Good evening. Thank you very much for still being here. I want to introduce my panel very briefly. Very briefly, we have Jonathan Care, he's a lead analyst with KuppingerCole and the director of the practice AI. We have Dr. Phillip Messerschmidt, he is the deputy head chief of advisory, sorry for that, and we have John Tolbert, he's our cybersecurity research director, right?
So, what we want to do and what we want to talk about, and as Warwick rightly put, this is the first time that we do this, so, if I blow it up, sorry! We want to talk about how we can do IAM in reality properly. That's the idea. And my notes, of course, IAM has always been complex. It's changing. It's not just complexity, it's velocity, and many organisations are just struggling on how to deal with that. The market is reshaping itself continuously. New technologies come up, and we've heard the term NHI already this day.
Vendors consolidate, and yesterday's assumptions about architecture, about processes are just not valid any more. IAM teams are caught up between tactical demands and the need to maintain strategic coherence, which is difficult. This session is not about chasing the next acronym. We have tons of them in IAM, and we don't need any more. Even IAM is one. What we want to explore today is a harder question. How do you succeed in IAM when the ground keeps shifting, fortunately not in here, keeps shifting beneath you?
To start with that, and this is not scripted, just to make sure, let me start with a short lightning round, and I just do a round-robin with you. You have two minutes, all of you together, lightning round, not thunder round. Let me start with a short question. What are organisations in IAM underestimating today? Maybe you have your own answers to that, so keep them, maybe they meet them, starting with Jonathan. Good evening, everybody. Thank you for coming. I think that organisations are struggling with some of the old problems we've seen for quite a while.
We still see people asking us about the joiners, movers, and leavers problem. I could talk about the new technologies, but what we're seeing is that there are still organisations that are mired in heavily manual processes and are struggling to escape and evolve beyond that. Thank you. Philip?
So, for me, I would say clearly it's the strategy, the strategy behind the whole IAM space that you as an organisation have, and the most important part about that is connecting all the different pieces to ensure that everything works with everything else, and that you have one IAM landscape and not many silos. Thank you. John? I guess I would go a little bit more broadly with that and say they underestimate the cost of getting IAM wrong.
You know, if you think about it, I've done research on CIM and now B2B IAM. On the CIM side, you can lose customers if you don't have a good implementation of identity, and if you lose customers, of course, you lose revenue. On the B2B IAM side, if you don't get identity right, then you increase your risks, your attack surface.
So, planning for IAM for the future, making it modular, I think is something that can help reduce those risks and make you avoid the cost of getting IAM wrong. Right.
So, what we have right now is the strategy aspect and the B2B and the CIM as new parts of the architecture of the strategy. Philip, when we look at combining all of that into a common strategy, what are you seeing in reality? Are there the same teams that are doing that, the same responsible person? Is it one IAM team that includes B2B, IAM partner management, customer management, or how do you see that when it comes to putting that together in a common strategy?
I mean, the common answer is it depends. Sure. But in the end, we need to think IAM end-to-end. We heard that when it comes to risk management, we need to ensure that we start at the beginning and think all the way through it, through all teams, through all disciplines to the end. We see that with the teams, we cannot have a CIM silo, we cannot have a B2B silo, an IGA silo, an IDP silo, continue that till you get to AI.
Yeah, we cannot build another silo next to it. We need to start to have a strategy how to combine or at least somehow interact with these teams to ensure that we use the same processes. Why would I design a joiner process for every of the silos? That's fairly sad, stupid in the end. You can use 80% of the same process, and depending on the silo, you change that a little bit, feeding it in a common database and trying to align all the different types of identities and IAM disciplines in the end.
Right, and Jonathan, you talked about join and mover, now we have more types of identities with different types of join and mover and lever processes.
Well, I was actually struck by something that John said, and he talked about his extensive research into consumer IAM, and yes, we're all consumers, and we know that the most fragile part of a consumer relationship is right at the beginning, but we are still stuck in this loop of demanding an awful lot of information in order to validate trust, and I think that that particular aspect of the joiner process, I think, is still somewhat broken, and I am struck by this because, as you say, as we move towards a consumerization of IT in the workplace, then we become consumers in our work lives as well as in our personal lives, and I think that, again, becomes more fragile as we, as you say, as we sort of move away, yeah, move away from, as you say, a joined-up strategy.
Right, John, maybe you wanted to add to that, and also from the research perspective, when it comes to B2B, when it comes to CIM, is this an issue, or is this also at least tackled from a vendor perspective, from product perspective? Yeah, I think so.
I mean, if you think about even like joiner-mover-leaver processes, yes, they're there in B2B IAM situations too, but they tend to be different. It requires, you know, a different level or a different set of features of IGA components in B2B scenarios, so I definitely see that that's the case.
Right, and you've mentioned that already, so we are talking about, and I said that the ground is moving under our feet, and this happens while we are adding new types of identities and new types of business processes into that, so what is a proper approach to really make sure that the B2B processes, which are close to IGA processes, they are onboarding people into our systems, giving them access like they were our own employees. How can we deal with that when it comes to getting to this common strategy that you were demanding for, Philip?
How can we make sure that these changes that we are experiencing are taken well care of in our strategy once we have that? So I think the first step is to be aware that most organizations don't have an IAM strategy. When I take a closer look to the organizations that I know and ask, I ask, what are you doing in IAM for the next two years across all silos or all IAM disciplines, there usually is not a common strategy. At least I've not seen a lot of organizations having that.
