Welcome to the KuppingerCole Analysts Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor at KuppingerCole Analysts. My guest today is Warwick Ashford. He is a senior analyst working with all things identity and access and much more out of the UK.
Hi, Warwick. Good to see you. I'm Matthias. Good to be here. Great to have you. And the starting point is some research that you just published. And it's a topic that is interwoven in many things that we currently do at KuppingerCole. We are adding new identity types to our identity fabric. We are looking at different life cycles of these identities, be they non-human, be they human. And your topic was third-party and third-party access to systems within organizations. First of all, maybe before we start, how would you define third-party access? What is that actually?
Simply stated, third-party access, and in this case governance, it was third-party access governance that I was looking at. It means that you're controlling and monitoring what external users like contractors, suppliers, or partners can access inside your organization systems.
So when you let someone from the outside of your organization into your network or systems, even if it's just for a short time, you need to know who they are, you need to be able to limit what they can do, you need to monitor what they're doing, and you need to make sure that you remove their access when it's no longer needed. So that's exactly what third-party access governance helps with. And I think it's important in the context of identity-centric security, because this focuses on protecting systems by managing and securing digital identities, not just networks or devices.
So in this model, the biggest risk is unauthorized or excessive access by anyone, especially outsiders. So third-party users are often the weakest link because they don't work for you. You can't fully control them. They might use shared or reused credentials, or they might need temporary or limited access, but they get too much. So without proper governance, third parties can accidentally or intentionally cause data breaches, ransomware infections, or some system disruptions. Right. And you've already mentioned it partially.
So they are under different lifecycle processes because you inherit them from somewhere. But you said you wrote about third-party access governance. So that means that these are different types of systems. And how do they differ from internal identity governance?
Well, I think they're different to internal identity governance because internal IAM is designed around HR-driven workflows and user lifecycle events like JML processes, right? And also third-party access lacks these triggers and oversights mechanisms. External users are often onboarded manually via unstructured sort of means and processes like from spreadsheets or email invitations. And then that means that governance practices such as recertification, policy enforcement, audit logging, which are standard for internal identities are typically absent or sort of fragmented for third-party users.
The question often is also, why? Why are we talking about that now? Have things changed that people, that organizations are more involving third parties? Is this kind of changing supply chain? What is behind that?
Well, I just think in today's kind of hyper-connected world, organizations are kind of dealing more with external organizations. And so I think the biggest problem is that in many organizations, third-party identities are now often outnumber internal users, particularly in industries that rely on things like, as you mentioned, supply chains, outsourced development or services. And these external entities frequently gain access to sensitive systems without the consistent processes as I mentioned earlier for onboarding, identity proofing, and certification.
So this inconsistency results in stale credentials, excessive entitlements. I think that's one of the big problems is people get too much access to too much. And then this creates like invisible access pathways, creating an expanded attack surface that's often exploited in breaches because the bad guys know this. And they know that people aren't paying much attention. That's where they go to work. Right. And when I look at customers or organizations in general, we are talking to many organizations.
I will not give any names, of course, but often external users are just maintained within the regular IAM for purposes. For example, if I maintain them myself, I have a better control, which I would disagree with. But when it comes to the architectural limitations, do traditional IAM systems limit the management of third-party users?
Well, as I mentioned already, most IAM systems are designed for employees and known partners within the organizational boundary, within the controls. So there's a lack of organizational identity structures. So traditional IAM systems operate on a flat identity model and they don't support N-tier ecosystems. And there's limited delegation. They fail to provide mechanisms for delegated governance, which is essential for managing access across external organizations.
Also traditional IAM, the identity proofing and onboarding, they rely on a sort of a structured thing, whereas I mentioned earlier, the third party, it's unstructured. And so this creates a credential sprawl. Also there's infrequent certification. So these systems rely on a kind of a point in time reviews. And so they miss the access changes that happen in between. And finally, they lack cross-organizational P-back and R-back policy enforcement. So this again leads to over-permissive access. Right.
