Welcome to the KuppingerCole Analysts chat. I'm your host, my name is Matthias Reinhardt, I'm advisor and analyst with KuppingerCole Analysts. In the recent weeks, at the end of 2025 and at the beginning of 2026, we had some episodes with our analysts looking at predictions for the upcoming year, which has already started a bit. So we looked at IAM topics and what will happen there and the predictions for cybersecurity. And for those topics, we had Jonathan and Martin and Alexei.
And we want to continue this with a special edition of the analyst chat, because we don't have any analysts in the room, but we have advisors in the room. And as I said, I'm an advisor and analyst at KuppingerCole. And advisors are Charlene and Reiner, and I would like to welcome them to this podcast. First of all, of course, with the lady.
Hi, Charlene, good to have you here. Hi, Matthias. Thanks for having me again. Great to have you. And for the first time, he's not the new kid on the block, but he's new with KuppingerCole, but a really experienced IAM advisor for many, many years. I would like to welcome Reiner.
Hi, Reiner. Hi, Matthias. Thanks for having me here. Morning.
Yeah, great to have you. And we want to look at the second pillar of what KuppingerCole does when it comes to interacting with our different types of customers. And this time, it's end user organizations, and we're doing advisory there for all the end user organizations out there that we are doing business with.
No, we don't talk about your projects. We talk about patents that we see, about topics that might be interesting for you or for others to have some additional conversation when it really comes to improving, introducing, evolving your IAM, your cybersecurity, where KuppingerCole can shine. And when it comes to this perspective of the end user organizations, let's dive deeply in there. Maybe starting with you, Charlie, which topics are most critical when it comes to implementing IAM and cybersecurity right now?
And then I would like to hand over to Reiner, because maybe you have different perspectives. Yeah, thank you so much.
So, first of all, I have to say that, of course, this differs a bit from organization to organization, but this is mainly because organizations have different drivers. Some are driven more by compliance. Others are driven by efficiency or cost pressure. But if I look for sort of a common denominator across those organizations, I would say, at least from my perspective, it's mainly operability. And what I mean by that is the ability to run systems and to run processes that they design in day-to-day operations.
This is because most organizations already have IAM and cybersecurity tools in so they barely start from a greenfield. And the challenge is mainly not to introduce new tools or to implement new tools, but to make whatever is existing at the moment work reliably, especially in large organizations. Another factor that I would like to add is that besides technology, what I see in practice are topics sort of unclear ownership, overlapping responsibilities, and especially with IAM sitting somewhere between business, IT, security, there can be a lot of friction.
So many organizations, they struggle with clear frameworks, with guidance, also with governance, and how to properly embed those into their organizations. With that, handing over to Okay. Yes. Thank you. So I can only underpin that. So what I see is a lot of modernization. So what we see is that at least highly regulated companies are doing IGA for more than a decade now. And what we see is that they are running into modernization projects and putting efforts into that.
So they find that organizations have changed their different requirements or they have due to their history, a very heterogeneous IT infrastructure and maybe a lot of local solutions. And they are looking for a consolidation in that area, a modernization of the products. And with that are questioning their IGA strategy and looking into, okay, how do we want to run our IGA? They understand that IGA is not only a project, but a program which needs to be run over years.
And yeah, what we see a lot is that we help them then with roadmaps, for example, understanding, okay, what is your vision for the next three, five years, maybe, and then derive a target vision and also then some roadmap for that. I can also underpin this increased regulatory pressure, which brings me to another topic, which we see.
With that, we see that auditors are more and more also looking into privileged access. And it's asking, okay, it's no longer enough to just do IGA with employees and partners, but you also need to look into privileged access. They expect this to be kind of an integral part of the identity access management efforts of a company. And they are no longer seeing this as a nice to have.
And yeah, companies are also then looking into that. And I think they also sometimes struggle with that quite a lot. You've mentioned already privileged access. And I think that is especially a topic for many organizations right now because organizations are forced to do it because looking into privileged access from the outside or from the inside is sometimes even considered to be part of third party governance. So when you have an external supplier, an external partner who does things on your own systems for you as a service, then this needs to be properly controlled, maintained, and audited.
And that is something that has not been neglected or ignored, but it sometimes did not get the attention that it deserved. So is this one of the reasons why privileged access is coming around again, that we are doing policy work with our customer organizations, but also look into not the technical parts of PAM, but the process work? I don't know who wants to answer Rainer first.
Yeah, so maybe. So I already said, so one of the main drivers I see is regulatory pressure again. So that companies see that auditors are asking for privileged access and they're again looking into that. And sometimes they also see that out of their IT security strategy, topics like zero trust, for example, also drive this topic. And the reason behind that is that, I mean, back in the days, it was a human identity actually doing administrative tasks on servers and machines and this kind of things.
