven track record of getting things done — driving initiatives over the finish line without ever losing sight of the user experience.

Manish Periwal

Manish Periwal

Senior Security Engineer, NBIM

Manish is a Senior Security Engineer at Norges Bank Investment Management (Oljefondet) with over a decade of IT industry expertise. His professional journey encompasses Application Security and Cloud Security, with a specialized focus on Zero Trust Architecture and Implementation using Azure and Microsoft 365 technologies. In recent years, he has concentrated his efforts on Identity Security, leveraging his extensive background to strengthen authentication and access management systems. His deep technical knowledge in cloud-native security solutions positions him as a key contributor to NBIM's cybersecurity initiatives.

Identity governance is often a graveyard of accumulated permissions — years of role changes, project access, and forgotten entitlements quietly compounding into a sprawling attack surface. At Norges Bank Investment Management (NBIM), we decided to tackle this head-on using AI.

Over the past year, we leveraged large language models, intelligent automation, and custom-built AI tooling to conduct a comprehensive identity and access cleanup across our organization. The result: over 10,000 stale or excessive access entitlements identified and remediated — accumulated over nearly a decade — dramatically reducing our identity attack surface.

But cleanup was just the beginning. We built an ecosystem of AI-powered tools to make identity governance sustainable and accessible to the entire organization: interactive dashboards for access intelligence, MCP (Model Context Protocol) integrations for real-time identity data querying, AI-powered chatbots for self-service access insights, and reusable AI skills that enable non-security staff to make informed access decisions.

This talk walks through our end-to-end journey — the technical architecture, the organizational change, the wins, and the hard lessons — so you can take practical ideas back to your own environment.

  1. Sikring i sanntid av sanntidsteknologi for web 1 · Frimurerlosjen, rom 1
  2. OIDC: (In)security by obscurity 1 · Frimurerlosjen, rom 2
  3. Balancing Security, Usability and Performance in Real-World E-Voting 10 · HeartBox ,Teatersalen
  4. Infrastructure as Code Is Still Infrastructure 10 · HeartBox, Byscenen
  5. Når jussen møter teknologien, og begge møter virkeligheten– Sikkerhetsstyring og etterlevelse i 2026 11- Breiseth, Storlon
  6. Hva kan gå galt når ferga ligger til kai? 2 · Home hotel Hammer, moen nede
  7. Kan vi stole blindt på «smart» teknologi? 2 · Home hotel Hammer, moen oppe
  8. Jeg ble kåret til en av Norges viktigste CISO’er – av en algoritme jeg aldri har møtt 3 · Hvelvet, Gullsalen
  9. Leverandørkjedeangrep sett fra trusselaktørens perspektiv 4 · Kommunestyresalen, Lillehammer rådhus
  10. Sikkerhetsloven – neste compliance-sjokk for norsk næringsliv? 5 · Kulturhuset Banken, Festsalen
  11. A Question of When, not If: How Cyber Threats Can Endanger Financial Stability 5 · Kulturhuset Banken, Holbøsalen
  12. Linux under angrep: Hvordan sikre kritiske systemer i møte med moderne trusler 5 · Kulturhuset Banken, Kafeen
  13. Storskala sikkerhet - hvordan verdens største selskaper jobber med IT-sikkerhet 6 · Lillehammer kino, sal 2
  14. Hva skjedde når vi tok med adferdspsykologer inn i kultur-arbeidet? 6 · Lillehammer kino, sal 4
  15. From Chatbots to Autonomous Malware: The Evolution of AI-Powered Threats 9 · Victoria Scandic, sal 1+2
  16. DataOPS - on-prem logg og analyse i stor skala 9 · Victoria Scandic, sal 3