A community for professionals who care about digital identity
Identity and access management hub
In a large organisation, the job of managing digital identities and access can feel like a non-stop challenge. You’re constantly balancing the need to stay ahead of new threats, navigate complex compliance rules, and adopt the latest technology. It’s a demanding mission, and you need a reliable partner.
Welcome to the Hippo Identity and Access Management Hub. We’ve carefully gathered and organised the most essential, actionable intelligence, from technical guides to strategic insights, all in one place. Stop wasting time hunting down scattered information, and start focusing your energy on securing your enterprise and innovating with confidence.
In a large organisation, the job of managing digital identities and access can feel like a non-stop challenge. You’re constantly balancing the need to stay ahead of new threats, navigate complex compliance rules, and adopt the latest technology. It’s a demanding mission, and you need a reliable partner.
Welcome to the Hippo Identity and Access Management Hub. We’ve carefully gathered and organised the most essential, actionable intelligence, from technical guides to strategic insights, all in one place. Stop wasting time hunting down scattered information, and start focusing your energy on securing your enterprise and innovating with confidence.
Watch our National ID Webinar
Hippo's Identity Director Jim Small, CEO Adam Lewis, Senior User Research Consultant Lauren Gorton, and David Rennie of Orchestrating Identity explore what national ID means for trust, access to services and real user journeys.
Join the latest "I am IAM" webinar and podcast on Monday 1st December.
Qualitative insights concerning the UK Digital Identity scheme
Hippo commissioned a qualitative research report in December 2025 to engage with the public and with the aim of understanding the downtrend in sentiment toward the national Digital ID scheme. The full research report explores public understanding and attitudes toward the initiative using in-depth interviews, and makes a set of recommendations for implementing digital IDs across government digital services.

Latest identity articles and news from Hippo

Customer Identity and Access Management (CIAM)
Discover what’s next in our new eBook

Putting users at the heart of financial services
Putting users at the heart of financial services can protect customers, prevent fraud and build better experiences through design and data.

