Video: Not All CIAM Is Created Equal: Modern CIAM for Financial Services in the Age of Fraud & AI Agents | Duration: 3608s | Summary: Not All CIAM Is Created Equal: Modern CIAM for Financial Services in the Age of Fraud & AI Agents | Chapters: Introduction and Context (23.775s), Identity Trade-Offs (199.72s), CIAM Research Insights (319.26s), Fraud Prevention Priority (623.965s), Risk Signal Integration (1276.5701s), AI and Identity (1462.3151s), Self-Built SIAM Challenges (1847.1449s), Vendor CIAM Advantages (2149.125s), Future of CIAM (2617.985s), Strategic Leadership Insights (3084.24s), SIAM Business Ownership (3261.045s)
Transcript for "Not All CIAM Is Created Equal: Modern CIAM for Financial Services in the Age of Fraud & AI Agents":
All right. Hi, everyone, and thank you for joining us for today's webinar, Not All SIAM Is Modern SIAM for Financial Services in the Age of Fraud and AI Agents. Today, we'll spend the first part of the session briefly setting context around what's happening across financial services, the pressures institutions are facing and how the landscape is shifting. And then for the majority of this discussion today, we'll dive into some research from Datto's insights on SIAM maturity and why not all SIAM is created equal. Before we begin, a quick safe harbor note that some of what we'll discuss today may include forward looking statements. With that out of the way, let's dive in. So my name is Christopher Otman, and I'm the Staff Product Marketing Manager for Financial Services at Okta. Today, I'm joined by David and John. So I'll pass it over to you both for some brief introductions. Thanks, Chris. My name is David Janekowski. I am a strategic advisor here at Okta. I focus primarily on the financial services vertical. But prior to coming to Okta, I spent about twenty six years in industry for different banking and healthcare payer organizations building their SIAM and digital experiences. And my name is John Horn. Christopher, you. And David, thanks for having me today. I lead the cybersecurity practice at Datos Insights. So I lead research and advice to financial institutions, banks, insurance carriers, and other financial services firms. And within that, I lead our research on identity and SIAM. Before Daedos, I spent twenty four years leading at Fiserv and owned our SIAM deployment there. Happy to be here today. Perfect. Yeah, thank you both. We're excited for today's session. So with that, I'll start a little bit by talking about the broader landscape and some of the forces reshaping financial services today. I know to a lot of those in the room, some of this isn't anything new, but it is important to hit on all of these different tipping points converging at once. So we have things like M and A, which is very present in the industry, Open Finance, which may be more impactful to you depending on your geographic or the size of your organization, Tech debt across lines of business, business silos, and of course, the most important of all AI agents, which is the talk of the town right now, and evolving threats and compliance that comes along with that. So with that, all that to say that there's really a big battle going on between the balance of agility and security, user experiences and compliance. And it doesn't necessarily mean that improving UX may weaken security or that tightening controls increases friction. It really just means that to get the right balance right, you have to make sure you have the right SIEM in place to achieve all of those objectives. And ultimately, as I mentioned, those balance there's, it's really a great segue into my first question for David, which is really around your perspective of working in the field of where are financial institutions experiencing some of these identity trade offs today? That's a great question, Chris. And yeah, from both my experience, pre Okta as well as being here at Okta, all zero, I can kind of give you some of my thoughts. So, the trade offs are throughout. Think the idea here is that, especially when you talk about our digital channels, we want to make it easy our customers or prospects to get access to our systems. But the struggle is that sometimes making it easy, maybe in some estimations or people eyes, make it less secure. When we think about registration and onboarding, these are some areas that come in contention. Some of the different implementations of MFA that folks are used to. So not just when they're looking at the organization that they're setting their account up and setting that up for, they may have different experiences in the many different digital products and services they used. So that inconsistency leads to how do we better build that experience and how do we ensure that we're not sort of starting to experience things like MFA fatigue and things of that nature. KYC, always know your customer, always a challenge out there. And then in many cases, at least from my experience, when I supported different lines of business from consumer to commercial to wealth, everyone did it differently. Right? So I think trying to figure out how to unify that in an organization to leverage certain capabilities throughout to make the organization stronger and not reinvent the wheel, but at the same time, have both those member experience teams as well as the security team working together to ultimately provide a secure, delightful experience for end users. Yeah, that's a great point. I think unifying the two teams, and it kind of touches on this slide a little bit where we still know that identity is at the frontline of modern fraud, that's no surprise, but it really takes the unification of folks to understand, okay, we know that phishing and credential stuffing, ransomware and account takeover is still a thing, but how do we make sure that we can still innovate and be present for those younger generations or digital first folks who want the best experience, but still wanna trust your organisation to stay secure? And I think that's kind of where identity plays that role, and really why CIAM is built and operated as this key driver of all of that. And it goes back to what John's research is and what we're gonna talk about in the different types of SIAM and why choosing the right one is critical. So I'll pass it over to John to really just start diving into some of research they did around SIEM maturity and outcomes across financial services, and talk around first the scope and the approach of the research that they did. So, over to you, John. Thanks, Christopher. And I ought to anchor us on that word trust that you mentioned before, right? For financial institutions, trust is actually what they sell and what they provide. It's the anchor value proposition for the consumer. So as we looked at these two research items here that are on the screen, these are