Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts. We want to talk about CIAM. And for I have invited my dear colleague, John Tolbert, hailing from Seattle.
Hi, John. Hello, Matthias. Good to see you again. Good to have you again. It's been a while. Last time we talked about security practices for everyday life. Now we're back to your research. And you have just completed and published a leadership compass, a market segment analysis for CIAM. And this is a we are following this from the advisory perspective as well. But if we go to the mere basics, CIAM, IAM is Clear Identity and Access Management. But what does C stand for in that context? And that seems like a simple question, but it isn't, right?
Yeah, you're right. It is a bit more of a complex question than you might think so at first. So we've been covering CIAM as its own market for about 10 years now, probably about seven different leadership compass reports over those 10 years. And it has changed significantly. In the beginning, we started with calling it Customer Identity and Access Management. And I used to say that the C stood for customer, which can be, you know, a business-to-business customer or a consumer, someone who's, say, engaging with an online retail site.
And then as the years progressed, we also included G2C, or government-to-citizen interactions, because many of them are intermediated by CIAM solutions, too. But this time, you know, we have seen enough of a shift in the overall CIAM market with the big C to justify breaking this into two different markets. So this time, I'm calling this Consumer Identity and Access Management.
And it's really focused on use cases involving, you know, sites that do work with thousands, hundreds of thousands, millions, or in some cases, even billions of consumer identities for both e-commerce or lots of different use cases. But it's really not addressing the B2B CIAM use cases, because we're going to quickly follow this up with a special report just on B2B CIAM use cases. Exactly. And I know somebody who has asked for that quite a while, me, because I think this is really a different type of market.
And especially when you talk to larger end-user companies, they are doing business in all areas, including the B2B CIAM or B2B CIAM segment. And this is something that we deal with in real life all the time. But this is for another episode. If we go back to the mass volume consumer business, and it's been a while since the last edition has been published. So what are new developments, new requirements that have been emerging since you last covered that market?
Well, you know, a lot of the basic requirements, of course, remain the same, but we see an increased emphasis on integrations and interoperability with different kinds of third-party platforms. Examples of that might be customer data platforms, which are designed to pull in information from many different sources, CIM systems being one of those, but also CRM systems, or CRM systems too, should be able to integrate with CIM systems. There's increasingly interest in having built-in integration with chatbots, AI-powered chatbots, to help with customer service functions.
Some solutions have integrations with payment service providers, just to make it easier for other customers or customer prospects to connect to payment services. There are third-party consent and privacy management solutions that you can integrate your CIM solution with if you feel like your own CIM solution does not have sufficient consent and privacy management capabilities.
Of course, this is probably very relevant in jurisdictions like the EU or places where you have stringent privacy regulations. So yeah, we see much more emphasis on integrations out of the box. And you can look at this field, CIM, that is, in many different ways. There are turnkey solutions, which are kind of what they sound like. You sign up with a service and you just start using it. There are other developer-first types of solutions where there's an expectation that the customer will do some amount of custom coding to integrate it with their own applications or other directories.
So being able to have connectors for these different services can make it quite a bit easier for a customer to get going and integrate with different kinds of applications. Probably the biggest thing, and this is not going to surprise anybody, but one of the biggest requirements now is, what do you do with AI in this? I think about, if I recall correctly, maybe five or six of the nearly 25 solutions that we surveyed have some capabilities with regard to being able to distinguish and register and track AI agents that are operating on behalf of consumers.
So I expect that area will continue to grow significantly over the next couple of years. And I think from what you've just explained with these integrations being in place, I hope and I think that this narrows the overall definition of CIM so that you can say, this is CIM and this is what it does very well. Authentication, authorization, progressive profiling and many functionalities that previously have been included in these solutions because they just packaged it with that.
Consent management or analytics, business intelligence, that is more moving towards integrations to have a proper platform approach with the right connections to the right systems. Do I get that right, or is this still all included if you want it?
Well, you know, there are CIM solutions that do have really good consent and privacy management features built in. And for a lot of organizations, probably what is available in the CIM solution is sufficient for their needs. But there might be others that operate across many different jurisdictions, have lots of different regulations they have to contend with. And for that, having an out-of-the-box integration for a third-party CPM solution would probably be very helpful to them. Right.
When it comes to using these systems, and usually when we are talking about solutions and especially in the cybersecurity area, where there's a limited amount of users, but we are all, if we are technical or not, users of CIM systems because we are using these platforms for logging into our favorite retailer into, I have to mention that, Amazon or even Netflix or something like that, where all this is built into this. So we are all the harshest critics of these systems sometimes. What are your top findings when you look at the market as of today? What has changed? What has improved?
What is new? I was pleasantly surprised to see that Passkey authentication is accepted by, I counted, about 88% of the vendors that I looked at. So that's wonderful. That means just about every solution out there can accept Passkeys as authentication. And I like Passkeys for all the same reasons that most people do. They're the other methods that are out there.
