In 2025, attackers are increasingly targeting the identity layer, bypassing traditional security measures like Multi-Factor Authentication (MFA) and Identity Governance and Administration (IGA). This shift from device and network layers to identity presents a significant challenge for organizations striving to maintain robust cybersecurity defenses.
Privileged Access Management (PAM) and identity resilience have become essential components in safeguarding organizations. By implementing comprehensive identity threat protection architectures and integrating them into risk management strategies, companies can strengthen their defenses against sophisticated attacks.
Paul Fisher, Lead Analyst at KuppingerCole, will delve into the current state of identity-based attacks and their implications for IT security. He will discuss the limitations of traditional IAM approaches and introduce advanced concepts for building resilient identity infrastructures that can withstand and recover from modern cyber threats.
Andre Priebe, Chief Technology Officer at iC Consult, will present practical strategies for enhancing identity security posture. He will outline a 100-day plan to improve defenses against evolving threats, covering topics such as effective identity security assessment, building robust identity threat protection architectures, and integrating these solutions into comprehensive risk management frameworks.
Hello, good afternoon, good evening, or good morning, depending on where you're watching this. And welcome to this KuppingerCole webinar today in collaboration with my good friends iC Consult. And we'll be talking about MFA and IGA, as we often do, but why those aren't themselves enough in 2025. And I will talk a little bit about where we're going with that. And then Andrea will talk about a bit more in detail with a 100-day plan. So just some housekeeping, you don't need to do anything, just listen, sit back, relax.
There will be a couple of polls, which we'll run, and then we'll look at the results during the Q&A. And of course, the Q&A itself is your chance to ask questions to myself and Andre, and you can do that by entering the questions into the panel on the Livestorm control panel. And finally, we are recording the webinar so that any of your colleagues can watch it, or you can watch it yourself, because it'll be so good, it's worth watching twice. And that'll be ready in the next few days. So that's the agenda here, as they spot the typo.
What we're unpacking during the session is not what it should say, but I'll be doing some background on MFA, IGA, et cetera, where it is. And then Andre, I'm pleased to say, will be talking about his 100-day plan in the second half, and then we'll have our Q&A. So before we get into that, let's look at the first poll. And we're asking, what were your organization's key focus areas for cybersecurity investment over the past year?
And would they be IA identity, access management solutions, threat detection and security analysis, or any kind of XDR, cloud security in general, and specifically data security protection? So those four, again, IAM solutions, threat detection, security analysis, cloud security, or data security protection. So that will keep running in the background while I get into the first part of the webinar.
Now, we are actually, for those of you in the UK, and possibly in Europe as well, you probably will have heard about the attack on Marks and Spencer's, the well-known British food and clothes retailer, which has cost them something like 300 million pounds. It's caused the stock price to submerge, and the damage is still ongoing. So if you are like me, a shopper at Marks and Spencer's, many of their food items are still not available, and many of their clothes items aren't available, and their online operation is not available. So you can imagine the damage that this is doing.
Now, the reason I bring it up is because this attack, like so many, was based on identity, and it wasn't so much that MFA and IGA were being bypassed. It was a good old-fashioned piece of social engineering that, just like the attacks a couple of years ago in Las Vegas, the attackers managed to dupe a human-based support line, saying that they need to change their passwords, and were granted new passwords, and had straight access into Marks and Spencer's.
So what that shows is that we, even when we put in place sophisticated MFA and IGA, that if it's not done properly, then we can easily fall prey to such attacks. And it's really quite sad that this has happened and caused so much damage by something that could have been so easily prevented. I'm not going to judge Marks and Spencer's on this. The investigations are still going on internally for them, so I'm sure at some point we'll know exactly what happened, but we do know that this attack was caused by an identity theft situation.
And that's just generally the pattern that we're seeing now in cyberattacks on major organizations, major corporations, hospitals, things like that, that the attackers are no longer trying to bash their way in, going straight to the networks of devices, but are actually looking at the identity layer and using various techniques to see how they can get in through using an identity. And often that involves either stealing that identity or piggybacking alongside a genuine identity and spoofing that, and then getting access sideways to stuff.
