Compliance with frameworks like NIS2 and ISO 27001 is a challenge for organizations, especially as cyber threats and regulatory demands intensify. Maintaining robust cyber hygiene is complex and costly, particularly when onboarding third parties.
Modern Privileged Access Management (PAM) systems, powered by artificial intelligence, offer a way forward. By automating compliance processes and integrating intelligent threat detection, these solutions streamline security workflows, lowering the total cost of ownership.
Paul Fisher, Lead Analyst at KuppingerCole will provide a strategic overview of how AI-powered PAM addresses key compliance requirements. He will highlight critical parts of NIS2 and ISO 27001 and explain how automation and analytics can help mitigate risks and support regulatory alignment.
Stefan Rabben, Sales Director DACH at Fudo Security will demonstrate how Fudo Enterprise Intelligent PAM and its new ShareAccess product solve real-world challenges. He will showcase how these solutions enable seamless third-party onboarding, ensure continuous compliance, and deliver significant cost savings through automation.
Good afternoon, good evening, good day, and welcome to webinar with me, Paul Fisher, Lead Analyst for KuppingerCole, and I would today be joined by Stefan Rabben from Fudo, and we'll be talking about the next generation of PAM and what it can do for you from compliance to cost savings. So that's where we're going. We have a number of housekeeping. You don't need to if you're watching, listening, just listen and relax.
We'll do a couple of polls during the webinar and discuss the results at the end, and there will be more time for Q&A at the end where you can enter your own questions into the live storm control panel you should see in front of you. And finally, we are recording this, so if any of your colleagues wish to listen to it or if you wish to listen to it again, you can do so, and that will be available on the KuppingerCole website in a few days. So the agenda is pretty simple.
First, I'm talking, then Stefan is talking, and then you can talk through the medium of the control panel. But before we start with that, let's have a quick, quick poll which you can do in the background. So talking about your own organization, what were the key focus for cybersecurity investment over the past 12 months, was it identity and access management solutions, was it threat detection and security analysis, was it cloud security stroke cloud infrastructure entitlement management, very typical product subject, and or just privileged access management itself.
So one, two, three, four, IAM solutions, threat detection, security analysis, cloud security, Kim or Pam. So we'll leave that running and you can vote. So what do we want to talk about? Traditional Pam. Pam has always been seen as a relatively unglamorous, very rather static product that is reactive and has not really contributed that much towards compliance in as much that it was reactive, it was checklist driven, it made audits and attestation cycles expensive. It also wasn't very good or isn't very good with multi-cloud and hybrid environments, which we now see everywhere.
And it was often seen by organizations as a sunk cost just to meet regulations. So it wasn't really monitored, but it was most of all just seen as a literally like a ticker. So it was actually seen as not a value creator, but a cost and something that you have to have to meet compliance. No one really thought about how Pam could be used to create value, how Pam could be used to tell you a lot more about your organization rather than just whether you were keeping privileged accounts safe. So that's sort of where it comes from. So let's like rethink this a little.
Let's think about where Pam could be. And of course, Pam is changing everywhere right now, not just for compliance purposes, but Pam is becoming the thing you need for almost every identity in the organization. And you need it for machine identities too. And you need those identities to be tracked. And quite often now, what we consider privilege is not just traditional, this identity has access to an admin account or this access, this account has access to certain data, but it can be stuff that is needed just on time.
It can be data, it can be credentials, it can be stuff in the cloud, it can be developers, it can be third parties. And of course, it can be identities which are no longer human. We categorize them all as machine identities. And then we find now we're on the cusp of a world potentially of organized chaos or just simply chaos where agents created by AI will also start creating identities and will have access to stuff that you have in your cloud.
And already, even now, without AI or without machines creating identities, we have human owners of multiple identities, almost like multiple personalities, but an individual will set up different identities for different things, but they will feed back to that one person, which of course is a risk. So that's what PAM is there at the moment to try and stop that situation that, well, picture has changed. But PAM isn't, we all see, just about stopping hackers.
