Maybe a short introduction again of all of you who are joining me here on the panel and yeah So my name is Mihails Galuška, and I'm really happy to support in some aspects at least your story and from the practical perspective I work for The largest insurance company in the Nordic countries, If P&C Insurance, as the global IAM product manager Thank you My name is Christopher. Today.
I'm here as the CISO with KuppingerCole So probably some interesting insights into how the company who is for instance running this conference is doing B2B Federation and its stuff and the challenges Patrick faced In his slides and maybe we sit down I hope you can see us So first of all if you had now the talk maybe or listen to the talk, you heard it Did you recognize any of it? Maybe also in your practical experience now where these issues you faced as well? Or what is your view on this federation? How do you started when I'm looking at your talk?
I see it's driven mostly by the Efficiency and how it can boost it also your security, but what is your view? Absolutely we I can say we have lived through Things you've shared here so and maybe we haven't covered everything But what was the absolute truth the first truth I've seen in this in the slides was that tooling is the starting point.
However It's in my story as well later, but it was the Our business was the most afraid of that part And what came as a surprise maybe more to them rather than to the IAM team that The policies and and the processes is the most complicated part today not the tooling.
Mm-hmm Christopher your view when you're hearing this and being responsible for the security Yeah, very interesting point because in reality You share that people organization processes and policies The reality and if you just think back the tools are there people use them and Hopefully there are some kind of policies in the past we took a lot of care of how an internal employee was able to access things then we got teams or Use Skype then have teams and people try to share information word document PowerPoint presentation, whatever whatever with others and without what you mentioned some kind of general agreement between these organizations and your beautiful animation and That is an interesting thing.
I mean just keep it a bit practical as I mentioned We are running this conference the presentation that is shared here the people in the background This is not Copica coal and they need to access to the presentations the speaker uploaded in the portal like you did and There is a lot of somehow Federation Ensuring that the information is there the governance that you only see your presentation don't see internal data and all that stuff and This is really something complex Which is in combination mixture like you mentioned from starting with boring policies Like don't allow anyone to access up to open it a little bit and then define some basic Set of framework like for instance, the internal employee is usually forced like yes, I've read the ISMS policy I will follow them forever This is happy if you sign the contract and if there is no controlling Monitoring even training.
This is worthless. Mm-hmm, and probably same applies here. Mm-hmm Maybe to ask in this direction Michalas in the topic of the Federation how he implemented then with the partner organization I was the thing is like when I was Thinking about all of these or when when I was assembling it I was always sticking with this trust trust and we see that the conference as a permanent thing where you're at some points Surprised how differently other organizations were doing it like I am Did you vibe also with the thing that I set you with the thing where you are assuming things?
So did the assessment also like cleared out that you were thinking? Oh, this is a it seems to be a quite mature organization But then you saw okay, they are quite mature, but not under our understanding or they do things just different.
I can say that I'm sometimes or Very much surprised about how different it is within our own Talking about partners even so because we we have established also the Kind of not control, but as guiding and supportive Process for assessing every new change or new Channel or system being rolled out or prepared for production where we meet and we bring all the experts from different areas to support teams and this is where we see a lot of inconsistencies within our teams and we try to align and the patient to to teach and to share our knowledge and set the The bar Across the company on the same level.
So and then we try to stretch it out to the partners That's the approach because but we have to start from ourselves first and this is a very important point I think when you started like with the building the tower and so on you have it already in your own organization, right? So you like the Federation we are now building outside the organization sometimes depending how you're building your orchestrating your Organization then also Federation can be a topic already inside your company if you are a group for example, right? Yes.
Absolutely and and and before you can Expect or demand something from the teams You have to set the rules and set the policies and and clearly say okay guys This is what we want and in order to do that you have to bring also legal team and everybody to sit down to have a Plane a number of workshops and and to define okay This is for example, like we have this we call it authentication instruction where we define what this level of assurance for us level like one two three and Not only saying okay.
