Identity Maturity and Disconnected Apps: 2026 Ponemon Research
Hello, and welcome to today's dark reading webinar, identity maturity under pressure, twenty twenty six findings and how to catch up sponsored by Cerby and broadcast by Informa TechTarget. I'm Terry Sweeney with dark reading. I'll be your moderator for today's discussion. By way of context, in this session, we'll be looking at, data recently collected from more than six hundred IT and security leaders that assesses, the scale and impact of disconnected applications. Our speakers will help us understand why mature identity programs are still driving audit friction and stalled initiatives. They'll discuss the risks of manual password and credential management, and they'll also talk about how AI agents are expanding identity risk and practical steps organizations can use to regain control. On that note, I'm excited to introduce our speakers. I'm joined today by Matt Chiodi, chief strategy officer with Cerby. He's joined by Mike Fitzpatrick, founder and CEO of NCX Group. Gentlemen, welcome, and thanks for being here. Awesome. Thanks, Terry. For having us. Fun. Matt, before I hand it over to you, I just wanna remind our audience of a couple of things. If you've been here before, you know this webinar is designed to be interactive between you and the speakers. At the bottom of the screen, there's some buttons that'll allow you to download a copy of the slides, share this webinar on social media, and learn more about today's speakers. This is also where you'll participate in the q and a session that takes place at the end of the presentation. You can use that q and a area to let us know if you're experiencing any technical issues, and our team will do their best to assist you. I think that's it from me. Let's get to it. Matt, the floor is yours. Wonderful. Well, thank you so much, Terry. Mike, it's good to see you again. Good to see you, Matt. It's been a little while, but it's good to be back and hanging out with you. I love it. I love it. So let's just let's jump right into it. So seventy seven percent of organizations experienced at least one cybersecurity incident in the past two years caused specifically by their inability to secure apps not connected to their identity stack. I'll say it again. Seventy seven percent of organizations experienced at least one cyber security incident in the past two years caused specifically by their inability to secure apps not connected to their identity stack. So this is what Mike and I are gonna talk about over the next thirty, forty minutes. And again, as Terry said, if you have questions as we go through, please drop them into the chat. We will try to answer those in real time as we go through it. So please ask those questions. So Matt Coyote, I am the CSO at Cerby, former chief security officer at Palo Alto Networks. I've been doing this cybersecurity thing for over twenty years. Mike, who's joining me, been a Ponemon distinguished fellow for over eighteen years, and he helped design some of this research. Mike, tell us about yourself. Well, Matt, I'm CEO, founder of NCX Group. We're a cyber risk advisory firm, and we've been doing this now for about twenty five years. Thousands of assessments later, it's still amazing to me some of the things we walk into every time we go out on a project. So, this research from an identity management standpoint is fantastic. It's a lot of really informative and granular information with a problem area that we see literally in every project we do. This this research, it really quantifies, I think, something that practitioners have known for years, but maybe didn't have the didn't have the numbers for. Why don't we don't we jump into it? Tell us a little about it. Well, so so the the research project is is one of the things I love about what we do with at Poneman and at the institute is the research projects are always very thorough. Six fourteen IT and security leaders. It's an independent research project, but the important thing is it's cross industry, so it's not one specific industry. I mean, this particular one was retail, financial services, manufacturing, tech, health, energy. Eighty percent of it supervisory and above. So in this, we measured five things. We measured identity coverage, security incidents, compliance, operational burden, and that all too famous AI wildcard these days. I love that. I love it. So this is pretty this is very wide ranging. And for those of you who are watching this live right now, this research is very fresh. This just came out literally, I think in the last month. So very good. And again, this is the first study to put hard numbers on disconnected apps specifically. So if you wanna get a full copy of the report, Mike and I, we're just gonna touch on probably only twenty percent of what's in the actual report. We'll try to touch on the things that I think we found to be most interesting. But if you scan this code, you can take the link and and and download that. I'll show this again later in the in the presentation. So let's jump into just, you know, some of the some of the numbers. Alright? So I wanted to start with this one, Mike, because I I think this will set the tone for the rest of the conversation. And here, the question behind this was we asked respondents to rate their confidence in their identity program's ability to provide consistent security controls across all their apps, connected and disconnected. And as you can see here, six out of ten was the average confidence score that their identity controls covered all apps. That's that's not a lot of confidence. This means, like, their their Okta, their Entra, their SailPoint. Right? They have these tools, but they only cover what they can see. So there's a lot that's invisible. So best way and there's there's a reason for this visual. Right? Like, there's the blue circle. These are your connected or your federated apps. That's where your I'm and all your controls live. Those little dots that you see all around it, those those are the gaps we're talking about. Well, and I I gotta say the the the confidence factor, it seems to me to be more hopeful than anything else. The other thing that that strikes me, Matt, and it's a little fun here, is, you know, remember the movie Meet the Falkers circle of trust? Right. Right. It it kinda it kinda the visual