In this episode, Robert Garskamp, Founder of ID Next, joins Empiric's Ruby Tucker from our IAM and PAM Cybersecurity desk to discuss the SAP IDM end-of-life migration, the growing significance of non-human identities and why identity and access management teams need to think beyond technical delivery.
Robert brings over 20 years of experience in identity and access management across large enterprise environments, combining hands-on programme execution with a trusted advisory role to senior leadership and boards. His view of the discipline is broader than most, "What really fascinates me about IAM is that it's often positioned as a technical domain, but in reality it's much, much broader because it touches governance, it touches risk, compliance, user experience and also increasingly even business agility."
If your organisation is facing an IAM migration deadline or rethinking how identity teams are structured, Robert's perspective should be on your radar. Watch the video below and read the full recap, below.
TLDR: Key Takeaways from the Conversation
- SAP IDM's 2027 end of life leaves organisations with tight migration timelines - projects of this nature typically run two to three years including preparation, realisation and aftercare.
- The biggest migration challenges are organisational, not technical - aligning stakeholders, embedding new processes and assigning clear accountability matter more than the tooling itself.
- Non-human identities now outnumber human users in most organisations, creating hidden exposure, overprivileged accounts and lifecycle management risks that many businesses are not tracking.
- IAM maturity varies by sector, with financial services leading, energy and utilities accelerating and retail and manufacturing catching up as digital supply chains expand.
- A phased hybrid approach to IAM modernisation delivers better outcomes than big-bang replacement, provided governance and a clear roadmap hold the process together.
- Consultancy IAM teams need people who can translate technical delivery into business language - the role is as much about stakeholder conversations as it is about systems.
- Hiring managers should prioritise adaptability, collaboration and strategic thinking alongside certifications when building identity teams for what the market now demands.
What Does SAP IDM’s End of Life Mean for Organisations That Haven’t Started Planning?
Organisations yet to begin planning their SAP IDM migration are already under significant time pressure, given that transitions of this scale take two to three years.
With SAP IDM reaching end of life at the end of 2027, organisations still in the planning phase are running short on time. Robert is direct, "If organisations are still thinking now about how to do this migration, I won't say you will be late, but you are in time pressure because normally migration projects last for two or three years including preparation, realisation and also aftercare."
Rather than a like-for-like replacement, he is seeing companies move toward specialised best-of-breed solutions across three areas: identity governance, access management and privileged access management. The shift away from monolithic systems reflects a broader move toward modular, cloud-based IAM architecture, but Robert stresses that the technical migration is rarely the hardest part, "The biggest challenges are not technical. It's more about managing organisational change, it's about aligning stakeholders and also embedding new processes."
His advice to senior leaders centres on three actions: define a clear vision of what success looks like rather than defaulting to a tool replacement, assess existing systems and skills honestly, and invest in people and ownership, "Assign clear responsibility or accountability for the transition. Make sure that the teams have the right skills, authority and resource to drive the change."
Why Are Non-Human Identities Becoming a Critical IAM Challenge?
Non-human identities now outnumber human users in most organisations, but the hidden exposure they create is rarely governed with the same rigour applied to people.
The identity conversation has shifted. Where the past decade focused on human identity governance - onboarding people at the right time with the right access - organisations now operate in an environment where machine identities outnumber human users, "Non-human identities really are accounts used by machines, bots or software systems instead of humans and what we see today in most organisations is that there are more machine identities than human users."
Robert frames non-human identities as enablers of automation that allow businesses to operate efficiently across cloud systems, DevOps environments and microservices architecture, but flags three specific risks: hidden exposure where organisations do not know how many non-human identities exist or who owns them, overprivileged accounts carrying broad access "just in case", and a lack of lifecycle management where non-human identities persist long after they are needed.
The practical starting point, says Robert, is to treat all identities equally whether human or machine, "With clear ownership and governance, you need to implement simple visibility and monitoring practices, even basic tracking dramatically reduces risk, and start small with high impact areas."
How Does IAM Maturity Differ Across Industries?
Financial services leads on IAM maturity, driven by regulatory pressure and early cloud adoption, while energy, retail and manufacturing are closing the gap rapidly.