So I'll keep saying this, but I think that in some ways we in our industry need to think a lot more about the basics of what we're doing, the basics of identity access management, the basics of privilege access, et cetera, rather than focusing on perhaps technologies coming down the line in because if even right now in 2025, a company like Marks and Spencer's can be attacked so easily, it means that every business can be. So the thing about IAM right now is that it is designed for access control.
I mean, that's what it is, identity access management. It wasn't designed for threat detection. It wasn't designed to say, hang on a sec guys, this identity checks out, but it seems to be coming from a weird place. They seem to be looking at stuff they don't normally look at. And it is on its own inadequate against modern attack vectors.
But again, it's also inadequate if it's not used, if it's not being deployed, then your attack vector can be pretty old fashioned, let alone modern. Plus identity access management is a one way ticket. It doesn't have as yet recovery and response capabilities or any form of mitigation, which allows the attack to be analyzed, stopped in case it happens again, and so on. So there are some limitations. Identity access management is very, very good, and it's got a lot better.
But, you know, it still isn't the whole package. And Andre will talk a little bit more about what you can do to improve that through the acquisition of different technologies, different policies, etc. So we need to start thinking about strengthening the identity layer. So for example, the identity layer isn't just a directory, isn't just Windows directory, it isn't just entering things, it isn't just a list of identities. We need to think a lot more about how those identities are being used, how they send out signals, when they're activated, so that you can see what that identity is doing.
So that's detection bit. And then, for example, if an identity starts accessing Marks and Spencer's database, customer database, or anything important, you can do something about it. So we need to see the entering the the emergence of ITDR into the identity layer. And my friend privilege access management, which has been around for many, many years, but is still critical in adding an extra layer, so that you can control those assets, those libraries, those databases, those servers, etc, those web servers, that should only be accessed by certain identities, whether they're machine or humans.
And privilege access does that for you. I'm not going to go into great detail about privilege access, but privilege access simply means that you have an extra layer of protection against access to privilege assets.
Of course, that is changing as well, because this type and scale of both privilege assets, and the identities that are allowed to access them is changing very, very rapidly. And AI is also having an impact on that. So we also need to move from simply reactive. So even identity threat detection response is reactive. But we need to have more resilient identity security so that the unknown, or what potentially the risks of everything that could happen, should be built in to a layer of the identity so that if these situations happen, and of course, it's difficult to guess what an attack may be.
But I think the history shows us that attackers tend to use the same sorts of attacks. They're not quite as advanced as you're often told by vendors, for example, for example, Marks and Spencer's. So it's well known that the type of phishing attack, social engineering attack is going to be used. So why haven't we built a layer into an extra level of security in the identity layer, which would detect that?
Now, risk management has kind of a muddy reputation in cyber security circles. Some people say that risk management has become too dominant in that people think about risks, rather than situations and technological attack paths. But for me, risk management is still important.
You know, it's better to think about the risks, add in those likely attack paths into that risk strategy, and then align your identity access management with that. So yes, there can be a lot of fluff involved in risk management techniques. And certainly, some organizations see a risk management exercise as simply, okay, we thought about it.
Yeah, we'll, okay, that could happen, but don't do anything to stop it happening, which is not great risk management, that's just sort of risk assessment. And identity should be more than just a gateway. So identity isn't just your username, password, or your credential, or whatever, a certificate, ICH key, whatever that is, shouldn't just be the gateway, it should also be a control surface, going back to what I was saying earlier about what is this identity doing, where is it coming from? Why is it up at this time of night, and all that kind of stuff, where is it going?
So rather than just thinking about the compliance checkboxing, which will keep you compliant in as much as you allegedly are within compliance laws, but you're not actually compliant if you then suddenly get hit by a cyber attack, which proves that you haven't protected your personal identity, personal identification carefully, you haven't protected your customers data, you haven't protected your own systems, and so on. So there's a difference between compliance and continuous protection. One is saying that you probably have done this, and the other one is ensuring you've done it.
And that doesn't necessarily have to be the stuff that compliance asks for, it can be more. Okay, quick break, poll number two. So which of these identity security technologies do you expect being most adopted in the next three years? So we have password authentication, Kim, or cloud infrastructure entitlement management, zero trust network access, decentralized identity, or SASE or SSE. So those three, password authentication, Kim, ZTNA, decentralized identity, SASE. So we'll leave that one running as well when I get back to the theme.