It's about enabling safe operations, but it's also ways to unlock productivity and reduce waste, which you'll see later in Stefan's presentation, that we can do a lot more with privilege access than simply try and stop bad guys. And we can do this against the new backdrop that I've been just talking about of multiple identities, multiple types of identities, and identities accessing cloud, multi-cloud, your resources from all sorts of different places. So key to that is, of course, our friend, artificial intelligence.
Now, people often talk about AI in negative terms. People are worried that it's, you know, taking jobs, that it'll take over the world, et cetera.
Now, the thing is, for me, AI is either over-hyped or under-hyped. It's over-hyped in that people say it's going to take over, and it's under-hyped when people say, well, it's not really that great. The fact is that AI right now, as an assistant, is fantastic, and it's actually going to allow us to get more out of our IT, more out of our organizations than less.
We're a long way from individuals, I think, being replaced because what it does do in this world is allow mundane activities or routine activities such as doing compliance checks, et cetera, to be done automatically so the human operative can concentrate on much more important, much more creative, in an enterprise term, more creative things that will add value to the business. And so if we take PAM, as it is, and then add AI, it suddenly brings context. It brings prediction.
And also, crucially, it could bring dynamic policy and role enforcement, which is where we need to improve things, particularly in just-in-time so that when an identity requests access to, for example, a credential or requires access to a credential, it can learn an AI-driven database of roles and an AI database of policy. So it can learn from that straightaway. So effectively, doing the role of an admin who previously would have to manually go in and see where this identity is, what it is, and then say yes or no. So that's just one small example of how AI is going to help.
But there are things like it will have better ways to introduce behavior baselines. So you get fewer false positives that tell you that an identity is doing something it shouldn't, whereas, in fact, it's okay and stuff like that.
And also, you should be able to improve session monitoring so that you just don't have, which is why a lot of people ignore session recording and monitoring, because it literally just records everything, that you would be able to use AI to look at sessions, to then find trends, then find outliers, find where certain identities might have gone, why perhaps a breach occurred, or why perhaps a breach almost occurred, and so on. All that stuff should make people a lot more interested in session recording, session monitoring, than they are now, because it's such a pain.
It's such a chore to go look into it, which is why people don't bother unless there's a breach. So all of these things will start to work their way through into privilege access management and, of course, other areas of IT. So as I said, we will see cost savings, in another way of saying adding value, but through smart automation.
So as I said, you will be able to get just-in-time access, which will help us achieve the goal, the eventual goal, the ultimate goal of having zero standing privilege, and having instead always on just-in-time rather than always on privilege, because we know one of the main causes of breaches through privilege is when a identity is stolen, when hackers hijack an identity, as in the recent case with Marks and Spencers, and then use their identity's standing privilege to get into the stuff that they want, and that happens quite a lot, and that is where, you know, but if you don't stop someone ringing up the helpline and saying, I've lost my password, and then manually giving it to you, then all this is for nothing.
If there's no such thing as always on privilege, at least that would stop that a bit more. You'll probably find that there will be fewer support tickets for access risks.
In fact, there should be zero. There would also be a reduction in the audit and compliance overhead because, again, you don't have to account for all those standing privileges, and again, you can start looking at your AI augmented session recording and the reports it churns out for you, which will be able to add to your compliance reports and say, yeah, look, we're okay, and if an incident happens, there should be fast response. There should be ways of flagging something happening to human admins through AI agents and perhaps also tell you what might happen if this incident is allowed to run.
So, the second poll, take a breather. I think I need to take a breather. Which of these identity security technologies do you expect being most adopted in the next three years?
So, that's not necessarily you're going to adopt them, but the wider market. So, again, talking about PAM.
CIEM, a zero trust network architecture, which is technically is not the technology, but we threw it in there anyway. Decentralized identity and a secure browser. Zero trust, people are interested in zero trust, and it factors a lot in discussions about identity security.
So, PAM, CIEM, ZTE, decentralized identity or secure browsers, which have recently become quite fashionable in terms at least of not application, but in terms of people talking about them. But I think there is some future in that myself.
