Many organizations still lack a reliable view of their applications and who is responsible for them. Information lives in different systems, ownership changes without record, and access data is often incomplete. When an audit lands, teams spend weeks reconciling facts that should have been clear from the start.
A disciplined, automated application inventory changes this. By Application Lifecycle Management and specifically continuously discovering assets and validating ownership and access, leaders gain confident oversight: Clearer accountability, faster response to risk, and audit evidence that doesn’t require a scramble.
Dr. Phillip Messerschmidt, Lead Advisor at KuppingerCole, will examine the strategic importance of application inventory as a foundation for IAM. He will present market observations as well as operational and compliance challenges caused by fragmented systems, and outline maturity benchmarks and best practices. His contribution highlights how unified inventories strengthen governance and position IAM as a business enabler.
Asif Savvas, Co-Founder and CPO at Simeio, will demonstrate how Simeio IO operationalizes automated discovery, centralized visibility, and lifecycle management across identity assets. They will share real-world metrics, business value analyses, and outcomes achieved by customers. Their session will unpack how automation reduces support tickets, cuts onboarding timelines, and delivers rapid ROI with simplified audit readiness.
Who Should Attend
This webinar is ideal for IAM leaders, architects, application owners, and security professionals even beyond IAM that are seeking to reduce operational overhead, close reporting gaps, and modernize compliance readiness through unified application inventory.
Hey, everyone. So, welcome to today's webinar about Application Inventory and Application Inventory Management. The title of this webinar is Application Inventory – Identify What to Protect? Are You Missing Critical Assets? I'm your host, Dr. Phillip Messerschmidt, Lead Advisor for KuppingerCole. And with me, I have Asif Savvas in the webinar.
Welcome, Asif. Good to have you here. Do you introduce yourself? Yeah.
Thank you, Phillip. Good morning. Good afternoon, wherever you're joining from. My name is Asif Savvas. I'm the Chief Product Officer at Simeio, and I'm looking forward to our session today. Cool.
So, then let's start with a little bit of housekeeping here. Audio controls – you are muted centrally. We are controlling these features, and you don't need to mute or unmute yourself. Over the webinar, we have a couple of polls planned, so we will run the polls, and you can answer the polls. We will display the poll's results over the chat, and we will discuss the results at the end in the third session, the Q&A session.
Questions – whenever you have questions, you can enter your questions over the Livestorm Control Panel, and we will pick up the questions later and answer them in the Q&A section. So, recording and slides – we are recording the webinar, and we'll upload the recording as well as the slides that we have presented here in the upcoming days on the KuppingerCole website. And with that said, let's move on to the agenda.
Today, we have three pieces on the agenda. The first one is my presentation about Application Inventory Management as an enabler for IAM. The second part will be about Simeo's Identity Orchestrator presented by Asif, and the last part is the Q&A session where we will discuss the polls and the questions if you have some. And with that, let's move right into the content.
So, Application Inventory Management and Application Inventories. In my past as a system integrator, I had a couple projects in the IAM space, and we usually had one common challenge with them – basic information.
So, questions like, how many applications do you have? Who is the owner of that application? What is the criticality? What types of integration? How is the application deployed? That were some real challenges for some of the projects, and it took a lot of effort to find the answers to the questions. And when you ask the customer directly, there were some common answers from the customers like, yeah, that would be good to know, or we have an Excel list somewhere where you can find the answer to that. But usually, it was quite effortsome to receive the answers.
And that is the challenge, and I would like to show you the challenge based on the four areas of the knowns and unknowns. So, here in the four areas that are about your application landscape, you can see where the risk lies.
So, let's start with the upper left part, the knowns. These are the applications that you are aware of and that you actively manage.
So, the risk in that area is lower. When you think of your application landscape, there are also the unknown knowns in the upper right part here. These are the applications that you are not really aware of, but that are managed by somebody else.
So, overall, these applications are managed. Then we have the third area, the known unknowns on the bottom left part. These are the applications that you are aware of, but you are not managing them actively.
So, you're basically knowing that these applications are there, but you ignore them. And then we have the fourth area, the unknown unknowns. And in this area, there is the biggest risk because you don't know these applications in that area and you don't manage them.
