Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor with KuppingerCole Analysts. My guest today is Dr. Phillip Messerschmidt. We want to have a discussion on the EIC that's just been executed last week, a few weeks ago, and we want to learn more about how it was perceived by Phillip. So welcome, Phillip. Hi.
Hi, Matthias. Happy to be here. Great to have you.
And again, this is the first in a series of episodes that we're doing, and I will ask more or less the same questions to three of our participants. In the last years, I did this with Martin. KuppingerCole is a much bigger team, so let's do it with a broader view and looking back at such an event like the EIC. I hope the audience, they all know what EIC is. So we had 1,200, 1,500 participants on site and online for four days in Berlin at Alexanderplatz, and it was really a buzzing event. If we look at EIC from your perspective, you've been with me and with us for the whole week.
What was your personal key topic and your focus during EIC 2025? Why did that stand out, what you were looking at?
So for me, my personal key topic was really to meet old friends, to meet the experts that are usually just remotely available because they are joining basically or joining the conversations from all over the world. So it was good to see everyone in person and discuss the topics freely with them.
Also, people on site had much more time to discuss the topics, so we were diving deeper and deeper into the content that I like. So from a content perspective then, I focused very much on the authorization topics, so modern and dynamic authorization is a topic that I'm very interested in. And I have discussed that a lot with the others, for example, from the Auth Then Working group, but also on a more basic level with a lot of other people. So not just the high-end content of authorization, but also the basics and how it has been done in the operational world.
So really transferring everything that we learn as analysts into real life to really translate that into processes, into systems, into architectures. Why especially authorization? I know you come from a regulated origin, you have done large projects within financial institutions and authorization is important there, but it can improve?
Obviously, it can improve. So one of the most important statements that I've heard at EIC was made by David in his presentation Thursday morning, I think. Authentication is mostly a soft topic while authorization is not. And when we think about that and with a look at today's business or the daily business in general, you can see that while pretty much every system has a lock-in mechanism and we have rolled out single sign-on mostly for most of the applications. We have rolled out MFA for most of the applications. Authorization is still a thing that is keeping everyone busy.
So managing access on a manual level is one thing, but when we think about authorization at scale, this is another thing. It adds much more complexity when we think about static versus real-time access controls in the authorization space. And with all these experts, I can talk about the real-time and the static aspects, the modern authorization here in that context, while most of the organizations are still struggling with the basics. So as an employee of Copingacol, I have the full insight.
On the one hand, I have the modern research looking more towards dynamic and modern authorization, that with the experts as well. And on the other hand, in my role as advisor, I'm talking with the businesses and their daily challenges that mostly are on a more basic level. And they are maturing right now in the direction of zero trust and real-time authorization, but they are still not there yet.
And building that bridge between the more operational challenges-driven authorization approaches and the modern authorization approaches that come from the analysts and the experts that are developing that, this is a really interesting task. Exactly. And I think that's also the beauty of such a conference, that we on the one hand have these forward-looking, future-facing topics like NHA, of course, like AI and IAM, and much more identity-centric security.
On the other hand, there are these bread-and-butter topics where people are still struggling with the sheer basics of identity and access management to achieve compliance, to provide proper governance, and to follow all these regulations. I think this dichotomy is still there, but it needs to be there. We have to focus on the modern topics, but we have to provide best practices, guidelines on how to do things properly, even from ground up. Which leads me to the question where you contributed to that event. You did a keynote, I know that. We together did a workshop.
Maybe you can elaborate on that a bit. So the workshop was also, again, on one of these approaches where I say, I mean, I was just talking in the authorization space about the daily challenges, the daily business, and how to bring that together, the modern approaches and the daily business. The workshop was especially focused on that. So what we do as analysts, we think about the identity fabric and the reference architecture, two of the major frameworks of Kupfering and Co.
But the challenge is that these frameworks are very theoretical, at least that's the perception of most of the people that don't work on a daily basis with these two frameworks. So the idea of the workshop was basically to explain to people how the frameworks work so that they get more familiar with the frameworks. And we did that already two years ago. What we missed two years ago was to explain them how to utilize these frameworks in their daily business. And this is what we did in the second half of this year's EIC workshop. We focused on operationalization of these two frameworks.
And we did that with three different perspectives. The first one was how to use it for different identity types and how the reference architecture changes for different identity types. The second perspective was on how to use the identity fabric and the reference architecture for improving on a strategic level, thinking about the status quo, how to get to a target state, how to derive gaps from that. Based on the gaps, how do I derive action items and how do I use the action items and the details in the action items to tailor a company-specific roadmap.
And the last of the three operationalization topics was about really going into the operational challenges. So when we think about the two theoretical frameworks, there's always the challenge that the operational experts say, this is a nice strategic theoretical framework, but I cannot use that in my daily business. So the last of the three approaches was really showing, okay, how can I use the high-level framework to drill deeper and to get structure in IAM.
