{"id":1453,"date":"2026-05-22T13:58:54","date_gmt":"2026-05-22T11:58:54","guid":{"rendered":"https:\/\/iamfactory.de\/nicht-kategorisiert\/looking-back-at-the-heise-it-security-day-in-mainz\/"},"modified":"2026-05-26T08:39:11","modified_gmt":"2026-05-26T06:39:11","slug":"looking-back-at-the-heise-it-security-day-in-mainz","status":"publish","type":"post","link":"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/","title":{"rendered":"Looking back at the Heise IT Security Day in Mainz"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#04092a&#8221; use_background_color_gradient=&#8221;on&#8221; background_color_gradient_stops=&#8221;rgba(4,9,42,0.71) 0%|rgba(4,9,42,0.7) 100%&#8221; background_color_gradient_overlays_image=&#8221;on&#8221; background_image=&#8221;https:\/\/iamfactory.de\/wp-content\/uploads\/2025\/09\/case-studies_header.webp&#8221; background_position=&#8221;center_left&#8221; custom_padding=&#8221;100px||150px||false|false&#8221; bottom_divider_style=&#8221;asymmetric4&#8243; bottom_divider_color=&#8221;#dfe4e8&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row column_structure=&#8221;2_3,1_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_post_title meta=&#8221;off&#8221; featured_image=&#8221;off&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; title_font=&#8221;Hanken-Grotesk_bold||||||||&#8221; title_text_color=&#8221;#FFFFFF&#8221; title_font_size=&#8221;60px&#8221; title_letter_spacing=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_post_title][\/et_pb_column][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; next_background_color=&#8221;#ffffff&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#dfe4e8&#8243; bottom_divider_style=&#8221;asymmetric4&#8243; bottom_divider_height=&#8221;50px&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; border_width_right=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; text_font_size=&#8221;25px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2><span class=\"ez-toc-section\" id=\"If_you_dont_know_your_assets_you_cant_protect_them\"><\/span>If you don&#8217;t know your assets, you can&#8217;t protect them<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;|23px||||&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>Supply chain security does not end with software. Why Identity and Access Management belongs at the Heise IT Security Day in Mainz. <\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 ez-toc-wrap-left counter-flat ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Inhaltsverzeichnis<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#If_you_dont_know_your_assets_you_cant_protect_them\" >If you don&#8217;t know your assets, you can&#8217;t protect them<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#Nine_lectures_one_common_thread\" >Nine lectures, one common thread<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#Why_IAM_at_a_supply_chain_event\" >Why IAM at a supply chain event?<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#IAM_not_only_belongs_in_the_Group\" >IAM not only belongs in the Group<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#From_recruitment_to_exmatriculation\" >From recruitment to exmatriculation<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#When_things_get_serious_IAM_in_a_security_incident\" >When things get serious: IAM in a security incident<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#Digital_sovereignty_starts_with_identity\" >Digital sovereignty starts with identity<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#The_real_conclusion_of_the_day\" >The real conclusion of the day<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#Demo_request\" >Demo request<\/a><\/li><li class='ez-toc-page-1'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/iamfactory.de\/en\/update-log\/looking-back-at-the-heise-it-security-day-in-mainz\/#Experience_IAM_Factory_in_action\" >Experience IAM Factory in action<\/a><\/li><\/ul><\/nav><\/div>\n\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||3px|||&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">On 6 May, around one hundred IT security managers met on the campus of Mainz University of Applied Sciences to discuss a question that sounds simple, but in practice still overwhelms most organizations. How do you secure a value chain that you only control half of? <\/p>\n<p style=\"text-align: justify;\">The theme of this year&#8217;s Heise IT Security Day was &#8220;Supply Chain Security&#8221;. One day, nine presentations, speakers from banks, research, pentesting, product security and identity management. Anyone expecting an event full of tool demos and product pitches was disappointed, in the best sense of the word. The common thread of the day was not a technical one, but an organizational one. Anyone who touches a tool must first know what they actually want to protect.    <\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"Nine_lectures_one_common_thread\"><\/span>Nine lectures, one common thread<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">The range of topics made the day special. In the morning, the focus was on cybersecurity in the financial sector, viewed from the perspective of both attacker and defender, on auditable system hardening in the supply chain and on the question of what cyber resilience can learn from the error culture of aviation. This was followed in the afternoon by research findings on external collaborations during cyber crises, an in-depth look at FIDO authentication as protection against software supply chain attacks and the role of CERT@VDE in the Cyber Resilience Act. The final highlight was an incident responder with perhaps the most honest presentation title of the day: &#8220;hope is not a strategy&#8221;. Relentless, entertaining, with a clear appeal: Clean up. Now.     <\/p>\n<p style=\"text-align: justify;\">As different as the perspectives were, the pattern repeated itself. If you don&#8217;t know your infrastructure, you can&#8217;t protect it. If you haven&#8217;t defined processes, even the best tool won&#8217;t help you.  <\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"Why_IAM_at_a_supply_chain_event\"><\/span>Why IAM at a supply chain event?<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_3,2_3&#8243; make_equal=&#8221;on&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;1_3&#8243; module_class=&#8221;content-vertical-align-center&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;|10px||10px|false|false&#8221; border_radii=&#8221;off||20px||20px&#8221; box_shadow_style=&#8221;preset1&#8243; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/iamfactory.de\/wp-content\/uploads\/2026\/05\/sarah-Ringelspacher_Heise-IT-Tag.jpeg&#8221; alt=&#8221;ISB of IAM Factory AG gave a presentation at the Heise IT Security Day in Mainz&#8221; title_text=&#8221;sarah-Ringelspacher_Heise-IT-Tag&#8221; _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; border_radii=&#8221;off||20px||20px&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;][\/et_pb_image][\/et_pb_column][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">Between these contributions was a presentation that at first glance did not fit into the scheme. Our colleague Sarah Ringelspacher, Information Security Officer at IAM Factory AG, spoke about Identity and Access Management, from the person to the authorization. <\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">However, a university&#8217;s IT infrastructure is often very complex: students, teachers, administrative staff and external partners need access to a variety of systems &#8211; from campus management and learning platforms to email services and cloud services. Managing these accesses and authorizations is a logistical and security challenge that can hardly be mastered without professional identity and access management. This is especially true under the conditions under which German universities are trying to recruit and retain experienced staff.  <\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; next_background_color=&#8221;#ffffff&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#dfe4e8&#8243; use_background_color_gradient=&#8221;on&#8221; background_color_gradient_direction=&#8221;91deg&#8221; background_color_gradient_stops=&#8221;rgba(4,9,42,0.78) 48%|rgba(4,9,42,0.39) 100%&#8221; background_color_gradient_overlays_image=&#8221;on&#8221; background_image=&#8221;https:\/\/iamfactory.de\/wp-content\/uploads\/2025\/09\/Demoanfrage.webp&#8221; background_position=&#8221;center_right&#8221; top_divider_style=&#8221;asymmetric4&#8243; top_divider_color=&#8221;#ffffff&#8221; top_divider_height=&#8221;50px&#8221; top_divider_flip=&#8221;vertical&#8221; top_divider_height_tablet=&#8221;50px&#8221; top_divider_height_phone=&#8221;50px&#8221; top_divider_height_last_edited=&#8221;on|phone&#8221; bottom_divider_style=&#8221;asymmetric4&#8243; bottom_divider_height=&#8221;50px&#8221; border_color_bottom=&#8221;#0433d1&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;50px||50px||false|false&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk_bold||||||||&#8221; text_text_color=&#8221;#FFFFFF&#8221; text_font_size=&#8221;35px&#8221; text_letter_spacing=&#8221;1px&#8221; header_text_align=&#8221;center&#8221; text_orientation=&#8221;center&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Digital sovereignty at the IAM Factory<\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;@ET-DC@eyJkeW5hbWljIjp0cnVlLCJjb250ZW50IjoicG9zdF9saW5rX3VybF9wYWdlIiwic2V0dGluZ3MiOnsicG9zdF9pZCI6Ijc5IiwiZW5hYmxlX2h0bWwiOiJvZmYifX0=@&#8221; button_text=&#8221;IAM as a service&#8221; button_alignment=&#8221;center&#8221; _builder_version=&#8221;4.27.4&#8243; _dynamic_attributes=&#8221;button_url&#8221; _module_preset=&#8221;default&#8221; custom_button=&#8221;on&#8221; button_text_size=&#8221;16px&#8221; button_text_color=&#8221;#FFFFFF&#8221; button_bg_color=&#8221;#0433d1&#8243; button_bg_use_color_gradient=&#8221;on&#8221; button_bg_color_gradient_direction=&#8221;135deg&#8221; button_bg_color_gradient_stops=&#8221;#3fced0 