The Fabric has evolved over the past seven years to adapt it to the needs of an organization. All these things can be done with this paradigm, and it has proven a lot of organizations, with our help or sometimes without our help, did it. And I think that they can do it without our help, follow the paradigm, use it, that stands for it's easy to understand, it's good to understand, and it can be used in practice. And I think these things stand for the success of this paradigm. Welcome to the KuppingerCole Analysts Chat.
I'm your host, my name is Matthias Reinwarth, I'm an analyst and advisor with KuppingerCole Analysts. This is the start of a brief series of podcast episodes. We want to cover a topic that is essential for what we do at KuppingerCole Analysts. We use it for advisory, we use it for structuring our research and for developing new topics, and this is where we are right now. But before we go any deeper, first let me introduce my guest today. It's Martin Kuppinger, co-founder and distinguished analyst with KuppingerCole Analysts.
Hi Martin, good to have you. Hi Matthias, thanks for inviting me. Great to have you, and we're looking back first of all on something, and I had to look it up because I'm always asked how old is it, and I really do not really know, so I looked it up.
So I found in the vaults, in the archives of KuppingerCole Analysts, of course it's still online, a blog post that ended, written by me, based on the work that Martin, you and I did together in 2019, that ends with the section, and I just quoted, we expect identity fabrics to be an integral part of current and future architectures for many organizations and their IT. And the final sentence then reads, or the final two sentences, watch this space, especially our blogs and our research for more to come on all things identity fabric, and remember, you've heard it here at KC first.
So that was 2019, so this is almost seven years as of now, and we want to use these episodes, this series, to talk about fabrics, identity fabric, and more. So Martin, now that I've talked that much, when you look back at 2019, what was happening in IT and business around that time in 2019, when the fabric concept emerged, when you and I worked on that, to make the old siloed approach to identity untenable?
Yeah, so when you look back then, it was the time of still a lot of traditional workforce identity management, so the traditional identity management we know, but there was more and more consumer identity management emerging, and there were some first vendors around B2B identity management solutions, so looking at more the partners, the supply chain, and so we had some customer engagements, and we saw this evolution in the market, with those other areas and other new technologies popping up, and the segregation between access and IGA and PAM and others, and especially that sort of sprawl of new identity technologies led us, based on our research and analysis as well as our advisory work, to thinking that it doesn't make sense to sort of uncontrolled add more and more tools.
Back in the days, I think it was already visible in cybersecurity that an area where we have a huge number of different tools, that companies, customers, and organizations suffered from the uncontrolled sprawl of tools, and so the idea of the fabric was to build a layer that helps organizations in a more structured approach on what do they need, how do these things come together, and how to really deliver successfully on the needs in the identity management space.
If you look at our flagship event, the EIC, in the acronym there's still hidden European Identity and Cloud Conference, and I think that was also an important part that came way back then, so the dissolving of the traditional security perimeter also asked for something new, right?
That's true, so then you ended up with an on-prem IGA solution and on-prem identity management, and then the IDaaS space appeared, so Identity as a Service, which at the beginning, I think especially from vendor marketing, was pushed as something entirely new, which basically was just a different deployment model, and clearly sometimes with some interesting innovation, but at the end it was mainly about a deployment model.
But again, sometimes you doubled, so to speak, the number of tools that way, and again, too many tools don't help, especially if it's not exactly clear why specifically you need all these different tools. And that was also then, I think, when things really became important and interesting, that was also then this, how do we look at this entire sort of ecosystem?
And right now I said a couple of times tools, and I think another element in that thinking is a tool stands at the end of a decision process, which starts with your requirements and looks at quite a number of things before you finally say, okay, this is the tool I need to solve this, and way too many decisions are tool-driven. I have a problem, I use a tool without thinking about, do I maybe already have the tool in place or the tools that I can combine to do so? So that also played into this thing.
