How Can Organizations Move from Periodic Access Reviews to Continuous Assurance Using Event-Driven Lifecycle Automation and Dynamic Entitlements? And I'm very happy to have Christian Müller from DigiCert, Ashvin Saminathen from Pointsharp, Rolf Steinbrück from Yubico, and Malvin Zimmermann from Accenture on the stage. So I can't say gentlemen, I can skip ladies, unfortunately I have to say.
So yeah, maybe we start with a very quick introduction now, so 30 seconds each. Just your name, the company, maybe one key statement already about the topic then. I don't know, Malvin, if you want to start and then I start with the first question.
Sure, why not. I hope you can hear me all right. Good morning, everyone. My name is Malvin Zimmermann. I'm with Accenture for one and a half decades now. I'm responsible for INM and PUM topics in the realm of cybersecurity, part of the digital identity practice, and I'm looking forward to this nice conversation here today with our vendors.
Hi, my name is Rolf, working for Yubico. I'm working for Yubico now around about five years, but I'm in the IT security industry for, I don't know, 20 plus years already.
Yeah, I'm also very happy here to be here today. I'm actually jumping in for a colleague. He twisted his ankle, so I'm here on short notice. But as I said, I'm happy. Thank you. Christian Müller from DigiCert, 60 years, three kids, all out of the house. So I have enough time to take care of a small team in Germany for the company DigiCert as the leading CA in the world. And I'm happy to be here and share some thoughts about the integration of IIM and certificate lifecycle management and how it becomes one.
All right, then I am Ashwin Saminathan. I lead solutions engineering for PointSharp. So PointSharp is an IIM company, fully European, so completely made in Europe. And the two biggest pillars of solutions where we operate are really in the IGA space and access management. And we try to actually get something that can help customers in a very European context, I would say, when it comes to those two specific problem areas. Okay. Thank you very much. One technical request. Can I ask to start the timer, please? That would help me a lot. Thank you very much. Okay. So maybe first question to Marvin.
What does identity governance actually look like on the ground today in your projects, maybe? So how much provisioning do you still see? How much is still access reviews on demand and how much is actually already maybe automated today? That's a very good question. I think in 20 minutes, I will be able to answer all the questions. And generally speaking, just to summarize it all together, we see two project types over and over again.
One is the compliance-driven project types that have a limited budget that are focused on really closing findings as a primary goal, where we are asked to create awareness and collect all the relevant information for the feeds to the IGA solutions that's supposed to be established. So it's basically all you've been through. We have these SharePoints set up. We have all these documentation, digital authorization concepts, and those are used as the basis then to fill in the IGA tools.
And then we have security-driven projects, where really the focus is on increasing sustainability, gaining control, oversight, and enforcing then the security principles that ensure the resilience of the companies. And this is when we go into automated provisioning, or we go into ephemeral access and so on. Maybe I can just add something to the automation and the provisioning, especially in our case regarding the digital identity. I think this is one of the bigger challenges organizations typically have, is like enrolling or onboarding the user. It takes time.
It's a huge organizational effort, like any other project typically. But here we also have the hardware pieces that we need a logistical solution for. And what we from Yubico can say, that we can basically more or less provision these YubiKeys, in our case, from factory already. So we can pre-provision the keys. I think this is a huge step regarding identity security. Okay. Yeah. Thank you very much. So I was then also wondering, so how does machine identities and certificates, workloads, service accounts come into play? Because I mean, they outnumber human identities by a wide range already.
And do then quarterly reviews and these kind of things already break down? And maybe that is then a question for Christian.
Well, I think the answer already lies in the question, right? So depending on the statistic today, you have statistics saying you have about a hundred times more digital identities than you have users, right? So the question is really, how do I identify anything that is in my network? May it be a device? May it be a user? May it be an AI agent or a server? Then you have the whole Kubernetes clusters. You have servers talking to each other, et cetera. All of that needs an identity.
And we, yes, we do certificates. It's nothing special. It seems like it's just a long text file, right? Or in the future PQC, it's a bit different. But at the end of the day, the three questions I think someone needs to answer or companies needs to answer for you is A, how do regulations drive security? How do exploding machine identities influence your security and identity access management? And last but not least, what we're also seeing today, right? You have this PKI team, which is like somewhere working in the cellar.