Digital wallets
How to build for an emerging identity landscape
Digital identity:Seamless and secure
Identity and user access management solutions ensure that only authorised users can access your valuable services. By managing, and verifying digital identities, we can enhance security for your business and create streamlined, frictionless experiences for your users.
Digital identity:Balancing security and usability
Identity and access management helps ensure that only authorised users can access your valuable services. By managing and verifying digital identities in a user centred way, you can strengthen security without adding unnecessary friction. Done well, identity stays in the background for everyday tasks and only steps up when someone is accessing something high value or sensitive.
Digital ID in the UK:What do the users really think?
Hippo’s Jim Small is joined by Adam Lewis, CEO at Hippo, Lauren Gorton, Senior User Researcher at Hippo, and David Rennie, Chief Trust Officer at Orchestrating Identity, to explore how people in the UK understand digital identity and why uncertainty still shapes much of the conversation.
Together, they discuss what recent research tells us about public perception, why trust and accountability matter so much and how the conversation can move beyond concerns around centralised data towards practical value, everyday use and clearer public benefit.
Latest news from the sector
Ask an expert
Hippo are a proud member of the identity community. Our aim is support our partners, educate those with an interest and provide insights at every level.
What steps can we take during the transformation to future-proof the IAM solution against evolving technologies (like biometrics, Passkeys, and quantum computing)?
Future-proofing relies heavily on choosing a platform built on open standards and a flexible, API-first architecture. This avoids vendor lock-in and allows new authentication methods (like FIDO2/Passkeys) and authorisation protocols (like OAuth 2.0 or OpenID Connect) to be easily plugged in as they mature. Prioritise a solution that can abstract the underlying technology from the applications it serves.
In a complex regulatory environment, how do we guarantee our IAM program meets all necessary compliance and audit requirements (e.g., GDPR, NIST, sectoral mandates)?
Compliance must be a design constraint, not an afterthought. This requires integrating Governance, Risk, and Compliance (GRC) leaders from the beginning to define the required controls for data access, privacy, and sovereignty. A modern IAM platform should provide clear, auditable logs and features like fine-grained authorisation (based on attributes/roles) to prove compliance and simplify future audit cycles.
How can we justify the significant investment in a modern IAM solution to our financial sponsors and business unit leaders?
The justification moves beyond simply reducing risk; it focuses on measurable business value. This includes quantifying reduced IT support costs due to streamlined password management, demonstrating faster time-to-market for new services (enabled by better API security), and showing improved security posture (e.g., reduced time to revoke access for leavers). The goal is to tie IAM investment directly to both cost savings and operational efficiency.
Our current IAM is a complex mix of legacy systems. What is the safest way to transition to a modern, scalable platform without major service disruption?
The safest approach is a phased migration driven by immediate business value and risk reduction. This involves first identifying and unifying identity data sources, then implementing a new control plane that can sit alongside legacy systems. A strangler pattern is often used, where new applications are onboarded to the new platform while legacy systems are retired iteratively, minimising the single point of failure and allowing services to be tested thoroughly before full cutover.
How do we choose the right IAM technology vendor when the market offers so many complex solutions (e.g., Cloud Identity, CIAM, IGA)?
The decision should be driven by a thorough, technology-agnostic requirements analysis based on your target state architecture. Focus on criteria such as API-first design (for future integration), scalability (handling peak loads), deployment model (cloud vs. hybrid vs. on-premise), and the vendor ecosystem (partner support). A Proof of Concept (PoC) focusing on your most complex use cases is essential before committing to a final selection.
How do we integrate our IAM program with the wider Security Operations Centre (SOC) and threat detection framework?
Modern IAM must act as a crucial data source for security operations, not just a set of controls. The new platform must have robust logging and auditing capabilities that integrate seamlessly with your Security Information and Event Management (SIEM) system. This integration allows the SOC to correlate identity events (e.g., failed logins, role changes, privilege escalation) with network activity, enabling faster detection of compromised accounts and suspicious lateral movement, which is key to a Zero Trust strategy.
What is the role of ‘Zero Trust’ in our IAM transformation, and how do we begin implementing it effectively?
Zero Trust is a fundamental security model based on the principle of “never trust, always verify.” For IAM, this means moving beyond the network perimeter to enforce least privilege access and context-aware authorisation for every single access request. Effective implementation starts with identifying all subjects, assets, and resources, defining access policies based on multiple attributes (user role, device health, location, time), and constantly monitoring and verifying access after the initial grant.
How should we approach the increasing complexity of securing non-human identities, such as service accounts, APIs, and robotic process automation (RPA) bots?
Securing non-human entities requires implementing a robust Privileged Access Management (PAM) and Secrets Management strategy, tailored specifically for machine identities. This means eliminating hardcoded credentials, rotating secrets automatically, and using dedicated vaults or identity providers to authenticate and authorise services and APIs. This area is a significant blind spot and a major vector for modern attacks.
How do we ensure our new IAM governance model addresses issues like ‘access creep’ and maintains role clarity over the long term?
Maintaining governance requires implementing a formal Identity Governance and Administration (IGA) component. This involves automating processes like access certification (periodic review of user access by managers), defining and enforcing Separation of Duties (SoD) policies, and establishing clear workflows for role changes. This prevents users from accumulating unnecessary permissions (“access creep”) over time, which is a major compliance and security risk.
Once implemented, how do we ensure our internal IT and Security teams are ready to effectively own and maintain this sophisticated new IAM service?
Successful implementation requires concurrent capability building and knowledge transfer. The project delivery should adhere to a “one team” model, embedding your staff with delivery experts from the start. This ensures your teams are upskilled through structured training, develop detailed operational runbooks, and understand how to evolve the platform’s configuration and code using internal expertise.
Key contacts
We have an identity team of around 50 specialist consultants and supported by over 600 technology professionals. Our team work alongside and within clients in the largest public and private sector organisations.
Identity is a specialism
50+
Hippos with deep digital identity expertise
Part of a
600
strong team of technology professionals






















