I think I'm the last session before coffee break, the last one of this four segments, so I'm going to shake it up and ask for some input from the crowd. So, first of all, Jason Gzym, VP of Solution Engineering Advisory. I'm going to talk about identity security, identity governance, compliance, how going from good to great in your program, what that looks like, what that is. And the reason why it's important to me is I've been in this industry for 30 years, practitioner, and when I joined this world, I never really understood how this mapped to the impact of a business.
What's the financial ramifications of having a bad or good or great cybersecurity and identity security program? So, I want to share my thoughts, my journey a little bit.
But first, before that, how many in this room are identity practitioners now or have been? How many are leaders of those programs in this room? All right. You probably are asked by your board to try to figure out the metrics to map back to the board on what's the financial quantification of the cost of your program. What's the cost of it? What are you saving? And how are you reducing risk to your organization?
Well, we're going to talk about that. And the last session was awesome because I saw a screenshot that said 1993, Novell eDirectory, pioneered IAM. That's where I cut my teeth in my early days. I know a few of others I see also cut their teeth in some Novell technology. There was a screenshot of console one, the border manager. It was amazing. That's probably like 30 years old.
Anyways, so let's talk about data breaches. 70% of these breaches are involved in a failure of internal controls. Shouldn't surprise you. We see the data volume just massively exploding in the applications, identities, both human, non-human, machines, workloads. So the amount of access data that's out there is just ballooning beyond belief. Then you add in the regulations, whether that's the states and the SEC and SOX compliance, NIST 2, DORA, CRA. These regulations are helping us get budget to solve security and the access that the users and non-users have to things.
And I'm going to concentrate on the access to the financially critical applications. So we are here in Germany, SAP, everybody knows that, your Oracles, your PeopleSoft, your Workdays, even your supply chain, Manhattan Warehouse. These are all very critical systems to your business, running your business. And we're going to talk about how to not just get visibility and orchestrate access, but also get observability and what people are doing with that access. And if we look at 60% of our internal control budget goes towards SOX compliance. That's not just for the U.S.
I know that a lot of countries in the EU also look at SOX as a way. But there's also NIST 2, DORA, CRA. But organizations that do not have a mature continuous controls monitoring program, when I say that, let me define that, that is in these ERP critical applications, what are your users doing with the access they have and what does that mean? Is somebody approving an invoice over a million dollars when they shouldn't? Do they have that ability? Are they doing that?
So you want to have that fine-grained visibility into the deepest bowels of the security model of these very complex applications and then also what are they doing with that access. So we're going to talk about what are some of the costs that we have today by trying to solve for this problem and how do we reduce those costs to show value back to the business?
Well, first, big one, we all know this personnel cost. Skills gap in this cybersecurity industry is increasing as complexity rises. So you want to think about how you train your people. And then in the case of manual controls monitoring, there's data entry. There's reconciliation. There's people that are doing disparate data spreadsheets. They're correlating data. They're doing data hygiene across multiple systems, across multiple identity sources, whether they're IDPs or whether they're your HR systems, your non-employee systems of truth. A lot of data reconciliation, correlation.
And then there's errors in that data. So a lot of manual effort just to get the data right in the first place with a lot of manual effort that has a human cost associated to it. Another cost that you look at, IT cost. What's the cost of those workloads? Looking at the impact of controls and audits on your IT departments. Your IT departments are doing their jobs, and an audit comes along and says, hey, stop what you're doing. Stop your strategic program. Stop your R3 to S4 SAP transformation project.
We need to stop everything and look at the next audit rollout to have evidence that we can give to our external auditors. So there's a cost of all of this to your IT. It burns a lot of time. If we look at the next incident response and remediation cost, well, when there is a problem, you have to put some time into understanding how it happened and make sure it doesn't happen again.
Again, it kind of stops everything. And a lot of time, those are direct costs, but there's also indirect costs, reputational damage. How do you get that trust back from your consumers, right? And if you have to spend more money because of these breaches, are you going to just eat that cost, or are you going to increase the prices on your goods to your consumers? And then does that drive your competitors in there because your cost of things are so high, your competitors are not, right? So a lot of prevention to not be in that situation. The next is consultant costs.
To manually go through a lot of these, maybe you don't have staff in your departments. So you have to go outside, have external consultants, maybe you have third-party developers doing pen testing, looking at the security and the posture of your critical applications. So is your applications configured correctly with an SAP or Oracle or what have you? Is it a setting so easy for somebody to gain access? Incorrect. So you want to continuously have those experts. Those experts sometimes are external and cost a lot of money as well. The final cost, compliance fines and penalties.
