So I'm just looking for, ah, you have the clicker. You already made me nervous. Where's the clicker? So I hope I have the right. It looks good. The slides look good compared to last year where I had the wrong presentation for my keynote on. Welcome. Great to have you here.
And yes, this year I'll talk again a bit more about The Identity Fabric. But I'll bring, we'll bring together a couple of themes. And this was the original title, The Identity Fabric for the 2040s with Strategic Foundations for Digital Identities in the Age of Quantum, AI, and Decentralization. You will notice I will not talk that much about quantum. I think we need to be prepared. But for me, this is also a bit like fusion energy or general, not generative, general AI. It will probably come sometimes, but we don't know exactly when it will happen. So be prepared.
But that's the main thing here. A lot of things to do, and there are a lot of wonders out there, by the way. I just recently published the Leadership Composite Enterprise Secrets Management, which are really good in helping you to be prepared here. But let's really go into the topic. Why 2040s? You may ask, okay, typical analyst outlook into the future.
No, there's a very practical reason. And that is this equation. It's a relatively simple equation. And that equation is we are in 2025. When we do something new in identity management, when we do the next step, we have a time of planning, we have a time of implementation, and we have quite some years of lifetime. And then we are in the 2040s. And that is when we do something, it should last that long. So we shouldn't just think about what we need today. We need to think about what do we need in 2040 and beyond. It's a simple equation, but I believe it's an important one.
So many years ago, we introduced this concept of identity fabrics, which became well adapted and quite popular. And the fabric, as we said from the very beginning, has basically two meanings. One is really the production of identity services. The other is, in English, the mesh. So connecting things. And both will play a role here. So identity fabrics really are a production mesh of identity services. And when we look at identity fabrics today, so this is the picture we released, our 2025 edition of the fabric and the reference architecture early this year.
This is the picture, which basically started with the thinking of what is the job of IAM? The job of IAM is provide seamless yet secure and well-governed access for everyone and everything, left-hand side, to every service, right-hand side. In between, we have the fabric, what we need for doing that. So we need certain capabilities. We combine them into services. We use the right tools to deliver. We integrate with legacy IAM. We serve the modern digital services. We serve the modern IT environments with that.
And when you look at IAM today, that it's still, in many cases, a bit more about loosely or uncoupled tools. So we have an IGA. We have a PAM. We have some custom integrations maybe. We have access management. We may have some new things like, or not so new, CRM, CDP. We have maybe already started to do something around non-human identity management, one of these bus terms of the year. But what we are not really good at is in delivering services via an identity API layer. We're also usually not good in serving all types of identities.
So we have some gaps, and we have the custom integrations, which in some sort tend to be a bit of a heavy-lifting thing, and make it relatively complex for us. For the ones who are a bit further ahead, there's some notion of, also from a vendor side, moving into more combined solutions where you have, for instance, not like here, all different connectors. Here you have more connectors that you can use from different components. You may have a bit of an orchestration platform. So you bring it together, and you're changing the way you couple things.
And there are orchestrated integrations versus custom integrations, a broader set of identities served. And so we're making progress. And this orchestration thing, I believe, is very important also, that we don't have application integration done for every single IAM component. We always struggle in every project with getting all the applications onboarded. And if we need to do it for every tool separately, it doesn't ease our job. So it helps us to have a bit more combined capabilities, integrated capabilities, orchestrated capabilities.
But usually, so the positive thing in green is, yes, we are moving to a bit more integration, to a bit more also modular technology. But we still have clearly some open question marks. And I believe for 2040, we need to get better on that. We need to move forward. But we also have a couple of things that potentially can help us in doing so. And we see these things happening. When I look at, I talk with vendors a lot, things are progressing. And there are a lot of things going on, a lot of positive things.
And so the first thing I'd like to do is, what are the trends of today and the trends of tomorrow that are and will reshape identity management? And basically, I'll look at seven trends for IAM and digital identity for 2040 and beyond. And so today, tomorrow, the trends of today, policy-based access control, still not where it should be. By the way, next year, we can do a nice celebration.
1976, IBM Rack F has been released. So policy-based access control is not really new. So we know how to do it, and we can do it. And it helps a lot, because this helps us to go to zero standing privileges. And to be very clear, standing privileges, static entitlements, are the root cause of all bad in identity management. This is where the problems start. We need to get rid of that. We need to develop applications so that they don't rely on static entitlements. This is just bad programming.
So we need to make decisions based on not only static data, but context, signal, behavioral data, risk data. And this helps us to get more autonomous, more agile in what we are doing. We need to shift towards modular, modern architecture. This is really happening. When you look at the vendor landscape, this is the very, very clear trend. Most vendors have done, are there, or have done really a great job in moving forward and really making very good progress. It helps us also in the flexibility of deployment. And everything needs to be exposed via APIs, which is, by the way, the norm nowadays.
When I talk with vendors, most vendors build their functional components, and then they build their UX on top of it using their own APIs. Makes sense. Orchestration.
