Thanks for the introduction. Thanks for joining my session today.
Yes, I will talk about 365 Days of Change. Basically, I think you all know what changed in the recent year, I would say. And thereby also answering the question why we need European IAM and why it matters now. And also a short shout out that we all from Europe participate more into the standard bodies here. As you outlined, we have one of the best conferences already. And now we now need to push it also into the standard bodies and to be more active there. So the thesis is quite clear. Digital Sovereignty has shifted from political slowing to business asset.
And IAM is the layer where European companies either capture the value or simply absorb the cost. And this shift, we experienced it from ourselves as a European IAM vendor. We proclaim this Digital Sovereignty story under different names already since 10 years. It was always a good awareness topic. Now it became a decision factor. So I've summarized three shifts into one new picture. So each alone is incremental, but jointly they really push forward and that makes it an unavoidable topic. So first of all, regulatory use case. Enforcement, not legislation.
I think quite clear we have NIST 2, for example, which gives regulations to many companies. We have DORA for financial institutes. We have ERS 2.0 upcoming with a concrete wallet timeline for all the states. And hopefully also all the companies utilizing that. And now the conversation moved from the drafts to really enforcing that and also audits requesting companies to really fulfill the regulatory requirements. And second, I think one of the most important things happening is the geopolitical shift. So I would say the Cloud Act was already there.
Since before that, data privacy is proclaimed already. Okay, you need to keep that into your account. But with the shift of the US administration, that moved from a theoretical question to like an actual issue. So 2028 and 2023, it was like a topic in the risk report. Now it's in the board.
And third, as an answer to that, Serenity becomes part of RFPs. So that's where we as an IM vendor and other professionals can also gain awareness and can gain profit out of that. We have the governmental side, we have critical service providers, insurances, financial institutes, who all consider that now in their RFP processes. So the turning point, as outlined, until 2024, it was like a theoretical exposure.
So SRAM 2, others, it was like a footnote. We as an IM vendor used it to gain awareness, but that was not a decision factor. It was more like, oh, there's a European player, let's also consider them and be convinced by features, not by being digital Serenity or a European story.
2025, we have a few logbook entries, that's just a few examples, which were in the media and which helped to understand the topic, what is happening there. We have Karim Khan, I think that's one of the most common, most well-known cases, as chief prosecutor in the ICC. Microsoft blocked email account, UK bank accounts were frozen after US sanctions on the ICC. And for him, it was like, I would say a nightmare. I also wouldn't blame Microsoft directly here, because that's what they need to do. That's the legal foundation.
But it also raises the question, if they are enforced to do it, what actions or what measures do we have to react to that? The same happened to three ICC judges also. So they were blocked from PayPal, bank accounts, also European banks already blocked them as preliminary action. And we also have more geopolitical topics, like Maxar Technologies, who blocked Ukraine's access for three days, which really also was a limiting factor for them in a critical situation, I would say. And exposure runs into any direction. So it's not limited to one company or one person. Anyone can be affected.
So a kill switch argument moved from theoretical exposure to becoming effective in 2025. And logbook entries are already happening. But it's bigger than that. So kill switch is only the visible question to us. We really have to decide as European companies, organizations, and people, citizens, what do we want to do? So we have three questions.
Data, who hands on our data? So who decides that? That is not only the logins happening, but also all the metadata, telemetry, what is happening there, that can be used, can be analyzed, and gives insights onto what we are doing. So if anyone has access to that, they have a lot of insights and leverage there. We have to decide who decides what identity means in the next decade. That's where we as people, professionals in the IAM space, need to be active also in the standard bodies, because then we can influence what's happening there. Simple token formats, but trust frameworks and more.
That's where EI does 2.0, and where also regulation can help us. And the posture. Are we just shaping the field, and that's really the decision? Or are we just shaping it, or are we just playing on that? So basically, certainty isn't only resisting a kill switch, finally. It's also deciding not to leave the field and being active in that. And we as an IAM vendor, we need to do that. I'm honest on that. We didn't participate so much in the different foundations and so forth. We did a lot of marketing, but we need to shift it, too.