0%|#0433d1 0%&#8221; button_border_width=&#8221;0px&#8221; button_border_radius=&#8221;10px&#8221; button_font=&#8221;|700||on|||||&#8221; button_use_icon=&#8221;off&#8221; custom_padding=&#8221;10px|20px|10px|20px|true|true&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; button_bg_color__hover_enabled=&#8221;on|hover&#8221; button_bg_color_gradient_stops__hover=&#8221;#0433d1 100%|#3fced0 100%&#8221; button_bg_use_color_gradient__hover=&#8221;on&#8221; button_letter_spacing__hover_enabled=&#8221;off|hover&#8221; button_letter_spacing__hover=&#8221;1px&#8221; button_bg_color__hover=&#8221;#0433d1&#8243;][\/et_pb_button][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; custom_padding=&#8221;||0px|||&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"IAM_not_only_belongs_in_the_Group\"><\/span>IAM not only belongs in the Group<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">Sarah showed where Identity and Access Management is actually used today and where it is not. Banks and corporations have been using IAM for years, driven by regulatory requirements and sheer complexity. Universities, administrations and non-profit organizations, on the other hand, fall through the cracks, even though the challenges there are no smaller. Three things come together: lean personnel structures with few dedicated IT staff, tight budgets with long approval processes and, for a long time, no regulatory pressure that would have forced them to act.   <\/p>\n<p style=\"text-align: justify;\">This is changing faster than many of these organizations can react.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"From_recruitment_to_exmatriculation\"><\/span>From recruitment to exmatriculation<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">Sarah used the university example to illustrate just how complex an identity lifecycle really is. The basic principle sounds simple: joiners, movers, leavers. Someone joins the organization, gets access. Someone changes roles, the authorizations have to grow with them. Someone leaves, access is blocked. Three situations that sound manageable as three separate processes.     <\/p>\n<p style=\"text-align: justify;\">But a university doesn&#8217;t just have employees. Students go through enrolment, semester changes, course changes and, at some point, exmatriculation, with each of these steps changing access rights. There are also external service providers with their own onboarding and offboarding, special representatives such as senate members with temporary special roles and research partners from other institutions who are connected via federation. If you manage this manually, you lose the overview. If you lose the overview, you have forgotten accesses, which is one of the most common attack vectors for attackers.    <\/p>\n<p style=\"text-align: justify;\">Sarah described the standard IAM process in three building blocks: source systems such as personnel administration or campus management provide the data. A process engine controls approvals, rules and authorizations. The final step is automated provisioning to the target systems, i.e. directory services, specialist applications and cloud services. What runs through the entire process: clearly defined statuses, traceable transitions, auditable logs.   <\/p>\n<p style=\"text-align: justify;\">Or, as one slide put it: IAM is the &#8220;logistics backbone&#8221;, it regulates who gets what access and when.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; next_background_color=&#8221;#ffffff&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#dfe4e8&#8243; use_background_color_gradient=&#8221;on&#8221; background_color_gradient_direction=&#8221;91deg&#8221; background_color_gradient_stops=&#8221;rgba(4,9,42,0.78) 48%|rgba(4,9,42,0.39) 100%&#8221; background_color_gradient_overlays_image=&#8221;on&#8221; background_image=&#8221;https:\/\/iamfactory.de\/wp-content\/uploads\/2025\/09\/Demoanfrage.webp&#8221; background_position=&#8221;center_right&#8221; top_divider_style=&#8221;asymmetric4&#8243; top_divider_color=&#8221;#ffffff&#8221; top_divider_height=&#8221;50px&#8221; top_divider_flip=&#8221;vertical&#8221; top_divider_height_tablet=&#8221;50px&#8221; top_divider_height_phone=&#8221;50px&#8221; top_divider_height_last_edited=&#8221;on|phone&#8221; bottom_divider_style=&#8221;asymmetric4&#8243; bottom_divider_height=&#8221;50px&#8221; border_color_bottom=&#8221;#0433d1&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;50px||50px||false|false&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk_bold||||||||&#8221; text_text_color=&#8221;#FFFFFF&#8221; text_font_size=&#8221;35px&#8221; text_letter_spacing=&#8221;1px&#8221; header_text_align=&#8221;center&#8221; text_orientation=&#8221;center&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Digital sovereignty at the IAM Factory<\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;@ET-DC@eyJkeW5hbWljIjp0cnVlLCJjb250ZW50IjoicG9zdF9saW5rX3VybF9wYWdlIiwic2V0dGluZ3MiOnsicG9zdF9pZCI6Ijc5IiwiZW5hYmxlX2h0bWwiOiJvZmYifX0=@&#8221; button_text=&#8221;IAM