And again, here it's decoupling data from functionality from UX. Orchestration is important because it allows us to bring the pieces together into a real mesh of things. And when we released this morning, we released our Leadership Composite Identity Fabrics. And orchestration was a much more relevant and higher-rated aspect of the capabilities than it was in the previous edition, because it's an essential thing for a modern identity fabric, to have the ability to orchestrate different components, different modules.
And it also will benefit, I come to this a bit later, from decentralized identities, which will play an important role. So decentralized identities will help us to get rid of silos. It doesn't mean that we don't have a system of records internally, but when I touch it a little later, I think some of the things we struggle with in identity management are, because we always try to build the silo.
With decentralized identities, in the enterprise identity management as well, identity management as well, in consumer identity management, for non-human identities, we can do a lot of things much better. And this is beyond just a verified identity. It is that you have a ton of credentials around it which you can use. Employed in this company, this job role, all these things can be part of decentralized identities. And we can use it for dynamic authorization schemes, because we have the attributes. Verifiable identities basically are the attributes.
And we don't have a single point of attack on identities anymore. So if it's a decentralized identity, you can attack one identity, not the hundreds, thousands in your directory. It makes a difference. What is coming up? Signal sharing. Really look at all these things. Continuous access evaluation protocol, shared signals framework, all this stuff. This is really essential for what is going on. It will definitely fundamentally change the way we do a lot of things in identity and cybersecurity. It's also a foundation for autonomous identity. I'll touch this as well in a minute.
For next-generation authentication, I'll come to this. I think one thing we should be clear about is if we have a large number of signals, we create signal strengths. So if we combine a lot of signals, and they are pointing in the same direction, then we can have potentially better proof than with the try to have one strong signal, for instance, in authentication. And you can just, if you're a bit deeper into mathematics, for instance, look at trying to visualize it in vector algebra, and it becomes very clear.
Autonomous identity means we are doing decisions with good governance, very clearly, but we do them AI-powered, I call it. So the AI knows a lot about the behavior and what is benign and not, and can help us in making better and more adequate decisions. So when we do it today, we usually say, allowed, not allowed. But it's not always black and white. That is where AI and signals can help us doing things better. For non-human identities, we need autonomy, because handling agile environments permanently moving by human manual administration will inevitably fail. We can't do it. We need AI here.
We need identity act autonomously. And the same for OT, which then can be also very small. But if you have decentralized, decoupled, air-gapped components, we also need some sort of an autonomous identity. And we need AI identity. AI identity is, I believe, one of the big themes. AI for identity, but also identity for AI. I hope to have a talk tomorrow afternoon on that as well. It's about this intersection, but it helps already in authentication decisions. We do it all day. In fraud reduction, we do it. And we know it works. But it also can help in authorization decisions.
And it's elementary for becoming autonomous. So I have five thesis here about how and where I am will evolve.
Oops, I thought I have animated it. Yes, I have. At this point, probably not a bug.
Not a bug, just a feature. Convergence versus mesh. I believe we will see a lot of solutions that have a lot of capabilities provided as modules. But not as a monolithic block. It will be about modularity and the orchestrated mesh at the core. It gives room both for the vendors who have a lot of capabilities by delivering many of the functions, as well as for innovative, specialized startups, etc. Adding other components here. But it will be essential that everyone supports orchestration. That they allow to integrate capabilities much better than today. AI identity, I already touched it.
And it will help us to go away from the standing privileges and the rules. Over time, but that's probably more a couple of years out there, it will at least augment policy-based access control and help us creating, maintaining, but also sort of filling that gray area much more efficiently than humans can do. Autonomous identity, I already touched it.
As I said, for agile, large-scale environments, we need to work much faster, or much more autonomous. We will see authentication change. I believe that not only the password is something of the past, it should be at least, but also the username.
Honestly, how frequently do we use usernames? We use our finger or our face, not our username in many scenarios. And what I believe is, and what I envision is, we can move to a world where we basically have a passive authentication, where we just use our devices. And based on the passive biometrics, on the signals around it, on the device information, we have the context, all that stuff, we can be sort of authenticated. The system can assure that it's really Martin or whoever else is doing that.
And that is something which will be another step forward, and will help us to simplify all that stuff, to increase the user experience, because the worst thing in user experience is the list of username and password. We are used to it, but it's cumbersome, and it never will become good. No way.
So, I frequently read, oh, we help you in making these passwords better, or yesterday I read something about how long your password should be from a tracking perspective. Wrong question, I would say. The only thing we should think about is how to get rid of it. And last but not least, policy-based access control is important, and it will be a very important step, but we will see an evolution beyond that.
Because, as I've said, it's a long-awaited evolutionary step away from standing privileges. We need to do this. But we will also be able to work more efficiently, more granular in this world, by autonomous decisions. And then there's where decentralized identity comes in. It's a foundation for modernization, I believe. We not only need to think about decentralized identity, as there's a wallet I use for authentication, a verified identity for certain governmental services and other things. We can use it way beyond that.
