Engagement Dashboard

2,400
Total Employees
29%
No MFA Coverage
847
AWS Access Keys
$12.5K
Engagement Value
Engagement Timeline
WEEK 1
Discovery & Documentation
Stakeholder interviews (8-10) • Architecture documentation review • Directory services assessment • Current state mapping
WEEK 2
Deep Analysis
Authentication flow testing • Policy and configuration review • Cloud IAM deep-dive • Gap identification
WEEK 3
Synthesis & Presentation
Findings consolidation • Roadmap development • Executive presentation • Technical workshop
Critical Findings Preview
CRITICAL: 4 AWS root accounts have active access keys - immediate remediation required
HIGH: 3 separate identity systems from acquisitions never consolidated
HIGH: 14 users in Domain Admins group - should be maximum 4
MEDIUM: CyberArk deployed but utilization under 20% - significant license waste
What You'll Master in This Simulation

Discovery Phase

  • Conducting stakeholder interviews
  • Reading organizational dynamics
  • Gathering technical documentation
  • Identifying key pain points

Analysis Phase

  • Evaluating IAM architectures
  • Assessing cloud IAM posture
  • Identifying compliance gaps
  • Risk quantification methods

Synthesis Phase

  • Building strategic roadmaps
  • Vendor evaluation frameworks
  • Executive presentation skills
  • Technical workshop delivery

Client Profile: Nexus Financial Technologies

CLIENT PROFILE: NEXUS FINANCIALCompany: Nexus Financial Technologies, Inc. Industry: FinTech (B2B Payment Processing) Headquarters: Austin, Texas Employees: 2,400 (grew from 800 in 3 years via acquisition) Revenue: $340M annually Founded: 2015 KEY BUSINESS CONTEXT • Processes $12B in B2B payments annually • 3,200+ merchant clients • SOC 2 Type II certified (audit in 4 months) • PCI-DSS Level 1 compliant • Acquired "PayFlow Solutions" 18 months ago (600 employees) • Acquired "SecureTransact" 8 months ago (400 employees) WHY THEY HIRED US • New CISO started 3 months ago, inherited "identity chaos" • Failed internal audit finding: "Inadequate access governance" • 3 separate identity systems from acquisitions never consolidated • Board pressure after competitor breach made headlines • Want vendor-neutral assessment before $2M IAM platform investment

Pre-Engagement Intel (From Intake Questionnaire)

Current Identity Systems
System Users Origin
Okta (Primary IdP) 1,400 Original Nexus
Azure AD (Secondary) 600 PayFlow acquisition
Google Workspace 400 SecureTransact acquisition
On-prem AD (2 forests) 1,800 Legacy + PayFlow
Cloud Footprint
Provider Accounts Primary Use
AWS 340 accounts Production workloads
Azure 12 subscriptions PayFlow apps
GCP 8 projects Data analytics
Budget & Authority
Approved IAM Budget (FY2026)
$2,000,000
Decision Maker
CISO + CFO Joint Approval
Implementation Timeline
12-18 months

Key Stakeholders

Mentor Note: Understanding stakeholder dynamics is CRITICAL. Watch for hidden agendas, political tensions, and who actually has decision-making power vs. who thinks they do.
JW
Jennifer Walsh
CISO
3 months at Nexus
EXECUTIVE SPONSOR DECISION MAKER

Former VP Security at a major bank. Brought in specifically to "fix identity." Under board pressure to show results before next SOC 2 audit.

Key Quote: "I need to know what I don't know. Give me the unvarnished truth."
MC
Marcus Chen
Director of IAM
4 years at Nexus
TECHNICAL LEAD DOMAIN EXPERT

Built original Okta deployment. Team of 6. Concerned about job security with new CISO. Has deep institutional knowledge but may be defensive.

Key Quote: "We've been asking for resources for years. Maybe now someone will listen."
TB
Tom Bradley
Cloud Platform Lead
4 years at Nexus
INFLUENCER AWS EXPERT

Manages 340 AWS accounts with team of 8. Frustrated with IAM bottlenecks. Strong opinions about cloud-native solutions. Potential ally.

Key Quote: "Every IAM request takes 2 weeks. My developers are going around the process."
SM
Sarah Martinez
Compliance Manager
5 years at Nexus
COMPLIANCE AUDIT LIAISON

Owns SOC 2 and PCI compliance. Has detailed documentation of every audit finding. Knows where all the bodies are buried.

Key Quote: "Last audit, we scraped by on access reviews. Next time, we won't."
DK
David Kim
VP Engineering
2 years at Nexus
SKEPTIC BUDGET HOLDER

Came from PayFlow acquisition. Prefers Azure AD and Microsoft stack. May resist Okta expansion. Engineering budget competes with security.