both commissioned sponsored by Okta. Okta actually deserves a lot of credit here. Didn't ask us to go to specific financial institutions, just off zero, so I am accustomed to know. We actually went in twenty twenty three, 2024, this phase one, where we did a worldwide research study, two thirty eight financial institutions, 20 of which I spoke to in an hour long deep dive, what we call qualitative interview. And it research was a piece to figure out how far along financial institutions were on unified digital banking with SIAM. Most everybody knows what unified digital banking is, but for the couple that don't, I want to define it really quickly. It's where all the services that you bring to a consumer, mobile banking, online banking, every payment vehicle, lending, certainly the ability to manage your profile, your security profile. But all these services are rendered through one common login and authentication experience. And that was aspirational twenty years ago, and I've been around enough. I've just dated myself to say that. But it's just the expectation now. So the first study, which was just a tremendous study, was really helpful for us to see where the financial institutions were, where they were per region, and some of the regional nuances there. And even we proved some points out on what is a password reset ROI. We proved it. We proved out some numbers. We proved ROI for revenue growth, which was on cross sales, not new customers. And we also proved out some speeding up of services to market through robust science. So great, great effort. But then when you do a good research effort, we said, what could we do next? What does that interest us? And so the second phase study, which we're going to focus on more today, narrowed into North America only. It was 64 financial institutions, eight to 10 of which I got to speak to in this hour long face to face format where I can of dig into an answer when I sense something interesting. And that's what we're going to mostly talk about today. But the phase two was mostly driven on the three kinds of deployments that banks and finance institutions had brought to the market for CIAM, build core banking processor and vendor. We'll talk about that in a bit. And then we really was outcome based, like how are you achieving your goals? How are you achieving business outcomes? And that proved to be an interesting bar. So it wasn't what's your run cost basis? It wasn't what's your tech associated with SIAM? No, no, it was what are the hardest things the business wants you to get done and how are you doing and achieving those outcomes? And that was the basis for this research. If you tip us over to the next slide. Yeah, and I just have a question for you, John, before we jump into that first finding. Who are the types of personas or different folks at these organizations that you and the team chatted to for some of this research? It's a great question. So, on the first research piece, we actually said, who's the budget owner? Who's the champion of SIAM? And like in The United States, it's a tie between the CIO, who's the traditional SIEM owner, and the CISO, who's kind of the emerging owner for SIEM. In Europe, it was much more CISO because they're the number one owner. In APAC, in Japan and Australia, it was more CIO types, but it was largely the owner, the budget owner of the solution is who we talked to there. Good question. Awesome. Perfect. Anything to add on, David, or should we jump into the first finding? No, I think we're good to jump in the first finding. All right. All right, here's the first finding. And if you're in the market a lot, this might not surprise you, but there's some interesting things here. The headline is, you know, fraud prevention is the number one cyan business driver right now. And that is a difference. If you look at the chart on the right, it's one of our stacked bar charts and there's a lot going on there. So let me help you with your eyes for those in the audience today. If you see that green dash box, that was the 2023 result in the top two drivers for Customer Identity Access Management Solutions, or CliAM, were customer security and multifactor authentication, or MFA, and customer experience. Those two have been the champions for the last decade, the last fifteen years. It's always about experience and security. Well, in 2024, we'd heard this in 2023 from, hey, by the way, John, fraud prevention is starting to sneak up on me from my C suite. They're starting to lean on me, don't know where this is going to go. Well, on the research, the North American research with the 64 financial institutions, fraud prevention or enabling real time detection and a three sixty degree risk view of the user was number one. In fact, it was number one by a large margin. If you see the 73% said it was critical, 22% said it was very important, and that's 95% of the market. So we've heard this, and so the backstory is interesting. Let me say what it doesn't mean. Some of you might look at that third row and say consumer experience, wait a minute, that's not as important as it used to be. No, that's not what the research says. The researchers though, the financial institution SIEM leaders said that it's just lower in priority because they kind of had it licked. They've gotten experiences to bot where they need to get, and so just like if you have a broken leg and you go get a surgery done, after your surgery is done, the recovery is done, it's a little less important emotionally to you. So experience is huge, but they've gotten it in a pretty good place. Where they were having the pain points was executives said, You got to come over and help the fraud side of the house. This is a hard area for financial institutions. If you're a seasoned professional, you watch this kind of grow. Fraud prevention, these are great men and women battling it out for card fraud, online payment fraud, all those things. But they've been fairly siloed historically, and they've had kind of the backstop of being written off. Fraud losses have been written off historically as part of mitigation approaches, but fraud is just growing by leaps and bounds. It's tracking real time payments growth across the world. 