Hi everyone, and thanks for showing up, but not everyone did, so I'm happy that you guys at least are here. And I'm a little bit of a strange one in this long line of vendors basically, presenting their solutions as if they're going to solve all of your problems. And to be honest, solutions, technology, they can only go so far. Identity and access management projects are hard. Solutions are hard, getting the organization to change is very, very difficult, and tools can help you with that. You can facilitate that and all that kind of things.
But at the end of the day, it's still going to be very difficult to get your organization to change and to implement it, and this is true for your classic use cases, you know, your end users and that kind of thing, and it's even more difficult when we're talking about non-human identities, AI, and everything that's been discussed this week. That's really strange, right, because if you look at it at the bottom line, we're in a golden age of identity and access management. We've never had it this good.
We've never had so many solutions supported by stuff like AI to help us improve our identity and access management within our organization. We have all kinds of architecture frameworks to support the stuff that we need to do to talk to our business and explain that it's all part of a big picture, you know, that kind of thing, and we also have a lot of great solutions that help us in these challenges that we're facing.
We have real, full-blown, mature IGA solutions that even some of the market analysts say are mature enough to basically solve all our needs, but we also have stuff like Microsoft Entra that's taking huge leaps in coming from an IGA-like perspective to more of a full-blown IGA solution. And yet, we still have those same issues that we had a couple of years ago, right? We still have managers that click on approve all and give all access to everyone within the team because our operational processes are so much more important.
We have escalations within our organizations where even though from an authorization perspective and from a process perspective, people shouldn't have access, that if those operational processes demand people to get access as soon as possible, right now, even though the onboarding process wasn't followed or there's no reason to, they still need that access and they will call the service desk and they will escalate until they get that access. Solutions are not going to solve those issues. We have compliance issues out of the wazoo.
We have all these types of organizations that are putting demands on us, not just European or American law, not just stuff like specific ways to operate with our customers and with our partners, but even internally within organizations, we're talking about data sovereignty where we want to do all these kinds of things. So all these compliance things are heaping up and there's no organization that I've met that can guarantee that they're 100% compliant. They all hope, they're all skating by and they solve their issues with short-term stuff and that's it.
So if you ask, I am experts and I know a lot of you are in here, is your organization in control even though we have all that stuff available to us? We are in that golden age and everyone will say, no, I'm not in control. The place is on fire. And that sucks, right? Because at the end of the day, what we're talking about is simple stuff like giving access to people, making sure that we have an understanding on who has access to what and why. And from that perspective, it hasn't really changed much since, you know, these days. In these days, people also joined your organization.
In these days, people also had to have their stuff they needed to do their job, to work efficiently and get access to the stuff that they needed. Even though there weren't IT accesses, you still had, you know, a couple of guys that were required to get stuff, certain amounts of paperwork and other ones who were not allowed to have access to those things. So at the core, IAM has always been here. So that means that when we're talking about resolving those issues, then we need to learn from even those days, but also the past 25 years in how to resolve that.
And how do we learn from that is to narrow it down, to make it as basic as possible. What are we talking about? We're talking about identity and access management. What we are talking about is risk management at its core. Making a decision on which person should have access to what and why. And making sure that we have an understanding on that, that we are in control over that process and also that we can demonstrably show that we are in that control. That we can click on a button and see who has that access and that kind of thing.
And when you talk to organizations about risk management, they always say, well, that means that this is not an IT problem. This is a core capability, a key capability within our organization. This is not something that is just IT. This is something that we need to do not as a project, but as a key capability, and we need to develop that within our organization. Because at the end of the day, when we're talking about getting access to our information, that information is our golden egg, right? That's who we are. So we need to make sure that that is secure.
Okay, then if we look at a couple of numbers, and if you look at it from the perspective of market vendors, then you see, if you do the analysis, that 10% of organizations only have a mature IGA solution in place. What does that mean? That means that even though all organizations are doing stuff with IGA, only 10% can say that they have a mature solution in place. 8% of organizations have successfully implemented end-to-end automation of access requests and provisioning. Only 8%.
And those are typically large organizations with strong regulation, you know, enterprise level and that kind of thing, running robust IGA programs. 30% of organizations manage to reach a partially successful or operational situation. I often call this implementing the fundament or installing the product, basically, where if you ask an organization, do you have IGA, they will say, yes, we have SailPoint, yes, we implemented Omada, or we have Sapient, or even, you know, within Entra, we have their identity management module in place.
