Thank you. You're already like 25 seconds late, and as a German, it's just like unacceptable. So everybody just sit down, relax, let's talk about clear skies. What happens if the cloud is no more unavailable? My name is Ingo Schubert. I'm the field CTO for the international region for RSA. I've been at RSA now for 23 years, and I've seen some outages, both at customers and at RSA. So like probably most of you as well, outages are, of course, not good, but they do happen. Any outage is bad, right? If a single system is no longer available, yeah, I mean, help desk is busier than usual.
People complain, they cannot really do what they want to do. And it will cost some money, but yeah, you'll probably survive, right? The problem comes when multiple systems suddenly become unavailable. The help desk will be super busy, or maybe actually the help desk has an outage as well. In this case, that gets really interesting. And the employees probably cannot do any work. You're losing money a lot, and the survival of the organization is in question. Well probably with the exception of your government, right? But like if you're a private company, survival might be actually in question.
So and one thing to keep in mind when we talk about disaster recovery, business continuity, recovery from a disaster is not business as usual. It's a disaster, right? So things are chaotic, even if you have a plan, right? So just keep that in mind. So the goal should be that the organization survives as long as possible, of course. Recovering from a disaster may include reduced features, reduced performance, reduced usability. But the point is that the lights may be dimmed, but there will be light. That's the whole point.
I think we also sometimes, you know, engineers is like, oh, it has to work, you know, a hundred percent or nothing. This is more like, yeah, you know, we have to make a compromise here. It's a freaking disaster. So things do not work as usual. So there will be some consequences there. So the light will be dimmed. Now let's look at this from an IEM point of view.
Many, many providers out there that provide cloud-based IEM solutions. RSA is one of them. And it's becoming more popular. It doesn't matter which part of IEM. It could be MFA, it could be identity governance and lifecycle. It doesn't really matter, and lots of others. So this has advantages for customers. Let's just be clear. There's a reason why they're cloud services.
Of course, the advantages for the vendors as well. I'm not denying that, but for the customers, there are advantages. So operating in IEM or any infrastructure takes know-how, it takes money. And especially in terms of security, the SaaS providers often can do a better job at providing secure environment than their customers can. Not you. You are all great. You can definitely run a secure infrastructure way better than anybody else. But judging from what I've seen at some of our customers, that's not always the case. Let's just be clear.
So they have problems keeping up to date with patches and all this. So the vendors probably can do a better job there. So you have the usual benefits. You don't have, as I said, don't worry about patches, features just show up magically on Monday morning. So that's great, clear advantage. But what is your plan if things do not work out as you think? If there is an outage. Now I think we as an industry, we can also learn from other industries like aviation. If there's a problem while the airplane is in the air, they do have plans.
Trust me, they have plenty of plans and checklists. The checklists are used and there are three priorities.
Aviate, navigate, communicate. So if there's a problem with the airplane, the first thing is keep the airplane in the air. That's priority number one. Right? Priority number two, if priority number one is fine, point the airplane to where I want to be. Right? And point three is communicate. Tell air traffic control what's going on. Tell the passengers what's going on. There will be no more coffee, for example. And this structure should be, of course, also in IT and IT security, but often, quite frankly, is not where it's supposed to be. Classical risk management.
And of course, everybody in this room, yeah, I know you do it perfectly, right? But again, judging from what I've seen, the customer is not always the case. Right? So you should have a plan and say, like, what can happen? Anticipate what can go wrong. You should have a plan and have that plan available and up to date. Right? It doesn't really make a lot of sense if you have a disaster recovery plan and that's on SharePoint and SharePoint is offline. Yeah. Doesn't make a lot of sense to have a printout somewhere and the printout is five years old, all those things.
Classical risk management and disaster recovery. Train people to follow the plan. Might be important to let them know what they actually need to do. And of course, have the right architecture and technology in place to actually help you with all that.
