Okay, so I'll make, put my statement out here. This is not a what and a how session, this is a why. So if anyone in the room is looking for business case information to help them get some funding, let's start the conversation right now. And I'd like to start by making a statement and putting myself on the line and saying, okay, I think as an industry we're kind of ignoring 80% of our workforce, of our users, okay? I blame myself for that as well. And I think with the agentic, a rising agentic, it's only going to get worse and expose this gap even more.
It's going to be quite a few of the cliches you've heard all week around trust and gaps. So what is the frontline?
Frontline, in old money, was blue collar workers, okay? Does anybody in the room consider themselves as a frontline worker?
Okay, I've actually had one person put their hand up and say that when I've done this session before. So 80% of the global workforce sits in the frontline. Around 70% of that 80% work in critical infrastructure.
So energy, water treatment, health care, all these critical services. And yet 50% or more often admits to circumventing controls that we've put in place. For example, credential sharing. I'm sure everybody's seen in a retail shop or in a pobo somewhere else, people just moving from point of sales to point of sales. Those are the people you see. The ones you don't see are the ones who just do it in a warehouse or in a manufacturing plant. And I'll come to the reason why.
Very, very few organisations, as few as 13% of organisations actually really think about these people and their challenges when they're building their identity access management policies. So one thing we need to do is dispel the myth that frontline is just manufacturing. Frontline is anybody who works on an actual task, really. So think about it as warehouses, logistics, utilities, point of sales, and health care, which touches most vertical industries.
FSI, maybe not quite the same, but some of the same challenges are there. So this basically touches everybody in every industry. I use the term at PING, and this is definitely not a sales pitch in any way, shape or form. We refer to workforce as the extended workforce.
Now, why do we do that? Because workforce traditionally is about employees, people like us, potentially on long-term contracts, job security-ish, contractors. We're in IT. A lot of people, I'm sure, in this room have done contract work. You're still tasked in the workforce or as a temporary employee. And this is where we have the intersection beyond the workforce. This is where the B2B. So if anybody was in this room yesterday afternoon, you would have heard all about B2B.
Frontline is a fantastic intersection across this because all of these industries, all of these types of roles sit across an extended supply and distribution network. And most organizations cannot survive without that extended distribution network. So partners, business customers who have very similar use cases to business partners when you actually dig into the detail, and obviously the agents. I'll try and keep the agentics of light if I can. Problems. Let me talk about some problems. So lots of AI used for building these images.
For the last two years, myself and a few of the guys in our industry, guys like Marco Venuti, who was here yesterday, have been trying to preach we've been looking at it wrong. We've been operating in silos. So hands up, who comes from a workforce background? Who comes from a Scion background? Did you really cross over all that much? As an industry, we've been very, very siloed. And thanks to giving a call to John Talbot, we now have B2B. And that's why I am now the B2B segment lead at PING, because we've realized this has to be addressed specifically because it has its own challenges.
However, it does not operate in isolation. It's the intersection between workforce and consumer. And Frontline sits across all these. What does that actually mean? Lots of words on a slide. Think about workforce. When you talk about workforce, you talk about lifestyle management, entitlement management, IGA, PAM. Consumer side, it's about progressive profiling, social registration, experience. B2B has brought forward a delegated administration. It's not a new thing.
However, granular delegated administration to third parties, to fourth parties is kind of new. And organizational relationship management is kind of something we haven't really thought about. And then we have the universal services that sit across everything, such as SSO, MFA.
Now, what does this actually mean? Now, working for a vendor, and I've worked for SIs as well, is we deal with a lot of tenders. So if you're a customer and you send out a tender, it's an exam question, isn't it?
Okay, can you hit these X amount of technical questions? What happens if you send out a, I need to deal with partner identity access management?
Well, that tender is going to be the stuff on the left. If you put out a tender for partner identity, you will get a workforce solution. You will get IGA, you will get lifestyle management. You will not get anything over here. If you brand your tender B2B SIAM, what happens? It's this stuff. You get what you asked for.
Okay, and it's this realization. And actually, frontline, B2B, all these things, you need bits of all of this, really, because you're dealing with B2B to E, B2B to C, so employees and customers, or even more extended supply chains. So what's the solution? I tried not to just steal and plagiarize. People can call it Identity Fabrics graphic, or put the pink graphic on there, but I could have put here, Identity Fabrics is a really good start.
Okay, because what Fabrics actually does, it removes these silos of identities. It says, okay, we have some problems. We have some identities. Here's the capabilities. Let's apply the correct capability to the problem and to the right set of identities without this bias and silos of workforce or SIAM.
Okay, so that is the first takeaway. Think about the Fabrics as a good starting point to build out your frontline and B2B solutions. What does it actually mean? Let's do some comparison between knowledge workers and frontline of white collar, blue collar. First one is around devices. We're corporate workers. We get issued a laptop. We might get a mobile device. You have a one-to-one device relationship. On the frontline, it is anything but.
It's a one-to-many or a many-to-one, which means if I'm an operative in a shop, I could go into any number of point-of-sales machines during one shift, and that machine could have any number of users on that device. It's a completely different device model. So how do you do device binding? How do you do biometrics if you have that kind of model? Access predictability. We work nine-to-five-ish, okay? If you just look at our access patterns over 12 months, it's a very consistent pattern. Not the same on the operational front.
Okay, they work shifts. They work on call. They work in different geographies. They might have different tasks as well. Everything is different about the access patterns and access requirements. The work environment. We get health and safety assessments to make sure we're sat straight, with nice lighting, a cup of tea, the correct keyboard, anything but on the frontline. Point-of-sales, running around, working on a shop floor, in a manufacturing plant or a pharmaceutical plant. Dirty environments, clean environments, dark environments, dusty environments, masks, hats, gloves.
Completely different to what we do on a day-to-day basis. Problem.
So, we've heard a lot about runtime this week. I'm pretty sure everyone's talked about runtime.
So, to explain what runtime is, I'd like to position it side-by-side with what we mean by admin time. So, admin time is the traditional workforce kind of management, okay? Mark starts at a company, is a product manager based in the UK. Based on that, those attributes, certain policies say you get these roles. That's great at that time of onboarding. And my access will only probably change if I change roles, change jobs, or request additional access.
Very, very static. In a disaster scenario, no one does these things. You don't really care about those kind of capabilities. Runtime and the operational side of things is all about context. Different locations, different times, different shifts, different activities. And what we end up with is a significant drop in assurance around the identity itself. Okay?
So, when we're building solutions, traditionally, we're building for that side. We're not really, generally speaking, building for this side or considering this side as much as we should do. And to totally go off the identity topic, I'm bringing this forward, we can't forget about the people.
Okay, 80% of the workforce is frontline, the people. Even with agents, there will be humans working with the agents as well.
So, what are we doing? Where's pressure? Operational systems don't wait for authentication. Okay? All we're doing is putting in barriers. They see it as barriers.
You know, we see things as barriers. Oh, I have to sign on again. That's a barrier. If you are in a manufacturing plant or taking a patient into an A&E ward, you can't think about, oh, I need to sign on. I need to change my password. It's seen as barriers. And all these barriers create pressures because these guys work into actual operational pressures. Okay?
So, when we say, oh, we need to get this quarter out by midnight on a certain night, that's not a big thing. Lives are at risk is pressure.
Quote, and tender processes are not actual pressure in the real world. And what we need to do is think about the actual fault of the problem, not the symptom.
So, credential sharing is the symptom. The problem is how we are managing and putting these barriers in front of the operational workforce. What does this lead to?
Well, this is just one of a thousand different things I can say it leads to. The reason I picked consignment fraud is because every single logistics company I speak to globally at this moment in time, this is the number one ask. Can you solve this problem? What is consignment fraud? Okay. Think back to the 1920s. Consignment fraud would be a bunch of mobsters turning up, give us your truck, running off with a truck. Okay? We all know the phrase about everybody logs in these days. Everything's done by logging in. Okay?
Well, that's exactly what's happening here is some bad actor is going to a warehouse or someone picking up a truck saying, I'm the person you think I am driving off. That is the problem. And that literally hits every single organization assorted with a supply chain.
So, this is a major, major issue. So, the shipment looks right. The person looks right.
Yeah, you've got the right credential. Goodbye. How do we verify? How do we kind of think about the trust at the time this is happening? This is where we kind of talk about the actual trust element of this.
So, implied trust. What is implied trust? Okay. I log on in the morning. I sit there with my laptop. Don't touch anything else. That trust is correct at the time I authenticate and access my machine. And that's single sign on to absolutely everything else. Works okay when I'm sat at home in my office. But as we've seen, when you're on the operational front, you don't have that ability to just kind of sit there and just be implied that I'm trusted permanently. What we need to do is move to explicit trust, explicit continual trust. Okay.
And these are the things we need to think about in real time. So, identity. What are you? Human or you're an agent? What about the organization you're working for? Are you a partner? Are you a customer? Are you an employee? Is that relationship still valid at this time you want to do something? Where are you? Are you in warehouse one, warehouse two? Are you in a warehouse in a different company? Are you up at telecoms mass trying to do something? Where are you? What time is this? Is this your normal time of work? Okay.
