Hi, I'm John Tolbert. I'm the Principal Analyst and Research Director here at KuppingerCole. I recently published a leadership compass. That's our comparative report on B2B IAM. It's the first report that we've done on that. It's the first report specializing on B2B IAM as far as I know in the industry. And why are we going to talk about B2B IAM? Because do you know who's really working for you? I think you've all probably seen stories like this in the news over the last year or so.
The research indicates, I think it's by CrowdStrike, that 320 companies have hired North Korean remote IT workers. So we'll dive into a little bit about why this happened and what you can do to prevent that. So I think you can see this is corroborated by multiple credible sources. There's been a big increase in this over the last year. They report almost $500 million in income that's been generated this way.
About 100,000 remote IT workers in 40 countries that are doing this. How are they doing it?
Well, they're using good old AI deepfakes in a lot of cases, including, you know, virtual camera, camera insertion. To do live video during video interviews.
And then, of course, they they get people in Western countries to run their laptop farms for them. And then they use VPN to sort of mask where they're actually coming from. So let's talk for a minute about the difference between IAM, you know, Workforce IAM, CIAM, which has been around for a while. And now what we're looking at here with B2B IAM, I think I really just kind of want to focus on, well, what are the sources of the identities? So on the workforce side, of course, you have HR processes. HR hires the people. They do the vetting.
They get put into an HR system, which then populates your directory. And there you go. You can build policies and assign attributes to the users as needed. On the consumer side, you know, it's totally different. There's self-registration processes. Most of them come in using social logins. And there's really not that much of a notion of access control.
But it's, you know, the sources of the identities are very different. B2B IAM, well, it can be a little bit of both. It depends on what kind of B2B business you're in. You might have many large partners that have good identity verification and authentication. You can trust that. So you federate with them. Or you might be the kind of business that hires a lot of freelancers. And you've got to provide all those services.
So, you know, again, depending on where your business is, you might have a little bit of both. So what kinds of identities are we talking about here? So let's think of customers, contractors, partners, freelancers. On the customer side, these are external companies that are coming in and maybe using your buyer's portal. They come in and they buy goods or services. Maybe they have fixed terms.
But, you know, this is a pretty well-established type of customer organization. And these are relationships that we see all over the world. Other types are the contractors and freelancers.
You may, you know, we've been talking about OT, ICS in here for the last hour or so. Most of those arrangements involve having the manufacturers of the SCADA or HMI systems probably need access to their customer deployments. Or they have systems integrators who help out with regular maintenance. But they need accounts. They need the ability to come in and do updates or maintenance or fix things when necessary.
So, obviously, they're different companies, but you've got to be able to grant them access to your machines if you're, say, a manufacturing organization that has SCADA equipment. You may have resellers or brokers. Think about the insurance business. An insurance broker may be able to get into the insurance company's systems and write policies. Service provider agents and drivers.
You know, one interesting use case I heard during the course of the research was a company that hired thousands upon thousands of delivery drivers, but just for specific tasks. So they need to be able to quickly identify and onboard people to get access to their portals so that they can learn what their assignment is. And maybe they drive, you know, this widget from this city to that city, and at the end, they're done.
Now, they need to be at least temporarily off-boarded. They might hire them back next week to do something, but they want to cut off access to that portal at the end of that particular task. So you can see the scale and the speed is a lot different than what we're used to in workforce or even in the CIM world. And then lastly, think about big complex supply chains. Maybe you are a prime contractor at an organization that's doing work for the aerospace and defense business. I'm kind of familiar with that, you know, from my history. And they have hundreds or even thousands of supplier companies.
And, you know, you may, as that prime, release specifications for parts that need to be built, but you're you're intending on collaborating with your suppliers to do the R&D. So you need a collaboration space where you can grant them appropriate access to come in, read the specifications, and submit their parts of the design, but not clobber other people's designs and not get access to things that they shouldn't have because in many cases, you may actually be competing against some of your suppliers in other areas.
So again, this can be extremely, extremely complex and fine-grained access control is really, really needed here. So we'll run through the use cases. A lot of this is probably self-explanatory, but, you know, onboarding and activation, this applies to the organization level as well as the individual, and I'm glad that Thomas just talked a little bit about LEIs because that's a great way for trying to validate the businesses or the organizations that you're going to be forming a trust relationship with.
But we also have things that we need to do sometimes like sanctions screening, looking at various names on watch lists, doing background checks. If you're hiring people directly, then you may need to do HR background checks on them. There's lots of services for that. Or maybe if you're in one of these situations where you've got a bunch of mature supplier companies that you're working with, you delegate administration to responsible individuals there, but you want to do multi-step approvals.
You want to say, okay, supplier A says this group can get access, but as the actual data owner, I want to be able to second that before they get access. Fine-grained access control.
You know, it can get really, really deep. I thought this might be a good example. You might want to look at, well, what organization is this user coming from? What's their actual relationship to that organization? Are they an employee? Are they a contractor to a contractor? Many organizations require a work order or a specific work agreement in order to get access to project data, so you'll need to know that.
Of course, there's group memberships and roles. We're all familiar with that from many years of working in IAM. There can even be, you know, this can work in national security settings. You might have to have clearance and classification. And a lot of organizations require training to get access to certain types of materials, so you'll need to check certification status and whether or not mandatory training has been completed.
That, too, is an attribute that can be coded into policies, where necessary. Federation, I mentioned that.