58% of fraud leaders in some work after even this research said they expect a 10 increase in fraud in the next three years. It's just the AI attacks from cyber criminals. The gap between the attackers and defenders keeps getting larger. And so fraud prevention and getting a three sixty degree risk view of the user is actually harder than it might. It's easier to say it than it is to actually pull that off. So that's the number one problem and the biggest driver at financial institutions in North America. And then the consumer security and multifactor authentication actually went up in a year. It was in the 55% as urgent. Now it's up to 61%. Again, multi factor authentication, not all MFA is the same, right? So the attackers and what the analyst calls adversarial AI and beating fragile workflows, it might not be on authentication, but it's on account recovery, it's on password reset. So fraud detection has become the new king or queen, depending on your metaphor, and consumer security and MFA have risen in priority also. Know, John, those are great points, and I can speak to it from a couple different lenses. Prior to joining Okta and AltZero, I was on the forefront of implementing sort of the Zelle P2P payments within our platform. And one of the big concerns working with financial crimes was making sure that their requirements to minimize fraud were included within the overall budget. Because to your point, who owns the budget? Sometimes it's CIO, sometimes it's CSOs. But in previous endeavors, their voice and requirements weren't always heard. And as they kind of help educate me, fraud prevention is key in a multitude of ways. One, I think you used a great word earlier about building trust. Organizations wanna build trust. At the end of the day, you know, it's been statistically found that financial services organizations, they do experience fraud, it's at a higher dollar amount than other industries. Right? And the third thing that I learned, which sort of makes sense, not that I didn't know it, but I think when they call it out, it makes a lot of sense, is that it's a lot it's a lot easier to prevent fraud than trying to recoup fraud and chase it down and all the hours that go into that. And even if you do recoup it back to the word trust, many individuals out there when they're thinking about who do they wanna do business with, starts with trust. Experience is certainly tied in there. And I like the point that you brought up about MFA. So many of these different capabilities and components are very interrelated. And that's when you think about it, it's not one capability versus the other. It's working them cohesively together and having partners that allow you to bring all those things together. Because at the end of the day, right, there's not like one golden solution. It says we have everything. It it's a cons it's it's bringing different capabilities from different vendors as the threat landscape continues to evolve. You mentioned account takeover. Right? There's all types of different things that are happening from spoofing email addresses and phone numbers and devices and man in the middle. Maybe person in the middle might be more appropriate. But the idea there is that you need a robust set of capabilities. The likelihood is you really do need to bring kind of where you can best of breed and you need to stay on top of it. Because I remember when I first started building systems, you know, most things were user ID, password. Then one day somebody said let's add security question and answers. But the the explosion of what it takes to have a capable SCIM platform that can really help prevent fraud can be daunting. But again, finding the right partners absolutely can lead to fraud prevention and reduction in that and ultimately making a better experience of building that trust. Well said, David. Yeah, with that, I think let's jump into finding two. Of what you mentioned, David, really hits on some of those inconsistent identity controls. So, John, I'm curious more about this finding too. Yeah, so we asked, and again, as a researcher, you ask questions in a different way to draw out the response. So we sort of use the quality assurance term being blocked, And said, where's your business blocked? Where do your executives you could say you don't agree or not with where the executives want to take the business, but what do they think? Where do they think you're blocked? Whether it's legitimate or not. And it's always legitimate, right? The researchers ask that way. It's always legitimate. So where the business was blocked, these are financial institutions only. Number one was with Open Banking and API integration and just the customer sharing element. And so Open Banking and Identity together, we we at Datos view as the hardest solution to build at the bank. It's just the hardest one to build because there's just multiple components. So if you look at the Open Banking API integration, fraud prevention was number two being blocked, and then even Open Banking identity kind of fueling access control. These are places where there's inconsistent controls create these, like where the slide says blind spots. Let me say even more. This is the place where SIAM or customer identity has to become not the outcome, but the signal to something that's better and even more important. So some of the bank identity leaders that I advise, they're used to the SIEM and the authentication stuff being yes or no, throw MFA, yes or no, and their world is dictated by that summit of the mountain. The hardest solutions now where has to turn into a signal to something else. So you're left to things that advisors like me call Identity Fabrics, right? This shared risk ecosystem where SIEM has to become a piece of data at the API security infrastructure takes dependency upon, or a piece of data that fuels into the fraud model where the user never gets to the transactional step because they've gotten some bad cyber piece of data or science piece of data along the way that tells them you shouldn't actually be, this is a risk to even head toward like a real time payment transaction. So these outcomes are hard, They're what the executives want most, open banking. Mean, Frank October, most know that that's kind of fallen by the wayside. That was driving things for a little while. This advisor saw a lot of goodness in October, but some things that were just absent, just absent that were fundamental from October. So getting practitioners back to the basics, you need identity to become part of open banking. The number one problem with APIs right now is business logic abuse, right? Good calls to the APIs, but they're actually manipulating your business logic without identity inside that ecosystem, without SIEM data inside that ecosystem, you're left with coarse grain tenant level authorization, and that's just not going to cut it for cyber attackers. They're way past that today. So finding two is really about other higher order outcomes at the financial institution that CIAM has to be a signal for. And I'm using that term because that's generally the term we're using for one part of the risk ecosystem informing another in real time or near real time if there's a problem there. And these are the hardest solutions in the market. And this calls to another order of delivery because traditionally SIAM hasn't really functioned as a signaler to other things. It's been the outcome in itself. David, from