Good. Then let's start. Welcome back. We haven't changed the line-up still.
Lisa, Reiner, Christopher and myself, Phillip. We haven't changed the fact that we want you to participate in our presentation.
So again, you can scan the code now. We ask a couple of polls in the second session. There will be more polls because this is more interactive this time. And we start right away with a poll. So I will explain that in a second. But now you can scan the code. For the poll, I think it's already open. I see a couple of people. For the poll, we want to talk about the maturity assessment. But before we start talking about the maturity assessment, I would like to know what is the most important piece strategically seen in such an assessment. So will it be the status quo? So where are you right now?
Is that the most important piece? Is it the target state? So understanding the vision and where you want to go. Or is it the way to go? So the next steps, how to get from the status quo to the target state. So what is most important for you from your perspective? We have target state. Status quo is the last thing. So I can share my vision on that. As we are doing the maturity assessment, I think one of the most important pieces is the status quo. So I'm with you 19% right now. Because it's nice to have a vision somewhere. And that you know where you want to go at some point.
But that's the same with traveling. I could say, hey, let's go to Munich. And everyone would know, hey, Munich is there and there. So we have a direction. But if you try to explain somebody how to get to Munich without knowing where that person is, it's quite difficult.
Right now, we know we are in Berlin. So we have an indication. But when we think about what Google is doing, use my current position for estimating where to go. That is not a given in IAM.
So in IAM, you don't have that current destination for the calculation right now. And that makes it a little bit more complex. In the end, for every roadmap, all the pieces are equally important.
So, yeah. We will have a little bit for everyone here. So let's dive into the maturity assessment. As Rainer explained earlier, we have two approaches for the maturity assessment. A three-level approach and a five-level approach.
Today, we will focus more on the five-level approach than on the three-level approach. The three-level approach in itself is more or less a simplified version of the five-level approach. Because it's easier to process for upper management when you work with just three colors. For all the experts, it is easier to work with five levels. Because you have much more options to differentiate between the maturity of certain processes or the governance or whatever you are assessing or whichever capability you are assessing.
So, we have the five-level initial repeatable defined managed on optimizing of one to five. This is what we will assess later with you from one to five. And the idea is when you have a level one, you are more or less a starter. That means you have not a real structure. You are doing stuff manually. You have not much when it comes to automation. Maybe you are decentralized working and so on. Up to level five, this improves stepwise.
So, level two is already a little bit of structure, a little bit of automation and so on. In the end, we want to reach level five.
So, the best state that we have in this assessment, that is where you have a strategy about all of that. You have integrated all of that. You are reducing manual work wherever possible. You try to act proactively and try to reduce risk wherever you can. That is the overall idea. Five levels don't give us much to talk about.
So, that's why we have the criteria. When we talk about the maturity based on the reference architecture capabilities that we have heard in the first half, we need to ensure that we cover certain criteria for every capability. We have 12 criteria in total, automation, centralization, integration, and all that you can see here. Every criteria in itself can be assessed for the five levels for every capability in the reference architecture. That is the idea of the maturity assessment.
So, when I talked about identity lifecycle management in the first half, I could ask pretty much each and every one of you, what is your level of automation for the Joiner process? This would mean identity lifecycle management and just this one criterion on automation. This is how you do an assessment. And then you rate that for each and every criteria from level one to level five.
Of course, there is a definition. I will show that in a second. But that means, in the end, for every capability across all 12 criteria, you get a maturity level.
So, as I said, there is a definition. I have prepared that here for an example for entitlement management, not for identity lifecycle. But as you can see, we have these levels for the capability predefined.
So, what means level one for entitlement management? For, in this case, automation to future readiness.
So, that is the depth that you have based on the 12 criteria in the end. So, that means we have comprehensiveness. We are modular doing that maturity assessment. And in an interview, we create a lot of awareness because we talk about the different states, the different capabilities, and how you can become more mature in the end. All of that is very much a discussion that you want to have to ensure that everyone is on the same page in the end.
So, this is the depth that we have for the five levels, but also for the 12 criterions. But we also have that for the five levels.
So, entitlement management for automation comes across five levels. And this is how you improve based on this one criterion overall.
So, that is how you ensure that you provide the right guidance. How can I improve from a level one to a level two? Maybe just in this one criterion. Maybe you want to stay the same level of maturity for the other criteria and just want to improve the automation level. And that also helps when I talk about improvements. That also helps with your strategy and how you improve in the future.
So, that gives you the ability to plan ahead. So, a full example for entitlement management looks like that. And that's a lot of stuff to talk about. That's not for you to read. That's why I have that so small. But this is just one capability. You have seen the reference architecture. You have seen the little boxes. We have that for all the core boxes.
So, that means we have 12 criteria for every capability. We have five levels for every capability. And for 29 core capabilities, that makes a lot of data points to discuss and to evaluate in such a maturity assessment. And I hear a question from the first part. Is that not too academic? It's not. It's not. We have done that. Lisa is here to explain how we are doing that and how that helps.
Of course, we don't need all these data points. And we didn't discuss all of them. But we guide our clients through that process based on the capability descriptions. We have already shown how that could look like. But that is then the result. That is very easily processable. Even though behind these little circles with the maturity here is a lot more that you don't see. And that stuff that you don't see is something like that where you say, hey, what is my maturity for a single capability? And the circle, they give you an indication that's true. But this is where the details come into play.
Besides the 12 criteria here on the right side where we describe how everything was rated, we also have the expert opinion to obviously add our expert opinion on that and don't only rely on the framework itself. And in the spider graph, you can see the overall rating. So that's how a result could look like. And when we have the result, that is your status quo for, I don't know, entitlement management. I'm still in entitlement management. That is then the point when you have that and you are able to or you understood that, you can move forward as explained.
I've asked the question at the beginning, what is most important, status quo, target state, or the way to go? This is your status quo right now. The question is, how do I move forward? Designing a target state is usually not too hard when we talk about a single capability and have already understood what the capability is and what the maturity levels are. So it helps us then to have the reference. So we have seen on the last page, we are here on a capability score of 2.23. That means that I am somewhere between two and somewhere between three.
