Can you guys hear me? You can hear me. How are you all doing tonight? Are we at the point where speakers are keeping you from having lots more fun of the other kind? I think so, maybe.
So, a year ago at EIC, I presented my ideas about what I called Mastering IAM's Higher Purpose. And some of you were probably here for that. I've now deepened my research and my work in this area and written a book about it. I have a confession to make. It's about identity, but I didn't write it for you. I did write it hoping that you would be able to use it to persuade, to convince your CEO, your C-Suite, possibly board members. Because we know how important identity is to business and its customers. But it's constantly misunderstood, deprioritized, and trapped in turf wars.
So, I developed some practical approaches to help you ensure that identity actually shapes corporate strategy and cultivates trust in the connected world. And I think that this is very consonant with the panel that we just heard about strategic reality when it comes to identity.
So, you've probably seen this phenomenon before. The international bank that has five lines of business and hundreds of internal apps. Every app does things its own way, including user onboarding and authentication. There's ten entirely different methods of authentication. And authentication and access management and PAM all have different owners. And there's somebody who's responsible for something called identity. Air quotes, yes, air quotes.
But, they're an individual contributor. So, this is a real example. Can you guess how much this particular international bank had to pay to fix the problem and unify the solution? If you've been there, would you believe $50 million?
So, in the meantime, the U.S. Federal Trade Commission and the EU DORA auditors are out for CEO blood when it comes to security and identity and liability. And we're used to thinking of the CISO as the chief scapegoat officer, but increasingly, that's the CEO now, too.
So, identity is failing not because of technology. I say it's because nobody can figure out who should own it.
So, why is this so hard? We know that identity originally wasn't designed in. It evolved, shaped by internet survival pressures.
So, I've discovered that four distinct forces have molded digital identity into what it is today. The challenge is that identity is different things to different people, but to succeed, it has to be great at all of those things.
So, I call them the four P's. You might remember them if you were here last year. Protection, personalization, payment, and people. Each of them is something like a fundamental force.
So, protection is kind of gravity in this situation. It's everything risk-facing, everything your enterprise risk committee tracks.
So, gravity has an inexorable pull, and it has long-range risk management effects. On the other side, personalization is market-facing. It's electromagnetic. It sparks powerful shifts in user behavior. Payment is transaction-facing.
So, I think of it as the strong force in business because it exerts a constant subatomic pull. The people force is human-facing. Unfortunately, this is the weak force creating a subtle field that governs relationship health between people and organizations.
So, I want to give you an example that I collected in my book research. This was a customer call center for a massive consumer-facing enterprise. This one actually has 10,000 brick-and-mortar locations, and it's managing 250 million external identities. I imagine some of you can relate. What did it look like for them to verify callers?
Well, it wasn't good. They were using the old-fashioned, cheap, inaccurate method of dynamic, knowledge-based authentication.
So, the help desk staffer would open up the profile of the user who claimed to be calling and then would quiz whoever was actually calling. So, we do still rely on this method, don't we?
So, here are some of the problems that they experienced. Protection is just the start of the problems.
So, awful security, serious problem with points fraud, and privacy risks if the caller ends up social engineering some personal data out of the staffer. On the other end, personalization issues abound because it's an onerous process, it's demanding hard-to-remember facts, and it's costing loyalty and trust. Payment issues abound as well.
So, financial fraud is as much about this pillar as it is about protection. And they were also losing sales. And finally, people are always last, it seems, in this list, but they suffered too.
So, the customer couldn't get the actual thing that they came to get, the convenience, the value, and the help desk staff were in a no-win situation. So, identity failure like this is common, but it's a disaster for every part of the company, even if they don't know it.
So, our identity challenge has metastasized. It probably started as a simple project to provide employees with a single login to some SaaS apps, or to add registration and login to a single customer mobile app or a single line of business.
And now, it has a homelessness problem as a result. Siam will forever be too customer satisfaction-related for its security owners, and too department of no for its security owners, for its marketing owners. Workforce IAM will forever be too governance-related for product owners, and too incident-related for IT owners. Our industry toyed with the idea of proposing a chief identity officer to solve the problem, and I noticed that we don't really talk about that too much anymore. It's my belief that the Cheeto idea was too simplistic. Did it not go? I don't think it went. There we go.
So, last year, I shared this four-set Venn diagram. There you go. Some people would be very happy that I got a Venn diagram onto the screen. I don't know if some of you may remember this one. And I have been, in my research, keeping a running catalog of where identity responsibility lives, based on my experiences over the last couple of decades and the book research. If it's in bold, it's oftentimes, sometimes, owned there, maybe partially owned there, and you can see that there's a difference between workforce and customer-facing IAM and where things might live.
