All right, then let's start. Good morning, everyone. Welcome to the last day of EIC. And I also like to welcome you to today's track called Enterprise IAM and Infrastructure 5. My name is Charlene Spasic. I'm a senior advisor at KuppingerCole. I will be your moderator for this track today. And I will also be a speaker of the first talk that you will hear in a couple of seconds. For the housekeeping, if you want to raise questions also to our online audience, you have this QR code that you can scan. Let the magic happen, please.
Yeah, here it is. You can raise questions. And in the first talk, we also have a poll. And I would encourage you to participate in the poll because we are very keen on your answers, right?
Okay, so in this track, we will talk about identity, of course, as it has become one of the most critical control planes in modern enterprise security. And attacks are increasingly targeting digital identities, as we are all aware. So that being said, IAM is no longer simply operational discipline or a compliance requirement, but it has become a core part of enterprise resilience and cybersecurity strategy. And across this track, we will explore how organizations can align IAM, cybersecurity, zero trust and authorization into scalable identity infrastructures.
That being said, our focus today is not to talk about theory for theory's sake, but we want to talk about execution, organizational reality and pragmatic transformation. That being said, give a warm applause for my co-speaker for our first talk, Dr. Lisa Zimmermann. Thank you. Good morning, everyone.
Yeah, so to give you a bit of background story, you can already put the title of the first talk. Yeah, exactly. Lisa and I, we will talk about IAM and cybersecurity, two disciplines that ultimately share the same mission, which is to protect digital identities. And to give you a bit of backstory, Lisa and I, we are both practitioners in IAM for about 10, 15 years. And we had this discussion about that it naturally comes that we say, IAM is a part of cybersecurity. They belong together in theory, but our observation in practice shows something different.
And that's why we started to like raise the question, why is that? Why is there this operational separation and ideas on how to overcome it? And that's what we will talk about today in the first talk. Yes. It's great to be here with you. My name is Lisa Zimmermann. I work as a competence owner for identity and access management at Fresnaf MaxiZoo. But actually today, I'm not really here in that role because this is just a topic that's been very close to my heart for quite some time. Charlene explained where this has come from. So I'm really happy that we can do this talk today.
Although it feels a bit like preaching to the wrong crowd because everyone who is here and who is doing IAM cybersecurity, I think we all know what we are talking about. But still, like Charlene said, outside of less IAM-centric cybersecurity, we felt this gap at different stations, talked about this, wrote about this. And that's what we thought, hey, we really have to do this.
Because if cybersecurity and IAM don't work close enough together, then we feel, I'm just going to put this statement out here, that actually without IAM, cybersecurity is watching activity, maybe, and doesn't really know what normal means. Just as a first bold statement. And I hope, oh, it's really dark up here. I tried to put this little picture here. Not to overbear this, but because we all know that your teacher is actually supposed to be blind, right? That's actually supposed to happen.
But honestly, your teacher can only be blind and render her judgment based on all the rules that are out there because she can rely on her instruments. She can be sure that her sword and her scale are working. If that were not the case, well, that would be really, really bad. She'd probably have to peek around sometime and see, is that correct what I'm doing there? Because I don't really know what it is. And you can, without stretching that comparison too far, say the same thing about IAM cybersecurity. Because cybersecurity is supposed to be kind of blind, right?
Really relying on the rules and the policies that is making this up. But this only works if the instruments that make up the whole cybersecurity space are actually working. And honestly, if your IAM is broken, then that doesn't work. Exactly. So here you see a simplified cyber attack, and we want to show you why identity failures matter and that they have real-world consequences. And of course, probably if you've been here a couple of days, you've heard this story, I don't know, five times already.
But still, it's important. So we talk about the why. Why do we even assess this topic? And usually, or in a certain specific scenario, an attack might start with credentials. So the credentials can be valid or stolen, and they are used to log in as a legitimate access, right? The attacker then is in your system. The access will be used to exploit your environment.
And in case they have a lot of privileges, you never do recertification, for example, you have all of those, all of those, the privileges somehow stored or connected to one specific identity, you will be able to elevate and ultimately access sensitive environments and also sensitive information. And once this happens, the impact is data loss or disruption or financial reputational damage. And now we are not talking IAM anymore. And basically, it becomes clear that identity is not just an IAM issue. But when it fails, the impact is business critical.
So it's not just IAM, it's the whole business. And Lisa experienced such a scenario in real life, and we give you some practical input.
Yes, I always have to say something about this, because that's also why this topic is so close to my heart. In 2020, way before I joined Fresnaf, I worked at the university hospital in Dusseldorf, at least within Germany, some might remember this. This hospital, I think it was the second hospital, but with a very, very big impact was attacked in 2020, in the midst of Corona. And what we see here actually happened the exact same way. And actually, I still get goosebumps when I talk about this, because it was horrible.