So when I want to improve, I will probably move or want to move towards a three or a four. And this reference here for entitlement management level three would enable you to move one level up. So from a 2.3 towards a three. What do I need to do to get there? That's something that you can say very specifically when you have the framework in the back. So that is basically all I have as an introduction to our framework. So you have seen the capabilities in the first half. You have seen the criteria now. You have seen that we have five levels.
And now we move into the part where Lisa is explaining how that works for Fresna. And therefore, we change the slide deck right now towards Lisa's slides. Good. Then I hand over. Thank you very much, Philipp, for the introduction.
And yes, again, welcome and thank you for having me here. And I will try to explain a bit what we did in the sense of a maturity assessment at Fresna MaxiZoo. But let's first introduce myself and why I'm here, actually. So you need a bit of background. Just quickly to me, again, I'm the competence owner for identity and access management at Fresna MaxiZoo. That's the team lead for identity and access management. I also work as a delegate speaker for the German SAP group in the working group IAM for security and vulnerability. I come from a rather SAP background.
And this will become quite important throughout why we did what we did here. And also working at Fresna MaxiZoo, I'm a dog enthusiast and also an astrophysicist. But so much for myself. Why am I here today?
Well, because what you hear throughout this conference or what you've heard in the last year is that a lot of people in IAM talk about transformation. There's a lot of transformation going on. Non-human identities, agentic AI. So many things that will actually bring identity and access management to the next level. We have to change things in comparison to how we did it before. But some of the companies even face different challenges. They can't just look at what's the new trend, what do I need to do? But sometimes you're even forced to move. And that's the case for Fresna MaxiZoo as well.
Okay, I forgot the dog photos. Enjoy. They're always in here as well.
Yeah, the dog enthusiast always comes too. But here we are for IAM transformation. Because if you use as an identity and access tool SAP IDM, then you're actually forced to move. You're forced to transform and you don't have much time. Because end of life is 2027 and we have 2026 already. You have an extended maintenance until 2030. That gives a bit more time. And most companies that I see, so that comes from my delegate work, actually use this. And we use it as well. And this means that if you use this tool, then you have a toolbox that's deeply integrated into your company.
Often with topics that are not that IDM related. And that becomes important for us as well.
You know, as an IAM expert, that migration takes at least two to three years, including tool choice. The longer we wait, the more possible it may become that contractors actually become bottlenecks.
So, yeah, I see a couple of doing this. So, you're probably in the same seat as us. And then there are some decisions about, yeah, you want to keep the toolbox. You want to move towards standards. You want to stay on-prem. You want to go to cloud.
So, that's all the things that move Fresnaf MaxiZoo when we're talking about IAM transformation. And now quick to introducing the company a bit. Because that's very important for how we do IAM and why as well. Because actually Fresnaf MaxiZoo is very good at transformation. This is just an overview of where this company came from in the 1990s. When the founder actually opened the first Fresnaf store.
Actually, the very first Fresnaf store that he opened, it failed. But then he opened another one. And that actually then took the story forward. And over the last 30 years, it's changed a lot. It developed from German franchise partners, an important part in identity and access management. It moved towards international stores in Europe, which are Fresnaf-owned. And in the last years, of course, the online business has become much more important as well.
So, now we're really an omni-channel retailer. And so, on a whole scale in Europe, we are the biggest pet retailer. Always with a corporate vision, which we really live for making our pets happier. Because that makes us happier as well. And I can relate to that very much because I feel that. And that's an important part of the story. Because Fresnaf is really built on their stores.
So, everywhere you see in Europe, stores actually outside of Germany, they're not called Fresnaf. So, they are called Maxizoo, if you've ever seen them. And we are not just selling. But if we go into the stores, and as a pet owner myself, it's very important. You want people not only to tell you the price of the product that you buy. You want them to be able to actually tell you what's good for your pet. You have a senior dog, what needs do they have?
So, these employees are really, really... Okay, what's the word there? They are educated so that they can help you with this. And that's actually very important if we're talking about more than 2,000 stores Europe-wide.
Now, what does this have to do with identity and access management? Well, it actually is. Because we don't want to keep those employees busy with logging into applications, making that complicated. We want to make their lives as easy as possible so that they can actually do their job and help us pet owners get information. And this reflects in how our identity and access management is built. And I want to give you this overview because it's really important to understand later how the assessment for us works and why we actually did this. This is a very quick overview of our architecture.
So, this is really the technical part that my team and I have been working on in the last years. There's a lot of legacy in here, starting with SAP IDM, which by now you can say is really a legacy product, with two main source systems, which is our SAP personal system. There's a reason why you have SuccessFactors slash HCM.
No, there's not a tool where both is in one. We really have both. And that is also important. Our franchise partners, very, very likely were the backbone of the business, at least in the first 20 years, but still today. They actually use SAP as an entry point to govern their employees for our needs. That's part of the not-so-IDM topic that is in our identity management system. And if you look on the other side of the target system, that's what we've been doing the last years and which is where we are going. That's why it says ongoing.
We have a couple of systems that will run end of life as well, because our R3 systems will be switched to S4HANA. We have a couple of non-SAP systems, especially our POS system or point of sale, which is, of course, one of the most important systems in the whole business, because if you cannot buy your things at the store, that's bad for both of us. Let's put it this way. We've changed this as well. And we started focusing on Microsoft Entry ID as our IDP, but also maybe in some direction of at some point laying to rest SAP IDM and just using Entry ID more.
And here outside you have this active directory, which is kind of an island, although it is, of course, connected to Entry ID. And if you look at this, you see we have our technical side. We know what we're doing. We know where we need to go. But you see it doesn't look perfect. And that's the technical side. And when I now come to the – OK, right before I come to the organizational part, here you see again the importance of our store employees, because the whole green part here is our store employees. So that's really the main focus for our identity and access management.