where you sit in the market, I'll ask you, what do you see in the field around these kind of outcomes in Cyan's role? Yeah, absolutely. And I think you had some great points in there around what we're seeing as well. And I love the fact that you kind of called out those blind spots and inconsistent identity implementations. One of the things that I've been seeing a lot, I was just having a discussion just before really this webinar itself around sort of digesting risk signals. Is AMFA enough? Should we use MFA? And I talked about a broad ecosystem of risk signals. It's not just a single vendor or a single risk signal. It's bringing in those multiple signals into an environment to be able to identify, to your point more proactively, what is something bad is trending towards happening? Is it more likely than less likely? And then what action should we take within that environment? And I really do see that. And I I like the fact that you brought up ten thirty three, you know, within The US as we refer to sort of open banking, which is much different than what you might see in The EU and other parts of the world. I've worked some with some international customers, and and one of the things that we embedded in into our platform is something called highly regulated, but it's around FAPI, financial grade APIs. And it was sort of the the response to to a little bit of what you were discussing is that sort of the current way we build APIs and things isn't secure enough. It's not enough. And in some parts of the world, like FAPI, there's different certifications around it, it's required, especially when you're integrating third parties. In the European Union, you see things around payments like PSD two. And as a practitioner and somebody who likes to learn and see what others are doing, we also can learn from what others have done, not just in The US and even if ten thirty three doesn't include all the things that we needed to or we're not necessarily regulated to do so, there are some good practices out there that can help mitigate a lot of these inconsistencies and potential areas for fraud and abuse out there. And again, I think within an organization, as I mentioned, I supported different lines of business. And some of those inconsistencies also came from we had different owners who had different outcomes they were trying to achieve. And so they always didn't necessarily work together to ultimately come up with something that was better for the organization at a broader standpoint. So awesome findings. Think I love this conversation and the conversations that you had because there's a lot of things for many of us out there that we think these things. We always don't necessarily get those data points to help us understand, is that a true statement or a false statement? And deeper than that, not just true or false, but to what level should I be concerned? What are other people concerned about? Because it's also those areas and shades of gray. So I thought you did some outstanding work, John, in collecting this data, kind of putting it together for us to understand and be able to sort of kind of measure some of the things we are all thinking out there as an owner practitioner. So appreciate that. Thanks. Awesome. Let's keep diving in then, think, Craig. Yeah, I wanted to just add on one piece. I know, David, you mentioned about kind of what are others thinking about? What are they should be concerned about? What's new? What's up and coming? John, I know when this research came out, AI was something being talked about in the industry, wasn't necessarily fully included in this report just by nature of what Auth0 had commissioned. But I'm curious, obviously, AI agents, AgenTiC, all of these talking points are very critical for financial institutions. So, where do we see that fit in the place of everything else that's of significance? We talk open banking, we talk fraud being in the mix. Let's just add one more non human identity to the piece. So, I'm curious of your thoughts there. Yeah. So, maybe two Oh, I'm sorry. Where's that going to be? I'm good, John. No, you go ahead, John. You lead it off and then I'll add on. So generative AI has just added scale to all these attacks, right? All these phishing and social engineering attacks and to a large extent, institutions had to know where they were already vulnerable and then bolster that up, which has really called into question traditional MFA and getting more toward PASC keys and stop counting the number of factors, but strengthening the factors. That's what vital based PASC keys are all about. But with Agenic now on the field, right, and emerging, you can't gosh, our CFOs go to conferences and they're talking about Agenic, right? But Agenic kind of tips us over a bit and brings us back to the on behalf of days where you will not only have to secure, this is where non human identity comes in, you not only have to secure the Agenic platform or the plugin that's going to come in the vendor product that you buy next week, right? But actually who the on behalf of is, who's the consumer behind that? Who's the vendor behind that? So it's sort of stretched, if you will, the customer identity side of things, because there's different ways that financial institutions are going to use Agenix. So AI really is reshaping this whole space. There's certainly some there was some buyer's remorse on early AI buys for defense purposes. There's been some correction recently on that. But I'm pretty bullish on AI and identity in that combination, because I think AI for the good, what you can use in a product and an identity product, I think that's a pretty revolutionary combination that's going to help the market evolve faster. I'll pause there and let David throw in his 2¢. Awesome, John. And I love the fact that you talked about on behalf of, right? That's a great term because when you think about what these agents are doing is they're acting on behalf of something, a system, a person. And we've kind of moved in this space with agentic AI to now they're autonomous, They have the ability to make decisions, and they're accessing things and finding pathways potentially to data that we didn't believe there necessarily was a path. I like to think they're trying to be helpful, but sometimes that helpfulness can actually lead to not desirable outcomes. And this is where you get into things like needing or agents going to do something on behalf of, there's a term called human in the loop. Somebody needs to be there to sort of decide if that action that it's about to take, again, not just pulling back information, but being able to take action if that's acceptable or not. And it also is pushing on sort of the traditional authorization models. A lot of folks use RBAC models. Right? But now what we real recognize, and I think you stated