So, just to sort of wrap up about where modern PAM is going with all these AI capabilities and everything else, we'll see increasingly AI capabilities built in by vendors, not boltons. But we should see it's important that the AI is used to help reduce the human workload rather than actually being said to be doing something much more advanced than it actually is capable of. At the moment, AI can only look at what's logged. It can only make decisions on trends. It can only look at data and give you answers.
But the same, this is why it's useful for things like policies, et cetera, because it would automate yes, no answers to that. So, those vendors that go around saying that we have got AI that will take you to the moon, well, that's not true. And we will also start to see more integrations with ITA, with Kim, and of course, with SIEM, as I mentioned, S-I-E-M, AI will help drive those integrations better.
So, again, what you get out of a SIEM is a lot more useful. It's not just endless, endless numbers of dates and videos and things like that. Support for non-human or machine identities is there now.
But as we, depending on who you ask, machine identities outnumber human identities by four, up to about 10 to one. The trend is they're going to be everywhere.
And so, PAM must support machine identities or support control for machine identities. And it also should and will be usable for those parts of your organizations that work in perhaps slightly different ways to other departments, for example, developers, coders, engineers, et cetera, and who increasingly need access to privileged stuff, but really, really hate being slowed down.
So, modern PAM should give them access just in time without them even noticing that they're being given privileged access and so on. So, PAM, finally, just to wrap up, is no longer just a control.
In fact, it hasn't been just a control for some time, but it's definitely no longer going to be just seen as, that is a static everywhere you go, and only this identity has access. So, we're moving on from that. It's a lever.
So, compliance, just basic compliance, is the baseline. But AI will also make security smarter. It'll make it faster and leaner for you. And it should make it more efficient. And it shouldn't necessarily mean that anyone gets laid off because people, the one thing you always hear about cyber is that people are overworked. There's too much to do.
So, this should help. So, using forward-looking PAM, using forward-looking PAM from a forward-looking vendor should start turning what has always been really just a cost center.
Like, you didn't get much back for your money, apart from the reassurance that your privileged accounts were protected. It will turn all that into value creators. And with that, I shall hand back to Stefan. Thank you very much for listening. Thanks a lot, Paul, for this great introduction. My name is Stefan Raben. I'm the Regional Director for the DACH region, Germany, Austria, Switzerland, for the European PAM technology provider, Fudo Security.
And yes, today, I will follow on this great introduction of Paul to talk about our technology, about the security requirements, and yes, then the automation and also the usage of artificial intelligence for incident management activities. But before I really start, I would like to start with a real big statement. A security incident is always preceded by a privileged account access breach.
And you see at least the two words in red, privileged especially, because this is all about the root cause of a real successful cybersecurity incident, because you only can be successful when you are able to hitchhike to take over a privileged account. Otherwise, you may have a local phenomenon, which is not ideal for sure, but it really becomes critical when a privileged account is breached.
So, why PAM? A short summary for everyone. At the end, I think this is already well known. We want to ensure that with the control of privileged accounts, of privileged accesses, we can really close a lot of security vulnerabilities, like with the password sharing, with password rotation. You see a lot has to do with credentials. And this is also one of the main outcomes of this presentation today, to prevent attackers for identity theft. But before we go there, we will do a short first exercise for the warm-up and talk about some basics.
And this main basic is the need for the protection of privileges. Because in the basics of privileged access management, and even what Paul has already explained, at the end, we want to have identities talk to assets. We want to have a secure interaction of human, but also machine identities with any type of digital assets. And this could be really everything. This could be in the cloud, this could be on-prem, this could be applications, network components, security components, really everything.
And to have this communication really secured, and we are talking about a dynamic security, for sure we have to understand the nature of the identities, but also the nature of the assets. And to make it very simple, we can say identities are organized based on their privileges. So the options they have to do changes, to work in the organization, and also with the risk, for example, to create damages.
And therefore, we typically differentiate between administrative accounts, who have very high privileges, they can work with operating system, the network, the applications, the services, and they can create, modify, even delete. Same as the super users, who normally don't have access to the operating system or to the network, but they have typically very high privileges on applications, like super users on databases, like an SAP super user, who can do a lot of manipulating data, he could steal data. And this is also something what we have to consider when we are setting up a pump technology.