This is this should be like I don't know bank ID, but How does this relate to the data which we exchange? So that's important point as well And and it's not always possible to tell even if you know what the data will be because sometimes it's just General principles you have to follow. Mm-hmm. That's one aspect another aspect of this is even when you define the policies Okay, we want to be here Life is is different.
Mm-hmm, and we can't jump straight away. Yeah, and and and also to refer to your to your Presentation it's more of a risk based approach because even if something proposed or suggested by the team Okay, let's do this. We it doesn't really match. Yes the level we we expect But it is anyway better than we have now. So let's go for it and let's take next step later So that's that's how we practically implement it.
Yeah, this reminds me a bit about the Cyber security framework from the NISTIA you all have the organizational profile and just doing one step at a time Yeah, not aiming for for the stars and so on but to have like steps you can achieve and not shooting for the stars Yeah, okay. That sounds pretty Well, or yeah vibes also with me Christopher maybe in your direction like seeing it from the overall Information security perspective. My question is like with I am we are very special topic within information security as it is like spa.
Yeah expanding into also other areas and How would you say when we are talking now about this when you're thinking about data classification and so on talking about cross organizational? Collaboration Do you see also this movement in other parts of the information security like assessing your partner? Organizations not only with I am but also what comes beyond in terms of information security So I would be interested to see your opinion how in general when we are lifting it up to the information security in general How you see the collaboration also with other organizations there on this level?
Yeah, you had one important Abbreviation on your slide the ns2 Which is something many organizations maybe also in the audience special finance regulated or industry is dealing with because they are forcing us to Verify what the supplier is doing there on one hand. So it's not like I mean, it's it has good good sides and also bad sides It's difficult because you need to monitor a lot of vendors or suppliers in that case You need to ensure that they do in proper information security management system.
They are certified I mean in general the idea of for instance an ISO TSX or whatever you have was like, okay I trust them now. We need to also verify this on a certain level.
Do they have an Proper business continuity management or all everything depending on what you mentioned The risk appetite of your own organization combined with the criticality of the information you want to access and You mentioned that at a point of time when you decide, okay, I want to collaborate with or federate With a specific company for that purpose then maybe you have like internal classified classified data and not confidential or top-secret and Then you work project is done and half a year later There's another project and suddenly you talk about top-secret information.
That is for instance something we as coping a call Do if you do advisory stuff? We have this very often but we are done the supplier in that case and if you then don't do and regular review and Ask yourself what you mentioned exactly. Is there some change in this process?
So it's everything also about in In my introduction when I said like, okay having a policy assigned someone very nice, but that's it you need to review it and the next service you need to monitor that and Going back to the b2b federation cases This is getting complicated because sharing to someone is too easy sometimes I mean for sure if we keep an example with teams you can flag them with a tag with a identity as information security label Confidential define specific roles like okay not allowed for sharing you can do that But honestly how many organizations do have a really good implemented?
for Information classification program for everything.
I mean you sure you define in the policy everything what is not defined as per default confidential awesome Everyone who laughed knows For Sure, there will be some this is under topic artificial intelligence that helps you to identify Data leakage prevention and so on and this is I think when we go more back from policy like technically enforcing them Monitoring and things like that, which will really become important in the future But comes at the end back to the risk appetite whether I accept I'm maybe not 100% compliant to a nice to or accept some a certain level of Loss of data information Yeah And what?
So I have something in mind that I want to share you also on this The thing is like also to make the thoughts and I hope I transmitted it with the talk and I have to stress it again You have to make the your thoughts you had around it before the audit comes, right?
If the audit is there and then you start and the auditor asks for the proof and so on Say I have to first find out how the other organization is doing I am it's not a good answer Yeah, you hope I hope you have the the breath to are to talk that long that the auditor forgets its question But this is not always the solution Yeah So this is what we also can I think extract you that you have to really?
Think about it first before you can answer these questions another question I would have here in in this regards is when you are now Or have you ever undergone like from your perspective any audits where you already were validating if it works as you have Intended. Yeah, so did it work out?