And then the final thing was, and I think this becomes quite well visible in the blog post you referred to from seven years ago, where we also stepped back and started asking ourselves, what at the end of the day is the job of identity management? And I think this is a very important question. The job of identity management is at the end of the day, provide seamless access for everyone and everything to every service, application service, whatever it is. That is the job. And that's where we then started bringing all these things together in the first Fabrics graphics. Right.
And that's actually enough history because we still need the same approach today, still for identity, but I think we need it beyond that. And the term Fabric, the core idea behind that, I think you've already mentioned that. So giving access to every type of identity across a bunch of capabilities to all services, infrastructures, platforms, whatever you want in a unified manner. That exactly is the term Fabric, which is in Germany or in German often just associated with the term Fabrik, which is factory. And on the other hand, it's Fabric, which is the woven texture of a piece of cloth.
So connecting all of this, but the Fabric term still holds and it still brings together capabilities to services, to tools and to give access to all identities, to all relevant services. And this is why we're here. This is the core of the series to apply this notion again, because it's valid. Yes. And I think that it's important. And I think this dual meaning of Fabric is really essential in the entire conversation because it is that social, I see some coming up with related terms, but it's not just something which is about production as a Fabric in production. It's about both.
It's about delivering the services. So that sense of Fabric and orchestration, bringing things together, connecting the dots, so to speak, which is the mesh, mesh meaning of Fabric. And so I think Fabric is a very appropriate term. And the basic principles we developed for the identity Fabric can be applied and we did this just recently to other areas such as cybersecurity, such as the entire field of AI security and AI identity. So it's about using certain concepts and all of that is orchestration because we have a lot of tools.
Another, I think a very essential element and I touched this a bit of all the Fabrics is we go from capabilities. So effectively it is, we have requirements that we map to capabilities. So capabilities is the first perspective that can be mapped into services like the capabilities you need for a security operation center in the field of cybersecurity or the capabilities you need for your central authentication service in an organization for every type of user. This is mapping capabilities to services and then you need tools to deliver on that.
And so it's always capabilities to services to tools. And that is one fundamental structure that holds well. When we look at other Fabrics, we define the AI security Fabric, the cybersecurity Fabric, they have the same structure as the established and widely used identity Fabric. So that is one of the things. And it's always about asking the fundamental question, why do we do that? So for cybersecurity, it's securing the access of everyone and everything again to every service applications, all the as well as data.
So cybersecurity needs to look at these, but it's again, at the end, it's the same foundational picture. We apply to different types of use cases and this has proven to work very well for organizations. So we see more and more organizations across the globe adopting the concept of the identity Fabric. And we are confident they will also look at other Fabrics. I have great hope for cybersecurity Fabric, for instance, because cybersecurity Fabric is a, from my perspective, a wonderful tool to get a grip on the zoo of cybersecurity tools organizations have in place.
Because you also can map what you have and look at, does it fit? When we start from capabilities, where do we have the capability overlaps? Where can we optimize? How can we rebuild, reshape services, all that stuff? And the benefits once this is really accepted are really in various ways. So we use that, of course, in our research to structure market segments, because if you identify the right capabilities for a market segment, you can really say, okay, I need this and that for a tool that will show up in leadership compass X, Y, Z.
So this is really something that we can retrospectively apply to a market and say, okay, this tool obviously fits into the market segment because it has the following capabilities. And the other way around in advisory, we use it to identify what our advisory customers actually need when we do requirements analysis based on such a capability map or where they are, when we will use that for a maturity assessment, and we will dig deeper into that into upcoming episodes. So the benefit that can be derived from organization is mainly understanding where they are and where they want to go to.
So status quo plus strategy plus long running program. I think there's a lot of benefits. It helps everyone in the industry. It helps vendors to understand where they position themselves. It helps organizations to analyze what they have to take a more capability driven instead of tool driven approach to fill the gaps, but also to define services in a more structured manner, not the tool defines the service, but the service defines the tool. So this is the service we need. And these are the tools we need to underpin the service.
Instead of saying, okay, I have a tool around that I built, build my service, so to speak. I think that is a very important element and it helps when we look at the newer editions of the fabrics. Also that is an evolution. It was always this capability approach, but, and it was always an approach looking at, we need a consistent API layer so that the services can be accessed from applications. We need to support different deployment models.
We need to integrate, but it moves forward with, for instance, right now moving to consistent set of connectors across different types of capabilities and services. So not the same connector or the connector is the same application for IGA, for payment, for access management, but consistent connectors. It moves to orchestration as a layer to consistent data layer. So it also helps organizations to see architectural principles when they evolve their infrastructures.
So the fabrics concept helps to look at what do I have, how does it fit to measure it, but also to, to build a target picture, which always is a moving target. The fabric has evolved over the past seven years to adapt it to the needs of an organization. All these things can be done with this paradigm. It has proven a lot of organizations with our help, also sometimes without our help, did it. And I think that they can do it without our help, follow the paradigm, use it, that stands for, it's easy to understand, it's good to understand, it can be used in practice.
And I think these things stand for the success of this paradigm. Exactly. And if you look at the blog post, the picture that is in there looks a bit different to what we have as an identity fabric as of now. So we always considered it to be some kind of quasi-stable, but to be able to evolve over time. So to be versioned, adapted to what's happening. And in 2019 and today, we don't have the crystal ball to know what will happen in two years, but we know that the framework is capable of being adapted to what will happen in two years. And that's what we're doing right now.
Of course we have not yet, or we have mentioned the term AI already, but that changes a lot. Does this change the identity fabric, the fabric as a whole concept at all?
Yes, it will, but it will hold stable and it will hold valid. And so there might be some capabilities missing in the underlying reference architecture, but the overall concept will still hold true. So every work you invested before still is valid and will contribute to future the crystal ball at the 2025 EIC, where it talked about the identity fabric for the 2040s. So 15 years ahead and the basic principles remain the same.
And just as a side note, from the very beginning, we not only looked at humans as identities, from the very beginning, we looked at hardware, non-human identities, because there are so many different and that's a separate topic maybe to look at is non-human identity a meaningful word, maybe in another podcast episode at some time. But we looked at this from the very beginning. We made it neutral to the deployment models.
We always requested certain architectural principles like API first, that was something which was in from the very beginning, like modular architectures, like flexible deployment models. So a lot of these things are here to stay. And so the view into 2040 demonstrates, yes, this is made for the future and helps you to plan for the future across different areas of IT.
So to wrap it up, we have a concept which is capable of structuring individual market segments and overall architectures in cybersecurity, in identity and access management and forthcoming in AI security that are able to define, identify your status as of now, to define your place where you want to go to in the future and to structure that in a roadmap manner, in a target operating model manner. So this is something that holds stable for a long term. So this was just an episode to talk about the overall concepts. And you've mentioned that.
So capabilities mapping to services and then to tools to really understand how to structure infrastructure, how to orchestrate that. We will follow up on that with episodes on the identity fabric, of course, where it is right now. But also looking at the newer developments that we have when it comes to, you've mentioned that cybersecurity fabric and the AI security fabric, because this is really a new kind of field, or isn't it? Let's wait and see. There will be an episode around that. But the fabric as a concept still holds true. And that is the good thing.
And remember, in 2019, you've heard it here first, and we will continue that messaging. Any final words before we close down and we continue on with that with identity fabric with Philipp and you, I think, in an upcoming episode? Final words? I would say stay tuned for the upcoming episodes.
Yep, that's how we do it. And if you are interested, there's tons of material on our website, also in front of the membership area, but membership is always a good thing to do. So do it anyways. So join us, join the conversation on identity fabric and how to use it. Also in the upcoming identity fabric impact days and all our impact days later this year. This was the commercial break.
Thank you, Martin, for being my guest today. And see you soon. Bye-bye.