Now, I put a picture here saying the do nothing club, which is a slightly tongue in cheek picture here, but it's sort of saying, kind of IAM can help you achieve these things without having to do as much, maybe not do nothing. But some people mistakenly think that using a managed service for identity access management simply means that they can then roll over all the responsibility for data protection, data privacy to the managed service.
Well, that's not true. You can't do that. You still have to be responsible.
In fact, you are legally responsible. The data owner or the data controller is the one responsible for the data. But it does mean that if you find a MSP doing IAM, they will be able to provide properly a wider, bigger, more continuous service than you can do on your own. They will have access to experts that you perhaps do not. They should, if they're good, be able to rapidly contain and remediate an incident. If they're not, then they shouldn't be in business.
And also, they would have had a number of real world use cases, which hopefully will have seen them understand the threats and how they're used, how attackers go about what they're doing, and would lead into them being able to quickly find a solution to an attack on your organization. So if you go to managed IAM, you're not sold. You can't just say, great, now our job's done. We can forget it.
But it is an option for smaller organizations, particularly smaller SMBs, et cetera, that don't have big cyber teams, don't perhaps have big cloud security teams, et cetera, and also don't wish or have the skills to manage identity because managing identity has become more complicated. So this is where we, I hand over in a minute to Andre. And what we're talking about is not magic, but it involves work. But if you work with a IAM provider, so MSP provider, for example, they should be able to do stuff like this as part of what we're calling 100-day identity resilience plan.
So they should be able to look at your IAM posture. They should be able to read it, assess it, see where the gaps are, see what should be done to close those gaps, and see where your areas of vulnerability and risk are. They should be able to, if needed, deploy ITDR tools. And if you don't have privilege access at the moment, you will probably find you do need it because even the smallest organizations now and will have or allow access to stuff which is critical in terms of what it does, what it leads to. And don't forget, we're all in one massive supply chain.
So your small SMB, it might not have an awful lot real estate, IT real estate, but you are connected to something bigger. And that's exactly what happened to Marks and Spencers. The attackers came through a third party. So at some point, most companies are a third party to another. So privilege access management is hugely important. Don't let anyone tell you that privilege access is yesterday's technology because it isn't. It's just changing in the form that it takes. But privilege access is still access.
And then finally, part of this could be to train your own people on identity instant response. There's lots more to talk about. And I'll let Andre now, and I'll hand over to Andre to tell you more about the 100 Day Plan. So welcome, Andre. Let's talk about what you can do. I think it's crystal clear that the identity layer is really cornerstone when it comes to safeguarding the enterprise. It's protecting the IT assets. It doesn't matter where they are. At the same time, it is not just a new parameter.
No, it's unfortunately, as you pointed out, Paul, it's also a tech surface. And at the same time, it is the loot for the attacker. Marks and Spencer already informed their customers that unfortunately, customer data has been exposed. And this is now a perfect starting point for a lot of identity set. So that's something what we also have to be aware of.
And Paul, you mentioned PAM several times. And having a PAM tool is absolutely crucial. But what we often notice is that the limitations come in that access via PAM is not always enforced everywhere. So we are protecting a few assets via PAM and a large area is out of scope or to do for the future. And then it is not completely leveraged there. And so when it comes to the 100 Day Plan, the first important thing is really to structure and understand the landscape. And let me provide you some insights into that. So typically, we have the area to really protect assets.
And that's an area in which we are applying multi-factor authentication, of course, phishing resistant, and having at least privileged paradigm applied, IGA tools in place, and so on and so forth. But there are other phases we have to focus on as well. And I would like to start with identification. Here is it about getting, first of all, a good understanding how your identity attack surface looks like. Because today, it is not enough to think about, hey, what services do I expose to the internet? What ports are open? What applications are running there?
Because remember what was happening to Ticketmaster, for instance, last year? Snowflake was a kind of entry point for the tech as well as SaaS service outside. But one point we will talk about a little bit later is responsibility and how does it look like? Because that's a very important point, Paul.
