TL;DR: Rising demand for resilient identity controls, passwordless access, AI-powered threat defence, and identity security posture management, with DORA cited as a regional driver, according to RSA Security, is reflected in its new EMEA Central regional director appointment. The signal is that identity programmes are being judged on access resilience and regulatory readiness, not feature breadth.
Editorial analysis by NHI Mgmt Group, based on content published by RSA Security: “RSA to Power Growth in EMEA Central with Appointment of RSA Regional Director Sabine Davies”.
Key questions
Q: What frameworks should teams use to align identity security with resilience?
A: Teams should map identity controls to the NIST Cybersecurity Framework 2.0 and use NIST-based control language to connect access decisions to protect, detect and recover outcomes.
Q: Why does DORA change the way identity programmes are judged?
A: Because the standard pushes identity controls toward demonstrable resilience, not just policy compliance.
Q: What are the signs that identity posture management is not working?
A: Common warning signs include unknown identities, inconsistent ownership, privileges that survive role changes, and federation paths that nobody can explain.
Practitioner guidance
- Align identity roadmaps to resilience objectives Review whether passwordless, posture monitoring, and privileged access controls are being justified as operational resilience capabilities rather than isolated product features.
- Map identity controls to DORA expectations Document which identity controls support continuity, recovery, and secure access during disruption, especially where regulated business units need audit evidence.
- Assess identity security posture across all environments Check whether cloud, hybrid, and on-premises identities are being measured with one control view or fragmented reporting that hides policy drift.
Bottom line: The article is a hiring signal, but the underlying message is that identity security is being evaluated as a resilience and compliance function.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Regional identity hiring is now a proxy for control demand: This appointment is less about organisational structure than about where identity security budgets are moving. When a vendor frames regional growth around resilient controls, passwordless access, and posture management, it reflects buyer pressure to justify identity programmes in operational and regulatory terms. The practitioner takeaway is that identity security is being evaluated as a resilience function, not a narrow access layer.
A question worth separating out:
A: Bring them into one roadmap. Passwordless adoption, posture management, and privileged access governance affect each other, so separating them creates blind spots in control design, reporting, and funding decisions.
👉 Read our full editorial: RSA's EMEA Central leadership move and identity security priorities