And from the asset side, we have a similar scenario. So some assets are really high risk, and other assets are low risk. And especially, we need to consider and to focus on those where the business continuity is affected, in case of a cybersecurity breach of an incident. And therefore, we have to concentrate our cybersecurity really on the high critical, high privileged accounts, and also on the high critical, on the high risk assets. So at the end, what we want to achieve, because cybersecurity is one thing, the other thing is the operative efficiency.
And this should be in a very healthy balance. Cybersecurity, what does it mean?
Yes, we can use benchmarks, like the framework, like an ISO 2701, a DORA, a NIST2, or other frameworks like an ISMS. And we also need to control the risks. For the operative efficiency, it's important to provision the technology very fast, and then also to consider the operational costs. So to have an optimized total cost of ownership, so an operational efficiency. And at the end, the objectives for such a technology, yes, that's control first. The second thing is the incident management, that we are also able to react in real time on potential detected incidents.
And this is why where pattern detection AI is getting a role. And also the documentation and the reporting of everything. So every security changes, policy changes, configuration changes, are in the same importance than the activity of each privileged user. But for today, we will focus on the incident management part. So also to have these objectives, to control the incident management and the documentation and reporting, we have to do some basic concepts. And this is even what every cybersecurity compliance framework is asking for. You need an authorization concept.
And for such an authorization concept, we have to consider a role model, which is based on the identities. So the role is the profile, the task, Paul mentioned it, zero standing privileges, that we can really assign the authorizations, the real needed privileges based on the user role, the user profile, the user organization. And on the other side, we also can consider the risk models based on the assets, what are the high risk and which are the low risk targets.
At the end, automation is the key objective that you can use the privileged access management really as a dynamic technology, which is able to provision and deprovisioning tasks automated. So in principle, what we are doing, we are identifying a user, a human or even a machine user, we are authorizing it. So what is he able to do based on his role, we can work on dynamic approvals, JIT, for example, just in time accesses. And we are able to control the session itself.
And at FUDO, we are able to use AI driven technologies to have a faster and a real time assessment and thus a reaction on potential threats. And the PAM system, and this is also important not to forget, is also able to do the credential management for the critical devices. Here we have machine created credentials with a rotation rules to make it really secure. And the idea behind is that the normal privileged user is not able to know the credentials anymore of the target system. So at least another barrier to avoid identity theft. At the end, still, we want to automate it.
And when we have done a real preparation on the authorization concept, we can do all the provisioning and deprovisioning automated. Yes, that means an investment at the beginning, but finally, you can automate fully. And how that works, I will show you at the example how a role is declared in FUDO. So a FUDO role could be really everything. But here also we differentiate between administrative super user and also standard user roles with very low privileges. And we give members to these rules, which are typical natural persons, but can also be machines.
We can provide the accounts that can be used for the role. So these are typically generic role based accounts, shared accounts, but also possible to use person based accounts. It's a question of configuration, but this is all possible. And finally, we declare the assets that are eligible for this dedicated role. And this is more or less the principle of these main big object classes. And this is more or less similar for all other roles we can copy. The difference is how these objects are interacting with each other.
For sure, in management systems, or all synchronize it with the directory services. But the real declaration of a role of the criticality and the security, the protection of it, is based on those steps you now see here. This is the way how they have to authenticate. This is the authorization, which accounts they can use, which are eligible. We can talk about approval workflows. We are managing the connection policies. And finally, we are defining the credential management for the targets that will be finally addressed through the privilege access management.
Then we are fully controlling the session. And this session data is the for the incident management. Short example, we are using the DB administrator is the DB role. He has members. He has targets. In this case, for sure, it's databases. And then we have accounts. And these are the accounts that dynamically can be allocated to the members of this role. And then we are defining an authentication method here. For example, the open authentication standard, multi-factor authentication. We are provisioning the right database accounts for the DB administrators.
