Okay, great. Thank you.
So, welcome in this session about the role of IAM solution in Alliander's NSE transition. It's going to be a 20-minute talk where I won't go really in technical detail, but I would like to share you my experience as I'm currently working for Alliander in building a sustainable and future-proof IAM landscape.
So, as a short introduction, this is me. So, probably you can try to guess my age, but this was long ago.
Where, sorry, where I also are being founder of IDNX Platform. Maybe some people already know this. That's a platform where we are trying to bring people and experts together and sharing experience and knowledge based on digital identity.
But again, it's not about me. It's about Alliander and about the position that they currently are undergoing. And as we also know, is that there is a significant energy transition going on. It means also there's a shift from traditional fossil fuel-based systems into wind, solar, hydro, or even green hydrogen. And driven by the urgent need to address climate changes, that means also a growing global energy demands in a more efficient manner. And a fundamental redesign of the infrastructure, market models, and also the consumption patterns.
It requires additional investments in smart grids, energy storage, electric mobility, and also digital solutions. In order to manage decentralized energy systems. The energy transition represents not only a technical approach or technical challenge, but it's also part of a societal transformation towards a more sustainable and resilient future. So if you're talking about the mission of Alliander itself, it's really about to ensure that we have a more sustainable future.
A secure, reliable, and trustworthy digital foundation to deliver energy and supply for everyone. In this context, IAM plays a vital role in safeguarding the critical infrastructure and ensuring that individuals have timely, appropriate access to systems, data, and also physical assets. As you can remember, a couple of weeks ago, we do have a real power outage in Spain and also in Portugal, where until now it's still not being communicated or not being unclear what the main cause of this outage is.
Some people say it has to do something with a really difficult word, which I don't want to rephrase here, but also about the fact that maybe there's been a cyber attack. So still, hopefully the outcome of this outage will be being communicated soon.
But still, as we know, cybersecurity risk is really something that we have to take into account, especially from Alliander's perspective. So if you're talking about Alliander itself, it's one of the largest network companies in the Netherlands, one of the grid operators.
Currently, there are four grid operators in the Netherlands. This is the biggest one. It's publicly owned, active in six provinces, and it has more than six million subscriptions. So as you can imagine, Alliander really has a big importance in the Netherlands regarding supplying electricity, but also gas. So it's built up with a holding with some other companies there who are delivering different types of services, and the shareholders are municipalities within the Netherlands and are also the key stakeholders.
And as you can see, not only electricity is being provided by Alliander, but also electricity and gas. If we're talking about identity action management, I always start with the basics. I know I already have seen and heard a lot of presentations of future developments that are going on, like AI, which is also here on this slide. But especially building a future-proof foundation is really one of the most important things for organizations. And my experience shows that still organizations are struggling with setting up this basic foundation.
So especially, joint and move-and-leave processes, normally we take it for granted that they are working as they should, but in practice, it's not always the case. And you also need to make sure that you comply with compliance and also share of trust. So the future of IEM is really in grid operations. Is this familiar? Does everyone have someone in the past, this face where he was talking about, hey.
Yeah, can you raise your hand who has this experience? No?
Yeah, more hands. OK, so maybe you have this experience. You are happy because you are able to get the right access to applications. And maybe it's not always about escalation. It could also be on a pretty manner.
But still, there are different use cases that apply to a stable working IEM landscape. IEM is really based on strategy driven. So they have seven strategic pillars that they're working on. This is all in Dutch, so I won't translate this. But what I did is there are two pillars in a strategy where we believe that IEM plays a big, important role. One of them is called, meer werk maken in Dutch, and it makes in English, make work, make more work.
And that has to do with the fact that they are really And that has to do with the fact that they are really are interoperating with contractors which are working in the field and making sure that we can all have the energy that's needed. And as you can see, also, it means also that growing the workforce, we have third party contractors who need to have access to the application landscape of Ariander, although they are not working only for the grid operators Ariander. They have different companies that they work for. We still make sure that we are compliant to the things that they are doing.
And especially about using the right IEM protocols in this case, where we are trying to have an efficiently managed access rights, maintain security and also make it a dynamic, expanding work environment. Other thing is about developing new market services. Also really important, because we are, as a grid operator, obliged to share data with third parties, to our customers, to contractors, to suppliers. And this is something that you would like to do in a secure manner.
And that's why we also are enabling seamless cooperation in that part between the stakeholders and also protect sensitive information like MPE data or financial data or other data. And the last one is about future proof foundation. I think that's one of the most important pillars that we currently are supporting, because a future proof IEM landscape focus really on flexibility, on incorporating cloud native solutions, automation and also, again, AI.
And also, as Ariana doesn't only have an IT landscape, they also have an OT landscape, operational technology landscape, where are the assets which are being there for the critical infrastructure? So we would like to integrate with new technologies, IoT, blockchain, but also means also that we are paving the way for a sustainable growth in order to support our customers, our contractors and our suppliers. And we're not the only ones who are, let's say, are doing things within Ariana. We have a big program.
It's called Fits for Future, where we do have different programs currently working on the same landscape. So you can also mention that there are a lot of dependencies between those programs in order to make sure that we are doing the right thing. And the main goal is going towards 2030, because that's within the Netherlands, really the aim to have their sustainable energy solution available for each citizen of the Netherlands. So if you're looking at the strategic pillars that I just explained, we have tried to transform this into challenges and also a solution.