And nowadays this is more done by, let's say, infrastructure as a code, for example, by CICD deployment pipelines, more automated stuff is doing this administrative work. And with that, then all this kind of non-human identities topics comes into the play here. And when you talk about the partners, for example, and getting access to, let's say, kind of critical systems, we see that the identity is the new control plane, right?
There's no longer the perimeter actually safeguarding your domain controller or safeguarding your critical systems anymore, because also your critical systems could be outside of your network somewhere in the cloud. And that is the reason why then people are looking into this kind of topics here. Right.
Charlie, your thoughts? Yeah, I agree with what Rainer said. I also see that PAM has moved from being a purely, let's say, technical admin topic to more sort of a business resilience topic. It is used to enforce this privilege and ultimately limit the blast radius of an attack, but also to ensure organizations can recover fast. And it's no longer limited to administrator, but spread across a lot of systems, multiple environments.
What I see in sort of modernization is that probably it's not about adding more controls, but about really deciding what should be protected with PAM controls and where lighter approaches might be sufficient. Because when we again think of operability and day-to-day business, the controls that we implement shouldn't hinder the employees within the organization.
And here, I can also repeat what I said before that PAM requires clear ownership. We need to be clear who is responsible for what, how the privileged access is defined and managed. And while Rainer was talking about auditors, that's true. And also auditors care less about the tool, but more about how things are implemented. For example, how privileged access is handled in practice. I'd like to add on this modernization topics here. So I think companies understand that, I don't know, password vaulting is no longer sufficient, right? They are looking into just-in-time access.
They look into topics like privilege on demand. So how to avoid standing privileged access accounts.
And yeah, with the change or with this agile development topics and these DevOps topics, they understand that also non-human identities become a huge part in this privileged access management area. And they also understand that this no longer is a silo topic somewhere on the side of the infrastructure. It needs to become integral part of the identity access management. And they're also then looking for modern features, of course, like session recording, but also then API support and support of infrastructure as a code, which let's say usual normal IGA solutions do not provide here. Right.
And the good thing is that we really have a common denominator across all three episodes that I did on predictions, because first of all, NHI is not only a hype, it's a topic and it's there and we need to deal with that. And the hybrid environment is driving change. These were common denominators across all three episodes right now. So there is really a pattern that we see that has arrived in the organizations and where advisors and other organizations, consultants are supporting because you cannot avoid it. It's there. It needs to be dealt with. So you mentioned technologies driving change.
You've mentioned the regulatory aspect and even efficiency and cost efficiency as driving factors. But if we look at organizations as a whole, I think this hybridization, if this is a word, is also changing the way organizations are actually working, how teams work.
Now, I think this is a topic that has been with us quite for a while and I think it will get more important over the next years. This is the way how organizations build target operating models to deal with the way they deliver their services, they deliver operations. But beyond that, every kind of governance control of their IT organizations. Maybe you can dig a bit deeper into that, because with external teams, software as a service, with partners doing parts of the works that you have been doing yourself earlier, you need a new way of control, right, Charlie?
Yeah, exactly. We need a new way to, let's say, get over the challenges that we see at the moment. And I think when we talk about Tom or target operating model, we should briefly clarify what actually doesn't work well at the moment, so to speak, because the Tom is meant to describe in practice how identity is managed. Let's say we have a Tom for identity, how this is managed across responsibilities, across teams and across processes within my organization and maybe also with external parties that are in a relationship with my organization.
And a challenge that I see with Toms is that either they remain too abstract or they exist on paper and are not followed in practice. So a Tom should also be operationalized and mapped again to the operability part that I was talking about, mapped to my day-to-day work. And also with that, another topic that I would like to pick up again is the ownership, because when ownership is unclear, it's hard to build a Tom, right? So where responsibilities overlap or things are not clearly assigned, accountability becomes quite blurry.
And this has a direct impact on my organization and also on my processes and at the end of the day, also on compliance, because when we think of auditors, they look for evidence that processes are working. And if that's not clearly defined and if that's not clearly traceable, then it's really difficult to demonstrate that you follow the compliance, right? Even if the technology is in place. Yeah. So you were talking about responsibilities and I also see exactly this topic when it comes to target operating models. And what I also see is then that you said there is this hybrid environment.
So that's identity and access management topics, process and technologies are nowadays more spread around. And we see that either that services are going into the cloud, but also that due to the history of the companies, that services have come up in local entities of each of the companies and the organizations. And the companies then struggling, okay, how much centralized identity and access governance should I provide and how much should I allow in the organization? So how much autonomy do they actually need?
