<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Maryeme BOUSSOUIS, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/maryeme-boussouis/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/maryeme-boussouis/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 18 Sep 2024 08:08:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Maryeme BOUSSOUIS, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/maryeme-boussouis/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fighting fraud: a new challenge for digital identity?</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/09/fighting-fraud-a-new-challenge-for-digital-identity/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/09/fighting-fraud-a-new-challenge-for-digital-identity/#respond</comments>
		
		<dc:creator><![CDATA[Maryeme BOUSSOUIS]]></dc:creator>
		<pubDate>Wed, 18 Sep 2024 08:08:23 +0000</pubDate>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[fraud fighting]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management strategy & governance]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=23932</guid>

					<description><![CDATA[<p>The banking sector has rapidly modernized, and online banking has become a matter of course for both banks and their customers. These players are increasingly reliant on the Internet, with all the advantages that implies, but also the risks. At...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/09/fighting-fraud-a-new-challenge-for-digital-identity/">Fighting fraud: a new challenge for digital identity?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">The banking sector has rapidly modernized, and online banking has become a matter of course for both banks and their customers. These players are increasingly reliant on the Internet, with all the advantages that implies, but also the risks.</p>
<p style="text-align: justify;">At the same time, fraud has grown in scale and complexity. According to the Banque de France, payment fraud will represent <strong>a loss of 1.2 billion euros by 2022</strong>, a considerable sum which is unlikely to diminish as fraudulent transactions continue to increase. Around 70% of these fraudulent transactions come from online banking.</p>
<p style="text-align: justify;">The fight against fraud is therefore one of the most important concerns for online banking, but other sectors are also beginning to address the issue.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Identity fraud, business fraud</h2>
<p style="text-align: justify;">The term fraud is part of everyday language and can have a wide variety of definitions. It&#8217;s possible to “defraud” a metro ticket, an insurance policy, or a loyalty account with a major retailer.</p>
<p style="text-align: justify;">When it comes to <strong>computer fraud</strong>, particularly banking fraud, <strong>we distinguish between identity fraud and business fraud. </strong></p>
<p style="text-align: justify;">The former involves manipulation of the <strong>issuer&#8217;s identity data</strong>, the context in which he/she accesses the service, or information relating to his/her authentication and authorization. This can be detected by analyzing the user&#8217;s authentication behavior, the machine he is using, the IP address from which he is connecting, and so on.</p>
<p style="text-align: justify;">The second involves manipulating <strong>data relating to the transaction</strong> itself, the banking profile of the sender and receiver, and the context in which the transaction was carried out. Indicators of business fraud could be, for example, a receiving IBAN from an unusual country, a large transaction amount, etc.</p>
<p style="text-align: justify;">The two types of fraud and their detection rely on different signals, but these two protection mechanisms can and must exchange and <strong>feed off each other</strong> to provide additional context and enable a more holistic analysis of risk.</p>
<p style="text-align: justify;">This need for synchronization has led to a recent <strong>organizational rapprochement</strong> between business fraud and IAM teams.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">What risks are covered by identity fraud detection?</h2>
<p style="text-align: justify;">Identity fraud conceals many different uses. Detecting it therefore covers a wide range of risks that are difficult to apprehend today. Here is a non-exhaustive list of techniques used by attackers that could be detected by an anti-fraud tool:</p>
<ul style="text-align: justify;">
<li><strong>SIM swapping</strong>: SIM swapping involves convincing the victim&#8217;s telephone provider to send a new SIM card to the attacker, who can then validate double authentication requests via OTP by pretending to be the victim.</li>
<li><strong>MFA fatigue</strong>: MFA fatigue involves sending a large number of MFA validation notifications, to the point where the victim ends up accepting the request and inadvertently authorizing access to one of their accounts.</li>
<li><strong>Social engineering</strong>: social engineering is used in attacks targeting an individual, where the attacker gathers information about them and their bank account, then exploits it to extract money from them. An increasingly common example is bank advisor fraud, in which an attacker poses as the victim&#8217;s advisor and urges him or her to make a bank transfer, often under the pretext of a risk of&#8230; fraud.</li>