Key Quote: "We already have Azure AD. Why do we need two identity systems?"
LW
Lisa Wong
HR Systems Manager
6 years at Nexus
HR INTEGRATION WORKDAY OWNER

Manages Workday HCM. Has been requesting automated provisioning for 2 years. Key ally for identity lifecycle automation project.

Key Quote: "New hires wait 3 days for access. Departing employees keep access for weeks."
Stakeholder Power/Interest Matrix
HIGH INTEREST KEEP SATISFIED MANAGE CLOSELY Jennifer (CISO) HIGH Marcus (IAM) POWER Sarah (Compl.) MONITOR KEEP INFORMED LOW Tom (Cloud) POWER David (Eng.) Lisa (HR) LOW INTEREST Legend: = Primary stakeholders (interview priority) = Secondary stakeholders (informational interviews)

Kickoff Meeting

Mentor Note: The kickoff sets the tone for the entire engagement. This is where you establish credibility, clarify scope, and identify potential landmines.
Meeting Agenda
Time Topic Lead
0:00 - 0:10 Introductions & Engagement Overview You (Consultant)
0:10 - 0:25 Client's Vision & Pain Points Jennifer Walsh (CISO)
0:25 - 0:40 Scope Confirmation & Success Criteria Joint Discussion
0:40 - 0:55 Interview Schedule & Documentation Access You (Consultant)
0:55 - 1:00 Next Steps & Action Items You (Consultant)
Documentation Request List

Send this to Marcus (IAM Director) within 24 hours of kickoff:

  • Network/System Diagrams: Current identity architecture diagrams (if any exist)
  • User Counts: Current active user counts per identity system (Okta, Azure AD, Google)
  • Application Inventory: List of applications with SSO integration status
  • AD Documentation: Active Directory forest/domain structure documentation
  • Cloud IAM: AWS Organizations structure, Azure subscription hierarchy
  • Audit Reports: Last SOC 2 report and remediation tracker
  • PAM Configuration: CyberArk deployment documentation and vault structure
  • Policies: Identity and access management policies

Week 1: Discovery & Documentation

Daily Schedule
DayActivities
Day 1 Kickoff meeting • Documentation request • Environment access setup
Day 2 CISO interview • IAM Director interview • Initial doc review
Day 3 Cloud Lead interview • Compliance Manager interview
Day 4 VP Engineering interview • HR Systems interview • AD walkthrough
Day 5 Documentation analysis • Current state mapping • Gap identification prep
Week 1 Deliverables
  • Complete all 6 stakeholder interviews
  • Document current state architecture diagram
  • Compile user population by identity system
  • List all applications and SSO status
  • Identify initial red flags for Week 2 deep-dive
  • Send mid-engagement status update to CISO
Discovered Current State Architecture
NEXUS FINANCIAL - CURRENT IDENTITY ARCHITECTURE (Post-Discovery) WORKDAY (HR Source) 2,400 users MANUAL SYNCOKTA AZURE AD GOOGLE WORKSPACE (Original) (PayFlow) (SecureTransact) 1,400 users 600 users 400 users 47 SAML apps 23 apps 12 appsAWS Salesforce Slack Azure DevOps BigQuery Gmail Looker 340 accts CRM ON-PREMISES LAYER AD FOREST #1 AD FOREST #2 CyberArk (nexus.local) (payflow.local) (PAM - underused) 1,200 users 600 users 156 accounts vaulted 14 Domain Admins 8 Domain Admins 20% utilization NO TRUST CRITICAL FINDINGS: • 3 separate IdPs with NO federation between them • Workday Identity sync is MANUAL (3-day onboarding delay) • 2 AD forests with NO trust relationship • CyberArk at 20% utilization - massive license waste • 22 Domain Admin accounts across forests (should be <8)

Stakeholder Interview Simulator

Mentor Note: Select a stakeholder below to practice conducting discovery interviews. Pay attention to what they say AND what they don't say.
Interview Best Practices

DO

  • Ask open-ended questions first
  • Listen for what's NOT being said
  • Follow up on emotional responses
  • Take verbatim notes on key quotes
  • Ask "what would you fix first?"
  • Probe for specific examples

DON'T

  • Lead with yes/no questions
  • Show judgment about current state
  • Promise specific outcomes
  • Share other stakeholders' opinions
  • Rush through to check boxes
  • Interrupt when they're venting