For over three weeks, the emergency services were not available for one of the biggest hospitals in one of the most densely populated areas in Germany, simply because a breach was used. Luckily, not identity and access management, but unluckily, this happened. The attacker, they played themselves upwards and at some point took over the active directory and encrypted over, I think, 500 servers. And it was catastrophic, especially for a hospital, because it's not only just money there, you really have lives at risk.
And the good thing about it, the only good thing about it, was that IAM was also very crucial in the recovery part, something I could do a whole talk about itself. And it finally put the topic on the security map, because before we were, as usual, very business driven. And at that point, security really realized, okay, we have an IAM, that's great, it really helps us. And just to keep this short, so that's one of my personal incentives why I'm here today as well.
Yeah, so if IAM is so important, that's what we just learned, that's what we all know. Why is it so hard to empower still? And as you can see, in an organization, everyone depends on IAM, and everyone has different expectations towards IAM. So we have the business, IAM wants to enable the business so they can get a great customer experience and enable digital services. We have compliance, which is responsible for auditability and traceability. And we have, of course, cybersecurity, which focuses on control and risk mitigation. And IAM has to serve all of them.
It spans the organization, but if the ownership is unclear, its strategic role cannot fully manifest, so to speak. And also IAM is usually not empowered in decision-making or funding or in, how do I say, in budgeting rounds, right? Because it has this sort of different responsibilities that pull it into different directions. And with that being said, we would be super interested in your experience. So where does IAM sit in your organization today? You have the poll. You can access it through the Q&A section. Can we show the QR code again, please? Okay.
Scan the code, and then you will be able to vote. And at the end of the session, we will take a look at the results. Yes. And just to play a bit of an oracle here, we are guessing that it might be a pretty wide spread across the possibilities there.
Probably, you have a few options that were not even on the list, and we'd just be very interested in that. Because in our experience, it's, well, very seldom IAM already sits in the space of cybersecurity, but is largely spread around other IT functions or maybe even outside. And I just want to take a quick look at why this actually is. Where are we coming from to understand how this relation with security is building? Because well, if you look back, then most of us who started with IAM came more or less from the idea of, well, you have to enable access, make onboarding faster, right?
If you have someone new, they have to be able to work at the first day completely with everything. That's a very big incentive. Very little about thinking what happens when someone leaves. So that security thought came much later. And then this led on to a lot of system integrations. And very often, like Charlene explained this before, especially if you're very business-driven, you're often in this firefighter mode, right? Projects don't realize how important it is, come at the very end, and then just have to build something.
And over time, this show that IAM is very time-consuming, especially if you do it this way. And because it's complex and cross-functional, you're very busy doing just that and maybe just not even realizing or even we maybe even have not realized for a long time how important this is until all the governance controls and issues actually came up and security and risk reduction, identity-related threats actually became more important. I also try to put this together as kind of a timeline. I'm not going to read all the small things.
It's just here that you see the two disciplines over the last 20, 30 years with IAM, again, coming more from the users and directories in the beginning, going over to provisioning, federation, becoming more automated. Again, this onboarding thought being very, very thorough. And then more and more when cloud entered the scene, cloud identity, the governance that goes in there.
And on the other hand, cybersecurity, which is very strong, of course, looking at the perimeters at networks, firewalls, VPNs, then at some point realizing, okay, you have to gather more data to be better to actually react to alerts. So the early stages of CM and so on coming. And then also, I mean, zero trust has been around for a long time, honestly. But if you look at who adapted it, I think I wouldn't put it into the 2010 or so. I put it here because now it actually starts to gain traction. And at this point, you can really see that the two disciplines start naturally to move together.
And realizing that actually the identity, if you look at this, is the natural control plane that you should and where you could actually move on this. But what happens if that's not the case? What happens if your identity and your cybersecurity are disconnected? Because for some reason, your IAM team is doing all that stuff, and your security is looking at vulnerabilities and doing CM and focusing maybe on information security and risk awareness, but somehow you're just not really connected. Then you're missing this shared understanding of what your identity really is.
And I deliberately put, although it doesn't look that nice on the slide, the should know who the identity is, should know what access is granted, should define what normal looks like. Because if this disconnection happens, it could just be that your IAM is not as empowered as it needs to be to really answer those questions. And on the other hand, your security, who sees activity and who wants to react on this, might lack the identity context, might lack the right identity context, because your instrument is broken. Or at least it's not evolving as fast and as good as it should.
