Organizations obsess over stopping cyberattacks, yet often ignore the quieter, daily failures that damage trust even more. Slow onboarding, endless login issues, and delayed offboarding don’t just frustrate users, they corrode confidence between businesses and stall collaboration. The real risk to digital trust isn’t always the headline breach, but the persistent identity friction no one talks about.
The path forward demands rethinking how we manage external identities. Seamless onboarding, adaptive authentication, and immediate access revocation are the baseline for trust. Companies that fail to modernize their third-party identity practices risk losing not just efficiency, but credibility in the digital ecosystem.
John Tolbert, Director of Research and Lead Analyst at KuppingerCole Analysts, will reveal findings from the 2025 Digital Trust Index – Third-Party Edition. He will spotlight the most fragile points in the identity lifecycle, challenge outdated practices, and share data-backed recommendations on how organizations can rebuild confidence through consistency and accountability.
Marco Venuti, B2B IAM Business Owner at Thales and Jose Caso, Product Specialist, B2B IAM at Thales will show how the OneWelcome Identity Platform turns these principles into practice. They will discuss how delegated user management, adaptive access control, and externalized authorization eliminate friction while strengthening security, and why organizations that don’t adopt these measures risk falling behind in trust-driven ecosystems.
Hi, welcome everyone. I'm John Tolbert, Director of Cybersecurity Research here at KuppingerCole. And our webinar today is entitled Revealing the Weakest Links in B2B Identity and How to Fix Them. And I'm joined today by Jose and Marco from Thales. And I apologize for my video not working. I've tried three cameras. Over to you, Jose.
Well, thank you very much, John. So let's get started. So today's agenda is we're going to be talking about the challenges of managing third-party identities. Then we're going to be talking about the main reason we are here today is to talk about the Digital Trust Index third-party edition research that conducts research to end-users. Then we're going to be talking a little bit more on what is B2B-IM? Why Thales? And finally, we will have a section for Q&A. Please don't forget to add your questions in the Q&A panel. Right. Everybody's muted and we'll take the questions at the end.
But yeah, please feel free to enter your questions in the blank in the live story control panel. All right.
Well, let's get started. So collaboration ecosystems go well beyond your business boundaries. Third parties connect to your organization through a growing number of digital channels. So if you can see the image at the right, you can see that at the center, you have all your core business systems, ERPs, cloud storage, SaaS applications, web, mobile applications, and portals. And surrounded by them, we have a lot of external users like suppliers, resellers, distributors, professional services, retailers, and even customers.
So these third parties need access to your internal systems to do their job. But each connection introduces risk. And as the number of these apps and access points grow, so does the complexity of managing and securing these relationships. It is not just about who they are. It's about what they can access and how they can access and how this access is controlled. And of course, this challenge is compounded by the challenge of scaling this third party access.
So as value chains grow, digital assets that used to be just employees now need to be shared with a whole network of suppliers, partners, and logistic providers. But every new connection is a potential security risk. That is that if it's not well managed, well, there's a lot of consequences with that. In the past, many companies have handled third party identities through one-off point-to-point integrations. That might have worked when you have a few partners, but what happens when you scale? Each new supplier and partner just adds more risk and far more complexity.
And as these multi-tiered partner relationships keep expanding, so does your security gaps and the operational overhead that comes on trying to keep under control. So with this, over to you, Marco.
Yeah, thank you very much, Jose. And thanks, everybody, for joining.
And again, I'm glad to be in this conversation today to be flanked by John Perspective as an analyst on what the market looks like. And by Jose, which is a solution specialist.
Again, in my case, I've been myself in this space for now in the third decade. Let's put it this way. Working for different identity company, but always on the product side. I've never been myself a practitioner, though, meaning an identity manager responsible for one of the organizations that the pleasure to work with. But I thought it would have been interesting to share a bit of what is the nomenclature and the types of relationships that Jose just commented about. And we put together a visual representation of what is that structure like.
So, of course, I believe that each and every of you in this conversation today belong to an organization which is indeed surrounded by other organizations more than ever before, including customers. Meaning for the purpose of this conversation today, B2B customers company with users, not just individual and tend to ask customers. And those customers can be reached depending on on the way you address the go to market side of your ecosystem directly, as currently depicted.
Or maybe through intermediaries, through some partners which are in the middle in managing the services and product you deliver to customers, maybe at sales time, maybe at support time. And this is just the go to market side of the equation.