But if you ask your IAM leaders, they will say, well, we have nothing automated. We only have a source system connected or something like that. So that means, simply, at the bottom line, that only 50% of organizations cannot state that they have successfully implemented IGA in any way, shape, or form. That's scary, right? Because all of that money going there, all of these vendors in this building telling us that they are the solution to all our problems, and yet we are still challenging, we still find challenges to get everything in place.
And then we come back to basically the title of this presentation. We've been in the field of identity and access management for 25 years, and in those 25 years, of course, we've had a lot of success implementing identity and access management, but we've also hit every pitfall that you can imagine. And I think it's very important for us all as an organization to learn from each other, and not just focus on all the capabilities that are coming forward, but also, where did things go wrong? Why did we really fail in implementing those identity and access management solutions?
And the reasons are legion, so I'm going to go through a couple of them. The first one is too large a scope. I'm sure that I could talk to about half the people in this room that have been forced by their organization, either by the business or by IT management, to implement using Big Bang, to go all out and implement a solution with all the connectors that we need in place and that kind of thing, and then you're setting up to fail, right? You're setting up for delays and all those kinds of things. A real challenge is limited data quality.
I'll come back to that later, but we need data to automate our processes, right? And if the data's not complete and if the data's not correct, then we have an issue as well. A lot of organizations approach IAM as a project and not as an operating model.
You know, I used to say a program, but it's even bigger than that, because IAM is part of your core business, as I said earlier. It's not a project that you can do and say, well, now we're going to implement IAM, and in half a year, we're done, and that's it. It's something that continuously involves and continuously needs to be improved. Weak integration steering is one, and that's what I feel is a very important one within organization as well. If I go to an organization, usually one of the first questions I ask is, who's the owner?
You know, governance, that's a very important one. And the second question is, how is this regulated within your IT department on an architecture level, for example? And then a lot of the organization will say, well, we have architects, but those architects work on a project basis or are focused on the IT part and that kind of thing.
Architecture is essential in making sure that all these tools that we currently already have or get for free when we, you know, get a Microsoft 365 subscription or something like that, how are we sure that we use those tools for the right reasons with the right things in mind and that kind of thing? And the last one that is in this list is lack of understanding of change management, because change is essential.
Like I said, when we're talking about an organizational adaptation and not an IT project, we're talking about adapting all these things that we're going to be seeing into new ways of working. We did this 100 years ago. We had people joining the organization. We had people getting access rights and that kind of thing. So now we need to make sure that we wrap it up and make sure that we improve it. We're always talking about improving something that's already there, and that makes it really, really difficult. And this results in no real control over your access.
It means that we use Excel sheets to assign access. We use the solutions that we have, but through the processes in all different kinds of directions. So what are the real reasons, then, if we narrow it down? One of the key parts of an IGA implementation, like I said, is governance. Do we know exactly who is responsible for these processes? And are they also on board to change those? Because when we're talking about identity management processes, we have end users that are authenticating and need access on an authorization level. We have AI that needs access. We have non-human identities.
But we also have managers that are involved in the decision-making progress that give access to these people. We have security people that are setting up policies regarding access. We have risk management involved. We have basically C-level that's also in charge and responsible, basically. It means that this is a challenge and a problem for the entire organization. And in reality, when it's a problem of everyone, it's no one's problem, right? Everyone will point different fingers and say, well, this is something that HR should resolve. Or this is an IT problem first. They should fix it.
If you do not have a clear understanding of who your owner is within the landscape, then you cannot improve it. Because everyone will pass the buck. Because this is the heart, like I said. It's a real challenge. The second one are processes. The processes that we use and rely on when it comes to identity and access management are often incomplete. We might have processes in place for our internal employees.
You know, they can get access in a certain way. They can join the organization. When they join, they get a certain set of attributes. And based on that, they get roles and access and that kind of thing. But is that true for non-internal employees as well? Is that true for partners that need access and that kind of thing? Or are they non-standard changes within our IT department? They get an account and we don't really connect an identity to that. And that means we lose control. That's a real challenge as well. Then one of the biggest ones is information.
