All right, everyone is seating. Welcome to our talk about identity security in retail on this first day, two days of event, and man, what an event. The slot is a bit unfortunate because in these two days I think we all have gathered so much input that at least Tom and me, we figured out a few things that we wanted to squeeze in the presentation as well, so let's see how it goes. Thanks that you are helping us through this and welcome to our talk. Who's standing here? My name is Tim. I'm spearheading the consulting department at amiconsult.
We are a full service provider in the surprise field of IAM, and well, I consult on IAM topics because I'm just so passionate about it, and I'm very happy that I'm here with my colleague Tom from SPAR ICS, and Tom, you wanted to say a couple of words about SPAR and yourself. Yeah, thank you, Tim, for introducing me also. As you said, I'm working for SPAR ICS, which is the IT company of the SPAR Austria Group. Maybe also giving you a little bit of context about our company. So we are the SPAR Austria Group. We are operating in three business segments.
We are doing grocery, shopping center operations, and also sports fashion retail. So operating over 3,000 stores, in our countries where we operate, and over 30 shopping centers.
Yeah, and talking around 94,000 digital identities for our workforce and for customer identity, we even have over 3 million installations of our Austrian SPAR app, our customer app. So just to give you a short context about who we are and in which field we are working. But Tim?
Yeah, so the numbers are big, and apparently we figured, well, we might have something to say here at EIC. And when we got together and figured out, well, what could we talk about? We took a quick glance at the pre-agenda, and we saw all these high-tech topic, decentralization, AI, the quantum age, and I don't think we do anything quantum just yet on the AI topic.
Well, we are trying to figure that out, but frankly, as opposed to you guys, we still suffer from a couple of master data issues, and AI somehow relies on that. But we also didn't really want to go on stage and say, well, here we are, and we are struggling from time to time. That's not really something where you can take anything away from. So we decided, well, to share a bit about why are we struggling with certain topics, even some key concepts, and what kind of solutions we come up with.
So hopefully, maybe someone else who is in the same situation from the retail sector or from the industrial sector might have something to take away from that, and also might want to collaborate and discuss with us. Let's see, maybe there are good ideas also.
Yeah, maybe some good ideas. So identity security that actually works in retail. Whenever we talk about IT topics, there's something we have to consider, and that is the corporate IT bias. By the way, if you haven't checked out this series, you should. You're in IT, that's a must-have. Corporate IT bias says that, well, IT plans and strategies, they are often made for, well, these central organizations, which are very meticulously planned, right? Everything is high-tech available. The work is highly organized. But that doesn't necessarily apply to the real world.
You also often work from a central institution, and especially here at Spar, which is a company that actually takes power from decentralization and local independence. The two worlds don't necessarily really match up, and that is also something that we consider as we roll out IAM to the bigger company. What is Spar trying to do? The strategy topic, I think everyone here has a slide for his or her management as well that says, well, these are the goals of IAM. This project initially started just as a risk mitigation topic.
To justify that, you also always have to consider, well, operational efficiency, you have to run a business case. Then zero trust arrived, so we wanted to enhance security. We learned, well, digital transformation is important, so IAM is at the core of zero trust and digital transformation. In case you did not know, you're welcome.
Also, we wanted to include end users, and the user experience is also something that gains traction, and IT has to learn about this. Well, what our users, modern users, are willing to accept nowadays?
Well, the European Union, they don't sleep up, so there's always something new regarding regulatory compliance. The scope of this undertaking, it actually increased massively. Thankfully, we have Tom, so everything is figured out, right? We know what to do, or any struggles?
No, not really. Yeah, as you said, several years ago, we started just with the topic risk mitigation. Our business department said we would like to take out risk in our central payment processes, but as Tim already said, a lot of other topics now came in addition. We have the problem of, yeah, we have heterogeneous and fluctuating workforce out there in our stores, so sometimes employees don't show up on the next day again. We need new workforce. We put them in the store, maybe from the street, so we go out there and ask.
We need somebody who puts in the fresh goods into the shelves because we don't have enough workers today. We need seasonal workforce. We have day contracts. We also have different contracts in warehouses, and so on, so very specialized in different fields. We are also decentralized by designers, as Tim said. We have over 3,000 stores in our countries. The shop managers do a lot of things like also having HR tasks. They do the initial onboarding of the new employees out there, so not everything can work out in a central HR department.
We also have, let's say, technological patchwork, like we call it. It's also we have a lot of legacy systems. We have OT systems. We have warehouse management systems, which I would say are legacy from some perspective, at least from our application architecture perspective, so we have no standard interfaces available to connect them, to authenticate to them, but also we are using cloud-native systems, for example, for our enterprise workers, so there is a big gap in between, and so bringing all of that stuff under one hood is a little bit complex.
Also, digital identity is also limited, I would say. Often out there in the stores, for historical reasons, we were using generic identities, non-human identities, so let's say having accounts store 1, 2, 3, 4 in the past.