So, you don't know anything in that area. And as a security expert, the idea behind these four areas is to minimize risk, meaning that I would like to move everything, at least in the upper half, but in the best case to the known knowns area on the upper left part of this diagram, meaning into the area that I know and that I manage. Everything that is in the unknown unknowns area is a risk to me, a risk that I don't know, that I can't quantify, that I'm not aware of. And that's what I would like to reduce.
An application inventory and application inventory management is a possibility to do that. So, what is an application inventory? An application inventory is an overview where I list or catalog all my applications, all my systems, all my software with additional data points to provide a good overview. The application inventory is that application inventory management is that piece that adds lifecycle to these data points.
So, actively managing, updating, providing data to the application inventory. And a strong application inventory management approach is something that ensures that I have the right data at the right time, at the right place, and updated to make it a relevant record of all my software applications available to everyone. That is the idea of an application inventory.
So, let's move on to the first interactive part, the first poll. My question to you is, do you have an application inventory in your organization and do you actively manage it?
So, remember, application inventory, overview over all applications, application inventory management is applying life cycles to it so that it stays up to date. So, we have four questions here, plus the one for the undecided people. And the idea is for the first two answers, yes, I have an application inventory and I manage it or not. And for the third and the fourth, no, I don't have an application inventory, but I would like to have one for third or we don't need one in my organization, there is no need for it.
So, we will discuss the, yeah, we will pop up the poll in a second and we will discuss the results at the end. So, moving on with the next slide, talking about the advantages of application inventory management. The idea of application inventory management is to provide visibility, to provide transparency. And that helps us in several use cases, in several scenarios. One of that is the enhanced decision-making.
So, transparency and visibility. Visibility in that particular case helps us to speed up decision-making and helps us to make better decision because we have information at hand and we have it fast at hand and available.
So, the second one is efficient support and maintenance. With a good overview over my applications and the idea of whom to ask and how the landscape in itself looks like, the support teams are able to react faster and in better quality for your requests. And when we think about the maintenance and security teams, they are able to respond much quicker to incidents. The third scenario or third use case here is optimized IT governance. When I have an application inventory in place, I have a defined, a structured landscape.
And with that definition and landscape, the definition of an application and a structured landscape, I'm able to position, to focus my IT governance much better. So, the streamlined efficiency, that's the fourth point that I would like to highlight, the fourth scenario. And that is about duplications.
So, a good and organized application inventory is able to reduce duplications, reduce redundancy based on visibility. So, that overall saves me money, that enhances security, and that helps me straightforward with compliance benefits.
So, that are the last three here on the slide that are a result of the benefits that I have above. So, in general, cost savings are a result of improved efficiency and redundancy reduction. Enhanced security is something that I can get from visibility and the reaction speed when I think about the security teams. And the compliance comes from a clearer scoping and more transparency so that I can apply my controls.
So, the interesting part now is, when we, after seeing the advantages, what are the challenges? So, there are some challenges and I have listed now five here for you. The first one is the amount of data that I need.
So, when I build up an application inventory, I need the right data points and I need complete data. These are the two challenges that I have with the amount of data. If I don't have the right data and I don't have complete data, my application inventory quickly can become meaningless and then it's not useful anymore. And that is more or less a seamless connection to the second challenge here, the data accuracy.
So, when my data is not accurate and not up to date, it's not creating any value because it's not reliable for the people that need that kind of information. So, that's why you need application lifecycle management and need up-to-date data that is accurate for usage. The third is the standardization. And standardization is a challenge that is interesting because when we think about the data that we have in an application inventory, we need to ensure that there is not much room for interpretation. That means standardization.
So, the perfect example for that is criticality. Criticality can be interpreted differently if it is not properly defined and if there is no process that clearly states how I get to a defined criticality. That means criticality medium, if it is undefined, could mean something completely different to me than to somebody else. And that makes standardization important because if there is room for interpretation, it means that this data is not accurate anymore and inaccurate data becomes worthless in the end or the worst case. Moving on to utilization, the fourth here on the slide.
Utilization is more or less the result of the first three challenges. But even if you are good at the amount of data, if you're good at accurate data, if you have standardized everything, that doesn't mean that it's also used. Because having data and using data are two different things. If you have the data, the relevant data and up-to-date data, that's good. But you also need to derive the right insights from these data. And that is what utilization here is about. Having the right data in place and using them, using them for analysis and insights. And the last one is perspective.
And perspective is a little bit different to the other challenges. One thing that application inventories are struggling with is a dynamic environment. So you need to build your application inventory so that it is able to react to dynamic environments and scalable enough to react to increasing numbers and complexity. The data field integrations is a very good example for that. So imagine that you want to display the integrations of your applications in an application inventory. And therefore, showing the up and downstream systems of the different applications.
If you now merge with another organization and you increase the number of overall applications, that also increases complexity a lot and the number of integrations. And that is a challenge for an application inventory. But enough about challenges. So what is it what we need in an application inventory? When it comes to data points, there is no limit, no right or wrong. In the end, it depends on what you need, what your organization needs, and what your requirements are. So it's up to you. But there's surely a basic foundational pool of information that you need.
So for example, application name, the version, the deployment information, and ownership are some classic data points that you definitely want to have in an application inventory. However, in the end, you need to decide what data you need in that application inventory. Because you just need that data that create the most value for you. If data points are not creating any value for you, you don't need to maintain them, but you don't need to store them. And how important that is, is something that I want to show you in a minute, based on a couple IAM use cases.
And that's why we dive deeper into the IAM overlap. So three things about application inventory management and identity management first. What we have already learned is that application inventory management functions are an operational accelerator for other domains, such as IAM. And that's what I'm trying to show you now. Another thing that we already learned from the benefits is that application inventory management and IAM share the same core drivers. And these core drivers are business value, or cost savings, as I mentioned earlier, security, so risk reduction, and compliance.
These are the three core drivers that IAM and application inventory management share. And what we have also seen is that a well-maintained application inventory is able to strengthen all these three core drivers.
Meaning, not just for IAM, but also for the other domains. And to show you how that works, I have a list with example use cases of the IAM domain, and how they are accelerated by IAM. We will dive into them a little bit deeper, at least into some of them later. But for now, I will explain you the different cases. Starting with application onboarding into IAM. So the idea of application onboarding into IAM is to onboard an application into any kind of IAM tool. Meaning an IGA, or an IDP, or whatever you can come up with.
The idea behind that is that you need a lot of information to perform such an onboarding task. Meaning, you need the application owner, you need the deployment, you maybe need integration, you need the current authorization authentication structure. All of these information are potentially available in your application inventory. Even if it's not everything, it will be most of it. And the second point here on the list is ownership clarification. So when we think about ownership, this is important to mention that this is a core information of an application inventory.
So every time I have a question regarding that application, whether it is integration types, authorization requests, or authorization approvals for example, this is something that I would address to the owner. So ownership clarification is a very important information that is being stored in an application inventory. Then we have the access lifecycle support. Access lifecycle support has two important points to make. The first one is the integration. So integrating applications downstream to push access lifecycle events forward.
But also the second one is to understand the access lifecycle in that application. And in the worst case, ask the owner about it.
Again, application inventories are storing information about that, about the owner, about the criticality, about the downstream systems. And this is where you get the overview over your application landscape. The fourth is the criticality assessment. And this is something that I've already mentioned earlier. So criticality is an important application inventory data point. Why? Because in a security domain like identity and access management, it's our duty to protect the most critical assets or most critical applications.
And an application inventory is telling me which applications are these assets that I try to protect. And it's also having consequences for the access lifecycle. So for example, an access request and the approval steps, just as an example. So this is something that I want to be delivered by an application inventory. And that I want to be defined very clearly from the process side. Then we have the authorization concepts. This is an interesting piece because authorization concepts are documentation of access information.
It's comparable to an application inventory, but with a rather specific perspective to the IAM piece. In one of my past projects, we have used the application inventory to link the authorization concepts, to keep them very close as a source of information. So mitigating controls. When we think about a very complex application landscape, we want to have mitigating controls that take events into account.
And a ZM, for example, can collect these events and aggregate them and make decisions based on these events. But to do that, we need to be aware of our applications and how they interact with each other.
So again, it's a topic where integrations downstream and upstream systems are important to interpret these events. Same goes for integration and provisioning. When I try to connect applications end-to-end, I need to be aware of my landscape. I need to understand what happens upstream and downstream. What are the consequences of my doing in the end? That is something that an application inventory can deliver. Audit preparations.
So when you think about regular audit tasks and regular internal and external audits, there are always questions that ask for data that is freely available in an application inventory. For example, what applications do you have? What is the criticality? Who is the owner? And so on. So this is basically available right away if you have an application inventory. And even if you don't have the answers in the application inventory, you have the ownership in the application inventory. So you know whom to ask. That is definitely speeding up your audit preparations.
And with that, we are moving to the second poll. And for the second poll, I would like to know which one of these IAM use cases is the one which benefits the most from a working application inventory? So what is your opinion on that? And as I'm asking for the most effective accelerator, you will probably have just one answer. Good. Then I'm running a little bit out of time. I see that. So I need to speed up a little bit. Next is the deep dive into the IAM use cases. And as said, I shortened that a little bit.
So when we think about IAM use cases, there are three specific use cases that I would like to highlight. Application onboarding, lifecycle automation, and end-to-end integration. I've talked a little bit about the application onboarding piece already. And the important piece about application onboarding is that you need a lot of data, a lot of information to onboard an application, not just from a technical perspective, but also from an organizational and functional perspective.
So namely, the application owner, integration options, the current deployment, the current access structure, and so much more. So this information is probably available in an application inventory right away. You don't need to go out there and look for answers. Same for lifecycle automation and end-to-end integration. These are basically two different perspectives to the same coin. Lifecycle automation, more from a functional and process perspective, and end-to-end integration and automation, more from a technical perspective.
In the end, you need to understand the upstream and downstream systems, the consequences if you do something in application A for application B, and the overall process through all these applications. This is important when we think about lifecycle automation and end-to-end integration. So coming to a conclusion here, what have we learned? So what we've learned is that application inventory management and IAM have a strong overlap.
So application inventories can accelerate IAM and IAM use cases like application onboarding, like lifecycle automation, like integration, end-to-end integration, and like audits. But something that needs to be highlighted is that IAM also exposes gaps in application inventories and in application inventory management.
However, IAM can also work without application inventories and application inventory management, but at higher operational cost. So the last thing and the real takeaway that I want you to take home with you is that application inventory is not just a documentation. It is an operational capability and it will create long-term value for your business if you are able to do it right. And with that said, I conclude my part of the presentation and hand over to Asif.
Thank you, Philip. I'm going to share a little bit around what you just talked about here, and for the audience who hasn't previously had an opportunity to see or hear about Cimeo, Cimeo Identity Orchestrator, Cimeo I.O., as you call it, is Cimeo's product in the space that addresses a lot of the use cases that Philip just talked about, enabling the discovery of applications and the management of applications to really achieve IAM program success.
Cimeo, first and foremost, is an identity and access management business. We work with a number of enterprises to make identity programs successful, and we believe, based on our experience, that getting a really good application inventory in place is key to IAM program success. So we'll talk about that specific use case today. Cimeo I.O.,
of course, covers a lot of other use cases that takes where the discovery of applications is really the first step, and then we take that forward into a number of other use cases as well, but we'll focus our conversation today on this specific use case.
So for our agenda, we'll talk about, you know, Philip already touched on what some of the big challenges are, so I'll summarize some of those challenges and also talk about our solution to those challenges with regards to how we address it, and then we'll talk a little bit around our methodology and process based on, which is founded based on over 20 plus years of doing identity and access management programs for large enterprises, so we'll talk about our methodology that has been successful that's incorporated into the product, and then we'll show you some screenshots from the product as well with regards to how we do it, and then we'll go ahead and take some questions.
All right, all right. So with regards to the challenges themselves, Philip touched on them quite a bit, you know, there are a number of enterprises that we work with where when you start an IAM program, enterprises invest millions of dollars going down the path of buying the products necessary to achieve the IAM use cases to improve, you know, to get a stronger security posture, reduce risk, improve user experience, right? So often a big part that is overseen is really getting an understanding of what assets the organization needs to protect, right?
And Philip touched on this a little bit as well, he talked about the four types of known knowns and unknown knowns and so on, right? Truly understanding what to protect has been one of the biggest gaps. When we start on these initiatives, after large investments, when enterprises start rolling the projects out, they find that they do not have a really good handle of who their application owners are, what are the risk levels of the applications and assets that they need to protect, what is the usage of these applications, right?
Understanding what are some of the high value assets versus low value assets is often a big challenge and this is what has traditionally delayed a lot of IAM programs. The faster we can, you know, understand what we need to protect, the sooner we can engage all those stakeholders, the app teams, the business areas that those apps support to, you know, to bring them on board and engage them in the program and start, you know, delivering results. The reason this problem exists predominantly is because we find a lot of CMDBs in most enterprises not up to date.
They're not up to date, they don't capture the changes or the evolution that a traditional business goes through. People come, people leave, right?
So, it doesn't really have up-to-date information around who owns the applications. The application risk management exercise often happens in other systems outside of the CMDB is what we've seen in our past.
So, while some assets may have been categorized and inventorized, the ownership is missing, there's no one centralized area where risk or criticality that pertains to an application is captured as well. So, what happens, what ends up happening is if when all of these data is not put together, the IAM program often struggles to identify stakeholders as well as understand criticality to actually apply the identity security controls, right?
So, the way we go about it is, you know, we try to solve for all the four components that that Philip just touched on, right?
Understand which applications we already have a good understanding of where we know who the owners are as well as applications that may have been already onboarded into, you know, maybe a legacy or if the enterprise already had some identity program in place, applications are already protected, we are able to bring them in by connecting to the IDP such as Entra and Okta as well as having a process in place to be able to detect applications that are used by the enterprise, the unknown unknowns, right? That nobody knows of.
So, the shadow IT scenario, how can we capture some of those applications as well, make the IAM program team aware of them to see if there is any exposure that's happening there to see how we can get them under control and start protecting them as well. So, we do this by four different approaches that I just touched on.
Once all of that is brought together, we have an approach where application owners then can go in, respond to a series of questions based on the confidentiality of the data that is contained within an application, what happens if the integrity of that data is compromised, what is the impact to the business, what is the impact of the business if, you know, if a malicious actor takes the application down as we saw in in the hospitality industry a couple of years back, you know, businesses were not able to check people in and so on, right?
So, there are various types of impacts that can be realized if critical assets of the enterprise undergo an outage, right? So, we have a process with regards to how we do this, right?
So, the end goal of it is really understand what we need to protect, having an approach to prioritize, you know, so that we spend the most amount of time protecting the most critical assets because there is a cost to protection as well, right? So, you don't go out and protect everything, you want to make sure that funds are limited, there's only so much things that you can do within a certain amount of time, you want to make sure that, you know, from a risk management perspective, the most amount of your time and investments goes towards, you know, where your risk is the highest, right?
And then providing the ability for an ongoing basis to evolve as the applications change, as the risk profile for the enterprise changes, being able to have an ongoing process that can scale with the growth of the organization. So, what is our approach to do this?
So, we do this within our product called Simio Identity Orchestrator. What Simio IO does is, you know, has the mechanisms to discover applications. It does that by, one, plugging into the various enterprise browsers, right? This is the known, unknown situation where there are applications used by the organization that nobody's aware of, it is not in your CMDB, it is not in your IDP, maybe there is some local authentication going on with regards to how users are accessing that specific service or application, right?
Being able to detect that and bringing that to the visibility of the various stakeholders in the identity program, right? So, that's one approach, right? Detecting applications using this approach. The second is there is always a CMDB or a notion of a CMDB in Excel sheets and so on. Most security programs have this in place. The common challenge we find is they're not very consistent and they're not updated, but they still hold some valuable data.
So, we want to be able to harness what we have and then be able to consolidate that. So, we will identify a set of applications and assets from the CMDB. We want to be able to bring that in, right?
So, we do that. Once we've done that, we tie into the IDP systems, mostly the authentication products out there, and then from there, be able to detect all applications that are authenticating off of a central IDP, identifying who's authenticating to those IDPs and then be able to bring them in as well. That's another approach.
And then finally, if there are IAM tools already in place, we want to get an understanding of which of these applications identity controls have already been applied for or they've already been onboarded into the identity security program with a good identity control framework, right? So, what this gives us is a holistic view of all the applications in the organization, right?
Once we've understood that, what we do is where we already know who the application owners are, we're able to, you know, send out notifications and so on to them and have them go through an application criticality scoring process, right? Based on the three parameters of confidentiality, integrity, and availability, have them go through that criticality scoring process. Some enterprises may already have their own technology risk management processes in place. We're able to bring that in as well.
