Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Moonpig and CIAM conversion: what should IAM teams take from it?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Personalized account strategies can improve customer conversion while preserving security and global scale, according to Ory, as Moonpig used it to build one. The practical lesson is that CIAM design now has to balance identity assurance, friction, and lifecycle control rather than treating registration as a purely marketing problem.

NHIMG editorial — based on content published by Ory: Making Every Moment Matter: How Moonpig Mastered Customer Conversion with Ory

Questions worth separating out

Q: How should organisations balance CIAM conversion with security?

A: Use a shared decision model that treats conversion, fraud resistance, and identity assurance as one programme.

Q: Why do customer identity programmes fail when they focus only on sign-up?

A: Because sign-up is only the first moment in a longer identity lifecycle.

Q: How can security teams tell whether a CIAM migration is actually working?

A: A migration is working when active users are moving without repeated login failures, support tickets are falling, and the legacy system is shrinking on schedule.

Practitioner guidance

What's in the full article

Ory's full blog post covers the operational detail this post intentionally leaves for the source:

  • The account strategy choices behind the Moonpig implementation, including how customer journeys were shaped for conversion.
  • The practical CIAM design trade-offs that were considered for security, scale, and personalised identity experiences.
  • The implementation details that matter once teams move from programme design to production rollout.
  • The broader context for teams evaluating customer identity patterns in their own environments.

👉 Read Ory's Moonpig case study on customer conversion and CIAM →

Moonpig and CIAM conversion: what should IAM teams take from it?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

CIAM conversion is now an identity governance problem, not a marketing side issue. When customer journeys are built to maximise conversion, the identity team still owns the security and lifecycle consequences of those choices. That means registration, account recovery, and profile growth have to be governed as one identity system, not separate product motions. Practitioners should treat conversion goals as part of CIAM design review, not as a reason to weaken identity discipline.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, which shows how often policy intent fails at execution.

A question worth separating out:

Q: What is the difference between customer convenience and weak identity assurance in CIAM?

A: Customer convenience reduces unnecessary friction, while weak assurance removes controls that are still needed to prove identity, manage sessions, or recover accounts safely. The test is whether the user experience can improve without making identity records less trustworthy over time.

👉 Read our full editorial: Moonpig’s CIAM conversion strategy and what it means for IAM



   
ReplyQuote
Share: