By NHI Mgmt Group Editorial TeamBased on RSA Security: “RSA to Power Growth in EMEA Central with Appointment of RSA Regional Director Sabine Davies” (July 22, 2025)

TL;DR: Rising demand for resilient identity controls, passwordless access, AI-powered threat defence, and identity security posture management, with DORA cited as a regional driver, according to RSA Security, is reflected in its new EMEA Central regional director appointment. The signal is that identity programmes are being judged on access resilience and regulatory readiness, not feature breadth.


At a glance

What this is: RSA Security’s EMEA Central leadership move is a regional hiring signal tied to demand for resilient identity controls, passwordless access, AI threat defence, and identity security posture management.

Why it matters: For IAM, PAM, and NHI teams, the point is that buying conversations are increasingly shaped by regulatory pressure and the need to harden access pathways across every environment.


Context

RSA Security’s leadership move in EMEA Central is a business development, but the article’s underlying message is about identity security priorities in the region. The vendor links its hiring decision to demand for resilient security solutions, passwordless access, AI-powered threat defence, and identity security posture management.

For identity teams, the practical question is not who joined the regional business. It is what this says about the controls that are becoming mandatory in buying conversations: access resilience, governance depth, and the ability to support compliance-driven programmes such as DORA.

The article is a hiring announcement, but the governance signal is broader than personnel. It points to a regional market where identity security is being evaluated as part of operational resilience rather than as a standalone authentication problem.


Key questions

Q: What frameworks should teams use to align identity security with resilience?

A: Teams should map identity controls to the NIST Cybersecurity Framework 2.0 and use NIST-based control language to connect access decisions to protect, detect and recover outcomes. For NHI and delegated access, the most useful step is translating governance policy into provable ownership, scope and revocation behaviour.

Q: Why does DORA change the way identity programmes are judged?

A: Because the standard pushes identity controls toward demonstrable resilience, not just policy compliance. Teams must be able to show that access remains secure, governable, and recoverable during disruption, which raises the bar for monitoring, recovery evidence, and control ownership.

Q: What are the signs that identity posture management is not working?

A: Common warning signs include unknown identities, inconsistent ownership, privileges that survive role changes, and federation paths that nobody can explain. If teams only notice these issues during audits or incidents, the posture model is already behind the environment.

Q: What should security leaders do when access modernisation and governance are being planned separately?

A: Bring them into one roadmap. Passwordless adoption, posture management, and privileged access governance affect each other, so separating them creates blind spots in control design, reporting, and funding decisions.


Technical breakdown

Passwordless access as an access-resilience control

Passwordless access reduces dependence on reusable credentials such as passwords and makes phishing-resistant authentication easier to operationalise across cloud, hybrid, and on-premises environments. In practice, it is not just a user experience change. It changes the attack surface by removing one of the most common identity takeover paths and forcing stronger assurance at the point of authentication. That matters most where users operate across mixed environments and where credential replay is a realistic threat.

Practical implication: treat passwordless as part of access resilience planning, not as a standalone login upgrade.

Identity security posture management in mixed environments

Identity security posture management is the continuous assessment of identity controls, exposures, and misconfigurations across the identity estate. In mixed environments, the challenge is that cloud, hybrid, and on-premises identities often follow different control models even though attackers do not respect those boundaries. A posture programme has to look across entitlements, authentication methods, privileged access, and policy drift if it is to expose the gaps that matter for resilience and audit readiness.

Practical implication: assess posture across the full identity estate, not just the newest cloud layer.

Why DORA raises the identity governance bar

DORA is relevant here because resilience regulation pushes identity from a support function into a control domain that must demonstrate operational continuity and recoverability. When the article cites DORA, it signals that identity programmes are being judged on their ability to sustain secure access during disruption, not only to authenticate users on a normal day. That shifts the governance question from feature adoption to evidence of control effectiveness under stress.

Practical implication: map identity controls to resilience and recovery expectations, not only authentication coverage.


NHI Mgmt Group analysis

Regional identity hiring is now a proxy for control demand: This appointment is less about organisational structure than about where identity security budgets are moving. When a vendor frames regional growth around resilient controls, passwordless access, and posture management, it reflects buyer pressure to justify identity programmes in operational and regulatory terms. The practitioner takeaway is that identity security is being evaluated as a resilience function, not a narrow access layer.

