The Identity Automation Crisis: What 500+ Leaders Exposed
Alright. Well, let's let's jump right in. So let's start with what I would call a stark reality, and you'll see this as we go through the data. Only four percent of organizations have fully automated their core identity workflows. So if you do simple math, that means that ninety six percent of us are operating with a fragmented manual in probably dangerously inefficient system. And this isn't a future problem. Right? This is an identity automation crisis that's happening right now. Based on what we've learned over from over five hundred secondurity and IT leaders, the way that we manage identity is fundamentally broken for a huge number of applications our businesses rely on nearly every single day. In today's session, we are going to expose a massive automation gap. You'll learn from the latest research exactly why this is happening, and more importantly, how to identify and close these critical gaps in your own I'm program. But before we do that, I just wanna introduce myself, Matt Chiodi, chief strategy officer at Cerby. I've been in cybersecurity as a practitioner for over twenty years. Before I joined Cerby, I was chief security officer at Palo Alto Networks. And my claim to fame is that way back when the Cloud Security Alliance launched their cloud certificate of security knowledge, I was one of the first one hundred in the world. So that means if you go on the Cloud Security Alliance's website somewhere and you dig through their old pages, you might just find me on that list. Also joining me is Aaron Turner. Aaron, tell us about yourself. Hey, Matt. It's good to join you today. So, Aaron Turner, I'm a little bit older than Matt. I guess when it comes to CCSKs, my equivalent would be I think I had one of the first MCSE plus security ratings that Microsoft released back in the late nineties. But back in that day, I was part of the Microsoft team that was tasked with building a system that would displace Novell from the ecosystem. And so I spent some time working on active directory and all of the technology offshoots, the security things like trusted platform module and did some work on Windows Update. And so spent eight years at Microsoft doing interesting things. Then later, I've been an INS faculty now for twenty years trying to help people make good decisions. I love that. And, Aaron, I gotta ask you, what is behind is that a real background, or is that is that actually a Volkswagen of some sort behind you? So I'm joining you from my maker space. This is a a workshop that I've built where I restore oval air cooled Volkswagens. So this is the nineteen sixty six Volkswagen Combi is what they call it. Some people would call it a van, but I've hopped this one up with the little bit overpowered engine. It's got a convertible roof on it now. So kinda some cool stuff that I've done to make it sort of a custom mod Volkswagen from the sixties. You you are a Renaissance man. Every time I and I've known you for many years. And every time that we meet, I learned something new. So that's pretty cool. We're gonna we're gonna have to talk a little bit more about that. I I didn't have a bug. I had a bug. I didn't have a I didn't have a bus back in the day. So, all right. Well, let's, let's jump into the topic, right? Let's just start with a site that is familiar to everyone. The consumer, what I call the consumer first login screen. So think about apps like ADP, which probably seventy percent of organizations use, Zylo or even X's new AI, Grok. These applications were built for ease of use, not for enterprise identity integration. They often lack options for single sign on. And when your marketing, HR, or finance teams need to use these types of business critical apps, they're often forced to create these accounts outside of your official identity provider. And this is just talking about SaaS apps. We know this this challenge exists in with on prem apps, legacy apps, and I would call this just the very beginning of the identity automation gap. Aaron, I know that you've seen the application landscape evolve from on prem to cloud, now to AI. Does this slide reflect the reality that you see day to day? Well, in another past life, I was the CEO of a startup that was focused on selling stuff to enterprises. And and if you think about someone who's trying to get up an enterprise product to market, you know that the moment you try to do enterprise identity, you're gonna get sucked up into all sorts of stuff. And so when you're even for SaaS applications that are being marketed to the enterprise, they're gonna go this route. You know, log in with Google, log in with Facebook, log in with, you know, whatever, you know, social, application login you can because they know that's gonna be less friction to attract users to their platform. And in today's age where your valuation is dependent upon how quickly you can acquire users, That's why we're seeing this. Right? It's it's essentially most startups perceive enterprise identity as friction to getting the deal done, not a facilitator. The other thing I've seen is is I've worked with now probably a hundred fifty plus customers and also ION's clients, I'm also on faculty at ION's like you are, is that they've got the new SaaS apps they're dealing with. A lot of times the assumption is that these new SaaS apps support all the standards. I think we need to be clear, right? We're we're not talking about true enterprise grade platforms like a Microsoft three sixty five or Salesforce. They support SCIM. They support those single sign on standards. We're talking about industry specific applications. We're talking about applications that are maybe newer to market, but it's a massive, massive category of these applications. And we we did some research. We kinda hinted at this when we started, but we looked at the top ten thousand applications that are used in the enterprise. And we know ten thousand sounds like a lot, but we know there are tens of thousands of apps that are just in the ecosystem that are out there for the enterprise. We just looked at that kind of that top third, and these are some of the some of the takeaways here. Right? When we when we look at support for what would be required to do enterprise grade single sign on, fifty four percent of applications, they don't support SAML or OIDC. And if you have that app, that means that, well, you've gotta u you gotta do username and passwords. But probably the the the statistic on here that I find probably the most staggering is around the ninety three percent of apps that don't support SCIM. To me, that's huge. Right? The SCIM standard, SCIM two point o, was released in twenty fifteen. That means it's a decade old. It's not like it just was created and