<li><strong>Bots</strong>: attack automation opens up new possibilities for attackers, who can target a large number of accounts in a single campaign. By emulating devices or launching massive phishing campaigns, it is becoming increasingly easy to recover personal information and passwords.</li>
</ul>
<figure id="attachment_23913" aria-describedby="caption-attachment-23913" style="width: 559px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" class="size-full wp-image-23913" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image1-ENG.png" alt="les identités peuvent être attaquées par social engineering, des attaques automatiques, des attaques qui joue sur la fatigue face aux nombreux MFA demandés, et l'impersonification d'une personne." width="559" height="326" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image1-ENG.png 559w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image1-ENG-328x191.png 328w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image1-ENG-67x39.png 67w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image1-ENG-120x70.png 120w" sizes="(max-width: 559px) 100vw, 559px" /><figcaption id="caption-attachment-23913" class="wp-caption-text"><em>Figure 1: Identities face many risks</em></figcaption></figure>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Banks in the lead, but joined by new players</h2>
<p style="text-align: justify;">Unsurprisingly, the banking sector has a head start on these issues. Firstly, because the impact of fraud is very real, and <strong>the bank is a prime target</strong>. Secondly, because users are accustomed to, and even reassured by, significant security processes at the expense of their user experience. Finally, because the massive shift to online banking has raised questions that other sectors didn&#8217;t have to ask themselves immediately.</p>
<p style="text-align: justify;">Today, fraud detection for an online bank focuses on <strong>three key stages of the user journey</strong>:</p>
<ul style="text-align: justify;">
<li>Enrolling a new device.</li>
<li>Validating a payment.</li>
<li>Performing sensitive actions on the account, such as adding a beneficiary for transfers.</li>
</ul>
<p style="text-align: justify;">While the banking sector is undoubtedly the most affected and the most protected, other sectors are beginning to address the issue of fraud detection. <strong>Retail</strong>, <strong>e-commerce,</strong> and <strong>luxury goods</strong>, for example, are all in the crosshairs of attackers. This is forcing these sectors to devise new processes and invest in the fight against fraud, in turn driving the evolution of solutions and practices to limit the impact on business.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">New technological advances: protocols and algorithms</h2>
<p style="text-align: justify;">The pressure of attacks explains much of the interest in fraud detection solutions. These have developed rapidly, embedding more and more functions and demonstrating a <strong>growing capacity to combat the complex attacks</strong> that are on the rise.</p>
<p style="text-align: justify;">Recent technological advances in fraud detection are manifold, but two main mechanisms have made these solutions more powerful: the ability to <strong>exchange information</strong> between detection bricks, and the <strong>precision of risk estimation algorithms</strong>.</p>
<p style="text-align: justify;">The first mechanism is a product of the current trend towards <strong>standardization of detection protocols and signals</strong>, enabling the various IS bricks to pool the information gathered and the appropriate reactions. The <a href="https://sharedsignals.guide/"><em>Shared Signals</em></a> working group (Okta, Cisco, Disney, OpenID Foundation, etc.), for example, has produced a framework used in two protocols: <em>Continuous Access Evaluation Protocol</em> (CAEP) and <em>Risk Incident Sharing and Coordination protocol</em> (RISC).</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The second mechanism &#8211; the precision of algorithms &#8211; is based on the <strong>growing number of criteria that can be exploited</strong>. A few years ago, a detection engine relied on IP analysis, geolocation and a few identity attributes. Today, the criteria are multiplied, including the <strong>user&#8217;s own behavior</strong> (mouse movements, typing speed), analysis of the<strong> devices used</strong> (model, OS, browser), <strong>account history</strong>, <strong>common user paths</strong>, as well as a panoply of weak signals from other applications or IS bricks. This multiplication of signals entering the algorithms enables a much more refined analysis of each transaction, and an ever more pertinent estimation of risk.</p>