There's, of course, another part, which is the supply chain, which is by definition also featuring multiple types of organizations that need access to digital services centrally managed by the blue central organization. So each supplier is indeed a company with users belonging to them.
Now, this taxonomy of different constituents, supplier, partners and customers has different names depending on the specific vertical each of you operates into. So, for instance, if we look at banking, the partner could be brokers or aggregator or maybe regulatory body, while still just speaking in this example, the partner column in manufacturing could be reseller or retailer. This is to say that the name might change the vertical, the go to market side or the supplier side.
But there are some commonalities which are independent from the vertical or at least largely such and are independent from whether they come from the go to market side or the supply chain side. So, for instance, if we look at the central organization, if we had a bird eye view, 10,000 feet, I summarize what are the key concerns, the key problems they're confronted with in dealing with now extended enterprise.
Well, as Jose already captured, there are multiple challenges and the number matters. Of course, there is an explosion in terms of magnitude of number of entity that the blue organizations need to deal with. We have customers with maybe, say, 4,000, 5,000 employees and 35,000 B2B users. So an order of magnitude of difference that, of course, imply complexity and challenges, including cost. And they are very different. They belong to apart from the nomenclature that I just commented upon.
They might need a different level of assurance, different level of authorization, depending on the nature of the business of the blue organization, depending on the types of digital services those green entity need to get access to. And, of course, last but not least, there is a huge visibility problem. And I trust, John, this is also matching what you commented in some webinar before that I had the pleasure to assist. If I'm right, in terms of maybe with a slightly different TALIS flavor, look and feel, but similar, I would say, isn't it?
Yeah, I mean, there's a lot of different types of relationships that we see and various levels of complexity to one that you've got marked as organization. Sometimes we call it a prime in a supply chain scenario where you may have many, many different suppliers that need access to supplier portals, where they may give updates on what they're about to ship you, customers or contractors that may have a very specific relationship. And maybe their contract defines what kinds of digital assets they get access to.
Of course, that can be different for every contractor organization that's working with the prime organization. And then I know we're going to get into it in a little bit. How do you do identity verification on these external users as well as figure out how to do access control?
You know, we've already mentioned federation, and I'm sure we'll get into it some more. That's that's a good door opener. But there are many more facets to doing fine grained access control and starting with getting the right level of identity assurance in the diversity of these kinds of relationships.
Yeah, absolutely. Indeed. And and we're still talking here of the perspective from the concerns from the blue organizations. Right. But today is also very much around looking at the other perspective. So if we if we now dig a bit deeper into what are you, what is the experience like from those ecosystems of third party organizations? What is what is the current status of the way they interact today is of today in their B2B or third party relationship context? And that's where Jose is giving us a bit more around the recent survey that Estales we conducted. So thank you very much, Marco.
Very nice explanation. So now that we have set the stage, let's look at the research itself. So this research focuses on a critical question. How is trust built or lost when organizations give third parties access to their systems? So we looked into the full lifecycle of of external users from onboarding to new partners and suppliers to updating access when responsibilities change to removing access when the relationship ends. So in these insights, you'll find you'll see today that from a global survey of thirteen hundred procurement, commercial and professionals across 10 countries.
These are people who live the reality of everyday managing suppliers, distributors, logistics, brokers, experiences that paint a clear picture on how digital trust is handled in B2B relationships and where organizations really need to improve. So with this context in mind, let's walk through the research and what it tells us about how how we can build or lose trust with third party ecosystems.
All right, let's jump into the data. So the first thing that we see is how quickly access delays can damage trust. So thirty one percent of third party users tell us that they have to wait more than one day to get started. So that's business stalling before it even begins. So if we put this in context, a lot of consumers get access to their portals and to the portals almost immediately. So delaying it for more than one day, it's it's something that that it's not understandable for a lot of business users.
And thirty four, thirty four percent says it takes two or more business days to to get updated access when the responsibilities change. Whether it's someone moving to a new project or shifting roles, these delays create frustration and risk. This to me feels like even a bit of underestimation.
I mean, in my experience is very often. I mean, I'm positively impressed. I think it's either that.
OK, at least in terms of maybe I'm biased because the customers I have the opportunity to talk to. Are probably coming our way to fix a problem, but the magnitude of that problem is higher than that. So what you're describing here feels like a very much of a joiner or joiner mover lever flexibility and agility.
