Supply-chain attacks are surging — doubling in 2024 — and forecast to impact nearly half of all organizations by 2025. As regulatory pressure mounts under frameworks like DORA, CPS 230, and CMMC, securing external identities is no longer optional. Enterprises must urgently modernize their third-party access strategies to mitigate operational and compliance risks.
Technology leaders are now shifting to zero-trust identity models, adopting phishing-resistant passkeys, automating onboarding, and introducing continuous certification for external users. These capabilities are key to cutting audit fatigue and achieving real-time, provable control across global supplier ecosystems.
Warwick Ashford, Senior Analyst at KuppingerCole will explore the regulatory landscape driving urgency in third-party IAM. He’ll offer a market overview, explore emerging threats, and map the essential capabilities enterprises need to reduce risk, accelerate onboarding, and stay compliant with evolving mandates.
Mike Andren, Sr. Director IAM Product Management at Exostar, and Kevin Hancock, Director Solutions at Exostar, will jointly explore how Exostar Access One helps organizations automate identity proofing, delegate access administration, and achieve compliance alignment. They will present real-world deployments in aerospace and defense, showcase technical differentiators, and explain how automation delivers ROI while scaling to global partner ecosystems.
Hello and welcome to this webinar on Automating Third-Party Access with a view to ensuring compliance with a growing number of regulations as well as reducing cyber risk in real terms. Joining me in this webinar are Mike Andren and Kevin Hancock from Exostar.
Welcome, gentlemen. Thanks, Warwick. Looking forward to today's conversation. Good. We'll be looking at the important topic of mitigating third-party risk in the face of increasing supply chain cyber attacks and mounting regulatory pressure. I look forward to our discussion later. But before we go any further, I'd like to just run through some housekeeping and the agenda. As you can see, you are muted centrally, so there's no need to worry about the sound controls. We have a couple of polls for you to participate in, and we'll discuss the results later. There will be a Q&A session.
This is your chance to put your questions to the panel. So we'd like to make this as interactive as possible. So please enter your questions at any time. Using the questions tab, not the chat tab, but the questions tab, which you'll find in the bottom right of your screen. And don't worry about taking detailed notes because we are recording the webinar, and the webinar and the slide decks will be available for download in about a day or so. So now to run through the agenda.
First, I'll have a look at the threat and compliance landscape driving urgency in third-party IAM and how organizations can not only ensure compliance, but also reduce risk. Then I'll hand over to Mike and Kevin to provide the ExoSTAR perspective, give an overview of ExoSTAR Access One, and share some real-world deployments.
Finally, we look at the poll results and run through your questions. Remember, you don't have to wait until the end. You can enter your questions at any time by just going to the question tab. And just before I begin, I have a question for you. Here is our first poll question. What is your biggest challenge in managing third-party identities today? Select from one of the following options. Onboarding and offboarding inefficiencies, lack of visibility or auditing, manual access reviews and certifications, credential misuse or phishing risk, and third-party lifecycle tracking.
So please make your selection now on the polls tab on the control panel. But now let's get cracking. Anyone who follows cybersecurity news, and I'm sure that includes most of you, will know that supply chain attacks are becoming increasingly common. This is definitely a growing trend with several notable supply chain attacks. These include, but are certainly not limited to, Target in 2013, NotPetya in 2017, SolarWinds in 2020, Haseya in 2021, MoveIT in 2023, and Marks and Spencer in April 2025, which is not very long ago.
According to the retailer, the cost will be at least 300 million pounds, which is roughly $406 million. And the breach is thought to have begun through the systems of a third-party supplier of IT services, where tech support staff had their credentials stolen via social engineering.
Well, it's no wonder then that regulations are increasingly focusing on supply chain and third-party risk. Third parties, such as vendors, contractors, and partners, are a well-known attack vector. And there's several key reasons for that.
First, an expanded attack surface. Each third party added to an organization's ecosystem increases the number of access points into systems and data. Many third parties require access to internal applications, systems, or sensitive data, and this creates new pathways for attackers. Second is a lack of control over security posture. Organizations often have limited visibility into their third-party cybersecurity controls and hygiene. And smaller organizations may lack strong access controls, patch management, and network segmentation.
This creates weak links in the security chain that can be exploited. Third, overprivileged or persistent access. Third parties are often granted excessive or long-term access far beyond what's needed to get the job done. Access may not be revoked when a project ends, a contractor leaves, or a vendor relationship ends. This violates the principles not only of least privilege, but also of zero trust. The fourth thing is credential theft and compromise. We've already mentioned that compromised third-party credentials are a common entry point in breaches.