people are just learning about it. Aaron, for like the security and IT leaders that are in the audience that are listening, maybe explain in practical terms what the absence of SCIM means for them on a daily basis, especially when an employee joins, changes roles, or or leaves the company? Yeah. So, you know, when you've got a centrally managed identity platform like Active Directory or Okta or InterID or whatever, you control what goes on and off of that. But let's say that you do have another identity subsystem that's running some line of business application and it doesn't support SCIM, what that means is you're gonna be fully near fully manual for enabling that identity. Right? What are you going to do to basically make sure they're in the right role, that they don't have any sort of conflict of interest, or you've got appropriate separation of duties? When there's a lever or if they transfer, you've got to manually make the change inside of that role. You've got to manually make that change to make sure that they've been disabled appropriately. And so the absence of SCIM and I will say again, having been the CEO of a startup, why would you want to support SCIM? Because you don't want people to automatically disable accounts who can reduce your license count. And so there's sort of a conflict of interest here where these new age enterprise focused apps don't necessarily wanna reduce their revenue through SCIM. So they make it so you have to manually, you know, cancel someone to avoid paying the license for them. Yeah. If you think about it, it is it's it's kind of again, if I'm a start up or, you know, maybe I've I've had my product in the market for a number of years, there's actually it's actually a pretty wise business decision to not support SCIM. And I think that's why this number is so high. Like, when I first saw this, I was like, no way. Come on. But there's a lot of what I would call enterprise class apps that are out there that maybe have partial SCIM support. Like, I've noticed a lot have just for onboarding, but not like you said, but not the deep provisioning. Not not deep So that's a that's a that's a huge piece to it. So let's look at let's talk about what the lack of protocol support, creates. Right? And I think that there's really three three major problems the way I can see it. Right? There's a we talked about the massive automation gap. Right? Only four percent of organizations have managed to fully automate their core identity workflows. Simple math means that that means ninety six percent of us are stuck in manual mode. And disconnected disconnected apps, they just widen that risk. Every app that isn't connected to your identity provider is essentially an island, creating visibility gaps, security blind spots. And then when you, as you mentioned, these apps, what it means is that there's manual execution, it becomes your default. When you can't automate, you're forced to rely on manual processes, which is slow, expensive, and oftentimes dangerously error prone. So when when you hear a number like this, right, that, you know, ninety six percent of companies are still running on manual identity processes, does that does that surprise you, or is that just one of those dirty little secrets that enterprise security that people just don't really talk about? If we look at the last two decades, you know, everything that's within the walls of your enterprise and you have control over, great. But that's not how businesses run. I remember when we first started talking about the importance of using password generators and and that sort of thing to help people solve for online identities inside of their browser, and we started to see the first enterprise Internet password browser. Right? That you could plug in and go out, and they would discover, oh, I'm I'm entering a username and password. I'm going to capture that and log it. So this is probably twelve, maybe even fifteen years ago when those first started coming out. Remember speaking with a a very large bank, one of the super, you know, super duper banks in the United States, you'd consider them your sovereign. They found a massive password sharing problem because that big bank had to work with a lot of little banks. And those little banks did not have the ability to have enterprise grade usernames and passwords and identity. And so what ended up happening was there was one identity created for each community bank they had to work with. And let's say there's a team of sixteen people that's coordinating wire transfers and commodities trades and all the stuff that needed to happen between those those banks. Well, that one username and password had to be shared with sixteen analysts at the bank. And so, you know and that's just the way it was because the little bank didn't have the the maturity to create all the passwords that were needed for all those people. And so so I think there is something deeply rooted in the real world way that identities are used that are is always gonna make this a reality. Like, I don't think we'll ever get to a point where it's ninety nine percent. There's always going to be a set of identities that are gonna be outside of your control because of the lack of sophistication of the counterparty. That your business partner doesn't have the identity maturity to do this, and so you're gonna be stuck doing this. And whether that's a SaaS app, a small community bank, it used to be that federal government did this for you. Like, back back in the battle days of federal procurement, you would have to share a username and password for all of your federal procurement stuff. And so talk about, you know, going against the NIST standard. Right? The the government wasn't even walking its own walk. So I think there's always going to be a set of those business focused processes that are going to have an anchor in the past of non modern identity. Yeah. I think you're right. We I've seen that with so many different, clients that I've worked with over the years where I seem it seems to be like, if I'm talking with a younger company, let's say a company that's been around a decade or less, they they tend to think like this really isn't gonna be a big problem for us. You know, we're we're kind of this tech forward company. And then as we dig in to their apps that they're using, it's like you said, they every company, whether you're a, you know, a five person AI based startup or whether you're, you know, fifty thousand people, you have third parties that you're dependent upon. Like, you're not truly an island. And that is really what I think makes this problem so persistent. And and we've got a slide that talks about, you know, really just quantifies what manual execution really means. Right? We know it's a world of hidden