I've mentioned that in the beginnings, we are thinking where we love to think of identity systems as being constructed following the concept of the identity fabric. And our colleague Jonathan Kerr was here a few weeks ago and he talked about the cybersecurity fabric. How can these models be beneficial to support third party access governance? Do they help? Do they allow for integration?
Well, absolutely. But I think in this bit of research that I did, one of the interesting things that came out for me was that in a way, third party access governance, I think should be thought of in terms of being an evolution of the identity and security fabric. So it's the same idea. It's just going beyond by recognizing. So the identity fabric must, if you look at the identity fabric, it must evolve from a user-centric approach to an organizational aware model. So it's not just about user, but talking about a wider organization.
And it needs to include third party onboarding, delegated approvals, policy inheritance and lifecycle orchestration. And it also must accommodate federated identity sources and manage access across multi-tier partner ecosystems. So that's the identity side of things. And then the security fabric needs to integrate with the identity fabric to provide cross-tenant logging sort of behavioral analytics and policy enforcement. So they should be able to detect analogous behavior and trace access violations across external systems rather than just internally.
So think of third party access governance as governance overlay. It acts as a dedicated governance layer, so to speak, that bridges the gaps between both fabrics. So it bridges the security and identity fabrics and it provides capabilities like event-driven certification, delegated governance and risk-based access controls. So that enables visibility and governance beyond the enterprise.
So I think that's just the best way to think of it is being able to see and govern what's going on beyond your enterprise, which is increasingly important because more and more now, I've been doing quite a bit around third party access failures. And I was surprised just how many breaches in recent times and going back the last 10 years, where it's traced back to a third party. And so I just think this has never been more important. But we say that about most things, really. Exactly.
And just everything what you said, if I think one year back, so we were discussing with many organizations and the dust has settled a bit, but the problem is not yet solved. Many organizations were talking about upcoming regulatory frameworks like DORA for finance or NIST for critical infrastructures, while the scope was immensely growing. I think everything that you said is part of these regulations. So having a proper control insight into what third parties, what your supply chain does within your systems is as important as what your own employees do.
So is this a driver and does that shape the need for third party access governance and make you write this thing at least partially? Yeah, sure.
Look, I think regulation is a very important driver, but even it's a good indicator of what should be the best practice, really. So what's great about the regulations that you mentioned is that they recognize that third party access is a board level risk. It's not just a technical detail that must be taken care of.
This is something that can, so if you speak to the board of maybe Marks and Spencers, they might agree that third party risk is something that they will pay a little bit more attention to now that they are having to spend a couple of hundred million to recover from something that at the moment still looks like it was traced back to bad third party access. Specifically, DORA mandates that financial institutions govern the entire life cycle of third party ICT providers. So that includes continuous certification.
This too requires identity centric security for all access relationships across critical infrastructure. And then the CMMC enforces identity verification, MFA and authorization life cycle for entities within the US defense supply chain. But more importantly, I think all the shared expectations across these frameworks, and I think this is what the end user organizations need to imbibe, is that identity verification for third parties is important. Strong authentication and continuous access certification is important. Policy based governance is tied to business relationships and risk levels.
And finally, auditability and accountability for external user access. I think the days where boards or organizations are responsible only for the people within the walls, so to speak, of their organization or within, even if it's a multinational organization, it used to be sort of clearly defined. Back in the day too, in terms of when we had perimeter controls, the perimeter was ours and anything beyond that wasn't our problem. Things have changed and we've been talking about it for years, but businesses still seem to be struggling to implement this.
I think we've understood it for a while and we've been talking about it for a long time, but I'm still seeing organizations where they just aren't doing things in a practical way to say, yes, we understand this, we get it. Okay. Let's assume that everybody who's listening right now understands that. They understand what you've mentioned, credential sprawl, entitlement drift, unstructured onboarding. What are some typical capabilities within these third-party access governance solutions that help organizations in actually addressing these risks? How do these solutions look like?
