Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor with KuppingerCole Analysts.
Today, we want to look again at a really important topic when it comes to doing real-life identity and access management and for this, I have invited and she has allowed me to invite her, Shikha Porwal. She is one of our senior advisors working in customer engagements. Good to have you.
Hi, Shikha. Hi, Matthias. Thanks for inviting me and thank you for the introduction.
Yeah, I want to leverage your experience because you're working daily on the ground with our customers and we want today to look at an important part that always sounds a bit dull and boring, but it's so important when it comes to steering and controlling and improving your identity and access management. We want to talk about KPIs and KRIs, so key performance indicators, key risk indicators. The main thing is we want to measure IAM and want to improve based on these measurements. From your experience, why is it so important to measure the effectiveness of IAM?
Well, when we talk about the effectiveness of IAM, usually there's a lot of budget put into it, but so when we see from the traditional practices in advisory, people do not realize where this budget has been spent. Well, there are a lot of traditional metrics, especially in regulated industries that have been there for quite long, finance, healthcare, because they are highly regulated and in order to meet compliance. But when we talk about other industries, they might miss the point because the user experience might be quite important to them.
And of course, cybersecurity is becoming more and more important and part of the overall strategy of a company. So in order to know where your budget in cybersecurity has been utilized, in order to know how well your security is, how good your posture is in terms of what is the visibility you have on the entire attack surface, and of course, there are other benefits like productivity gains and being more reactive rather than proactive. So all this together makes the measurements of various KPI and KRIs quite important for IAM.
I think the list is quite big, but just to very quickly summarize, I would say that there are many benefits to it, especially knowing the security posture of your company, user experience and operational efficiency, something I would put on. There are a lot of buzzwords around like outcome-driven metrics, zero trust, and of course, these are important things.
But essentially, they're talking about having more visibility of how various technical and traditional metrics can align with the business value as well as to move towards a more proactive approach towards security and IAM in general than being reactive. So I guess that sums it up. Exactly. And I think the more that the IAM team gets out of the machine room and does stuff that nobody sees, and the more visibility they have, I think the more it is important to just make transparent what you're actually doing and where you're getting better.
When we look at the terms, and I've mentioned them very quickly in one sentence, KPIs and KRIs, sometimes you can look at them from – it's the same thing from a different dimension, but it's not. So performance is not the avoidance of risk, etc. When you describe KPIs and KRIs and their usage towards your customers, how do these two differ? And how do they add value to the IAM program in their individual roles? That's a very good question. In very simple definition, when we talk about KPIs, it's a big umbrella and we generally try to see the various performance metrics, performance scores.
But when we talk about KPIs, it's more like an early warning system. We are talking about how you can help anticipate and mitigate certain risks, such as segregation of duty violations, a knowing number of orphaned or unauthorized accounts, and things like that. So usually KPIs help define a lot of goals when we talk about IAM specifically, like MFA adoption, volume of password resets, coverage of application or assets under IAM. But some of these goals can also be very security specific or have an underlining security message, which helps also give an idea of the risk related to it.
And this is where you can say, okay, the KPIs entered into the game to essentially avoid incidents. So we have a lot of, for example, Martin has mentioned in his previous podcasts or talks that essentially KRIs could be a small subset of KPIs.
Well, you could also say that, but of course they're looking from a more risk based perspective. And we see this more and more now because of the upcoming regulations. So you can say that, but essentially KRIs are also something that every organization roughly already has defined. And you have then the IAM metrics that also talk about a lot of risk factors, and then you try to link both of them. And this is where you can integrate both KPI and KRIs, and sometimes it's just a one-to-one mapping.
So essentially to just revise that, KPIs are any performance metrics or score around IAM, specifically talking about IAMs, and KRIs are more like an early warning system, which is also sort of a measurement in terms of security performance, let's say, to see if you can anticipate any threat. That's interesting. And in German, we have the saying, do something beneficial and talk about it.
So really, that is, I think, also often the idea behind KPIs and KRIs. On the one hand, of course, proving efficiency because somebody asked for it. On the other hand, having this transparency driven by an IAM team, I think it's also really important to say, okay, hey, we have improved the number of or reduced the number of orphaned accounts from, I don't know, from very much down to almost zero, and we healed the process so that there are no longer new orphaned accounts there because we have finally managed to get our lifecycle management into order.
I think that's an important thing, but that does not mean that everybody running an IAM can now start and say, hey, let's make it transparent what we're doing. Are, from your experience, prerequisites for making such a KPI, KRI-based approach and for being successful in that? Funny that you mentioned this example about reducing orphaned accounts. This is something, okay, IAM or security specific, but what does that mean for the business? So this is where you now see how KPI and KRI-based framework in IAM can, there could be successful adoption of KPI or KRI-based framework in IAM.
So when we talk about orphaned accounts and reduction of orphaned accounts, what does that essentially mean for a business? It means that the risk exposure due to accounts that are just not being used at all is reduced. So overall, you're improving the security posture of the company. And this is quite important, again, directly linked to a risk indicator.