The already mentioned Target breach in 2013 being a classic example. With more recent breaches using compromised credentials, including the London Metropolitan Police in 2023, Cloudflare in 2024, PowerSchool in the US in January 2025, and M&S here in the UK in April. The problem is that vendors may reuse passwords, lack multi-factor authentication, or share credentials. We all know that attackers will always seek to exploit poor authentication processes and practices to gain access through legitimate accounts. Fifth is a lack of monitoring and logging.
The problem here is that many organizations do not monitor third-party activity around the clock. They just don't have the resources.
Now, without strong logging and anomaly detection capabilities, malicious actions can go undetected for a very long time. Sixth, insufficient vetting and risk assessment. The problem here is that onboarding of third parties is often fast-tracked without adequate security, and it is more than often not rare for organizations to reassess third-party risk on a continual basis. They may do it once, if at all, but not again.
Seventh, exploitation of trust relationships. Supply chain attacks typically abuse the fact that third parties are implicitly trusted once inside the network, and so this is why the zero trust principle is so important. To prevent the abuse of this trust and to prevent lateral movement by attackers. Eighth is the lack of central access management. Many organizations lack a centralized capability to manage third-party identities and their access rights, and this leads to siloed access provisioning, manual errors, and the inability to enforce consistent policies. Ninth are regulatory blind spots.
Third-party governance is often neglected, leading to gaps in auditing, documentation, and access reviews. So there is a long list of things that can be exploited unless strong third-party IAM and governance controls are enforced, and as a result, regulations are emphasizing accountability for third-party access, making it insufficient to merely manage internal issues. So there are three key examples of this. First is the EU's Digital Operational Resilience Act, or DORA. It applies to financial entities and critical ICT service providers in the EU.
But DORA is not limited to companies physically located within the EU. It applies to financial institutions and ICT service providers regardless of where they're located. If they operate within the EU or have EU clients. So even if a financial entity or ICT provider is based outside the EU, they may still be subject to DORA. Looking at third-party risk, Chapter 5 of the Act mandates rigorous oversight of third-party ICT providers, including identity management practices. It emphasizes risk-based access controls, continuous monitoring, and contractual obligations for security.
Looking at the IAM implications, financial institutions must ensure secure and auditable identity management for all external ICT service providers. This drives adoption of centralized identity governance, least privileged access, and federated identity models across provider ecosystems.
Next, we look at CPS 230, which is the cross-industry prudential standard on operational risk management that is used by the Australian Prudential Regulation Authority, what a mouthful, or APRA. And it applies to all APRA-regulated institutions such as banks, insurers, and superannuation funds. Once again, if a foreign financial institution has operations in Australia, they are still required to comply with CPS 230, but only in relation to their Australian branch operations.
Looking at the third-party risk, there is a strong emphasis on operational resilience and management of service provider risks. And it requires institutions to identify, assess, and control risks from material service providers, including cyber and access-related risks.
Now, looking at the IAM implications, it enforces implementation of strong access controls for third parties. It promotes continuous access reviews, segregation of duties, and visibility over who has access to what systems and data. It also requires institutions to ensure that outsourced service providers follow equivalent IAM controls.
Lastly, we look at the Cybersecurity Maturity Model Certification, CMMC. This framework is implemented by the U.S. Department of Defense, DoD, and it applies to defense contractors in the DoD supply chain. Looking at third-party risk, it requires strict identity and access controls to protect controlled and classified information, CUI, across multi-tiered supply chains. And CMMC Level 2 and 3 explicitly call for identity proofing, multi-factor authentication, MFA, leased privilege, and auditability of access.
Looking at the IAM implications, contractors must implement granular access controls, not only for internal users, but also across subcontractors and partners. It requires strong monitoring and reporting of third-party access to sensitive data and systems. So looking across those three, we can identify some common themes. All three recognize third-party ecosystems as a major source of risk that needs to be managed. This can't be overemphasized enough. Access governance is important. There is a regulatory shift to comprehensive identity governance across external parties.
Also, auditability and accountability are key. Organizations must ensure full traceability of access and provide proof of compliance through reporting. So there again, reporting is an essential element. And finally, we look at zero-trust alignment. Regulations are effectively mandating zero-trust principles, especially verify explicitly, use leased privilege, and, of course, the classic assume breach. Another common theme is time pressure. DORA compliance was due by January 2025. CPS 230 becomes effective July 2025.