strikes me as you've got those inside the circle of trust and those outside the circle of trust. The the the six out of ten, I I see that more as a hopeful strategy rather than what we typically see when we go in and we're doing a project, and when you see what the reality actually is, it's a very different world once you get into really digging into it from an assessment standpoint to determine what's working, what's not working, what's inside the circle of trust and what's outside the circle of trust. I think you're right. You know, the a lot of times when, you know, in my previous roles as as a CISO, the the score, if we would have been talking to, you know, an advisory committee, a leadership team, a lot of times, you know, if you would have asked me in the past around this, I I probably would have given our program a similar rating. I'd have been, yeah, it's like, you know, there's some gaps and whatnot. But I think that, you know, there would have been there would have been gaps around these disconnected apps. Right? Because I think for many organizations, and we'll talk we're actually in a minute here, we'll talk about we'll put a fine definition on what we mean by disconnected app. But a lot of times these these apps, the management, the governance, the auditability, it's kind of built into business as usual. Right? People are just kind of used to doing the manual management for a lot of these. It doesn't show up as like a big a big headline item. So this is a lot of times, it's just a built in assumption, and it's a part that I think most CISOs don't even bake in when they think about their kind of their overall I'm security posture. Well, I think you're right about that. I think the other part of it that comes into play, too, is, you know, the walls that exist between IT and security from that standpoint, and how you actually, you know, how you go about dividing and conquering. Who should really have ownership of this across the board, I think is also a question from an organizational standpoint. I love that. I love that. Again, if you have questions as we kind of go through this, please please feel free to ask those and we will do our best to answer those in in real time as we go through. So let's let's keep going here. So let's let's let's look at the reality. Right? So this was more of a the first question was more of like, what do you think? Here, we asked them to really quantify what their application portfolio looks like. So here's what it looks like. And again, these are averages. And I think these are these are right. I have hundreds of these conversations with CSOs, I'm leaders. And what they said was that on average, they've got it right around three hundred applications that are in their portfolio. Right? So this is SaaS, this is on prem, this is third party apps, things like that. Right? They're saying they have about three hundred. I think this is this might actually skew a little bit low. I know from speaking with, you know, some large financial services companies, like, they have got thousands of apps that are that are in their portfolio. But let's just say for the purpose of this, right, like three hundred, it's it's about right. And if we if we build this out a little bit more and we ask specifically, okay, now tell me about these apps in here. Well, we know that they said that about eighty eight of these apps, they are not centrally managed with any type of MFA. Meaning, they can't they can't set a policy at the IDP layer and enforce MFA on these apps. So it's eighty eight. Seventy of these apps have no single sign on. That means it's manual credentials. It's they're using a password manager, something like that. And this last batch, this this sixty, this is what I call that that the absolute perimeter of rest. This is pure manual administration. Now, those sixty apps with the manual administration, that creates like massive exposure at the end of the day. That's always at the top of the list for us. And we see a lot of it, quite frankly, with with roles and permissions within cloud environments is really where it is run amok. You have a lot of maybe former consultants that have been brought in that were given access and privilege that are no longer part of it, or team members that were no longer part of it. So, applications, these orphan type of accounts that are out there become a real problem, but those sixty applications that are not covered, that definitely becomes a problem area. Now, Mike, I know that, you know, in the work you've done over the last twenty twenty plus years, you've you've done a lot with with M and A. Like, happens in a transaction when a when an acquirer finds out that there's nearly, you know, almost a hundred of these apps that are sitting outside of identity governance. What's that look like? Well, what what that ends up becoming once once they figure it out, and that that's also the the dynamic that's also interesting too. But once they find out, it definitely becomes a delay in the acquisition, in transaction, which, you know, all sides hate. The M and A guys, the PE guys, they all hate. Everything is built about speed. And we're also getting to the point, too, where in the past, companies and parties in these transactions have been utilizing insurance to insure the problem away. Those days are coming to an end quickly, too. The insurance companies have had their time being the responsible party in the room, and they're just not going to waste the cash anymore. So they're demanding that the businesses step up and take a more proactive approach, and if you don't, they're not going to insure you. So we're finally hitting something that I've preached about for about eighteen, nineteen years now. This should be part of every policy renewal going on, is a cyber risk assessment within the organization. Appreciate that. Well, let's let's put a fine definition on we've been kinda talking about a connected, disconnected, federated, nonfederated. Let's put a definition on what do we mean by a disconnected app. Now one of the one of the challenges in our industry is we have a lot of different terms for the same thing. And for this category of problem that we're talking about, a business app that's not integrated into an organization's identity stack due to a lack of support for standards. Like, if you ask Gartner, like, they call this