All right, so after the introduction of talking about AI regulation, so this is not an AI talk, this is about two steps before that, but let's start at the beginning. I'm Daniel, I work for DigiCert in the solution engineering field and my regular day-to-day job is to consult our customers on how easy it is actually to manage and to put a life cycle on non-human or human identities, so there's just a small part, non-human identities.
And if I do a good job today, I not only show you how easy it is to put a good and easy life cycle on those identities, but also and let's, I know we have all the big challenges about AI and so on, but never forget there are regulations in place that we have to meet. And so I want to talk about how to not only automate your identity life cycle, but also to achieve this in an audit-ready compliant way. So let's dive into this.
So my entire premise is that all those regulations that you see nowadays, whether you're in the finance industry and DORA or you do any smart gadgets around the CRA or you're in critical infrastructure, then this too applies to you. So all those regulations, there are not so many surprises when it comes to identity management and cybersecurity. They all basically base on best practices that are now required.
So one of those, the four pillars of those audit-ready compliance and identity management is like you have to know your assets, know your identities, and of course an Excel file won't do the trick anymore. You have to govern your identity. So most likely you have to do risk-based assessments and based on your assessment, you will come up with policies on how to guide your identities. And of course, and that's why everybody is coming in the first place, of course, automation, right? Average company, and I'm not talking about big ones. Let's take my previous employer. We're 160 people.
We managed about 2 million device identities. So automation is the key to success.
And well, let's face it, automation is also important because most companies don't have the staff to do this also manually nowadays. And the key point about my speech today is, of course, this is what you want. You want to automate, you want to know this is your business purpose, but your auditors, they want you to prove this as well. So this is also something that you should take care of. So let's tackle those four pillars. So the first thing that you have to do is, of course, know your identities because what you don't know, you cannot govern, you cannot monitor, you cannot secure.
And again, as I said, Excel won't do the trick. So apologies for the analogy. I'm a big fan about scuba diving, so this helps me guide through the speech a little bit. So imagine you're a cave diver and you're asked to map out a new cave or new cavern for the tourists to come to have some fun, right? So you have a lot of tools, like you have your spools, your reels, you have your wet notes where you can make little underwater drawings to map out the cave with lines and you come back with insights. So of course, we have tools to automatically find your identities.
So and again, this is not just agentic AI stuff. This is like all the fundamentals, all the basics, your services, your applications, your servers, your machines, your human, your YubiKey tokens and whatnot. So the first and easiest way, of course, is doing network scans for everything that has an open port. So we can easily scan those infrastructure on premise or in the cloud or in the internet and to discover all your identities and put them into a general inventory. We have multiple ways to do this.
Of course, since we are as DigiCert, we are a SaaS solution, so we have to bridge the gap between our environment and your on-premise infrastructure. So one of the key keys to that are our DigiCert sensors, which are basically closing the gap between our two infrastructures. So you can easily scan your networks internally. Second thing is, and this is almost effortless, doing cloud scans, meaning they are coming, originating from our solution.
You just basically, and we will see this in action, basically hand in the endpoints and we will scan them and let you know about the identities and, for instance, cipher suits that we have identified on those ports. CT log monitoring, even less of an effort than cloud scans, because you just type in your domains that you want to monitor for your public identities, for public CAs, like Let's Encrypt or us.
You just hand in your top-level domains and we will, for you, discover from the certificate transparency logs your identities that are by now most likely published there, if we talk about public trust. Now a little bit closing the gap to also your agents, which in the past we called them clients, but nevertheless, we also can put or manage identities on any machine or any infrastructure. We can place them, we can renew them, and system scans are powerful to do this.
And let's move away from the fancy stuff to the very old school stuff, because every company, I would assume that makes goods and produces goods still have that. You have your non-human identities somewhere deeply buried in OT, non-accessible, non-automatic, but you still want to at least monitor and track them.
So hey, just upload your identities via API. We will see what this means in a second, but at least you can monitor it, you can check the validity, and you can make decisions based on the insights you get from there. And the most powerful one and the one that we will see in action in a second is what we call connector discovery. All our clients, when we sum them up, there are like 50 to 70 common use cases that we see every day.
