So, good evening, everybody. I realize that I stand between, well, this presentation and the drinks.
But still, I hope that I can give you some entertainment before you go into that. So today, I'm going to talk about moving towards a future-ready digital capability, digital identity capability, and I think that's important. One of the reflections that I have, sort of now being two days here on this event as well, there's so much things that we need to think about and that we need to talk about.
So, I'm going to talk to you about that. A little bit of a personal intro.
So, I lead the digital identity team for PwC across EMEA and I work with some of the larger clients that we work with and I work with the IEM teams, I work with CISOs and I also work with the boards. And I'm on a mission and that mission is that I want to create the digital estate and make that a little bit safer and so far that is not going super well.
So, I also hope that I can transfer a little bit of the ideas that I have towards you so that you can help me to get to that mission. About us, we are with 1,700 digital identity people globally, 500 across EMEA, and we are business consultants, we are architects, we are engineers, and we also do managed services for our clients.
So, I wanted to share that with you because I think it's important to realize that we're not just talking here about making PowerPoint slides, but we're actually in the trenches building digital identity solutions together with our clients on a daily basis. But let's take a step back.
So, let's first look at what are the market developments that many of our clients are facing. So, I already said we talk about this a lot, we have emerging technologies, we have increased risk, we see that the war for cyber talent and privacy talent is increasingly important because there's so many things to do and there's not enough talent in the market that actually is able to help us.
And not only that, the increased technology complexity that our organizations are facing are really important to start to drive action and it's not the complexity just in the digital estate but also, for example, from a supply chain perspective. If we look at the geopolitical things that are currently happening in the world, are we sure that we can continue and are we resilient with our business?
Then, we have increasing economic and also other threat actors that are looking at exploiting data or other assets of our organizations. And on top of that, we have in Europe, the EU, and globally also a lot of other regulatory bodies implementing a whole bunch of new laws and regulations that we need to think about and we need to adhere to. Personally, I'm happy with that. The reason because of that is that it gives us at least a starting point to think about what should good be looking at.
But the other side of that equation is that regulations always are at least four years behind the actual market trends because before market trends were being translated into public opinion and into regulations, you're already four years further. And last year, I spoke about cyber warfare and IAM and that's still a very hot topic but I'm not going to spend all my time on that this year. I want to talk about a couple of the threats.
So, we see if we look at our digital trust survey and our CEO survey that we do every year, you see that cloud-related threats, connected products, and third-party risk is still driving a lot of the convergence of cybersecurity and identity and access management. And I think that we spoke about this also a lot already today.
So, here you see in this slide, you see that cloud-related threats and the preparedness around that, there's a huge gap in combination with hack and leak operations, third-party breach, and attack on connected products. So, the OT environment is also coming into play. And just to illustrate that with a little bit of a number, which is not from us but from Microsoft, is that Microsoft is battling at least 240,000 identity-based attacks every single minute of every single day and these are the latest stats that they released.
So, it's really, really an important topic to think about how do we manage the future of our identity capabilities. But it's not only the threats, it's also about compliance.
And if you then look at how our technology capabilities, our CSOs, our IAM teams are confident with the capabilities that we've already implemented versus how the business is looking at it, we see that there's also a big gap, specifically around artificial intelligence, but also critical infrastructure in our organization or the ability for us to sort of understand what's happening through an ITDR framework, for example, and being able to also disclose that.
And that is becoming increasingly important, specifically because also these new regulations that are coming in, hitting many, many more organizations than what you used to have. So, almost every organization is now subject to certain regulations that are also impacting how you deal with identity and access management. And at the same time, the business is evolving, digitizing more, and digital identity and IAM is becoming the cornerstone of that success.
So, if you look at how can you position cybersecurity and digital identity as a competitive advantage, you see that there's many around customer trust. If we look at the voice of the customer report that we do, we see that 90% of the people, except in the Netherlands, because there we think that pricing is more important, value a company that is dealing with privacy over another company.
So, they're making conscious choices already in the market on sort of which type of companies do we want to work with. And that's touching brand integrity, but it's also touching how do you stay ahead of business disruption, making sure that you're part of that, that you're helping your public relations team to make sure that you're engaging in the appropriate way when things are happening.
So, being a cornerstone, that sounds nice, but what does that actually mean and what does it mean in terms of how do you then change and how do you orchestrate? We had a really good discussion earlier today with one of the clients that we're working with and he put it really nicely.