risk, but when fifty nine percent of organizations are still manually provisioning and deprovisioning user accounts, that means, like you said, every time someone joins, moves, or leaves, it's a manual ticket and really a prayer that every account is updated correctly. So I know from speaking with, you know, being in organizations where I've run the security program, you know, we've had the large IGA platforms. Right, the SailPoints, the Saviants. And for those apps that don't support standards, what happens is is like if I need access to an app, I come to where the request portal, I fill it out, I select it from the catalog, It'll go through an approval process, whatever workflows it'll go to my manager, know, should I have access, whatever the approval workflows are. Once it gets to the final approval for a disconnected app, it just drops into a ticketing system, BMC, ServiceNow, whatever it is. And then you're at the mercy of the application owner. It could be a day, it could be weeks, sometimes it's months. And just think about the reverse of that on the deprovisioning side. It's often the same way. So I'm curious, Aaron, from your perspective with, you know, almost sixty percent of organizations admitting that they've got a fragmented approach, what is it like, what does it feel like for a CISO trying to prove compliance or manage risk effectively? Like, what are some of those what are some of the biggest blind spots created when identity execution is spread across different teams, manual processes? Yeah. So first, let's look at the business driver that makes this a problem. So if you take a look at the modern business reality, there's a huge amount of m and a that takes place every year. Right? Company a acquires company b or or company a divest company b or whatever. So you're you're you're constantly seeing this mashup of of companies. And every time one of those mashup events occurs, you've got a different identity system. And so in the modern age where a CISO is in a relatively successful company, the likelihood that they're going through m and a activity is super high. And in that process, that means they've got very divergent identity platforms they're dealing with. And so there's always gonna be a jump between the mothership and the newly acquired company or whatever. And so there's the business reality, is is the rhythm of business is driving identity diversity. Now when it comes to where a CISO sees this is when when they go, let's say that they're a regulated entity, you know, the publicly traded or they're a critical infrastructure provider. In those cases, the the CISO has to attest to the identities that are being passed through their system. And in that process, they've gotta go through and say, well, when was how do I run a user attestation report? Well, I'm gonna merge all this stuff into an Excel spreadsheet and try to make it work so I can get this report done. And then they're doing that every quarter. And then they have three people managing spreadsheets that are doing it. And then you have the auditor comes and says, well, actually, this spreadsheet was wrong because you didn't do it right. And so this is like a a tar baby. Right? You touch it, and you talk about it the wrong way, and all of a sudden, your entire security program is now wrapped up into identity attestation where you don't have the staff and you don't have the tools. And so so I think the business reality is forcing these diverse identity platforms, and the technical reality is because of the lack of consistency in tooling, people have thrown people, Excel spreadsheets, you know, sometimes even trying to create their own data lakes to try to, you know, make sense of this. And so that that's the tail end you gotta clean up is you've got to explain how you're accounting for this. And oftentimes, it's not a great look because you're not. You're not appropriately handling this diversity of identity. Yeah. I think you make a good point there. Like, businesses by their very nature are constantly moving, constantly changing systems. And as part of that, especially if a company has really any type of scale, like, there's almost always some type of of m and a. Like, especially when I talk of course, you know, you talk about the financial services sector, like it's kind of funny, you know, you do your, you know, one or two calls with them and usually ask like, hey, what does your identity infrastructure look like? And you usually get a laugh because they're like, we have it all. And you're like, well, what do you mean you have it all? I've got Okta from this acquisition. I've got PingFederate from this one. I've got Active Directory, like original Active Directory. I've got Entre ID, like, and they literally go through every single tool. And it's no wonder why these statistics, especially in some of those more regulated industries, are don't really shock me. You know, the forty one percent that still handle credential sharing and password rotation manually, everybody still has service accounts. Right? Everybody has service accounts, and, you know, they've gotta be handled manually. There's no way to, you know, automatically do that for many of these organizations, and they don't even know where these accounts are. And oftentimes, they don't wanna rotate those passwords because they're not sure what might break if they do. Exactly. So it sounds like there's, you know, from your experience, there's a ton of blind spots that are created when when identity execution is spread across different teams and manual processes. Oh, and and let's take a look at what just happened with the n NPM incidents. Right? With that code injection problem, what was the target of that last round? It was going out and looking for hard coded identities that were laying in code. Right? Hard coded API keys, hard coded, you know, SSH keys, these sorts of things. And so so I think the the attackers have realized because of the brittleness of some of those critical identities, meaning that we're we're hard coding them into apps, we're hard coding them into in the DevOps pipelines, that's where they're going. And and and that's the SalesLoft and the Salesforce situation too. Bad guys crack the SalesLoft API keys, use those API keys to get into Salesforce, use that Salesforce access to get inside of Google Workspace, Microsoft three sixty five. And so so, you know, the the brittleness of our identity capabilities and the identity ecosystem, it's causing the attackers to notice and they are going after these things now. Yeah. Attackers are they've always been opportunistic in terms of, you know, hey. You would do the same thing if you were on the other side. You're gonna look for the easiest, softest target. And what we've been kind of talking