Well, did you have did you see? Maybe gaps also from your perspective when the auditor then really came. So how did you include them in the discussion? How did you include like for example the regulation into your framework? Can share any particular experience but but like more generic thing is that the good friends with the legal team Because that helps a lot That's just a very general suggestion on that side because really I can't I can't share any any experience.
We don't it being audited and and as you said on the early stage and and that what makes sense a lot and We from our side promote them and they promote us internally very much So that that this kind of support is very helpful to prevent any any issues Being audited. That's that's absolutely correct. Let's say Thank you. And that what goes along with this is like when you're looking now a bit further So the thing is like we were talking now a lot about how you as organization define the trust the trust framework and so on We're looking at the NIST definition of it.
They see like trust framework as yeah a network of Organizations. Yeah that agree on something and you can create mutual trust. So yet not assessing Just one-on-one, but you have a network because they are all following the same standards Do you see from your perspective that goes in both of your direction?
Maybe how you can start Do you see this already evolving in this direction that you see like when you are exchanging with others is like the insurance branch in in your country like going and First of all, we operate in multiple countries and from our business perspective I will I can't say we're very much interested in having everybody Talking to each other because we believe having Federation with partner is our competitive advantage because we want to because Our partner for example, let's take those who distribute insurances they have like eight nine ten Offerings from insurance companies and on their desk when the customer comes we want ours to be paid first So therefore we are interested to become the most convenient partner for them The easiest and the final that the best So therefore if everybody is connected with everybody we lose this competitive advantage in this case in this particular case, okay So, okay.
Yeah, so in Germany We have it a bit different with a by process and so on in the financial industry or leasing insurances But yeah, I understand your point. So but this also then means in the consequence. It's a strategic advantage Selling point in your country. So we see it also gives you a strategic advantage and this is quite well Christopher Do you see or like we have talked talked about t-sex or you mentioned t-sex?
Of course, do you see like this also in other areas?
We're like this trust for make also evolving Similar things or also your opinion on t-sex is how treating this I Have a very special opinion about t-sex, but maybe that's too much for this round here I mean t-sex was Maybe I share t-sex was or is mainly I don't know who Everyone is aware that is for the automotive industries and the suppliers set of Standards that you Need to implement and ensure to auditors depending on a specific assurance level Whether you can access confidential Prototyping data information stuff like that Because automotive industries like you mentioned they don't want to collaborate But they also working with a lot of external partners in production process.
They have external partners and that's the insurance The ISO on the other hand is usually also so 27,000-001 like okay. I have an isms.
I have policies and I accept risk That's more or less the foundation and the understanding of the t-sex guys, I mean the truth is somewhere in between Now the new standard ISO 42,000 or one or 40,000 regarding the artificial intelligence comes up Well, there's another standard and what I currently see so from the Caesar perspective Depending on the organization you work with whether for instance Financial industry where we're working a lot with it's really a mess because everybody is auditing by themselves and you have to do a mixture of from effort perspective like in t-sex ISO certification every half a year or sometimes Once a year with all companies we work together and that's not a benefit because there there are currently some beginning of having some kind of tool support and Basic stuff but currently we are in that phase of the NIS to that they need to take care of their supplier And ensure their security and that's what they are focusing on and working on and they have to Some of them are more into Dora and in that topic and it's really a lot of effort filling out Different kind of questions was was the same answers.
That is the current state I'm dealing with and I'm really looking forward into getting this better done more efficient. Maybe with AI Okay The thing is so maybe to the audience. Do you have any questions in the meantime evolving or want to share? inside sorry Today, I'm not falling just the phone so any Comments from your end any questions you want to raise the audience?
Yeah, of course Hello Just from technical side of things I mean is what you were talking about like establishing a framework that all the partners could plug into it's like central point instead of like point-to-pointer So from a technical side of things it's possible to do with the saml because saml and OAuth are two technologies that enable a federation and like you can establish Federation with like a Federation agreement and everybody who complies to that agreement is welcome and then you trust that Federation and not But in terms of OAuth, which is like more used protocol today It's not as far as I know it we're talking about it's not possible yet.