And CMMC compliance is being phased in, but it's required for DoD contracts starting in the financial year of 2025. So this effectively creates a global urgency for third-party IAM improvements, especially in the light of the fact that, in addition to the three that we've mentioned, there are many other regulations that now explicitly require identity and access controls for third parties specifically, such as NIST CSF, SAC cybersecurity rules, NIST 2, SOX, HIPAA, GDPR, CCPA, PCI DSS, the UK Operational Resilience Framework, and many more.
So you can see that there are a real whole host of regulations that are focusing on this. So the bottom line is that auditing and reporting expectations are rising. Auditors increasingly require proof of leased privilege access for third parties, evidence of periodic access reviews and revocations, and detailed access logs and reports to demonstrate control. Failure to meet these can result in fines, reputational damage, and contractual risk. It's important to note that liability is shifting to organizations.
Regulations are making organizations responsible for the security posture of their third parties. There's reduced tolerance for, we didn't know, defense, and zero trust mandates are assumed that knowing here in trust third parties must be validated continuously. So it's also worth noting that a dynamic workforce and remote access are amplifying risk. After the pandemic, many third parties now access systems remotely, often from unmanaged devices. So regulators are pushing for stronger authentication, such as MFA, session monitoring, and time-bound access provisioning.
The obvious conclusion is that regulatory pressure is making IAM maturity imperative, which means securing external identities is no longer optional. Regulations are requiring organizations to strengthen their IAM capabilities to manage external identities with the same level of control and oversight that is applied to internal identities. Organizations must, for example, view third-party IAM as a core compliance and risk management function. It's not an optional IT feature.
It's therefore urgent that enterprises modernize their third-party access strategies to mitigate operational and compliance risks. I'd say for most organizations that deal with third parties, an essential IAM checklist would include the following six things. First thing is third-party identity lifecycle management. It's extremely important. This includes things like onboarding and identity proofing, workflows for contractors, vendors, and partners.
We are talking about the classic many-to-many problem of managing relationships between a large number of identities and a large number of resources. In this situation, automation is essential, especially automated provisioning of accounts and automated deprovisioning. You'll get a copy of the slides afterwards, so don't worry about reading things now. You can read the detail for yourself later. Second on the checklist is access governance. So this is definitely important. Access controls and policy-based approvals for access requests.
Policy-based access control is an important step to take today because this helps to eliminate standing privileges. As Martin Kuepinger likes to say, standing privileges or static entitlements are the root cause of all that is bad in identity management. Next is authentication and authorization.
Now, this includes strong authentication enforcement using MFA, context-aware access based on device location, time, and so on, support for phishing-resistant authentication methods such as passkeys and certificate-based authentication, and, of course, the application of zero-trust principles. Next is monitoring and audit logging. This includes activity logging of third-party sessions, deployment of tools for real-time threat detection, session recording for high-risk systems or privileged third-party access, and alerts for anomalous behavior.
Next is privileged access management, or PAM, for third parties, things like temporary or just-in-time privileged access for third-party admins, prudential vaulting or shared accounts or emergency access, and session recording and real-time oversight of privileged actions. And finally, compliance, alignment, and reporting. Please ensure that you have the ability to generate audit reports aligned to the key regulations and provide policy documentation for auditors.
So, in summary, as Kuping et al principal analyst Martin Kuping has said in his opening keynote at EIC, we shouldn't just think about what we need today. We should think about what we need in 15 years' time and beyond. And to help organizations do that, Kuping et al has evolved the concept of identity fabrics.
Now, this provides a framework for organizations to deliver frictionless yet secure governed access for everyone and everything to every system and service. So, providing secure access for human and non-human identities on the left to systems and services on the right. In between is the fabric, if you like, or mesh that we need to do that. This fabric is made up of all the core capabilities that are combined into services to power the tools necessary to deliver the desired outcome. Integrating with legacy IAM where necessary and serving modern IT environments.
For more help on this, I suggest you contact Kuping et al's advisory team and they can go through this rather complicated looking diagram and help you with your particular application. But I'll end off with some recommendations. Anticipate technological advancements and ensure your identity strategy can adapt to developments. Adopt modular architectures in identity management systems by using things like microservices, external policy engines, federation protocols, and so on. Implement AI into identity systems to automate decision-making and improve security.
Use decentralized identities to eliminate silos and improve identity verification and authentic authorization practices. Move away from static entitlements if you do nothing else.