So when we talk about different prerequisites of successfully adopting such a framework, quite important is the strategic alignment, which unfortunately we have seen not done in the past, especially with really old organizations that organically start IAM as technically essential functions, which are coming from different departments and then growing into many different technical things.
But since security is a very important pillar when it comes to a company's strategy, these traditional technical metrics coming from a very traditional, technically organically grown, let's say, IAM team directly do not translate into the business's big picture. So if you tie IAM's visions and its objectives back to the business goals, that is something that is a very good way to, first of all, create a good basis of having such a program.
Second thing would be to define accountability for IAM, which is also sometimes a problem, especially when IAM is a team that comes later and has now been, in banks and all, you have seen that long back, but still IAM as a team is also not very common in a lot of the other industries. But having an IAM governance board which could closely be in communication with the security team or ISMS team is something that's quite good. That takes me to the next point, which is the communication channels.
If you have a well-defined accountability for IAM, then when it comes to reporting or any contextual interpretation of metrics, well-established communication channels with other departments just makes the collaboration easier, and then sort of working out a solution or trying to resolve any sort of a trend becomes easier.
But now we're already talking a little bit ahead, but the most important thing would be to actually have a baseline IAM maturity, so just IAM processes which are administrative, joiners, levers, and certain standardized policies and controls around, for example, authentication, this is quite important. And then this tied with an already existing risk and control framework makes it very easy to map IAM risks to the corresponding KRIs.
Risk and control framework is again something that is well-established in very well-regulated industries, but could be loosely defined in other less regulated industries such as e-commerce or so. So in short, before adopting such a KPI or KRI-based IAM, organization needs some clarity on the governance, some mature processes to start with, reliable identity data, asset data, and then all this. It's the best if it's all is aligned with the business and risk objectives of the organization.
Right, interesting. So first of all, you need to really know what you actually want to measure and what you want to make transparent and what you want to prove in the end. So it's really, first of all, do the alignment. To get to another aspect of this, if we look at the areas where one could actually find good examples and good demonstrable kinds of KPIs, we've mentioned the access governance part, which is always a bit more dull because we're just improving security, which is nice. Security is at the core of coping a cold, but difficult to demonstrate.
So again, the number of offhand accounts, business doesn't care. Cybersecurity does, but it's not a good story to tell. Where would you see two areas where good examples of KPI can be found and where you can really prove efficiency, just as an inspiration for those who have not done yet? One example I could give is probably some, we can talk about onboarding and offboarding. Essentially, onboarding is when there is a new employer or someone changes contracts within the company, so they have a new identity or a revised identity.
That's when you onboard a new employee to the company and offboarding is when you're letting an employee go either to another department, to a transfer or just quitting the company. So these are quite good risk signals as examples. So when now we talk about how can these be translated and what do these tell us? So if there is delayed onboarding, so that means if, and this is measured probably in terms of average onboarding time, a delayed offboarding just doesn't look inefficient.
It's not of course saying that the operational efficiency is low, but it also increases the attack surface because you're leaving a lot of unused orphaned accounts active, which are then open for just a great invitation for a lot of attacks. This is one example where you can map these indicators directly to risk dimensions and they are already also talking about operational efficiency, so that is another factors.
When the average, if you look around the other way around, if there is a faster offboarding, that means there is reduced insider threat risk and this is directly then linked to efficiency and security. If you see in a company, how can that materialize? You can already set like a range of what is considered a good average time for onboarding and if this sort of deviates, then that means there might be some problem either efficiency-based or definitely security-based, so that is one example.
Similarly, faster onboarding also indicates productive gains and user experience. Could or could not be related to security risk, but then it again directly ties to business and operational targets of a company. What else? I think helpdesk metrics are also a good way of measuring user experience and IAM maturity. For example, if you have a lot of MFA-related, multi-factor authentication-related tickets with the helpdesk, then that does talk about the gaps in adoption of the IMFA strategy.
It might not be user-friendly and maybe people are bypassing that or trying to look for other ways to log in. It could also be seen as a risk because people are not using the right methods to make sure that there is high level of security and they're trying to bypass it. It definitely talks about the risk of productivity, adoption of security. These are some things that you can see how user experience and security in different departments are directly linked to an organization's risk. I hope that roughly answers your questions. Right.
Also, I think especially this helpdesk aspect is something which is immediately perceived also by the customer, by the employee. They realize, okay, I have to go through helpdesk because this and that does not work and that's also a perception thing, so that might be right, that might be wrong, or it might have changed in the meantime and I have not realized because I haven't been to the helpdesk in the last two weeks.
If you have transparency there, then you can really say, from an IAM perspective, this access request and approval and assignment and provisioning process just went well and nobody noticed because you had not to go through helpdesk to have it fixed. To tell that story, that is also something that you don't only tell to the management, to cyber security, to the one who has the money for the IAM and pays for it, but also to the end user and sometimes it's good to have them on your side and to tell them, hey, we're really getting better. End users are essentially an entry gate as well, right?