And the problem that we have here is that something I think everyone can relate to, right? IM is everywhere, but it's hardly ever really visible. And that's the organizational part that drives us, which is the reason why I'm here today, is that we have around 80 to 90 projects per tertial at Fresno throughout the business. And around a third of that at least needs IM support from our side. We do only workforce. We have a different group who does customer identity and access management for the online shops.
And they need all sorts of consultation, from join-and-move-a-lever processes to concepts to authentication, single sign-on. So sometimes smaller, sometimes bigger, we are all in there. And the processes that surround these projects, let's say it doesn't always end in the way that people come to us early enough. Most of the times it actually feels like this. I guess you can relate to that, too. So pretty much at the end of a project, someone realizes that you do still need identity and access management, because, whoops, you need users. And here we go. And what does this mean for us?
Well, it means that the last two years, because our team is quite young, still we were really just busy, busy, busy all the time. Kept doing projects. And in the same time, we tried to figure out, because we knew for the last two years that SAP IDM is going to die, that we need to do something. So while we're doing this, we're trying to figure out how to make things better, how to make things move forward. But it was really hard. And that most of the time actually felt like this.
And that's not a nice thing, because if you actually know that you can move forward, you know you have these round wheels, and you just see that your organization doesn't really keep up with it, and you're not really able to make your point why it's more important to build a better foundation for identity and access management. Well, this is kind of the result. And the time is running away for us. We know this. So after two years, we were just like, okay, it's time to start rolling. We need to change something. And we need to do it now, because we don't have the time left.
And we decided on doing an assessment, because we could not do this on the fly. It was not possible for us. We kept those last two, three years. We discussed everything. We would try to understand how this architecture works, how Fresno was built for this. And we had all this knowledge, but we couldn't find the time or the structure in everyday life to really put this together. But we knew that we needed to. And that was the point where we decided, okay, we need to do something.
And the first step is to do an IAM maturity assessment, because only from there we can finally get the management consent that we still kind of feel we are lacking sometimes, because, well, we've been busy these years, right? We've done a lot of magic. And some of that looks really good. And then try to explain to people that, yeah, that's nice, but we still have all that bad stuff down there, and we need to change that. And it's like, yeah, but just do more of your magic. Maybe that's enough. We're like, no, we need to do this, because otherwise at some point there's no magic left.
And because only from there, if we do these two steps, and that relates to what Philip explained, we saw it the exact same way. Only from there can we plan a roadmap. It's something maybe you've experienced that as well. Management likes to jump to step three.
You know, give us the roadmap first. Tell us what you need to do, and then we talk about this. And we're like, no, this is not something that we just pull out of our hats. We can't do this on our own. But I now proceed. I want to focus on step one, because step two and step three actually are not there yet. But this is where we want to go in the future. What was the scope of our maturity assessment? We decided to do it with Kupinger Coal, because we really wanted to make it vendor neutral.
I really wanted to make sure that if I do this assessment, that I don't have the slightest hint of someone telling me, maybe, you know, they just want to do something great. They all like identity and access management. They just want to sell you something. I was like, no, I don't want that. I have so many great consultants that I know.
But still, I really had to make sure that this was watertight in this very first step. And that's why we also just focused on the first step, really doing the assessment, saying, OK, where are we today? And from there, we then decide how we proceed. And so the scope was really just evaluating the status quo, trying to define a strategic target state, get an idea where do we want to go, at least as a team, and maybe even a bit further, and also start analyzing the gaps, and maybe try to find a couple of quick ones. Because that's always good if you need money to do an assessment.
It's always good if you put something. You don't just want to show the problem. You want to show a couple of fixes that makes it easier. The timeline for us was actually one month. That's really, really short. And it's kind of our own fault, because we overheard bargain. But in the end, we were very happy that we did it in such a short timeline. This consisted of a kickoff meeting, four workshops with the core IAM team. We have four team members, including me. It's not a huge team. It's not small as well, but four team members. And with those, we did the whole workshops.
Philip over here was the lead consultant who did this with us. And we also had two interviews.
Well, actually, not us. But of course, Copenhagen Coal did two interviews with our IT security and with HR. As our main stakeholders, we didn't want to bring in too many. But this was enough to give a first overview where we are today, and how do other stakeholders actually at FESNAP view the topic, who work with us, and where we work together, and where do our views maybe diverge.
Also, all of those sessions that we did, we did everything online. Again, hard bargain. But all those sessions were recorded. And that was really, really important also for us that we still have the possibility to go back to our own thoughts when I now explain to you, because now I'm going to show you how we actually did this. But I needed to explain to you before where we actually come from. We focused on the core services. 20 in the whole, 21 capabilities as a whole, because we also did IT service management down there. But the focus was really on the core services.
Not all of them that are up there. I didn't mark each one of them. But it's pretty much what Philip showed before for the IGA. So this is just an overview. I continue to the next slide. So what I tried to do, I want to give you an example how this worked for us and what we did.
Now, I'm a bit in a pickle in here, because doing such an assessment, let's face it, you don't do an assessment because you think you're going to ace it. You're doing it because you know you're having areas that are not working that great. So what I tried to do, I wanted to give you an example how you're having areas that are not working that great. So whatever comes out there, whatever results there are, that's not really what I want to focus here. Because for you, it's more interesting, I guess, to see how it in general can look.
Because in the part after this, you will get a better view over your own maturity if you do this example assessment. But here, it's more about how did we do it and how it worked for us and what were the main results and lessons learned. So the example that I bring you here are the identity repositories. I think we didn't show that one yet, so it's fine here. So this is the classical coping or call slide for the reference architecture for the capability identity repositories. And this was really the base for our discussions.
When we met in those workshops, we went through those capabilities one by one, starting with these slides, starting with the questions that you see over here. I'm not going to go in detail into everything. But I think it's important. What we did not do is our team did not sit down and take these questions and this and started writing next to it. I don't know, thinking about each and every single question and thinking, what's the real optimal answer from our point of view to this? That's not what we did. What we did is we took this. And as a team, we knew what it was about.