Also, the traditional authentication methods don't fit on a lot of use cases, but we will come to that also later on, I think. All right, so these are a couple of our struggles, and we have picked two core use cases that revolve around IAM, onboarding master data, and the actual authentication process out in the store. The identity life cycle wise is difficult for us, right? Like Tom indicated, we have workers just showing up on the curb in the morning and making a deal to a centralized system that just takes too long, because they say, hey, can I work?
Yes, you can work, and they want to stop work. So we have a struggle with this central approach, but we take power from this autonomy that we have out in the world.
Also, like I said, we often have no central account, and we actually have to deal with these local permissions. We also have a couple of security flaws in there, maybe.
Tom, what have you tried out to actually mitigate that? Maybe let's start. We are always seeing Identity Fabric 2040, the topics like decentralized identity, AIDAS, and so on. So of course, that could be long-term solutions for our scenarios, for our topics, but we need something in between. We need short-term solutions. We need mid-term solutions, which we can bring in place now to overcome these issues we have.
So like, for example, here shown, short-term solution, really using, in addition to these shared accounts, which are often used out there in the stores, already trying to do temporary identities for our workforce in addition. So giving the shop managers the power to immediately onboard some temporary identity out there for their workforce. They maybe take from the street and tell them, you have a one-day contract. You are a one-day contractor and do the work in my store now. You get a temporary identity.
And maybe we even match that with a later HR onboarding, where we get then really verified data out of our HR system. But we need such solutions where we can overcome these topics before we really also invest in redesigning our complete HR processes. So of course, on midterm, we have to invest a lot also together with our HR teams to really redesign the HR processes to make them more efficient and to have more power in there. But of course, also really doing fussy matching in IJA systems, so in core systems then.
So matching together data we get from HR, maybe also putting in data in addition we get from, yeah, let's say ERP systems or our cash desk systems. Of course, the people need a personalized login on the cash registers, but this is also not going over a central IDP and central IJA system up to now. But we could use also this data to match it together with HR data or temporary identities. And then maybe from time to time over days and weeks, let's say upgrade the identity assurance level for our workers.
So we start with a low assurance level, just having some temporary onboarded data and get it to a higher identity assurance level than when we get really the verified data out of the HR system, where also HR checked everything and yeah. Yeah, so we know that a struggle from this process results from the friction that we have between a central institution and all this decentrality. We also look very, we're looking out for this decentralized identity topic, but we are also having like a worker council to be considered, for example, that actually forbids to use a personal phone on the shop floors.
I think in the industrial department you will have something of the sort as well. Also, we're having like workers that don't even have a phone, right? I think we had a talk the other day where we talked about, well, low-income families, for example, would actually share devices. So how do you account for that? So the message here is maybe to Martin, sorry, we are just not fast enough, right? We can't do this in a very short amount of time.
But the value offer that we have from the identity perspective to SPAR is, well, we can at least enable a rapid onboarding for all these workarounds that we have to do at the moment. And maybe also interesting, there was a podcast of the IM lead of McDonald's, I think two weeks ago now, he has exactly the same challenges. So he told in this podcast, also they want to bring down the onboarding time to one hour, I think he said. So good master data and having all accounts prepared for a new employee in the restaurants out there in one hour, that is a challenge.
I want also to achieve that out in our stores, that if the store manager onboards a new employee, we can provide him with digital identity and digital access also in one hour. That is definitely a goal for the future. Second core topic is authentication. I'm hearing over the last years consecutively that passwords are dead. We have it even worse. Sometimes we don't even have a password in place because a password is something that is personally assigned to an individual.
And like Tom indicated, well, our accounts in individual, they often have a name like, well, store Carl Strauss in Vienna or cash register number three, right? So what's the password of this? And of course, to get the workers then working on cash register three, well, they have a shared password. So we have to admit, we are actually using shared passwords at the moment still, right? So at least not on the cash registers. Not on the cash registers, maybe.
Yeah, thanks, Tom. But in some areas we do. So this topic of identity driven security, that's something that's critically important. And we are really looking how to steer this massive vehicle into the right direction so that we can improve on that.
Yeah, and what could be solutions for that? Also, to say the long term solutions, we know what it could be. So for proper authentication out there, we could bring out FIDO, we could bring out decentralized identity. So all that stuff is on the table, but that is nothing we can achieve in our setup in the next, I would say, five to 10 years, maybe. So that's a five year plus topic. But on short term, we can just say, yeah, maybe take context over identity. So really say, we know we have to share accounts, but put additional personalized authentication in the app context on it where we need it.
But in addition, also doing things like assigning the shared accounts to roles at least. We're already doing that in our bigger stores. So we don't have one account for the whole store there, but maybe saying this is the account for the role shop manager, this is the account for the role, yeah, Kassenaufsicht, or how is it called, cash register observer, yeah, and such roles. They have dedicated non-personalized accounts, but we of course also want to get that away.
