So, I'm here to talk about how to securely navigate B2B relations in an ever-changing world. The funny thing here is, in the good old days, all this was based on trust, and we have spent the last, I would say, five, ten years eliminating that trust, and that is one of the biggest issues I see. To kind of set the stage, we have had an identity explosion over the last couple of years.
If you look at the way we communicate with our partners and suppliers, we were used to managing ordinary user accounts, then we had service accounts, then we started seeing AI, and we started seeing agents, and other great stuff, and automation, where we are doing, to some degree, close to real-time collaboration with our partners and suppliers. So with that comes some growing pains. So we have fragmented authentication methods, so no size, or not one size fits all.
For obvious reasons, we can't expect a small family shop to have fully implemented single sign-on and federation and all that stuff that we can expect from a big company. Other than that, it is the same issues we are facing across different types of vendors. And the funny part is all this leads to complexity at scale. So what we are actually faced with is we have several brands, several franchises, we are present in several markets, and we just acquired Remy Baltic a couple of months ago, so we just got 12,000 new employees to onboard on top of that.
And the fun part here is, at the moment, we are dealing with about 8,000 suppliers across the scale, so we have everything from, as I mentioned before, mom-and-pop shops to big international organisations. So we took an identity-first approach, because we don't really see any perimeter left. Just like many of you guys, we jump to the cloud. We do most of our collaboration in the cloud, and the only things that we kind of keep on prem for now is our SAP, but that's, funnily enough, moving to the cloud. So we are on a separate journey, and that means we don't have a perimeter anymore.
And that led us to take the obvious choice of going for identity-first. So, when you look at identity-first in retail, it is a funny size, because, when I referenced the number before with 8,000 suppliers, that's just not 8,000 users. That might be 10,000 or 20,000 user accounts that we need to manage and give granular access to different parts of our systems. So we took a very low-key approach to this, and we said, so there's nothing, or there's no one-size-fits-all, right? So we kind of made three tiers.
We said, for the small vendors and suppliers, we are going to keep it simple. We are going to manage basically everything for them, so they will have a selling group external account that we manage.
We do MFA, we do everything for them, so the only thing that they need to focus on is their core business and core value that they are adding to our stores. Then we have the mid-tier and enterprise tier, and here, we heavily leverage that they already have federation, they already have single sign-on, and we encourage them to bring their own identity, so the only thing that we will manage is what do you actually have access to, and how can we manage and verify you on onboarding and on job role changes, whatever you want to call it. And I will be honest, it is a big headache.
Just imagine somebody at some larger corporation changing positions, do they still need access to our systems? When are we informed that they had a role change? How do we verify that the user logging in is who they say they are? And honestly, we are struggling a little bit, because if you look at some of the compliance things that are coming, so for us, this too is a big thing, we got flagged as critical due to our volume in the grocery department, or grocery retail sites, and that just brings along a new set of compliance and regulations that we need to adhere to.
And then lastly, we have all our partners, where we kind of took the same approach as mid and enterprise, but we are giving them more of a self-service approach, because we have an inherent trust, so they will be able to manage their own users in a portal that we provide. So it is kind of an interesting story on how we actually did the revalidation and stuff.
So today, we are in a good position in Denmark, where we have meet ID, so that is the government's wallet, so to say, where we can do verifications on who we sign up. So when you sign up, you will actually be verified using that government credential, and we trust the government credential in the way it is set up, and how it is run and maintained. So that is kind of the first step. Second step is we are waiting to see what actually will come of the European standards, so what kind of wallets can we trust coming from Germany, coming from Poland, coming from Lithuania, and so forth, right?
And it is kind of a waiting game. And then we are definitely pro-federation, so wherever we can federate, we will federate. And lastly, we took a kind of different approach on how we used to do things. So we embedded governance as one of the key elements on day one. So what we are doing is we have audit tracking on basically anything you do in the system that is tied to your identity. If there are service accounts, non-human identities, they are mapped to humans, so we can always go back to a human person and say, okay, so this system accessed this and this and this at this time. Why?
And all that good stuff. So our backbone was initially a tough setup and sell internally, because all of a sudden we had multiple identity processors and providers. We did not a real lift and shift, but close to. We went from a legacy IGA system to a more modern cloud-based one, to again allow to do federations and single sign-on better than what we were capable of doing on site.