He said, so one of the things that we really started to do is we look at what are the things that we are, that we're seeing the business do, what are the business initiatives that they are going into, and how can we hop onto those waves and help them to ride that wave, and then making sure that the identity capability is actually part of that, so that we're actually leveraging that transformational change that is happening in the business to also transform our identity teams. And I think that is a really interesting and a good way to approach this.
So, we came up with a model to help to prioritize the right digital identity initiatives, and it looks like a complex model, but that's not really the case, because most of these things the organization is already doing, but there's not always a connection immediately with the digital identity practices. So, you see that portfolio management is managing where I'm going to invest in, what will be the return on investment, how do we organize ourselves around that.
And at the same time, the cyber team is already looking at threat exposure management, thinking about, okay, what does it mean for our exposure, bringing in threat intelligence to make sure that you can identify the risks, and do industry benchmarking to look at where is your organization in terms of maturity of certain controls versus your peers.
And if you then combine all of that together, and you put that into a risk analytics and orchestration tool, you start to actually think about how do we make sure that we are investing the identity capabilities that we need to invest in to, on the one hand, decrease the risk, but on the other hand, to also help to increase the operational speed of the digitization of the organization, or where we can really enhance the user experience, for example. So, that's where portfolio management and these things come all together.
And based on that, with that risk identification classification, you can start building a really good prioritized list of things that you need to focus on to bring you to that next era. So, things to consider, and I think many of those we've already touched upon in other presentations as well. But like I said, if we are able to quantify both from a threat perspective, as well as an investment perspective, what are we actually helping to bring, and we're able to show that, then it's becoming more easy to actually get the right investments organized.
And that's about regulatory compliance, it's about efficiency gains for automation, but it's also looking at the different elements of identity security and how you need to do this. Wallets being one of those, and so many of us look at wallets, for example, as a thing for customer identity related topics, but I believe that this could also be related really well in certain employee or third party related aspects.
For example, to take one example, is that normally when people onboard into an organization as a new employee, somebody from HR used to look at the passport, used to look at you, and decides yes, that seems correct. Then you are being entered into the authoritative source, nowadays that goes through email.
So, are you still able to actually understand that you're allowing the appropriate people into your organization from an employee perspective? This is where wallets can start helping, just to give an example. But it's not only that, we are also, as PDBC, we look at our digital innovation office, where we are looking at the trends that we are tracking, which we think that are important.
So, I think a lot of them have already been discussed. We have talked about wallets, we have talked about Kype, we have talked about zero trust and identity first security, we talked about ITDR, and we talked about Keem, which is helping to make also sure that the cloud state is going to be more secure.
So, looking at those trends, and what does that mean in terms of priorities for building a modern capability? This will be around cloud security and resilience, not only making sure that the identity parts are correct, but also that if something happens with the cloud that you are able to recover from that and being able to come back into business quickly. Gen and agentic AI, I think that that's a very specific topic that needs to be addressed in itself.
It can be part of non-human identity, but I think also that if you look at the threat actors, one of the challenges that you have is that with AI, the threat actors can scan your entire digital environment for vulnerability. So, if you look at our latest security review of 2024, we see that sort of the spike of how threat actors are trying to get zero day exploits organized so that they can actually leverage that. It went from zero day to zero minutes because they are so fast at exploiting these type of things.
Zero trust ITDR, I think how there's already been a lot of talks about that, and then the wallets and the SSI and verifiable credentials are the other topics. I think these are the things to focus on, but at the same time, and this is a little bit of a forward-looking thing, but looking back, we also see that it is very difficult to move to that new modern capability because of variety of topics.
So, we see a lot of tech debt that organizations still have, both on data integration, and I think that Ian also spent some time on this in his previous conversation, high maintenance costs, which means that you are using budget to maintain things that are already legacy and you don't get that budget or that capability then free to actually help you to move to a modern place. The risk of operational failure.
So, one of the organizations that we spoke to, we asked sort of, okay, how do you make sure that from a business case perspective, you can justify moving to more modern things? And some of those organizations justified this by just explaining, okay, but the amount of outages that we have because we moved to modern capabilities became less. And because of that, that's already justifiable enough because our business is not really happy when those outages happens. And the security vulnerabilities, I already mentioned that in the topic of AI as well.
I think that this is a very important concept in itself because I see that still many organizations have their critical applications and the critical infrastructure onboarded into their IAM systems, but not everything. Well, with moving to the clouds, the attack factor or the attack surface has increased quite heavily. And then in combination with AI means that sort of had the vulnerability is increasingly there.
So, we need to spend time on making sure that we are securing from an identity perspective, the whole digital landscape of our organization. So, then a couple of considerations, also looking at what does that mean?