So when something is changing, you should ensure that this fits somewhere in your strategy and ensures that this is reflected. Quick question, who would agree with Philip that many organizations, we're talking about your organization of course, so that you see that they don't have a say two years, three years IAM strategy, would you agree?
Okay, you already surprised me, good. John, you've picked up the microphone, your thoughts? I was thinking again about some of the medium-sized businesses I encountered when I was in the UK, and Philip's comment rings very strongly, resonates very well. IAM was relegated to a minor back office process with no real thought about automation, any strategic development, with a kind of a desk side thing at best. And I think, yeah, we need to elevate IAM, as you say, it is a business level event, because it is something that can allow the business to flex and move in an agile manner. John?
Foreshadowing a little bit of what I'm going to say tomorrow in my own CIM presentation, but yeah, CIM can be a business enabler. I think it's always important to remember that. It's not just a cost setter.
I mean, I heard that for years working in enterprise, you know, we've got to spend all this money on digital identity stuff, and what does it do for us? Well, if you're customer facing, then obviously that is a good way to help you make money. And if you think about your consumer or customer interactions, what those are like, there might be opportunities for improvement.
You know, Jonathan was mentioning registration processes. They can be quite cumbersome, you know, trying to right size the amount of friction that occurs during those times would be optimal. But then there's also authentication, you know, using passwordless authentication, stronger forms of authentication can be useful as well.
Okay, so now we have some seven minutes left to give two minutes back to Yves. But the question is how do organizations actually succeed in IAM? Now we've really put our fingers on the hurting parts. I think that's important. But how can organizations really make sure that they operationalize IAM strategically? So what would be good steps to get out of the machine room to get into the light of the business enabling team? I don't know who wants to start.
John, do you want to start? Jonathan, sorry. I'll take a stab. I think that, again, looking at the experience I had with these midsize organizations, I heard people say, well, we'll move to Entra and that will make it all right. Or we'll move to Google Cloud. And I think the danger there, as Philip says, without a strategy, you are going to faithfully replicate all of the mistakes, errors, and omissions in your, as you say, your manual machine room processes and add a few more into your new cloud environment.
So I think the most important thing, I think, to get, if you like, to get out of the pit, I think, is to analyze where you are and have a plan for change, as Philip was saying. Right. Analyzing where you are.
I think, Philip, you did the workshop this morning. So analyzing where you are and making the right decisions to take the next steps, that's actually what you're doing, right? Yes. Good answer. But picking up the question from earlier, what would help? The thing is, you need to talk to each other. This replication just happens because people are not talking to each other. And an easy question is, who is talking to whom? Talking on an operational level sometimes doesn't help. So you need an executive force or task force or group or person that keeps the overview and talks to the people.
And the easiest question you can ask is, how many IDPs do I really need? One might not be the right answer, but 27 for sure is also not the right answer. Right. I think there's another part to talking to each other as well.
Again, moving to some of the larger enterprises I've been dealing with, tier one banks, for example, data sharing is actually a fundamental plank of that communication process. So it's not just talking to each other. The exec task force can empower it by making sure there's data sharing between the different groups. Right. And John? I just thought I might add in identity fabrics as a way to help future proof that.
I mean, modularize your IAM deployment, make it so that when business requirements change, it's easier to snap in new or additional services. And for that, you know, adherence to standards, standards development. I see some friends of the audience who've worked with me for years on standards.
Hi, Alan. So, yeah, standards, using standards with identity fabrics I think is a good way to help future proof your IAM architecture.
Yeah, but we all know that. Typically somebody comes in and says, there is this new tool, call it IVIP, ITDR, whatever. This will solve our issues. What would you reply, Philip? I'll be very blunt. Don't be distracted by the shiny things. Yeah. Okay.
Thanks, Philip. I mean, I said it very clearly in our workshop today. The tool is the last step in a sequence that you do before that.
First, I would always think about what identity am I talking about and what are the requirements of that identity? What capabilities do I need to have to fulfill these requirements? And how do I combine that into a service? And then when I have done that, I can think about the tool. That's the last step. But there are four steps ahead of that. Right.
John, you're nodding. Anything to add from your side? You're doing the research with these tools. I think it's okay to occasionally get excited about the technology, though. If you see that the technology legitimately solves a business problem that you have, like I think about ITDR, you know, that's sort of applying the same principles that we have in consumer-facing fraud prevention to enterprise identities. And a lot of organizations really don't have good capabilities in those areas today.
So if you identify a gap and you see a tool or a tool type that might be useful in plugging that gap, then I think it's definitely a good thing to check it out, but evaluate it fairly. Okay. So if I summarize it, so we're already at the end of this first try of an unusual type of session. Talking to each other, gathering requirements, finding the right services that we need, that would be a starting point. Not jumping on every bandwagon when it comes to technologies and doing the groundwork right when it comes to process. Microphone. Using the microphone is also important.
Sharing the data, I think, is a key success factor. Right. And we are at the end of our time, so we give back a few minutes to Yves to allow for being at the end on time. So thank you very much for listening to these four people talking from the battleground, and you are on the battleground as well. So if you have any questions, reach out to us. We are here to talk to you in the next days. And let's make sure that we all create IAM infrastructures that still hold steadfast when the ground is shaking. Thank you very much.