We need to be more active and need to really influence what's happening. And there's a lot of certain washing happening there. So we first had sovereign cloud as an answer. The market gave. Also a lot of hyperscalers who really use that, but then maybe solves only one layer. So where the data sits.
Frankfurt, Paris, Madrid. I would say the checkbox for the region data residency is done, but we have two more layers. So who writes the code as a small statement? Who influences that? So who patches? Where do the developers sit? Under which jurisdiction do they fall? Do they have backdoors implemented? Things like that. So that's important. And the third level, the control and contract layer. So that's basically the jurisdiction question, what we have in that game. So that's the jurisdiction you sign that, and also under which jurisdiction do the company behind that act.
So even if they sign a European contract with you and they have an influence from US, they might still be enforced to hand over data, to terminate the contract, to freeze any relations with you. So sovereign washing, that's the statement of Corey Kreider. When sovereign becomes a marketing word and the contract still answers the foreign law, that's sovereign rushing, and that's happening quite often in the market right now. So solving sovereign layer one, and coincidently, that's not a strategy. That's why we at CITAS Knips and Klawek decided to run on European providers.
We obviously have, as a European company, also the European jurisdiction. And we also actively decided to not answer US requests, what we have gotten in particular in the last year. So we actively fight against these access and these pressure what we have received. And one layer of four regulations, that's also the regulatory aspect. So identity is only architectural surface. It touches every EU major regulation, I would say, or compliance regime. I just listed a few out of them.
GPR, EIS 2.0, NIST 2, DORA. There will be coming more in the future, and there were more in the past. The advantage in that aspect is if you modernize our IAM core ones, that might satisfy four regimes. That also means if you ignore IAM, we might fail four of the regulations. I try to bring that to four vectors now. So vector one is jurisdiction control.
Again, 2053, the question was, where do the data sit? So this data residency checkbox 2056, the question is, who can influence the provider and how? Under which jurisdiction can support staff also fall? So if they are outside, they might also access that. Who can be legally compelled to disclose or disconnect your service or access the data? And where do telemetry backups and AI interference run? And this AI topic is becoming really important because we are also using AI capabilities already for different things that might be for fraud detection, for ID verification solutions and more.
Also for monitoring things. And that's a big question we need to answer. And thereby, sovereignty is not a map of data centers. It's really the map who can pull the plug and under whose law. Vector two is this privacy by design topic.
This is, in particular, the GPR topic, what we already have. So it's not only running GPR compliant. It's also offering the capabilities here like concept management, what we need to have, right to be forgotten, data portability, records of processing. So EU regulation is not a feature backlog here. It's a brief. We at CDOS has already been delivering for years now. Vector three, regulations as architecture. And that's where we can state the final thing, read NIST and DORA the right way. Your modernization roadmap writes itself. So it's also part of your modernization strategy.
And if you have, for example, in this tool, we have this MFA mandatory across critical services. Basically, for the architecture, that means phishing-resistant authentication, passwordless. If we have the same for DORA, third-party ICT risk management, that means we need to manage third-party access as part of our IAM story. And for eIDAS, that means that citizen wallet acceptance for relying parties, that means open ID for verifiable credentials. So we need to rely on a standard. So that's an architectural pattern.
And four, interoperability and exit. Serenity is the freedom to choose. That's always what we outlined. It will also come in the end. The platform playbook, it's quite easy. Lock in by that. We know that from hyperscalers, we have this express traffic, which is super expensive. That's basically the anti-pattern of the freedom of choice and being open. And the European playbook must be trust by openness. So we need to support the standards like open ID for authentication, verifiable credentials, or then for fine-grained authorization.