And we started talking. We started explaining how our world looks like, how it works. We had the architecture slide that I showed before. We have this in a bit more detail. So for identity repositories, we went in there and explained, what repositories do we have? Where's our active directory, for example? Where does SAP IDM fit in? What does Entra ID do? How are our HCM and success factor systems in there? The fact that our franchise partners actually use our SAP IDM as an entry point for their users.
This is something that we explained here in depth, although before the assessment, we did agree in our team because we are a couple of seniors. And when we start discussing, this goes deep very fast. We were clear to ourselves that we explain where we are. And we tried to keep it as lean as possible, always with the feeling that we have everything in there, but trying not to go too far. Because sometimes, yeah, it didn't work for all capabilities. I think Philip can relate to that. But most of the time, we managed to dump our brains in those sessions.
And honestly, that felt really, really good. Because those last years, we learned everything how we worked.
And here, finally, we could just put it out there without having to do the structure, without having to write everything ourselves or thinking, oh, does this go here or there or not? Because that's actually what the colleagues from Copenhagen called it from us. They gave us this structure. They were the bumpers to the left and to the right, keeping us in line, asking deeper questions when they felt necessary, making clear that maybe some things that we talked about were not in the scope at this point. And that was really a great dynamic. It's helped us to go through slides like this.
And afterwards, having the feeling, OK, everything that we know about this is now in this session. It's now recorded. It's out there. And then you did your magic. And we get the results from that. And the results that we saw were exactly what we felt should go in there. And that's what we needed to do. And from the next slide on, I'm going to show a couple of those results to you. One quick question, because I coded out a couple of the things in there as well, because it is internal. And there's only very few things that I can show to you. But to give you an idea, I'm going to do it anyway.
Please, if it's OK, refrain from taking any photos from the next three to four slides. That would be really great. So this is one of the results slides that actually came out of it.
One of, I think, 150 at the end. So happy I'm not showing everything. This is a summary of the status quo where we are. Yeah. And so you can see on the right, the repositories, the way that we wrote them, that we showed them here. And down there is a snippet from the architecture slide that we used to show the results for the assessment. And there are actually a few things that should not be in here.
So please, really, don't take any photos. That clearly didn't work. OK. Yeah. And so you see on the side exactly what I showed you in this overview graph as well, that you have SAP IDM, HCM, Active Directory, Entry ID, the SAP Cloud Identity Services. And what is also clear, whatever is not in the graph is obviously still decentralized repositories. So we have those as well. And the summary over there is then the base for the grading that comes on the next slide, which Yeah. You don't have to read it.
It's just I know that it's all correct, that it's all in there, that it's everything that we needed from this capability to have this here. And we really have this for each capability, and that's really, really great. Yes. And so this is the maturity rating in our case now for the repositories, 2.5 score. That was what we expected. Because we are on a repeatable level, we have an SAP IDM. We have a lot of stuff in there that we still do manual, so that's fine. So we know that. We need to get better there.
And so the expert opinion there that actually tells us that we have these three factors that still prevent us from being the real single source of truth, that we are still having a lack of governance, some inconsistent data sources, and manual ad hoc processes. Everything that you could actually see in our architecture before is reflected down here. And this is the spider graph where you see the capabilities as well. And the detailed criteria ratings, as Philip explained before for the other capability, you can see this here as well. For example, like future readiness.
SAP IDM is out of support. Awareness of topics like global identifiers and something that we need to do something there and solid foundation, but significant changes required. So that's not so bad, but it reflects what we wanted to show, what we also want to give into the organization, that there are still things that have to change. This is one of the slides that you receive at the end of the year, which is like the summary of the assessment rated over all capabilities, which you have for the management part, the business part, and this is for the technology part.
And for the technology part, this, of course, focuses on SAP IDM because it is a factor that is just there, but still, even though it's there, it's not the clearest indicator for everyone to start to get moving. And so we have the replacement of SAP IDM at the top because this just totally makes sense. Very important for us as well, this information that you should think about putting non-IDA topics like using an IDM as an entry point for too many users manually is maybe not a good idea in the future. We should change that. I think that's clear for everyone.
And the source system integration, because we are not completely clean there yet because we have success vectors, HCM and the Active Directory and Entra, and it's still not connected in a way where we would say, okay, this is clean and makes sense. And this is, of course, also very important. I'm going to refrain from the other ones down there, and then you have some plans of actions there that you can do. I did not put in the slide for the quick wins because that's actually a bit too internal as well, but we had a couple of those as well.
And as a summary here at the end, this is what Copenhagen gave to us as well. So this is more of an overview that is good, especially if you give it to someone to have a quick idea that, yes, we are doing things, but that we really do need improvements at a lot of levels, that there are several quick win areas, that we need a roadmap that was very important to us, that we need a roadmap also because SAP IDM support ends, and that our management awareness at this point is really critical, that we had to get this buy-in and get away from the idea that our team can do it all.
That was really, really important. And the results for us, if I put this together now, was that it was a really time-efficient assessment. That was so important for us.
Honestly, we didn't have the time to do this. I know last year my manager said, Alisa, but you have all these seniors, right? You can do this by your own. I was like, even if I could do it in this way, if I had all the experience and have done it so many times before, no, I couldn't. We simply do not have the time. We need to choose somewhere in between. So doing this assessment was for us perfect because we could really preserve our team capabilities and still get this done. And now we have our capabilities structurally assessed and in writing. This is so important.
I cannot stress this enough. We've wanted this for such a long time, but if you simply do not find the time for it, you don't get the priorities and the capacities, well, this is a great way to do it. And now it's there. It exists. Also important, the quick wins that I did not show you in details, that was really fascinating because you get new angles on that. We stood so long in our IAM topics that some of the quick wins that Kuping et al told us, we were saying, are you sure? I don't know. Maybe.
No, we don't think so. But we started to discuss things that before we had already discarded like, no, that's too big. We can't just do this. That's not a quick win. And opening these discussions also helped us a lot to open our minds again and think about smaller steps that we could do before.
Overall, most important for us was that the assessment really underlined that the organizational challenges were more important to us, actually, than the technology side, what I started in the beginning as well. We know our technology, but if the organization doesn't help in a way that we can actually move forward, then that's not helpful.