You know, nobody really wants to handle PKI. Then you have IIM and then you have IT architecture. And actually those three teams, from my perspective, should be one. And I think they should be led by the IIM teams because they hold the overall governance, at least from what we see.
So, yes, our personas change of the people we talk to, of our whole holistic identity access management used via certificates for software, servers, users, agents, whatever. Okay.
So, maybe we should get a little bit more architectural and discuss a little bit more about solutions. So, what are the building blocks for kind of a more like event-driven lifecycle and automation?
I mean, we cannot handle all those machine identities manually anymore. And how do we then see integrations to HR and cloud platforms and the signal aggregation? Maybe that's a question for Ashwin then. Absolutely. Thank you very much for that question. And I think this is really the core of like when we're talking about assurance, particularly in an IGA perspective, right? We have to move away from just thinking of human or non-human from, yeah, we are going to provision you and then we are going to remove your accesses when the time comes or do recertification.
The industry, the organizations are changing. It's a very dynamic environment where things are changing almost every day. The bigger you become, the bigger the changes are in the roles, in the entitlements, in the authorizations that you have. And to your point, absolutely, getting signals, correct signals from multiple source, actually. We can't even say now that your HR system is the master source. It can't be. You will have to get signals from maybe your agent registry. You might have to get signals from things like Ops Jenny who are actually handling your roster.
But more important, I think, what a lot of organizations are actually missing out right now is it's not only about pushing the information. It's about pulling the information as well. You need to go into your different systems. You need to go into your different applications and actually figure out what is changing in there every day. That has the potential to create segregation of duty problem. And you can't actually just do that by looking up and saying this is what you have to do. So the world is changing, really, when it comes to how we govern continuous assurance.
Recertification don't work anymore. Nobody does them, honestly, in practical reasons. Nobody wants to do it. It's just impossible to do, right? So having the possibility of reading those signals and aggregating them in a central location is primordial in actually maintaining continuous assurance. Thank you. Okay. Yeah. Makes sense. So maybe back to Rolf, then. I was thinking authentication itself is also a signal, isn't it? And I was asking myself, then, what does then the phishing-resistant authentication, what kind of role does that play in the discussion we are having here?
So I think there's a short story about that and there's a long story. And the short story is when we talk about phishing-resistant authentication, I think this is key for every organization. I think there's no discussion around that. Because at the end, when we tell the short story, the hackers, they don't typically hack in anymore. They simply log in. They steal the credentials if you're not using phishing-resistant authentication. So I think this is a really key milestone for a secure IAM management platform to make sure that the identity is a person that is actually logging in there.
And from my perspective, every organization needs to focus on phishing-resistant authentication. There are different types of certificate-based authentication, passkeys, but I think this is absolutely key. From my perspective, there's no way around that. Okay. Yeah. Thank you very much. That makes sense. So I still see that we have some time left over, so maybe there is also already a question from the audience here to the panel. So something you have in your head at the moment you want to ask to the panelists about what we are discussing here. Any question? We're getting the silence.
Sometimes you have to stand it. There's one question. Great. Can I have one of your microphones, please? Anyone? Okay.
So, yeah. Thanks, guys. Those are interesting points. So continuous, you know, watching the environment, all of that stuff. People get a bee in their bonnet, you know, they get really worked up about the whole concept of ephemeral identities, particularly, you know, agentic, NHIs. And then they go into just in time, you know, this notion of stable and ephemeral identities. I've got my own opinions about these things, but I'm just curious, like, if you kick that around for a little bit, because it feeds into the continuous topic, I think. Okay. Thank you.
I think this is an extremely valid question, right? And the world of governance and assurance and identities is changing because ephemeral identities are something which is happening now. The real answer is, we're not really sure how to address it now, because things are changing every day. But building the building blocks, right, where we start, where the pillars are, this is something that we can already start looking at.
I mean, I was at the session by the team from Keeping Eagle when it came to, like, managing an AI identity, as they call it. Very interesting. And one of the things is, yes, you need to have the registry in place. You need to actually start looking at intent instead of only deterministic, I would say, permissions or roles, right? And it's going to change a lot. And this is going to probably be a different story next year, by the time we're talking again. But building the basic principles still remains the same. Go with least privileges. Go with the zero trust, right?