Paul, you often mentioned that already. So getting good understanding by really discover what kind of identities are used, what credentials do I have out there? What service do I access by my users? What devices do they use? We have a very good understanding of that attack surface. It's absolutely necessary to then protect that very well. But we don't want to talk too much about the protection piece, but focusing now on the area of detecting that right now an attack is ongoing and then responding to that ITDR.
That's typically something that is often combined because something that is also necessary is to respond very fast. CrowdStrike published their global threat report I think one or two months ago and it was always kind of an eye-opener to see what is the average breakout time from an attacker to perform lateral movement. And the average time is getting smaller every single year. Average is significantly below one hour and the fastest one hour, one or two minutes, something like that.
So respond is absolutely important, but when it comes to the detection it is absolutely crucial to understand what kind of attacks am I able to detect. And that's something we will dive into deeper from an architectural perspective because ITDR is not equals ITDR. There are a lot of different things going on and that's something that is important for architectural understanding and looking at the different areas.
And then the area you hopefully never need to have the recovery part because if you are in that situation then the attack was very successful in bringing your whole IT infrastructure down. And sometimes we are not paying enough attention on what does recovery means from the perspective of identity because this is more than just a database you have to directory. Several domains, forests, and getting something like that up and running is a precondition for everything else.
Because identity layer is up and running it doesn't make sense to bring any business application back to life because the users can't access it. They can't do the work to earn the revenue of your organization. And yeah Paul you mentioned the 300 million pounds that are right now the damage Marks and Spencer is estimating so far. And so it can be really significant and we have seen companies going out of business after a successful attack. And so therefore the recovery part is important and that also applies of course to identity provider you're operating in the cloud.
Because don't assume that this is a kind of responsibility you got rid of by purchasing a SaaS. We will look into that part a little bit later. And so now let's really focus on the challenges that we have out there. First of all is having good understanding about what measures do I have and what attacks can I detect and prevent and what other areas I'm just not aware of at all. And then the lack of governance, enforcement and control. So having a PAM system deployed and using it as a password vault and that's it. It's better than just having an extra sheet but not much better.
It's not really a layer to protect your IT assets to protect the most critical accounts. There you have to really make sure that you enforce on a technical level that this is not bypassed by any means. So this is something to take into consideration as well. And then timing. What is the mean time to detect an identity threat that's going on and respond to it? Is this something what is significantly lower than the average breakout duration? So that's something the question should answer for yourselves in order to understand if you are in a good shape in that area.
So before we look into the architecture and just two frameworks, I don't want to explain these details. I'm sure most of you are very aware of them. The zero trust pillars, identity devices, networks, application workloads and data and the cyber security framework functions we have seen before. But one exercise that might be very valuable to stand on a very, very high level, the capabilities you have in place is building metrics of that focusing everything before the breach. Identification.
So getting real insights, a tech surface and what devices are accessing my applications, my touch points and so on. The protection layer. What do I have in place? What do I really enforce? For instance, do I enforce a just compliant managed devices are able to access my IT assets? Likely that's the case for some of the assets, but likely not for all of them because of contractors or customers, consumers, user populations with devices completely out of your control. Then the capabilities to detect that right now an attack is ongoing. For instance, having the endpoint protections in place.
But again, also understanding what do I have on my identity layer, capabilities to respond to that. Is it sufficient to lock the account in the active directory, the primary account? What other accounts might be related to that? What accounts are living at SaaS services? What sessions do live at SaaS services and refresh tokens? All these kinds of things that you also have to revoke in order to stop an attack that's just depending on the identity and the cloud, not within your organization, IT, not on your devices at all. And then the recover capabilities as pointed out.
So we'll just pick out one area, the detection area in the identity space, because that alone is adding a lot of complexity. So let's now jump into the architectural perspective. So we have user accessing resources that might be SaaS, might be on-prem or on your infrastructure and that are connected to a modern identity provider in the cloud via protocols like SAML, OpenID Connect, OAuth or are using Kerberos or still things like NTLM might also be the case.
And if we are now talking about ITDR or Identity Threat Protection, then the first important step is to look into that market, the solutions out there, important things to understand. How is that solution working? What kind of threats does that solution detect? So is it focusing on the identity provider itself?