<figure id="attachment_23915" aria-describedby="caption-attachment-23915" style="width: 605px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-23915" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image2-ENG.png" alt="de la détection des différents risque, puis l'analyse et jusqu'à la réponse, tout peut être automatisé" width="605" height="348" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image2-ENG.png 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image2-ENG-332x191.png 332w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image2-ENG-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image2-ENG-120x70.png 120w" sizes="(max-width: 605px) 100vw, 605px" /><figcaption id="caption-attachment-23915" class="wp-caption-text"><em>Figure 2: From telemetry to automatic response</em></figcaption></figure>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">AI and orchestration in the fight against fraud</h2>
<p style="text-align: justify;">Increasing the number of criteria helps to improve algorithms, but to get the most out of this information it is essential to take advantage of the capabilities of <strong>Machine Learning</strong> and artificial intelligence. Each criterion becomes a dimension enabling AI to <strong>dynamically</strong> learn user behaviours (such as common paths, mouse click locations or typing speed) and what constitutes a normal, non-risky access context, in order to better detect anything that deviates from it.</p>
<p style="text-align: justify;">Despite AI&#8217;s ability to produce a decision from a very large number of parameters, it remains a victim of the setbacks of all decision algorithms: false positives. And with the interest of new sectors, which need to <strong>balance security and user experience to limit negative impacts on business</strong>, the management of false positives is an issue in its own right for software publishers. Today, detection models can be adjusted in several ways: by training them recurrently, to adapt them to new use cases; by playing with the weights of the criteria, according to the customer&#8217;s context; and by going back over the decisions taken by the algorithm in order to report false positives.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Beyond these adjustments, fraud detection solutions offer great flexibility in terms of <strong>orchestration</strong>, i.e. the reaction to be implemented in response to the algorithm&#8217;s recommendations. In this way, it is possible to limit the impact on users, by using <strong>invisible challenges</strong> for low-risk transactions, and by limiting constraining requests such as MFA or deferred manual processing to high-risk transactions. Orchestration also makes it possible to <strong>implement the tool progressively</strong>: reactions can be limited to raising alerts transmitted to a SIEM tool, for example, to refine the algorithm, then moving on to effective, real-time blocking.</p>
<figure id="attachment_23917" aria-describedby="caption-attachment-23917" style="width: 605px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-23917" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image3-ENG.png" alt="" width="605" height="359" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image3-ENG.png 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image3-ENG-322x191.png 322w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image3-ENG-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/09/Image3-ENG-120x70.png 120w" sizes="(max-width: 605px) 100vw, 605px" /><figcaption id="caption-attachment-23917" class="wp-caption-text"><em>Figure 3: two user paths, two orchestrations</em></figcaption></figure>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Conclusion</h2>
<p style="text-align: justify;">The fight against fraud is a subject that concerns many sectors. While the banking sector is ahead of the game, with e-commerce and luxury goods following suit, any organization can be targeted by fraud. This implies <strong>a wide range of use cases and issues</strong> to which fraud detection solutions can often, but not always, respond.</p>
<p style="text-align: justify;">The sector of activity, the context, the recurrence and type of attacks, the impact and associated risk, as well as the resources that can be deployed &#8211; all these dimensions need to be taken into account to <strong>contextualize countermeasure solutions</strong>. These solutions may be expensive or unsuitable, despite the innovative mechanisms put in place, and other remediation mechanisms may need to be considered depending on the context.</p>
<p style="text-align: justify;">This is the case with anti-bot solutions, for example, or risk-based authentication mechanisms, or simply the redesign of certain business processes to make them intrinsically more resilient to fraud. These remedies can accompany a fraud detection solution or be sufficient to counter the cases of fraud observed in the context studied.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/09/fighting-fraud-a-new-challenge-for-digital-identity/">Fighting fraud: a new challenge for digital identity?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/09/fighting-fraud-a-new-challenge-for-digital-identity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The European identity wallet, the digital identity of the state soon to be in our pockets</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/06/the-european-identity-wallet-the-digital-identity-of-the-state-soon-to-be-in-our-pockets/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/06/the-european-identity-wallet-the-digital-identity-of-the-state-soon-to-be-in-our-pockets/#respond</comments>
		
