Good afternoon, everyone, and welcome to this session with SAP stuff. And my first question to you is, how many of you are working on a daily basis with SAP S4, S4 HANA systems?
So, there's a few of you. And those of you that work with S4 HANA, how many of you are working with the SAP Cloud stuff?
Ah, that's good. That's interesting. I will see. I will be very eager also to listen to your feedback also afterwards, because I think this is a stepping into a little bit unknown territory to some extent.
So, could you start the clock also here on the monitor? It would just be nice.
Otherwise, you would just be like, oh, give me a hint. That's good.
So, yeah, just about very shortly about who am I and why am I standing here in front of you. I have a long history in cybersecurity space. I worked in the Danish National Cybersecurity Council for numbers of years. I've been in the Danish IT industry, ICT industry. I've been running a software company that specialized in cybersecurity. And now it comes to the interesting discussion between what is cybersecurity and what is identity management, because I've always been an identity management type of person.
While discussing with the people that were in the cybersecurity space, they are the ones that are in the trenches. And then we never really agree what is actually what is right cybersecurity. But I think in this closed forum, we can agree that good cybersecurity equals good identity management.
So, also today I work with the Swedish-Finnish consulting company Epico. I might not know them. But the last one here, you might have heard of them, which is the one why I'm also here and speaking to you about leading the security roles and authorization with the Swedish manufacturer named Husqvarna. And maybe just very quickly before I introduce what Husqvarna is, maybe how many of you know Husqvarna already? And I think even now we are in Germany and there's a lot of you also know Gardena. But anyhow, I've been around this business for a lot of, lot of years.
This is 1999 and yeah, we can think about how we are aging, but at least just give you an idea that I've been around there. So, that was actually the internet in the box, that blue thing there, but it's a different story.
So, Husqvarna, it's an extremely old company. It's very interesting to work with. It's nearly a privilege coming into an organization that is literally 335 years old. They are still having manufacturing at the same place. And you can guess what the city name of the company name is.
Well, it's the same place. So, roughly 13,000, 12,000, and then I don't know, I lost counting on all the numbers of people that are temporary workers and externals. Sales across the globe. Manufacturing in a lot of, I think there are 30, 35 sites where manufacturing takes place and the revenue of roughly 5 billion euros in yearly revenue. And as I said, you know, already forest, park and garden care.
So, those are, you know, chainsaws, lawn movers, robotic lawn movers and all the Gardena stuff. But also quite a lot of stuff in what they call light construction.
So, this is for typically construction workers in various cases. So, the SAP program is actually envisioned in two ways. To enable the world's oldest startup to shape great experience in a digital world. I don't know, maybe with, you know, company slogans. But I think that there's some grain of truth in this.
Now, being there for more than a year, listening into what they actually want to achieve. So, the program here is to consolidate more than 10 different EAP systems around the world.
So, we have actually, we're right now doing the first implementation in US and Canada. That's number one EAP system, but then there are another nine conversions down the line.
So, yeah, we have a lot of stuff to do. This is also to future-proof the digital business capability. And make a lasting difference for customers and partners. But I think the first sentence to future-proof, this is also for a company of this age and this size. Literally to make sure that they are competitive in a future world. And to get rid of a lot of legacy.
So, there's also a great, I would say, risk acceptance. We're moving forward and doing new things. If we look at the, and now it just comes to the phrase, because I'm using that all the time. The program is named Amplify.
Therefore, in day-to-day work, we talk about it's Amplify, or in this case, the SAP program. But there's some basic things from an identity point of view that I like to precise. Before I kind of go into what we've actually been doing right now until now.
So, the one thing is that we have a strict policy across all of the group. To have multi-factor authentication and single sign-on services to all of the SAP services. You're nodding. It sounds easy. But it's not easy. That goes for the SAP GUI desktop application. And it also goes now for Fiori and for the web GUI.
So, all of that has to be with SSO. Also, X509 authentication for system-to-system communication. I will come to a thing.
Ah, move on. Also, no local user management. Why can't we just do that user?