All the tools that we are talking about rely on information. Because when we're talking about identity and access management, really the only thing we do is transform information based on an identity and its attributes, the access rights that they need, the steps that need to be undertaken to get towards access and resolve into an account or in an access or something like that. It relies on information. And information can be wrong on lots of levels, right? It cannot be accurate, it cannot be complete, it cannot be available, it cannot be reliable, it cannot be on time.
And I often say garbage in is garbage out, and this is one of the key things that we have here. You can have the best solution in place, the best solution in the world, if the information that you put into that system, if the attributes of your identity are not correct, if you do not have your policies correctly determined, if your HR department puts organizational changes into the system a day late, then that can be disastrous for the access rights that you give to your different types of identities. And then that comes really down to all these other things that we have in place, right?
More reasons that things can go wrong. We can talk about vision and strategy. What is the vision and strategy of my organization? How do I want to approach identity and access management? Do I want to be like a bank where I want on basically a transaction level want to determine if people should have access or not? Do I want to connect that to all the different types of access layers that we might have and add risk to that as well?
Or am I more like a healthcare organization where getting access to information might be very difficult to regulate because of all the GDPR-related rules and regulations? But at the end of the day, not even having access to someone's medical files might result in a life or death situation. So know what your organization is and how you want to approach identity and access management and how to implement your solutions based on that. Based on a vision and strategy, both on the short and the long term. Do I know what the compliance rules are within my market, within my organization?
Not just external compliance, but also internal compliance. When am I in control? When am I in control enough? Or as an organization, do I approach the compliance issues from the perspective of if I'm in control, then I am automatically compliant as well? And can I do it that way? Do I know exactly what my organization looks like? Who is responsible for all of these processes? Or should everyone just call the IT department to get their issues solved? Can I do that in a balanced way so that everyone knows exactly who they should approach?
All these things are equally important, and they all deserve the equal amount of attention basically when it comes to implementation like this. And that's why we come down to approaching identity and access management as a change management project. Because the weakest chain will determine the strength of your entire chain.
If you have the best solution in the world, if you have Saviant in place, if you have Rubrik in place, if you have all these solutions there, but your processes are not aligned, or your governance is not in place, or your information is, like I said, garbage, well then you have an issue, right? You have a real problem there. So make sure that you give equal attention to all of these to make sure that your chain is as strong as it can be.
Okay, then wrapping up, what are the action items that my advice would be to use that knowledge that we have in the last couple of years to make that step to improving our identity and access management? The first thing you need to do is determine where you stand, not only from a technical point of view, but specifically in all those other areas that we discussed. Because that determines the maturity where you are as an organization. Where am I on process level? Where am I on a technology level? Where am I on an information level?
Technology is not just the tools that I have, but it's architecture in place as well. Those kinds of things determine where you are on a maturity level. And if you have that, if you know where you are, you need to determine where you want to be. And usually that is based on your specific needs and requirements. A lot of stuff resolving around managing access to NHI at this moment, of course. But also the maturity growth that you want as an organization. And usually that is taking small steps to getting to a higher level.
But use these things when you have your current situation and your to-be situation, you know, to define your gap and determine how your roadmap should improve all the things that you are currently lacking. And that means focusing on those things that are, you know, in need the most. If you have the best solution in the world, don't focus on technology. Focus on your governance. If you have your organization in place, but your information cannot be relied on to automate processes and that kind of thing, focus on that. Make sure that you put the focus on that level.
And the last one is the days of, you know, getting a bunch of money and your organization telling you we'll see you in a year and see what you got there, those are gone as well. Make sure that you hit your low-hanging fruit, that you improve your organization step by step and relate those to business goals and business benefits that you as an organization want to achieve. If you take these things into consideration, I'm sure that we can learn from our mistakes and then improve the situation a lot. That's it. Thank you very much for your attention. Thanks Kirin.
In your experience, what is the clearest indication that a company has kind of crossed the divide from going, treating identity as a business capability to something that is strategically important? One of the most important indicators is if your C-level is on board, right? You see a lot of organizations where identity and access management becomes an issue for either IT management or the CISO or anything like that.
But once you get this on the table of C-level, where you have your CFO taking responsibility because it is risk management in the core or your CEO putting it on the table as one of the primary drivers for the organization going forward, then you're taking good steps. So it's a lot of politics involved there as well. As always. Once again, Jeroen. Thank you. Thank you.