Identity and Access Management (IAM) is positioned as one of the most critical yet underestimated responsibilities in a CISO’s portfolio because it sits at the intersection of data protection, productivity, and compliance. Traditional IAM capability models are increasingly strained by complicated permission landscapes across devices and applications, alongside relentless privacy and regulatory demands. Many IAM programs fail to meet management expectations, largely because requirements are gathered and implemented in a reactive, demand-driven way—often initiated by governance, risk, or compliance—triggering isolated projects whenever a request becomes large enough.
This pattern commonly produces a vertical, technology-centered IAM organization built around silos (pillars) such as access management or identity governance, each spanning strategy, development, and operations. Such structures obscure end-to-end visibility, complicate coordination of dependencies and roadmaps, and trap knowledge inside individual teams. Limited cross-team communication encourages duplicated solutions, missed reuse opportunities, and uneven requirement coverage.
IAM’s historical growth has also pushed IT into managing core business functionality rather than focusing on infrastructure operations. The situation is worsened by “planning the unplannable”: incident-driven security work that frequently diverts resources and derails objectives without clear prioritization and processes.
Usability emerges as a decisive success factor. IAM is often perceived as inefficient and confusing, especially when users must navigate inconsistent portals and opaque processes; password resets remain a persistent pain point even in otherwise mature environments.
A capability-based, horizontal service architecture is recommended: define capabilities, map them to building blocks, identify gaps and duplications, and orchestrate reusable services into an “Identity Fabric.” Success depends on enterprise-level ownership, future-proof architecture, comprehensive user coverage (employees, customers, partners, technical users), and a strong service organization focused on user-centric processes and self-service.
See All Locations
See All Locations