No, no, no, no, no. You're not allowed to do that. SAP standard roles. No shared accounts. And access request approval flow with line manager, role owner, and risk owner. It's a package. We're not that far away. We're not that far away, but I think there are some arm-wrestling sometimes happening in some meetings. But just to give you a short hint into what I call the goal right now. I think we have an HR system, obviously. There's an intra-ID. There's an access request and approval. There's an IDM system. I've promised Husqvarna not to go into details on which systems these are.
Maybe we meet on the boat later tonight. Maybe I can disclose a little bit more there. Then comes these three components, which are all SAP. SAP B2P platform, the business transaction platform. The cloud identity service, which is the IDP, but also a user repository. And then comes the IAG service, which is the identity and access governance. And for whatever reason, SAP has not combined those two things into one. But they work independently. The good thing is that this thing here is provisioning into that thing there. Which means it makes some work a lot easier.
Just very briefly, I think you know all of this, but I just took it with. Just to precise how authentication also is moving around all these, I would say, moving parts. And obviously, authentication is a little bit more complex than this one. But the reality here and discussing the problems in this model is somehow also interesting discovery. It's somehow also been a little bit, I would say, reverse engineering. Looking at the landscape and the joiner process, that's where I've kind of, as you saw from the initial, you talk a little bit about EID, also different authentication methods.
But now we're focusing now here on the landscape of the joiner. So right now, we're ending up by having all access requests going there. But you remember my goal where I had the one here. And that gives me, or gives us, this issue. Because in the SAP world, everything is happening from this point to this point. Everything that is on this area, it's not part of SAP equation. It's just not there. So this is a perfect implementation, but it does not fit with the governance in Husqvarna. So that's what we're battling with. But that's the reality.
So hopefully, in a very short future, within already this year, we can start moving this process to this process. And now comes the discussion with APIs. Because apparently, we heard, I saw Martin Kubinger just a few hours ago talking about the future as API. I would say there are some SIs or system integrators around the world that might need a little bit of education. Because in their world, the only thing that is an API is what you can do in clicking in a GUI. But for me, as an identity person, of course, APIs, yeah, sure, bring them on. That's no problem.
So that's what we are planning to do. And any one of you working in this environment, I can tell you this is actually working. It is doable, and it is functioning. We can actually onboard users in this way. So initially, start asking, okay, what are available business roles?
Ask users, okay, to select from the business role. Then we can check, okay, are there any SOD risk or are the users there already?
You know, that kind of stuff. House cleaning. And then we can ask the IDM to provision the user. And I think, yeah, finally, we can even approve the access roles. Because then we can run all the services with a simplified user experience and the reuse of existing process. And there should probably have been a little bit more than governance, but we will get good governance in this sense. Is this a surprise to you that it's possible? Or I think it's interesting. I would say it took us half a year or more than that just to get this model accepted with some of the SAP specialists.
Not the SAP people from SAP, but other SAP people in this, I would say, big program. And no criticism of their expertise, because I think they are extremely good and very skilled on discussions on order invoicing flows or vendor invoice management or production code or God knows what else you're doing in an ERP program like this. But there's no discussion that the insights on the identity flows are a matter of discussion. But I think we are moving a little bit ahead also future-wise. And so how about that we could onboard users using level of assurance?
Because that's another issue we are facing. Of course, every company is facing this problem. How do we get a new user onboarded? How do we get these temporary workers? How do we get people in? You remember no shared accounts. So I need an account. How can I do that with EID? That's something that we are deeply into right now. And I will come back a little bit on some of the thoughts on that area. But of course, we also like to map the business roles here with HR roles. And I actually thought about this just today on listening in on all the AI stuff.
When will we get autonomous authentication or autonomous authorization? Why can't we have autonomous car driving? Why can't we also figure out something here? Because we already know a lot about the users. And maybe we can do a lot with some good algorithms instead of having all these manual processes.
Then, of course, back to the REST API. Check the user. Check the SOD risk. Run all of these things. And actually, down the road, I was in discussion with another vendor yesterday on exactly the SODs area. How can we utilize? How can we actually put a host into the S4 system and then start correlating that with other user data in other areas of user behavior? Those are the things that I also see is highly relevant.