about this whole time is what we call disconnected applications. Right? They're called these apps are called different things. Gartner calls them nonstandard applications. A lot of the more regulated industries, special financial services, them disconnected. If we're talking just about the authentication side, you might hear the term non federated applications. But really these are these are applications that are business critical, that your identity infrastructure, again, like your SAML, your IAM, your IGA tools that they can't govern. Right? They lack support for SSO, SAML, SCIM, and oftentimes have no usable security APIs, which is why I think on one of the previous slides, I forget the exact percentage, but I think it was like some somewhere in the sixty percent range of apps don't have MFA enabled. And it's because it's a manual process. There's no API to call. And so when we look at the world of disconnected apps, we see they generally fall into two buckets. What I call fully disconnected apps, that might mean that they they've got no single sign on support, no SCIM support, they're truly an island and there's really no way to get in there. And then you've got partially connected. Maybe they support single sign on. We see this a lot with EMR, right, in healthcare space where they support single sign on, but there's no support for SCIM, or it requires expensive licensing, or some kind of crazy development to unlock that integration. And so you kind of have this this bifurcated world of apps. You've got those that are connected, and then you've got the disconnected world that really falls into, these different categories. To double down on the importance of those, you take a look at the criticality of those applications relative to your brand. Right? So like, if someone gains access to Twitter, what can they do? Right? If someone gains access to Facebook or Instagram, what can they do relative to your brand? One of the most interesting cases I had with IONs was a major financial services player was trying to reduce the likelihood of someone breaking into their App Store publishing channel. So their Apple ID that they were using to publish to the App Store was not federated back to the ownership. So they had no accountability of who was actually publishing stuff at the App Store. And so we had to think through how do you bring consistency to those core places, right, which are super brand critical. I love that you bring that up because I know that, before I got really deep into this space, I wouldn't have thought that much about those enterprise social media channels. Right? But but, you know, in the aftermath of COVID, that's the primary place that consumers go to learn about a brand or other businesses do. And I know for, you know, if you are in any type of specifically consumer facing industry, if you're part of the consumer products type of industries, your marketing teams, PR teams, they are sometimes spending tens of millions or hundreds of millions in advertising through those social channels. And those are tools that are completely not federated. Right? So when someone leaves your company, they retain access. Maybe you've got third parties that are doing your your paid social media. These are just these are applications that you don't traditionally think of, but they have a massive impact on your brand. This happened to think it was the SEC, was it two year and a half ago, where remember it was Gensler's post that came out saying that we approved the spot Bitcoin ETF, and they're like, actually, we didn't. The account got taken over. And then a month later, they act then they actually did actually approve it. So who knows if that was just a what that real purpose of that was. And then it happened to I think it was CrowdStrike, sometimes similar in the last year where their account also was taken over. So these are you're right. These are you know, it's not just the on prem legacy apps. It's not just the the SaaS tools. It's also enterprise use of social media that really falls into this space. Well, let let's let's dig in a little bit more to the the real cost of of manual execution, and then we're gonna get into a case study, which I I think is absolutely fascinating. So fifty eight percent of teams told us that former employees have retained access to systems after leaving the organization. Like, let that sink in. Fifty eight percent. So a majority of companies, this means the off boarding process is failing, leaving doors open, lingering access, compliance challenges, perhaps operational disruption. Like, this is a crazy statistic. I know, Aaron, like, I I wanna hear your take on this because you've worked at you've worked securing national critical infrastructure at Idaho National Lab. Like, do you even begin to calculate the potential damage from just one privileged user, Snowden, there's an example, retaining access after they've left, especially especially if they're a disgruntled employee? Like, how do you, like, how do you even begin to calculate the potential damage there? Well, if you look at critical infrastructure, the most likely way that someone retains access is when when you are a process control engineer and need to have access to certain grid components to make sure things are working at two AM, exceptions get made. Like, look, we know you need to have access to this, and so an exception gets made. Maybe it's a a hard coded VPN key that's installed on a system somewhere. Some some trust relationship is built between your home network and a critical infrastructure network. And so it's done out of the desire for reliability and to make sure you can maintain the grid at two AM or whatever you need to do when you're at home. But in so doing, you've created this exception that oftentimes is not managed. Right? That that trust key, that that VPN exception, that firewall exception isn't properly managed. And so it's a combination of they still have their creds. You've created a network exception to allow it through, and now you've got a situation where someone leaves the the electrical utility, but they still technically have access to whatever they need to do to get into that system because of those exceptions that have been made. So there's an infrastructure based exception process. Now, if we look at things like, you know, more run of the mill knowledge worker stuff, I've worked for some pretty sophisticated companies over the last decade. And in a case where I was an employee, I left, you know, it was a separation where, you know, we basically agreed that I'd be leaving as part of a package and that sort of thing, but I still needed to maintain access to my health benefits and my payroll stubs to make sure that I could pay taxes and that sort of thing. And this organization