We are setting an approval workflow in this example for ICE principle. We have admin policies to avoid or to protect against database threats. And then finally, we are managing the credentials. So machine created credentials that cannot be hacked and that are not appearing in any password lists. And here we can also say for this high critical tier zero admin accounts, the password rotation should happen every two hours. While for the tier one accounts, it's okay when the password rotation is happening once a day. So we can be very granular. We declare this session is so important.
We need to have a full video recording. And this is also then the basic for the incident management.
So yes, this can all be fully automated in a FUDO safe. So what does it mean? We will have a short look to the architecture that you can imagine how such a technology works. At the end, coming back, we want to ensure the secure interaction between the identities and the assets. For the identities, we have the roles, the profiles, the tasks they have to perform. And for the assets, besides their security assessment, we can also say, hey, we are protecting on-prem cloud services. It does not really matter. The principle is that the FUDO, the pump system is a proxy in the middle.
So we will have not a direct connection anymore. We always have a media break and every connection goes in the primary connection to the pump system and in the secondary connection to the final target. We also have a very nice dynamic user portal. And this can be used if you do not want to use your existing remote connection clients like the RDP or the PuTTY client. You can also do it fully with a connection portal, the user access gateway, where you only get those connection options displayed you are entitled for because of your role.
And if you click, you will get a single sign-on connection with all applying policies and other parameters declared for this role, for this connection automatically. These are processes happening in the background. And as a result, you will get a secure role-based access and a full documentation with the possibility of automated incident management. And this helps us to go quickly in the architecture, a technology used in the DMZ. You have a very strong cyber security architecture behind, well documented by the way, you can get it if you want. And we are able to talk to different protocols.
So RDP, SSH, HTTPS on the user side, but we are supporting far more native protocols on the target site. So also the management of such a technology needs to be secured. This is why we have a dedicated management interface to control everything. We have the opportunity to integrate a smartphone application for approval processes. We can use the pump system in high availability mode, but also this allows us to do a mesh architecture also to provide some PUM instances near to the final targets. This is all possible and depends on the design.
And yes, very important, PUM is also a source, a data source for communication with the ZM or even with the security operating center. Then we may have some scenarios where the customer is clearly saying, hey, the PUM technology should not be in the DMZ, it should be in the trusted zone. Please no connection to the internet because all the data are so sensitive. And then we are saying, no worries, put it in the trusted zone. And then we are using a ZAS technology, it's called Fudo Share Access, where we can provide authorizations directly to external service providers.
And this is also an improvement of the onboarding and offboarding of third-party service provider doing services for me as a company. This is another topic we can go in detail, but here the message is with such a technology, you can very easily manage all your external service providers and remote maintenance organizations.
Okay, how does it work? A very simple example is we are doing a remote connection to a Windows server through the RDP protocol as an administrator.
So first, yes, you have to log into the Fudo and then you get your user access portal and then you can select the connection you want to do. In this example, we are selecting the Windows Server 2022. And then we directly establish the session, single sign-on, user do not know the credentials, the session just started. And the user is elevated to an administrative role. But then the risk is coming. So the best practice is always to use strong authentication, even with certificates or with multi-factor authentication.
But even in some scenarios, it is still the case, and there may be some good reasons for it, still to use static passwords. And this could indeed lead to an identity theft. So if this is happening directly at the Fudo, the damage is still under control. If this is happening directly at the firewall, the problem could be huge. But anyway, nobody wants to have a, let's say, compromised session even at the PUM technology. And this is where the artificial intelligence gets a role. So what we are doing? So we have an integrated AI for anomaly detection.
As you see, the PUM is monitoring the full exchange between the users and the assets. And therefore, we have an integrated on-prem AI module.
On-prem, very important. Also compared to some other PUM technologies, we believe as a European technology, such a technology, such a module should be on-premise, not any operating or personal data in a cloud or as a SAS. So it should work locally. And that means you as a customer, you can decide how the AI is used, if the AI is used. But here and now, I guarantee to you that no data is leaving the Fudo appliance, never, ever. And so how is it working? This AI module is analyzing the user behavior. And this is the biometry.