Enterprises may have already gone through, you know, another tool such as Archer and so on, which captures application risk. So, we're able to consume from other tools or consume from other processes that exist in an organization. But the end goal of this is to really classify your applications so that you want to make sure that your crown jail assets are actually protected with the identity security controls and the investments that the enterprises made, right?
So, we ask the application owners to go through this criticality scoring process, and then once they've done that, we're able to then give these applications a certain criticality score and then start from there driving the process of onboarding the applications for identity security controls, right? So, a high-risk application may have to have more rigorous IAM controls in place, right? Whereas a low-risk application may have fewer controls in place, right?
And as well as you might have some applications that have very little usage in the organization, it is then, you know, worth a conversation for both the IAM team and the app owners to see, is this application really a good candidate to bring onboard into our IAM program, right? So, that's the high-level methodology and the process that we go through, which then takes us to some of the screenshots, right, with regards to what we already have in the product today.
So, this screenshot here basically shows you, you know, the use case of the unknown unknowns where we've, from browser activity in the organization, we've brought on board all the different URLs and we have an intelligence aspect to this as well, where we're able to apply, based on our understanding and past experience, which application some of these URLs pertain to, which then gives us, you know, those URLs as well as tells us how many unique visits or how many individuals within the organization are using these applications and the IAM team will also have intelligence with regards to who these individuals are in the organization who are visiting this.
We're able to detect who are normal users versus privileged user activity and then send a notification out, perhaps that the privileged users in that application who have a little more different behavior than the normal users, maybe the administrators of the applications start sending notifications to them to say, is this an application that you and your team use?
Should it be in the purview of the application inventory that we manage for the purpose of identity security controls and from there they can make decisions around whether that is an application that they should start managing or if that is an application that they should consider ignoring, right?
So once, you know, the applications have been brought together, this screen here shows you the risk assessment or the criticality assessment process with regards to, you know, asking questions such as is there PII information inside this application or is there financial information, is there cardholder data, right? Are there other data that is really sensitive that would compromise both our, you know, our end users and stakeholders as well as compromise the enterprise, right?
So able to ask those questions based on these questions, we're able to then assign the criticality criticality score that is auto-calculated. Once we've done that and once we've plugged into the various IAM tools as well, of which we have integrations into all the leading IAM tools in the market today, we're then able to map which applications we've discovered and brought in as well as we've connected to the various IAM tools in the enterprise to say which applications have any identity security controls implemented or not implemented.
This is often a big challenge area that we find in many organizations. Enterprises are often even running their various IAM programs in silos. The IGA team does their thing, the PAM team does their thing. It's often, the visibility is often lacking with regards to saying here is my application and then what are the IGA controls that are in place, what are the authentication and authorization controls in place from an access management standpoint and what are the privilege controls in place for that specific application.
We find most enterprises do not have a good level of visibility into this data. So what our product provides is that level of visibility so we can truly understand where the gaps are and then that's where the aspect of the actual remediation kicks in which is touching on some of the use cases that Philip just talked on.
Once we know where our protections are missing, we can then go and onboard these applications into your IGA tooling, into your access management tooling, into your PAM tooling, start vaulting those accounts, start turning on MFA, start turning on role-based access control or stronger access review processes for your applications. So this gives you the insight that Philip talked about, that is a 360 degree view of your total number of applications that are discovered.
Your 121 applications are discovered here and we see that about 33 of these applications have some level of access request or account management capabilities implemented, none implemented with any access recertification or segregation of duty controls. The goal is really to start closing your rings and this is not just available at the program level for all the applications. Each application owner also has their own specific view of this data. So you can truly put this level of visibility into each application owner's hand.
You can put this level of visibility into the specific line of business owners, large enterprises we work with also have a line of business technology risk managers and so on. They can have access to this data then so that they can then take the next steps to onboard these applications into the identity security program, which is also completely provided in a self-service model in Simio IO. So that's the program level view. This screen here shows the view for one specific application owner.
Nicole is the application owner represented here and she's responsible for let's say 8 to 10 applications. We see the criticality score for those applications as well as which ones have governance controls implemented, access controls missing and PAM controls in place. And then once they are implemented, these applications also go through change. We are also able to detect version changes, security model changes in the applications to then further manage these controls on an ongoing basis. The lifecycle management of controls is also a big gap in a lot of IAM programs today.