So our connectors are basically plugins, whatever you want to call them, that integrate into the most common appliances environments that we have seen on our customer side to not only discover certificates or identities that are placed there, but also to use it to issue new identities. Because let's face it, when we talk about identities and companies, somewhere in the loop there is deeply buried in your own infrastructure a, for instance, Microsoft CA or like an active directory certification service or certificate service.
So let's take a look how we can discover the identities in your organization that are managed by your own on-premise Microsoft CA in a quick video. So I talked about the sensor.
Of course, we need to have this little thing in the middle. Here you see all our connectors that we have for all the common problems that we see or appliances that we see every day. It's as simple as that. Credentials. It will read out all the templates of your Microsoft CA. It will read out all the certificates. And in the first step, you see discovered certificates 81 and you already have them in our inventory. And the second option, and maybe I skipped this, but it almost looks the same. It's the cloud-based scans where you just decide, okay, you want to do one.
You hand in the endpoints that you're curious of. You make a small configuration in the next step showing or configuring what else TLS handshake cipher suits a server configuration, for instance, and then you end up with a search result about the endpoints and discovered identities on this. And with building an inventory automatically, that's good, but it's just the start. The second part about having this automatically generated with us, you already get like insights out of the box.
And second of all, you can also for those just recently discovered identities, assign, for instance, owners that will be informed about the life cycle of this identity. So now we know what's broken. Let's put some rails in place, some guardrails in place. Let's move on to governance. So we mapped out our cave to Stavis' analogy. And now we have to like place all the warnings based on our findings, like, okay, no diving beyond this point. Only death will await you here. So we will do the same for our identities. So what we have, of course, is we put everything in profiles.
We use those profiles to enforce, for instance, validity periods of identities, key sizes, key types, what can go in and cannot go into an identity and who can issue it, who can renew it and whatnot. And of course, this all evolves around role-based access control. These are all the things that, of course, you have to have by now.
I will skip this a little bit due to time constraints, but in essence, you will end up with a bunch of rules stating that, okay, from your Microsoft CA, you want to issue server certificates or identities that are valid for one year based on RSA or elliptic curve, whatever floats your boat. This is how you configure it. And you end up with a solid configuration and set of rules for all your identities based on the risk that you identified evolving around those identities. All right. So we have our set of rules now defined, right?
Every regulation wants you to put everything in paper, but as for the discovery, we can already generate some insights and from those governance profiles, we use them as the base set to automate those identities. Well, I said we have a lot of standing integrations for many day-to-day appliances, cloud workloads, and whatnot, what we see in our customer infrastructure, like from zero-touch provisioning all the way to connecting CAs from, of course, our own and external ones on-premise like the Microsoft CA.
But again, all those common things that we have made way more than on the slide, majority is only 51%, right? 49% corner cases. So you need a strong foundation for those corner cases. And this is standards, industry standards, right? There's nothing fancy to it. These are all well-established components or protocols. We love standards because it's always good to talk about an RFC standard instead of negotiating the perfect way that somebody wants. But these are all our enrollment methods. We have way more to this. And let's see one in action.
We just used our connector or one of our connectors to integrate the Microsoft CA. We already discovered 81 certificates that have been issued somewhere else. Why are this? Let's use it to issue a certificate for a NGINX service running on an Ubuntu machine. So it's something that usually a Microsoft CA doesn't do natively. So there's another tool. We call them agents, have nothing to do with AI agents. They're basically a remote controllable ACME client on steroids.
And once it is installed on an entity, it discovers either file-based certificates or it discovers your typical application service. When you have your profile set up from the second step, all these default configurations are part of the profile. And this video was almost shot entirely in real time. I just cut out a little bit of waiting time. And of course, again, we love standards. We are part of ACME. We are donating and supporting CertBot. So of course, you don't have to use our tools because, well, we use standards and there are a lot of tools available for all of these standards.