So I've seen identity, or some parts of identity, report in, obviously, to the CISO, could be to IT, could be to the CTO, or could be to product. And sometimes, certainly in financial organizations, you see some parts of the identity picture owned by the fraud department.
Now, there's a whole bunch of other stakeholders that never own identity. You see them here, not in bold, added.
Like, finance as a whole does not own identity. Privacy as a whole never owns identity. The COO really cares. Humans in general, by which I mean both end users, who know that they have a login, and also people for whom there's a profile that they may not have claimed yet. There's information being managed about them, too. All those folks are stakeholders, and they care, but they don't own identity. By the way, do you see the hidden fifth P in this picture? Right there in the center? Productivity. Productivity.
So, that's the efficiency of everybody doing everything in an organization owned by the COO. They never own identity.
So, is it any wonder that our organizational paralysis is killing identity progress? So, great. Identity is relevant to the entire organization and every human being on the planet. Yay! That also makes it relevant to every new trend that comes along and everything that looks or smells like a trend.
So, that means we keep having to assess whether it's time to reinvent our approach as each new assault on digital trust arises. So, in the last few years, we've had deepfakes, non-human identity, agentic. I was looking up when the word agentic started being searched for as a Google term. November of 2024. Really new. And look at us now. Identity wallets have been around more like 10, 12 years.
And, of course, we're all familiar with the phenomenon of declaring things dead. Whether it's XACML or SAML or LDAP or consent.
So, you're doing your best to keep up, but here's the challenge. Your leaders cannot help but make decisions on expired assumptions. And you need to help them.
So, to simplify things, I've developed a quick sorting mechanism for actually any technology landscape. And it helps you and your execs decide how to handle what's coming at you.
So, I had the four P's. Now there's the four T's. Trends are legitimate developments that you need to pay attention to. These technologies will reshape the future. Could be risk. Could be opportunity. And they require a proactive plan. Transients are revolutionary sounding technologies that can be expected to fade.
So, in that case, you can bookmark those and come back to them later at the right time. Tropes are innovations or interventions or risks that have gotten so much airtime that mentioning them produces eye rolls or scare quotes. And each one is going to take investigation to determine whether it's a trend, it's a transient, it's as usual, whatever it may be. Now the most dangerous category is the transparents. They are right under your nose. And they are either reshaping or threatening your industry. But you're looking through them instead of seeing them clearly and being able to act on them.
So, I'm probably going to start some fights by using some examples. And I will say your mileage may vary. It depends on the industry you're in, your sensitivity to market factors. But I thought I'd use these three examples. What do you think identity security is out of those four Ts? All right. My read is that it's a legitimate and growing trend because it complements and leverages a whole host of other star security things. Now we might say, oh, endpoint security is a transient and it's kind of going away.
But there's a whole bunch of very relevant cloud data network, SaaS, API, a lot of different star securities. And I think identity security is finally taking its place next to them.
Next one, identity wallets. I consider this one a trope. And this is where I duck in this room. The reason is that there's been so much ink spilled on this topic. And there's been a lot of promises that have been made. And I think we're only just starting to learn over the last year or two where our focus might not have been appropriate or where it's not yet proven to have the positive effects, for example, on privacy. There's a lot to be learned here. So it bears investigation.
Finally, identity relationships. What do we think? I think this is still transparent for most people. This is still transparent for most practitioners. I think a lot of us in this room know the power that not just going one by one with identity records can be for your organization, that the edges are as important as the nodes and we know that there's graph technology that can be very helpful in this situation. But I think right now that is being completely missed in most cases.
Okay, so if you're an identity leader and you're feeling the pain of these challenges, I want to suggest three key moves that you can make. First of all, I recommend that you reframe identity from a perimeter to a product. What do I mean by that? We know that identity is kind of the organization's business model in disguise. But how to prove it is the challenge. So what I want to suggest is that you need to look for product-market fit in more than a hypothetical sense.
So to go from an IT ticket mindset or an incident mindset to being able to impact strategy outcomes, an identity leader needs to be a true identity product owner. So there's product management tools that they can use, like the Jobs-to-be-Done framework. You reframe stakeholders as your customers. In the book, I share an example actually from workforce identity. User access reviews. We can see that as infrastructure to support compliance only, but in fact, there's so many customers for this. Executives who want to stay out of jail.