Well, you mentioned credential sprawl, so a TPAG could enable an organization to, well, it kind of requires an organization to enforce phishing-resistant authentication. The push towards pass keys and use of FIDO-2 compliant tools and methods, because it eliminates reliance on shared credentials and email-based invitations. I think that's the first thing in terms of credential sprawl.
Then it also helps control entitlement drift, which as you know, and in your advisory business, this is a perennial problem with many organizations where people change roles and the entitlement just don't get updated. With TPAG, it's event-driven recertification, so it's triggered by status changes and it's linked to risk signals, so it automates, it ensures things like automated deprovisioning, so where access is no longer justified. If you change role, you leave organization, project ends, your access ends. It's no longer this kind of thing.
It introduces the idea of structured onboarding for people beyond the organization, so it enables multi-tier onboarding, invalidating both users and their organizations. It incorporates identity proofing, document and biometric verification, and then also has delegated workflows. It also applies policy inheritance that I mentioned earlier to ensure that there is consistent enforcement across external organizations. These capabilities all ensure that external access reflects the current business context and not sort of outdated assumptions.
It kind of helps the organizations keep pace with the reality that's out there rather than just a point in time. Right. That's really fascinating. I already come to my famous final question, as usual. If we think we are also here to educate and to raise awareness, if there are organizations out there who realize there is a gap in my security posture, in my identity fabric, I have not yet really thought of this third-party access because I'm not critical, because I'm not a financial institution, but I think I should do that.
Before running and buying something, a solution, what would be – and that's the question, this famous last question – what would be a good first starting point to embark on that journey beyond tools? I think there are quite a number of things that organizations need to consider, but I think the most important thing is to treat third-party access as a governance domain, not sort of just an integration task. As we said earlier, third-party identities outnumber internal ones in many environments, and they often present a higher risk.
I think it's just kind of that mindset change that I was talking about earlier is that you need to think beyond the organization. Managing access cannot be limited to provisioning accounts or federating logins. Governance must include onboarding assurance, delegated administration, lifecycle orchestration, and continuous certification. Just like in the cybersecurity world, there's got to be continuous verification that people that things are who they are and that things are being checked all the time.
Actors or entities that are doing things need to be continually certified, and then extend your identity and your security fabric architectures with TAP capabilities, which we've been talking about. So really interesting, and it adds another facet to this identity fabric that we are talking about, adding these B2B customers, these – no, not customers, partners, everything that is outside organization and that need access to our internal systems, to our cloud access, whatever. So really interesting.
Thank you very much, Warwick, for being here today, for telling really freshly from your just recent research around that topic. If people are interested, that paper is also available. We have Warwick's name. Just Google for him within our system and just try to find him. And there is lots of information around these topics and many other where Warwick provides research as a foundation for everything that Köppinger Co. does. If you have additional questions around that topic, and if you're watching this on YouTube, leave a comment in the comment section of this video, just below that video.
If you are listening or watching this on any other platform, just reach out to us. We are happy to answer your questions. And if you have specific questions that might spawn another episode of this, why not? Let us know. We are interested in that. So third-party access governance sounds a bit dry and not boring, but challenging. But it's really an interesting topic, and I think many organizations are still beginning on that journey and trying to fulfill their requirements when it comes to that. Any final thoughts before we close down, Warwick?
Yeah, I think it's just important to remember that having this third-party access governance ensures that external users are governed by the same principles like least privilege, strong authentication, and continuous certification as internal users, but with mechanisms designed specifically for inter-organizational contexts. And go do it now, today.
Exactly, exactly. For those whom we just informed that there might be something to do, do it. So really starting there. And reading Warwick's paper might be a good starting point as well.
Thank you, Warwick, for being my guest today. Looking forward to having you here again soon regarding your research or any other interesting topic that we cover. Thanks again.
Thanks, Matthias. Bye. See you. Bye-bye.