And, well, I would be, I think, happy if putting myself in the shoes of many of those organizations, if this was only the relative magnitude. Yeah, you know, there are business models I've been made aware of where, let's say, a very large prime organization uses delivery people for very short term gigs like a one day delivery job. So you need to be able to, in this case, you need to be able to onboard that person in less than one day and then terminate their access as soon as the job is complete.
So, I mean, that business model will not work at all if it takes one, two or more days to even get access to the portal. So, yeah, I mean, we really need to increase the speed on provisioning, deprovisioning and full lifecycle management just to enable the kind of business that we see evolving in the world today. Absolutely. And you just mentioned the provisioning piece.
Why, when nobody is making sure that you don't forget to remove my account, I'm leaving. That's not happening. Right. So probably this assessment on how long it takes is even worse if we were to project that on the provisioning side. Believe in the old cliche, time is money. If you are onboarding, if you're a big organization and you're onboarding 100 people a month and it takes three days to get access for each one, then you're losing a year's worth of productivity, essentially. So making it faster is just essential, I think.
Yeah, totally agree. Yeah, the speed is life in many businesses. So another big barrier to trust comes with identity verification. So here we can see that 69% of the verification processes are digital. On the surface, this sounds very efficient. But the problem is the consistency. Sometimes the host organization handles this verification themselves. Sometimes it's the partners. And sometimes this is even shared. Though the lack of clarity slows down everything.
New suppliers or distributors can get stuck in the maze of different document requirements, phase delays, and even have to repeat these steps unnecessarily. So the result is that there's a lot of confusion from various stages of the relationship, which undermines the trust and makes onboarding harder than it needs to be. I understand that, especially my experience in banking, in pharma, where the relative sensitivity of the information that digital services are exposing. The central organization cannot just trust the onboarding that a partner organization provided.
Even if we federate the partner organizations to simplify the onboarding process, that would result into an interesting and very significant notion of trust. We would be trusting not just the identity, but also the degree of verification that they provided. That's not always the case, in my opinion. And that probably goes in line with what you are saying, that there is indeed an inconsistent, at times repeated, intentionally repeated, verification, which creates frictions inevitably, but is in this case for a good reason. So a good reason. A trust reason.
The central organization doesn't trust to just federate and let in people which is onboarded by third party organizations. Yeah, if you think back to the org chart that you had up earlier, you know, the prime organization, let's say they're operating in a heavily regulated industry, and yet oftentimes they'll do business with smaller businesses.
I mean, some very small SMBs, maybe two or three people. And, you know, they don't have rigorous identity verification processes, but maybe they do possess the ability to federate.
Well, the prime contractor in that relationship has a regulatory requirement for assuring a certain identity assurance level before letting them access sensitive resources. So how do you go about doing that?
I mean, we've seen in specific industries the developments of ecosystems where identity verification, identity management and federation have been outsourced entirely to large third party firms to do this sort of thing. And then, you know, to the part here about this being digital, I think, you know, we've been hearing more and more over the last few months and years about the rise of deepfakes. So let's say you've got, you know, what you think is a good remote onboarding process where a user, you know, uses their modern smartphone to scan their authoritative government issued document.
And it can do NFC reads against passports maybe and take a selfie and match that picture to the official picture in the document. All those things are good.
You know, we've been using that since even before the pandemic started. But there are, you know, a whole host of presentation time attacks, enrollment time attacks where fraudsters or, you know, other nefarious actors are trying to exploit the identity verification layer.
So, you know, having consistent processes, processes that meet the regulatory requirements of the industries within which you're working are very important. And I really just can't emphasize that enough that there's in many cases regulations that will govern what you have to do for identity verification. And some of the processes that are still in place out there that may not be leveraging some of the newer technology may not be able to get new employees or contractors in at the right identity assurance level. So that increases your risk, too.
Yep, absolutely. So, well, let's go on. So it's just not about getting access. It's about being able to use it reliable. Here's a striking number. So 96% of third party users experience login issues when trying to access their partner systems. 96%. I think this is huge. And that's essentially pretty much everyone. And these aren't just small annoyances. On average, each user wastes around 48 minutes a month just trying to get in. So what happens if we multiply this across dozens and hundreds of suppliers, contractors, and distributors? Now you're looking at a massive drain of productivity.
But more importantly, these inefficiencies erode trust. If a partner can't even log in smoothly, they start to question whether the host organization is prepared to support the collaborative relationship. I think this is a critical aspect that a lot of organizations have to take into account. I think John was commenting before right around how numbers build up quickly in becoming cost and inefficiency in onboarding and joining a mover lever. And now also, as depicted here, in getting access are indeed determining the cost. And it's also a matter, as you said, of reputation.