And then you're struggling to distinguish normal from abnormal. What is it? Is this user real? Is he supposed to be there? Is this job description, is it correct if he logs in from there? Or even worse, if you respond without completely understanding your business risks. Deactivating users, not understanding that they have like, I don't know, tons of other accounts than just your network account, and that might still be a bad thing.
Or making decisions what to implement and not understanding that actually this decision impacts something else in your identity space and raises the risk there as well. So this is trying to really underline why this broken connection is that without reliable data, identity data, cybersecurity is, from our point of view, navigating blindly.
Yeah, exactly. And to somehow, let's say, provide a solution for that. So what naturally might apply concept-wise is zero trust. We all heard of that. But in reality, many enterprises are not there yet. They still have static entitlements. They still have role-based access controls. So it's hard to go from zero to 100 and implement zero trust. And our point is that what we need at first, before we think about zero trust, we need the right identity context to connect the two.
Because IAM can then provide who the identity is, which activity they process, and security can, based on the identity context, monitor prioritized activities, detect abnormal behavior, because now they know what actually is normal. Think about when you have a signal from a security perspective. A login is just a login. Someone accessing an application is just an access. But if you have risk insight, if you have more context, you can then evaluate what is happening. Let's say a user is logging in at midnight.
A finance user, a privileged one, is logging in from Shanghai, although he's usually located in Germany. And he tries to access or tries to do a privileged activity, right? So this whole context gives you a better understanding if what you are observing is risky or if it's not. And then you can prioritize your response based on the actual risk. And now we have to hurry up. We only have three more minutes left. And from a sort of like value chain perspective, this is what you see here. And at the bottom, we have the identity foundation.
And this is reliable on, this relies on having proper identity data. If you don't have proper data, the whole value chain will not work. So from an organizational perspective, you need a shared understanding of identity risk. You need to know who has access to what and why. And you need to improve the quality and completeness of your identity data to then use the data and integrate it into security processes, because then you have the context and it will improve detection, protection and response. And you can enrich your monitoring signals with access rights, with privileges and the context.
Naturally, what we all want to achieve is to support the business. So we want to create business value. And whatever we do in IAM and cybersecurity, it should be aligned with business outcomes. So you shouldn't treat identity as an IT project, but as a strategic capability and measure value not through, for example, how fast can I process an access request, but how efficient and resilient is my organization and how much risk did I reduce. At the end of the day, it doesn't work bottom up only. We also need top down to create a proper governance. And also ownership is very important.
Governance is a prerequisite and not an outcome of this whole process. And we need shared ownership to create accountability and trust. All right. From a maturity perspective, WISC-Aware IAM needs a reliable foundation. That's what I said before. So we have to rely on the data that we get. We have to make sure that the data is correct and that we can then base decisions on that data. We have the foundational IAM, which is, I don't want to call it basic, but we have the lifecycle management, provisioning, access governance without that IAM wouldn't work.
On the other side, we have this sort of like transformation into WISC-Aware IAM, which is policy and risk-based access, continuous monitoring, and ultimately zero trust in ITDR. But those on the right will not work if the left is totally corrupted. And to wrap it up, IAM should be treated as a strategic capability. And to conclude our question, should it belong together or not? IAM is a cybersecurity discipline, but it is more than that. We cannot only focus on cybersecurity. It serves more. But what should we do? First of all, establish a baseline, understand where your IAM actually stands.
You need to review your data quality, your maturity, and also the integration into security. You should define ownership. You want to position IAM as a strategic capability with ownership, with budget, with KPIs to make it measurable, and also to create accountability across the organization. Point three, build collaboration loops, connect IAM security, business, and all necessary stakeholders through shared activities like shared risk reviews, escalation paths, and feedback loops. Not only after the incident happened, but best case, do it before it's too late.
And the fourth point, create early momentum. Prioritize first steps that create visible value also for the business. For example, you need to identify high-risk identities or use the IAM data to enrich selected security use cases. Anything to add?
Yes, well, it's all there, but really as a call to action for that, we really view it as a cybersecurity discipline. And it doesn't really depend on where it sits in your organization. It's important that you're endorsed by it because it is the pillar of your security. And because it is so much more, it has this wonderful ability to actually enable the business to bring user convenience. It's one of the few disciplines in cybersecurity that actually does this.
So use it and bring it there so that your organization can really blossom using both tools, being secure, and being on the front line of your business. Thank you very much, but we should look at the polls.
Oh, yes, the polls. Actually, we don't have time.
Okay, maybe we will post them on LinkedIn or something a bit later. Yeah, let's share them on LinkedIn. I don't want to take too much time away from our next speaker.
Yeah, okay. Thank you so much for your attention.
Thank you, Lisa. Thank you, Shirley.