Instead, use policy-based access controls and dynamic authorization. And explore continuous signal sharing frameworks for improved identity assessments and cybersecurity practices. Pursue passive authentication methods to improve user experience and to streamline identity verification, such as device fingerprinting and behavior analytics. Evaluate multiple signals to strengthen authentication processes beyond traditional single-factor approaches. And utilize identity reference architectures, like keeping a calls to bridge communication gaps between business, security, and IT departments.
So this helps ensure cohesive planning and implementation. I hope you'll find these useful. And now in the transition, it's time for your second poll question, which is, which security enhancement is highest on your roadmap for external users in 2025? Choose from adopting phishing-resistant authentication, such as passkeys, automating third-party onboarding and offboarding, implementing continuous access certifications, and integrating external IAM with zero-trust architecture. Please make your selection on the Polls tab now, and we can have a look at the results a little later.
And now we turn our attention to Existar, which is a provider of industry collaboration solutions and has experience in supporting the defense life sciences and aerospace sectors. Existar also brings to the table a particular perspective and approach to the challenge that I mentioned earlier. And so to share that perspective with us, please welcome Senior Director, IAM Product Management, Mike Andron, and Solutions Director, Kevin Hancock.
Hey, everybody. So my name is Kevin Hancock, Director of Solutions here at Existar. And with me today is Mike Andron.
Mike, you want to introduce yourself? Sure.
Thanks, Kevin. I'm Mike Andron. I'm the Senior Director of Product Management for our IAM portfolio. ...kind of a unique approach and background in this identity and access management space. What we're going to do is talk a little bit about that approach, why we're unique in that, and then give you a practical example of how we support this in this case, a particular industry. And as Warwick mentioned, one of our key areas is aerospace and defense. But please understand we do this for a number of different industries.
Our IAM solution in those have a particular name, but they all kind of follow the same basic principles. And for those of you in the EU, our solution is called Access One. That particular solution works across our financial services, insurance, and other service industries.
And then, as I mentioned, we have similar IAM across other industries as well. And we'll talk a little bit about those. So as Warwick mentioned, this is coming to the forefront today simply because of the changing regulatory landscape. And this is going across many different regions. As Warwick mentioned, all of these really focus kind of on two key trends. It's that operational resilience, making sure your systems continue to work, making sure your systems and processes and procedures can meet the changing environments that you see out there.
But most importantly in this space and what ExoStar really specializes in is making sure that those requirements go across your partner supply chain or your service industry. Understand that most of these relationships are between organizations. So it's ensuring that you have a trust relationship with that organization, that they meet the requirements of your industry and the regulations that your organization is required. And so your partner chain is also required to meet.
And then being able to obviously have the necessary auditing, logging, other requirements that meet that particular regulation. And as I mentioned, ExoStar has a unique approach in this particular space and does some things to ensure we're not only requiring, if you will, the vetting of organizations, but then also doing the proofing and credentialing of individuals that provide you that peace of mind and establish and maintain that trust relationship. And we do this through these trusted networks that we develop and create across these different industries.
All of these are partner ecosystems where people are invited in by an ExoStar customer to participate in their particular network. But as is often the case, you'll find is that one service provider in one industry doesn't typically just have one customer in that industry. They're also working with others.
So ExoStar leverages those relationships and that, if you will, trust relationship that is established with one to establish the baseline for that ecosystem or for that partner to get access to particular systems, but then leverage that baseline to get provisioned into and approval to access maybe another partner's systems as well to, again, enhance that community effect, build out that overall trusted network, and then allow efficiencies on really both sides of the equation to allow other sponsors to leverage the community and know that they can bring on these partners more quickly because they already meet a particular baseline, and then allow those partners to leverage that information that they provided once to be used many times to allow their credentials that they were provisioned for once to then leverage those to get access to other systems as well.
So with that, let me dive in and kind of show you an example of that network. Now, this is an example of ExoStar's Aerospace and Defense Network where individuals or actually organizations are invited by the large prime contractors out there, the UKMOD, BAES, et cetera. As I mentioned, we have similar networks in financial services and service providers with our Access One product.
We also do this in life sciences and healthcare where in our life sciences space, you're talking about researchers and the pharmaceutical companies collaborating together in drug trials and working together across that ecosystem of clinics and providers, et cetera, that gather data around those different drug studies. In the healthcare industry, it's supporting a particular initiative in the US where we're doing electronic credentialing for doctors who prescribe controlled substances.