		<dc:creator><![CDATA[Maryeme BOUSSOUIS]]></dc:creator>
		<pubDate>Tue, 25 Jun 2024 07:34:53 +0000</pubDate>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[DIgital Identity]]></category>
		<category><![CDATA[European identity wallet]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity & access management]]></category>
		<category><![CDATA[identity wallet]]></category>
		<category><![CDATA[regal identity]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=23327</guid>

					<description><![CDATA[<p>The need for a regal digital identity stems from the need to guarantee the reliability of online exchanges and transactions, in the face of rising fraud in a context of increasing dematerialization. The European Union responded by introducing the eIDAS...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/06/the-european-identity-wallet-the-digital-identity-of-the-state-soon-to-be-in-our-pockets/">The European identity wallet, the digital identity of the state soon to be in our pockets</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">The <strong>need</strong> for a regal digital identity stems from the <strong>need</strong> to guarantee the reliability of online exchanges and transactions, in the face of rising fraud in a context of increasing <strong>dematerialization</strong>. The European Union responded by introducing the eIDAS regulation in 2014, aimed at promoting the <strong>interoperability</strong> of electronic identification and authentication systems within the EU.</p>
<p style="text-align: justify;">Regal digital identity brings together all the <strong>information</strong> essential to formally <strong>authenticate</strong> an individual or organization in the digital world. This includes personal <strong>identification data</strong>, electronic <strong>certificates</strong> and <strong>biometric information</strong>. This identity is crucial for securing electronic transactions, <strong>facilitating</strong> access to online public services and <strong>protecting</strong> citizens&#8217; rights and privacy.</p>
<p style="text-align: justify;">In France, a program was launched in 2018 to create a high-<strong>guarantee</strong> digital regal identity. At the same time, France is committed to the introduction of a <strong>smart ID card with a chip</strong>, which will form the basis of this electronic identification. This authentication mode will be integrated into FranceConnect+ created at the end of 2021, an online <strong>identification</strong> and <strong>authentication</strong> service of minimum substantial level.</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter wp-image-23329 " src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture1ENG.png" alt="Evolution of regalian degital identity in Europe" width="721" height="424" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture1ENG.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture1ENG-325x191.png 325w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture1ENG-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture1ENG-120x70.png 120w" sizes="auto, (max-width: 721px) 100vw, 721px" /></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>Examples of use cases depending on the target :</strong></p>
<h2 style="text-align: justify;"><br />Companies</h2>
<p style="text-align: justify;">A potential B2E use case could be re-registration and access recovery. The use of regalian digital identity becomes particularly relevant in companies where employee authentication relies exclusively on FIDO passkeys linked to a device, often their phone. If this device is lost, the employee is unable to authenticate. With regalian digital identity, access recovery is simplified. Employees can use their digital identity to restore their access, then get a new phone and re-enroll their FIDO passkeys. In this way, the re-registration and access recovery process is greatly facilitated, guaranteeing enhanced service continuity.</p>
<p style="text-align: justify;">On the CIAM side, banks could use regalian digital identity to verify the identity of customers when opening online accounts or carrying out sensitive transactions, and thus improve the security level of their service and their KYC (know Your Client) process. Currently in France, customers can use FranceConnect to authenticate themselves with banks such as BNP Paribas when opening online accounts, guaranteeing secure and simplified identity verification. Similarly, e-commerce sites could use the regalian digital identity to enable users to authenticate themselves securely when purchasing products, further enhancing security and reducing the risk of fraud.</p>
<p style="text-align: justify;">In the context of the extended enterprise (a form of organization enabling collaboration between a company, its subsidiaries and its partners), the secure enrolment of partners to access the company&#8217;s information systems (IS) is crucial. The challenge is to increase the level of confidence in enrolment, while at the same time making it easier. <br />The use of the European Identity Wallet or other identity wallet could significantly simplify and secure this process. Partner employees could prove their identity to the company they wish to collaborate with, using their identity wallet. Here&#8217;s how it could work:</p>