So, the first thing that I really want to bring home, and I think that many of us also spoke about this, but I want to reiterate this, bring IAM under the merits of the CISO. And when I say that, I mean all of IAM under the merits of the CISO.
So, I see still many organizations that have their access management capabilities like AD or AAD sitting in infrastructure, IT infrastructure, or connectivity, or somewhere else. And that means that you are not capable to actually make sure that you can quickly respond to the threat actors that are trying to make leverage of those.
So, conditional access policies, it's very difficult to work with that. It's very difficult for the CISO team that is doing a red teaming engagement to then bring the data from that red teaming engagement back into the IT teams that actually need to do something. The idea of why these different teams exist are very different, because IT operations is there to keep the ship running, and security is there to make sure that you don't get threats, or at least that when something occurs that you can quickly recover from that.
So, that's easier said than done. How I want to frame it is that if you don't have your access management capabilities, or your AAD under control of the CISO, you're fighting the battle against cyber warfare with one hand tied behind your back. And that's not good.
So, I think that needs to change. The other part is, and I think that, so Ian I think really made a good statement just about sort of how can we reframe the way that we're thinking about identity and access management. But that also means that you need to revisit the way that you are dealing with your roadmaps.
So, I still see a lot of organizations that are working with annual roadmaps, or even longer, three to five year out roadmaps. The reality is that you cannot predict what will happen in the next six months or after.
So, you will need to continuously be updating your roadmap. And that's not just from a threat perspective, but also because of your business. And your business is continuously changing. And that also means that you need to think about what is actually my engagement model with the business.
So, putting it very simple, who do I want to be for my organization with my IAM capability? Is it a tech, centralized tech capability that we provide, and then the business can use that? Are we really going out to the business to ask them, hey, how can we help you to digitize? How can we do that smarter? What does that mean for the team that you actually have within your organization and within your IAM team?
So, do you have all technical people, or do you have maybe also some creative, forward-thinking extroverts in your team that is actually going out to the business and doing those type of conversations? And if you only have those, and you don't have the technical capabilities, sort of, how can you then manage all the technical complexity that comes around it?
So, I think this is part of the new setup that our identity capabilities need to start thinking about. And this comes not only to just the role that you have, or the job description that this is, but also how do you make sure that you have the right personalities in your team, so that you are complete, diverse, and making sure that you are covering all of the basis because of all of the different things that you need to think about.
And then, last but not least, address technical depth as fast as possible, because I think the way to unlock value and to start helping the business to actually create more value, that's where you need to focus on. And that means that you need to get rid of your technical depth as quickly as possible. And that could mean augmenting on what you already have. It could mean throwing away some old stuff because it's just too difficult to maintain, and bringing something new in.
That is, for every business, it's different. But I do think that if we look at this from a cloud perspective, where the cloud vendors will actually help you to become more resilient, and through DevOps, and making sure that you're using APIs, and you're also allowing the business, who, when I started in this business 15 years ago, did not have anything that they understood about identity.
Now we see that a lot of our client organizations, business teams, that are developing actually the applications or the business processes in the IT department or in the business departments, they're also digitally savvy. So how can you actually let them help you as well? And what does that mean through API security and DevOps modernization? Which room can you give back? I think that these are the things that I wanted to give you to think about when you're either on the rivers pre-cruise or doing a drink. Maybe have a chat about it.
I know it's not about standards and those type of things, but I do think it is really important topics to think about, to work through, to look at if you're ready for your future. And with that, I want to thank you for your time. And if you want to catch a drink and to discuss this a little bit further, I will be somewhere out there in a couple of minutes. Thank you for your time and have a great evening. Thanks Ivo for bringing us to a very nice close. We have just one short question.
So as you know, everyone faces more or less the same threats, but not all organizations and all businesses have the same in-house resources and financial resources and so on. So the question here is, does your approach also work for small businesses? I think it needs to work for small businesses, but I think that if you look at how much of this do you need to build in-house, how much customization or sort of control do you need to have over this and how much can you actually ask, for example, third-party providers that are providing some of your IT infrastructure.
I think that that's where you can think about sort of how do you want to scale this up or down. And that goes beyond asking for a SOC 2 report at the end of the year, like, oh yeah, we're compliant, so we did everything right. So you really need to get entrenched in what is your IT provider that is providing your application landscape actually doing in terms of that support.
I think that there's a lot of ways that as a small or medium business enterprise, you can actually do to still think about these things, but leveraging maybe the capabilities from the IT service providers that you already have. Okay, great. Thanks. Ivo van Bielekom.