Week 2: Deep Analysis

Analysis Schedule
DayFocus Area
Day 6 Authentication flow mapping • MFA coverage analysis
Day 7 AWS IAM deep-dive • Access key audit
Day 8 Azure AD analysis • Conditional Access review
Day 9 Active Directory security assessment
Day 10 CyberArk utilization review • PAM gap analysis
Technical Assessment Areas
  • MFA enrollment rates per identity system
  • AWS access key age and rotation compliance
  • Privileged account inventory (DA, AWS Admin)
  • Service account password age
  • CyberArk vault utilization metrics
  • SSO coverage across application portfolio
Technical Assessment Results

AWS IAM Analysis (340 Accounts)

Metric Current Target Status
Root accounts with MFA 287/340 340/340 84%
Root accounts with access keys 4 0 CRITICAL
Total IAM access keys 847 AUDIT
Access keys > 90 days 312 (37%) 0 HIGH
Unused keys > 90 days 156 (18%) 0 HIGH
Users with AdministratorAccess 34 <10 CRITICAL

MFA Coverage Analysis

System Total Users MFA Enabled Coverage
Okta (Original Nexus) 1,400 1,372 98%
Azure AD (PayFlow) 600 534 89%
Google Workspace (SecureTransact) 400 256 64%
TOTAL 2,400 2,162 71% (29% gap)

Week 3: Synthesis & Presentation

Final Week Schedule
DayActivities
Day 11 Findings consolidation • Risk scoring
Day 12 Roadmap development • Budget estimation
Day 13 Vendor comparison • Recommendation drafting
Day 14 Executive presentation • Q&A prep
Day 15 Technical workshop • Final deliverables handoff
Final Deliverables
  • Executive Summary (2-page PDF)
  • Detailed Technical Report (30+ pages)
  • Current State Architecture Diagrams
  • Future State Architecture Recommendation
  • 12-Month Prioritized Roadmap
  • Vendor Comparison Matrix
  • Executive Presentation Deck
Vendor Comparison: Identity Platform
Microsoft Identity
85/100
  • Bundled with M365
  • Best Azure integration
  • Conditional Access maturity
  • Migration complexity
Enterprise Identity
78/100
  • Strong on-prem support
  • Complex deployment
  • Higher TCO
  • Not a fit for cloud-first

Consolidated Findings & Risk Matrix

Risk Register
ID Finding Risk Business Impact
R1 4 AWS root accounts have active access keys CRITICAL Full environment compromise if keys leaked
R2 53 AWS root accounts missing MFA CRITICAL Account takeover via password spray/phishing
R3 29% of users (700+) have no MFA HIGH Credential-based attacks, SOC 2 finding
R4 22 Domain Admin accounts (target: 4) HIGH Excessive blast radius for compromise
R5 34 users with AWS AdministratorAccess HIGH Privilege creep, audit finding risk
R6 No automated provisioning from Workday HIGH 3-day onboarding delay, orphaned accounts
R7 CyberArk at 20% utilization MEDIUM $200K+ annual license waste
R8 No Conditional Access / device trust MEDIUM No context-aware security controls
R9 PayFlow using SMS-only MFA MEDIUM SIM swap vulnerability for 600 users
Risk Heat Map (Likelihood vs Impact)
IMPACT LOW MEDIUM HIGH CRITICAL R1CRITICAL R7 R2 (Certain) R8 R3HIGH R9 R4 (Likely) R5MEDIUM R6 (Possible) LOW (Unlikely) LIKELIHOOD CRITICAL: Immediate action (R1, R2) HIGH: Address within 30 days (R3, R4, R5, R6) MEDIUM: Address within 90 days (R7, R8, R9)

12-Month IAM Transformation Roadmap

Budget Summary
Phase Timeline Budget Primary Focus
Phase 1 Months 1-3 $150,000 Critical remediation, SOC 2 prep
Phase 2 Months 4-6 $400,000 Identity consolidation, HR integration
Phase 3 Months 7-9 $300,000 PAM optimization, secrets management
Phase 4 Months 10-12 $350,000 Zero Trust, device trust
TOTAL 12 Months $1,200,000 Under $2M budget approval

Final Deliverables Package

Engagement Complete! Below are all deliverables you would provide to the client at the end of a real $12,500 IAM Architecture Review engagement.
Executive Documents
Technical Documents
Skills You've Practiced in This Simulation

Discovery Skills

  • Stakeholder interview techniques
  • Organizational dynamics reading
  • Documentation request processes
  • Current state mapping

Analysis Skills

  • AWS IAM security assessment
  • MFA coverage analysis
  • Privileged access review
  • Compliance gap identification

Synthesis Skills

  • Risk quantification
  • Roadmap development
  • Vendor evaluation
  • Executive communication
Technical Interview Questions (Based on This Engagement)