<p style="text-align: justify;">First of all, for the <strong>initial registration</strong> employees of partner organizations use their identity wallets to register with the main company&#8217;s system. Identity is then verified using electronic certificates and other secure information.<br />Once registration has been validated, these employees can <strong>access</strong> the main company&#8217;s <strong>information systems</strong>. The identity wallet enables secure authentication in line with corporate security standards. Or secure enrolment in the company&#8217;s local authentication systems.<br />The identity wallet can also be used to <strong>manage and modulate access rights</strong> according to the specific roles and needs of partner employees, reducing the risk of over-provisioning and increasing security.</p>
<p style="text-align: justify;"><strong>If identity information changes</strong> (for example, if an employee changes position or responsibility), access can be updated seamlessly via the identity portfolio, without the need for cumbersome administrative processes.<br />Imagine a construction company working with various subcontractors on different projects. Subcontractors&#8217; employees can use their identity portfolio to authenticate themselves and access project plans and documents hosted on the main company&#8217;s IS. This ensures that only authorized and verified employees have access to sensitive information, and that their access can be quickly modified or revoked if necessary.</p>
<h2 style="text-align: justify;"><br />Citizens</h2>
<p style="text-align: justify;">Regalian digital identities offer citizens numerous advantages, notably by simplifying access to various online services and reinforcing the security of digital transactions. In France, for example, insured persons can use their digital identity via the Ameli service to access their personal space. This enables them to consult their reimbursements, book appointments with healthcare professionals and manage other aspects of their medical cover securely online.</p>
<p style="text-align: justify;">Similarly, for tax purposes, French citizens can use their régalienne digital identity via impots.gouv.fr. This feature facilitates online tax declarations, enabling users to fill in their returns, consult their tax notices and track their payments and refunds simply and securely.</p>
<p style="text-align: justify;">Beyond France, other European countries are also implementing digital identity solutions to improve access to public services. Students, for example, will benefit greatly from the regalian digital identity for their administrative procedures. They will be able to use it to enroll in universities, access their transcripts, and manage their student accounts in a secure and simplified way. What&#8217;s more, international students will also be able to use this identity to validate their residency status and access various public and academic services without the hassle of paper procedures.</p>
<p style="text-align: justify;">In Spain, regalian digital identity enables citizens to electronically sign official documents via the FirmaDigital.gob.es service. This solution is used for tasks such as signing rental contracts, submitting administrative documents, and other procedures requiring a legal signature. This makes administrative processes more efficient and secure, eliminating the need for physical signatures and reducing the risk of fraud.</p>
<h2 style="text-align: justify;"><br />The European Identity Wallet (EUDI)</h2>
<p style="text-align: justify;">The European Identity Wallet (EUDI Wallet) is a major initiative by the European Commission to provide EU citizens with a secure, interoperable way of managing their digital identity across borders. Designed to offer a convenient and secure solution, EUDI Wallet will enable citizens to store and share their electronic credentials seamlessly, while preserving their privacy and complying with the EU&#8217;s strict data protection standards.<br />This concept emerges against the backdrop of the increasing digitization of European society and the need to reinforce trust in online transactions. With the diversity of electronic identification systems used across the EU, EUDI Wallet aims to harmonize these systems and facilitate access to cross-border digital services, such as public services, commercial transactions and online interactions with businesses.<br />The EUDI Wallet will therefore function as a secure digital wallet where citizens can store their identification information such as electronic certificates, biometric data and identity documents. They will be able to use this wallet to authenticate themselves online and access a range of digital services across the European Union.<br />With the EUDI Wallet, citizens will be able to easily access their healthcare data, such as patient summaries and electronic prescriptions, anywhere in the EU, promoting better continuity of care. In addition, Wallet will enable diplomas and professional qualifications to be securely managed and verified, simplifying the recognition of qualifications and promoting worker mobility. Finally, it will facilitate online transactions by ensuring strong, harmonized authentication, thereby boosting confidence in cross-border e-commerce.</p>