And we need to support eIDAS architectures and reference architecture. And we also need to provide exit options. And there shouldn't be any artificial barriers to force customers into your platform. You need to convince them by openness, by a feature set, by collaboration, not by making it so expensive to leave the platform. So for everyone, it's important to look for openness on the way in, look for the exit door on the way out, and both means warranty, not just the way in and then having the block and extensive cost in the end.
Before I come to the moves you should take out for your Monday morning briefings, maybe a little story to us. We are made in Germany, and we used that headline long before it was a headline, I would say. We are built and hosted in Germany or Europe. That means headquartered in Baden-Württemberg. That means hosting on really European sort of infrastructure. That might be, for example, DT Cloud, that might be Spark Huston services, own data centers and so forth. We scale internationally. We don't rely on hyperscalers for the European setup, which is really important. And we are certified.
So we have this ISO 27001, this PSI C5, and we provide a capability stay. For example, around GPR. So compliance is not a product roadmap item, it's a flow we are built on. And what changed in the last 365 days is our architecture. What changed is that the market caught up, and they really also detected that there might be issues, and the issues are really enforced. So what does that mean as moves for the future?
Move one, consolidate. So bundle a compliance project before they become four. In many things you can really have leverage. We have NIST 2, DORA, GPR, EIDAS, and many other regulations. Bundle them and use them as an argument to fight for your budget and to not make the budget four times. That makes it even harder. And at NTD, if you have an IM project who might already have solved 80% with one program for four regimes.
Move two, rescore your vendors. That's also what we need to do as an IM vendor. We also have vendors ourselves. So we need to ask three questions. First question, under which jurisdiction can you support staff, access, or tenant? That's what we have seen beforehand. Where is our authentication telemetry if you put it to IM? But in general, for any vendor, where is the telemetry, metadata, and backup stored, processed, and analyzed?
And third, if a non-EU government compels disclosure, what happens to your data? That's the question we now ask all our vendors. What happens if, like we in the last year, get a request by an American agency to access certain things? How do you react? And that will be part of our procurement templates by 2027. That's our prediction. And we should be the team, as IM teams, who can already answer that question. And move three, in particular for IM professionals, monetize that.
Use that marketing serenity topic as a sales argument, not a checkbox, and sell it internally, as well as also to all your partners. So the old ROI model was serenity equals costs. You need to have, like, a European host might be more expensive, not the same capabilities as the big hyperscalers. To be open, the European players become better and better every day. But the new ROI model, serenity is becoming revenue. In particular for us as professionals and vendors in that area, we can really use that as a selling argument in our stories.
So in your next sales deck, use serenity and give that more space than the feature backlog. And finally, the last marketing slide for us. Why we talk like that? We currently manage more than 1 billion user identities for more than 300 customers for more than 580 instances and have daily access from 182 countries. We have a good analyst recognition in the meantime, and so I would say 300 customers across 182 countries. That's a trust identity layer we can be happy about, and that's the brief we deliver.
So for us, that's really the push and why we feel confident to answer these questions. And one last thing, that's also what I'm saying. Serenity isn't doing all yourself. Serenity is the freedom to choice. What you build, what you outsource to whom, and under whose jurisdiction. And that doesn't also mean you shouldn't use US players. But if we have more competition from the European market, we put also more pressure on players outside of Europe. That enforces them to change how they act. So if we have good solutions not only in the IAM space, that really helps us to pressure that.
So last 365 days gave Europe the choice. Next 365 days will show how we use it and who uses it. And that's it. Thanks for joining. If you have questions, feel free to ask now or later. Thank you very much for keeping on time. And please ask questions.
Well, you put a hand up. Thank you. That was really good. Your question about the subject access request that you're getting from the US, how do you handle that? So you basically say no and here are the reasons, or does it just become protracted and they, I mean, you may not be able to answer this question and you may not be able to disclose everything, but is it enough for Europe to signal back this is not in accordance with our law or is it a constant process? The question is hard because it's not like they ask nicely, please, can you help us there? The question comes like that.