Often, this is a functionality that is delivered as out-of-the-box capabilities by the identity provider or as an additional module for that. When it comes to Active Directory, sometimes it's even required to look into two different aspects here. One is really kind of very runtime-focused attacks on the token layer, silver, gold, and take a pass, a hash and so on. Or when it comes to privilege escalation, something what is happening at admin time, what is really persisted in the Active Directory.
This is very critical when it comes to that kind of after breach thoughts and how to get back into a state in which the attacker doesn't have access to the Active Directory. And then solutions that are focusing on the identity layer of SaaS applications, really leveraging the user events that are happening there. For instance, what is going on if the user is accessing, reading all the documents he has access to, modifying all the documents, purging the history of them?
Yeah, likely a randomware attack. Yeah, it's right now, the attacker's right now encrypting everything, right? So just user behavior that gives a high level of evidence. So it's really kind of an indicator of compromise regarding SaaS service out there. And then the same as a focus on resources running on servers, clients under your control. So everything that is really endpoint-focused. For instance, if someone is accessing the sessions locally available on a device, cookies, and so on, and so forth. So that's a kind of high-level overview.
Last part here is really kind of leveraging the outside threat intelligence because the attackers are highly professional. They are focusing on their core competence, and their core competence might be just spear-phishing credentials, enabling devices with MFA in order to log in. But they are not logging in. They're just selling that information to another professional attacker that is focusing on logging into systems and then that removal and randomware, all these kinds of things.
So having that in mind, it gives good indication if information credential of your organization is out in the dark net for sale. All right. That's identity threat protection piece. Another part I just want to cover briefly, and then talking a little bit about what to do the next 100 days. It's an identity recovery piece because what is very important, and that's something you really have to make sure that there's no kind of misunderstanding around that, is that shared responsibility model that Paul mentioned at the beginning. So what is your provider doing in regards to identity?
Because if you're having a standard SaaS service out there, and configurations, and also content is your responsibility. And therefore, which would have the capabilities to recover after an attack, making sure that you are able to restore configurations, but also the user data, and group information roles, privileges, all these kinds of things, right? So that's something where it has to be crystal clear what is your responsibility. And then also, what do I have to do in order to make sure that the tech isn't able to lock in directly after I restored everything, right?
So just restoring a backup might not be sufficient as well. So that's the part on identity recovery.
And now, let's talk a little bit about what to do the next 100 days. So the first task is really to have a good understanding of the capabilities you deployed, and the scope that deployment has. You deployed PAM, great. It's just a place where you're managing, where you store the password. Not more than that. Not so great anymore. So can you really enforce it? Yeah. So what capabilities, and what is the scope of these deployments? They are MFA deployed. Great. How many applications are we protected via MFA? Just the ones in the cloud, not the ones connected to Active Directory? Not so great.
Just 30% of the users are enrolled. And then also, there's a large tech surface still open.
But also, what are quick wins you might have? Because you're not leveraging the full potential of solutions, licenses you brought. So that's something that we often see, especially when it comes to entry ID, that just a small part of these capabilities that the customer is paying for are really leveraged. So there's huge potential around that. Then the next thing is understanding the wide spots you have.
Remember the metrics we have seen, and assess really the areas that comes with the highest risks, and map them to the capabilities you already need in order to really understand what are the benefits I get? What are the costs related to that? Because that really helps you to build a roadmap. Because resources are always limited, you will not get unlimited amount of money.
Okay, maybe if you have the Caesar of Marx and Spencer, and the company survives, then maybe you get that amount of money. But otherwise, you have to really think about what are the quick wins I can implement fast? What are the things I have to plan for, and where I get the best mitigations of the critical risks for my investments? Then one point I would like to mention, not everything is required to be a long running project to get the benefits out of that.
There are solutions out there that are also used in post breach scenarios in order to make sure that after the recovery, that TEPA isn't able to just lock in again and doing the same thing again, because it's maybe not crystal clear what was a path used at the end of the day. So that's also something you should have in mind. And this is really the homework for the 100 days. A good starting point is going really into some professional assessment into that. Helps you to build a reliable plan that you can then execute, and then right away making sure that you really leverage what you already have.
