Okay, cool. All right.
So, I obviously see this is the track on compliance, so we're going to talk about compliance once more. So, welcome everybody.
So, the good news is if you've got an overdose on agentic AI and futuristic security, this is very down to earth. And the bad news is Guido is off sick. He had to leave, unfortunately, so you're stuck here with me.
So, please bear with me for the next 20 minutes because I'm not the expert in the field, but I will do my best to present Guido's presentation. Guido is our field teaser, and if after this session you have questions or you'd like to still get in touch with Guido, he is available and hopefully will be back on his feet soon.
So, let's start with the different factors that influence cyber security and specifically identity and access management buyers. So, obviously, we start with the number one, is security. That's one of the reasons, obviously, any vendors out here will tell you that products get purchased is because, you know, you obviously want to augment your security. We know that 70% of breaches today, even more depending on, you know, the statistics, are from identity.
So, it clearly makes the reason for identity and access management even more valid. In terms of attacks per day, there is a study done by Microsoft which is 600 million identity attacks a day.
So, this security influences, obviously, the need for compliance because why would, you know, we have all this compliance and regulations if it's not to protect further. So, I'm sure you've been to some of the keynotes which talked about tons and tons, I won't give the figures not to get them wrong, but the compliance and regulations are only increasing depending on the sector you are. You surely have at least a number you can name, the most common ones in Europe being NIS2, Dura and these specific regulations explicitly talk about and mandate identity, they mandate access, auditability.
But all this has the ultimate purpose of creating business resilience, making sure your operational continuity. So, it's not just about how many security tools you have, but what happens if things go wrong? What happens if you have an incident? Can you keep operating? What are you going to do if something fails? And ultimately, it's this last reason or this last focus that the board cares about. And earlier, the presentation earlier talked about accountability.
So, the board members or the CEO, they're the ones accountable for if anything goes wrong, they're the ones that can be fined, they're the ones that can even go to jail. Governments, regulatory agencies and companies around the world work to increase oversight of cybersecurity incidents and by doing so, are increasing regulations.
So, once again, tons of regulations which are demanding for more powerful and greater cybersecurity, transparency. And yet, if done right, it can provide more resilience, trust and a certain way, a competitive edge. Because if your partners, if your customers have trust in your operational model, it's also an extra benefit for you as a business.
So, let's look, deeper dive into specific regulations and map them out. We do this a lot at Wallix.
So, if you have any particular regulation you want to look in detail and understand the different requirements, please feel free to visit our website. You'll find tons and tons of documentation.
So, two things from current regulations that are more and more prominent. First of all, it's becoming more and more process-orientated. We're no longer talking about, you know, we're talking about controls, we're talking about processes. And the other thing is, if you read one, two more regulations, you'll actually find that said differently, they're repeating the same thing.
So, it's the same processes that are described based on different, you know, whether it's environment, regional factor or for your sector. So, once again, if you are looking to become compliant with a particular regulation, don't just look at ticking boxes and adding more and more controls, because you're just adding complexity and you're not necessarily reducing the attack surface. What you need to start by doing is understanding the processes. Read the regumentation documents with processes in mind.
So, let's have a look here. For example, you've got enforcement of least privilege, access restriction, sorry, accountability, monitoring of critical infrastructure access, you have third-party access, administration, etc. Understand your processes, map your processes to your business and then only then start adding controls. And once you understand the controls, then you can go on to selecting the tools and making sure that the tools actually tick the boxes that you're looking to tick. And in doing so, you will find that some controls have a greater impact in terms of resilience than others.
So, one euro invested in a selected control can have more impact, can be equal to three euros. It's called the high impact zone. And specifically in our area, in our density and access management, we are in the high impact zone. Every euro invested in this area is going to have higher impact. And this links back to the maturity, cybersecurity maturity model, which you're probably familiar with, which is quite a standard. It's referenced by different standards, such as NIST, etc., has different layers.