IAM maturity is not uniform across sectors, and Robert maps out where different industries sit. Financial services leads with highly advanced processes driven by strict regulatory requirements, mature reporting structures and early adoption of cloud IAM and adaptive authentication. Energy and utilities is moving quickly, motivated by the need to protect critical infrastructure as digitalisation spreads across grids, IoT and operational technology. Retail and manufacturing has historically moved slower beyond basic access controls, though Robert notes acceleration driven by digital supply chains, e-commerce growth and cloud adoption.
The broader shift he identifies is that leadership across sectors is starting to treat IAM "as a strategic business enabler rather than a compliance checkbox."
What Is the Best Approach to IAM Modernisation for Legacy Environments?
A phased hybrid approach consistently outperforms full replacement for legacy IAM environments, provided governance and a clear roadmap hold the transition together.
For organisations still running legacy IAM systems alongside newer platforms, Robert favours a phased hybrid approach over full replacement, "Full replacement may sound attractive, is possible, but it's often also too disruptive and risky."
The practical model he describes involves introducing new capabilities alongside legacy systems, migrating applications and identities in phases, focusing on high-risk or high-value areas first and gradually decommissioning old systems. Three factors drive the decision: technical debt (how outdated the current system is), business urgency (regulatory or operational pressures) and risk appetite (willingness to tolerate disruption versus gradual change).
Governance holds the process together, "If you have a clear roadmap, then you can also prevent ad hoc decisions during transition." From Robert's 20 years of experience, IAM projects of this scale typically run two to four years from foundation-building through to full functionality, "It's not out of the box. It's not standard. It's based on things that have been configured by people who don't know it anymore or the documentation is unavailable."
How Do Consultancy IAM Teams Differ from In-House Identity Teams?
Consultancy IAM teams need people who translate technical delivery into business language, while in-house teams focus on aligning identity programmes with internal business outcomes.
The skills required shift depending on whether an IAM team sits inside a consultancy or within an end-user organisation. Robert sees the distinction as a matter of translation, "It's not just a technical project anymore, but also a business project in a business shape. That also means that you need the perfect people in there to make sure that you are going to translate what's being done on the technical side into the functional side and have the conversations with the business."
In-house business stakeholders are rarely concerned with how identity systems are built, "They are more about, hey, I have to deliver business value for my organisation. How can identity and access management be there of any support?" Consultancy teams, working across sectors with varying missions and risk profiles, need to read each organisation's priorities quickly and adapt their approach.
What Skills Should Hiring Managers Prioritise When Building Future IAM Teams?
Adaptability, collaboration and strategic thinking now matter as much as technical certifications in IAM teams that need to carry organisations through significant change.
The CrowdStrike acquisition of SGNL signals a market moving toward identity-driven security where access decisions happen dynamically based on risk, context and policy rather than static permissions. Robert sees IAM becoming increasingly interdisciplinary, blending security, IT operations, cloud and DevOps knowledge, and argues that hiring managers need to adjust, "Really hire for adaptability, collaboration and also strategic thinking. Not just certifications."
Technical expertise remains the foundation, but Robert is clear that soft skills now carry equal weight, "It's a combination. It's about technical skills and building up your technical experience based on your career, but it's also about the soft skills... make sure that you really understand what is being asked there and how can I help here." The end goal is teams that can carry an organisation through change, "Strong teams are those that can guide the organisation safely through change while improving security and efficiency."
Robert sees AI as a net positive for the identity space, with caveats, "AI can certainly be a benefit, but at the end it also means that you have to make sure that it's going to be controlled and monitored and also maintained." He positions AI as useful for automating certain processes and workflows within IAM systems but stresses that human oversight remains non-negotiable.
His closing message to organisations navigating geopolitical uncertainty and infrastructure risk is blunt, "Organisations should invest in people and processes, not just technology. If you are doing that, I believe that you will get the long-term benefits of identity and access management regarding resilience, compliance and also business agility."
Moving Forward
Our dedicated IAM recruitment team connects organisations with professionals who can drive your identity strategy forward. If you are looking to build out your IAM team, hire identity and access management leaders or are a technology professional seeking your next role, get in touch with our team today - we'd be happy to assist.
Be sure to connect with Ruby and Robert on LinkedIn to continue the conversation and be sure to follow us on LinkedIn and sign up to our newsletter to stay in the loop on what's next.
Johnny Beverton