Yes, I'm there. Please give me a call back. Then you reply, what's the topic? Then they reply, that's not of your matter. Please give me a call back. If I request you to give me a call, you call. And then you answer no. And then at time they come out with what they want and then you can react. But that's always, we don't do it ourselves. You put in a lawyer. That's not a business what we do. I'm the tech guy and I have the legal team on that side and you have multiple requests. So they don't disclose.
No, no, they don't disclose. They just tell you hop on a call with me. So that's not like how they react. Their perception of themselves is different. So they think they can ask that and you have to answer. And that's also the confidence how they step in. But one additional question to that is if you get a hop on a call and there's no agenda, how do you even know it is the... We don't hop on a call. You don't even know the...
No, what I'm saying is you don't even know that the person has the correct identity or is from who it is. So there's a flawed process right from the start. Correct. That's the main issue and that's why we reply. What's the topic? Please reply to us that we can... So obviously we reply nicely. Please provide us the topic, some ideas and all that that we know who to plug in. What's the basis and all that? And after two, three mails, then they start to outline what they want. That's not from the beginning. So any more questions?
Otherwise, I'm going to ask one. There's one question I have to say. There is a precedent for all this and that's what happened with Chinese telecom equipments about 10, 15 years ago. And then we went through the same cycle where big providers like Huawei and ZTE were actively taken from the networks after procurement. It's hard. That's also why...
Basically, since we're European law, it's not our data. So we are always handing data on behalf of our customers. So that's... If you don't know the topic, you cannot involve the customers directly. Once you know it, you can then involve a customer and outline that. I can give you one feedback from what we have seen in the last year. So finally, they started with pressure and then they said, yeah, it's not about us. It's just... So once you reply and block and be hard, I would say, then also their voice gets or their confidence gets down and they say, it's not about us, don't worry.
We just want an exchange with you. So then after the first peak, then it goes down. But obviously, it's like diplomacy. You have to react, but you never should just reply, yeah, what do you need? Here's the database access, whatever. So in that aspect, for example, you just... You have to have first all the data, all the information on the table, then you can react. Then if it's affecting a customer, in our case, no customer was affected because they didn't outline everything. They just outlined it was like a request and things like that. Then you can involve the customer.
If no customer's involved, you already know how to react and then you have the clear guideline. Thank you. So I'm going to ask a question and I'm going to ask a question of you.
Now, at the beginning of this presentation, there was a list of people who had their credit cards and so forth stopped. Oh, dear. What a shame. Nevermind. How long could your organization survive if your identity infrastructure was not available? Do you think it could last a day? 90 days? I'm going to ask you, how long do you think your infrastructure could survive? How long you would- I wouldn't say not even a day since if I take the ICC judge example, one of the judges didn't have even access to the bank account. So then you have just the money you have with you. That's it.
And we all think about, yeah, you don't have credit cards, PayPal, and all that. But even if your bank account is closed, freezing of a European bank, then you really have issues. You can't pay. And the same is for IAM. So if you don't have access to your IAM system because it's shut down or whatever, I think in the case of Mr.
Kahn, it was like seven days until Microsoft had to block it. So also in that aspect, I can be open. Microsoft supported that so that the judge or the prosecutor can move away to proton mail in Switzerland. That's what they tried to do. That's the best they could do, but still it's not the perfect result, right? For a company like an organization like the ICC, that's not the way how you can work, right? If you get shut down because of sanctions by a U.S.
player, what is the result? Yeah, so basically, identity infrastructure is fundamental to everybody's business.
Now, for geeks of compliance, there's some breaking news. On the 27th of April, the German BSI published a standard, C3A, which actually gives some specifications, some concrete details of how you judge sovereignty. And it includes things like being able to run without connection. And actually, it talks about 90 days as being the ability to run without being connected. So these are serious points that we have to consider. So if there's no more questions and there's no more questions online, I'll ask you all to show your appreciation of the good talk. And thank you very much. Thanks.