Passwordless and posture management are converging into a single buying conversation: The article ties authentication hardening and security posture into the same regional growth story. That convergence matters because many programmes still treat login modernisation and governance visibility as separate tracks. In practice, security teams are being asked to prove both reduced credential risk and sustained control over identity drift, which changes how roadmaps get prioritised.

DORA is turning identity governance into an evidence problem: The mention of DORA signals that identity controls must now support demonstrable resilience, not just policy intent. That means access continuity, recovery evidence, and control monitoring carry more weight in stakeholder conversations. For practitioners, the market is moving toward identity governance that can stand up in audits, incident reviews, and board discussions.

Identity security posture management is becoming the bridge between strategy and operations: The article’s emphasis on ISPM shows that organisations want a way to connect identity design decisions to measurable exposure reduction. That bridge is important across cloud, hybrid, and on-premises estates because policy gaps often appear at the seams. The practitioner implication is to align posture reporting with the real control surfaces attackers and auditors both see.

EMEA Central is signalling a broader shift in identity expectations: The region’s buying criteria are moving toward resilient access, governance depth, and threat-aware identity controls. That means vendors and practitioners alike must speak the language of operational resilience, not just identity feature sets. The practical conclusion is that identity programmes need to be defensible under compliance pressure and disruption scenarios at the same time.

What this signals

Identity security is being pulled into resilience planning: The article shows that regional hiring and go-to-market decisions are now shaped by the same pressures that drive control investment. For practitioners, that means identity work has to be framed in resilience language if it is going to secure budget and executive attention.

Passwordless, posture, and privileged access are no longer separate conversations: Buyers increasingly want one story that links authentication strength, identity exposure, and control evidence across the full estate. Teams that keep these domains siloed will struggle to explain how identity risk is actually being reduced.

Control evidence will matter more than control claims: If a programme cannot show secure access continuity across cloud, hybrid, and on-premises environments, its maturity will be questioned. That pushes identity leaders toward measurement, not just feature adoption.


For practitioners

  • Align identity roadmaps to resilience objectives Review whether passwordless, posture monitoring, and privileged access controls are being justified as operational resilience capabilities rather than isolated product features.
  • Map identity controls to DORA expectations Document which identity controls support continuity, recovery, and secure access during disruption, especially where regulated business units need audit evidence.
  • Assess identity security posture across all environments Check whether cloud, hybrid, and on-premises identities are being measured with one control view or fragmented reporting that hides policy drift.
  • Re-evaluate authentication assumptions Identify where reusable credentials, weak MFA, or inconsistent device trust still create avoidable identity takeover risk in regional operations.

Key takeaways

  • The article is a hiring signal, but the underlying message is that identity security is being evaluated as a resilience and compliance function.
  • Passwordless access, posture management, and privileged access governance are converging into one buying conversation across the region.
  • Teams that cannot show secure access continuity and control evidence across environments will struggle to meet the new bar.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on access resilience, entitlement control, and identity governance across environments.
GV.RM-01 — Risk Management StrategyThe post frames identity decisions as part of operational and regulatory risk management.
Recommendation — Apply PR.AA-05 to validate identity entitlements and keep access aligned to resilience requirements. Fold identity security priorities into the organisation’s formal risk strategy and resilience planning.
NIST SP 800-63SP 800-63B — AuthenticationPasswordless access is an authentication topic directly tied to the article’s core message.
Recommendation — Use SP 800-63B to strengthen authentication policy and reduce dependence on reusable credentials.
DORAOperational resilienceThe article explicitly cites DORA as a regional driver for resilient security solutions.
Recommendation — Map identity controls to DORA resilience expectations and retain evidence for continuity and recovery.
ISO/IEC 27001:2022A.5.15 — Access controlThe article is about governance of secure access and identity controls in mixed environments.
Recommendation — Use A.5.15 to structure access governance across cloud, hybrid, and on-premises identity estates.

Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Identity Security Posture Management: Identity security posture management is the continuous assessment of identity configuration, privilege, and exposure across an environment. It focuses on drift, overprivilege, and control gaps so teams can see where IAM, PAM, and NHI governance are failing before those gaps become incidents.
  • Operational Resilience: Operational resilience is the ability to keep critical services running or recover them quickly after disruption. In identity-led environments, that depends on authentication services, privilege management, and recovery procedures that can be tested under realistic failure conditions.
  • DORA: The Digital Operational Resilience Act is an EU regulation focused on ICT risk and operational resilience in financial services. It requires organisations to identify critical services, manage risks, test controls, and maintain clear accountability so they can withstand disruption, respond effectively, and demonstrate resilience to regulators.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org