did not have a way to do that without keeping me enabled in those systems with my old username and password from the enterprise days. And so Oh my goodness. Sometimes we're forced into those corners where, you know, it was their regulatory requirement to make sure that Aaron had access to his health insurance coverage and payroll stubs and that sort of thing. So as a result, I had to maintain that identity even though I'm no longer an employee. But what I discovered in my I guess I wasn't being malicious about this. I was just saying, well, I wonder what other systems I could have. Oh, wait a second. I still have access to an Office three sixty five subscription where I can use Word online and that sort of thing. And so I was actually adding to their licensing burden because they didn't properly remove me from that stuff. And so sometimes you think through this, like out of the regulatory requirement that they must have access to health benefits, they create these secondary follow ons and say, well, did we remove Aaron from Office three sixty five licensing? Maybe not. Yeah. Yeah. I mean, think, you know, when I zoom out and I think about these challenges that we've been talking through, you know, identity is something that is intensely personal, right? And we are going to have multiple identities as we move throughout our lives, different corporate identities, But, you know, specific to like the cost of manual execution is as much as possible, it's important to try to automate all these apps that are in your environment. And it's usually really difficult to do that again, because we talked about the lack of standards. Well, one interesting use case, mentioned this here. So monday dot com, this is a customer of Cerby. And just to kind of walk you through it, right? This is, you know, it's, for me, you can talk about statistics, but it's not until you really kinda get into what does this look like for a real company that it really often connects for me. So let's make it real with this case study. So monday dot com, this is a company that I think we've all we all know. They've experienced incredible hyper growth growing from a startup just over a, just over a decade ago in twenty fourteen to now a multi product public company with over three thousand three hundred employees. They hit over a billion in revenue and they just have had a massive number of growth over the years. They're close to, I think over a quarter million customers who are now using their platform, but like any high growth company, they have a really high employee turnover rate. I think it's somewhere around forty percent. And so, you know, you know, depending on where you're listening, maybe you're in a company that's got five hundred employees, so this sounds really big, or maybe you're working for a multinational and you're like, we've got, you know, four hundred thousand people. Just when you look at some of these numbers in their case study, just multiply it by the size of your company, just to get a sense of what the impact could be. And the thing I love about Monday is that they did an amazing job quantifying at the beginning of the project. And as you see, as we go through this at the end, and this is something that a lot of cyber teams, they don't do well. They don't do really good at quantification. So when they looked at their manual identity costs, twenty two thousand hours annually on manually identity lifecycle management. So that's equivalent, basically of more than ten full time employees just clicking buttons. That's massive, right? And again, three thousand three hundred employees, that's massive. And so if you're at a company that's got a hundred thousand, just multiply that out. And then if we look at the, you know, another two thousand four hundred hours per spent on just manual evidence collection for compromise, all told, all their operational costs of this manual workflows was just under two million dollars per year. That's a very tangible price of the identity automation gap. And I know Aaron, you've worked at some really massive companies. Do do these numbers surprise you? Do they sound accurate? Are they small? This is very much in line. And the thing in that time when you showed the start, this is a company this is a modern company. This they started in twenty fourteen. Right? This is not some super legacy conglomerate. You know, I've worked with companies in one case, one company that was founded in the eighteen thirties. Right? So they've been around literally for two centuries. Right? They have twenty five thousand employees. You know, the amount of stuff they have is significant. Right? So I would say if if this is happening to a relatively recently founded modern focused organization, what's gonna happen when you're working for a multi decade, potentially multi century conglomerate? Right, the problem is just gonna be worse. Yeah. And I think from Monday's perspective, like you said, this is only, this is like an eleven year old company essentially. They had hundreds of these disconnected applications that were causing these challenges. And again, this isn't their internal systems, They don't have any on prem legacy. This is them relying on an ecosystem of vendors that maybe it's a state tax app in one location, maybe it's this vendor, that vendor, they just accumulate really for for any business. So I always tell people, you know, if they're especially if they if they're in a quote unquote high-tech startup, they're like, yeah, we really we really don't think we have this challenge. I usually send them down a couple different paths to look and then they come back and they're like, oh, I didn't, I didn't either, they didn't, it wasn't, maybe they weren't, they weren't on the identity team, they weren't aware of it, but every company, every company absolutely has this challenge. You know, from, from Monday's perspective, they broke down the before and after. So Monday, obviously a Cerby customer, For them, their challenges really kind of fell into two different categories. There was their identity lifecycle management, so primarily onboarding and offboarding. We mentioned they had a fairly high employee turnover rate. That's pretty common, especially as you're in high growth mode. But it was taking days to weeks for employees to be fully onboarded. So just picture this, you know, you hire this this great employee, you're excited to get them started, and they can't get access to the apps they need to do their work. And so you've got lost productivity. On the flip side, then you have when people leave, people are retaining access, and you're not really sure do they still have access. What do they still have access to? So this is you know, we've been talking about this, but this is a this is a