And, of course, together with SAP IDM's end-of-life time for action. The whole thing, we're going to use it for a management decision. How much future IAM do we really want at Fresnoff? Because now we can say, okay, this is where we are. Where do we want to go from here? And those are our next steps as well to really now get this management content and then do a roadmap, which we are going to do with the colleagues from Köppinger Coal as well, because now we get this credibility for the first step. That was really important, too, because now we have the freedom to do the next step, too.
We weren't allowed to do both together in the beginning, and now we are. And our lessons learned? Expertise and field structure are just really invaluable because it makes things really, really quick. It makes them clear. And if you have your own IAM, your knowledge there, that helps, too, because together that's a really good fit to do this assessment in a lean way.
And, yes, an assessment helps to gain attention, and that's probably one of the reasons that a lot of us do this because we know we need to move forward and we need to get this consent. Just a reminder, choose the timing wisely because once it's out there, it is out there, and it gains attention. And you can't just, it doesn't go away again after you've done it. So it's necessary, but beware of it as well. In our case, you could have said, you waited two years, you know for two years that this system was going to be end of life.
If we had done this two years ago, we wouldn't have done it in this way. Our team wouldn't have been far enough. Our knowledge wouldn't have been far enough.
So, yes, it seems a bit late, but for us it's actually the right moment, and together with coping a call, it was also really the perfect fit. So, thank you for your attention.
And, yes. Applause Perfect. Perfect. Thank you very much, Lisa, for sharing a practical insight into the maturity assessment. And I didn't knew about the dog stuff. We need to share pictures later. Regarding dog, I also have a black one.
Okay, so next part will be then the most interactive part. So now it's time to wake up. Do not put away your phone.
Yep, as you need it to answer questions. We will again use the capabilities regarding the Slido tool and basically go on a very detailed level through one specific capability. And hopefully everyone remembers the slides with a small font Philip shared at the beginning of the second part. This will be the foundation.
No, just kidding. We will talk about access governance with that, because I think regarding this group, we prepared for that. That's the most interesting one.
One, access governance. I think we saw now four or five different slides of these capabilities described. In a short phrase, access governance is focused on managing and mitigating security risks related to improper access, ensuring that organizations can monitor, control, and audit who has access to what, why they have it, and who granted it. So everyone aware of that? Is the baseline defined enough? Then we will jump into the next thing. First of all, again, here is the QR code. And I need to enable in parallel always the question. Maybe you just take 10 seconds to reschedule.
You don't need to run away. Perfect. So you remember the 12 dimensions Philip shared, if not an issue. We prepared for all of these 12 capabilities this slide here. And from an efficiency perspective, I'm pretty sure it doesn't make any sense that everyone reads through all of these five different dimensions. The slides Philip shared have been mainly about what does this mean. So we have the five different levels, so the common maturity model, and each of them is a bit different.
I would say we start with something like three is more or less you have a standardized automated governance workflow. So we are talking about automation. That is the baseline. If you don't have a fully automated governance workflow, you are potentially more in repeatable or even in the number one area. And if you have end-to-end automated and monitored governance, this is then level four. And this principle is, I think, something we should handle with all of the capabilities. And with that, I enable the voting.
And we can maybe then switch in 10 seconds to the other slides, as people might need this for references. So I think it's important to also understand in the end, you will see a summary of all the voting you're doing. So that will be then really a good chance to have all the results. So that is now initially just for this evaluation criteria, but you will see kind of this spider chart, which you have seen from Fresnap and also from us. You will see that for your voting at the very end of what we are doing here now. Yeah. So we have 67 votes right now.
That is more or less the average, I would say. Okay. So what can we see on that level here? Access governance and the level of automation. The majority says, at least, that they are level three. So standardized and automated governance workflows. The second biggest one is a bit less. So basic automation. And then we... That is interesting, honestly. And it's a good point.
I mean, that's why we are here potentially. If you are answered level one, you need to do something.
At least, I would say. At least access governance is really a foundational thing. And if you are not regulated right now, someone will join and find something. Some regulations. Also 16% of this group says they have level four. And interestingly, at reality level five, no one. Yeah. So I think that's the first thing here. And then we can jump into the next one. Yep. I don't need the clicker.
No, because it's just this one slide. So the next one is then about governance and compliance.
And again, we have those five levels here. And yeah, usually this is a bit more complicated.
I mean, automation is... Everybody knows that. The compliance and governance is how much do this really relate to a formal governance framework you established here? How much assignment do you have to standards like GDPR, SOX, or maybe some ISO standards where you have controls in place? And how well do you manage these frameworks? So if you have a formal governance structure already established and you have assigned responsibilities for the access governance activities, then you are more likely to be on this level three, which is the defined level there.
Below that, you have partial ownerships like there and more reacting to audits. And the worst is you don't have a formal governance framework at all. So when a department comes to you and asks, okay, I need to understand who has access to application YXX, and you just respond to that requirement, then you are in this initial state where you respond ad hoc. I think you can actually already start the vote so that they can vote while I'm talking.
Yeah, and then as already explained, once you go really into metrics-driven compliance and management, and then also into continuous compliance optimization, so you manage your framework actively, then you are going into the direction of level five. I can't read that, so I'll take a look on the screen here. I have glasses.
So yeah, again, most of you see yourself on level three, which is good. So that means you already have a formal access governance framework in place. So there's a relation between your regulatory requirements and the access governance activities you have in place, which is very good. Some of you are on the repeatable level number two and then, I mean, okay, almost no one on level one, and then also not too much on level five. I think that's what we always see, right? I've never seen the company on level five for this conformity topic here.
So yeah, thank you very much. How would auditors work? Are people achieving level five? If they're all on level five, I agree.
Okay, so it's still ongoing, but the trend is quite clear. So the next one is flexibility.
So again, here we have how flexible is your organization or your governance model in case of new requirements. Access governance models are standardized but extendable.