a nonstandard app. If you talk to an identity provider like Okta, they call these non federated apps. But the industry is pretty close with using the term disconnected app. So what I want to be really clear about when we talk about this, because this is really where all the research is centered around in this report, is we're not talking about Shadow IT. Some people think, oh, this is all Shadow IT. No. Like, the research shows that certainly Shadow IT could be a part of this, but is not the majority of it. We're talking here again about business apps that are not integrated with your org's IDP because they don't support the standards. Not the IDP, but the app itself. These are legitimate tools. These are HR systems, finance platforms, marketing SaaS tools. It could be something as seemingly as benign as your organization's enterprise social media credentials. Right? Those are all fall into the category of a disconnected app. So just just so we're all clear kind of on the definition of what we're talking about, this is what we mean by a disconnected app. Alright. Let's let's look at this, Mike, from from two different perspectives. I think this will really drive home the point. Right? So let's familiarize the audience with this. Left hand side of the screen, this is really the area that your identity and access management platform was built for. And this is typically when you do your slides and your stats, this is what you're talking about. This is the SAML, the OIDC, the centralized credentials, the the automated scheme, the one click audit. The the right side, of course, this is this is the disconnected reality. This is the the fifty five percent of the research we found that say that fifty five percent of their of their of their apps, disconnected apps, use password only authentication. Forty seven percent said that, guess what? IT doesn't manage the credentials. It's end user man managed. And by the way, thirty nine percent thirty nine percent of those are shared credentials. Now the truth is is, and I'm sure Mike, you've seen this in some of the due diligence work that you've done and many of the audit work you've done, right? I have not found a single org that I have worked with over the last four plus years that doesn't live simultaneously in both of these columns. Right? It's the almost of the governance and the due diligence is done on the connected side, and that disconnected side on the right, this is where the manual work that's that that, you know, as Mike used the analogy, right, outside that circle of trust, that's where that happens. No, I agree with you. Both the organizations that we work with definitely live in both columns. I think the really troubling part is that leadership only usually sees one of them. And that's the big you know, especially with several of the measures and ways that assessments and this we seem to be developing a focus solely on technology elements as far as the risk is concerned. And you and I have been around and have done this long enough that we know that it's people, process, and technology. A lot of what used to be caught, companies are not including in the scopes from an assessment perspective, and I think a lot of things are going to end up falling through the crack. These disconnected apps, as we're talking about, are going to be at the top of that list, so they need to have a way to really gain control of those. There's a couple of companies that we have worked with in the past that come to mind that are nothing but disconnected apps. And, you know, so from that standpoint, giving them a way to actually gain control over something that would live outside the normal controls and normal apps for identity management is a big thing. So I think Cerby is in a fantastic place to be able to solve this particular problem. Let's let's look at this from, you know, one of the things I appreciated about the research is that it really didn't just kinda talk about the problem, but it it really dug into how organizations are attempting to address it today. So, you know, let's talk about the scenario of a termination signal. Right? So someone leaves the organization, maybe you're an FTE, maybe it's a contractor. I'd love to hear from the audience in the chat here, like, is this, you know, let's do an informal poll, just drop it into the q and a. Right? But, you know, how many of you fall into this scenario that we're pointing in here. Right? So if someone leaves the organization, maybe it's a, you know, unregrettable termination, we'll call it that. It's a nice way we call that. The HR termination signal comes in. What happens next? Again, in the case of disconnected apps, we know that from the data that fifty one percent said that it goes to a manual ticket, right, to a ServiceNow, some type of service desk. So termination signal comes in, whether that's an automated feed from an HR system, or whether HR literally opens up a ServiceNow ticket, the point is that a human is involved. Okay? That's what's happening fifty one percent of the time with these disconnected apps. The next part of it is organizations have attempted to do some automation around this. The challenge is that they're usually trying to do it in a way with scripting, maybe they're trying to use RPA, something like a UiPath, Blue Prism, but it's very fragile. So forty eight percent have attempted to do this in some automated fashion, but it's very it's very brittle. The the last group here completely is relying on humans. Alright? And so this is what we call that. This is that swivel chair work where, you know, HR sends in the signal, however they're doing that, maybe they manually go in, maybe they send an email, an extremely manual scenario, or maybe they're a little better, they open a ServiceNow ticket. And then whenever that IT admin gets around doing it, one day, five days, never, thirty days, they have to manually log in. So two screens, right, I've got the ticket on this screen, and the other screen I've got to log in to that app. Maybe as IT, I don't even have access, so maybe I have to reach out to the business app owner, wait for them, and it's this very manual process where at the end we're like, hey, maybe maybe it was revoked, maybe it wasn't, maybe we're still paying a SaaS license cost because we weren't able to reclaim it, and I stamp all this as an IT