And then here in the aerospace and defense industry, it's supporting that supply chain into not only supply chain portals, but also leveraging access to other systems that allow those organizations to collaborate, not only around purchase orders and invoices, et cetera, but also actually in product development and quality of products and first unit inspections and things like that. Where again, these organizations are invited by those prime contractors to get access to those applications.
When they come in, that organization is vetted and may provide those third-party assurances that they meet particular cybersecurity requirements. In the DOD space, as you heard, you may have a requirement to have CMMC certification at a particular level and things like that. And so that organization gets vetted. And then there's a delegated administration model to also then allow individuals access to the various applications that they need. But obviously with that final approval and access being provided at a particular level by those organizations that are inviting them in.
So that network effect, again, allows those organizations to get onboarded more quickly by others. And then obviously that organization gets to leverage their parties across that ecosystem as well.
Now, the foundation of this, as I mentioned, in this particular space are those large aerospace contractors. And as we talked about, those typically work across their supply chain. And what we find, and this is very common across most industries, is that individual organizations that supply to one prime contractor also work with others. So those people who supply parts and services for GE Aviation also provide those same things for Rolls-Royce.
And so that ability to leverage that foundation and then ever expand that as, obviously, products and suppliers, et cetera, expand across the globe, you can then start to build out that network effect. And that's what we do at the organization level. And then we also bring that down to the individual level as well.
So when we're talking about that organization proofing, what we also talk about is that identity proofing and credentialing for the individuals, that ongoing authentication to allow that ongoing verification and those zero-trust principles to work against the individuals that is being granted access to those applications. But then also providing, you know, kind of those standard-based access to those many different applications themselves. Some of these applications are your typical off-the-shelf software. Some of those are ExoSTAR applications that are hosted in the cloud.
Some of those are ExoSTAR sponsor applications that are providing a deeper, if you will, integration in with a partner to do co-development or first unit inspection or things like that that I've talked about, or access to particular studies and things like that across other industries. And what ExoSTAR does is unique is around that individual proofing as well.
So, you know, for example, in the defense industry space, there is often access to applications that isn't just grant or it's not just about the type of authentication I want an individual to have to get in. What kind of multi-factor authentication? What kind of, you know, credential do I want them to have? But it also could be, I only want individuals that are UK citizens or are a citizen of a particular ally or something like that to have access to this because this information is gated by other regulations as well.
ExoSTAR can provide that kind of level of proofing of the individual to further enhance those capabilities and what you want to be able to lock down and make sure that only these kinds of users have access. So, it can, it fits not only that organizational vetting and requirements, but also those individual requirements as well.
Now, I'm going to turn it over to Mike to talk about how this is kind of implemented at more that level and the different things we do to ensure that. So, Mike, I'll turn it over to you and just tell me when you want me to go to the next slide.
Will do, Kevin. Thank you so much.
So, as Kevin said, going to dive into a little bit of the particulars here. For any one of these trusted networks, there's a certain set of capabilities that we find are commonly required across the board. But also there are variances within the different ecosystems, within the different lines of business, even within the individual customers that are operating in here. There are different rules.
So, the platform has to support this broad variety of requirements that are both externally applied from regulation and internally applied by policy. The key to all of this, the key to any partner IAM solution is the delegated administration. There are two parties involved.
It is a, you know, that's hence the partnership. There's two parties involved.
So, one side, right, needs to operate their controls and so does the other side. And they need to be able to trust that they do that. But as we've discussed, the world is moving towards a zero-trust model where, yes, you have certain expectations and legal obligations to maintain both sides of the equation. But it always helps to have the rules and policies in place that will automatically take care of things, or at least monitor and make people aware that they need to carry on this responsibility of controlling both sides.
So, on the one side, you have the enterprises who are trying to engage with their partners and they need to be able to exercise control over who, from an individual perspective, has access to what within their network. And then on the external side, the partner side, they have the requirement to maintain an accurate list of who those people are. As Kevin said, there's an organization-to-organization relationship. And then within each of those organizations, there are, of course, people.
And so the third party, the delegated administration, gives the power and the responsibility to the third party to at least, to some degree, control who should access things or who should be proposed for access from their side. And that's the delegated administration. And on both sides, on the enterprise side and on the third party side, this is a system that should continually monitor. It should continually request renewal of access requests. And our solutions provide those policies that can be applied at an application level.
When it comes to the actual users themselves, and this is where we have a vast variety of requirements, both regulatory and internal security policies. Specifically, this comes around proofing. How do you know if this person is who they say they are or who their organization says they are? And then ongoing with authentication. How do you confirm that this is the same person that keeps accessing our network? So we offer a variety of proofing services, and Kevin talked a little bit about some of those.
