Welcome Kami from ABB and Martin from Boehringer Ingenheim, who are the real practitioners here. And, as Warwick said, the topic is Implementing Real-World Cross-Company Identity Management.
So, before we start, maybe some quick introductions from the two of you. Kami, do you want to start?
Thank you, Martin. I'm really happy to be here.
So, I'm Kami and I'm responsible for Identity Access Management at ABB. So, ABB is a really unique organization where it's engineered to outrun to allow our customers to deliver services to our industry through electrification, motion, automation, and robotics.
And, it's a very unique space because we have four business areas and that means it's a perfect topic to talk about cross-company. Okay, great. Martin. Thank you.
Yeah, I'm with Boehringer Ingenheim, pharmaceutical company. Headquarters are here located in Germany, a bit away from Frankfurt.
Of course, we are also acting globally as a pharmaceutical company. And so, in my role as process owner for IDM, I can also tell a bit on that.
Okay, great. And, I think one element of the title is cross-company.
And, you both already said it's not sort of a single organization. In most large organizations, we have multiple legal entities. We have different divisions in different countries, different regions.
And, also, I think when we look at the M&A activity, which is very typical for large organizations, you probably also ended up in having some parts of the company that comes in with an own IAM solution. So, how do you understand the term cross-company and what are the challenges in handling IAM cross-company? Do you want to start with your perspective, Kami?
Okay, sure. So, well, I think one of the challenges when it comes to cross-company is recognizing that although it's one company, but there are many different cultures depending on location and history in terms of when the organization, like an acquisition, joins the parent company.
So, that would mean that they would have their own story, their own journey, and learnings, and pain point. So, at the same time, it's also depending on how the cross-company is organized. Although we are a parent company, there are a lot of infrastructure in IT, which is pretty much localized depending on region.
And, with that, the decision-making affects, as well, identity access management, because they would have a certain precondition in terms of how they transact with the parent company, and they want to apply the same for identity access management. And, for you, Martin?
Yeah, for us, it's a little bit different, I would say. We did not have that big acquisitions in the last years.
So, smaller ones could be done relatively easy. And, also, on our side, let's say the company is having, for sure, in the countries, different legal entities, but they are, let's say, more driven centrally.
Also, we have a global IT organization, and this then makes, sometimes, a bit easier to apply the identity management processes. So, Kami, how do you handle, then, your, obviously, a little bit more tricky situation, where there seems to be a little more autonomy in the organization.
So, how do you handle it? And, I think there are many ways to do that. There could be the approach of saying, okay, we have just relatively much freedom, or we try to put them into a core set of things.
So, where do you stand on that? So, I think it's really important to recognize which part of the identity capabilities is beneficial to be driven centrally, and what are the areas that you want to leave the decision-making locally.
So, take, for example, the join and move a legal process. Typically, with HR as an authoritative source, that is pretty much centrally driven, and you can set the policy, governance, and your processes quite centrally.
But, when you look at applying role-based access controls, then you wouldn't want to drive that from the center, given that the decision-making will take longer. You want that proximity with the business.
And, also, at the same time, through that model, you kind of educate them to kind of take ownership around the role model that is being defined for their particular business area. So, it depends.
And, also, depending on where the pendulum swings, right? So, you need to be sensitive in terms of the timing, whether you centralize that, and then, eventually, you want to decentralize to kind of allow more autonomy. Yeah.
So, I think, at the end of the day, with this challenge we even have at a more granular level, because I think when we look at entitlements and applications, then, clearly, it's always, what can we define centrally? What needs to be done by the application owners, which know their applications? How do we then reflect this again centrally?
So, I think what we, at the end of the day, have, also, from my experience, is clearly a need to define well. I think there's, depending on the organization, it could be more on that side or on that side, but I think we need to define well what is done centrally, where is it done centrally, and what is the degree of freedom we leave? And where are the no-go areas in that sense as well?
So, what just needs to be done? And sometimes, it's even that regional regulations play a role in that.
Martin, anything to add from your side here? Yeah. I think that, simply from the identity management perspective, we need to realize how the company is set up, how is the situation in our company, and, as you have described, then think on how to apply it best.
So, I think you cannot say a company should move into that direction. It is as it is. That's a board decision most times. You cannot change that. At the end, I believe, from my experience, there are different companies and cultures. As you said, I think the culture is a very important word here. There will be always a certain level of centralization and a certain degree of decentralization. It really depends on where you are. Just try to make it clear what is done centrally.
By the way, I had a very interesting conversation today with someone as well, which was about non-human identity management. I would better say workload identity management, where you have a bit of a similar challenge between IT, IT security identity, and developers. At the end, again, if you want to get a grip on that, it also means find a good balance and a defined balance of what is done where, who is responsible for what, and find an agreement. Talk with the other people. I think this is the same.
What I say many times is that a lot of trouble comes from not properly talking and getting them on board and explaining why certain things are done centrally or not. Let's shift a bit to the second part of the topic, which is how to make it a success or turn it around. When you look at cross-company identity management, what are your learnings from your own deployments, your own initiatives, on what others should consider to run it successfully?
Martin, do you want to start with that? Yes. Sometimes after some projects, you are then looking at the learnings, the challenges that were out, and you then were thinking, okay, why is it that way? Often it is said identity management projects are complex, and especially this morning when I was joining the workshop, I again realized, okay, what is the reason for that? Because in the workshop it was said, usually for identity management projects, multiple capabilities are impacted.
Out of that, I think very quickly you then deal with multiple stakeholders, and this is then getting a chain that brings the challenges here. I think good planning, what you want to achieve, is very crucial. You brought up our second part, stakeholder management. I think that is the second element of your response.