But yes, speaking as a consumer, I myself find that I get frustrated because there are not nearly as many sites that offer it, which also leads to the question, well, why not? Why aren't they offering Passkey authentication if they are using one of these modern solutions that we've reviewed? Other requirements that we see is sort of an increasing need for identity governance and lifecycle management. Some of the largest vendors here will say that they have, you know, multiple billions of identities under management.
So you will see that very, very large sites probably have untold numbers of abandoned accounts. And abandoned accounts, first of all, take up space, but they're also a risk.
You know, an account that could be potentially compromised and used for fraud or some other malicious means. So identity lifecycle governance has become a much stronger requirement, especially on the consumer side, you know, which leads to a discussion about account recovery. So I think we've all learned over the last couple of years that the account recovery process itself is highly targeted in both, let's say, insider IAM fraud or risk cases as well as consumer fraud.
So being able to have really good account recovery processes that could do identity verification in order to get access to the account again, I think is, we're only going to see the need for that rise. And something else we're beginning to talk about too, just like we've been talking about continuous authentication for years, where we're evaluating factors like device intelligence and maybe behavioral biometrics, just to kind of constantly make sure that the user is who they purport to be.
I think we need to start thinking about continuous identity assurance too, and how to implement that as a way to help with not only account recovery, but just in general, increasing security posture for consumers. Right. And the other thing you want to mention? Kind of going along with that built-in identity verification services, we see quite a few of the vendors now offering at least some level of identity verification out of the box, or if not, they will have connectors for several of the very many third-party identity verification services out there.
And that too, I think is very useful for organizational customers of CIM solutions to be able to get up and running quickly and say, okay, yes, I do need to have a higher identity assurance level, and here's the service that my CIM solution provides. And hopefully that's good enough for a lot of them.
If not, then yeah, there may be some custom coding to integrate other identity verification services. Right. And if you look at runtime, you've mentioned already that you're looking at continuous authentication at constant checks and in-session governance to understand, yeah, that this is still Matthias who is using this account. Does this also lap over to device intelligence to understand, yeah, this is Matthias and he has been using this device for quite a while and it's unchanged and it's not jailbroken or whatever? Is this something that is available as a service?
It is built into many of the CIM solutions that are out there today. Yeah, I would think that's a very highly desirable requirement if you're looking for a CIM solution, especially the device intelligence. Behavioral biometrics, you know, how you interact with your computer or your phone, that's not as common, but it's definitely another risk signal that could be used. But those two can certainly help reduce account takeovers. Right. When we look at other devices, depending on the service provided, the association of IoT device, is this something that is more common right now?
Yeah, that's been there for a while. IoT device identity management is still a pretty key requirement for many organizations. We have lots of different kinds of IoT devices we interact with as consumers, everything from home electronics to smart thermostats and smart lights and things like that.
And yes, we do want to be able to control those and use our favorite ID from our favorite identity provider to do so. And having a really good experience built into the CIM solution that enables that, I think is a big plus for organizations that are looking for that. So some will merely offer API level connectivity for you to build your own self-service user interface for that. Others have some pre-constructed and extensible user self-service portals that can be used for controlling those kinds of devices. So this report has been published already, so it's available.
So if you are interested as the audience in learning more about consumer identity and access management and the state of the art there, just head over to cupingacol.com and have a look at this document. So it should be easy to find. It's the latest Leadership Compass and it's about CIM. Before we close down, John, any final detail that struck you when you did the analysis? I'm still struggling with the AI agent stuff. I don't know what I would tell an agent to do on Amazon for me, but maybe I'm not thinking hard enough. What are the key facts that you took home from this research?
I would say that the most commonly cited example of AI agents acting for consumers are the travel agent AI agents. You configure your agent to be interested in looking for flights to a given city. You prefer window seats if you like to leave at this time of the day, and you empower it to buy the lowest fare that meets all your requirements.
I think that's an interesting example, but of course they could be problematic if not configured properly, that's true, but they're also AI agent-powered financial applications, so I think it's going to be very, very important for those who are deploying those kinds of AI agents to be very careful in how do you go about authenticating, of course, the user before they configure it, but how do you authenticate, so to speak, the agent and how do you authorize what the agent can do, and at what point do you want to bring the human back into the loop to do an authorization for, let's say, a very high-value transaction.
I think there is a lot of work that needs to be done to ensure that this doesn't greatly increase fraud or just general errors that lead to loss. Yeah, that was also my fear a bit, do I really trust that agent, but this is a general topic that we're just discussing in the industry anyways, how far can we trust the agent and how can we tell the agent what our intent is and that it pursues it in the platform.
I think that's an interesting part, but anyway, it will not go away, so we have to be prepared for that, we have to govern that and have to make sure that we have the human in the loop or just to kill the agent if things go wrong, and so I think the agent governance is also an important part. Thank you, John, for telling us about this new research about CIM. This is a really heavily changing market. Maybe we pick up with the B2B topic in an upcoming episode because this is shortly before being finished and published as well, and that is the different angle that we should have a look at as well.
So, thank you, John. I'm looking forward to having you then again soon and bye-bye. Thank you. you