At the highest level, we can do the identity verification, which proves that an individual is who they say they are. We do that both through self-service and webcam. And then under certain circumstances, in-person proofing is also enabled. Beyond that, we're able to check other attributes of these individuals and make sure that that is known throughout the ecosystem, be that the trusted network for the air and space, or the ecosystem could be a single financial company working with all of its service providers.
But this additional attributes of these individuals can be verified through this process as well. So anything you need to know to apply additional policies around access can be captured and decorated on that user account. Once the account has been verified, we issue credentials to those individuals, and the credentials come in a variety of form factors, depending on the level required for the applications that these users need access to, and the internal policies of the customer. So we have a list of types of credentials here that we offer.
Our list actually goes well beyond that when it comes to the different industries. I think we're up to something like 22 different types of credentials that we support, those issued by us and by other trusted third-party credential providers as well. And all of this together gives enterprises what they need to meet those new compliance regulations. They have the assurance that the individual who's accessing their networks is who they say they are. Each time they access the network, they're doing so using this trusted credential.
And then over time, individuals who are no longer a part of the ecosystem are then removed from the system and can no longer access the network. And we do this by applying those rules, right? We can ensure if MFA is needed by the regulation, it's there. And then all of this is, of course, auditable because it's all flowing through a central system.
Okay, next slide. So to give you an idea of what this would look like from any single customer. So this works for both a participant like in the aerospace and defense network that we talked about earlier. But this example can also apply to a single financial institution who is doing this with all of their suppliers. So you have your internal systems that are all being integrated. You can imagine the middle box there is that identity fabric that Warwick talked about. So you have a variety of different applications serving different business functions.
And then how do you make sure that those suppliers are passing through? That's secure access and master data layer. That's your identity fabric. So all of this should be managed here. And in addition to the identity verification and the authentication side, the other part that's key here is your governance side of who is able to do what within this network also needs to be controlled. In most of our financial institution customers, we've had great success partnering with IBM to provide the identity governance side while we're managing the access and identity verification side.
And this has proven to be a very effective solution for large financial institutions dealing with dozens and dozens of suppliers, tens of thousands of individual users. Manually keeping track of all of that is nearly impossible. So this combination of solutions has proven very successful for those individual customers who are basically managing their own little ecosystem of all of their suppliers. In our other spaces, life sciences and the aerospace and defense, where ExoStar has been operating for, in aerospace and defense for over 20 years.
So we've had time to build up that community that Kevin talked about, where it's a shared trust model across all of the participants. But in general, this is what this would look like for any large customer who needs to manage a large number of suppliers. I think that's it, Mike. Thanks so much. I think we can start looking. It looks like we've gotten some questions. The first question that I'd like to address has been updated to the top.
So, right. So the question is, these requirements for lifecycle management, especially permission or modification and removal, are difficult to discover, let alone audit. What techniques or solutions does the panel recommend to address this?
Well, over to you guys. Yeah, exactly. I would recommend ExoStar.
But it is, you know, in order to enable that, it is about centralizing that and getting one place to look for all that information. So you're not trying to struggle, if you will, to go from either identity system or application to gather those different, you know, people and permissions and privileges that they have across those different systems. So that is why you kind of need that central point to figure out where that, you know, to make it just a more easily auditable and monitored thing.
Yeah, I'd just say that this is an opportunity, though, just to discuss maybe something that you kind of only just touched on peripherally, is that, you know, we mentioned the identity fabrics, and I think more and more organizations are turning to identity fabrics to sort of control what goes on within their organizations. But the challenge that we're dealing with here is that it's beyond the organization.
So I think, you know, the sort of one thing that I'd observe about the identity fabrics is that, you know, it doesn't extend easily beyond an organization because you don't, as we were pointing out earlier, you don't have that oversight or insight into what the third parties are doing. So I just wonder whether you guys would just like to talk a little bit about this whole idea of third-party access governance because I think that's really interesting because that takes identity fabrics.
Well, that's the next sort of step on from identity fabrics is because it provides this sort of additional layer that enables the internal stuff to be sort of almost extrapolated beyond the fringes of the organization. I see it a little bit differently. I see that the identity fabric should encompass all identities that need to participate or have access to your network. All of those identities need to exist within the identity fabric.
What the third party and the delegated administration does is it shifts the least amount of necessary administrative tasks to that third party, usually to the organization for who these users actually work for. But everything else should remain the same, right? You have a centralized set of policies for who's able to access what within your network. That applies to all of the identities within that identity fabric.
