Thanks a lot. Yeah, I have my guests here, yeah, to pick up what now we have with the strategy now, as I said, the marathon, yeah. Now we are starting with implementation. We set the pace, yeah, and now get the real-world problems really solved in the world. And there I invited also some experts from different angles of the thing, authorization, yeah, authorization models.
And, yeah, I would take the moment, yeah, maybe quickly start to introduce yourself for the ones newly joined, so please, Oliver, as well. Yes, as some of you already joined the panel before, so my name is Oliver. I am product owner in Erste Digital, IT service provider for Erste Group.
Yeah, next. Hi, everyone. Good morning. A little bit too late. So I'm Heiko, CEO of Nexis, and an identity guy by heart. Yeah.
Hi, together. I'm Dennis. Dennis from Deutsche Telekom, responsible there for IT governance in the whole IT landscape. Matti from ABB, responsible for running IGA solutions, which we have in – for the global enterprise. So maybe I close it also for the ones newly joined. I'm Patrick Teichmann, working for Copenhagen as lead advisor, helping to solve the identity challenges that exist in Iran. So the first topic, as you do it with the panels, goes, yeah, directly to each of one. I want to answer from all of you. Maybe we start with you, Masti.
Looking across your experience and looking, yeah, at the topic around authorization, what is in your reality and from the various positions that you have the biggest challenge when we talk about authorization? The biggest challenges are coming from my perspective, from the complexity of organization. We often think about our HR as a great source of information about our roles, about our assignments. But when we start drilling down, it turns out that we just get the several level, not to the one which is necessary for us to drive the whole authorization management until the end.
And this is where I think the biggest challenges are. Dennis, please.
Yeah, for me, as I think especially I'm a big fan of moving everything away from ABAG to ABAG. But the big topic is how to get your old monoliths like the old CRM systems, the SAP board and something else with 100k plus worlds away from that and get it to a full flexible model without so much topics to solve and to let the business run always. So that's the biggest issue, how to get to that. So now I have to decide. So basically, I'd say it's visibility. So visibility across the variety of systems, like you said, older ones, newer ones, legacy ones.
So different kind of IMs every company has there. There is not just one single one, unfortunately. And then the proper intelligence to remediate stuff that's not right, that should be fixed. And last but not least, probably the most important one, to have some user experience that works out for the business. So when tech products made by tech guys for tech folks, then it's hard to get an HR manager, marketing manager or so to have really fun when doing recertification sessions, access reviews or that kind of stuff.
Likely, it's never really fun, to be honest, but it could be at least better than a pure technical experience. Well, as I meant before, absolutely right. If you're an IT service provider, you're used to deal with authorization, you're used to deal with solutions. As I meant before, we have around 2,500 solutions ending up in millions of entitlements at the very end. And as time speeds up, there are new visions. You already mentioned ABAC, you already mentioned maybe policy-based.
What I miss in the area is a fundamental attribute store where you then are able to feed information in like, oh, well, it's not only the division, it's maybe a tribe, it's maybe something different. What can be used as a basis for authorization? So this is not only about the model. I think this is from Marcin, from you and the same from Oliver. It comes back to the missing information somehow.
Maybe, Marcin, do you have an example about this topic, the missing information, so it gets a bit tangible for our audience? Yes, I think that I was trying to explain that too. We discussed this, that, for example, if you have a company which has, let's say, several tenants in a country, like we have, let's say, five companies within one country, legal units. And each of those legal units needs to report their financial results to the tax authorities every month, and they need to have a signature on the bottom by two people, one of them being controller.
And you need to know those controllers, you need to have those names somewhere, and you need to know who is it for each of the companies. And actually, for three of them, probably, we will have one person, for the other two, we will have another one. And from HR, you'll just get one.
Because, obviously, that person doesn't have three contracts. They have one contract with the mother company, usually, and the subsidiary are just natural consequence. But that natural consequence is never explicitly stated.
So, we have those structures, those organizations which have interdependencies, and we don't really pin people to the roles in those organizations. And it's not our buck anymore, because, obviously, you have those attributes, but those attributes are flexible. You have countries, companies, you have legal organization, management organization, HR organization, in case of companies like mine. We have at least three or four different structures based on which we can grant access.
Probably, same with ERSTE, right? Right. There's a gap between the data you get from HR and data you need for identity and access management. There's a big gap. The question is how to make the gap visible. If you just say, oh, well, I need this and that attribute, it might be too less, because you don't know who will maintain this kind of attribute and where. And reliably, that is the thing.
Also, when I look at my past, then we were building attributes in our solutions, but somehow no one took care about it. So, when we had information that was most of the time outdated, but we had the things and suggested somehow reliability.
Now, let's talk to the vendor. Let's talk to the vendor. How do we solve this? Do you see this challenge in the reality? How do you overcome it, or do you see the challenge?
Yeah, so kind of attributes doing something. So, you said your favorite thing is attribute-based access control. There is a lot of discussions out with dynamic access policies and so on.
So, my thesis is it will be anyway a mix. So, there will be RBAC out, dynamic RBAC, ABAC, policy-driven access control.
So, a lot of things. The big thing, however, is when you are relying on attributes, you have to have proper governance processes in place. Because when an attribute is suddenly now involved in access decisions, in authorizations, then it can be crucial. And probably it was not very important further, whether you are a junior marketing manager or a marketing manager or some other specific title. When it's the basis for authorization decisions, it gets probably a completely new difference. And just recently, I think it was the day before yesterday, somebody talked about his IGA project.