New roles, entitlements, or review processes can be added within governance framework through significant adjustment can still require some IT effort. So that is, I would say, good in class level again. So I start the vote. I think most of you understood the concept here. Voting is enabled. And I think at the end, the most interesting part will be not the average because I really expect average about something around two and four in total, sometimes more in the direction of two, sometimes more in the direction of three plus, but the outliers are also relevant.
So what would be the total best in class version here and the weakest one? I think that is also very interesting. So we have 52 votes. So the tendency is going down of people voting.
Feel free, four more. I can see who is not voting.
No, I cannot. Now we have the same figures.
And again, in that case, level two is the winner. So limited flexibility for predefined cases, one. And then with 20% less, we have level three here. And the first time someone said, okay, level five. That is interesting. Was this a clicking error? Was this an error?
Okay, perfect. Then let's jump into the next one. Great. So next one is about security. I think one of the most important criteria in that area, it talks about how much do you improve the security of your organization by implementing access and governance capabilities and key functionalities here. And I was talking about the GDPR, like the regulatory things, but if it comes to security, you often have these ISO controls in place. And if you're on this defined level, you have security significantly improving through structured attestation cycles.
You have standardized entitlements in place, and you have a first detection of segregation of duty, for example, in place. So you pretty much have already a decent level of access governance in place. You're managing entitlements and rule assignments quite well. And then again, if you are below that, you reduce quite obvious risks like overprivileging, for example, you recognize that and try to handle that, but it's still kind of more like ad hoc. And if you're on level one, then of course you have a high risk.
You know that there are people in your company having a lot of administrative access, or you even know that you have a lot of identities or accounts in your system where you have no idea to whom they belong. And to the other direction, if it goes into the direction of risk-based and continuous monitored governance, this goes into the direction of real-time alerts. I think Philipp was talking about that, that this is more and more becoming important to you the more you have non-human actors in your environment.
With that, I think we can switch already then maybe to the results and have a look. Okay, it's already there, great.
Okay, again, level three, that's great. So you're already managing it actively. Some still on the level two here. So you see obvious risks, but you're still reacting more or less. And just a few on the managed security. So from my point of view, that is something which is what we see a lot. So nothing too much surprising from my point of view. Do you want to add something here or?
No, no, we can just go ahead, right? Otherwise it gets boring.
Yeah, then we can jump into the next question. Decentralization or centralization is maybe the better thing. Number three is a central governance framework is established through identity and access management tooling covering major systems while some legacy or departmental local processes remain decentralized. That is layer three or level three in that case. So let's start the poll. That was a confident start. We can also already switch to the results. It's more interesting to see it live. Okay.
Okay, so almost 60 people voted in total. In that case, we have a level three as a winner or maturity, 10% difference to level two.
Honestly, that's also what I would have expected. One question again, by raising the hand, which of your organizations is regulated? On which level? Regulated persons, please raise the hand. That's potentially the 40, 93%, I would assume. You know what a common problem with a five-level measurement is? People stick to the middle.
Yeah, and we framed it a bit like that is the baseline. Yeah, they do not decide then.
Okay, so I think next one is focus. And focus has a lot to do also with your program, I would say. So how much do you actively look into access governance and how proactive you go through improvement cycles, for example? And that is again, then already the level three. So if you're already managing governance in proactive improvement cycles actively, then you're on the defined level here. And if your awareness needs improvement and you manage that more like ad hoc, then you're on this repeatable level there on level two.
And yeah, if it's just audit-driven, so if you start working on your access governance, maybe still on Excel spreadsheets, once you get asked to report on your governance, then you're in this initial state. So from the results I have seen before, probably no one is in this area here. I can already predict the result, I would say.
Yeah, maybe we answer that. Maybe we answer that. Then do it. I predict no one is on initial state here. Wrong.
Wrong, okay. How much wrong? Oh! Where is level one?
12%, 10%. Five people. Five people. At least they're honest. That's good.
Okay, yeah, but again, a lot of you are on level three. I mean, if you're really on this level one here, I mean, that is then really the time you should stand up, go to your management and start to act, right? Because that exposes then in the end the high security risk back to the topic of security in that sense.
Yeah, maybe next question then. Perfect. The next one is talking about scalability and resilience. Maybe we do it a bit different. Level two means scales for limited growth. So manual processes can handle limited volumes if supported by templates or standardized forms.
However, scalability is constrained as growing user populations or complex systems overwhelm reviewers. Failures and gaps are common under pressure. That is level two. So let's start with a poll. If you are better than you are level three. That works with the framing. No. I think it would be interesting to see automation again because that is somewhat related to automation, I would say. The next one will be the best one. Next one is the best one, okay. Documentation. We will double check if one clicks two or three.
Okay, so 62 votes. You proved me wrong. So most of you decided for level three and the second one is level two. And interestingly, I know that's level four. Level four, we have 13% or 12% and only one, two persons clicked. They are level one, which is a good one. I think they said half of them are regulated organization, right? I think that fits them to the defined status here.
So, okay, next is documentation. Yeah, funny one probably.
So, yeah, level three again, if you think you have a standardized and maintained, that I think is the important thing. Maintained documentation. So that does not mean you just have some documentation laying around on a file share somewhere, maybe on SharePoint. That's not sufficient to reach level three. You really need to maintain it and update it and people know where to find it.
Come on, now you're raising the bar very high. The vote is already open, isn't it? No. Here we go.
Okay, so yeah, maybe let's already then look on the results because I mean, people can read the headlines themselves. That's not too bad, isn't it? If we assume that 40% of the people in the room are regulated. Yeah. Now they voted. Then there's room for improvement, you say? Okay.
Yeah, but I mean, we're just kidding now. I mean, that's reality, let's face it. The documentation is the least thing or the last thing you actually then do. So no surprise in the results from my point of view.
Okay, next. 66 votes, perfect. Then I already start to open the next one. Talking about integration. Level two is again partially integration with identity and access management components and level three is more or less standardized. In that case, I need to switch the slide. So level two, partially integration with identity and access management components and level three is at least on a standardized level. It is there. And Paul is open. Oh. What?
Okay, it switched. Because at the beginning, level four was number one. Okay.