Now, this seems like, thank you, Captain Obvious, this should be clear, but for some, apparently, this is still like, yeah, I need to do that. But now when you think about regulations like NIST 2 and DORA, they force now many to look into this again in much more detail. Let's switch to the interactive part of this presentation. Who actually has some NIST 2 or DORA customers or is a NIST 2 or DORA customer on your own? Hands up. Who has to do with NIST 2, DORA?
If you didn't put your hand up, we check your answer because if you look at the NIST 2 list of industries which are affected, it's probably easy to say who's not affected by NIST 2. So re-evaluate your answer there. So how does it look for identity governance and administration? So let's assume you have an IM solution consumed from the client. What happens if your IGA solution is no longer available? Well exit reviews and reports are no longer available, obviously. Now you have a disaster. Remember we are in a disaster scenario.
So you probably have better things to do than doing an access review. If you happen to have an auditor knocking at the door, you probably can tell the auditor, you know what, you wait. In worst case scenarios, they get reports which are a couple of days old or so. Access requests are also no longer possible. The fulfillment, so somebody wanting a new account, having more access rights, no longer there because that's in the cloud. But you know, you could do that manually. I know we shouldn't, but again, this is a disaster, right? So you want to keep things running. So you can do that manually.
And once the IGA solution is back online, you can reconsolidate all that and clean everything up. So in the end, the IGA is probably not on the critical path. If the IGA solution from the cloud is not available, probably inconvenience, but not the end of the world.
Of course, if the outage is weeks long or so, it may become a problem, right? But at least in the short and medium term run, probably fine. Different with MFA, right? So let's assume we have an MFA solution from a cloud provider, doesn't matter which cloud provider.
Yes, it could be RSA. So everything I say now applies to RSA, but applies to everybody else as well, right? So if the cloud-based MFA is down, that is an issue because you are a good security architect. And of course, integrated everything into MFA, because that's the way to do it. You want to secure everything. So with one outage, potentially, everything is also out, right? And that is an issue, right? Now why can that be an outage? It could be a true outage. I would call that, you know, the MFA cloud provider has an outage. Yeah. I don't know, code update went wrong or something else.
It could be that the cloud provider that the MFA cloud provider uses, because often they actually rely on Azure AWS, GCP or whatnot, they have an outage. Does happen, right? And it's like, yeah, but we can handle that. They probably have multiple locations and all that, you know, they should take care about the availability. And that's right. But there are more reasons why that could be an outage. The connection from you to the cloud could be somehow interrupted. Could be an excavator ripping out the fiber optic cables. Could be an anchor dragging along the Baltic Sea.
Plenty of reasons where the connection to the cloud is suddenly unavailable. So that means the cloud is unavailable.
The cloud, of course, is still there, but for you, it's just not available. Or there could be, you suddenly have a really an urge to mistrust the MFA provider for whatever reason. Maybe that MFA provider got breached. Maybe for any other reason, you should suddenly say, I don't trust those guys anymore.
And yes, I'm fully aware that I'm here from RSA and American MFA provider, right? I'm fully aware of that, what I'm saying right now. But you have to ask yourself that question, right? That's what I'm saying. So that's the truth. The thing is that potentially all your applications are suddenly becoming unavailable. Other cloud applications, on-premise applications, and whatnot. But the thing is, it's not just about availability. It's also a security issue. Because you might be thinking, ah, you know what, if MFA is unavailable, I just go like, you know what? Passwords are enough.
It's a disaster, right? So I just want to keep things going. So I somehow magically, if that's even possible at all, you switch to passwords only. Thing is that attackers can take advantage of that outage. Maybe even they caused the outage. Maybe they just made it look like the cloud providers offline. And you go into this panic mode and say, you know what? Passwords are fine. And that is an issue, because they can and they will take advantage of this. Think about an outage also as a disaster in general, as a perfect time for attackers. Because everybody's super stressed.
I mean, everybody's super stressed normally. But this is taking it to a whole new level. This is turning it all the way up to 11. And attackers love this, because they can do stuff and it goes undetected, because there's so much noise and so much panic all around. They can do that. So they can take advantage of that. So keeping everything secure, even during a disaster, is critical.