So, the layers of identity and access management with a lot of impact are the ones between two and four. So, there's all sorts of details you can go through. And each control obviously has a different impact. But generally speaking, this is what we call the high impact zone. Looking at this maturity model, looking at this maturity model, just quickly go through it. It starts at one. This is reactive. Something goes wrong, I fix it.
Layer two, descriptive. You find what goes wrong, then you try to work it out. Goes to then preventive at layer three. That's where you reduce risk. Then you go to predictive, to more full, managed, resilient. And then finally, very autonomous, prescriptive, where decisions are taken automatically. Self-healing model, optimizing. Where do you think most of you are? Anyone thinks they're at one? One? Two? Three?
Gosh, you guys are very confident. You're all at four and five? Okay. The majority of our buyers are below level three.
In fact, 90% are below level three. So, most of us are still struggling to implement the model.
Obviously, some sectors have more demanding regulations, more heavy regulations. For example, I give you one example, financial services, which are early adopters, for example, of PAM solutions.
So, they started early. Therefore, they've got maturity level between three and four for the most part. But most of us and most of our customers are around two and three. If I look at critical infrastructure, so industrial security, where you would expect it to be higher.
In fact, because of legacy environment and additional complexity, they're still struggling at level two to three as well. And healthcare is another example, which is unfortunately still quite low. And that's due to underfunding for these types of solutions and still struggling to get up to speed.
So, you go from the foundational level through to advanced. And basic processes around identity and access management start around two. At level three, you start implementing IGA, MFA, initial PAM. And level four, you have a fully-fledged PAM, governance, integration. When you start selecting products, once again, look at the processes before selecting tools. Establish the fundamentals first, securing external networks, for example, remote access, look at controls. This is representation of our portfolio, which could be another. Map it to the relevant controls. Look at the deployment options.
They need to correspond to what you're after, what your environment requires. And select based on your actual need as opposed to what the vendor presents to you.
So, finally, to sum up, analyze modern compliance frameworks. Deconstruct them to single business processes. Make decisions based on your needs. Select the tools that can be combined in a meaningful way. Make sure the tools are interoperable because, once again, piling up tools and having a zoo of tools only creates additional complexity and doesn't reduce the attack surface. And you'll see that by covering the different processes, you will become compliant and, therefore, more secure and, hence, business resilient.
We worked with Martin Kupinga to create a white paper called From Controls to Business Resilience, Prioritizing Identity-Centric Security Investments, focusing on ISO 27001, NIS 2, DOER, and Zero Trust. All these have been mapped to specific controls explaining what needs to be done, the order, and the return on investment. If you're interested in that, come to our booth. We'll share the white paper with you. We can talk in more detail, and we can also take appointments if you want to still talk to our experts.
And, once again, I apologize that Guido is not here. He's able to help you map, create assessments, frameworks, and audits if you need to. Thank you very much for listening. And are there any questions so far to Vera? Anyone? No one. Okay.
Vera, may I ask you one question? Yes. It's okay if you say I cannot answer it because it's Guido, but we will try at least. We will try. Okay. Frameworks like DOER, NIS 2, and ISO often create pressure because different stakeholders interpret them differently. And where do you see organizations overcomplicating compliance requirements or especially in identity and access management? Yes.
I mean, this comes back to understanding the business processes first and not jumping to technology. And, as I mentioned earlier, the good thing about the regulations today, they are less and less technical. They're more focused on processes.
So, we're getting there slowly, and obviously, technology evolves. Maybe one day, we'll just have AI running for such and such compliance and ticking the boxes and making sure everything's done automatically. But it's not the case today.
So, it's still business. By creating business lists and controls and processes, you also need to prioritize and have your risk factors. Each business is different.
So, you need to start with what matters most and then try to approach vendors who have the mappings, like we can provide, for example, for the regulations I mentioned, and then try to find the controls that respect those mappings and not overload with products which are unnecessary. I see. Yeah. Thanks a lot. Thank you. Yeah. Applause to you. Thanks.