really common problem at big companies, small companies, and and really the larger the company, the longer you've been in existence, the the really the bigger and more complex this this this problem grows. And from those two bullet points, the unintended consequence of not being able to immediately onboard people drives password sharing. So let's say that you're a junior person that's just come onboard. You're expected to do some task. You're leaning over to your neighbor. Hey. How do you get that done? Oh, you have to do it in the system. I don't have access to that system, but I have to do this thing. Okay. Well, here's my username and password. You know, you go and do it too. Right? And so so the unintended consequence of not being able to do the onboarding and offboarding effectively is password sharing because people are trying to get their job done. They're like, don't wanna fired. I just started here. I wanna get this job done. When it comes to a user experience situation, imagine it you know, what what what I find cool about you guys' platform is you actually have a story to say, look. We could take an uncontrolled, unmanaged app and bind it to a passwordless experience. Like, users love passwordless. Right? You could actually make it so someone could log in for Windows Hello for Business using their finger on their laptop. They bind Entry ID to Servi. They have an uncontrolled app. You're managing that last mile identity. You've now provided single sign on passwordless capability into that ecosystem, which makes users happy. Right? It it says, well, I don't have one more thing I have to remember here. So so you're reducing the unintended consequence of password sharing and increasing the user's likelihood of enjoying what they're doing. That's a win win there. Yeah. You you really nailed it there. You know, it's only been in the last, I'd say, two years that I've heard anybody in cyber really even start talking about how cyber can help the user experience. And this has been really pushed by, I know, a lot of CIOs when they're dealing with their their CISO counterpart. Like, How like, all these different passwords, it makes it horrible. Users, they don't wanna manage passwords, but this is what Monday was dealing with. Right? They had passwords stored in all different solutions. And when they're stored in different solutions, that means they're not following policy. It means they're persisting beyond policy. Users don't wanna have to manage them. And with the Cerby platform, we, of course, automate all that for them. Monday is an Okta customer. Now there are users. They don't have to manage those passwords. They can just access all those applications in their Okta portal, and passwords are automatically rotated. And like you said, the users get a passwordless experience. So better UI better UX for the end user, better compliance, full automation. It's a it's a great great way to great way to look at that. Now, I mentioned at the beginning that, you know, my experience in cybersecurity, many different cyber teams really struggle with quantifying the return on investment of their tools. Monday was able to quantify that they saved over four thousand two hundred hours on what was previously manual life cycle management. So putting that in perspective, again, that's the equivalent of getting back to full time employees. Just imagine like with your security team or your IT team, like what else could you be working with if you had two extra people dedicated to high value projects, maybe AI or, you know, whatever else you want them focused on instead of repetitive tasks like onboarding and offboarding. They recouped over a half million dollars of costs, which would have been just manual costs. So this is essentially newly found budget for them. It's money that can be invested in other tools. Maybe it's hiring more engineers. It could be perhaps, you know, I have a colleague who, did this process themselves and they actually gave back budget to other parts of the organization because their predecessor had come in and bought all these tools and they were overspending. They were actually give a significant amount back to other parts of the organ And just to put a a final point on this is around the return on investment. This means that for every dollar that Monday invested in Cerby, they received almost four back in recoup gains and productivity. So this is an example of something that's not that's not only just a security fix, but it's a powerful financial decision. Aaron, you and I have talked about this before, but as an advisor to CISOs, like how important is it for security leaders to be able to talk about their initiatives in these financial terms? Recruit costs, ROI, especially when they're trying to get budget or getting buy in from other areas of the business. Yeah. So when a CISO is sitting around the table with the chief financial officer and the head of product and, you know, the head of customer success and all these different folks, what ends up happening is is that all of those other business leaders have very easily measured return on investment. Hey. We invested six hundred thousand in this initiative, and we netted six million dollars over three years. Here's how we did that. Now part of it is the role of cybersecurity is oftentimes to stop the bad, and you can't really show that in ROI. You can't say, well, you know, we intercepted fourteen thousand emails that could have been phishing emails, and we saved x amount of time. That's that's a stretch. Right? And and and while we've tried over the last two decades to build those kinds of stories, it doesn't ring the same as actual provable. And so these these are great numbers here, obviously, that, you know, you for every dollar you spend almost four x back that you're saving in operational overhead and and, you know, time wasted or frustration with users. The other times that I've seen this happen is when you go out and and do this and you actually have that discipline to measure, and when you communicate that as a CISO to your peers, it up levels your respect among those peers. It's like, oh, wait a second. This person is speaking our language. Right? They're they're showing how they're investing and how it's giving rock to the business. And so, you know, having these kind of metrics is really important to up level yourself as a CISO in those senior leadership conversations. Yeah. I I think anytime that when you're a security leader or a security practitioner, anytime that you can align what you're doing with a business initiative or if you can if you can I I think, know, you and I were talking about this yesterday, that if you can find somebody that is a an ally in the business that's outside your function, it just strengthens