Using it, I used an example to explain it based on the join-up process and show the deficiencies that we just made up for that example and how to use the structure and the capabilities of the reference architecture to analyze a join-up process, to identify the challenges and to resolve these challenges in a structured way. And these are the three different perspectives on operationalization of the two major frameworks of Copenhagen Coal.
And the positive feedback that we have received was interesting because many people came to me and told me, hey, that's exactly the challenges that we have, the pain that we feel. This is a good explanation how we could use it and tackle our daily challenges. So I think the workshop was quite successful in delivering that message that this is not just a theoretical framework, but also an operational method or instrument. Right. And especially because it's nothing that requires us to be in these efforts involved. We can do that, but it's not what we were talking about.
This is something that we give away freely that everybody can use to have a common language, to have this way of discussing with stakeholders and in the end also creating based on that the architecture that they deploy for their organization over time and evolve it. And so it's really something that I also received as feedback that this is really usable and in the end also well understood and the videos are available. So if somebody's interested in this, just head over to our website and this is possible to watch afterwards.
Now you've explained how to understand the frameworks, how to operationalize these frameworks. This requires money and funding and budget. That was your keynote, right?
Yes, that was exactly my keynote. So in the first workshop, we've learned how to use the material. In my keynote, I explained how to sell that material to the sponsors and how to convince them to give you the budget to do that. The focus was mainly to remember some foundational knowledge actually. So something that we all know, but we might have forgotten in the meantime. The idea is really to talk to your sponsors and how to talk to your sponsors and convince them. So to convince somebody, you need to know what is his or her main driver for whatever he or she is trying to do.
For a sponsor, that means that they are driven by something. When it comes to IAM, we have basically three main drivers that are efficiency, security, and compliance. And depending on who your sponsor might be and in which industry they work, these drivers differ. So based on the industry, we can see that, for example, efficiency-driven industries like a retail company or sometimes a manufacturing company, they are not that regulated.
So they focus on operational efficiency, while other industries or organizations like the banking or finance departments or in general, the finance industry is more focused on regulations and on risk. So their decisions, their sponsors, they will focus on risk-driven topics, on regulations-driven topics. And this is how you can try to convince your sponsors. Focus on what they feel is most important. Try to speak their language. Sell them what you need by giving them something to identify themselves with. This is basically the idea.
If you have a more open sponsor, you can also try to raise their awareness for the other drivers and convince them with all three drivers. But most of the time, at least from my experience, you focus more on one driver and convince them with that. Right. So we and you shared also the experience that you gathered over your time, your tenure as an IAM expert. And as you are an expert, this was not your first EIC.
Maybe as a final question, although it was not your first and you really contributed to a lot of our events already, was there something that stood out to you that was, I don't know, fun, energizing, that you really remember that you didn't expect at EIC 2025? I wouldn't say that there is this one moment that was outstanding. I think the event in general is outstanding. So what we have seen this year in EIC, and that surprised me a lot, is in the past EICs, we have seen like two or three or four trend topics across the agenda.
This year, Martin came up in his final keynote with 10 different trending themes. And this is basically three times as many as last year or two times depending on how you calculate that. But it's much more than last year and the years before. So what we can see right now, and this is a major takeaway for me, and IAM is getting much more complex. It has much more to offer when we think about that. In the past, it was, okay, a little bit of administration, a little bit of authentication, a little bit of authorization.
But this year, we are talking about different types of identity, different types of delivery methods, different kinds of topics when it comes to authorization. Authentication is still a topic. HI is still a topic. You mentioned that earlier. So there are lots of trending topics, especially when we think about the digitalization of our world. IAM is becoming more and more important. And this is clearer than ever, I would say. And this is one of the big surprises to me that also the executives of organizations start to recognize that.
So thinking about, for example, one of the major buzzwords, Zero Trust, people understand now that Zero Trust is basically impossible without IAM. So they are, now they are making their homework and get it done to get Zero Trust done.
Yeah, I leave it with that. I think that was a great closing statement, how broad the topic has become, how important it has become, how relevant in our daily lives it has become when you look at wallets at decentralized identity. That was a theoretical thing two years ago. Now we are really approaching the era of wallet-based decentralized identity authentication and authorization.
Thank you, Philipp, for being my guest today. I will follow up with two of our colleagues as well and let's see what they will focus on. So thanks for your insights, for your view on the event, and looking forward to talking to you very soon. I know we have something scheduled around that workshop again, where we will answer questions around the identity fabric and the reference architecture. And it gained that traction, which is good. Thanks again, Philipp.
Thank you, Matthias, for the conversation. Thanks for having me. Thank you and bye. Bye.