And then, of course, onboard the user. And I think also use the tools and the APIs for adding people. What I also can say is that this is work in progress. That is happening more or less every single month there's a new version. And SAP is adding a lot of APIs in that stack. So I can only encourage you to go on the API documentation side of SAP and check what is happening there. What we did is that we put up a postman project. So we have a shared in the team. We have a postman project testing ideas, of course, against the test system, all that.
But just to see how is this working, these small pilots or POCs, just to figure it out. If we can do that manually, then we can go to the IDM team and then we can ask them to get that implemented. So it's actually been very interesting. And I will tell you that also, again, when you're speaking to people down here, they might not even be aware that the check role request automated approval was an option. They were only convinced when we showed them from the postman project that we could do it.
Ah, that was interesting. Of course, what are benefits here? Governance, again, simplified user experience, securing and simplifying the onboarding. I think that is a major thing when you have, you know, a certain turn through and numbers of users. And then time savings. It's something that I start working with now figuring out, can we actually calculate? Can we multiply? What does this actually mean? Can we cut half an hour every time? And what would that mean in terms of, you know, per year or per three year in terms of financial efficiency?
And just a quick thing on the lever, because that has also been a tremendous challenge. Because they more or less send an email, then we have someone sitting in a user board management here, and then we move people. We figure out that, ah, there's an HIV trigger. So you just, you ask the SCIM API to disable the user account. And then we tell the IAG, hey, this person just need, you know, terminate that user. And this exactly, API is doing exactly that. It's just wipe everything from the user account, strip all the roles. And then in S4, the user will be no longer active.
We can discuss what do you then do if the user comes back and all the kind of additional corner cases. But I think that's a little bit out of scope today. Then comes the other question. So now we have users in our system. And so we work with, right now we are working with four use cases. Authentication to handheld Android-based label scanners and tablets. Easy and quick authentication to operator stations and factories. Temporary workers who is provided by an agency. And then finally, external contractors that need access for support and maintenance.
And I will go into the number one case here, because that's the most urgent case right now. And then just reminding you, no shared account, and the users, they don't have mobile phones. Or at least they don't have their own phone. So what have we done so far? So for the handheld device use case, I guess some of you might know these rocket devices. In this case here, Zebra. It could have been Honeywell, but for the presentation, I found those great images and used them. It really doesn't matter. They all are Android-based.
They are just a smartphone wrapped in additional hardened plastic and with QR code scanners and a lot of other hardware features. At the end of the day, they have NFC. So just here, warehouse workers, FIDO2, NFC authentication with SmartGuard. And then one of the pitfalls, yeah, well, Android, NFC, authentication, FIDO, for whatever weird reason, that one is not on the list of doable things. You can do that on iOS, but you can't do it on Android. If someone here can tell me why that is not possible, I would be very happy to hear that. But we ended up with a small U.S.
company named Blue Fletcher on the recommendation from Honeywell saying, hey, we know these guys. They have made a wrapper app. They can actually do the job, and we made that work. So we're using MS Intro right now for onboarding. But for phase two, we're looking into more options, and especially also the authentication ways of doing that. We're looking into onboarding with a dedicated kiosk system and potentially a native app. And you'll see these are just sample test cards. So moving a little bit forward, I don't know where we are. We are one minute, so we will do that.
I will say the SAP bubble is a big bubble, but we are in the identity world, so we must take that. Basic authentication, it's a struggle. Third-party apps are also a struggle. You need to make sure that all these different teams are pretty well aligned, because otherwise they will divert in different directions. We learned that GRC processes of the group was not necessarily aligned in the program of data because SAP, why would we do what we do in SAP? And then we also learned we need fast, unflexible onboarding with EID. Role requests must be user-friendly.
And then I would say the Agile versus Waterfall delivery, that's an interesting thing also in the terms you saw. This is a project from Husqvarna, people delivering different. So maybe next year in EIC, I can also give you a little bit more on the segregation of duties, business role mapping, access review, onboarding process, real-time anomaly effect detection, and just-in-time SSO claims. I hope we can add some more into the area of AI as well into this equation. I think that's my one minute. Perfectly fine. Thank you very much.