Also, Paul mentioned managed identity provider services, security managed identity security services. So instead of building all the capability for yourself, it's also, of course, an option going for a provider that can really help you with that by providing, first of all, the know-how, but also the tools already that you need to cover all these areas post breach and after breach. And it's working based on defined SLAs, but because if your IT team is getting a notification and then responding to it after three hours, then the average attacker already moved within your enterprise IT.
That's too slow. So having a provider might be the best approach if you don't have the capabilities inside your team. All right. So these are my recommendations.
And now, Paul, I think we have time to cover questions around that. We do. Thanks very much, Andrei. It's very important to say that this is not just the 100 days and that's it, right? It's like the first 100 days of government. Everyone always talks about that. But I mean, that's just to get the basics done. I really like the way you talk about the easy wins, et cetera, and then build on that, right? The basics, having the basics in place, and then having also a plan in place. So that's really the goal you want to achieve in these 100 days. Yeah. So we do have questions.
In fact, we have a few. So this is from Tom Bushuren. You mentioned the NIST CSF.
Sorry, I'll say that again. You mentioned the NIST CSF. So how does the framework relate to NIST 2, which is the EU thing? Quite confusing, but anyway, they are different. So how do the two frameworks relate where many organizations are subject to NIST 2?
So yeah, that is one of the problems, I guess, that we do have overlapping frameworks. We do have overlapping sort of governance and compliance. But I would imagine that NIST 2 is the one that's of more relevance to EU-based companies initially.
Yeah, well, of course, because that's really kind of regulatory you have to comply to, right? But when it really comes to kind of guidance, how do I tackle these challenges, then NIST with the CSF is providing very valuable tools around that. At the end of the day, our experience is when it comes to the technical implementations that you have to do in order to protect your IT infrastructure, they are not forcing you doing completely different things. It's more about how you're really mapping controls or things you implemented to regulatory requirements.
So that's something where you have to work on. But when it really comes to the technical solid foundation, there's not a huge difference around different regulations in these routes.
Okay, the next question is, what are the most effective strategies to ensure identity resilience in a hybrid environment with both on-prem and cloud identity systems? So that's quite a big question, but you could maybe just, in a nutshell, give some strategies to follow, and perhaps they could follow up with you afterwards, a sort of more detailed description.
Yeah, well, first of all, I would recommend targeting for solutions that have a broader set of functionalities so that you have one solution that helps you to provide resilience around your on-prem system, at the same time for your SaaS and identity systems you have in the cloud. That might not always be possible, but I would say that that area is developing very fast, and there are solutions out there that are not just focusing on that one single active directory piece, but really helping you also with your cloud identity.
So we are often, during the assessment phase, working with different vendors to make sure that there's a crystal clear understanding of what is fitting best into a client's organization. So we have to support there and providing then possible solutions that fit to that combination of systems that are relevant.
Okay, so that question was from Alfred there, so Alfred, you could follow up with IC Consult, if you like, to talk more about that. Another question, and then we'll look at the poll results, one of the poll results. This one is more basic, I guess. Can my IGA tool cover the new topics you mentioned, or do I need to buy a separate solution? So I guess what he means is, what they mean is, they do have some IGA installed. Do they need you to reinvent that, or can they keep it?
Yeah, so even if you're somehow saying IGA is not enough, it's absolutely not possible to say, okay, we're not doing it anymore. We are having identity threat protection in place, so no need to do IGA anymore.
No, that stays absolutely relevant. And when it comes to the functionality side, so IGA vendors are heavily investing, also looking into other segments. So there's one vendor also that started two, three weeks ago, their ISPM solution. If you're already working with that vendor, that might be a good fit.
Otherwise, their specialized tools covering especially that area. So I would say it really depends on how your IGA solution looks like, if you can leverage that, or if you have to go, or better going for something separate.
Okay, unfortunately, I can't see the poll results on my tool here. So let's just carry on with the questions. Is there a specific need, this is from Roshan Kariadan, is there a specific need to have a dedicated ITDR tool? We have tools for managing IGA, MFA, SSO, and PAM. Just trying to understand the perimeter where a dedicated ITDR tool is needed.