<p style="text-align: justify;">In order to carry out these use cases, the European Commission has defined two main scenarios describing very basically the portfolio&#8217;s use flows; </p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter  wp-image-23331" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture2ENG.png" alt="ios defined by the European Commission for the portfolio's use flows" width="708" height="347" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture2ENG.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture2ENG-389x191.png 389w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/06/Picture2ENG-71x35.png 71w" sizes="auto, (max-width: 708px) 100vw, 708px" /><br />To date, the countries of the European Union have agreed on the content to be included in the European wallet, and have agreed on a global standard for the project, with a target implementation date of 2026. What remains to be done is to finalize the standard, draw up precise technical specifications for it, and develop the technical solutions to be implemented in each European country to ensure compatibility with the established standard.</p>
<p> </p>
<h2 style="text-align: justify;">Conclusion</h2>
<p style="text-align: justify;">The introduction of the European Identity Wallet (EUDI Wallet) represents a crucial step towards a more integrated and digitized digital Europe, offering numerous benefits to citizens and businesses across the European Union. In France, the adoption of EUDI Wallet will depend on several key factors. Firstly, the establishment of a robust regulatory framework that complies with data protection standards such as the RGPD will be essential to ensure user confidence and the security of their personal data. In addition, public confidence in the security and reliability of EUDI Wallet will play a decisive role in its widespread adoption. Public awareness and education campaigns on the benefits and security measures of EUDI Wallet could help build this confidence.</p>
<p style="text-align: justify;">However, the most important element for EUDI Wallet will be the rate of adoption by private services. The involvement of private companies is crucial, as they provide a large proportion of the services used daily by citizens. Widespread adoption by the banking, healthcare, education and other private services sectors would ensure wider and regular use of the wallet, making its integration more fluid and natural for users.</p>
<p style="text-align: justify;">The technology is still emerging and not yet mature enough to be implemented immediately. However, given the many potential benefits, it is crucial to follow this technology closely and adopt it as soon as possible. This is particularly true for the banking sector and extended enterprise use cases, where EUDI Wallet could bring significant improvements in security, transaction fluidity and operational efficiency.</p>
<p style="text-align: justify;">Nevertheless, by overcoming these obstacles and taking advantage of the opportunities offered by EUDI Wallet, France could play a leading role in building a more secure, innovative and connected digital Europe for years to come.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/06/the-european-identity-wallet-the-digital-identity-of-the-state-soon-to-be-in-our-pockets/">The European identity wallet, the digital identity of the state soon to be in our pockets</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/06/the-european-identity-wallet-the-digital-identity-of-the-state-soon-to-be-in-our-pockets/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Which IAM for the Extended Enterprise?</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/05/which-iam-for-the-extended-enterprise/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/05/which-iam-for-the-extended-enterprise/#respond</comments>
		
		<dc:creator><![CDATA[Maryeme BOUSSOUIS]]></dc:creator>
		<pubDate>Wed, 22 May 2024 07:57:58 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[B2B]]></category>
		<category><![CDATA[DIgital Identity]]></category>
		<category><![CDATA[extended entreprise]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity & access management]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=23192</guid>

					<description><![CDATA[<p>The IAM market has considerably matured as it relates to its coverage of classic &#8220;employee&#8221; use cases and is increasingly focusing on the &#8220;customer&#8221; perimeter- both on the part of IAM solution vendors and the companies deploying them. Over the...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/05/which-iam-for-the-extended-enterprise/">Which IAM for the Extended Enterprise?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">The IAM market has considerably matured as it relates to its coverage of classic &#8220;employee&#8221; use cases and is increasingly focusing on the &#8220;customer&#8221; perimeter- both on the part of IAM solution vendors and the companies deploying them. Over the past few years, however, new use cases have emerged that do not fit into either of these two categories resulting in the increasing openness of information systems to different types of partners (suppliers, subcontractors, etc.). Market players refer to these new use cases as the ‘extended enterprise’.<br />IAM solutions on the market don&#8217;t always adequately cover these emerging needs and companies haven&#8217;t found the right approaches and governance modes to address them. More often than not, these use cases are managed on a case-by-case basis, without any IAM solution or common global governance.</p>