Okay, again, we have level three. Most people answered. That is a good answer in total. Any outliers?
Level one, two, three person. And I think 60% in level four is the best one we had right now. Perfect. Then let's jump into the next one.
So yes, so that is user experience. And I need to explain a little bit and put the focus right, I would say. So this is not just about providing good reports and audit information here. Remember that access governance also is about the access requests and reviews doing here. So this is really touching the user experience of your employees and partners and all the identities you are managing here. So if you think you already have a good user experience here on level three, then you have a predictable role appropriate experience. So that means people understand the meaning of the roles.
They can easily find the way how to request them and get them assigned. And the effective authorization they then receive is really in line with what the role actually said. If that is not the case and you see, okay, there is room for improvement and you need to improve the role descriptions, for example, or improve the requirements or the availability of reports, then you are more like on the level two and less. Towards level four, you have the real low friction guide and governance experience. Everything is super documented.
The first page on your intranet already explains how to receive access. All these things are, yeah, working very well. So now I'm really curious how the results look like. Okay.
Again, I would say an honest answer, right? So you see yourself on the repeatable level. So the user experience usually needs some experience. Probably some of you face the problem that role descriptions are not that intuitive like they should be or yeah, not all the user reports and audit information is available at hand easily as you wish to see that.
So yeah, thanks for this honest voting here. Next. So the next one is the maintainability. Also very important part of access governance. Level two means you have something like repeatable processes, maybe in your very good documentation somewhere and still a lot of manual processes or even IT support is needed to adjust something. Level three, then it is a bit more tool driven. It is standardized and can be changed without IT knowledge, I would say in that case. So let's start with the voting. This one. Touch this one now.
No, it's the right one. Yeah, yeah. So did I catch you with a documentation of processes thing here? Not really.
Okay, interesting. So looks like we have currently again 60 votes. Level two wins or leads. I don't know if this is winning. Level three is the second one and at least around about 10% are saying, okay, we are in initial or even in level four and again, no one in level five.
Okay, then even if this is hopefully a lot of fun, we come to the last one. It's really the last one already.
Yeah, it's about future readiness and when we talk about future readiness, we need to look into topics like real time monitoring, automated segregation of duty detection, advanced analytics you do probably in real time and yeah, how you are prepared to tackle those challenges. So if you think you are actually in a situation where you can't implement that at all, then you're on this initial level.
If you think, okay, I have some awareness for this, but I'm not taking action, then you're on level two and if you already have designed your governance processes and technology with automation and real time monitoring in place here, then you're on this level three and from there, if you're actively already doing something about it, then you're level four and five is then, if that is a strategic topic for you, then you're on level five here. Is the vote already running or? Yep.
Yep, okay. So then we can look into the results again.
Okay, good. So most of you say, okay, we have an awareness of the future needs here and you're about to start to do something about that. Not too much. Surprisingly, level three and level two is close to each other, right?
Yeah, thanks for your voting. I think the most interesting part would be then the complete picture. I don't know. When we put it together, you're sitting there, no. Now he said he's setting the baseline higher than we can deliver in that case. Initially it was, so we can switch back. Initially it was planned that we create this beautiful slide with the results. Unfortunately, due to technical issues, this is not possible, but we saw the example of Lisa and basically that is some kind of real average example. We also know from the outside. I can challenge a bit.
You need to trust me again, but you can see the results in the voting as well, I think. So for instance, let's take automation. We had most people voting between three and one. So the average would be potentially something like 2.1. I would assume, isn't that? So automation is round about two in total. So that is more or less a good example here. Here's the detailed number. Then what else is very interesting? Flexibility, I think is also a good point. Most people voted two, some three and a few ones. So I would say something around 2.5 and flexibility is four. Okay.
Philipp, how good is this example? It's just a few words. I thought that's our good one. We probably looked at this. Don't forget what this guy said here. Talking nonsense, okay. But the good thing is everyone thought, okay, he's right. In that case, next one, security is also around three. Maturity is below three, so it is 2.6, 2.7, which is potentially something in that area as well. And one thing I want to figure out, documentation again.
Two, three. So more or less, I would say 2.1. I was right.
Yeah, so that is basically how this works. For sure in reality, Lisa mentioned this, and the reality usually looks like that we sit together with you or you sit together with your experts, take the framework, take the idea behind it and really challenge it. So it is not living by only asking questions, answering. It's really in your organization, bringing the right people together and discuss, talk to each other.
See, okay, where are our strengths in those specific capabilities, the maturity in a view for the whole organization. That is the important thing here. And this then really leads to an as-is state. So status quo, the important thing, and as Philip mentioned, allows you to derive the next steps.
Philip, maybe you want to talk about those examples here. I can do that, certainly. What I've done here is basically we wanted to align all your votes to an average. Unfortunately, we haven't been able, so we have the example numbers. But to show you how it works to improve and how to move forward, I've assembled, based on the access governance example, a couple of recommendations, how to move from level two to level three. Since I didn't know if you would vote for three, I have the same slide for level three to level four.
So those that are a little bit better than the average, because from what I've seen, the average would be around 2.8 or something, you can use these improvements to move forward because that's what a maturity assessment is about. When you have your status quo, you want to improve. The target state can be the next level or can be the level above that, from level two to level four, but you want to move forward at some point. That's why we are doing that.
The more specific the recommendations are, the quick wins that you have, the big wins that you can describe, the easier it is to explain that to the management. Because just saying, hey, we are level two, we want to level three, will not win you anything. We had the question earlier, how can I convince my management to give me the budget to do that? This is what convinces them. You get the recommendation, very specific.
You tell them to your manager, hey, we are doing, in the case of excess governance, we are improving recertifications and the quality of, I don't know, the role descriptions or the level of automation, the frequency. I don't know, whatever you can do with that. And that's what gives you the budget. Maybe we switch to the second slide. I'm not explaining the recommendations in detail, so that you have seen it once at least. This is what could bring you from level three to level four.
And again, the slides are all available online. So just mentioning it again. But exactly that is what we have done with Lisa and Fresnaf. We have figured out the level that they have and the next step that they should take to improve. This is just a single capability.