your your hand? And, I think we'll talk a little bit more about this in another slide, but but I think anytime you can do that, that that is a it's it's it's really powerful. So you're probably wondering now you're, you're hearing about this and you're thinking, all right, like, how do I know if I have this problem? Well, you, there's some of you here that are, that have probably lived in identity for a number of years. And you're like, yeah, we have this problem. I wanna do something about it. And maybe there's some of you who are just like, I didn't realize this was that much of a challenge. Maybe you don't live in the world of identity. We put together what we call our five question challenge, and it's really it's really it's really simple. Ask these questions of your team. If you answer yes to any of them, you have a disconnected app problem and likely an identity automation gap. You know, I look across these these five questions. Probably the one here that is most easy to dig into is just to look at your your ticketing system in your organization. So question four, does onboarding and deprovisioning rely on manual ticketing? This is one that probably is easier to surface than, say, trying to figure out every single app that you have that doesn't support SSO. It's much easier to go in a ticketing system, just say, hey. Is there is there manual joiner mover and lever workflows? Because you're gonna see a ticket trail for these. Hopefully, you have a ticket trail, but there will be cases where there isn't a ticket trail as well. So, Aaron, as I guess as a as a final thought, like, looking at these questions, what is, like, maybe one piece of advice that you'd give to our audience to help them get started on a problem that probably for some of us feels overwhelmingly large? So going back to what you mentioned on the previous slide, you need to find an ally. Who is the one who also cares about identities? Oftentimes, that's someone in procurement who's looking after licensing of third party applications. Sometimes it's someone in in compliance who doesn't feel like there's a good enough handle on e discovery. Sometimes it's, you know so you have to go find someone else who's also suffering with this through another lens. You find that person and then you say, hey, how can we work together to drive this? So for example, in the case of like a an e discovery problem, let's say for example, you know, last quarter, the legal department got a discovery request through a legal sorry, a court order, and they had to produce certain things, and they felt like they couldn't produce everything they needed to. Well, when that happens in in a legal case, that means the other side generally wins by summary judgment. That's a good way to lose a lawsuit if you cannot produce what you should. And so you need to find those elements of pain outside of IT, whether that's eDiscovery or compliance or licensing payments or whatever. Go look for the pain somewhere else and have them help you go along for the ride here. I love that. I love that. Yeah. Mean, and this some of this is just, you know, kind of leadership one on one is building your alliances. You know, I'll think for many years, security teams kinda did exist as the kind of the team that was off to the side. And as cybersecurity has moved to the forefront over the last, I'd say probably the last five to seven five to ten years, it's becoming more important to be able to do this. So let's let's let's bring this, let's bring this full circle. The key takeaway is this, manual identity processes for disconnected apps, it's a huge unaddressed risk in most organization. But it is a solvable problem. And focusing on the last mile of identity, you can close the gap, produce risk, and often save an incredible amount of time and money. So there's really three a couple of takeaways. Right now, we'd love for you to download and read that, the identity automation gap report. If you scan the QR code on your screen, it'll take each other report. We only covered a a really small portion of some of the findings in the report. Otherwise, we probably would have been here for another two hours and nobody wants that. So go ahead and download that now. Over the next thirty days, start the process of identifying other disconnected applications and accounts across your organization. And you really need to look far and wide. IT, OT, legacy, cloud. Don't just look in one place. If you're looking for a quick win, we talked we touched on this a little bit earlier in the beginning of the conversation, you can reach out to your marketing team and just ask them like, hey, how are we managing access to our corporate social media accounts? Typically, you're gonna get a little bit of a sheepish look like, yeah, we either manage it in spreadsheets or don't really know, like, this is a great place to start. And it's something that, you know, we're helping at Cerby well over a hundred plus different customers solve in their organization plus all kinds of other applications. So that's a way to get a quick win. And then as you discover those applications over the next ninety or so days, start adding those disconnected apps to your risk register. It's the best way to begin to start building that business case for an investment around a solution such as And of course, we'd love for you to start a proof of concept or a proof of value with Cerby. So that takes us to the end of our presentation today. It looks like we've got a couple questions that have come in. Well, this is a question that I get a lot of times. Aaron, feel free to chime in on this as well, but it's like, what are some examples of business critical apps that don't fit easily into today's identity and access management infrastructure? So I think we mentioned some of these, we already talked about like social media. ADP, this is one app that we mentioned previously, but there are literally thousands of these applications. We work with a very large food services company, and they have an application that, you know, ninety nine percent of the world will likely never use, but it runs all of their routes across the world. And this is an app that is completely disconnected. No single sign on, no scam. Right? So again, this isn't gonna be a household name app, but we find this from time to time. A lot of times when we work with financial services customers, they refer to this as, third party SaaS. They'll say, hey, you know, we're working with this other organization. We're using their app and we can't control. Like they have to put all this like citrus they try to put like a citrus citrus infrastructure in place. So somebody has to jump jump out through a proxy, but that's the only way they can control the access. So these these