tax, right? I mean, thirty one hours per week on average maintaining and fixing these workarounds. Every single week. I call it an IT tax because this is I just got off a call right before this where oftentimes this tax, it never actually hits a budget line. And oftentimes that's why this kind of continues to exist in many organizations. Well, it's definitely one of those things that never makes a report from a cost, dollars and cents standpoint, or a budget standpoint. Did an article probably six months ago on are you spending the right amount of money to cover a possible breach within your organization? Frankly, most, Matt, just are nowhere near the spend that they need to spend to actually survive a breach and the cost related to that breach. So they're not even meeting that threshold. So being able to identify what that cost is and put a number to it is definitely an important aspect of things. And I think, in general, putting a dollars and cents cost to everything within a cybersecurity assessment is critical today. Yeah. And I I think you make a good point there. And again, this is an average here, thirty one hours a week. Right? If you are a, you know, a large scale multinational, you know, ten thousand plus employees, This number is dramatically greater than thirty one hours a week. Right? I spoke to a Fortune fifty healthcare provider a couple months ago, and they told me that they have a team of twenty five people that are doing this manual work every day, all day. So their number is much larger than that thirty one. So Mike, my question for you is, like, when you're advising a CEO, CFO, like how do you make the cost of this visible so it actually gets resourced? Well, in our reports, and what we provide back to the board, we're actually, as I mentioned previously, we're actually now starting to identify costs that go to that IT tax that you're talking about. We're including some of that data and trying to put dollars and cents to it because of what I mentioned before. They're not spending where they should be spending. That's been a consistent problem. Matt, how far does that problem go back? That problem with consistent spending and what they should be spending, I think it goes back to the creation of the term cybersecurity. It does. It's a constant battle, and a lot of it comes from cybersecurity not having its own budget, but being a line item within IT. So, I think it becomes really problematic. I think as the executive teams are starting to learn more and understand more and take a more proactive approach, a more business risk centered approach, rather than treating it like all IT, I think that you're going to see that change. I think that being able to apply cost to those hours, the thirty one hours times fifty employees that might be doing it, it's a crazy number. The other part that comes to mind, too, is like on third party risk. There's one of our clients, and he's got a team of twenty five people just doing third party risk, you start looking at the hours that are manual within third party risk in the data, and it's a recent Poneman report, you know, you've got forty to one hundred and sixty hours per assessment that side. And again, that's another cost like this that isn't accounted for in those assessments, in the reports, in the findings that go to the boards. Vikram asked a good question around, like, how do you measure identity maturity? Vikram, that's a great question. I we have a slide that we are going to cover this a little bit later, so just stay tuned. We will directly address that question. Let's one of the questions I often get is, okay, like, I understand I kinda get the concept. I know about these disconnected apps. I have them in my environment. What would that look like in a breach scenario? So this is a high level of attraction of the MITRE ATT CK framework, but specifically applied with the disconnected apps. So let's walk through it. Right? So step one, I call this the weak gate. This is where an attacker gets into a disconnected app because it's got no MFA. The research shows forty one percent of the time, these apps do not have MFA. And guess what? The other thirty seven percent of time, they have easily guest credentials. Right? So they're very susceptible to credential stuffing attacks, things like that. Right? So that's the first one. So you get in, you find your initial point of entry. Then what do do? Well, step two is you expand. Right? You see what else can I do? So in this case here, an attacker could pivot via either shared or unsecured credentials thirty three percent of the time. And then what do they try to do with that? They try to gain excessive privileges. Right? Because the data shows that fifty four percent of the time, these disconnected apps, the the authentication and the roles and entitlements, fifty four percent of the time, it is showing that they have excess privileges. And then the last step, right, is now what I'm going do is I'm going to establish persistence. Right? How do I do that? I create some ghost accounts and the data shows. Thirty six percent of the time, we know there are orphaned accounts on these disconnected apps, and there are also upwards of forty nine percent of the time users who never got off boarded. So key point here, right, is every step is directly enabled by the disconnected app gap. There's no zero days that are required in this scenario that we're talking about here. No zero days, right? This is kind of a low tech way If we look at most breaches, they're not via zero days. They're usually via identity, via factors just like this. No. It's and I I would say the figure there with forty eight percent is is right in line with what we're seeing in our own data within the assessments that we do. The other point that comes to mind with all this is, again, going back to the insurance side of it, is no insurance carrier is really going to look favorably at this kind of approach. I mean, this is going to be really problematic for them. We're now seeing Matt, I did a presentation a month or so ago, and it was basically a canary in the coal mine, a trend that I'm seeing, and it's a term called subrogation. You familiar with subrogation? Refresh my memory. So, subrogation is kind of like a tag team wrestling match. So, in this particular case, the insurance company took care of one of their clients who