Now, if this was a consumer identity and access management, this would not be happening because nobody would tolerate that. They would just pick another provider. Reputation and differentiation matter. You would just walk away and pick another service provider. The reason why we're looking at this number is because in B2B, this is still allowed, so to speak. It's not necessarily triggering you to transition to another company or a competitor because of that. But that doesn't mean that it isn't relevant.
So there is a broader notion of user experience, which is not limited to consumer, but is also applicable because of the evolving digital experience that each of us expect, even in this context, even in the B2B or third party identity and access. And so this is, of course, a reason for deep frustration in each of us.
Marco, I even think this is an alarming number, considering, let's say, if you have a go-to-market partner and you're in a competitive relationship, let's say an insurance company, and they have to face and even offer different options. And if they don't have the right access to the right provider, they can certainly go to another insurance company. So I think it becomes critical in many ways. Perhaps it is not as acute for supplier scenarios, but certainly for insurance, for all those go-to-market partners where you certainly do business with, it becomes a very alarming number.
Yeah, and like you said, the time builds up quickly. I mean, this translates into a lot of lost productivity and reputation damage. And like Marco said, it's not like if you're in a long-term contractual relationship, it's not like you can go somewhere else. You don't have that flexibility like you do in a consumer experience.
But yes, this definitely has an impact on the bottom line. Big times. And now this leads us to start talking a little bit about passwords. So passwords continue to be a major source of friction in third-party access. Here we can see that 40% of users receive their passwords once or twice a month. That means nearly half of those external users are stuck in the cycle of forgotten or expired credentials. It's more than an inconvenience. It interrupts workflows, frustrates users, and wastes time for both partners and the host IT team.
When this keeps happening month after month, it signals a weak point of the relationship. So the good news is that this problem, we know there is a possibility to solve it.
You know, passwordless methods like passkeys, biometrics can remove this ongoing burden entirely. You know, what I find interesting is since I've been doing the leadership compass on consumer identity and access management for about 10 years now, I know that pretty much every CIM solution out there has more and better authentication methods present that can be used. Like the things you mentioned, you know, Fido passkeys are a great example.
You know, passwordless is where consumers want to be. I think it's also where business users want to be. And it's where IT management should want partners, contractors, customers to be, too. Because it can reduce friction. It can improve security. It's appalling the amount of time we all spend dealing with passwords, password reset, account recovery, you know, in our daily lives. And to see this in a business context, knowing that there are better ways to do it, becomes increasingly frustrating.
Not to mention, as per the title of this session, which is the weakest link, that in the weakest link domain, the weakest, weakest link is credential recovery. This is the highest peak of vulnerability that you can have. This is where attackers can sneak in more likely than not.
And so, indeed, the reliance on password and the need for credential recovery is making just for a very, well, outdated approach to a very present problem. I think it's great to go back to the title of the talk, you know, and talk about trust.
Because, yeah, what do you feel like when you go to a site and you know that you're going to be accessing sensitive information and you're presented with a password login screen? I mean, my initial gut feel is, really? You're still using this? Yeah.
Yeah, very vintage. Yeah, maybe nice.
Yeah, absolutely. So, it also, well, and when it comes about authentication, as we just mentioned, we see a mixed picture.
So, at the top, we see that 58% of users still rely on SMS one-time passwords. We all know that this type of one-time passwords are widely recognized as vulnerable to interception and phishing. And we know they're quite familiar. They're everywhere. And we use them for a lot of use cases. But certainly, whenever we're talking about supplier risk and we see these kind of breaches going day in, day out in the news, I think this is a quite concerning number. On the positive side, we can see that they are relying on more advanced methods, such as 51%. They rely on biometrics.
42% rely on tokens or smart cards. And while these are stronger approaches, it's not always the most user-friendly.
So, what it's striking about, what I find quite striking over here is that 18% use besties. We all know this is a very modern and secure method available for a lot of organizations to provide this high level of security that does not involve phishing and with the lowest friction. But it's growing. I think this is something positive. We see here that besties are taking over. I would like to see this evolve over time. But what we can find here quite alarming is that 10% report that they are still using just username and password, which leaves the organizations completely exposed.
It is frightening. I mean, I know that there are some even, not large banks, but different kinds of financial institutions that are still relying on username, password, maybe with some risk-based authentication stuff going on in the background.