Again, because either the attackers say, hey, great disaster, I can take advantage of that. Or they even cause this to distract for things. So the cloud is perfect until it's not, essentially. So your plan should not be, ah, it's the cloud and we'll be up again eventually. So you pray to your favorite entity there and say, we'll be up tomorrow, in an hour. But that's not an acceptable answer. It's not something that doing a NIST 2 audit or anything else, DORA, that is an acceptable answer. It shouldn't be. By the way, it shouldn't just be because of NIST 2 or DORA, just proper risk management.
That shouldn't be a good answer at all. You should have a better plan.
So having, you can say, in this case, I'll just do some on-premise MFA capabilities. Easy, right?
Yeah, good thinking. That's a good plan. Keep the lights on for a couple of users. Securely recover. That's important. But having a completely separate MFA solution on-premise, this might not be the right idea. First of all, you end up with two things, cloud and on-premise. And you have to deal with all of this. So all the workflows, everything around it, which makes MFA MFA, it's just not a single authentication method. It's all those things around it. Enrollment, recovery workflows, integration applications, and all of that. But often you struggle to manage that with one system.
Now you have to do it with two systems. And if you have an outage, it's often not just a couple of users that need to worry about that. You have to do a lot of users. So you end up with things that don't really work, right? Either because of cost or because of technical reasons, you cannot do that. So you go hybrid it is then. That would be what I would say. In a true hybrid world, you have things that basically run cloud and on-premise. And if the cloud is no longer, the on-premise part just keeps on ticking, right?
Now the advantage of that is you don't have to worry about users enrolling into multiple MFA solutions, all the recovery and enrollment workflows, the integration to applications. You just have to worry about that once and the failover is handled for you by the system. And this is where the product pitch comes, RSA ID plus does that, right? So in a normal scenario, this is how it works, right? So you have the cloud, you have the on-premise part and the laser doesn't work. So usually then it goes through the on-premise part to the cloud. Everything is happy.
You can do all the cool cloud things and take advantage of those. And then this happens. Cloud is no more for whatever reason. And then the on-premise part just keeps on ticking. And everything that's created into this one just works.
And yes, it will be different, but secure. Because all those cool things like, you know, I can do biometrics or push to approve for those things, they don't work because they have some cloud communication somewhere. But good old OTP, that keeps on working, right?
And this, yes, is absolutely not an AI-generated picture. That guy has five fingers plus a thumb, that's obvious. So OTP it is. Now OTP is like, yeah, OTP is dying.
It's like, yeah, I'm not quite sure, right? Yes, FIDO is a fantastic authentication method.
And man, there are some issues to have with the FIDO lines currently where they're going, especially with SyncPath keys. But nevertheless, you know, there are users of OTP which will stick around. So if you have a hybrid, the enrollment of your users can also be done on-premise. So if the outage is long and you have new users, they can all be done on-premise just fine. And then later, everything will be cloud-based again if the cloud is online. But of course, this actually goes beyond just, hey, like I need to keep certain servers up and running.
It could be that some are then completely offline. Of course, your notebook or so, that's something that's offline once in a while. But what about all those other Unix and Linux servers that are out there and that you need during the recovery process? They can actually have completely offline modes and can, of course, then be used to authenticate users securely with OTP. So workstation servers and whatnot. So what should you take away from this session? Don't be afraid to ask the question, what happens if the IAM cloud, whatever that might be, is offline?
Well maybe you should be afraid, depending on what the answer is. But the point is, you need to ask that question. Or your customers, if you're an integrator, need to ask that question. And that is either just proper, boring, decades-old risk management, which forces you to ask that question. Or it might be now, fresh out, the NIST 2.0 regulations, so various cyber-resilient regulations around the world. They force you to ask questions. What happens if certain parts of the infrastructure become unavailable? And then you need to have a plan. You need to have an answer.
And that, especially for things like MFA, is probably not the answer. It's like, I'll just wait. So prepare for the scenario. There are ways to prepare.
Now yes, RSA is a technology to help with that one. I'm not saying it's the only thing out there, but I'm saying it's a pretty good one. And with that, I thank you.