was and experienced data breach through a ransomware event. They paid the five hundred thousand dollars in claim, but then they tapped in, and they became the offended party. And then they went to go recoup their five hundred thousand dollars one of the participants that they went to recoup from was the MSP that didn't enforce the MFA program within the organization. The other was, I believe it was Trustwave, if I'm not mistaken, the outsourced security SOC that was providing the service. They didn't respond to the attack. A situation of, you know, an oversubscribed provider that never responded. But the insurance companies, this is the twelfth case in two years, so where subrogation is starting to be used. So that ability to actually have the insurance company tag in and recoup their losses, it seems to be a strategy that is working. They haven't lost it on any of the cases. Wow. So no no cyber insurer is gonna cover the, hey, we knew manual off boarding was unreliable, but we kept doing it. Sounds like that's no longer going to be a valid excuse. Yeah, no, the days of trying to insure your way out of this, they're coming to a fast end. Well, you haven't taken the opportunity to download the report yet, just a quick reminder, you can download that here and get a full copy of the report. Well, let's let's keep going, right? So we often say in security that compliance is not security, and that's true. But as we know we were just talking about it, it's still something that we have to do. And so there are some interesting data that came out in this research. We found that forty six percent said that they needed a major manual effort to produce audit evidence, and it's still and it's still incomplete. So forty six percent of the time, it's a major manual effort and it's still incomplete. And perhaps most scary is that sixteen percent say they cannot produce audit evidence at all for disconnected apps. And and I think, you know, this this is obviously shocking, but the reason it is is, like, we've built our compliance programs around the apps that are connected. Right? We've got our sale points for our SOX compliance, our Saviance, right, for doing our SOX on on these disconnected app on these connected apps. But when they're disconnected, it's all manual labor. All manual work. Literally, somebody logging in, doing verifiable work. Right? And the other part of this is that sixty three percent admitted to already failing an audit because of disconnected apps, and thirty six percent said that they've failed it more than once. More than once, thirty six percent. I would have thought the number would have been higher, but you know, so from my perspective, it's the world I live in all the time. So, you know, it really comes down to the structural problem that is in the audit cycle and how they prepare for audits, how they track the data, keep the data, and how they do their day in, day out basis. And it's really It's a great point that you're asking. When the conversation has to shift from we failed a control to we have a structural gap, and the structural gaps are really starting to appear. They're becoming really clear, especially as we shift more from cybersecurity, in my opinion, has become about tech and tools. When you get into the business risk side of the equation with cyber risk, now we're starting to have a different structural conversation within the organization. And I think here is where that cost comes to bear, is in that data, and they got to start asking how they get better. Well, no presentation would be complete without at least some discussion on AI. And it used to be because, you know, people just wanted to hype it, but we're at the point now where it's, as you'll see here in the data, you know, we are we are well beyond the the first, maybe even second inning now with this. So what we found in the data, right, like, again, look look at that chart, right, so there's still absolute growth that's happening on the on the traditional SaaS app side. It's funny to call it a traditional SaaS app at this point. I mean, it feels like it was just a new thing in the last few years. Right? So there still is growth. But what we've seen with with AI powered apps and specifically agents is there is that exponential growth. And what we found is that, yes, fifty five percent of orgs said they reported a significant to extreme increase in AI apps that are bypassing IT completely. And the reason being is, like, pretty much every SaaS app has now built some AI enabled functionality into whether they like it or not. It is typically opt in by default. Right? And the other thing we found is that over fifty percent said they have over between fifty one and a hundred different AI apps that don't can't be managed with their with their IDP. Right? So it's got no SAML, can't do single sign on, they can't do SCIM, which means they can't do automatic provisioning, tracking roles, entitlements, things like that. None of these are in your identity governance program. So AI is making the disconnected surface grow faster than really any AI, any traditional manual approach can handle. Well, I mean, Matt, you're bringing up, and the research brings up a great point, you know, and it's a phrase I used last night, and I think it fits. We're now past approaching, or if not there, security at light speed at this point with changes that have to be made. And your point about governance is fantastic because what we're seeing in the research is that the policies are nowhere near where they need to be. The structural, and we see it with the work that we do, the GRC component within most organizations is not where it needs to be before they actually start to think about AI within the organization, and what intellectual property might leak out of the organization as they build these systems. And then you get into the shadow AI component of it, and with the points that you made as far as the disconnected apps, it starts to get very problematic very quickly. And I'm not sure how we put the genie back in the bottle. It's not possible. It's But it is something that, you know, and it was a Poneman report that we did probably about four months ago breaking down the policy question of it, And it was twenty six-twenty seven percent of the hundred companies surveyed had an AI policy in place. My question was, did the AI