Often IAM products are implemented, apps are onboarded and then they are forgotten for years, which results in a whole set of weaknesses. So what we really focus on is not just onboarding once and forgetting, but onboarding to identity security controls and managing these controls as the applications evolve. The application identity security controls need to evolve as well. Newer standards become available around IAM. Organizational enterprise policies may change.
Having the ability to push down these policy changes as well to all your applications and the app owners is another capability that we present and provide. With that I will stop sharing and then we are going to go into the questions section of our conversation today.
Thank you, Nasif. So then let's move on to the questions and answers section. We should start with the polls. I will show some marketing slides in the meantime. And the first poll that I would like to discuss is the poll number one. You can see it under polls in your window. Do you have an application inventory? Do you actively manage it? And what is interesting for me is that 70% say, yes, we have an application inventory. And nearly 60%, 56% to be exact here, said that they are actively managing it. So is that the number, Nasif, that you would have expected?
No, I think the audience's response has been far more optimistic than what I have seen in my experience. Yes, they do have an application inventory. Most enterprises do. But where I think the big caveat is, have you found how relevant has it been for the purpose of achieving the results for your identity security program? Does it have the data, the information around what is really truly required to secure those applications has been the biggest gap that we found. But I'm also probably jaded with 20 years of pain seeing this again. So my experience may be a little more jaded.
Yeah, I understand that perfectly. So when I think back to my projects, to my first project, I was in a financial institution, a big bank. They had an application inventory that was very well managed, I have to say. But some projects afterwards, this application inventory piece was missing. And it was really a challenge to get the right information quick enough to do a good job sometimes. So 50% of my job was not to onboard applications or something, but to hunt the right information, to ask the people.
Yeah, 50% of our job has been chasing people, unfortunately. But as you can see, there are some answers coming in here, and it's shifting a little bit into the 50% direction. So let's move on then to the other poll here. The second poll that I asked was about the use case and the most beneficial or most effective accelerators in the IEM space. And what we can see here is that application onboarding is leading the poll here with 40%, and afterwards we have ownership. Is that something that you expected?
Sorry, can you repeat that, Philip? So we have the second poll, we have 40% most effective accelerated by application inventories is application onboarding into IEM. And the second one is 20% of the ownership clarification. Is that something that you would have expected?
Yes, that is what I expected. Yeah, it definitely accelerates onboarding once you get your onboarding, then everything else that I touched on in my section of the presentation gives you visibility around, once you know what you have to protect, then you get a good visibility around, are your controls applied, right? If you don't know what you have to protect, how can you protect it, right? So that's basically, I think what it ties to.
Yeah, absolutely. And I agree to the audience, to the poll results and to what you said. One thing that I found very interesting when I was observing how the votes changed was the criticality assessment with only 13%. Is that a surprise to you? Because when we think about the criticality, I highlighted that in my presentation, that criticality and application, criticality is also an important piece. What do you think?
So, you know, large enterprises, such as, you know, you refer to one of the banks that you work with, large enterprises that are regulated, organizations who are regulated, publicly listed and so on, often have criticality figured out, right? They have to be figured out, at least for their critical assets, they haven't figured out. They might not have it for the 4,000 applications that they have, but if there are, you know, let's say 300 applications and so on that fall under the purview of SOX and so on, they have that figured out, right?
But the larger challenge we see is on everything else, right? And it also varies based on industries and size of organization and sector. Some organizations, you know, have more of it figured out and we find a lot more organizations struggling in that space. Interesting. Thank you everyone for voting.
So, let's move then on to the questions. Currently, we have two questions. The first one is, if an organization can only tackle a few use cases first, which application inventory-driven use cases deliver the fastest visible wins? And I think that's a good question when we think about the poll that we just had, right? What do you think?
Yeah, no, absolutely. I think the ones that can give you the fastest wins is, you know, identifying what we already have and then going, taking them through a risk classification process and then using them for onboarding, right? What you already have an understanding of.
Let's categorize those applications and then start driving them towards adopting the identity security program or onboarding into the identity security program is where we see the first few use cases that can deliver some quick, fast, tangible wins that IAM program leaders can show to the rest of the enterprises as takeaways and wins that gets further adoption from across the organization, right?