SAML, still around, still doing a good job, but OIDC. You know, if you do have a large supply chain of organizations that you're working with and, you know, they're sending over SAML assertions, but there can be differences in the way you name your attributes. You need to do claims normalization or attribute normalization so that whatever information it is they're sending you in an assertion makes sense in your access control system. You want to look for compromised credential checks in many cases, periodic access recertification.
You know, we're all familiar with access recertification from our IGA systems, but, you know, it gets a little bit more complicated. But, you know, it gets a little bit hairier when you're trying to do that with multiple organizations who's actually responsible for reconciliation.
Let's see, user and tenant enrollment. How do you get started? LDAP and SCIM, bulk directory import for cases where you need to replicate portions of supplier directories.
But, you know, very commonly now people do just-in-time provisioning using SAML or other tokens. And if you do that, you want to be able to set policies or account restrictions, you know, with what they can do. Examples of account restrictions might be time-limited accounts or even single-use accounts. You could log in with this once, but that's it. You might set specific time windows that can be used. You might do allow listing from specific IPs or domains, geolocation, geofencing, and then, of course, minimum identity and credential assurance levels.
So, in order to define access to specific kinds of data objects, you'll want to be able to dial it down to specific attributes, including those credential assurance levels. I've been talking a little bit about authentication, passwordless, FIDO2 pass keys.
You know, if you're going to be the one doing MFA for a large outsider workforce, then certainly you want to give them something that's user-friendly, but also secure. We need to instantiate things like risk-based authentication to be able to step up where necessary. A lot of the vendors that were surveyed do have SDKs that do device intelligence and behavioral biometrics and device posture checks.
Again, in a situation where you've got lots and lots of specific IP you want to protect, you want to make sure that your supplier ecosystem, those devices that are attaching to it, are not full of malware and are up-to-date with our patches. Authorization. Always the most difficult last mile.
I mean, we've had RBAC forever. We know RBAC's pitfalls. I think in B2B IAM, we really see the need for attribute-based access control, policy-based access control, and even relationship-based access control. Delegated administration is really important. Most of the solutions I looked at have some notion of delegated administration, but how well they do it, you know, varies. How deep can you go, you know, how many levels can you delegate, and then what sort of controls can you put on that to prevent inappropriate delegation onward?
I mentioned the subject and resource attributes already, but of course, it's always good to have a good intuitive policy authoring interface, low-code, no-code workflow builders. I mentioned a bit of this already, the need for trust screening, and then account lifecycle management. This is another area that's kind of interesting.
In CIM, you know, there's not too much of a notion of identity governance and lifecycle management, although I understand customers are asking for it a bit more and more when you have thousands or millions of users in the repository, and many of them haven't been used in months or years. A lot of organizations want to clear out that data, you know, to reduce liability, so things like duplicate or orphan account detection are becoming increasingly important, not only in CIM, but of course, it's very important in B2B.
Secure account recovery procedures, so this is a really weak point in the identity lifecycle. We've seen in many cases, like we mentioned scattered spider earlier, but they use techniques against helpdesk to try to get passwords reset or credentials reset, so this is a very sensitive part of the process, and secure account recovery procedures are necessary.
Let's see, and I mentioned the interface. It's really good to be able to have a policy authoring interface that not only your IAM experts understand, but increasingly we need to sort of delegate that to business people who understand the resources that they're trying to protect, because often those of us in the IAM or IT world certainly understand the policy side of things, but we don't really understand the sensitivity of the documents or the applications that need to be protected, so a good user interface is a real key to making this work.
B2B IAM requires lots of different kinds of integrations, but I think you'll find they're pretty straightforward. I mean, you'll want to integrate a B2B IAM system with other IAM components, an identity fabric approach, and of course your traditional security solutions like SIEM and SOAR as well as ITDR now. Some of the things that I found in the course of the research is, you know, everybody seems to say orchestration is really, really important, and I don't doubt that. In a lot of cases MFA is outsourced. I've already mentioned RBAC isn't quite good enough.
The LEI lookups, I think this is an area for growth. B2B in itself sort of implies that you need to KYB or know your business, and the best way to do that, a good way to start is by doing that domain investigation and LEI lookups. Hopefully we'll see more of the vendors that we looked at doing this in the future. IDV and sanction screening, you know, really deep name watch those screens, not really built into a lot of the solutions yet. Account lifecycle management in some cases has a little bit of ways to go there, and as I mentioned, delegated admin.
Most everybody does it to a degree, but some are more sophisticated than others. So depending on what you're looking for, what your needs are in B2B IAM, I think that's a real important and potential deal breaker. You need to really understand what the capabilities are in terms of the delegated administration. So before I run out of time, let's show a look at the report itself.
Again, this is the first time we've done this report. We had 23 vendors. Very happy with everyone who participated. Here's a quick look at the overall leadership chart. Overall leadership as we define it includes product leadership, market leadership, and innovation. So you can see a pretty good distribution from sort of top right through center left. This indicates not only size of the solution, numbers of customers, but also how we rate them in terms of product maturity and innovation on their roadmaps. And I'll just give you one simple sample spider chart.
We rate categories based on what I've been talking about. Hopefully that aligns there and show you how we rate each vendor according to these particular categories. And of course, there's a nice detailed write-up, and we are happy to take questions and talk about it too. So if you think of anything more you'd like to know about the B2B IM market, if you have feedback for me for the next time around, happy to discuss. And have a few seconds for a question if anybody has one.