So in essence, everything can be automated, right? It's just a question like how deep you want to go. Is it like a standard integration or is it a standard protocol? But so far, we've managed to unlock all the doors that are needed for your success in terms of automating your identities. And so far, this is what you usually want or what our clients usually want from us. But of course, we have to make this audit ready, right? It's not just solving the technical problem or your organizational challenge. It's also the auditors are always knocking on your door, right?
So let's see what we have in place to prove everything that I've just shown to you. And built for audits. It's a big title, but let's explain where this is coming from. Every company has their strong suits, right? You make products, you're a manufacturer of some goods, you know all about your goods. So what is our core business as DigiCert? So I think there are different opinions, but for me personally, our key business is we have to understand regulations and we have to adhere to them in an audit ready way.
Otherwise, we cannot offer you identities for Meta, we cannot be part of X9, we cannot be part of C2PA because these are all regulations we have to adhere to. So our core business is to understand those regulations, adhere to them. We have more than 25 audits every year. So this is more than two a month. This is not a practical routine. I don't know how often you test disaster discovery. We do this twice a month in essence. So this is how we adhere to the standards. We learn a lot from that and we give this to all of our clients. We learn how to do audit ready logs.
We have been asked to do it the same way and we give the same way also to our clients. So in short, of course, we lock everything that's happening on our system, not only the interaction and configurations. Every device that connects, every device that issues a new identity, it's transparent and completely locked. The next thing that we have is signature locks. When we talk about agentic AI, at one point we always talk about an identity, most likely something like a PKCS12 file stored somewhere else. It's a certificate. We talk about can we trust this model? Has it been manipulated?
So this is like all around software signing, SBOM signing. So these are all very well established methods to deal with those things. And in our signature locks, for instance, we lock everything around software trust. And this is not enough.
I mean, you might maybe have something already in place. You have your long locks if you're good, but then the auditor is ringing the doorbell. Can I see your locks? Text files, database extracts, people are involved.
With us, you just ask for the email of the auditor. He can or she can self-enroll and then they can connect their toolings to our toolings and pull all the locks while you have a coffee and a short break.
Of course, all of this is tamper-proof. We, of course, sign everything. And whatever is good for the auditor is also good for you to make your decisions or base your decisions upon. So everything is also available to you, of course, to extract it or to transfer it into your own Xeom environment and analytic tools, whatever you have in place. So you're not depending on our fancy UI, but maybe on the data sources that we collect on the way. And what I mean with this, just like a small, maybe I have two more minutes, I see. So maybe as a final note, a short story.
Five years ago, previous job, we've manufactured a small device, smart device. And at one point, we've been contacted by the third party manufacturer, you signed a software update poorly and wrongly. This is why the devices have been bricked. This is why we want the money back. Half a million euro are in the room. And of course, delayed development, delayed product launch. So if you ever find yourself in a situation where you have to prove that a signature to a very small, non-standard software is correct, well, good luck reverse engineering, because everybody can sign software.
And for Windows applications, your Java applications, it's easy to prove your signature. But for those like embedded devices, small SOCs, it's not so easy. I wished I had this kind of audit log, because audit logs should not only be for the auditors, but also for you as the consumers, as the generators of those audit logs to generate meaningful learnings out of it. And with this, with a log file like this, five years in place, I would say, OK, give me the file. I calculate the hash value of the file.
I prove, OK, I signed this file. This is the signature I gave you. You can verify it.
And yes, I did it. And this is the key pair that I used to. Have fun. Do not reverse engineer or try to understand how the signatures or software signatures of any product are working. You can basically just prove it this simple way. And this is what I mean. We really love audits, not only for the auditors, but also for you and placing those log files for you to have meaningful content. I will skip this.
This is, again, I think I summarized this quite well. Hopefully, this is not just audit ready. This is action ready for you to make decisions upon. And in essence, as a final note, I hope I was able to illustrate that those four pillars are easily achievable. You not only want to automate the automation, you want to automate the governance, you want to automate the building of an inventory. And of course, you want to automatically provide proof. So hopefully, this shows how easy it can be to put regulations into routine.
And if there are questions, if you want to talk about this, please visit us at Booth 3. And well, thank you for having me.