as a service&#8221; button_alignment=&#8221;center&#8221; _builder_version=&#8221;4.27.4&#8243; _dynamic_attributes=&#8221;button_url&#8221; _module_preset=&#8221;default&#8221; custom_button=&#8221;on&#8221; button_text_size=&#8221;16px&#8221; button_text_color=&#8221;#FFFFFF&#8221; button_bg_color=&#8221;#0433d1&#8243; button_bg_use_color_gradient=&#8221;on&#8221; button_bg_color_gradient_direction=&#8221;135deg&#8221; button_bg_color_gradient_stops=&#8221;#3fced0 0%|#0433d1 0%&#8221; button_border_width=&#8221;0px&#8221; button_border_radius=&#8221;10px&#8221; button_font=&#8221;|700||on|||||&#8221; button_use_icon=&#8221;off&#8221; custom_padding=&#8221;10px|20px|10px|20px|true|true&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; button_bg_color__hover_enabled=&#8221;on|hover&#8221; button_bg_color_gradient_stops__hover=&#8221;#0433d1 100%|#3fced0 100%&#8221; button_bg_use_color_gradient__hover=&#8221;on&#8221; button_letter_spacing__hover_enabled=&#8221;off|hover&#8221; button_letter_spacing__hover=&#8221;1px&#8221; button_bg_color__hover=&#8221;#0433d1&#8243;][\/et_pb_button][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"When_things_get_serious_IAM_in_a_security_incident\"><\/span>When things get serious: IAM in a security incident<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">Perhaps the most exciting part of the presentation was the security incident use case. Sarah is currently supporting the reconstruction of a university IT after a security incident, and you can see that in the slides. What happens when the directory service is corrupted and thousands of accounts have to be reinstalled? When external incident responders need short-term access, but this needs to be controlled and time-limited? When compromised applications are replaced by new ones and the existing authorization concepts still need to remain transferable?    <\/p>\n<p style=\"text-align: justify;\">Without IAM, this means Excel lists, unclear responsibilities and the constant question of whether all legacy issues have really been resolved. With IAM, re-provisioning can be largely automated. Role models can be adapted to new target systems instead of having to be rebuilt from scratch. There are regulated workflows with a clear expiry date for external helpers.   <\/p>\n<p style=\"text-align: justify;\">Anyone who only thinks about the software supply chain when it comes to supply chain security is overlooking this point. In an emergency, it is the identity infrastructure that determines how quickly an organization can get back to work. <\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"Digital_sovereignty_starts_with_identity\"><\/span>Digital sovereignty starts with identity<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">Finally, Sarah tackled the topic of digital sovereignty. Her thesis: sovereignty means remaining capable of acting independently. If processes are clearly defined and documented, the organization is no longer dependent on the implicit know-how of individuals. Open interfaces and standardization make it easier to change providers because the organization does not have to lock itself into a proprietary system. The operating location remains freely selectable, whether on-premises, in the cloud or hybrid. And there are now mature European open source alternatives that can be used productively.     <\/p>\n<p style=\"text-align: justify;\">The last point in particular strikes a nerve with public sector organizations. We regularly experience in projects that the question &#8220;What dependencies can we afford?&#8221; is only asked when the change would already be painfully expensive. <\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;Hanken-Grotesk||||||||&#8221; text_font_size=&#8221;23px&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_font_size=&#8221;30px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_font_size=&#8221;25px&#8221; hover_enabled=&#8221;0&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify;\"><span class=\"ez-toc-section\" id=\"The_real_conclusion_of_the_day\"><\/span>The real conclusion of the day<o:p><\/o:p><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p style=\"text-align: justify;\">If nine presentations from completely different perspectives allow one common conclusion, then it is this: Only those who know their infrastructure, their supply chains and their assets can protect them. This applies to the software supply chain as well as to identities and authorizations, for banks as well as for universities and KRITIS operators. <\/p>\n<p style=\"text-align: justify;\">The technology exists and the regulatory requirements have been formulated. What is missing in many organizations is the step beforehand. Take a look, tidy up, define processes. Only then automate.   <\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.6&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;||0px|||&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>If you have any questions after the presentation or would like to know what an IAM project could look like in your own organization, please <a href=\"https:\/\/iamfactory.de\/en\/software-as-a-service\/#demoanfrage\" target=\"_blank\" rel=\"noopener\">contact us via the contact form<\/a> or call us directly on +49 6131 4811 100.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; next_background_color=&#8221;#04092a&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#dfe4e8&#8243; use_background_color_gradient=&#8221;on&#8221; background_color_gradient_direction=&#8221;91deg&#8221; background_color_gradient_stops=&#8221;rgba(4,9,42,0.78) 48%|rgba(4,9,42,0.39) 100%&#8221; background_color_gradient_overlays_image=&#8221;on&#8221; background_image=&#8221;https:\/\/iamfactory.de\/wp-content\/uploads\/2025\/09\/Demoanfrage.webp&#8221; background_position=&#8221;center_right&#8221; custom_margin=&#8221;||-100px||false|false&#8221; custom_padding=&#8221;||80px||false|false&#8221; top_divider_style=&#8221;asymmetric4&#8243; top_divider_color=&#8221;#FFFFFF&#8221; top_divider_height=&#8221;50px&#8221; top_divider_flip=&#8221;vertical&#8221; bottom_divider_style=&#8221;asymmetric4&#8243; background_last_edited=&#8221;off|phone&#8221; background_horizontal_offset_phone=&#8221;0%&#8221; border_color_bottom=&#8221;#0433d1&#8243; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;|auto|-38px|auto||&#8221; custom_padding=&#8221;80px||33px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; header_2_font=&#8221;Hanken-Grotesk_bold|700||on|||||&#8221; header_2_text_align=&#8221;left&#8221; header_2_text_color=&#8221;#FFFFFF&#8221; header_2_font_size=&#8221;35px&#8221; header_2_letter_spacing=&#8221;2px&#8221; header_3_font=&#8221;Hanken-Grotesk_thin||||||||&#8221; header_3_text_align=&#8221;left&#8221; header_3_text_color=&#8221;#FFFFFF&#8221; header_3_font_size=&#8221;30px&#8221; custom_margin=&#8221;||30px||false|false&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Demo_request\"><\/span><b>Demo request<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Experience_IAM_Factory_in_action\"><\/span>Experience IAM Factory in action<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; text_text_color=&#8221;#FFFFFF&#8221; custom_margin=&#8221;||45px||false|false&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>In a personal presentation, we will demonstrate to you<br \/>what our modular Software as a Service solution looks like in practice.<\/p>\n<p><span data-contrast=\"auto\" lang=\"DE-DE\" class=\"TextRun Highlight SCXW129060329 BCX8\"><span class=\"NormalTextRun SCXW129060329 BCX8\">Experience modern Identity and Access Management in action and have your questions answered.<\/span><\/span><\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/iamfactory.de\/en\/software-as-a-service\/#demo-request&#8221; button_text=&#8221;Make an appointment&#8221; _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; custom_button=&#8221;on&#8221; button_text_size=&#8221;16px&#8221; button_text_color=&#8221;#FFFFFF&#8221; button_bg_use_color_gradient=&#8221;on&#8221; button_bg_color_gradient_direction=&#8221;135deg&#8221; button_bg_color_gradient_stops=&#8221;#3fced0 0%|#0433d1 0%&#8221; button_border_width=&#8221;0px&#8221; button_border_radius=&#8221;10px&#8221; button_font=&#8221;|700||on|||||&#8221; button_use_icon=&#8221;off&#8221; custom_padding=&#8221;10px|20px|10px|20px|true|true&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; button_bg_color__hover_enabled=&#8221;on|hover&#8221; button_bg_color_gradient_stops__hover=&#8221;#0433d1 100%|#3fced0 100%&#8221; button_bg_use_color_gradient__hover=&#8221;on&#8221; button_letter_spacing__hover_enabled=&#8221;off|hover&#8221; button_letter_spacing__hover=&#8221;1px&#8221;][\/et_pb_button][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Supply chain security does not end with software. Why Identity and Access Management belongs at the Heise IT Security Day in Mainz <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"5","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1,13],"tags":[],"class_list":["post-1453","post","type-post","status-publish","format-standard","hentry","category-nicht-kategorisiert","category-update-log"],"_links":{"self":[{"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/posts\/1453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/comments?post=1453"}],"version-history":[{"count":2,"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/posts\/1453\/revisions"}],"predecessor-version":[{"id":1455,"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/posts\/1453\/revisions\/1455"}],"wp:attachment":[{"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/media?parent=1453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/categories?post=1453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/iamfactory.de\/en\/wp-json\/wp\/v2\/tags?post=1453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}