write the policy, or did somebody put some thought to it? Of course, yeah, wrote it. Yeah, of course. Then you've got the other two sections. So the middle section, you had about thirty percent that were thinking about an AI policy. And then you had the final group that had no intention to ever allow AI in the building. Again, I don't think there's any way around it because almost every SaaS application that you see today, it's in there and there, as you mentioned, there's no way to opt out. We've talked a lot about kind of the problem, right? So there's I think really three power questions that I would give the audience to use and to think about how they can what they can do here about this. So the first is is to ask yourself a question. Right? Can your identity stack see the app? Right? Again, this is not a limitation of your identity stack for using any of the, you know, any of the big, the pings, the the sale points, the the octaves, the entrees. They support all standards. It's the app. So can your identity stack see the app? First question. Second question is, can the access be managed centrally? Or is your team having to manage access to these apps in a hundred different places instead of one back in your centralized identity stack? And the last question is, can the actions be audited? This is a big one. Right? You saw the stats behind sixteen percent said they had zero ability to do it, and I think it was thirty some percent said that, yeah, we can do it with a massive manual effort, but and and there's still a piece that's incomplete. So these are three critical questions so that you don't automate the blind spot. Think about those. These are three critical questions. Now, I want to show you from an architecture perspective what this looks like. Because I know for me, like having a picture is always ten times better than than hearing about it. So what the way we like to look at this at Cerby is is you're not you shouldn't be ripping and replacing your existing stack. Right? You've some organizations, you've made six, seven, maybe eight figure investments in your identity stack. What you want to do is you want to extend your identity stack to these disconnected applications. So for your connected stack, right, this is what it looks like today. You've got on the left hand side, you've got your single sign on, your Entre, your Okta, you got your joiner mover, lever, your governance, your sell points, your Saviants. That's that existing stack on the left. You've got your agents, which should be interacting directly with that stack. It's not always the case. And you've got your connected apps. Everything works great. The challenge is the disconnected apps that we've been talking about for the last twenty or so minutes. Right? And again, the use cases of these on prem, in the cloud, legacy, third party SaaS apps. This is where Cerby comes in and extends your existing investments to these disconnected apps. So again, you can continue to manage all of your apps connected, disconnected, all in one place back in your existing identity stack, and Cerby extends those capabilities to those disconnected apps, essentially obfuscating all of the the messiness and the heterogeneity of those disconnected apps and presenting back to your identity stack standards and just things that can be managed centrally. Let's look at a case study. I think this could be interesting, Mike, and I I love your love your kind of your your feedback on this. Right? So one of Cerby's one of our customers is monday dot com. So monday dot com known as the Work OS, this is a company that's been around for about fifteen years. One question I get sometimes is like, hey, if if a company is only been around for for, you know, ten, fifteen years, do they have a big disconnected app problem? And the answer is is yes. Right? Monday dot com, this is a cloud native company. They had upwards of two hundred of these disconnected apps that they could not protect. They use Okta, that they could not protect. They were spending, and kudos to them, they were able to quantify about twenty two thousand hours of manual life cycle management per year. That's roughly about one point seven million in security task costs. One point seven million. They were able, Cerby and working alongside with Okta, to enabled almost a hundred percent reliability, a hundred percent automation, provisioning, deprovisioning access across their full app stack. They saved over a half million dollars a year, and they had about almost a four x ROI in the first nine months alone. First nine months alone. That's a heck of a payback at the end of the day. Absolute justification for it from standpoint of this is what it looks like when an organization and leadership makes a decision to do something different and do it in a way that is going to help the organization from a cost savings standpoint and a productivity standpoint. I would imagine that all that manual stuff that they were trying to do, you know, that has decreased and allowed them to redeploy personnel somewhere else. It did. And one of the questions I often get is like, so they had this problem, like what like, what made them decide to act on this versus just continuing to manage it manually? Like, they they yes. I mean, you know, could an organization with as much revenue as they've could they have continued to do it manually? Absolutely. Right? You know, they're not they're not revenue constrained when it comes to that. They wanted not only to recapture the economics, but the risk, the cyber risk that's associated with not rapidly off boarding, especially around compliance frameworks like SOX that require it. They wanted to automate it. And so that's why they they did that, right? And this is what the ROI typically looks like when you automate what can be such a manual process for these disconnected apps. Matt, how long ago did they do it? This is in the last eighteen months. Would be definitely an interesting case study in how it works over the long haul, but that decision point to actually take this step, I'd like to say it's normal, but it's unusual. Yeah, yeah. And so kudos to them in doing that. But yeah, it would be interesting to see what the benefit is long term over the next few years to them, but the cost savings is dramatic. It is. It is. Well, I'll tell you what now. Vikram, you asked