And these are one of the examples that we currently have here. So one is about the future landscape, because one of the things is that you could have a lack of security awareness. And that means also that it could be a lead to more data leaks. And the way how to resolve this could be based on technology, but also based on people. And I think those are the most important elements in here. We also have about sharing data and new market services, which I just explained. There's more about cooperation between partners, means more data and more also access to the system itself.
And the ways in order to resolve this or find their manner is technology processes and people and processes are also important. So currently in the big program that we currently are doing, we also are reshaping our IAM process to make sure that they fit into the future state. And the last thing is about make more work. Ariane is really growing. It's a company that are trying to find skilled people in order to make this energy transition happening. And that means also that you need to have your processes in place and also your technology, make sure that the access to the applications are.
All right. The foundation of IAM self in the future landscape is the business architecture. So there we draw a business architecture to make sure that we can comply into regulation, but also into future developments. And we would like to dare to be inclusive because we need to be there for the different target audience that we support. We also would like to be smarter. By using information from multiple business processes, but especially also from HR. And I'm not sure if what your relationship with HR is in your organization.
Some organizations are struggling with the relationship between HR and IAM. Some organizations do have a good relationship. I must admit within Ariander that relationship is going very well in order to help them to make sure that the quality of their data is going to be on that level, but we can use in order to make sure that we provide the efficient access that is needed. And IAM would like to be faster by offering self-service and they are also improving processes.
And last but not least, but that's, I think, really correlated with IAM, you want to be more secure and means also better identification, prechecks, integration with SIEM and also with PAM. As you can imagine, previous access management using within the critical infrastructure is really important thing. So at the end, our main goal is to be inclusive, to be smarter, faster and also safer. Our goals that we currently have are provide an IAM landscape for Ariander's future.
Secure and flexible IAM built for change, but also for compliance, because there is current regulation not only about NIST 2, but also regulation from the Dutch government where we need to comply with empowering the organizations with digital access responsibility. So also give the ownership to the organization itself. We are currently looking into adaptive, context-aware access control to make sure that we are providing the access control based on rules or policies.
And as we are one of the grid operators within the Netherlands, we also need to make sure that we do a collaboration with our other grid operators and make sure there's going to be a big energy market for cooperation. And last but not least, it's not the last thing, but maybe it should be the first thing. It's also about cut IT costs with standards. So using standards means also reducing the cost. So give you just a little insight of currently where we're heading to. One of the most important things for setting up the foundation. So foundation means also technology, but also NIST partnership.
So who are we going to work with? How is going to be the structure? Because this is our, as you all know, experience shows long term projects that you're working on. This is not something that you are doing in a couple of days. So that means also your partnership should be based on trust. IM governance, also important decision making structure where in order to make sure that, you know, who's going to be responsible for what and which role.
Some people find it a little bit of a dirty word, governance, but I think it's really important to have structure there in your organization because that really helps each other to also to be certain. To also to be certain what you are doing, but what you are responsible for. Processes. Like I just mentioned, we are reshaping IM processes, but the thing is, we are in a part of a chain. So we are also depending on other processes that maybe needs input from us or output.
So we need to make sure that we do a collaboration with other organization units to make sure that we are going to cooperate and get the right process in place. Change in ownership. Must say that currently within our program, we think that's one of the most important things to be done. I won't say that technology is not that important, but especially change in ownership, making sure that people do are aware of the things they are doing. Make sure that this is an important part that we are have in there in place and make sure that they understand the need for change.
So that means not only communication, that means also sitting together. Do you know that you're responsible for this type of business roles? Do you know what that means? And it's not a one off. It's a continued process which you need to provide. And last but not least, evolution. Because we also are working on delivering the solution by ensuring alignment. And we are doing it in specifications also, but based also on new demands of new requests that currently are being taken. And it's not only about technical aspects, but also organizational aspects, because Ariana is changing.
Our world is changing. So we need to make sure that we need to adapt on those changes. And currently, we are working towards phasing out the current landscape, so we are there in a big transition. And our main goal is to have this done in 2027. Does it mean that the journey ends?
No, I think just the journeys will start because then there is a foundation. Then you can really enhance the solution itself, the processes. And this is one that you have to do for a long term way. So one of the challenges that we have. One of the three.
First, ensure secure, efficient third party access for the contractors, supplies and vendors. That's a real challenge that we have. Not sure if you have the same experience, but 15 years ago, when we had traditional identity management in place, we were putting, trying to put everyone outside of our company. Now we are trying to get everyone in the company, but it means also that you have to make sure there's going to be a secure way in order to provide that information that's needed. We are currently going to investigation of integrating customer identity access management and also PAM.
And especially PAM into the energy transition is crucial. Like I mentioned, we also have an operational technology where we have critical assets in the infrastructure. And especially there, PAM is really needed. And with the six million subscriptions that Arijanda has, we need to also make sure that customer identity management will be there fully in place. And last but not least, and I think it's on every year on this slide, probably. And I think it will be there also next year.
Still have a balance there between user convenience and also security, because we would like to close the back doors. We would like to make it more strict, but we also have to deal with our customers who are using these solutions and to make sure that they can use it in a more user friendly way. And it's always a challenge to find the balance between those two, especially from a CISO perspective that they would like to have secure. But where our COO is responsible, customers say, no, everyone has to have to get the access in a manner like I'm working with an employee.
There's always a discussion that we have. So my last five seconds is this a Dutch saying. I will translate this for the people who can't read Dutch. And probably there's a lot of you here in this room. But currently, the last two years, Arianas really are seeking for the right people. So they stated that the energy transition is impossible without you. And we stated it's impossible without a future proof identity access management. And that's it. Thank you. Thank you very much.