And the other topic around that or the topic which comes up then is that the classic IGA solutions are very monolithic, right? And I mean, with our reference architecture and also with the identity fabric, we are already saying, okay, these kind of systems need to become more modular and more services based in order to allow decentralization.
So to have certain parts organized centrally, like maybe governance, for example, but to be able then to also allow to do certain parts of identity and access management in the local organizations or in the local entities of a company or putting or moving this outside to a services partner, for example. I mean, without making that happen first, you can't do that. And that is something which we often discuss with customers.
Okay, how much decentralization do we allow and how much standardization and centralized services do we define and force our organization to actually use them? Right. And that goes hand in hand also with this trend of platformization that we see. So we're no longer talking about a single tool that delivers all the services that you need. One IGA in the center of the organization and that does everything. You need to have the proper tooling and the proper processes to allow for these levels of autonomy that you've mentioned. And that to be well built.
And this is something where we clearly can support it. Of course, this platform, we call it for the identity part, the identity fabric, but really to combine it, to put the right pieces in the right place under the right governance and with the right people. That is something that needs to be decided. It usually starts with the question, hey, we have eight people in our IGA department. Is this enough? This answer cannot be given without understanding the overall fabric of the overall organization. And that is something where we clearly see also the need for support to get to this properly.
And then we need to talk about things like KPIs, KRIs, service level agreements or really operational level agreements between organizations, et cetera, et cetera. So if this rings a bell, this is something you can most probably very easily talk to Charlie or Rainer to have a first thought how to continue there. Talk about platformization. One of the key topics that we have seen last year and the year before was replacing IGA platforms that went out of service or had been sundowned. I'm not looking at USAP, but in general.
So we need to also talk about modernization when it comes to actual replacement of existing tools and not rip and replace, but maybe have a softer transition phase. What are you seeing in that area, really looking at tools, at new requirements and just modernizing platforms, Rainer? That's a good question, I would say. So it very much depends on the maturity and let's say on the efficiency of the existing tools. So we have seen, I mean, companies want to save their investments.
I mean, as I said, a lot of them are doing this IGA stuff for more than a decade now. So 10, 15 years, they invested a lot of money there and they want to make sure that they at least can save some of these investments, which they have actually done. So they need very smooth migration passes to make sure that, for example, all the connections they have to applications that they stay intact, that they can somehow reuse those processes, which they have in place and does not have to renew everything because also in most of the companies, they do not want to go this big bang approach.
I mean, we all know that this usually does not work. It's too much risk to the business then because missing permissions may be an issue then. But I would like to pick up on that, to that thought, because on the one hand, we see the tool and the technology. But what I observed is that there are some underlying issues that are independent of the tool and they only become visible during, let's say, sort of integration. Customers have a certain expectation. If they switch to another tool, suddenly all the issues are gone. But in reality, that doesn't work.
Typical examples that I'm talking about is, for example, poor data quality, again, unclear ownerships or undocumented processes. And these challenges, they exist independently of whatever platform is used. And in my opinion, they have to be addressed anyways, regardless of which tool you will select in the future. That being said, I mean, to sum it up, replacing the tool doesn't fix the fundamentals. And one thing to keep in mind, from my opinion, for the end-user organizations is that tool isn't always the solution.
And as Rainer already said, you may think about the maturity of your organization, of your processes, and then build sort of a strategy, which includes data quality remediation and other topics, to really find a tool that picks up your specific requirements to then choose the way forward. I think most companies already recognize that tools often are not the problem. And I think often it's just the starting point. So they recognize somehow our processes do not work. They are not efficient.
We have a lot of pain doing recertification, for example, other topics and issues, and users then go to their identity and access management department and complain about that. And that is then often the starting point where then those departments start to think and say, OK, yeah, we might want to rethink our EIG strategy again. And that is what I already said in the beginning, where people then really start thinking about their processes and they understand that the tool is not the only problem.
And that is then also where we often come in and help them to develop this strategy and to review the processes. A lot of times it starts with a maturity assessment. So they want to understand, OK, yeah, I mean, it's normal that my employees are complaining. They're doing that all the time. But how are we performing compared to our competitors in the same industry? That is a question which you often see. So they want to actually see, are we doing well or are we doing not so well?
And based on that, they do then kind of get analysis and also want to understand, OK, hey, Kumpinga, what is your recommendation? What level should we actually reach when we are now modernizing our IGA solution here?