Those are the people if they do not have the right knowledge or the right means could fall in a trap of various cyber security attacks and also if they're not able to log in, it also talks about the productivity issues within the company, which is essentially a big budget. Your employees are just wasting and trying to log in as well and trying to get the work done, so it does talk at multi dimensions.
So not just security, but also something that is quite an indicator when it comes to helpdesk data and MFA data, for example, a great indicator for various dimensions of the business strategy and the goals of it. So I think helpdesk is something that should be given way more attention than now. I think in e-commerce, it's given sufficient attention, but when it comes to internal employees, I think it could definitely get better.
And when we do a presentation about the benefits of IAM, so really you start this presentation, we have a slide with the drivers of IAM, and I think exactly these drivers are the ones where you should apply the KPI. So we talked about efficiency, so throughput, we talked about governance, we talked about the aspect of really making things more secure, more compliant to the requirements that you have. Let's talk about business enablement. So when we talk about business enablement, there is another group of stakeholders, and of course, I'm thinking of those who build those new solutions.
I'm talking about the developers. Can you measure their quality, their enablement, their use of IAM as well to really also show effectiveness and efficiency there?
Yes, actually, that's interesting. It's emerging as a crucial dimension in IAM measurement, and very simple. To put it simply, if IAM is hard to integrate, developers bypass it, and this definitely leads to security gaps. And now that all organizations are shifting to a digital platform, developers are becoming the frontline users of IAM. If there is good enablement, then of course, there's faster innovation, there's less shadow IT and shadow identity management, and then the applications are just secure by design.
So some of the metrics you can see in this area is how fast is the API adoption, how much time does it take to integrate IAM into new applications, and how easy it is for developers to embed security-related or IAM-related policies within the infrastructure. This definitely, I think, developers and enabling the developers in terms of being able to implement IAM and be able to integrate IAM solutions with all applications and with the entire IT landscape is definitely quite important. And this then shifts IAM from being a gatekeeper to actually the role of being a business enabler. Exactly.
I think maybe one for us, first of all, thank you very much for these insights and really to cover everything that is important for your organization. That is maybe a good starting point to say, okay, I won't measure something that nobody cares of because I'm getting better there. That is not a value in itself. The other thing, maybe a final thought from my side is actually that KPIs are not built in stone because they need to be changed as well. Right. So they need to be adapted.
We did a range of episodes in the last weeks around the changing landscape of identity when it comes to non-human identities, however you call them, machine workload identities. And you talked about, or we talked about developers just now, the landscape is changing. So KPIs and KRIs need to adapt to this change to make sure that you not only change your landscape and adapt to it, but also tell the right story to your stakeholders when it comes to measuring effectiveness and risk mitigation in any area, especially, of course, in such a crucial area right now, like NHI is.
So making sure that these identities are under control as well, that's important. Any final thoughts from your side before we closed on? I think this was really an important session because it maybe gives some inspiration how to just demonstrate effectiveness. I think KPIs and KRIs are quite boring a topic, to be honest, but it is getting ascension and ascension every day. And when you actually explore what each of these metrics mean, then it's quite interesting because they expand the level of visibility.
So trying to translate them from a very technical terminology to what it means in terms of the business is quite important. You mentioned NHI, which is also, it has been there for a while. The terminologies are changing, but the KPIs around it are still something that are not implemented quite widely, unfortunately. It is getting there, of course, and people should know where these non-human identities, these various service accounts, who is in charge of them, if they are in control or will they take over your organization in the future? I think that's quite important a topic.
And I think if you look behind or read behind what each KPI and KRI means, I think that could definitely lead to a much more highly operational, efficient, and as well as just not security, but also highly productive work environment for any company. Right. And I think you've mentioned that I've said it as well, but the way that you explained it, I think KPIs are not boring. So if there's anybody out there who is really interested in getting better there, yes, of course, this is the commercial break. We can help you and Shika can help you.
So that's something where we really can also support organizations because it's embedded in an overall IAM fabric and an identity fabric to have the right things in the right controls in the right place and to continue from there and then getting to improvement. I think that's also really woven into the overall identity infrastructure that you're running. When you're doing that well, you can prove efficiency and that's what we do. Thank you very much, Shika, for being my guest today, for explaining this not so boring topic. I think really showing efficiency is always good.
So I think that's nice. I said it myself, but getting there to show efficiency might be quite a stretch to say, okay, these are my KPIs, these are my KRIs and continue from there. But you've expanded. How do we get from business targets that really make sense to goals that need to be achieved in KPIs and KRIs and reflected in them? So that's it for now. Looking forward to having you soon in another episode. So I really want to have more episodes around real life. So it's nice to talk about NHI and the future, but real life IAMs are as important. Thank you very much. Thank you.
Thanks, Matthias.