It's much, much bigger than that. And I believe a lot of what is currently happening is important, but there's more. We need to think much bigger here. Way beyond the current scope of, we look at this UDI wallet, it's so much bigger. What is the good thing? It's desiloed, it's reusable.
Currently, we have identities in silos, and it's hard to reuse them. Even internally, we need to synchronize, or then federate, or do other things. Here's the identity, it's reusable. It's verified, it's trustworthy, and everything can become a verifiable credential. And on the other hand, we have signals. We have a ton of signals. We have the standards evolving to work with these signals. And that means we can change the way we authenticate, we authorize. As I've said, no standard privileges, massive signals.
Decentralized identity, in that sense, adds proven, strong signals, verified signals to this. So there's the strong, verified identity, which is a super important, super strong signal. Put this together with all the context signals, behavior signals, et cetera, we have a very high level of proof. So this was policy-based access control, and then later on, AI identity, will help us to move to this future authentication, I touched this, and to a future authorization, which goes way beyond the traditional policy information point.
So the common policy information point, basically, is we look at static data from a directory, or from a database. Right now, we have behavioral data, historical data, we have signals, context data, everything we can use. We can do way more than we could do in the past. And the main point I'd like to make about the role of decentralized identity is, when we look at it, it helps us overcoming some important thing. It's a paradigm shift for all types of identities, because we always struggled with the single source of truth in identity management, especially in IGA.
Here we have a single source of truth. We have a lot of single sources of truth, but we have strong truth. And we have signals that even are bolstering this. So this single source of truth challenge we're always facing in identity management, we can overcome it, because we have it. We always can have it updated. And identity information quality, which is one of the big challenges in every IGA project, will disappear. Because we have a strong, high-quality identity. And that brings us to the identity fabric of the 2040s, which is a picture that is in some way similar.
In some way it's a bit different than what I had before. It's a full mesh. At the core we have orchestration, we have an authorization platform, policy-based access plus. So AI first, and then policy-based access control. We have a single set of connectors. We have a signal exchange with a lot of different environments. We have our core services that can come from few or many providers. We have the supportive services like UX, data, governance, risk, etc. And we can work with all these types of components. We will also look at other types of identities.
On the left-hand side we have organizational identities. We have smart infrastructures. We may even look at post-mortem identities. And we also have more targets. AI will become a target on the top. And smart infrastructures will become a target. So what we are doing is basically we are moving to a modular, orchestrated world of identity services well beyond what we do today. This will help us to move faster and to serve more use cases. That's it. Questions? And by the way, you can reach me on LinkedIn.
And for several aspects like the value of decentralized identity for enterprise, I look at my last year's keynote. And if you don't have access to it, go for a membership. Thank you. Amazing keynote, as always. Laid out all the key themes that we're going to be exploring this week. Even managed a sales pitch for the membership at the end. Well done. Don't forget that you can ask questions. You should have the QR code. If you can't use the QR code, it's not working for you, also go through the app. If you go into menu, stream, and there's a Q&A tab.
So, yeah. We want to make it as interactive this week as possible so that you can ask your particular questions. And the question I have for you, Martin, is what role do identity reference architectures like Kuping and Kohl's play in aligning teams across business, security, and IT? So I think the reference architectures always help because it's a framework you can build on, you can look at.
So what, for instance, our team does a lot with clients is looking at where do you stand? So what is it that you need? Where are your gaps? Where are you relatively mature to understand? And basing this on a framework gives you also sort of a confidence of something that is proven that has worked out for a lot of organizations. So a lot of this sort of alignment between different parties becomes much simpler when you build it on something proven.
You know, very short response. Oh, well, that's great.
I mean, alignment, I think, is an issue for many of the people here. Now, we have a question. Somebody's found the Slido functionality, which is great. Would AI not be a risk for biometrics? And if yes, what would then the solution be to make sure that the person is who he or she is? So we all know that AI is heavily used by attackers, yes. And AI can be used by defenders. My perspective is that in some areas, AI might help us more on the defense side because, for instance, for deepfakes, we must only spot minor deviations while the attacker must draft a perfect deepfake.
So in this case, it turns out to be a bit more friendly to the defender side, potentially. And I'm a positive-thinking person, mostly. We always managed to get at a relatively good level. So take standard initial phishing mails. We managed to figure out ways to reduce this to a relatively low amount of noise. Still there. Still a problem with ransomware, but we always find solutions, and we will do it here as well. But we need a strong governance for everything we do in AI. No doubt.
Okay, now, because it's Martin, I'm sure we could do this for the rest of the day, so we'll take one more. Can you name an identity orchestration platform suitable for enterprise deployment that requires self-hosting? I think that is very much a question that is about specific vendors, and I'm happy to schedule a meeting on this. So use the Event App as a meeting request, and we can discuss this in a small group, but I don't want to brace one vendor or name one vendor here or another. I think this is something for a one-on-one conversation.
Okay, thanks very much. Give it up for Martin Kuebinger.