TL;DR: ANZ enterprises are using customer identity data to improve customer experiences and support zero trust priorities, according to Ping Identity’s survey report on how CIOs are leveraging customer data. The implication for IAM teams is that customer identity programmes now sit between personalisation, risk, and governance, not just login and profile management.
NHIMG editorial — based on content published by Ping Identity: How CIOs Are Leveraging Their Customer Data
Questions worth separating out
Q: How should organisations govern customer identity data for personalization?
A: Organisations should treat customer identity data like governed source material, not campaign input.
Q: Why does customer identity matter to zero trust programmes?
A: Customer identity matters because zero trust depends on current, trustworthy context at the moment of decision.
Q: What do teams get wrong about personalisation and identity verification?
A: Teams often treat customer history, device behaviour, or engagement data as proof of identity.
Practitioner guidance
- Map customer identity data flows end to end Document where customer attributes, authentication results, consent state, and behavioural signals are collected, stored, and consumed.
- Separate authoritative signals from advisory signals Define which customer identity inputs can change access decisions and which can only inform them.
- Review retention and reuse rules for identity data Confirm that customer identity attributes used in trust decisions are retained only as long as needed and are not repurposed without approval.
What's in the full report
Ping Identity's full survey report covers the operational detail this post intentionally leaves for the source:
- Survey findings on how ANZ organisations are actually using customer identity data across experience and security use cases
- Breakdowns of the survey questions and response context that support the report's conclusions
- Additional customer identity and zero trust use cases discussed in the report beyond the high-level governance view
- The complete framing of CIO priorities, including how respondents think about data use and identity-driven trust decisions
👉 Read Ping Identity's survey report on how CIOs are leveraging customer data →
Customer data in CIAM: what ANZ enterprises are doing with identity?
Explore further
Customer identity data has become a governance asset, not just a personalisation input. Once identity information feeds both experience design and access decisions, the governance burden changes. The same profile data that improves conversion can also expand exposure if collection, retention, and policy use are not tightly bounded. Practitioners should treat customer identity data as a controlled security input, not a marketing by-product.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own customer identity governance when experience and security collide?
A: CIAM needs shared ownership across security, product, and customer experience teams because the impact spans access, conversion, and privacy. Security can define assurance requirements, but product and CX must help shape the journey so controls do not destroy trust in the process.
👉 Read our full editorial: Customer data, identity, and zero trust in ANZ enterprises