about that coarse grain, we gotta get down to fine grain. So now you're talking about RBAC, attribute based, policy based, that we have to be much more granular in in knowing what's being accessed, how it's being accessed, and there's new protocols and things out there like MCP servers, out there to help with part of this. There's new standards like cross app access. But the idea is that it's going back towards identity. And identity systems in the past were kinda looked at as just kinda like log in, we're done, maybe some course grain authorization. But one of the the concerns with AI agents and the sprawl is that is there somewhere central that's actually telling all these agents and the agents to agents communicating, what am I actually authorized to do? And that's becoming a very critical point that we're at this inflection point where identity is very important in that. And in this case, your SIEM platform really needs to be at the center of that and have the ability to do some of those other things we talked about, like the fine grain authorization to ensure that the right data, the right actions are being taken by the right individual or agent without causing additional due harm. So great points. And again, I'm excited to be part of this discussion and seeing where this is all going, but these are absolutely things that we very much are focused on and looking to kind of help organizations manage and get in front of because the results, we've all seen data breaches out there, free AI, the exponential impact that this could have on organizations that don't do this right, certainly don't want to be out there. And that would really go against the whole manner of trust. Yeah, we think about the younger generation, myself being one of those. The last thing you want to be is one of those institutions on the news. We've heard some airlines promising deals. We've heard new ways that agentic applications have allowed access to unauthorized actors. So, I think really the whole point of this is getting ahead of the curve, making sure you're secure. And this leads us into the next piece of not all SIAM is created equal. So I'll pass it over to you, John, really to start discussing those three groupings of how those different SIEM pieces operate. Excellent. This is cool stuff. So, from the first research effort, found, we asked how the bank, financial institution had deployed CIAM, and then we went back in the second research effort and asked a set of questions that were exactly the same to each of the 68 financial institutions. And then we organize them by how they deploy SciAm and can we correlate some interesting things in this? So just for the purposes of the audience here today, the first category is self built. And that sounds pretty obvious. Younger professionals will go, why would you self build SIAM? Well, it used to be you did self build SIAM quite a bit. It was much easier. I think David said before it was an ID, a hash of a password, a tenant ID, and maybe some knowledge based questions. That was as hard as it was fifteen, twenty years ago. Some are still operating that way, 15% in North America operate today. The second set is leveraging your bank processor. This is actually the greatest number of FIs in North America are delivering cyan this way. And if bank processor isn't a familiar term, it's your core banking processor. It's my former employer in Pfizer, where I was for twenty four years. The FIS is Jack Henry's DIs, all those Q2s, all those platforms that provide financial services for financial institutions and their consumers. Well, unified digital banking was one of the best things those processors ever thought of or created. Fifteen years ago, this was sold across North America wildly and actually across the world. And cyan in many cases was a throw in. And hear me out, it wasn't the main thing. It was just like the tires on the car. You're going to buy a car, SIAMs the tires. Well, as the risk has gone forward in the market, unified digital banking has become more the base product or what we would call table stakes in the market. And the SIEM piece is actually the more important spot. So banks today that are leveraging processor SIEM may have inked that deal fifteen years ago and they weren't buying SIEM, they were buying unified digital banking from their processor. And so today it's a little different. I know of a huge regional credit union in The US that is moving processors, and they're not moving unless the processor can support their own customized Cyan platform. Cyan is just more important now. That's the second category. And the third category is financial institutions that are using identity vendors like Auth0 and others. There's actually quite a big variance in SIAM by name only that can do some basic things that are very long the tooth in the market, all the way up to us, some other leaders that are really about signaling and the like. So we asked the same questions across these. We didn't show the financial institution in this grid. We just asked them the questions about how they're performing and how they're achieving. So let's dive into the first category, if that's okay. Sounds great. So self build. These financial institutions were exclusively self build shops. They self build everything. They self build unified digital banking. They tended to self build API infrastructures. And there's no shame in that, by the way. I don't want people on the call today, if you're operating a self built ecosystem, you know how hard that is, and high respect to you. But they had the hardest challenges, the research indicated. They had the highest pain point for consumer experience at 50%. And let me say, that's a laggard indicator because consumer experience was being managed pretty well by the overall set of financial institutions. This was clearly the area where they were struggling. It's hard to keep pace when you're doing self built SIAM. It's not just the PAPI path some of us used to call in the old days. It's the corner cases and all the aspects of account takeover now. But the highest pain point for a part of the experience, the part of the solution that others have gotten under pretty good control. They were also 72% or blocked at the highest rate to get secure open banking done with identity. It was like two in the qualitative discussions I was privileged to have, it was like getting two integrated self built solutions to integrate together. And that compounds complexity. Again, you're getting staff from your own development team or maybe outsourcing development to get this done but hard. And then maybe the bottom line is that one in three believe or they know they're not operating with the right solution. They need to get to vendor SIAM. They've had a hard time making the business case. Their executives would say the