The key really is to get that, the delegated administrative controls available to the individual, to those participants, to the other third parties that are, you know, do know who their employees are. And that really, I think, is what's new, is what's coming up is making that a central part of the identity fabric or making it a new portal which gives limited control to those third parties over the identities within your own fabric.
Okay, yeah, so, you know, I take your point, but, you know, I think identity fabrics, sort of the traditional model, only does go as far as the organization. And so that's why, you know, what you're talking about is essentially an evolution of the original concept, is to go through to this kind of overarching thing. And that's what, you know, Access One enables, really.
Okay, let's go on to the next question, is would you describe your services as centralized authentication provided by Existar with decentralized authorization by your clients? That's, I mean, I think that is true.
The, and I would actually agree that that is what our service is. It is a little more than that as well. It's also that because these are relationships between organizations, that's really where it starts. And it's that, if you will, extension that I think makes us a little unique in this space.
But, you know, at the end of the day, it is that, right? It's that central authentication around decentralized authorization. Because you can't, the sponsoring organization can't, it just isn't the holder of all this information because they are dealing with a partner at the end of the day.
Okay, fair enough. All right, well, we've got a couple of questions, so let's move swiftly on. Okay.
So yeah, here's something that mentions TPA-G. Why is third-party access governance becoming a board-level priority? And how does Existar uniquely address this shift?
Well, I think you gave the examples of why it's becoming a board-level priority, right? It has become the primary access point for bad actors because without that governance in place, it is an inherent weakness within your security system. So I think that explains why it's becoming a board-level priority. Existar uniquely addresses the shift by providing the tools. It depends, again, on the ecosystem that we're talking about, right? In the aerospace and defense industry, we've been there for a very long time.
And so that community itself provides a lot of the solution to this because not only do you have your relationships directly with the partner organizations you're working with, but you're now relying on your competitors or the other folks in the space that are also now supplying information into this, who could be trusted, who can't be trusted. Mostly it's that who can't be trusted. When something goes wrong within the ecosystem, that signal is then immediately spread across the entire ecosystem, which is a tremendous advantage.
But even for, say, institutions that are doing this themselves with their own identity fabric, we have solutions there. And again, it comes down to making sure you have the proper governance and policies in place that are continuously monitoring all the interactions of your third-party individuals within your network and becomes responsive to any risk signals that come out of that.
And again, that's the, you know, Access One, along with our VM partners, have provided that solution to a number of financial institutions in particular. Okay. Do you want to add anything there, Kevin? Or should we just...
No, I think Mike covered it. Okay, cool.
All right, so let's go on to the next question here. Many organizations still use manual processes or internal IAM tools for third-party access.
Yes, they do, and that's bad. What risks are they missing, all of them? And what does good look like? So this is really difficult to handle with just your internal IAM tools. It's...and not only that, but it puts a tremendous burden on your own internal IT organization to manage this space. Not only...and it's not only just, you know, the identity and access management pieces. It's also just supporting this stuff, right? If a partner has a problem, then they're going to call your internal IT team to help fix it, which, you know, again, just burdens that team more.
And so it is why you need to leverage, if you will, or think about leveraging third parties to help you manage that overall risk, and, you know, and just leverage that, you know, a solution that fits a problem. Okay, fair enough.
Okay, I'm just... Right, where are we?
Okay, right. How do organizations balance security with ease of use, a classic problem, for third parties, especially in industries where partner relationships must move quickly?
Oh, that's interesting. Yeah, speed is always the enemy of security, right? The faster you're moving, the more likely it is to end up with a mistake. This is where being able to govern by policy is most important, right? And being able to have... establish that business-to-business relationship.
Yes, you've got to move quickly, but at the same time, you've got to ensure that you know who is accessing your network and that they're supposed to be there. So having the governance policies in place is what will enable you to move quickly, right? As the earlier question, if you have manual processes in which you're managing external identities within your internal IAM system, that's an inherently slow onboarding and very slow offboarding process.
If you have the policies in place and a third-party delegated administration capability, then that enables speed, while you still have that degree of trust and security going on because they're able to engage in that partnership according to policy, according to the rules, but on their own. So that's how you get that combination of security and speed is with delegated administration.
Yeah, I'm seeing that as a definite trend. And of course, the other trade-off that the other traditional classic trade-off is kind of ease of use and security. And I think we're seeing a change in the industry now. We're finally getting this mindset that you can have ease of use as well as security. Would you agree? I absolutely would. And I think a lot of that's just being driven by all the consumer apps we're now utilizing. And to tell you the truth, people have an expectation of ease of use. And so you've kind of got to deliver that as part of just an overall experience.