And we are learning a keyboard biometry, so how you interact with your keyboard, how you interact with your mouse or touchpad. And we have also a semantic biometry to monitor and analyze an overall behavior. And for sure, it must be learned. It must be trained. And there are also some very good machine learning statistics. I do not go there in detail.
For today, I show you the principle. Let us see this diagram. And you see on the x-axis, this is the session time. On the y-axis, you see the probability of a threat calculated by the artificial intelligence. And then you see something like this, a lot of events. And this is a very simplified picture because you have thousands and thousands and millions of these events collected in milliseconds. And then you may see, oh, there could be some peaks. Is this dangerous?
Normally, no, because you always have this type of peaks. It is important that the AI is doing the correlation between these events. And this is happening everywhere. And then you will finally see that there are, with all these thousands of events, there is maybe two that could be critical. And this is what we have to determine. And when we have determined, we can create already reactions from the system. So we can say we have probabilities. And based on each probability, we can define the reaction of the system. What does it mean? You can create a policy here with the very creative name AI.
And here you define a policy. You give a threshold. How should the machine work? Is this the minimum, the maximum, or an average value? But finally, you give a threshold. And if this threshold is met, the AI is starting a behavior. And here you can also be very clear and say, OK, when here 50% are reached, you do something. And I show you now what does it mean.
First, we will have a look in the interface of the FUDO. This is the dashboard with all archived sessions. And you see here in this area, this is an overall summary of the session. And you see here three times you have a color. That means that the AI came to the result that there is a threat. This is a potentially affected session. You can go and look for it. And then you see, oh, in this case, the mouse biometric threshold has been overrun. So here we had a threat of at least 91%. And this is what you can see in the details.
If you do that, you will get a similar diagraph than before, but only focused with those timestamps where there is really something happening. And this is also something what you can see in detail.
So here, for example, if you go there, you will get a video. And this video leads you from some time ago where a behavior started and will end up to this event where we said, OK, the threshold is overrun and the system has created the activity. So you have always the full root cause. And you see it instantly in real time what happens to this before this threat appeared. And normally, the FUDO is able to stop at least a bad command before it is really given to the operating system underneath. So normally, we are able to stop the potential incident before it occurs.
And therefore, we can really create a full incident management. So let's see here. We are now integrating a CM or a SOC. And then we are saying, OK, we start maybe with the first baseline of, let's say, 10%. This is not too much. We are just doing an alert. We are alerting the CM. We are giving an entry in the session log. We are indexing the session as well. But we do not more. Once again, we also want to avoid the false positives. But then maybe the user is doing something else. And we're coming to a second baseline, which could be the 20%.
And then we are saying, yes, the session will be paused. And paused means the session is still active but frozen. And we can then do and see, hey, everything is fine. We can control the user. And everything is fine. We released the session. So no data is lost. The user can start continuing his work. And everything is fine. But if we see there is a potential threat, we can then still manually terminate the session, block the user. But since it is paused, nothing can happen anymore.
Or when the user is really raising a third baseline, for example, with 50%, which is then really serious, we can directly, OK, no further question, terminate the session, block the user, and stop any further activity. This is how it works. And this could be then also, in the best practice, fully automized. You remember, first, the users have their roles. And with the roles, we declare the reachable target systems, the usable accounts, how to authenticate, and yes, role-based connection policies.
And for the asset side, we can create also some GPO-based session policies based on the risk assessment of the system. So we are creating a group, let's say a risk zero group. And that means the access can only done through the PAM solution, no direct connection anymore. There must be an approval workflow for ICE, at least. Multi-factor authentication is a requirement. Video surveillance is a requirement. And the password rotation should happen every two hours.
And you see, the same policies, but with a lower strength, can be applied to the risk one, risk two, or even to a risk three or risk four systems. This is a reference where we are using the German BSI. This is the standard 200-3. And here you can read it with the link below. So what are the deliverables for FUDO? You will get an AI-powered security for privileged accounts and high-risk systems. We guarantee to you the full transparency and traceability of all user activities. We guarantee to you the reasonable part of compliance and the operational efficiency through automation.
