“We must stop attackers before they reach the customer” says Mathew
As cyber threats grow in sophistication and scale, the challenge of protecting digital identities is becoming more urgent than ever—particularly in Asia Pacific, where rapid digital transformation is colliding with regulatory shifts and AI disruption.
BW Security World spoke with Mathew Graham, CSO at Okta, to unpack the key identity risks over the next 18 months, the dangers of unmanaged AI agents, and the evolving role of CISOs in a region undergoing profound change.
What do you see as the biggest digital identity threats emerging across Asia Pacific in the next year or so?
There are several critical shifts happening all at once, but one stands out above the rest: the rise of AI-driven cybercrime. We’re seeing generative AI used to create highly convincing phishing campaigns, deepfakes and even fully automated scams. These tools are fast, effective and scalable—and that means identity breaches are going to increase sharply. Security teams are already stretched, and this only adds more pressure.
At the same time, regulation is tightening across the region. India’s Digital Personal Data Protection Act, and privacy rules in places like Singapore and Australia, are forcing companies to rethink how they manage and protect identity data. Businesses relying on outdated identity systems aren’t just at higher risk of breaches—they now face serious fines and reputational harm if they don’t meet compliance standards.
Another emerging challenge is the rapid adoption of AI agents in the workplace. These aren’t just chatbots; they’re digital workers that need access to sensitive systems and data. But because they aren’t people, they often fall outside traditional identity governance frameworks. That makes them a new, largely invisible threat surface. We need to govern them with the same discipline and care we apply to human users.
Lastly, digital identity fraud continues to rise as more people move online for shopping, healthcare and financial services. Fraudsters are exploiting weak identity verification processes to impersonate users, steal credentials and drain accounts. It’s not just a financial issue—it erodes trust in the digital economy.
Why are non-human identities such a concern, and how can governing both human and machine identities help organisations manage AI adoption more securely?
The challenge with AI agents is that they behave like employees—they access systems, process data, make decisions—but they aren’t people. Traditional security models weren’t designed for them. If you don’t know what an agent has access to, or whether it still needs that access, you’re flying blind.
That’s why governance must evolve. Human and machine identities need to be managed through the same lens, under one system. When you apply the same Zero Trust principles to both, you maintain visibility, consistency and control. You can track access, enforce limits, and ensure that whether the actor is a person or a machine, they only have the access they need—no more, no less.
This is urgent. While most organisations in the region are already using AI agents, very few have proper governance in place for them. That’s worrying. These agents often have broad, standing access, and if something goes wrong—a compromise or misconfiguration—the impact can spread across systems at machine speed. We call this the “shadow attack surface”, and it’s growing fast.
At Okta, we’re building tools specifically for this challenge. Our platform acts as an identity security fabric, managing every identity—human or machine—across all applications and environments. We’re also weaving verifiable digital credentials into this framework to help fight AI-driven fraud and create a more trustworthy digital ecosystem.
With the festive season approaching, fake e-commerce sites become more prevalent. What is the most serious challenge for brands trying to protect customer data and trust?
The hardest part for brands is stopping fraud before it reaches the customer. Imposter websites and fraudulent apps can appear overnight. If a consumer is tricked into making a payment or handing over data—even if the brand’s own systems weren’t compromised—the damage to trust is immediate and difficult to repair.
In India, this risk is particularly pronounced. Our research shows that while Indian consumers are highly concerned about identity fraud, they also place greater trust than the global average in organisations like banks, healthcare providers and government services. That trust comes with high expectations, and a single misstep can do lasting damage to a brand’s reputation.
What we often see is that fraud campaigns exploit human behaviour—clicking a link too quickly, trusting an unfamiliar site during a busy shopping period. Education and vigilance help, but businesses also need to take proactive steps to secure their brand across the digital ecosystem, from domain monitoring to strong customer identity verification.
What identity-based strategies can companies use to detect and deter fraud more effectively?
We need to move from reacting to fraud to preventing it entirely. That means making the attacker’s most valuable weapon—stolen credentials—completely useless. The best way to do that is to move beyond passwords and SMS one-time passwords, which are easily phished or stolen, and adopt stronger, phishing-resistant authentication methods such as passkeys or biometrics.
But authentication can’t be a one-time check. We need to be continuously analysing risk. This is where risk-based authentication comes in. By evaluating behavioural signals and contextual data—like device, location, and transaction patterns—we can flag unusual activity in real time and automatically trigger additional checks or block access altogether.
When done right, this approach is seamless for genuine users but highly effective at stopping fraud attempts before they gain traction.
With mergers and acquisitions on the rise in India, how should CISOs approach identity governance during due diligence?
Identity governance needs to become a core part of the M&A process—right from the start. One of the most overlooked risks in acquisitions is the baggage that comes with legacy access: dormant accounts, unnecessary privileges and poor visibility into who can do what across systems. All of these create opportunities for attackers.
By making identity a due diligence priority, companies can enter Day One of a merger with a clear understanding of access and controls. This means secure collaboration from the outset, faster integration of systems, and fewer surprises down the line.
How do you see the CISO role evolving as security becomes more tightly linked to business growth and AI strategy?
The role of the CISO has changed dramatically. It’s no longer about patching systems or managing firewalls. Today, it’s about guiding the business through complex transitions—whether that’s AI adoption, regulatory compliance, or mergers and acquisitions.
Security leaders now need to speak the language of the business. That means framing identity and governance not just as tools for risk reduction, but as enablers of growth and innovation. When you automate the basics and embed security into strategic conversations, you move from being a technical expert to a trusted advisor at the executive table.
Forrester’s study showed Okta delivered a 211% return on investment through identity governance. How do you help boards understand the business value of identity security?
Identity governance delivers tangible returns across the board. The Forrester study showed a 211% ROI, but the broader value lies in operational efficiency and business agility.
Good identity practices reduce the time it takes to onboard and offboard staff. They simplify audits, speed up M&A integration, and improve productivity by ensuring that people have the access they need—nothing more, nothing less. They also reduce hidden risks tied to unused accounts or overly permissive access.
For boards and risk teams, identity security should be seen not just as a defensive layer, but as a strategic investment in resilience, trust and growth.
Finally, how can CISOs balance day-to-day risk management with the need to strategically adopt AI-driven tools?
It comes down to knowing where to automate and where to stay hands-on. Let AI do what it does best: automate repetitive tasks like access certifications, policy enforcement and threat detection. That frees up your team to focus on the larger strategic issues—those that require human judgement and experience.
Then, take the identity conversation to the top. This isn’t just about securing logins anymore. It’s about AI readiness, operational continuity and business agility. When you position identity as the governance layer that enables safe AI adoption, you unlock executive support and demonstrate how security can drive—not delay—innovation.
As digital and AI transformation accelerates, identity security is no longer a backend function—it’s the connective tissue that holds trust, compliance and resilience together. And according to Graham, the organisations that understand this will be the ones best positioned to grow, safely, in the years ahead.