Yeah, and one interesting thing here is when we talk about the visible and fast wins, the quick wins, the discovery piece is definitely not to underestimate because when we think about the whole landscape, and I've shown that, especially the part that you are not aware of and that is completely unmanaged, this is a visible win. And the second thing that I would like to highlight is the ownership piece. Something that we learn when we are working with especially huge organizations is the ownership piece is not always clarified.
So, there are a lot of applications out there that don't have an owner. If you are structuring your landscape, this ownership is something that you want to clarify very early. And this is definitely one of the quick wins. Absolutely, I would agree. Good. Let's move on to the second question. We are done answering that.
So, the next one is for organizations already invested in multiple IAM platforms, how do you position Simeo I.O. as a replacement, an orchestration layer or something else?
Yeah, no, that's a good question that we're often asked. Our goal is not to replace the existing IAM investments that an organization has made. And we really, the goal of Simeo I.O. is to actually get more return on the investments that an enterprise has already made.
So, if you've made investments in a leading IGA product, we saw some of them on screen, leading access management product and PAM product. We do not provide the features and functions natively provided by those products. We are not a vaulting solution, we are not an authentication product, nor are we an IGA product. We sit as an overall identity control plane on top of these products, providing capabilities, using orchestration as a plumbing.
So, because we plug into all of these products, our real strength is using the integrations that we have, using orchestration as a plumbing to pull the data and provide unified visibility across all of these products. And most of the enterprises, I would say at least 90% of the enterprises that we work with are in a best-of-breed identity ecosystem.
So, they are not using the same tooling for IGA access management and PAM, they use best-of-breed for their capabilities. But when they do that, there is often a lack of visibility across your overall identity data.
So, we bring the applications that we talked about, we bring what controls have been implemented for all these applications across your various IAM tools, we provide the visibility, and then we provide the remediation capability as well. We are that unified control plane where we then provide the remediation capability to go turn on the controls in the identity products that you've already invested in and then provide the audit evidence and all of that in a unified approach. Providing that one identity fabric type of capabilities is what we do.
Or in a few words, you are the glue that enhances everything. Yeah, great to look at it. Thank you.
So, moving to the last question here, where do most organizations sit on IAM maturity when it comes to application lifecycle management and ownership and what indicators show that you've moved from reactive to strategic? Do you want to go first?
Sure, I can take a stab at it. We find most enterprises, you know, SMU has an identity maturity model, right? It is based on a five-point scale, right? It's based on a five-point scale. And we measure maturity across three primary parameters, right, is what's important to us.
One is, you know, what I would call as capability maturity, right? And in the rings that we saw, right, in the screenshot that I showed, we look at it as capability maturity. What are the capabilities or IAM capabilities or controls that your organization has today that's been rolled out or implemented, right? Which is you could have automated provisioning, privileged vaulting, single sign-on, multi-factor, capability maturity. The second is, now how widely is this capability adopted in your organization?
If you have thousands of applications, what percentage of these applications has this capability rolled out for? I think that is another big measure of maturity. The third is effectiveness. You've deployed a capability, you've adopted the capability, but how effective is that capability, right? If you've implemented automated provisioning or if you've implemented single sign-on or MFA for the organization, but it's still taking people five days to get access or 10 days to get access, then that capability is not effective, right? So we need to then look at what's broken in the process.
So those are the three primary parameters that we look at with regards to measuring maturity. We find a lot of organizations more at the level 2.5 on a five-point scale. We find a lot of enterprises are very immature still in their IAM program. I'll stop talking and turn it over to you, Philip, to answer that as well. So I will do a short and brief answer to that. We have already highlighted that, especially when it comes to ownership, organizations are not there yet. So ownership is often not clarified.
There are often applications without owners and when it comes to IAM maturity, this is really an issue. When we think about life cycle application, life cycle management and its maturity, from what I've seen, the organizations are in different places. I have seen organizations with very mature life cycle management, but I have also seen the other side. So that's a very diverse landscape, I would say. So that is my quick answer to that because we are running out of time. Thank you for joining our webinar. Thank you for participating in the polls. Thank you for the questions.
If there are any more questions, you can reach out to me, to Asif. Thank you for joining. See you in the next webinars.
See All Locations
See All Locations