roof's not leaking that bad. And they have actually said with this research, since some of them have seen it, oh, this is going to help me. It's just not me complaining about operating self build. One in three are wanting to get to another place. So self build is the hardest path for looking toward business outcome, but it was the original way SIAM was built twenty years ago. The next one on processors. Processors, again, you're getting it from the processor who's delivering all your digital services for consumers and unified digital banking for consumers. They had some pain points, really the slowest response. So I've heard this quite a bit in my career, hey, I can't get to my data, I can't get to the ability to define this myself and define policy myself. The SciENc piece is, they don't use the word black box from the processor, but it's in that vein that it's just not, it's sort of a one size fits all. Or if they're able to bring to bear some segments, it's coarse grain. It's just lack of control or slowness of control was a big pain point. The 54% is blocked from open banking and secure data sharing. Again, that's better than FIs who are doing self build. 54% is about what the market is struggling with open banking secure data sharing identity. On the good side, 87%, the highest rate enabled pass keys for FIs. So FIs from their banking processor had the availability, not early deployment, not we can only deploy it for 100 users. No, no, we can deploy it as an opt in for your consumers. And processors were on their front foot the most being able to glue this together, maybe through multiple vendors, but the processors deserve an attaboy and attagirl for enabling pass keys to the greatest extent across the three FI basis. And then finally, the identity vendor piece. Best scenarios before you even look at the numbers, they had the lowest pay points on aggregate. So it's not that every vendor SIEM solution is the same, they're not, they're not in spades. But in general, FIs have chosen vendor SIEM and that's what 95% of the FI market is doing today, they're pursuing that. They're in the best situation, lowest pain points. This is an interesting one. David, like your take on this one. They have the highest drivers, highest pressure from the executive tier to improve fraud prevention, bottom line. And the qual interviews of men and women I've known for a long time. It's sort of the story goes, well, we bought one of these top CIAM platforms, so the executives look at us and go, okay, now go solve fraud prevention with that. We bought it, it's pretty cool what you got, we funded that, now go solve something else for us. There's that dynamic of sort of fits the to whom much has been given, much is expected kind of paradigm and mindset. So the highest fraud prevention improvements. David, any insights on this one, brethren that are operating with some of the top vendor SIEM solutions? Sure, absolutely. And I think what I'll say to this is that when clearly articulating, I built this one view that talks about all the different capabilities within SIEM, including fraud capabilities and all these other things, even extending into some of KYC and things of that nature. But one of the things that I think is sort of when you buy a platform like SIEM, you need to understand what capabilities come within them. And some SIEM vendors, include what they'll say is we have these extensive fraud capabilities. Right? Or we we we just include it in the package. And and for instance, if I could speak to AltZero, you know, there's certain capabilities we do include from a fraud perspective, bot protection, impossible travel, things like that. But there are very specialized vendors out there, that very much focus on fraud as a core competency. And what I have found that worked the best is having a platform that can integrate these different signals. And if there is a fraud vendor that that's what they build, just like you talk about working with a SIEM vendor that built that has a platform that's built for purpose and focuses on that versus sort of like just a side thing or in lieu of something else. That there are very highly specialized fraud prevention solutions out there. And sometimes it's multiple. Some look very specifically at transactional things. Some look at just fraud from a perspective of a validation and a risk score on a phone number or email address. And the idea here is that as people are looking at they gotta recognize they need some specialized capabilities. And that, unfortunately, when somebody looks at a CIM platform and thinks everything's included, it's sort of like it may be to some extent, but it doesn't mean it's at the right level and it's as robust as you think. So some people think, great. I'm getting a great deal. I bought a SciAm platform and have some of this. I'm good to go. Look at that. I get everything I need. And then they wonder sometimes or see results that some of their fraud mitigation or fraud is is not trending in the way they think it is. And some of that is because that you really gotta look at those specific capabilities to ensure they're in. And most I'm platforms, don't include what I would say, the end all be all fraud capabilities. You need some additional partners in there, but you need a SION platform that can pull in those signals and then be able to react accordingly. Great addition there. As we say now, fraud prevention has really sucked. Retail fraud is distinct from commercial fraud. Are different animals. So I think the folks on the call in our audience today need to beware a little bit of trying getting something that solves all the world's problems. I don't see that, you don't see that. It's really a partnering approach where the leading SIEM vendors can integrate within some fraud models of other leading fraud platforms. In most cases, that's where I see the biggest progress. And again, the other statistics here, open banking and security data sharing is about on par with the processors. You might remember that's 54%, so about the same. And a surprising result is that PASCI opt in was a little lower than on the bank processors. And I think it has to do with some shared, it's a platform version to support PASCI's organically versus the partnering approach and that bank processors sometimes solve that in the back end for the financial institution. But again, the vendor centric SIEM, especially if you have the right kind of robust SIEM platform is the least painful and the highest degree of achievement for business outcomes right now. That's great. And I guess back over to you, David, we talk about the future of financial services, and it's really rewriting SIAM requirements. So we talked about AgenTic, not just from the standpoint of nonhuman identities, but I've been talking to colleagues about AgenTic Commerce, and