So so there are technical Obstacles probably of achieving something like that. What was just a comment? and that's really the thing so when we are start to I Think it's the the story of our lives here at consulting or advising on I am so whenever you have a tool you or standard or whatever you can use to To accomplish your targets you have to think first about what is the target that I want to achieve? What are my requirements and then to think what is the technology behind that could?
Support it and wherever you have to use a particular standard, but cannot use it on the technical side You have then to find other opportunities or other solutions to do so maybe on the organizational level And this is what I wanted to show there so when we have not only the tool aligning with each other the things that I cannot automate like the the governance the The controls that I'm implementing here Maybe on organization level have to fill a void that is created by the technology behind it So that would be at least my comment here.
So but that you still cover your The full stack your requirements, but if the technology is not able to do so then you have to find other ways Yeah Yeah, yeah, of course Of course to take the technology with and to be aware what it can deliver and whatnot But also to shape it from the bigger perspective.
I don't know if you want to add anything here Yeah, I mean that that was a good example and you need if you go back to the policy perspective You need to define some kind of standards and then maybe also some kind of rules that for certain application or out If this is a risk in that case by not having enough Governance on that that you don't allow it for a specific kind of information But this is coming back to what I said You can write this in a fancy policy and no one will read that then we are back in you need to monitor that Or in the worst case you need to prevent it, I mean In reality, we all know that from my daily business All this artificial intelligence LLM stuff.
I'm not even that fast like checking what is going on and seeing What can be done with that? Is this this is this is a risk with that? But we are an analyst company I cannot say no. No one is using chat GPT anymore Gemini not allowed like some companies do so I need or we needed to define some basic rules What kind of information is allowed to enter there? Then you have DLP or DLP mechanisms and verify that you Protect as much as possible, but allow the guys to play around as well. And I think that's that's the thing here Absolutely.
I agree that you have to establish The environment for your teams to be able to innovate and look for like new things and Introduce new things because it's a matter of competition anyway, but your job is to establish Okay, this is the like boundaries. We have to respect Overall in many other aspects as well.
I would like to add something on the technology sense We maybe we should ask ourselves whether an ID central IDP and if you go for Federation or B2B Federation most of people are using enter ID Federation B2B and If a central IDP is the right point To establish these trusts because they are kind of a shared media And they are growing and if you federate a lot They're growing a lot in the shared media and is this right point to control things on the other hand?
We're all going for zero trust, which means never trust always verify and then we build a large IDP which is enriched by thousands of B2B users We should ask ourselves. Is this right way to handle things? I mean the protocols and the technology is good.
The interchangeable features are very good But what we are missing are borders and ways to declare borders Well, I can only agree because it's not also only About if we speak about this authentication services, for example, then it's not all only about having several factors in it So it's about how you actually implement things and I have my colleagues here who deal with and redo IAM assessments Every day many of them and and they find so much so many surprising things About how you actually implement it and can you really ensure that?
Yeah, everybody follows those practices And this is now the I think a very good point in it as along with another talk you hear it here Yeah about the decentralized identity because at some point when we are going beyond With a federation having it really on the road and starting to do it on a Very high frequency at some point you will it will yeah kind of Be too much for your organization that you can still do all the assessments and so on when it comes to a quick pace But then hopefully you have now prepared with the federation have defined what you're expecting and then maybe you are already Starting your weight through decentralized identity.
So maybe that a question also To to you here to Michal maybe also to your project when you were doing it Did decentralized identities were already coming into the play? Do they already play a role in some regards or are you? With the Federation's that are focusing to get this flying and to get this working in your organization.
I can't say we have any any Clear ideas about where decentralized identities can be practically used at the moment in the b2b Scenarios, but b2c that's obviously the case The question would be from from governance perspective or the stuff we discussed What what is the difference from having an federated partner that verifies? This is Christopher should say he's working I was hoping a call to compared to using and decentralized identity that I bring that I'm verified by government I'm Christopher should does this change the problems afterwards?