And they have been relying on kind of org unit identifiers. And for whatever reason, it was likely the HR system. Those guys had a good idea on the weekend. But it might be a good idea to change the identifiers for whatever reason. And you can imagine what happened. It messed completely everything up. This kind of intransparent. Nobody sees it. Identifier.
Of course, it's just an internal one, they believed. And it's a mix for me.
So, for me, it's only a mix. So, if you're talking about data, we are doing it right now.
And also, there's a policy one, so to say. We have some where the location is, where the people can have access. We have the HR data. The question is how to mix this up.
So, how can we manage how much organizational effort you have if you want to have a matrix organization also in your HR system? How often do you have to change it?
So, that's a big question. So, to make it from the classical recertification or something like that and have some opportunities. But to bring everything in, how big the effort will be.
So, that's a big question for me. So, is there a good solution to not bring so much effort into it? And that was a question I wanted to follow up.
So, to you directly, Dennis. So, the question is, at the end, do we have – so, you want to go towards dynamic authorization. And we want to all this. And we know this.
Yeah, it's out there. And, Rose, we should not do this.
Yeah, we know. But the thing is, at the end, do we have – and from your perspective – the necessary information to really take these real-time decisions and really replace this manager request and approval where they have some logic, hopefully, in their head.
Yeah, which is not like, okay, he needs it. Do we have the information to do this?
Mostly, yes. From some parts what I mentioned.
So, we are doing decisions. But we also will share later on.
So, for the data perspective, where we say, okay, we have data which allowed in Europe or allowed worldwide or allowed only in Germany. So, that's what we are doing. We have the HR information. But this matrix organization, we have no chance.
So, we have changes every month. You have to fill it in.
So, we say, okay, it's on the managing one. We do the recertification mostly twice a year. That's for sure. In some parts also four times a year. But that's the part how we want to deal with it and how we try to solve this issue. Anyone? Something to add? I saw you shaking. In regards to data that can be combined.
So, again, it's a bit of mix. So, I think kind of having proper birthrights. But there is a need for recertification on the identity level, probably on the policy level up front.
So, that's an important thing. You read sometimes or kind of regularly there is recertification and reviews are that. That's bullshit.
So, it won't be that. So, it will be reduced sooner or later on an identity level. But you have always to recertify your policies on a higher level.
So, this work will continue. There is no one who gives it just as a blueprint and it's kind of there everywhere. Exactly. I'll give you a very short example. Imagine you have a transaction. You transfer money from A to B. Now you are allowed to approve the transfer at A's by a second factor. Totally fine. To which degree you are allowed to is coming dynamically.
So, the problem I see here is how do you prove that in that just point in time, because you got the task of the day, because the manager is not here, is on vacation, whatever happens, the task of the day you need to approve transaction about 100K. How do you prove this 30 days after? How do you do that? It's a tricky part.
So, either you go for just in time approach. Tricky.
So, I believe there must be a kind of baseline, which is normally, I believe, Airbag, isn't it? So, yes, you are, you can. Theoretically, you can be in charge of approving a transaction 100K. This is provable. And in the exception, you go for a second factor, something like that.
So, yes, I believe Airbag is necessary to do such things. This doesn't mean that policy-based or attribute-based is not needed any longer. It's a great stuff. We're also dealing with this on our level. And especially policy-based can, if you use data wisely, you can enrich access decisions so smart.
So, thinking about the GSE space, where you have third-party management, you have there, when you're kind of collaborating with external employees, consultancies, contractors, and that kind of stuff. So, you have clear information what you're normally doing when you do a vendor onboarding.
So, your procurement, there is an Excel spreadsheet filled in and saved in a SharePoint and never opened again, most likely. But in the spreadsheet, and if you put it into a system, there is information like, is this company ISO 2701 certified? Do they have the technical organizational measures in place that you require as the kind of contracting company? Is the hardware managed? And all this kind of stuff. And if you bake this into policies, you can, for example, say, okay, I have an operations team at an external systems integrator. Let's pick Accenture. Probably someone is here.
And they do operations in India. We know they are ISO 2701 certified. They have managed hardware. Their team is in India.
So, all those guys who are falling into this policy are allowed to access the production facilities and machines within their scope. When they're thinking, okay, let's transfer the team to India, sorry, to China, then all of a sudden, those folks is out of the policy and is not allowed to access anymore. And when you have not just only Accenture as a systems integrator working for you, but also this super smart, skilled contractor. With an Apple MacBook and administrative permission. And the children are playing computer games on the weekend.
Most likely, you really appreciate the skill and the smart brain, but not this MacBook. So, you will decide, okay, unmanaged hardware, no ISO 2701, not with this MacBook, but I provide him a VDI client.
So, basically, this guy has to go to work with the company in a different way. And this should not be your decision as the kind of internal manager who thinks properly about these issues or not. US IT folks or most IT folks probably do it. But that goes for the business departments as well that have probably never heard that there is an unmanaged or managed hardware or something like this out there in the world.
And so, policies can bring a big relief into this kind of stressful situation. So, we are already at the end. I would have plenty more questions to discuss and so on.
So, maybe, yeah, I think we get a bit distillated to get down to the topic. Yeah, somehow the approaches are staying and mixing, and I think there's a lot to do in the future, right?
Indeed, Patrick just needs another cup of coffee. Yeah, he wants a coffee. Afterwards, afterwards.
Oh, okay. This is the chance. Same applies to the people online. We have the Q&A here on a tablet, so we can see the question. If you feel you have a question to the panel, then please raise your hand or ask the question. Do we have coffee? Okay.
So, I mean, if that is not the case, then I'm also happy to close the panel and already announce then the next speaker. We have then some time for changeover. Thank you very much to this very interesting panel discussion here. Thank you.