there's a whole bunch of new things that are gonna be coming down the road that to have the right CIAM platform, you really need to make sure it's kind of evolving with your business. So, I'm clear from the field perspective, how is it for someone who's kind of transitioning from either a vendor built or a self built platform into this new world of, let's just say, all the bells and whistles, or some of the bells and whistles, depending on what they start out with? Yeah, absolutely. I think it's important the way John walked us through the different SIEM platforms from building your own processor to an identity, vendor solution like an AltSero. And they're not all created equal. And I can just, you know, add a little bit of, some anecdotes here to things that I see. Right? I some customers I talk about, they're like, you know, they they built an army of developers trying to keep up with, you know, building their own SIEM solution. And sometimes when I I was talking to one recently, and it's been a year and a half, and they still haven't been able to implement pass keys. To John's point, some of the vendors that are on the bank processor already did that. Right? I think where the challenge lies with some of the the bank processors are they're they're not always standard space. So where you see some of the struggle struggle with open banking and things like that in aggregation, when you don't support standards like OAuth and flows like that, makes it more difficult to adopt and and adapt to what what's being expected out there. And so they're not necessarily keen on doing things like FAPI and other things because it's part of the platform. And again, some of their specific special sauce is really an actual capabilities of being a core bank processor or building a unified environment. Not necessarily SIEM, right? And I've always had the thought for the longest time, especially when I kinda measure against developers can build a SIAM solution, but should they? I think about all the necessary skills and understanding and capabilities you need. That's a daunting task. Even if you have a very large budget or unlimited resources. And even within a bank processor, it it's evolved so quickly that it would probably benefit for even them to leverage some of the platforms that are out there, kind of that box three we talked about where there's identity vendor SIEM solutions. Leverage them behind the scenes. Let them continue where therefore full focus and investment is around building a SIEM platform. And then continue to add new capabilities to your digital banking and and all the things that you really do focus in on. Right? And if you find the right vendor, because I did find some of John's research interesting. We talked a little bit about the fraud, but some platforms like AltZero, when it comes to open banking, have built that into their platform. That's all about the highly regulated, basically within the platform. The pass keys, again, building that into the platform. Not all SIAM platforms are created equal, but if you really look at a detailed view of some of them, they include all those capabilities that you need and it gives you sort of that best of all worlds. Is the ability to sort of go from low code to pro code to build out the things, to know that you're compliant, and be able to really own that identity. As the next challenge, like we mentioned, Agenic AI, you brought that up. Now how do you handle that? Well, if you have a good strong vendor, and partner, I'll say I'll lean more on partner, especially within SIAM, that's already starting to be integrated into the platform to be able to build things secure by design. Not like, oh, how do we actually react to this? What do we do next? How do we bolt this on? And oh, by the way, it gives you more control. It's not an add on. It's not a separate SOW to go do something or ask somebody to do a one off because you're trying to lead the pack. It definitely gives you more of that control. And I think, you know, as we kind of move forward, you know, you're looking for platforms that can kinda take you to that next stage and beyond. So that's the open banking. That's the pass keys. That's integrating. We talked a little bit about the fraud. You know, having a marketplace where it is has the ability for integration with third party fraud offerings right out of the gate so you can quickly wire those together. Those are important things to really help a business stay agile and nimble. So you're not just meeting both the CIO and the CSO's requirements. At the end of the day, you're meeting the CMO or the digital officer. You're able to help pivot as needed more quickly, but in a secure fashion. And if I could add just two comments. They're great, David. There's to the three lanes we had before, self build, core banking processor, and vendor SIAM. This is early, and I'm not in a position to name names, but there's a couple core banking processors that are thinking about partnerships with vendor CIAM, that are in various stages of they know, they're here to serve their financial institutions and they can see their gap and they're starting to say, what if we used, fill in the blank SIEM vendor to bolster into our platform to serve their hundreds, thousands of institutions? So don't sell our processors short because I know there's some of those people on the call today that are thinking about those kinds of things. I encourage that. And then about the slide here in SIEM requirements, I'm a big believer in pushing SIEM requirements up the business. That SIEM leaders, yes, it's important for SIEM to be up all the time, past four nines, resiliency is huge in the market right now. I'm a big believer in that cyber hardening, right? So whether you're in multi cloud or some type of hybrid cloud, you can resist the attacks that you have to. Those are super important. But what's becoming more important is actually allowing your requirements to become KPIs at the executive level that say, hey, if we do this, we're going to bring fraud detection rate up by some number. And that's scary for SIEM leaders because that's like anchoring your success on the executive tier, which I'll say no more, right? That's just a little scary. But what I see leaders in The US beginning to do that, a couple are really on their way with letting the requirements be, okay, we have all these tech things that the executives can't even spell, the CIAM piece, but there's these functionality things that I really encourage CIAM leaders to get their executive to sign up for that outcome because you may not get there in a year, but you're going to get there in a more strategic way and you're going to draw your business partners in as actually funders of your solution. So I think SIEM requirements need to go up the stack and be articulate based