A MapleSec session on customer identity and access management — and why consumer-facing identity is consistently harder than teams expect.
CIAM is not workforce IAM
Workforce identity has a bounded, known population and an IT department behind it. Customer identity has unbounded scale, hostile traffic, and users who will abandon you over one bad login screen.
Friction is a security decision
Every control you add to a login flow has a conversion cost, so the right amount of friction is a business decision, not a purely technical one. Risk-based authentication earns its keep by spending friction only where the risk actually is.
Build on fundamentals
Session handling, token lifetimes, account recovery — the unglamorous fundamentals are where real CIAM breaches come from. Account recovery in particular is where a lot of otherwise solid systems quietly fall over.