And this is how you set up, like, the beginning, the building blocks to actually get something which is going to work. Is this going to be perfect? Probably not. It's going to change so much. But we have to start somewhere, right? By the time that we have a swarm of agents inside our organization, it will be too late to do it. So we have to start now before it is already all over the place. So that would be my question. My question has to say something about that. I think it really, I mean, we're always talking about how do you automate things?
How do you make sure you cope with the challenges in the future? Actually, the challenges today are a lot simpler, not simpler, but, you know, a lot of organizations today don't even know their assets in their organization, what accesses, how and when, right? So when we talk about how, for instance, we give certificates to agents today and how do we audit that and how do we track that, right? The first thing is always you need to discover what you have. And it's interesting, a lot of people say, so how do we manage that? What do you have, right?
So there's a three-stage process of discovery, making sure it's auditable, because for all the CRA regulations, NIST 2, DORA for the finance industry, the first thing you need to be auditable. And the third one is then how do I automate that in certificates? It's given by the CAA browser forum for public certificates. You need to renew in 47 days in the future. You need to validate your domain every 10 days.
And if you start to apply the same principles for your private environment, users, devices, et cetera, make sure it's auditable, you know what you have and you can automate it, then you get there, right? I know that this conference is more about people and identity access management of people, but I still run aways that there's other things than people in your organization and even customers accessing your environment. I totally agree to what everybody else said.
Maybe just to add to that is, so like two, three years ago, we talked a lot about phishing-resistant authentication, which is still key, I would say. But we shifted the messaging a little bit to phishing-resistant user. So we have to make sure that the complete lifecycle of the user is phishing-resistant. I think this is one important message.
The other demand that we see quite often from especially bigger organizations is the onboarding and the recovery process of phishing-resistant authentication options, combining it, for instance, with identity verification tools, so that you actually can onboard, let's say YubiKey, using identity verification like government documents. So I think this is also something that we see in the future.
Okay, so yeah, then maybe let's wrap up and do kind of a closing round. So I would like to start with Malvin and then take it from there. So what is a realistic 12 to 18 months path towards continuous assurance and how could that look like, assuming that a lot of people with their company are still on classic identity governance administration platforms? And then maybe we open up for the closing statement then from you. Sure. So the key goal should be sustainability and full control of the identity and access management.
So what we usually try to establish is to find the gaps in the automation and then to really enforce automating these processes and closing the gaps by enforcing technology. But before you do that, you need to be kind of like a handyman. You need to know your strategy, you need to know your goal that you want to reach, and then go from there and close the gaps with the technologies at hand. What do you think? I totally agree, and I said it in the beginning as well.
I think the automation part, especially from the identity point of view, from a hardware security point of view, is automating the complete deployment of the keys. Because the most bigger organizations, they see this as a real challenge. And this is where we are focusing in the future, that we want to automate this process.
Ideally, everybody knows the credit card experience. So the user is getting a card, and the second way he gets a secure PIN. And this is the way we go.
Yeah, I think I said it before, discover, report, audit, and then automate and make sure you have what you have in your environment. And even PQC people tell you, post-quantum cryptography, if you don't know what you have, you won't be able to deploy new algorithms, et cetera. So I think that's key. And as simple as it sounds, a lot of companies don't have that. They don't know what they have, which is the problem, especially with, you know, every department comes up with their new AI agent.
Hey, that's great. Create something. Let's build this because my boss said it will make money.
Oh, yeah, cool. Aswin, final words from you then.
Yeah, final words. And I think I'm going to be a little bit more vague than that. To say that actually, when we look at continuous assurance, it covers a lot of things. It covers the audit part, the compliance part, but also identity and phishing resistance and certificates. I still don't know how we're going to use certificates with ephemeral agents. I would like to have a discussion about that at some point. That would be great. But the bottom line is, ultimately, what we want to do is we want to protect the business. We want to protect the people. We want to protect the money, right?
That's the core concept of security. And applying some of the principles that we still know, like the least privilege and stuff like that, is going to be the building blocks.
But also, be flexible. Things are going to change every day in the foreseeable future, and you need to be able to adapt to that very quickly. So just setting something in stone is unfortunately not going to work for you anymore. And that would be my closing part on that.
Yeah, Ben, thank you very much. Then final words from me. Thank you very much for those panel discussions. For the audience, all of them have boosters on the floor outside. I think you may be still in the room here for a while. So if you have questions, because we have no time left, directly contact them. I'm thinking they are happy to have some discussions with you with that. Thank you very much. All right.