And yeah, certainly that is something which we do a lot then and provide them advice and then develop the strategy and this vision of how should this solution look like in three years, for example. Right. And I think it's important also to have a structured approach, which we obviously have with identity fabric and reference architecture. And you've mentioned maturity assessment that, of course, needs to go along a proper, structured, overall infrastructure approach. And on the other hand, we can also use this to really to do, you've mentioned gap analysis to say, OK, what am I really missing?
There will not always be a solution for every question that arises next year. We don't know what happens next year. This is about predictions. But my crystal ball still is in the polishing process. So we don't know what will really happen in two years time. But we need to have a way to deal with this change and a proper gap analysis to identify, hey, we have now these new NHIs.
Hey, we need to deal more with decentralized identities, with consumers that are changing over time because of regulations, apply a proper requirements analysis, a gap analysis, and then identify what needs to change. And ideally, very smooth, very transparent to the overall organizations.
So that, I think, is one of the most important approaches that we need to think of. Platformization, requirements analysis, components that work well with each other, APIs that are the glue between these components, and then creating a solution for today and having a strategy for tomorrow. A strategy for tomorrow, you've mentioned that already. And I want to go back to an aspect that we, as I said, we've mentioned that, but organizations are currently really driven to do changes. And this is not because they necessarily want to, but they have to. And that's regulations from the outside.
That's this too, for those who are either critical themselves or deal with partners that are critical and they need to provide proper third-party governance for them. And on the other hand, it's financial industry, the largest ones, when it comes to the DORA initiative or the DORA regulation, where people really need to improve the way they're doing governance security and resilience and interacting with their partner ecosystem. Is this something that has arrived? If I'm asking that question that way, of course, it has. But how do we see that surface in reality?
So, yes, we see that. But I think, for me, nothing has changed too much because compliance and governance always were the main driver for projects and efforts in companies to do this identity access management. It always has been seen as a purely cost-driving thing. Rarely that IAM has been recognized as really as a business enabler. It was always because of compliance and governance. And this has not changed.
As I said, I see that there is some more pressure on that. And I mean, especially with the regulatory auditors, we have seen that they, again, looking more into privileged access.
But that, from my point of view, is not mainly driven by one of the standards like NAS2 or DORA, but just because they think, OK, when we look into managing risk in a company and that's what they're looking for, yeah, this is then something which should be state-of-the-art nowadays. But with that, I'm happy to hand over to Charlie, who is our regulatory expert. OK. Thanks for somehow framing me into that direction again and again.
No, I can second what Rainer just said. The regulation was there for many years. And we see new requirements. We see increased requirements. We also see that some regulation gets replaced by broader regulation. For example, DORA is replacing other regulatory texts that were there before. But what I see from an end-organization or end-user perspective is that regulation, of course, can put pressure on organizations and it can increase urgency. But this is not necessarily a bad thing, because suddenly you might get budget for projects that you wanted to do. Priorities might quickly shift.
So topics like compliance, which are very important for IAM, might move to the top of the agenda. And suddenly, IAM is the most important. I'm exaggerating now but IAM is super important and the most important topic. And things can no longer be postponed.
So, issues that we have over many, many years, they have to be resolved, which is very, very positive sometimes. And with that, regulation also has influence on roadmaps and on architectures, on our priorities, more in a, let's say, direct but also indirect way, because regulation does automatically create better architecture. But it forces us to think about how we do things and how we do things sustainably over the long run instead of chasing the next checklist and documenting the next process.
But we really have to think about what we do and how we do it and how sufficient the things that we do are. I think what has changed is that board members are feeling a personal responsibility to be compliant to regulatory requirements, right? And that is what we see a lot.
So, it is on the table of the CIO in a company to make sure that they operate their business in a compliant way. And that especially is true for identity and access governance topics. And that has changed the game a little bit, I would say, because it's no longer just one of the projects running somewhere in the organization, but it's really in focus and top management and board members are looking for that and asking for reports and asking for roadmaps and plans.
Okay, yes, we are compliant, we have findings, but how do we get compliant now? I want a concrete timetable now on my table here, when you as a team will actually finish that. And what we see is then that, again, people come also to us because they want to also have some kind of, maybe is it an assurance or something? And so they have strategies in place, they have plans in place, and they want to have external opinion on that and also get some kind of a Kumpinger co-certified maybe. So something like, okay, there's also an external party looking on the things we are doing here.
And you can be assured, yep, now we get it done, now we get compliant, the plan is valid. So there's a lot of pressure from the management also to their own teams saying, hey, now we need to really get it done, right? And we need to get it right next time. There is no second, third or whatever, try to get it right. I want to have it right now, or I want to fix my problem with compliant issues now. I would never try to impose some bad feelings for our listeners.
