Thank you. I'm very excited always to speak about Converged Security Systems. I come from the background on the end client side. I believe I have quite experience in hyper-converged security systems. We're going to focus today, it's a large topic, mainly on IT platforms in convergence with physical security technology solutions. Why this is important? I believe we need to work together and there are plenty of governance challenges you'll see in terms of security perimeter. We have two silos not talking to each other. It's quite interesting. I even wrote the last two years, two publications.
One is in the legislative frameworks within the EU and another one is in the findings on governance challenges in hyper-converged environments. There is no blueprint for convergence, but I'm going to give you some angles and experience what I've found and what I work with my hands on delivering those kind of systems. Everything is around strategy here. So we need to have security strategy brain involved. Without further ado, I always like to talk too much. Let's introduce, pretty much we all hear mainly IT. But let's see what is converged security. There are plenty of definitions.
My favorite one is converged security is adaptive security following security by design principle. I believe it says a lot. It gives you the flexibility.
Again, being open but focusing on the case scenario, even if it's a site or it's an organization, always the same approach. Seamlessly integration of any systems. Talking about not only physical and IT side. Operational technology and IoT.
Okay, first things first. In IT, we have a nice definition that risk is vulnerability times threat. You all know that. I like this one. Because in this equation we have assets. What happens on the IT side, pretty much we have endpoint security. We all communicate same language. So we have the visibility of the assets.
Yeah, pretty much. On the IoT side and physical security solution, we are pretty much blind. Believe me, 90%. How are we going to deal with the risk?
27K ISO, it's not relevant here. Okay, by the way, all those tables you can find on my LinkedIn profile, three books, my academic publications, both of them. And you have the opportunity with some new of them for my post-doctorate. So those are all findings. We gather around numbers and then we discuss. So those are regulatives within the Europe. I'm sure that you're confused which one. And NIS2 is very popular today.
Oh, we need to comply with NIS2. Are we? I always say like maybe follow DORA. DORA is more something like GDPR. You have to. But pick which one fits for you. We have to understand them. And I hope this table is making this like the impact of each one of them is either high and medium. Just to clarify which one is, let's say, more important. I told you my frustration went so high that I wrote a book around governance challenges. Different streams not speaking with each other. I have this every day, all day. Pursuing each other to speak in the same language.
Everyone has their own products, priorities, objectives. I think the leadership needs to leverage this properly. There needs to be vertical. I come from the big enterprise where there is a matrix organization, lots of democracy. And this is a real struggle. Keeping those silos approach, it's not an option in any security organization. Why? Because we have evolving threats today. It's just taking those quantum computers which are coming and employing them with smarter and smarter AI behind. We don't have to be hackers. I can use a computer for that. And attacks are evolving so much.
So we need to work together. That's our obligation. It's not about IT perimeter security only or physical security. I don't care about your systems.
No, we have to work together. Let's see more about challenges. What challenges? Not fluffy words. As we mentioned, regulatory compliance. Which one fits to my organization? Doesn't have to be a big enterprise. Small organization. And this is an explanation of which one of them. So you can inform yourself a little bit later on if you want. So first is regulatory framework. Let me just stop for a second before I go to another slide. If you employ me, I will ask you, okay, what is your business resilience?
You say, okay, I have this and that. Okay, what is your security posture like real business resilience of your total environment? Pretty much every client says, well, I'm following ISMS, ISO 27K. That's fine. Okay. So what is your most valuable asset? I had an answer, my wife. That's great. Congratulations. Maybe let's focus on data. Yeah. But the data is everywhere. Everything is data. Yeah.
In IT, we know what our data, what are we exchanging. And physical security and operational technology, those are also data. But we also have a piece of paper. Yeah. Always like to highlight ISMS is 90% of cybersecurity, potentially 10% everything else. So this is how we're going to pick a right framework. Business resilience, defining the risk, defining risk controls, then procedures, then compliance. Not compliance first. Changing the organizational culture. It's about the leadership to make this happen. If we keep those silos, no communication, we're going to have this.
And everything is above 60%. Those are challenges. This is not a positive side of the story. Just to give you some insight. We know we have discrepancies between physical and cybersecurity. I can talk forever. So I will give you an example. Because they're hands-on in IT and physical security systems. CCTV system, as we know, usually this device in the middle, it can be a digital NVR. It's a video recorder. It's a video management system. It hides a camera, which is an IP camera. And you cannot monitor them.
So again, we are blind with the assets. How are we going to define the risk of those assets? Those cameras can be edge cameras with AI functionality. So we're breaching data privacy laws, frameworks, and direct exposure to the Internet. So vulnerability times threat. On the IT side, pretty much everything is organized. We have some freelance, we have segregation, DMZs and stuff. So if we understand the technologies and system as a system, not like a smoke. Even in physical security, oh, I'm focused on the CCTV because it's important. I want to have AI and I want to check this and that.
What about electronic access control? Terminology around that is not clear on both streams and within the industry. Understanding and then discussing about technology. Before we go here, we need to agree, define functional requirement.
Okay, who is going to define functional requirement in total group security? Well, group security.
Okay, I need a perimeter security in this area. How are we going to connect it? What kind of technology? It's going to be IT department, yeah? Somebody like me, yeah? With knowledge of this and that. Then we pick a right solution and then we comply with the framework. You have to test all this.
2022, the last one is 2024. Sorry, I don't have this information, of course. 67% of the integration challenges, 63. So it's getting less because we are trying to adapt, especially if you have a budget and we have the environment where I come from, so we can try and test. So we are doing testing in this interoperability because we can do it, but not every organization can do the same. So those are difficulties that are still present. I believe security is something we have to really, really focus. It's quite interesting within both industries. And those are challenges we have illustration.