a great question around how do you measure identity maturity. I told you we would get to this. So here here's the answer to your question. We have a a a model that we came up with where there's basically four levels. Right? So level one is what I call ad hoc. Right? And and this is very useful to say, hey, where is my organization today? Right? So level one is ad hoc. This is you've got no inventory, you've got shared credentials, you have no risk register, and we know from the data, right, fifty three percent said they're password only and seventy seven percent have had some type of security incident. So ad hoc. Right? This is the lowest level of maturity. The next level is what I call emerging. It's you have some visibility, you've got uneven controls. In this case here, right, maybe what we found is that from the research fifty two percent said they've started that discovery process of figuring out what are all my disconnected apps, where do they live, and the other forty one percent said, hey, we manage those credentials manually. The the third level is what I call unmanaged. Okay? Or managed rather. These are managed, right? So your high risk apps are identified, you're doing your joiner mover levers, it's partly automated, and, you know, your IGA integration, it's in process. And then last but not least, at the highest tier of maturity is what I would call unified. Full coverage, continuous evidence, but our data shows that only thirty four percent of organizations are here today. So use this as a map, Vikram specifically, to figure out where your organization where your organization is. So great question there. No, where we typically see clients is either one or two places. Somewhere in between ad hoc and emerging, and the other is between emerging and managed. And those are really the areas where we see them. I talk about it all the time. I've never seen a clean assessment in twenty five years of doing this. I've never seen a clean one. There's always something. There's always more work that has to be done. There's always things that have been missed. But, you know, after thousands of assessments, you would think I would find a clean one. We just have not. Well, let's let's give the audience a thirty, sixty, ninety day plan, so they can really put this into action very quickly after after watching this webinar. So first thirty days and mind you, some these timelines, they might shift a little bit. Right? If you're if you're a five hundred employee organization, maybe you can do it faster than this. If you're, you know, three hundred thousand, it's going take you a little bit longer. First thirty days, you want to find your disconnected apps. You wanna document them, rank them by risk, pick your top ten, and then ask add them to your risk register. That's step one. Right? It's getting that situational awareness. Step two, days thirty one through sixty, this is where you start to measure and quantify, like, how much time is it taking us to do this manually? You know, you'd ask the question, Mike, around like monday dot com, like, what made them do it? They did a really phenomenal job at quantifying, like, the tickets, the volume, how much are people getting paid, and they were able to say, hey, it's this massive number. That's the step two, right? It's really digging in and measuring what is this costing the business from hard economics, but then also what's it costing us from delivering audits, and what is it costing us? This is harder to quantify, but what is it costing us from a cyber risk perspective? So this is where you find your off boarding failure points. And then the third one is, you know, days sixty through ninety. This is where you pilot three to five, maybe of your top priority disconnected apps that you find. You apply that standardized control workflow that you defined, and hopefully it's where you start your Cerby pilot. Right? It's where you go in and you apply Cerby using your existing identity stack, and try these things out, and then you scale from there. Don't try to boil the ocean. Start with the top three to five, and then run it against those in those environments. Matt, that inventory step, to me, is the most important step. You can't manage what you haven't found. If don't have an account on it and you don't know where it is, then you're going to struggle. Every organization that we've worked with has gotten started exactly that way, by doing an account, finding out what's out there, and really clearly identifying what is within the control plane and what is outside the control plane. All right. So, we did have a couple questions come in. If you have questions, feel free to drop those in now. I want to answer those. So, the first question, this is I'm going go back to the I'm going go back to the other slide because this is the one they were asking about. This question here was, for an organization that's level one or two right now, what's the trap people fall into when they try to when they try to fix it? What what should they actually do first? I think, you know, I'll just echo what Mike just said. Right? Probably the biggest part of this here is just understanding what is this what is this and organizations call these different things. They call it an application rationalization. Right? You just gotta know what is in your inventories. That's the biggest step. Once you can kind of quantify this, and there's ways that you can do this, and we don't have time to talk about it today. But once you've done that, that will then help you move on to what we talked about then in in this one here, right, where you get to the second step, you're defining the operating model. You can really start to dig in and understand what's it costing the business. So start with the application inventory, and that's going to involve then speaking with some of those application owners to understand that app. That's what I that's what I would say to that. The the other question that came in was about the architecture slide that I showed right here, and I'll build this out real quick. Someone said, I'm still not clear on how Cerby actually connects to an app that doesn't support SAML and SCIM. What's happening under the hood? So there's a lot that's happening under the hood. So in the Cerby platform, we've got a number of patents that are pending. So we do use machine