If I'm sending off or signing off a consignment, okay, my working day is nine till five. If I'm trying to do something at 515, suspicious, do we need to maybe add some extra step up authentication or checks or stops at that point? It's all about context. It's continual context at the time, at the run time. And that is the big, big change.
So, this is it for the humans, but it also applies to agents. We've all heard about, and we all talk about speed and scale that the agentic is going to bring. But one of the questions I get asked over the last probably three or four months is, or one of the things I get told is, Mark, yeah, we're thinking about agentic, but we can barely get lifecycle management right after 10 or 15 years of trying to do this. We just can't think about it now.
Okay, well, organizations are going to have to think about this because other organizations, your competitors are doing this already. And what's actually happening on the front line and the B2B side is, okay, working across trusted boundaries.
So, we'll hear a lot about consumer agentic. We'll hear a lot about workload and workforce agentic. What about third party agents coming in and out across trust boundaries? You still have to ask the same questions. Who is this agent? Who is this agent acting on behalf of us or whose authority?
Obviously, no impersonation, always delegation. And does the context at the point this agent lands to try and do something, is it valid at the point of transaction? The third party, the B2B adds extra complexity because it's not your agent.
Okay, and at what point do you say, okay, my agent can raise an invoice. You can send me a package, but then we're going to pay this. At what point do you say, add the human to do the step up because it's over $100,000, whatever it is, okay?
Now, again, when I speak to some of our customers who say, we're not ready for this yet, I say, you need to do some research and look at companies like this. So, Walmart is a publicly available reference. I could have pulled up other ones. I quite often talk about British Airways as well. Walmart have been doing this for a good couple of years. They are doing what's called just-in-time restocking.
So, everyone's saying, you go to a retail store, you see the people scanning the shelves, that information gets handed off to a procurement process. And what does that procurement process do? It ensures those shelves are never empty, which is obviously the worst thing in retail. But the other thing is, you make sure you don't have 15 trucks parked outside your store, trying to unload all at the same time, because you end up with other inefficiencies as well.
And also, overstocking your warehouse, and overstocking your warehouse full of perishable goods, which is a massive loss for a lot of retail organizations. So, it's just-in-time restocking, and Walmart themselves are seeing over a 20% increase in their commerce because of this.
So, this is what we need to keep an eye on, see what these big players are doing in the market, how they are doing this, and then we need to start bringing these capabilities in. Because if we don't, you're basically going to fall behind. All the principles I've just mentioned, all the considerations I've mentioned around frontline worker, absolutely applies in the agentic space as well, 100%. Just a little tagline, it just has to work when and where the work actually happens, which is kind of the runtime tie-in. Thank you. Thanks very much. Questions?
I mean, one of my concerns, since you were ending on the agentic thing, and you come up with Walmart, and Walmart has done a good job apparently. My concern, and maybe that's because I've been in security too long, is that the security and identity management needs of agents will be theorizing about it aggressively and be ignored primarily as they get rolled out in real companies. Do you think it's going to be different this time? I guess I'm asking.
No, it's going to be exactly the same this time. That's what I figured. So what I found interesting yesterday, there was a lot of B2B sessions, and Jim from the Identity Center podcast was here, and Marco from TELUS was doing a panel session.
And Jim, you'd think he would know all the use cases, being where he is in the industry. He asked, what use cases are you seeing on the B2B side? And I think this is what we need to do as an industry, is not just focus straight on the what and the how, focus on the why. Think about what are the use cases we have for humans? How are these going to apply in the agentic space? And what's the difference going to be? And then worry about the technical side of things.
Yeah, I mean, essentially, get a seat at the table while it's happening. Absolutely. My presumption as a cynical security person is that we're going to wait for some nuclear explosions to happen.
Then, industry by industry, they'll pay attention. Well, I mean, it's bound to happen. I think if we don't think about the trust and security around the agentic side, it's only a matter of time before we have a whole series of catastrophic events.
Yeah, and that's what I'm looking forward to. Yeah, absolutely.
Well, we are as a vendor, obviously, but no. But yeah, it's bound to happen. It certainly drives action when that happens.
Well, I think, again, from a vendor's perspective is, the amount of people, maybe not so much now, how many people say, yeah, we don't really need to speak to you right about now, we don't have a problem. And then they come to us after they get hit with a ransomware attack and a $50 million fine. All the time. So we need to be on the front foot, really.
Yeah, I guess we at least need to be ready for when that happens so that we can come in and help out. Yeah. Excellent.