You see how we can benefit if we get there, yeah? When we ask for the budget, I am showing this to my leadership because I have companies behind that, yeah?
I say, okay, if we achieve that level, if we go with this strategy, in two years' time, we're going to have those numbers. Oh, I get the money. So I can play. And I showed with my last pilot, which was very successful in electronic access control, 67% of TCO, just 70% of the whole technology system to convert security. This is a lot. And then they say, why are we wasting 67% only in one part of the whole system? So this is a bottleneck potentially.
Okay, I'm fine. So, again, first we have to know our assets, our technologies. Then we can define the risk. Then we dance around this risk.
Okay, controls, procedures. Security first mindset. It refers to both streams.
Again, I'm IT, I don't care about physical access control or video surveillance and vice versa. Well, I covered the entrance, anything in IT side, it's not my problem. I know everything is important. I had discussion today as much as I could with some of the vendors. And I asked them, how can you seamlessly integrate all the systems? Because you all here sits on the IT side. Everything is known. When I ask you, can you give me an end-to-end solution? Because if I get to the data center server room, I can do whatever I want, yeah? I'm capable.
If you stop me at the beginning, this is a seamlessly integration with security first mindset of total security. How leadership can help in security governance? And this is so exclusive, yeah? I'm doing a third research on this one. This is an objective high level for you as a leader. Potentially, this is an idea of creating high level objectives, yeah? Metrics and target competition. I did it. I did it in even less time, yeah? So everything is possible. Zero money, believe me, zero money. Just people employed within the organization. We're just doing our work, yeah? So it's achievable.
Yeah, a little bit of expenses on the travels. I'm sure we're aware of that, yeah? It's a continuous cycle. For example, for project management, we have to fail fast. I like this.
Fail fast, learn, post-mortem, repeat. It is hard. It bruises your ego. But that's the only way you will succeed. Training awareness, I cannot stress around that. So it's not only that part. An implementation cost is medium, for example, here. But you see, regular communication, how much it costs you?
Low, I would say zero. Just have one week meeting of cross-skilled team, cross-organizational stream, but satisfaction is 85%. Amazing. All of those numbers are really high.
Again, this is a teaser for my leadership, and it's working. Those numbers are real, yeah? There is also effectiveness rating. All of them pretty much high. And then we will have executive sponsorship also high, yeah? If you achieve all of that. Start with the collaboration. And the last one, I'm sure we are aware that we have to embrace advanced technologies, but in an appropriate way.
Again, example, I want an AI camera. I always say, okay, what is your function requirement? What do you want to achieve?
Well, I don't want that people are crossing the forklift line where it's not allowed. I said, okay, what about data security governance following GDPR? You have to blow the face. This is how you're going to embrace appropriate technology, yeah? I can talk forever around this one, yeah? So your case scenario is health and safety, because you don't want people to get hurt. And that's the main idea, not following people with AI and breaching some union rules. So embracing advanced technology, yes. Thinking about it. Piloting a lot.
Improvements, if we get there, in unified governance structure, we are going to achieve, again, high numbers. Overall security push is going to be amazing. Please check all those numbers with the relevant information in the books or contact me. Importance of interdepartmental collaboration between the silos or between the department, even within the IT. We struggle with our colleagues, even on the same floor where I work. It's hard to catch some people.
Again, regular communication, same table, yeah? I would like to highlight once again this one. This is also something which is nice for leadership to show them, yeah? Downtown reduction, not only IT side, yeah? A converged situation. 10% before convergence, after 3%. In the big organization where we take care of this and we pay a lot of money for that, we can save a lot of money. Just by changing mindset in your organization, not paying the companies to have this, yeah? Improvement is 70%. Maintenance cost, 30%.
I would say even higher, but this is finding from interviewing stakeholders within the Europe. Energy efficiency. It's at its most time a data analytics utilization. If this is your source of true, and you have 113% of improvements. And this is the last slide. Always being proactive.
Again, fail fast. This is my approach, yeah?
Try, fail, get up, move on, yeah? Change yourself. We have to constantly change ourselves. If I have a rank, it doesn't mean that I'm the smartest guy in the room, yeah?
Be humble, ask somebody else, and then brainstorm. Only together we can achieve great goals. So this is it for me. We have a minute and a half if you want to ask some questions.
If not, we can do it later. Thank you very much, Vladimir. Thank you. Thank you very much. Just a quick reminder, if anybody has a question, please raise your hand. You will get the microphone. I have a silly question of my own, if I may.
Yeah, no silly questions. Maybe I'm biased because I come from IT background, but isn't it like the natural course in the future, IT security basically organically replace all the physical security controls? It's not. I had a discussion today about credentials and this terminology which I'm employing. Because we have focus on the IT side, yeah? On physical security, we're still using those cards, yeah? Within the factory where I work, we have to use the cards because of visibility. In all oil industry, if you don't have a card, the guy is allowed to shoot you even on the rig oil, yeah?
Believe me, that's the case. So we have to embrace legacy systems.
Yes, making them closer to work seamlessly within the IT advancement, yeah? Embracing new technology. It is a hard task. There is no blueprint for that. But never escape and say, okay, I'm going to scrap this. Even I have a lot of money, I'm going to employ something which is closer to the IT. It's never 100% success, yeah? Please always think about the hard way, how we can embrace what we have, yeah? Like having a good child and then maybe a little bit naughty child. You love them both, yeah? You have to embrace both of them and work together with both of them.
This one is not going to change probably, yeah? Maybe this one is going to get worse. But it is about governance, yeah? Maybe replace the bad one with a robot.