learning and AI, but we only use it for the development of the connectors. Right? So as Mike and I have talked about, right, so AI, if you ask AI a question, three times you get three different answers. So you do not want to use AI to run your AI IAM workflows. And so Cerby, we run our IAM workflows in a deterministic way. So they they'll run the same way every time. But we use things like machine learning, computer vision in order to build and maintain the connectors. So that's how we're doing some of these things, right? And we look at what does the app present, does it present any APIs, are there none at all? We can do all kinds of things like UI automation, whatever it takes, we obfuscate away all of that complexity that exists in your disconnected applications, and we manage it for the life of the subscription. So it's not just building a connector one time and you're on your own. Cerby is building and maintaining in real time and extending your existing identity stack to those disconnected applications. Alright. One other question. Again, you have another question, we're almost out of time. But there's one other question. It says this is a good question. Aren't most SaaS vendors moving towards SAML and Skin at this point? Isn't the gap you mentioned in the beginning just going to close on its own? Ah, yes. The melting iceberg problem. This is a common misconception. Right? We looked at we did research on this about a year or two ago where we looked at all the apps in the Microsoft app catalog, and I don't remember the exact number anymore, but it's like twenty thousand. Right? If you look at the number of apps, net new SaaS apps that are being created, most of them do support SAML at this point, but it's typically an extreme upcharge, whereas four to five x, it's called the the SSO tax, if you want it. And then if you look at the other side of it, which is the provisioning and deprovisioning the governance that's done via the SCIM standard, still only ten to fifteen percent of apps support the SCIM standard. So no, this problem is not going away, and again, we are seeing this with all of the with many of the AI apps and the AI agents that are being created. They're being created not with SAML or SCIM support. So good questions. Good questions. Alright. I think that puts us near the end, Terry. So I don't know if there's anything else that you wanted to add. I I I think that's gonna close us out. Appreciate the audience questions. Matt and Mike, great job. Really great deep dive on identity management here and how AI is, really altering the landscape externally and internally. Thank you both for your time and your comments today. Wonderful. Thanks, Mike. Thanks, Derek. Thank you very much, Terry. Thanks, Matt. Sponsor Cerby as well as everyone in the audience. We appreciate your attention and participation. Sometime in the next twenty four hours, you'll be receiving a personalized follow-up email with details and a link to today's presentation on demand. You're welcome to share this with colleagues and peers who couldn't have been part of today's live event. This webinar is copyright twenty twenty six by Informa Tech Target. Presentation materials are owned by copyrighted by Dark Reading and Cerby, individual speakers solely responsible for their content and opinions. On behalf of our guests, Cerby and the Dark Reading team, Terry Sweeney here. Thanks again for your time. Thanks for joining us for this session. We'll see you next next time.
Identity is under pressure. Identity programs have matured, yet hundreds of applications remain disconnected from centralized identity systems, operating outside governance and driving measurable security and compliance risk. New 2026 Ponemon Institute research, commissioned by Cerby, puts hard numbers on that gap.
What did the 2026 Ponemon research find about disconnected apps?
77% of organizations had at least one cybersecurity incident in the past two years caused specifically by their inability to secure apps that aren't connected to their identity stack. The study surveyed 614 IT and security leaders across retail, financial services, manufacturing, technology, healthcare, and energy, and is the first to put hard numbers on the disconnected-app problem.
How bad is credential risk on disconnected apps?
The research shows credentials for disconnected apps are largely unmanaged:
- 55% of disconnected apps rely on password-only authentication
- 47% of the time, IT doesn't manage the credentials, the end user does
- 39% of those credentials are shared
How do disconnected apps affect audits?
- 63% of organizations have already failed an audit because of disconnected apps, and 36% have failed more than once
- 46% needed a major manual effort to produce audit evidence and it was still incomplete
- 16% said they cannot produce audit evidence at all
Why do mature identity programs still have this gap?
Because identity automation reaches only the apps that support SSO and SCIM. Even well-run programs leave hundreds of apps outside centralized governance, which is where the audit friction, manual work, and credential risk concentrate.
How is AI expanding the risk?
AI is enlarging the disconnected surface area. As copilots and autonomous agents access the same disconnected applications, they amplify the credential risks organizations already struggle to control, which makes closing the gap more urgent.
What can leaders do to catch up?
The practical path is to extend existing identity controls to the disconnected apps they can't reach today, automating access and credential management for apps without SSO, SCIM, or APIs. Cerby completes the identity stack rather than replacing it, so the policies you already run apply to every app.
What you'll learn in this session
- Exclusive 2026 benchmark data from 614 IT and security leaders
- The true scale and impact of disconnected applications
- Why mature identity programs still face audit friction and stalled initiatives
- The risks of manual password and credential management
- How AI agents are expanding identity risk
- Practical steps leading organizations are taking to regain control
Presenters
Mike Fitzpatrick, Distinguished Fellow, Ponemon Institute
Matt Chiodi, Chief Strategy Officer, Cerby
Presenters
Mike Fitzpatrick
Distinguished Fellow
Ponemon Institute
Matt Chiodi
Chief Strategy Officer
Cerby