<p> </p>
<h2 style="text-align: justify;">What is the extended enterprise?</h2>
<p style="text-align: justify;">The extended enterprise is a group of entities and economic players working together on common projects. Companies have always needed to collaborate by sharing resources and exchanging data. To achieve this, the employees of each of these companies need to be able to interact securely with external users.<br />These external users can be suppliers, subcontractors, B2B customers, subsidiaries (that do not share the same IS), and so on. Collaboration can take many forms and can be time limited.<br />Because of this diversity of scenarios, it is neither possible nor relevant to define a single answer to every IAM project for the extended enterprise. The strategy to be adopted by any company wishing to address this issue will depend on its own context and specific use cases. <br />An extended enterprise IAM strategy can be initiated by answering two key questions: how should IAM governance and delegation be handled with the various partners? And, what type of solution on the market best covers these use cases?</p>
<p> </p>
<h2 style="text-align: justify;">What type of governance?</h2>
<p style="text-align: justify;">There are 4 main approaches to IAM governance in the extended enterprise. The choice of one of these approaches will depend mainly on two criteria: the level of IAM maturity of the various stakeholders and the sensitivity of the resources accessed.</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-23194" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture1-EN.png" alt="" width="624" height="619" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture1-EN.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture1-EN-193x191.png 193w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture1-EN-39x39.png 39w" sizes="auto, (max-width: 624px) 100vw, 624px" /></p>
<p> </p>
<h2 style="text-align: justify;">Which vendor&#8217;s solution?</h2>
<p style="text-align: justify;">A number of functionalities clearly distinguish CIAM editor solutions (customer scope) from Workforce IAM solutions (employee scope). These two types of solutions are at opposite ends of the spectrum referring to the criteria analyzed in the diagram below.<br /><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-23196" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture2-EN.png" alt="" width="624" height="441" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture2-EN.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture2-EN-270x191.png 270w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture2-EN-55x39.png 55w" sizes="auto, (max-width: 624px) 100vw, 624px" /><br />Extended enterprise (B2B) use cases can be positioned over a wide range of this spectrum for each criterion, depending on the context. It is therefore difficult to respond to them with traditional workplace IAM or CIAM solutions, however more and more software publishers are offering new dedicated modules to meet these new needs.</p>
<h2 style="text-align: justify;"><br />What new technologies to facilitate implementation?</h2>
<p style="text-align: justify;">One of the key factors in the success of an extended enterprise project is the ability to decentralize IAM processes and mechanisms. The technological advances presented in the table below make it possible to rethink traditional approaches to identity and access management from this angle. They offer more flexible solutions, adapted to the diversity of use cases encountered, thus enabling greater decentralization, particularly with less mature partners, thanks to identity wallets and passkeys:</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-23198" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture3-EN.png" alt="" width="624" height="391" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture3-EN.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture3-EN-305x191.png 305w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/Picture3-EN-62x39.png 62w" sizes="auto, (max-width: 624px) 100vw, 624px" /></p>
<p> </p>
<p style="text-align: justify;">In this quest for solutions adapted to a wide range of use cases, it is imperative to keep abreast of market developments and constantly assess the relevance of proposed solutions to the specific needs of each context.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/05/which-iam-for-the-extended-enterprise/">Which IAM for the Extended Enterprise?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/05/which-iam-for-the-extended-enterprise/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