Risk and compliance leads who say when they get up in the morning, well, I might have a breach, but I will get audited. So they have needs for transparent proof of what they're doing. Security professionals want least privilege and possibly greater zero-trust maturity. Line of business managers just want their people working and fast. Those workers want to be not left hanging when they go and request access to do something legitimate. And of course, IT wants to automate, scale, and save money.
By the way, I like to include threat actors as a customer so that we can be sure to not satisfy their needs for lateral movement and privilege escalation. So if you think in customer terms, a whole bunch of things become clear. Second key move you can make is to pivot away from zero-sum thinking. Quite often, we still think in terms of security versus experience, privacy versus security, risk versus reward, so on and so on. And the thing is, there's all kinds of great new tech and new business requirements that make it possible and necessary to hit a higher watermark in this picture.
So I want to give an evocative example here. This is an organization that I interviewed. They developed an entire internal marketing campaign for their workforce single sign-on and MFA program. So the scope went across 1,500 apps, serving both knowledge workers sitting at a desk and frontline workers out there interacting with customers. And people are so happy with this rollout that they have started to write to the CISO and kind of write little love letters. And so there was a real marketing campaign with kind of a product name and stickers and videos and all the rest of it.
This is very literally treating this product mindset in a way that is productive. And I want to give a second example from Siam. This is the happy conclusion to the customer call center example that I gave earlier. So using technology that this retailer already had in place, they replaced the dynamic KBA with an out-of-band customer authentication flow, something like CIBA, client-initiated back-channel authentication. All they had to develop was one new button for the help desk staffer to push. And they improved demonstrably all four P's at the same time. Really no additional cost.
This is possible when you think about not having to compromise. Finally, the third move that you can make is to bake all of those no-compromises wins into compound KPIs that are pre-designed to have board relevance. I have to say, it's been really hard to get a good view onto designing identity metrics. I asked everybody that I talked to, and I found a lot of uncertainty, hesitation, confusion. But I did collect a few gems.
So the really big problem is that whatever exec you report to, and I'm not here to say that you should report to any particular executive or function in the company, it's going to be one of them, and they're only going to own some KPIs. They're not going to own all the KPIs. So the product mindset, identity as a product, means that the right metrics should feel like testing a new product introduction or the rollout of new product features. So this is how you make product market fit be measurable.
So I had to put together good advice from several quarters to come up with this example here from Scion. Year-over-year fraud is already a compound metric because it goes directly to the health of protection and payments. And it relates to personalization, too, if you think about the adversarial personalization that takes place in mitigating fraud. Combining it with measuring something that comes from the UX designer world, that is to say, end users' time on tasks. So you're not counting clicks. You're counting the total time to achieve something.
And then combining it with site abandonment targets. When you look at these three things, you've got a powerful suite that tells you your health of all the four P's. And in fact, in some elements, the fifth P as well. And that means that you're checking that users are staying because they want to. You're checking that you're not giving money away to bad guys. And you're checking that your security is healthy. And you can do that while encouraging innovation and agility because you've got that product mindset. So it may seem impossible. Here we are talking to fellow identity leaders.
But I'm here to tell you it can take as little as 90 days to position your identity organization to accelerate board critical risk and growth objectives. So one of the things I do is to help translate the stakes, to help you make your strongest business case, and to deliver a clear vision for how identity supports and enhances your corporate strategy. So I talked about mastering IAM's higher purpose last year. I just want to say, it turns out identity really is a calling. You're not just building login boxes. You're building the reality and the experience of trust.
Identity is the invisible force that accelerates or undermines every interaction and business process you have. You are the ones who can ensure that it protects connects and respects everyone in the connected world. To do all these jobs at once takes strategic thinking, foresight, and superhuman levels of coordination. So as I say in Mastering Digital Identity, your identity-first future is irresistible. We must succeed in orchestrating trust and purpose into the fabric of digital humanity. So I hope that you'll join me tomorrow at 4 p.m.
in B6, where I'll be having a book signing. And I hope you'll reach out if you'd like help with workshops that we can lead your leadership through in getting to a better, more strategic, more impactful place. Thanks for your kind attention.
Thanks, Eve. Obviously, your fan club is in. They were hanging on to every word. There are no questions here. Just one question from me. What's the most common misconceptions you're still seeing with leadership in companies, even in companies about identity, even in companies that consider themselves to be digitally mature? Yeah. The biggest one is seeing it exclusively as a security control or an efficiency control. Yeah. That's mostly where it all starts. Okay.
Well, give it up again for Eve Malone.