But still, you know, you go to a site like that, and yeah, it's frightening to see that that's what they're relying on. SMS OTP, I mean, how many years has that been deprecated officially? And yet it's in widespread use. And not even appropriately used.
I mean, thinking, again, from the consumer experience, I'm asked to do SMS OTP for things that are, you know, it's protecting little value. So in some ways, it's just kind of, you know, peanut buttered across all sorts of consumer and customer use cases where it's not appropriate from either perspective.
But, you know, biometrics, you know, platform-based biometrics are great. You know, and that's closely related to past keys. You can use that, you know, for past key registration. And I think, you know, we are at a point where these systems are mature enough and useful enough that I would love to see a big push by businesses across every industry move toward past keys and more secure, more usable forms of authentication. It's also interesting, right?
If you add up the percentage, we get to 200%, which means, of course, that each organization is using at least, on average, a couple of those authentication means, which just makes sense. I don't know. I'm not aware of any large organization I had the pleasure to work with that just rely on a single or as a unified authentication. It changes depending on the users you're looking at, depending on the system, depending on history, merchant acquisition, number of reasons, right?
But also, we can derive that, indeed, pretty much at least half of them, if not all of them, rely on a one-time password, which is, indeed, an interesting data point. So, yeah, not surprised.
Sorry, positively surprised about the biometric authentication in 51%. Not so much, indeed, about the OTP part. Still scaringly high.
You know, for B2B IAM, physical tokens, smart card are still very viable, and I think they're going to be around for a long time, and that's fine, especially for certain kinds of use cases to highly sensitive intellectual property or, of course, national security kinds of situations. So, it's good to see that they're still used, but I would predict that there are going to be places where pass keys can replace that as well.
Yeah, for sure. Perhaps one of the most concerning findings that we found in this research is how common unauthorized access really is.
So, nearly half of the respondents, that's 47%, say they've come across information that they shouldn't have access. So, that means critical systems and sensitive data are regularly exposed to people who have no business in it. And this isn't just happening in loosely regulated environments. Even in industries such as where compliance and confidentiality are paramount, such as insurance and pharmaceuticals, this number jumps to 55%. This shows that these outdated permissions and inconsistent access reviews aren't just an operational issue. They are direct security risks.
Yeah, I find the numbers surprising and shocking, especially for industries like that. And both, you know, insurance and pharma have very complex supply chains, customer chains, where they're dealing with many different kinds of roles outside of their prime organization.
So, yeah, think about the risks that are involved if slightly more than half of the people that have accounts can get access to things that they really don't have any business getting access to. What do they do with it?
You know, that raises the risk of insider threat, always raises the possibility of those who are curious poking around, inadvertently causing damage, you know, regardless of the motive. I think it increases the risk considerably by not focusing on the access control piece afterwards.
I mean, we've been talking a lot about authentication, and rightfully so, but, you know, moving beyond the initial authentication into authorization, what should users and groups of users have access to? And I think we see that that's kind of the last mile problem still today. I think we've got lots of good options for authentication, and sometimes we hear people using the word authentication when they really mean authorization, you know, to do step-up authentication.
Well, in many cases, that's authorization, but we find that that's not implemented in about half the organizations out there that we're surveying. And that matches my perceptions as well, indeed. There is a dual problem, as you correctly said. Authorization has been often misunderstood as part of the authentication problem.
Of course, now it's a different thing. And in the context of B2B, as a granularity problem, very often the level of access you deliver to a user is a bit too coarse-grained. It's a bit too much, okay? It's oversimplified. It's not fine-grained enough for a number of reasons, and that's one side of it. The second side is the mover effect. In a B2B setup, you can have a role today, you can have a job title today, you can have a play, but tomorrow you change, and we saw before that it takes a while. I forgot it was more than two days, if you said in your previous slide, Jose.
But apart from that, you are now given new access to what your new position requires, maybe after a couple of days, but the original access you had before hasn't been revoked. And that stacks up and creates an over-implated set of access and authorizations that you carry along and probably is behind those very high percentage.
Yeah, absolutely. I think it's quite critical that they have this access. So I think one of the biggest questions in the question, addressing the big elephant in the room, is this happening due to practices, or is this happening because they simply don't have the tools to achieve this kind of outcomes? I think this is something that would lead us to try to understand what you guys are facing in your own setups, and if there's some way they can address it. Maybe what we're seeing here is the limitations of role-based access control.