But if we take one step back and look at patterns across many organizations, if we look at no matter where they come from, if it's really a technology company, if it's a government, if it's any type of public sector, large enterprise or whatever, are there any patterns that you can see and maybe you highlight one where you see, oh, typically there is something to clean up the basement in general to make sure that everything that builds upon that really needs to improve? I start this time. So I pick for something that Charlie had mentioned with a half sentence data quality.
So this is something that many organizations heavily rely on. And we are talking about new modern dynamic attribute based authorization concepts, but they will work with data quality and data accuracy and data timeliness is proper available. So that is something where organizations typically can improve and raise their maturity. That would be my point.
If you both can pick one as the final thought where many organizations as a pattern, not pinpointing, finger pointing anything, but just where organizations can actually improve, what would be your first thought where organizations at least could double check if they're proper there starting with Reiner? I see two aspects over and over coming up here. And this is not necessarily a very identity assessment specific. And that is that we see a disconnection between business and IT.
And I think if companies start working on this, really making sure that they have a business ownership for the IAM topics, that really helps a lot. Then also in the quality of the processes and also to make sure that the processes implemented in the IAM are actually also fitting the business needs, helping the business and not just hindering them. And the second topic is IT governance, I would name it, right?
So that we see that there is too many different responsibilities or unclear responsibility, even within the IT organization, who is actually managing the different technologies and processes in identity access management. And that is something which I see for more than a decade in all the companies over and over again. And I don't really see that as a purely identity access management topic. It seems to be kind of a generic topic within IT organizations and how they interact with the business. And I think if companies can improve in that area, that will really help a lot.
So as soon as I have a counterpart in business, I can talk to get things much easier, things get much easier. And also the processes get much better because they fit the business needs in the end. And from my end, I would like to add. So Rainer already talked about one topic that I wanted to address, which is clarity, especially around responsibilities, the connection points between teams and what I actually do as sort of a team within the broader organization.
But this also goes into the direction of sort of vision and strategic planning of what I want to achieve within the next, let's say, one year or five years or I don't know, 10 years, which is a broad scope. But if there is no clarity, starting from day-to-day operations up to this strategic level, then it's really difficult for the employees to identify with what they do each day and also on a clarity level, because it's quite difficult to explain your, let's say, purpose and your benefits towards the organization. Right.
Before we close down, we've mentioned topics and they need to be addressed in actual projects. If you as the audience do this with us or without us, they need to be addressed. This is a bit of the commercial break now. So we are to support that. And then we need to give this a label and typical labels are not improving interfaces between organizations, but it's target operating models. So talking about how you interact with your peers within your organization and with your partners.
So defining and implementing and evolving a target operating model would be an initiative where we could support, but also just choose choices. Maturity assessments have been mentioned by Rainer, just strategic advice when it comes to long-term advisory. And you said 10 years, that's true. I had an episode with Martin last year where we talked about how long can we consider the outcome, the effect that an IGA tool decision has, and it's 15 to 20 years at least, because it will be around for that time. And the effect of this will be around that.
So having long-term IGA and IAM strategy in place is something that you should do, no matter who is actually doing it internally with partners, whoever, and applying the identity fabric and the reference architecture, in our opinion, of course, is a good way to do that. It's published, take it, take it from our website, talked about somebody who has already done that, if you need experience. And that brings me back to my, or brings me to my final point. This is something where exchange with peers, with peer organizations, bypassing us is important.
And this is, there is a forum for that, and that's the EIC in Munich in May, where in Munich, in Berlin, it has been in Munich for years, but going back to Berlin, that shows you how long I'm with the company. So yeah, but of course, in Berlin at Alexanderplatz, there will be the EIC where it's a great opportunity to meet peers and talk about experiences without vendors, without analysts, without consultants to talk to them and to exchange there. But if you want to, you can talk to advisors, you can talk to Rainer. We are there.
Charlie, you can reach out to us, where we are easy to find. It's usually the initials of the name at cupingercall.com. If you have a question to me, to Rainer, to Charlie, all the other colleagues, just reach out to us. We are happy to answer. And if you have immediate questions to this episode, and you're watching this on YouTube, leave your questions in the comments section below this video, and there should be reply channels in every platform that you're using to consume this little podcast. Thank you very much, Rainer.
Thank you very much, Charlie, for sharing your predictions for 2026 when it comes to what do we see or what do we expect when it comes to advisory with end-user organizations. And I'm really looking forward to having you both again here.
Rainer, it was your first time. Charlie, it was not your first time. And I think having an advisor or many advisors in this podcast as well just adds some flavor.
So again, thank you very much, and see you soon. Bye-bye. Thank you. Bye. Thank you. Bye-bye.