Yeah, I mean, it's very much around the customer journey and the customer experience. Magically, Oscar in the background has kind of delivered the poll questions to me. So let's have a quick look there in the time that's remaining. So the first question I'll ask is, which security enhancement is highest on your roadmap for 2025? Interestingly, the highest number of votes were for integrating external IAM with Zero Trust architecture. Is that kind of predictable or are you surprised by that?
Not really surprised by it, to tell you the truth, because really Zero Trust is getting woven into kind of everything I see is kind of that next evolution of access management at the end of the day. So yeah, so absolutely not. And then we've got to come more or less an equal split between adopting phishing-resistant authentication and automating third-party onboarding and offboarding. I would have thought the automation thing would have kind of maybe been a higher thing, but yeah, equal split there. There seem to be equal priorities and that sort of makes sense to me.
Yeah, to me as well. We've seen, and I think just in the last year, last 18 months, we've seen a big surge of passkey usage, which is one of the primary phishing-resistant credentials that's out there. We've seen a large surge, not just at an industry level, but we've seen it at a regulatory level. And of course, at a user adoption level, once it got added to the mobile device manufacturers operating systems, we're just seeing it spreading out. You probably in your own personal life encountered the ability to add a passkey for various things just over and over again.
I'm getting offered that step up from standard password to a passkey. So that one doesn't surprise me at all. And onboarding and offboarding, as we talked about, is one of the biggest challenges when it comes to working with your partner ecosystem. But then almost half of that, though, at bottom of the line with just 11% of the vote was implementing continuous access certification.
I mean, from what I know of Existar, this idea of access certifications is quite an important concept. And so would you like to see people, more people having that as a priority or what is your feeling on that? I feel like some of that is subsumed by the zero trust discussion, since often that is about a continually monitoring the access and continually ensuring that that user, while they're logged in, should continue to be logged in.
So yes, I feel like that is somewhat subsumed by the other. Okay, fair enough. And then our second poll question was around what is your biggest challenge in managing third-party identities today? It was kind of almost an even split between the top three of onboarding and offboarding inefficiencies, credential misuse, phishing risk, and third-party lifecycle tracking. How does that strike you? Is that kind of sort of, are you not surprised that the one hasn't taken precedence over the others? Or do you think it's kind of just all of those are of equal weighting and equal challenge?
So that's why they've kind of more or less fallen in equal thirds. Yeah, I'm not surprised by that result.
And again, it speaks again to having a holistic solution that can address all three of those simultaneously is the best way to solve this problem. They're all painful. Solving one, you still have a problem because you have the other two. So that result of that poll, that fits with what we're hearing from the customers that we work with.
Okay, and sort of finally, the smallest, only 10% said that, you know, manual access reviews and certifications. But again, this is something that, you know, it's really a problem. So I kind of, I'm surprised that that maybe didn't feature a little bit higher as being a pain point, because, you know, in my experience, that is one of the biggest pain points of any organization on manual access reviews. And that's why at Clipping and Coal, we're pushing very heavily, you know, sort of to encourage and help people get down the automation track. We are as well at Existar.
It is one of the, you know, kind of one of our key benefits and features is getting you to that point where you do see, you know, accesses to your different application stacks. And so kind of relieving the burden of the application from that and more trying to bubble up that information.
Now, granted, you still have to get that to something that will actually, you know, automatically look at those logs. But it is a little easier if you've got them centralized. You're not worried about different, you know, different systems and different applications going to each one individually, et cetera. At least in this manner, I have a method to get them all.
Well, we're very nearly coming up to time. I just want to thank you guys for your contributions, Mike and Kevin, for joining me today. Before we came on to the webinar, we were discussing about sort of the length of 20 minutes and how much you could get done. And I assured you that 20 minutes wasn't really that long.
I think, hopefully, we managed to fill it with useful information. I hope you guys enjoyed your time on the webinar today. I did. Thank you so much for having us, Lork. I really enjoyed it. And also thanks to you, our audience, for joining us and participating in the polls and submitting the questions. And to our producer, Oscar Hernandez, for managing all the technical wizardry in the background. We welcome your feedback and your questions. So please don't hesitate to connect with us on LinkedIn or email. And we look forward to continuing the conversation. Until next time, goodbye.
Thanks, everybody.
See All Locations
See All Locations