I mean, just think hypothetically about pharmaceuticals. So I'm sure there's a role called researcher, but how much granularity can be attached to that role? If you're a big pharma company and you've got thousands of research projects going on, at that point, having a role of researcher doesn't really help you. You need granularity. You need attribute-based access control where you can sort of drill down and tie groups of users, and a role can be an attribute there, too, but limit them to the projects that they are working on.
Exactly, yeah. All right.
Well, let's move into the next one. This is a topic that Marco was touching upon when we were talking about onboarding and the motion of movers. So now let's talk a little bit about what happens when access is revoked on time. So our research shows that 51% of third-party users skip access for days, sometimes even a month after they no longer need it. So this creates a huge window of exposure. Former contractors, suppliers who have finished a project, or employees who have moved on within the partner organization still have the open doors into these critical systems.
Even if these individuals aren't malicious, the risk is still clear. Stale accounts are a gift to attackers. They are harder to track, often overlooked by all these kind of audits we can be able to run, and it can be exploited long after the relationship has ended. And this is clear. It's easier whenever you are doing it within the four walls of your enterprise. But when it's outside your enterprise, you have to be able to conduct it in a very different way.
Yeah, I commented on that before. This is indeed an old problem in a new setup. The old problem of the provisioning, which has a new place to be evidence, which is the B2B context. But it is indeed one of the original sins, so to speak, of identity and access management.
Yeah, this is a place where I think Federation can both help and hurt. Many, many years ago, I used to say Federation can help this problem because you can usually depend better on the home organization. Let's say you have an employee at a contractor firm that quits or is terminated for whatever reason. They're more likely to cut off access to that employee.
So, you know, if you have a Federated relationship, then when their access ends at their home organization, it should end on the collaborative sites that you as a prime are hosting. But that doesn't always happen. I think that's why we often see more language in contracts around identity lifecycle management to try to push the burden of identity lifecycle management back to those partners.
And, of course, language in contract is not security. Yep, absolutely. And finally, let's talk about breach disclosure.
So, one of these critical aspects in digital trusts. Here we can see that only 56% of respondents are fully confident that the host organization, the one that holds a lot of their information, would disclose this breach promptly. That means that almost half of the partners are left without doubt. And when partners suspect that breaches might be hidden, risk multiplies. Collaboration slows, transparency breaks down, and certainly trust erodes.
So, beyond the technical issues of onboarding and access, it highlights a deeper truth. The trust is much more about openness than it's about security controls.
Yeah, I think this is really a key thing. Think about all the organizations that we've heard of who've suffered breaches over the last five or ten years.
You know, a lot of that post perception hinges on how they respond during the breach, how much transparency do they have. And the fact that in this survey, the respondents are saying, well, we really don't trust our business partners that they would tell us in the case of a breach, I think, is a very concerning statistic.
I mean, now we have regulations in different places around the world that require disclosure within a certain period of time, and I think that's a good thing. But as we know from even recent breaches, we're not getting full information from companies or organizations that are experiencing different kinds of cyber attacks, whether it be ransomware or some other attack where it's designed to, you know, fraudulently expose lots of identities.
So, not having confidence, I think this is the foundational part of trust and digital trust. No additional comment from my side?
Yeah, I fully agree with that. Okay, perfect.
So, so far we have talked about the reality, you know, all these delays in efficiencies, gaps that undermine the trust across the B2B identity journey. So, the big question now is how we can tackle these needs and challenges. Because what it's clear from the data is that current practices aren't enough, and they leave too many cracks to the system.
So, with that, I'll hand it back to you, Marco, who will walk us through how organizations can go beyond this piecemeal approach and take a more strategic path forward. Absolutely, sure.
So, if we go to the next slide, everything we just discussed out of the survey can be probably summarized into three main reasons or spheres that determine attention level increasing the organizations we had the pleasure to work with and are behind the funding of an initiative to improve. Sorry, not the previous slide, Jose. Jose?
Yeah, thank you. And so, indeed, there is reasons tracing to being more efficient and being more timely in addressing the urgency that the business demand and the flexibility and the agility required. And this is, of course, vary depending on the vertical we're talking to.
So, there is a speed, there is a pace, there is how long it takes. And I think we largely commented on that before, right, in the terms to onboard, in the terms to manage the moving, in the terms in the time it takes to recover credential.
So, all those aspects are rolling up in the speed category. Then there is, of course, the risk side, which is also multifaceted in terms of making sure of the right level of assurance at onboarding and authentication and the authorization part.