So yeah, again, that's probably hard to answer quickly, but maybe just some ideas. Again, it depends on what tools you deployed for these different functionalities. I say there's likelihood that they can cover some of these ITDR functionalities. Remember the slide I showed, there's five or six different architectures when it comes to ITDR. So it might be that you have already one or two of them as part of your tools, right? And then it's really about looking what are the areas that are untouched, where you're blind.
And then assessing them from a risk perspective, if this is the next step to invest on. In that case, you would like to go for a dedicated ITDR tool. Or maybe you can add modules to the solutions you already have to cover these areas as well. Would you recommend running a separate identity provider instance as a hot standby? Just in case the one that you're running fails, falls over, et cetera. Yeah.
So that's something that was brought up from time to time, having really in after a significant attack, you want to just having a new identity provider already up and running so that you easily can switch over. So of course, it depends a little bit. So my experience is there are a couple of areas that are very, very challenging. One is really, are you able to have the user credentials available at the other provider so that the end user is easily able to access it? And if you're just saying, that's not a problem, I'm synchronizing the passwords and you have another problem, right?
Because password authentication isn't sufficient. So if you have something phishing resistant in place like passkeys and more Friday tools, then it might be very challenging because this is really bound to a domain. So it's possible, but there are a lot of things you have to take into consideration, but the other hard part are the application landscape. Is it easily possible to switch the applications to the other identity provider? And that's something what you really have to build in from a kind of onboarding strategy for these applications, making sure to have these capabilities in place.
If you're able to do that, then it's a huge benefit, but it comes with, I would say, obviously significant costs related to that. So it's not a crystal clear recommendation to do that always, but there might be situations in which that is adding value, especially if you're targeting for very, very high availability.
Okay, I have just got one of the poll results here we could just discuss. Unfortunately, I can't show it on screen, so I'll read them out. Which of these identities technologies do you expect being most adopted in the next three years? 39% said passwordless authentication, 24% said ZTNA, 18% Kim, C-I-E-M, then 15% decentralized identity, and finally just 3% for SASE.
So that, I guess, shows there is a burning desire for security, but also for ease of use for end users, and password is certainly generating a lot of interest there, and I'm not surprised myself. Zero trust is something that I think is hyped up quite a bit. So people think, oh, we must have zero trust, and Kim, which to me has surprised me, but obviously there is interest in cloud security or cloud management. What's your take on those results as well?
Yeah, that sounds very reasonable. Honestly, still number one priority is we have to have phishing-resistant authentication, because it's in place. There's no way around that, right?
But again, it makes a lot of sense to me, and it's my perspective, my direction too, to take the investments in the near future. Okay, and then I have got the second one, which was what were your organization's key focus areas of cybersecurity investment over the past year, and very much in line with what you've been talking about. We've been talking about by head 38% threat detection and security analysis, so people are definitely interested in detection and also seeing how things happen. Then identity and access management solutions, cloud security, and then data security protection.
So, I mean, no real surprises there, but obviously people are crying out for some way of stopping attacks before they can happen, which is precisely what is not happening too much. What do you think of that as well?
Yeah, I would say there are a lot of areas where typically you would have to do something to invest in, to improve around, and I think it's showing the right direction. The thing I always want to highlight is challenging you when it comes to the scope, what is really the capability is one thing, but is it really effective? What are areas the thing you deployed is just not looking at? And that's something what we always have in mind, and because attackers will find that white spot.
So, that's important to really leverage the investment you made. Okay.
Well, no more questions have come in. We've done the poll, so I guess really all that left for me to say is thank you very much, Andrei. I think our promotional video that we did together has really bumped up the numbers on this, so let's do that again in a year's time in Berlin. But seriously, I hope that you watching have got something out of it.
Obviously, it's just the first steps. There's lots more to ask both Andrei, but also Kup and Nicole, analysts and advisors. If you need any support on any kind of project involving identity and access management, please do get in touch. And that's about it, really. Thanks again for watching.
Thank you, Andrei, again. Thank you to Oskar back in Berlin, controlling stuff behind the scenes. He never gets a mention, so I thought I'd mention him today, and see you next time on the next webinar. Bye now. Thank you. Thank you very much, Paul. It was a pleasure, as always, and also thank you to our audience. It's always great getting a lot of questions and to discuss. I enjoyed it a lot, so have a great day. Bye.
See All Locations
See All Locations