And on midterm, of course, it should go into simple frictionless sign-in, but we need a possibility we can now bring out to personalize authentication and not depend on the future scenario because we also have device life cycles. Not all devices have NFC built in and such technologies. So we also have to look into how can we use maybe all technology. So like scanning QR codes and just using QR code plus pin authentication as a temporary solution till we can really put FIDO into our employee badges or have some other solution and have NFC enabled on all devices.
So that is where we are very heavily struggling at the moment, finding this short and midterm solution to overcome the, let's say, time window till we are prepared for all these future topics. Yeah, that's maybe also a request to the vendors out there, right? So these low-tech environments or low-digitalized environments, they might not have a personal smartphone or NFC-enabled devices just yet. And like Tom said, the device life cycle can be 10 years.
So if someone bought their devices just now for their new ERP, right, this will take 10 years before we can do the next step that is in other areas currently considered the standard. But we have ways of entering data very, very fast with a low level, with a low error margin, right?
Because, well, if you scan something for the customer, it also has to be absolutely 100% correct. So there are ways of mitigating this and which will enable us to like steer into the right direction and at least get more secure and secure with every year. So conclusion, couple of takeaways. The first one, and I think this is like a mantra within the industry. It's not a project, it's a program, and this goes out to all the leaders out there in the companies. You are hindering us massively if you just think from project to project. These things take time. These are very important.
We have amazing sessions. How important identity, be it for security or be it for the user experience, is important. How this is at the center of many, many digitalization projects. If you want, you can check out the keynote from Eve again. This was amazing just to show the overlap, how identity touches basically everything. Just great.
Your CIOs, CEOs, they should watch these things, right? So think about it as a program, as like a bodily function that just needs to happen, that you just need to reserve, allocate budget to so that people can work on this progress.
For us, one of these middle steps as well, we decided we have to accept things since the shared accounts for the given amount of time, but consecutively work on this, improve it just a bit year after year after year. Of course, a lot of business processes are also depending on that at the moment.
Yes, and quite a nice surprise. Vendors still innovate. They still innovate on all technology. We see these QR scanning functionality. Just now we see capabilities using cameras in your phones, for example, as well, or in shared devices that enable us to do great things here. Check this out. I will not name any vendor specifically, but there are a couple of things that are just arriving at the market. So if you need some help, if you want to share some of your insights, if you have some insights, if you're further or not far down the road, you can reach out to us.
We're also hopefully good fun to talk to. So you can just reach us via LinkedIn or here on the floor. We're here on Friday, both of us. So yeah. Seven seconds left.
Questions, comments? Thank you very much. I think that's Fabrice, right? Thank you. Thanks for sharing your journey. As you said, another point in time thing. Really two questions, one related to use case one that you just presented around kind of accelerating the onboarding of user and the GML process around that. You talked about increasing assurance level. And I just wanted to clarify what you meant by that. I appreciate that you may not have accurate or ultimately accurate information from the moment you onboard that identity into your system.
And what I assume you meant is progressive profiling as you validate and verify those data. Is that what you mean? It goes into the direction of progressive profiling, I would say. Yeah. Right. It's essentially the same thing, right? At a point, we need to secure the identity as early as possible at the moment it arrives. Usually we build on authoritative systems in the employee sector, but some other system will attest to us that this is an identity that in fact works for SPAR ICS. We can't make this assumption, but we need to catch the identity earlier.
So we limit the amount of entitlements that you can have at this point to get at least the base minimum of work enabled for you, but you don't get to any access to any sensitive data or as Tom thankfully catched, not the catch register, for example. Right. Thanks. Thanks. And the second element is a challenge. I think a lot of organizations face around the authentication in a low tech environment in retail, but it's equally true in manufacturing. That's a challenge I see a lot and many clients face it.
And I just wanted to ask because we are in Germany and I know that labor laws are very stringent for good reason. And we are also exploring use of identity verification like with your features, right? Like facial recognition or these kind of things. Is that something that you guys have explored for your specific use cases? We are exploring also several methods here. So for example, also I think there is some proprietary face ID solution also of our vendor, which provides this shared handheld devices, which are purpose built in our stores out there.
We are also, of course, testing with other authentication methods of proprietary vendors. We are testing with just QR code plus pin. So I think at the moment it's not clear into which direction we go, but that's a big topic that we're able to look at at the moment. Yeah. We saw a talk from Björk yesterday, who's consulting Husqvarna. We were just being pulled out for our talk of a little get together with him. He has also very interesting insights. So if you want to, you should connect them. They are a bit further down the road than we actually are. Yeah. Okay.
Thank you very much again for the insights and answering the questions. Yeah. Thank you very much. Right. I want to say it because it's lunchtime. The buffet is open. Not yet.