So, this is indeed further decomposed into multiple subdomains and each of which can be benefiting from depending on the context or form of federation. If we trust that for onboarding, definitely for offboarding and for authentication, not necessarily usually for authorization, which is still retained centrally. And finally, there is a cost, the workload, which is in a way bound also to the time it takes. As we said before, the number matter, there is an order of magnitude in terms of number of users to be managed.
Anything which is manual is inevitably converting into an overwhelming workload for the central organizations that deserves to be addressed. So, the organization we're looking at, they do not necessarily equally rank of the same degree of importance, the three of them. We usually have two of them, which are any combination apply, which are driving the initiative. But those are the reasons why we have customers conversations these days. Talking of which, conversation about what? There is no such a thing as an organization that starts from zero.
There is no nothing in terms of identity infrastructure, rather the opposite. They have multiple components very often because, again, of history, merger and acquisition, division, whatever, to be harmonized, to be orchestrated. But up until a few years ago, early 2020, we were looking at companies which were indeed managing onboarding and then authentication.
Of course, authorization and the services to the users, though, piecing together components or filling the gaps with custom development to address the external constituents. While there was a market offering for internal users or for consumers, there was no such a thing for the B2B domain.
So, it was broadly unaddressed and very often addressed with combination of SIAM solution and IGA solution. But what happened more recently and where we are today is that there are indeed, such as the Thales solution, capability design, especially tailored for this domain, which are factoring some unique aspects, such as the need for organizational body, which is unique to B2B. You don't have that in other identity domain.
Delegated administration, the ability to decentralize the workload and leave those partners alone in managing within the appropriate boundaries onboarding and access delivery to their own user population. That's what delegation is about, is an emerging set of capability, which is specifically tailored for this sort of domain. But this is not the end of the story, because the future is already coming.
And what we are assisting, and this is part of what we at Thales also, the way we look at that, is that the notion of delegated administration and authorization will eventually become a single thing. And then, why that? Because John mentioned that, right? Role-based access control. Can you just do attribute-based and so automatically delivering access? If you broaden that concept up, can you just automate and deliver just-in-time access out of policy, out of rules, out of contextual information, to have just-in-time access or zero spending privileges, as you like to call it today?
This is what is not just reducing the workload, but is also serving ephemeral identities, such as the agentic AI that are now part of this conversation. And you would appreciate that we are 48 minutes in the call before bringing up AI. This is my new weekly record, by the way. I'm usually much earlier than that. But this is where it really belongs.
Yes, I'm very happy about that achievement. I thought it would have been 20-something. But indeed, that's where this is leading. It's no longer just humans. Some of those activities will be eventually performed by agents. If that's the case, they will not be waiting two days. That's not the way it works. You need to be way faster. It's a form of delegation. It's a form of acting on behalf, too, which requires a much more prompt, still secure way to interact and the fusion of those domains. Makes sense, John? Yeah. I should have mentioned delegated administration a little bit earlier.
I guess we're implying it. But as you know, I'm working on the latest update to the leadership compass on CIM. And I can confirm what you've got written right here. People are looking for light IGA and PBAC. It's just absolutely necessary for B2B relationships these days.
Yeah, indeed. Thanks for confirming, indeed. We see that emerging in terms of real demand from the field. It's not a standard that is falling from the vendors or body to the market, but rather the opposite. It's an emerging demand clearly voiced from the customer we address or the system integrator we have the pleasure to work with. Which brings me to, from the Thales side, final slides. We at Thales do provide our customers with the complete coverage of the identity lifecycle for access, for consumers, for gig workers, for B2B.
And if we expand what is sign up, log in, use and leave, that defines a tessellation of the next level of detail coming from the previous slide of what different customers are asking us to provide them with. There is no such a thing as a customer that adopts the entire palette of capability here. It's more around replacing and optimizing individual components. But still making sure that they are properly orchestrated, meaning integrated to deliver the sound experience that is now expected and very often not fulfilled.
So, indeed, we at Thales are providing our customers with the option to address the specific needs without changing the entire solution. And in a broader sense, that's the business we're in. This is our identity and access management mission.
It's about orchestrating a frictionless, trusted and secure digital journey for all identities, where all means indeed all carbon-based identity, employee, consumer, gig workers, B2B organization made of people and, of course, agents, into being delivered access in the right and timely fashion and secure and auditable manner to the digital services that a modern enterprise needs to provide to external constituents. So, this is a concise way to represent and depict the way Thales addresses those needs.
Well, thank you very much, Marco. I think it's a very nice explanation.