So why FUDO and not another technology? Yes, we are available in productive usage within 24 hours, while others need weeks or even months. We have one of the best rating session management in the market. We already got two awards of our artificial intelligence, one for best AI, one for innovation. And one other point, which is very important to me personally, this is the security architecture.
Because of the very high resilient architecture of an hardened free BSD Unix operating system with process isolation, ZFS file system, internal sandboxing, key generation algorithms, all on open source basis. And yes, to show that this is a real strong architecture, we also have a NATO security certificate that allows us to use this technology also for military purposes.
And yes, we are European. Okay, so I know my time is now more or less over. So this is why I would like to finish here with my contact data. Maybe you can do a short screenshot. If you scan this QR code, you are directly on the requested demo site, because we are really happy to make a demo with and show you in detail how the European FUDO technology works.
Thank you, Stefan. Fantastic stuff and made in Europe. I like that a lot. Very important to say that these days. And really good presentation and great detail. We have some questions. So let me have a look at the questions. So the first one is, does your platform support multi-tenancy?
Yes, and I think this is even a very important requirement, especially when we are talking about managed service provider concepts. And this is even one of the big advantages having this free BSD Unix architecture underneath. Because here, this is a multi-tenancy option directly in the operating system. So it is called the Jails. And we can create individual instances out of one, let's say, virtual or physical machine. And we have on one machine, we can have n instances all fully separated to ensure multi-tenancy. Yes.
And okay, so this is a tricky question. But you obviously said how, why FUDO is good. But should it be more resilient than any other PAM system? Very good question.
Yeah, sure. This is what I mentioned just before. This is at least a security architecture. And even FUDO is even one of the best documented technologies in this area, I would say. And especially the way how we are managing the different administrative processes inside the FUDO.
There's a, once again, a very strong documentation about it. So I will not go in details. But it is nearly impossible to have, let's say, a hijack of a master process and to use it to get access to another process. So here we have a full separated and isolation that the user processes and the administrative processes are fully separated. And this is also the reason that you can put FUDO directly in the DMZ. And not as it is required for many other technologies, all the PAM should be in the trusted zone. FUDO is secure enough to be in the DMZ.
Please, I will send to you, Paul, the documentation. Maybe you can share it as a download that everyone can make his own picture out of it.
Okay, we'll do that. Okay. Now we have a question from Peter Hofer, who says, quite a lot of questions. I'll say it slowly. There appears, this appears to be a very FUDO-centric RBAC approach. He would like to know how to, you can use other IT data and, for example, policy-based access control. For example, OpsPerson is mapped to an asset in CMDB, which identifies the user is allowed to access a resource and there is a change request.
Yeah, absolutely. So what I showed before, this is the principle how a role is declared. So the principle is always the same. You have the user objects, you have the account objects, and you have your asset objects. They are not necessarily static. They can be dynamic.
And yes, you can have policies, you can have all these linked with other identity providers. The point is the principle is always the same. And what I wanted to show when I was going through this role model is to say, these are principles you can at least use for the main objects. And you just, for different roles, for different requirements, you can also have these connection policies I showed, but dynamic. And so this is why you will always have different looking, let's say, saves, different looking authorizations because of dynamic association of, let's say, cloud identity providers.
This is all possible. But the principle to say, if this is a static object or a dynamic object, it works in both directions. I hope I have answered it. But if this user wants to go in further details, please contact me and I show you how.
Yeah, Peter, we could certainly put you in touch with Stefan and go into more detail. But thanks for that excellent question. So another quick question on the capabilities. How can you see the training and maturity grade of the Fudo AI, which I believe is your own AI?
Yeah, it's our own AI. And this AI is also nothing new. This is not something, oh, there is no hype for artificial intelligence in the technologies. So Fudo already created it in 2019, 2020, and developed further. So it was also a long process starting with classic machine learning.