So, understand what you want to do and to achieve, and get the stakeholders on board. I think maybe to add, there are all the application owners you have to deal with at some point. And not forget the end users.
Really, to make the things user-centric, many times technical people are in the projects, and sometimes then the solution is thought much from the technical view, and sometimes the end user view is missed. So, that is very important. Very important learning. Just a story from the trenches. I once saw a project where we were asked to look at, and the departmental managers were asked to recertify SAP transactions.
So, are they correctly assigned and the trust didn't work? Because that wasn't really the end user experience.
Kami, what do you have to add here? Well, I think when we embark on any identity transformation program, we need to kind of have an outlook of three to five years, right?
So, I think as IAM leaders or enthusiasts or people in driving this in your organization, you need to think about that three to five years, and also understand that you are one of the many security priorities that's happening in your organization. And everybody is passionate about their own security program.
So, you need to be a little bit more realistic in terms of where you engage. And I think one thing which we're beginning to understand in identity access management is that we are operating in kind of a layer of defense. There are many different controls that actually protect that identity. And for the CISO, that's what he wants to understand and care about and not about separate security domain protecting parts of the organization. How does that picture come about?
And I do believe that the identity fabric that we spent a good two and a half or three hours this morning, the workshop really embodied to bring that to life, right? And if that is something that anchors in any identity program, you can kind of chart the horizon where we need to get to. And at the same time, a lot of different security initiatives would have dependencies. And you may not be able to go as quick because you have to wait for the guy at the back to kind of get through the line.
As such, it is critical to have that big picture thinking of three to five years to zoom out. At the same time, kind of address the key risk that the organization is experiencing. And this is where the engineers and the technical guys does really well, right? So I think that is what I would have experienced. I couldn't agree more because I think this is really the point that you understand which of these many things you could potentially do are the ones which are of the utmost importance. What are the gaps? Where are the things you really need to address? And what are the things you can ignore?
And even within identity, my learning is don't do too much at the same time. I don't see many organizations where I could envision that they are capable of running a large IGA and a large access management or PAM program at the same time. They may overlap because they may run a certain time, but really start with a focused approach. And sometimes, by the way, for waiting, you are in a lucky situation.
You said, okay, we have central HR. I also have seen organizations where the IGA programs, for instance, really always stalled because there were not one HR, but whatever, 50 or 60 or more HR systems in very different stages of maturity. And then you have one of these dependencies you talked about.
And, yes, we need to be aware of that because otherwise we fail. Anything else to add, Martin?
Yeah, so you mentioned different HR systems. We had this 15 years ago. So luckily now we could make progress here. And I think this was also a result of the stakeholder management at that time. So many colleagues were interacting with HR. And then HR also, they then also understood, okay, is there, let's say, that there is a benefit also for them.
So, for example, if they have expat moves, this definitely works also for them better if they have global processes applied. And, yeah, I think this is, in general, also something important really to explain the value that identity management can bring to the company, to all the business processes. And I also would say, in contrast to widespread opinion, it is possible to have constructive conversations with HR.
Yes, it works. And I think the problem of IAM sometimes also is that we just refrain from the conversations. So we have about three minutes or two minutes left before we come up with some questions. Any other very important advice that you would say, keep this in mind when you run your IAM program?
Well, I would actually say that identity being kind of front and center, and I think we all breathe and live that, I also feel that we shouldn't be cutting ourselves too short, right? So when we are partnering with HR, for example, it's actually equally sitting at the same, across the table, or side by side to partner. It's not really about IT. You figure out the problem and solve it.
I think that partnership is really important to establish right at the start of your transformation program, because then you get them to kind of engage correctly with you, and then you can kind of go through the obstacles quite easily. Yeah, eye level, cooperative. And I think also very important in many conversations I learned is trying to understand the language of the other side. I think everyone who entered conversations into conversations with operational technology, for instance, which you also may have done, quickly learns there is not only security, but safety.
And the IT people always think for security, the others think for safety first. So we need to do these things.
Martin, anything from your side? Yeah, so from my point of view, I can definitely say that this very important topic we see here, decentralized identity, and EUIDI wallet, such things is something we also want to take a look, simply to make our B2B processes more efficient, and taking here from latest technologies all the benefits that we can gain for our business.
Yeah, and I think if we sell this from a business benefit perspective, not just as a cool technology, we probably again will succeed more. So I think these were very important and very helpful points. And I would say they probably resonate well with a lot of the other practitioners in the room, have learned over the past years. Thanks for also referring to the Identity Fabric Workshop.
I think, yes, it helps having a structure abroad. Thank you for sharing these insights with us. Thank you. And good luck with your next stages in your IAM program, Stan.
Thank you, Martin. Pleasure to be here. Pleasure.
Well, there don't seem to be any questions from the audience. But, I mean, you were mentioning about business cases. And so I just wanted to ask, what are the business drivers in your experience or use cases, would you say, that truly justified the investment across company IAM?
Well, I think one of the business drivers is simplicity. It is a complex world when you have a lot of procedures, processes, and users get really bogged down when they do not have the identity problem solved, right?
So, I think one of the drivers there to kind of make things simple and also understand that we have a different layer of defense, that would mean that you may need to untweak a little bit of the more preventive controls and rely a little bit more on the detective controls that kind of enable seamless access at the front, right? So, that's something which is, that's my vision. That's why I think we hear about identity analytics being really important, front and center, user behavior as well.
So, I think it's really interesting to see where we can actually get faster to simplification, relying on some of this advanced, more advanced technology and adoption. Thank you.
Okay, thank you very much, everyone.