So, if you're interested in getting the report in your hand that we just discussed at large during this conversation, certainly there's a URL and a QR code if you want to download it. So, I guess I don't need to give you a complete explanation of what we talk about, but everything that has to do about this is a global study of professionals who rely on B2B services.
So, we're exploring the challenges and risk of managing this third-party access. So, I think this concludes the part in which we talk.
Now, we of course thank you, John and Marco, for sharing those insights. Now, we'll move on into the Q&A portion of today's session.
So, if you haven't done it, you can still send in your questions using the Q&A panel in the screen. Oh, we have a couple of questions over here.
So, I have this question. So, why do so many organizations still rely on SMS, a one-time password, despite the known vulnerabilities? Is it critical to phase it out in all scenarios?
John, yeah. Yeah, I mean, it is known to be insecure.
So, yes, of course, I think we should all recommend getting rid of it if you can. I think that's going to be very hard because it is so widespread in use. But definitely, I think there are much more user-friendly and secure ways of going about it.
You know, use authentication apps, mobile push notifications, and of course, our good old pass keys. Definitely much better for the end-user experience and increases your security.
Well, thank you very much, John. So, we have another question over here.
It is, federation is great with big partners. But how do they extend it into smaller ones that do not support it? How do you avoid federation becoming a barrier for smaller suppliers or brokers?
Well, maybe I can comment on that. You don't strictly need federation, right, to loop in and to work with external company. Depending on the size, you might indeed range from company which has not even an IT staff, or so small that are just a group of people with no infrastructure. And if that's the case, you're not expecting them to be federated. You're rather managing them in a traditional onboarding of users that you manage centrally in the blue organization, back to my original slides, and with your level of assurance attached to validation and to authentication.
So, federation is an option. It's not the only option. Federation plays very well in large organizations with mature organization and still have the inherent trust concerns that we discussed about before. You have a notion of trust applied to the quality, allow me, of the onboarding and authentication that those federated entity imply or deliver. I think for some small organizations, there's a bit of implicit federation that's used too.
You know, a big prime contractor, if they're working with a two- or three-person company, they're eventually going to wind up trusting one of the very large IDPs out there that these smaller companies are using. So, there's going to be some coarse-grained federation involved there, which makes it then much more difficult on the part of the prime to be able to do that fine-grained access control.
Now, thank you very much. So, we have another question over here.
It's, for third-party IM, do you know how many organizations do trust the LCM done by their external partners? How many do actually do that?
You know, I don't think we covered that specifically in this year's survey, but, you know, maybe that's one we should put up for the next edition because I think that's a very interesting question. And I was kind of alluding to that earlier about not necessarily being able to trust the identity verification done by partners.
You know, maybe the partner is doing what they think is sufficient for their business, and it's really not sufficient to meet, you know, certain regulatory requirements. And we know that there are a few industries where, you know, organizations have come along and sort of taken this on as a collaborative project in and of themselves to provide identity verification and account management for an entire industry, including primes that are competitors with one another's. But I don't think that model is widely used across all industries.
So, I think the question here is something that maybe we should try to dig into next time. What do you think?
Yeah, I think it feels like it's indeed a subject that we, that deserves, as you said, a double click and a more detailed conversation because you open up scenario implication approaches to address that definition of what can be trusted and what cannot. But what sits where? What is the hybrid approach of having what managed where? Onboarding and authentication on the one side, authorization on the other. Where do I need to properly maybe replicate and maybe re-authenticate, or sorry, re-onboard, okay, if I don't trust the original party.
So, that is indeed the food for thought for a follow-up conversation that would deserve a webinar per se, probably. I mean, this is one that kind of bridges the gap between identity verification and authorization because there are certain high security use cases where you want to know what identity assurance level before you grant access to a specific resource. Absolutely. Contextual authorization relies on that.
Yes, indeed. So, I have a couple of questions over here that we will be answering offline.
So, great discussion. Thank you very much for all the questions and the insights.
So, this leads me to pass the word to John. Okay.
Yeah, thanks everybody for attending. Thanks for the questions. Thanks to TALIS for joining us on the webinar today and doing the research. I think it's very insightful. I look forward to working with you on the next edition.
And also, yeah, when the slides come out, feel free to go look at that QR code and get a copy of the actual report. I think it's very informative, and there's more information in that report than we had time to cover today.
So, thanks again, everyone. Have a good rest of your day. Thanks for joining.
See All Locations
See All Locations