So this is, for those who have been around American politics 20 years ago, Al Gore, his fuzzy math, if you've heard of that, it's hard to quantify what the risk is to the organization of if we fail repeated external audits, if you are regulated, there will be penalties for that. What will those penalties be?
Well, look at your risk threshold, your risk posture, try to figure out what you're comfortable with, and have a plan in place so that if something does happen, you're okay with paying that fine, or if it's too much of a fine, that's going to hurt your revenue streams, then you want to have a plan in place to prevent it. So those are a broad overview of the costs associated with a security program looking at what users are doing with their access. So we're going to look at the manual controls testing and continual model. We're going to look at the types of risk that exist. Pretty simple.
Credentials. We all have them, whether they're passwordless or not. It's unauthorized access. The credential's been used by somebody that shouldn't have access to it. They were nefarious with that access. But then there's excessive privileges, and I know we're all trying to move to a zero standing privileges model. Not all applications really make that easy. So we have this least privilege security model that we've been using for the past 50 years. It kind of started with RACF back in the IBM mainframes.
But if you are over-provisioned or people have excessive privileges and they are doing something with that inappropriate access, that's a different type of risk. And you're failing your least privilege security model by that. But the other type of risk is segregation of duty violations. And this is where I have a combination of access in your crown jewel applications that allows me to do some internal fraud. I can create a vendor. I can pay a vendor. I can collect money from that vendor.
If I can do all three of those things, I could potentially take that money and put it off in the Cayman Islands or wherever and go retire, and you're basically stealing from your employer. You want to be able to detect who has toxic combinations of access so you can identify and remediate that problem. But there's always going to be people in your organization like your CFOs. They're going to have toxic combination of access because of their role, their responsibility.
Then you want to have mitigating controls in place to make sure that the person with that excessive access is being monitored, and we're going to talk about the continuous controls monitoring. So what does it look like today with manual effort of monitoring your controls? It's not just ITGC controls, who's logged in and used an application, your identity is not correlated to all the applications they're using. It's not just ITGC. It's segregation of duty, business process compliance as well.
But if you look at all the different players on the bottom there that are manually responsible for any part of this chronology of manually testing a control, just think about all the collaboration and communication. We as humans sometimes do a very bad job of communicating with each other, one-on-one, let alone five different business units, right? So there's always going to be human error, and this manual testing and all the different people part of it just invites errors because of the manual nature of it. But you start with, do I need a control? I documented that I need a control.
Did I have a step four? Okay, well, how do I actually monitor that control? Identify reports. Who do they have to go to? What data sources do I have to query? Did I generate those reports? I validate those reports with the application owner, internal audits, look at the data, is it right? Communicate that, email that, whatever that is. And then you're collecting data from multiple reports across multiple applications, business lines, units. You're coordinating across all these parties, and then you have to review the output of that report. Is it accurate? Does it make sense to the business?
Are there any segregation of duty violations? No. Are there any false positives? Internal audit loathes false positives because they're trying to remediate something that actually isn't a problem. So how do you prevent false positives?
Well, if you're only having visibility to, say, SAP role and not the T codes and authorization objects underneath of it, you're going to have false positives because you don't have complete visibility of what somebody has within that application. You might have missed events as well. And the last is, okay, we found something. We now have to go investigate it. We have to capture, retain the documentation as proof that we actually did something and we found that we had a problem. Just can't bury your head in the sand.
And then you prepare all of that for your external auditor, and that happens at least once a year. It might happen in different business units, different lines of business. It might happen quarterly, annually. But definitely, if you have all of this time-intensive resources across all this, it's bound to be a failure. So let's talk about how do we automate it. First of all, you need to get 100% of your transactions monitored in these critical applications. And it's not easy to. It's a lot of data you're ingesting.
But also, as we talk about the explosion of data, then think about things like AI, behavior analysis. Once you have a large data lake of all this, there's no way a human can go through all of that information. So let's look at AI and statistical algorithms to go through that. It's kind of like a business sim. So if you think of like QRadar, Splunk, from your Windows or Linux servers, think about taking all the logs from your ERP applications and using AI methodology to go through that and comb through it and look for anomalies for those violations or exceptions.
Then, once you have that, and all that compute power is occurring, it spits out results, and you can then email them, send it to a manager, risk owner for review, and then you have your documentation approved. So streamlining the manual control into an automated way reduces human error and has less time in humans interacting with that process. So how do we optimize these resources? Continuous controls monitoring.