And again, when you do that over a whole assessment, there are coming up a couple recommendations. For Fresnaf, we have focused on 18, I think, in total. There are more. There are definitely, the more specific you get, there are more recommendations that you can do. And I think that's everything that I have to say about this slide. So we can move to the next slide.
Yeah, so one thing to sum it up. You have seen how the maturity assessment works. We have done that for a single capability. So there are 28 more capabilities and the core capabilities to explore. We have prepared something for you. That is our mini maturity assessment on the website. It's not as detailed as this one. But that gives you a good first impression on where you are and how you are doing. And how you would fit into the landscape based on the reference architecture.
Good, what else do we have? I think we have made clear how important the maturity assessment is for moving forward. I have explained that. Lisa has explained that. I hope you have learned it by yourself based on the survey and the polls that we did.
Yeah, I think that's my summary for now. Perfect.
And again, thank you very much for supporting here and answering the questions. You can also find it at copingercall.com in the advisory section and then the maturity assessment. Good. Perfect. So we are already in the last part for sure. We also have prepared a takeaway slide for you to combine the knowledge of today. So identity fabric and reference architecture in general. That's what we really try to explain and to share. They are a service oriented structure to build your identity and access management landscape within your organization. To be flexible with new requirements.
And I think that is the most important thing here. Martin had a slide six or seven years ago. It's a paradigm. It's not a tool you buy. It's more or less an idea of how to structure your identity and access management landscape. And with that also the new requirements coming around like NHI, agentic AI. You will hear a lot during the conference about that. You can include this into this concept. Into this kind of how to use identity and access management within your organization. And then what we did together.
The most important part is starting by even if you disagreed and said you want to have the target state. The status quo is the most important thing at the beginning. And from that you can build ideas, understand, take such slides for executives, for managers. Really also to talk to them in business speech.
To tell, okay, we need budget. This is the impact if we don't do anything. And not every identity and access management initiative needs to be the big bang, very expensive tool. It's a stepwise thing. Also a program, not just a single project. And starting with the identity fabric allows you also to have a structure in place that can frequently and continuously improve without reinventing that thing. I mean the first incarnation is something like 10 years old. Around about 12 years. Started here at EIC or in Munich in that case. Or not even Munich.
And now we're here and also announced for next year an update. And that is a slide Philip added so he can tell what his thoughts are.
Yeah, I mean we have not talked much about AI, but it's certainly a topic for everyone. We have seen that in the beginning polls. Agentic AI is currently the top driver that we have. I was anticipating that to be honest, not sure. But anticipating that you would answer like that. Still my belief is that if you don't know your current landscape and where you are right now, your status quo, you won't be able to effectively navigate IAM to secure agentic AI. So that's the takeaway that I want you to take home. Ensure that you know what you have, where you are and where you want to go. That's it.
And with that, we have for sure also some closing slide where you can connect to each of us. I think it's the LinkedIn QR code. If this works from this distance, otherwise use the name. That's the easiest thing. And as we have around about five to six minutes left, I would also take the chance. We have some questions and ask to the people. So the first one, this is for Philipp, but keep it short, please. The assessment is very good. That's a good point. And provides a valuable input on the current implementation.
Can the assessment also provide guidance or calculation based on the required team capacity and organizational setup to focus? In the current state, it's not the focus, but we also have the target operating model. And as Rainer earlier explained, the operationalization steps also include looking forward. When we have the maturity assessment, we can move forward talking about the next steps. And part of that can also be talking about the target operating model. And that would include the numbers. Perfect. And then we have a question to Lisa.
Could you tell more about the differences in the perspective of your IT security team in contrast to the view of your own team? To the differences?
Well, let's put it this way. We're still working to find our way together because both teams are actually not that old in Fresnov context. And I think one of the things that we have is that our security works very risk-based, which is good. But I think Rainer explained that in the beginning that if you do this, it can sometimes lead to difficulties with an IAM team because in an IAM team, you want to start to establish standards. And you don't want any risk-based security to actually lead to go beneath the standards. That's not helpful if you go into transformation.
That's one of the things that we discuss a lot to actually find together that what they do and what we do actually fits better. Perfect. Thank you. And then also a good question. Would you always argue that centralization is more mature right now? Question for me. I would say no. So centralization is not always more mature than decentralization. And I think that is also not the only question. So maturity doesn't beat everything else. Your business still needs to be able to work and you need to have some efficiency and usability in the process and the way your business actually works.
For me, that sometimes is even more important than actually the maturity and the security discussion and compliance discussions in the background. Because if your usability is not good enough, then people simply start working around your processes and trying to get rid of it because they are annoyed by it. They're bored by it. It's simply not working for them. And then you gain nothing. And in my experience, if I just think about the last engagements I had, I think at least one time I also recommended to go with the hybrid approach.
So leave certain capabilities decentralized and try to keep some of the very important and critical applications and governance aspects centralized. That could also be then a quite well approach for you if you're in this game of, okay, how much decentralization do I allow? How much centralization do I need? Exactly. And a good thing to add here is if you are an international organization having different branches, it is not that easy to centralize everything. And basically, I think Rainer was it or was it Philipp also talked about target operating model.
At the end, it's also the idea of who is running what, who is externally, internally, what is SaaS, what not. And how much empowerment for my whole organization. Do I have a group CISO who is in charge of identity access management on top level? Or do I have multiple unique kingdoms with local kings and queens? It always depends.
I mean, as Rainer said, at the end, it depends. And hybrid approach could be the right thing. And with that, I would say thank you very much, Lisa, for joining us today, sharing what we did for Fresno. Thank you very much, Philipp, for preparing this great presentation and the workshop together with Rainer. And thank you very much, Rainer, for sharing the maturity assessment and supporting here. And thank you for participating and have fun at 2 o'clock. Opening keynote starts and I think something around 1 o'clock is for the new EIC participants, some orientation session, how you benefit most.
I think you need to check in the agenda. It's I think in the ground floor.
With that, thank you very much and have a good week in Berlin. Thank you.