And then lastly, we moved towards ABAC instead of RBAC, so we used to manage our 61,000 employees with 67,000 security groups, so that got out of control and we said, okay, so let's be smart about it, let's change to ABAC and minimise the amount of security groups that my team is handling. So we shaved it down to close to 2,500, so that's quite a reduction in security groups, and we are hoping to be able to bring that number down even further. And then we did the full auditing and compliance logging, and, again, this varies on the degree of business that we do with the partner or supplier.
So the next big thing that we are worried about is staying ahead of compliance and regulations that are coming up, right? So for us, we do two things.
We do the whole NIST GDPR and what have you not on that side, but as a retailer, we are also asked to gather all the information from our vendors and suppliers for all the documentation for deforestation, so we don't buy any wood without us being able to hand over the paperwork to the authorities saying we bought it from this vendor, it is already certified, it is, if it's wood, it is chucked down at this GPS location, and we can basically track that and hand that over, and that is part of the EU legislations that we also follow.
As we deal in a lot of other goods as well, we have, like you may know from the medical industry, we are obliged to track which batches that we bring in and sell at our locations, so if there is a recall on, let's say, milk or any other item, right, we would be able to say, okay, so we know we sent this shipment to the following stores, and we can do a recall in those stores, and we can make sure that the store goes out and pulls that item from the shelf. So, impact so far.
We have moved from weeks of on-boarding time on our vendors and suppliers, so that has been cut down to two days now, so, on a good day, we can do an on-boarding of the supplier in one or two days, when we have covered all the basics, having done the security audit that we are looking into for these two, making sure that their house is in order, and ours is equally in order, and we can do the federation and all the technical stuff.
And then we have reduced our operational overhead, so we are basically managing something in the vicinity of 110,000 user accounts, and we are a three-man team doing it, so we're not 50, we're not a large organisation, but we're actually four people, where three of them have hands-on on the system. So that is definitely a reduction.
And then we have made friends with just about any auditor we could get hands-on, so what we did is we have our main auditor who does the audit, and we keep them out of the initial loop, so we have internal audits that we closely align to, and they closely align to other auditors and saying, okay, so what's the best practice for this given area at this given time? And then it is all about communication with the auditors, so we are not afraid to sit down with an auditor and say, hey, this is how we do it. How do you actually view that from an audit point of view?
At this point, we have gained a higher trust across our organisation, and especially with our partners, because they now trust that we are doing things transparently, they know what is happening on our end, and we know what is happening on their end, so if they want to change anything, they will let us know ahead of time, and we will do the same. So we are kind of building trust again in a world where we are teaching everybody to not deal in trust, right? Zero trust. Fun concept. So the key takeaways I have is identity must be the starting point. Flexibility? Yes. All the way.
And again, you cannot pull the same expectations from a mom-and-pop shop that you can from a big corporation. And then one of my pet peeves is compliance is a journey, it's not just a check box exercise. So we live in a world where all our requirements are changing, not day to day, but close to, and especially when we start looking at what we are bringing to market with GenSec AI and other ways of automating and pulling stuff. And then I like to say that trust is kind of the key in this world where we are heavily verbal about not trusting anybody.
So what I mean by that is even though we do tell amongst us and talk about that zero trust is the way forward, that is just not how you should be approaching your vendors, how you should be approaching your colleagues, here you have to kind of change the narrative and say, yes, well, it might be called zero trust, but it is based on a healthy concern on how you do stuff, right? And you can't go and say, okay, so we will just run zero trust across the organization because it's not going to fly. We have developers, they will find ways around it. We will have users, they will hate it.
So it is this balance that we are looking for. So yeah, just to round up, anybody got any questions? We've got one question from the audience, and I have a question for you. What role does automation play in scaling secure identity governance across complex supply systems? That's a good question. So the way I see it is automation is key.
As soon as you scale up in the science that we are and many of the other organizations out there, you cannot scale to this level without optimization, and I really want to take it to the next level where we are not doing micro-automation, but we are looking at how do we scale on a policy level. So automation based on policy.
Okay, great. And the one question that we have so far from the audience is, how do you practically secure that the partner you're establishing federation with meets your level of assurance requirements in all major respects?
Well, we used to do the classical CEO meets CEO. They sit down, they walk through the rules and regulations, right? But that's not the case anymore. So what we do now is we actually reach out and say, do you guys have an IAM team? Can we sit down with these guys, and can we figure out what level are you guys on, and which maturity level are we on, and how do we align on that? How do we take into account that you may or may not be at a higher level than us, or a lower level than us?
Okay, great. Well, there don't seem to be any more questions, so please, everyone, give it up for Jerome Thorstensen.