Well, we talk about what can we do with the standing privileges that we have inside of these applications. It's really good to get visibility across all of the workforce, employees, non-employees, everybody. So you want to identify your most critical applications in your asset catalog first, onboard those, get the deepest visibility to the security model, understand what people can do with that access. But it doesn't stop there.
Just because somebody has the appropriate standing privilege, kind of talk about firefighter or emergency access or just-in-time access as well, do you do that for everybody? Does the application allow that to happen? Is it timely enough? Because we don't want to slow the business down either. So if you have to go to the least security privilege model, then you're going to have standing privilege, but what are they doing with the access they have?
And that's where you want to look at all your transactions and then quantify that information into euros, pounds, dollars, cents, what potentially does that impact the financial footprint of your organization. That's the holy grail. That's what I struggled with in my 20s when I was administering Novell eDirectory and having user ID and passwords.
I'm like, how does this map to what the C-suite is reporting back to the board? I didn't know. Now I do. So that's a way. Let's take a look at this. So on the first one, you have the ability to create or maintain suppliers and process supplier invoices. I have 208 users that can do both of those sides of the business function. Only four of them actually have used both sides of that business function, 2% of those 208 users. And what does that mean? That means that the value of those transactions, those exceptions, those 1,040 transactions, would equate to $5 million roughly.
So you can see that even if you have a small number, 208 users that can do something, you have an even smaller number of users that are actually using both sides of that permission and what the financial ramification is to your organization. On the flip side, somebody who can process invoices and process payments, there's only 37. Three have done it. But just because that's a small number of people, the financial impact potentially could be $11 million.
So just because you have a small number of users that can do something, an even smaller number that is doing something with that access, financially significant to your organization. And then there might be folks that don't have the ability to process purchase orders and process invoices, but that was a point in time visibility of the users, and there was zero at that point in time. Let's say you automated access a week later for a new joiner that did get those two sides of that business function, and you had one user that actually used it to the tune of $65,000.
So this continuous data ingestion is important because if you don't find that new joiner in a relatively quick amount of time, you can have an exception in that report as well. And last but not least, you want to dramatically reduce what you're looking at. If there is no problems, then I want to spend my time in the third row, not the last row. So we don't have enough time to look at all the data that's out there. If we can be given insights on where to spend our time and have the biggest impact, this is critical.
So if we look at the maturity model of whether it's identity security, identity-first security, identity governance, whatever you want to call it, in the world of compliance, first you must document your policies. And that's just not from an identity perspective. That's security, cybersecurity, all of your policies. Once you are there, basic automation.
HR, joiners, movers, levers, access requests for exceptional access, review access. I don't think when regulators said, hey, you need to have a process to review access, we ever thought that it was going to be millions of lines, millions of entitlements. And we knew that the people we said go review this, they would actually look at it. They're just going to rubber stamp it because they don't understand it. There's ways to reduce some of that. But basic automation is the next step in your maturity. Then you look at something like application access governance.
This is the fine-grained visibility into your most critical applications, your ERPs, your financial transit supply chain. And you wrap your own rule sets around what is a toxic combination of access so you can prevent that from happening, as well as detect and remediate and add mitigating controls. And in the maturation journey, the fourth, the last, is what I've been talking about a lot today, and that is continuous controls monitoring. The reason why it's last is because it's really hard to do that without the other three before you.
It is a lot of data, and there's a lot of manipulation of that data. So on your journey, like mine 30 years ago, I finally understand the power of continuous controls monitoring and how it really maps to giving visibility, financial risk visibility to my organization. And with that, I think I'm almost out of time, but yeah, continuous controls monitoring, CCM, it's not IT technology.
It is, but it's more than that. It's a strategic imperative for all of us on this journey to make sure that we're mapping to business outcomes, not just automation of savings by automating, you know, joint remover levers. This is the next level of making sure that you're providing business value of your identity security program to your business, whether your boss is the CISO, the CIO, because they have to report it back to the board, right? So that's all I have for today. I'm out of time. Thank you for your listening, and enjoy the coffee break and the rest of the show.
Well, thank you very much, Jason. Yeah, that was really a picture, an impressive one, an ideal to aspire to, I imagine, for a lot of companies, but are there actually businesses out there who have already achieved that level of maturity?
Yeah, so businesses have achieved this. Obviously, there's a significant investment in maturity for companies, but energy, oil, gas, financial, those verticals really have been doing this for 10, 20 years, but it's now moving into other verticals as well. So it is possible. That maturation is a journey, but yeah, it's not unattainable, but it's a great journey. If you're not in it for the challenge, then why are we here?