It will add another problem the governmental service will prove that you're Christopher should say but they won't prove that you're working at That's They can verify yes, we know a Christopher should say and he's working at Coping a call, but this doesn't tell me I'm in BW if Coping a call has a contract with in BW and if a service for the person called Christopher should say is included Yeah, it basically it basically could just help if you keep in the b2b to verify coping a call that I'm allowed to work with all the social security stuff you need to do and then we are back in Federation like Enbw for instance, let's keep it that is trusting coping a call which is by the way a good idea And Which then means my verified identity that I verified was an decentralized identity to my to my employee is trusted to you, but then we are back in the chain and Have the same problems About your contract with coping a call and my about your employment with coping a call and my contract Coping a call.
Otherwise, I wouldn't get the information And it Turns us back. We should maybe we should reduce the idea of the IDP to the plain Identification. I mean even if we were to federate with you with your company and we would accept the users In our case, you would see nothing because we have zero trust You know, we got a safe Christopher Schutze, but he can't see anything and he won't do anything It's just that we trust that he's an authenticated person. That's it Bringing the context is absolutely important as well.
Yeah, and and this at the end brings us back Okay, then we have an external partner with an federated identity. That is maybe accessing some project data in teams Because we use that example Is he allowed is he still working for us and then we have we are back in the basic internal employee partner management game somehow Maybe I should just point out in case some of you came here expecting to hear from a representative from Volvo unfortunately, he couldn't make it so that's why we've continued roll on but if We'll do this for a bit longer if there's any more questions.
Otherwise, we'll Could take an early break and then we have it. You're talking at 1135 so it's up to you guys The thing is if you yeah, if you have any further questions anything to add also, we are also curious to hear What are your experiences there?
Because I think as I said, we are having here a lot of Yeah ideas that go beyond the industry or beyond your business beyond the company beyond the borders But we are also fighting with these things and I hope that got clear with it Maybe with this a closing statement from from your and could get some free advisory A closing statement about this topic. Where do you see it evolving?
Yeah, maybe one sentence each of you in terms of identity federation. Where's it moving? from from your end from your organization I Think for us it's it's it's it's not the next question at least would be how to Maybe to enter also the customer space because now we're talking more about partners and in many cases We are very much interested in Getting customers also Tightly integrated with us also for competition purposes, of course for to be competitive and To extend our relationships, but also to bring the service quality to a different level.
I mean Commercial customers who have a lot of employees Insured and they need our services. And so that's it would be a totally different level. That's I think on the roadmap for us Thank you.
Yeah, Krista for me. It's I think it's depending on on the organization But but for us or general security, we have a stepwise approach with everything We cannot fix everything at the same time.
We need a proper level of maturity That is coming back to the risk appetite of the organization that you accept a certain level of risk And delivered it at the first place then you fix another thing Artificial intelligence attacks and all that stuff and then you improve that I really think as at the conference NH I is a very important topic Maybe there are similar similar problems like is this agent allowed to do whatever this machine so on Do they need real identities to the new technical identities or even just accounts and things like that?
Somehow combined integrated and on the other end not and then it's a focus topic. So it's I think in the next step is If for us we have something like like in for sure We have something like an ownership model for externals that have access review processes I think that is for now more or less sufficient.
There's always more to do I think the next step wouldn't be around when I said information labeling and stuff like it Really having some mature The foundation of how do I really identify the crown jewels that is critical to get access to I'm not talking about the static documents word like financial plans for the next 15 years more like the stuff in databases Even if in chatbots or things like that, and I think that is something It's from all ends getting better improving the level of maturity Thank you very much so with these words I would close it. Yeah.
Thank you very much for the chat and for the exchange I hope you got some insights something to start the conversations if you not have yet started in your Organization with your management and it gives you some ideas if you have questions. We also want to help you with this Yeah, so always feel free to approach us and we are happy to hear from you how you are going in this direction How you start your journey, so feel free to connect on LinkedIn or to chat here also afterwards Thank you very much and have a nice rest of the day here