on KPIs that the executive tier is looking for most. That's a great point, Shannon. It's also good insights to kind of know where processes are starting to think. So I think those are two great insights. I totally agree with the requirements going up and being able to be measured. If you can measure it, you have a better chance of achieving it at the end of the day. Yeah, it's also a great segue. We talk about the future of financial services, but our next slide here is, John, David and I talked, what should leaders be doing now? I'll touch on the four, and then I'd love to open it up to you both. But the first is establishing a clear baseline of your current SIEM maturity. So where do you sit on that curve? The second is focusing your modernization on high risk, high friction customer journeys. We know that it's not always easy to tackle everything at once, but at least take a look at where there is the most friction today. The third is defining your future state of identity for things like non human actors. We've talked a lot about AI agents and agentic commerce, so really just future positioning. And the fourth, which is very critical, is establishing clear ownership for SIAM. So who is that executive leader? Who has that say and will report statistics up, as John was mentioning, for that CIAM, either processor or that entire kind of engagement that you have? So with these four, I know we have a little bit of time left, I'll pass it over to David first, and then John for any final wrap up pieces. Think these, Krishna, I think you listed out four great areas that leaders should be kind of focused in on. And I think, I spent a lot of time as an architect, and one thing I always try to be as objective in my thinking and understanding, how are we doing today? How do we measure that? And how are others doing out there? And I think what's also awesome is the research and analysis someone like John has done. These are the things that when you read his article and he's done many others out there, I've been a long subscriber of John's work amongst others, but it's good to get perspectives out there in the industry to help you understand. So you don't necessarily, you don't have to take a vendor, one view of a maturity or what it looks like or what good looks like or what bad looks like. It's good to kind of understand that from a broader focus. The other point I like within this, and this is key, that you can't do all things out of the get go. You have to focus on something. And it's important to understand maybe where your deficiencies are or your pain points. And those could be from security perspective, those could be from a user experience and make sure that you're focused on those first. Number three, AI, non human agents, very important to understand and keep abreast of where things are going, where you are in your own maturity within your organization. Because just because you read these things, you may not there's gonna be a lot of folks that aren't gonna be early AI kind of agentic adopters. Aspects, maybe it's in the work environment or something like that or in their personal, but may not show up on their customer facing aspects of things. But it's important to understand where that's going and that you have the right partners in there to help you along that journey. And I think the fourth one to me is one of the most important ones. I think back a little bit to sort of the notion is you certainly want to have a clear ownership of SIAM, but it also goes, this might be an older one, maybe not everyone knows this one, but a RACI or RASCI. Somebody who is responsible, accountable, informed, things of that nature. That there is clear ownership, but there are people who are consulted about input. There are people who are informed about what's going on. So it doesn't mean just because you don't own it, that you shouldn't have a seat at the table to provide insights, input requirements. But ultimately, you do need one owner, somebody who's going to help put the organization on a path forward to really achieve all those goals. But it does take a whole village to really ultimately do this right and get that executive buy in so that as you're moving down that path, everybody is in lockstep moving forward to a direction. So John, I'm interested in your thoughts on this as well. Yeah, let me double click on four just real briefly. In my research and my interactions in the market, number four is the missing piece more often than not. We've come out of a season in the market, pre pandemic, if you will, where SIAM was like a multi headed monster in terms of ownership. Oh, you want to talk about experience? Go talk to the digital experience officer, chief experience officer. Oh, you want talk about security? Go talk to the CISO. And it was like getting four or five well intentioned people to all go to dinner at the same restaurant, and they just couldn't make up their minds. It slowed down the business. So I'm a big believer in a single man or woman being the business owner for they may not even own the technical part of it. They may have a deputy that runs the technical and the resiliency and cloud and security and all that. But the executive owner for SIAM needs to be able to speak identity at the C suite, at the board level. Maybe they use the term identity less than they might today, but it's what the business needs to get done in the context of identity. That's the most lacking piece I see at financial institutions today. And that's not a, I don't mean to offend out there. Certainly you could push back and reach out later and push back on that. But conversely, I see some really great business owners of SIAM and some banks you'd know by name, and they are making headway with the board and the C suite because they've helped keep the role of identity in the air and in focus for the organization through good times and bad, through new products, through AI. They just can kind of hold that rudder in a way. So four sounds easy, but it's where I see the biggest opportunity for many financial institutions in North America right now. That's great. Thanks for that tag on, John. I appreciate it, David, as well. We're just coming up to time here, so I'll close and I just want to hit back on that again, not all SIAM is created equal. And we're seeing that kind of SIAM maturities becoming more of a strategic capability, not just a technical one, not just to check the box. So it's important to consider that when you're evaluating the future of your organisation, future vendors, or anything of that nature. If you have any questions, John mentioned he's an open book, so is David, so am I, feel free to reach out on LinkedIn. And again, we thank you all for joining us here today. Thanks again to David and John for a great discussion. We'll see you all in the next webinar.