applications, they they literally exist across the spectrum. I don't know if Aaron, there's any of that kinda pop into your head as well, but there are a lot of these apps. You know, as I am faculty, I'm handling, you know, sometimes as many as a dozen Ask the Expert calls a week about identity. This week, I had one with an organization that runs a bunch of of amusement parks in the United States. You know? And so they have ninety percent of their workforce turning over every ninety days because, you know, who who runs an amusement park? They're teenagers, people who are going to college. You know? These are people who are not necessarily there for building a career, and so they're in and out, you know, within ninety days. And so in that situation, what we were talking about then with this is they had a bunch of disconnected apps. Ninety percent of their workforce is churning. Man, the amount of time they were spending, that is significant. And so you see those situations where you're in high churn situations, you're in massive diversity situations, that's where something like this pays off, is it gives you that consistency so you don't have to spend as much time chasing after it. Another question that came in is what does automating the last mile of identity look like in practice? So the best example I can think of, I'll give two specific examples. One is identity, a whole life cycle management process. So today, again, if you have a disconnected app and you have some type of IGA platform, you'll have a portal set up, someone will come, they'll request access to it. But again, if it's a disconnected app, it'll just drop into a ServiceNow queue. So an example of automating that last mile is not getting rid of your existing IGA tools, but hopefully bringing in a solution like Cerby that works with your existing IGA tools, it doesn't replace them, it simply extends what they do to those disconnected applications. So in that workflow there, if I'm a user requesting access to some new app, I come to the IGA portal, I put my information in, I select the app I want access to in the catalog. I click request, it goes through the approval process. When it gets to that last approval, automatically their access is granted. Cerby carries that out on that downstream formerly disconnected application. And it's that same process in reverse when it's Aaron's last day, that access expires at eleven fifty nine pm. When it flips over to midnight automatically Cerby's picking up that upstream skim signal from your, your IGA or your I'm platform. And it's automatically carrying out that on those downstream systems, whether it's one or a thousand systems. Alright. There was one last question, and then we'll close things out. What quick wins can leaders achieve in the first thirty to ninety days after identifying disconnected apps? You know, that's a that's a that's a tough one simply because everybody's environment is so different. And, Aaron, I know you do a ton of consulting, so you're really great with the it depends. But any any thoughts on this in terms of what are maybe some of the wins that a leader could achieve in the first ninety days after they've identified some of their disconnected apps. So going into the project, this is where it's gonna be very important where the security leader understands what are the buttons that need to be pushed in the organization. Is that cost containment because of budget cuts? Okay. I'm gonna save x amount of licensing revenue by, you know, eliminating this overspend on on provision users. Or is it, you know, we're going through a huge acquisition situation where we're going to be acquiring a bunch of companies to grow the company. Okay. Well, then my metric in the next ninety days is gonna be, hey. I reduced the amount of friction to onboard these users because I've automated this. So I think it really comes down. You need to find out what is the button to be pushed in the organization and tie your metric in the first ninety days to whatever that business success case is. I love that. I love that. Well, this has been a amazing conversation, Aaron. Thanks for thanks for joining us and thanks for listening. Again, please download the report. If you'd like to learn more, please visit us at Cerby dot com. Thank you so much.
Only 4% of organizations have fully automated their core identity workflows. That leaves 96% managing identity with manual, fragmented processes, and the gap is widest for disconnected apps: the business apps that don't support SSO, SCIM, or APIs. In this session, Cerby Chief Strategy Officer Matt Chiodi and security advisor Aaron Turner walk through what 500+ IT and security leaders revealed about the identity automation gap, why it persists, and how to close it without replacing the identity stack you already run.
What is the identity automation gap? It's the distance between the apps your identity tools can automate and the apps they can't. Cerby's research with 500+ IT and security leaders found that only 4% of organizations have fully automated their core identity workflows. The gap concentrates in disconnected apps, the apps that don't support SSO, SCIM, or APIs, so provisioning, access reviews, and offboarding for those apps stay manual.
Why is identity still managed manually for so many apps?
- Many business-critical apps don't support the standards (SAML, OIDC, SCIM, APIs) that identity platforms rely on.
- Access is granted through request portals and tickets, then fulfilled by hand.
- Large organizations run divergent identity platforms, so no single system covers everything.
- CISOs still have to attest to identities they can't see or control automatically.
What are the risks of leaving it manual?
- Orphaned access: people keep logins to apps, payroll, and email after they leave or change roles.
- Audit exposure: manual, inconsistent records make attestation and compliance harder.
- Wasted time: teams lose thousands of hours a year to manual identity work.
- Higher stakes in regulated and critical-infrastructure environments, where lingering access is a real risk.
How do you close the identity automation gap? Automate the joiner, mover, leaver lifecycle for disconnected apps the same way you already do for federated ones. Cerby applies deterministic automation, provisioning, deprovisioning, credential rotation, and MFA enforcement, and passes lifecycle signals upstream and downstream so an offboarding in your source of truth carries through to the disconnected app. It extends the identity stack you already run (SailPoint, Okta, Entra ID, Ping, Oracle, ServiceNow) rather than replacing it. Customers such as monday.com have used this to recover significant manual hours and cost.
Presenters
Aaron Turner
Faculty
IANS
Matt Chiodi
Chief Strategy Officer
Cerby