And yes, to assess the maturity grade, the training grade, we are also using the classic methods that you have in machine learning, in artificial intelligence systems, like the OROC curve that describes at least the relationship of false positive and true positives. And if you see, you can always see in the Fudo the learning statistics. And when this OROC is coming near to 100%, so at least greater than 90%, you see, oh, then the training maturity grade is good enough.
Typically, I would say in a regular usage, two weeks, and then you have a very strong behavior benchmark for a user. Okay, well, we have more questions online at the moment. So I'll maybe just ask you some bit of future gazing, always fun to do.
But, you know, we're entering this AI era, we're entering the era of multi identities and machine identity. Where do you see Pam in maybe five years? Or where do you see, do you think we'll, with AI, we'll be able to keep control of privilege? Or will it still be a struggle? Or will we have finally got a zero standing privileges, let's say in five years? This is also a very good question. And it reminds me a bit to the question just before about the dynamic allocation of authorizations.
And I think here, the AI will place a very important role, at least an understanding to say, okay, what assets we have in an organization, which are critical, less critical? What is happening in the cloud? What is happening?
Let's say, even on the on the user side, we will also face more and more AI based attacks. And at the end, yes, this is we are we are currently, I would say, in the change from static, static authorizations to real full dynamic authorizations. And this is and this is for sure, can be done with AI. And this is what we are currently also working on to have AI driven wizards, where you can then also say, hey, Fudo, please, on board, let's say all administrators with the following with the following parameters.
And please, please check what could be the right policy setting on based on the on the on the role of those. So this is really something where we where we where we want to have an understanding for sure. In interaction with other technologies, like in the in the MDR, XDR, EDR, to collect all this information and then being dynamic, because at the end, with PUM, you will never do just with PUM, you will never reach security, you need another cybersecurity infrastructure, but PUM will stay even in five years, the main control point between the real access of a user and an asset.
And the more we can automate by having, let's say, real time artificial intelligence support, the better it is. So this is my very clear prediction for the next five years.
Okay, we do have one final question. I think we've got time from Valeria Ardizani. I guess that's probably not how you pronounce it, but I apologize.
She says, some users have different types of identities connected to the same assets. Yes, that happens all the time. But with different roles. What can be said about the user experience of these users in managing the different federated identities on FUDO during the access to their assets during during the access to assets? Does that make sense to you? This makes perfect sense to me. So at least a natural user is always one natural user. There is only one Paul Fisher, I hope so. And only one Stefan Raben for the moment.
But yes, we can still have more identities more than one because every identity but still belonging to me as a natural person, I can have multiple roles, I can have overlapping roles, I can have unique roles. And this is exactly why this principle of accounts is coming important. So even an account is more or less also representing an identity.
I as a user, I can have the role, I can be an administrator, I can be a super user and what and when I'm logging on to a system like FUDO and FUDO understands me, then FUDO knows it is configured that I have the accesses using different identities, different accounts for different purposes. So when I need to do, let's say, an administrative task on a database, I may need to have a database account. But this is only given to me when my overall profile allows it. And this is the same thing for any other task we have. And with FUDO allows you to give several identities to one natural person.
And you can also create policies in which cases which identity can be used. So for example, to say, okay, during the normal office times and if you have the right geolocation stamp, then you can use more identities than if you are coming suddenly from an IP from China or whatever.
And yes, this dynamic is already fully available. Fantastic.
Well, we are now nearly at the end of time. So I'll just wrap up saying thank you very much, Stefan, for that. Thank you even more for you guys registering and listening in today. And thank you for your questions. You'll be hearing more of FUDO, not least because we'll be doing Privileged Access Management Leadership Compass for 26, quite short, quite soon. And I'm sure that Stefan will be keen to be in there. I'm sure he is.
And yeah, apart from that, let me say thanks also to my producer, Oscar, who's in his studio in Berlin, who makes sure that I'm asking the right questions and saying the right things. So once again, Stefan, thanks again for being with us today. Thanks a lot, Paul. And thanks a lot to Kupplinger Coal for making this platform happen. I wish you all a great day and see you soon. Thank you. Bye now.
See All Locations
See All Locations