Engagement Dashboard
Discovery Phase
- Conducting stakeholder interviews
- Reading organizational dynamics
- Gathering technical documentation
- Identifying key pain points
Analysis Phase
- Evaluating IAM architectures
- Assessing cloud IAM posture
- Identifying compliance gaps
- Risk quantification methods
Synthesis Phase
- Building strategic roadmaps
- Vendor evaluation frameworks
- Executive presentation skills
- Technical workshop delivery
Client Profile: Nexus Financial Technologies
Pre-Engagement Intel (From Intake Questionnaire)
| System | Users | Origin |
|---|---|---|
| Okta (Primary IdP) | 1,400 | Original Nexus |
| Azure AD (Secondary) | 600 | PayFlow acquisition |
| Google Workspace | 400 | SecureTransact acquisition |
| On-prem AD (2 forests) | 1,800 | Legacy + PayFlow |
| Provider | Accounts | Primary Use |
|---|---|---|
| AWS | 340 accounts | Production workloads |
| Azure | 12 subscriptions | PayFlow apps |
| GCP | 8 projects | Data analytics |
Key Stakeholders
Former VP Security at a major bank. Brought in specifically to "fix identity." Under board pressure to show results before next SOC 2 audit.
Built original Okta deployment. Team of 6. Concerned about job security with new CISO. Has deep institutional knowledge but may be defensive.
Manages 340 AWS accounts with team of 8. Frustrated with IAM bottlenecks. Strong opinions about cloud-native solutions. Potential ally.
Owns SOC 2 and PCI compliance. Has detailed documentation of every audit finding. Knows where all the bodies are buried.
Came from PayFlow acquisition. Prefers Azure AD and Microsoft stack. May resist Okta expansion. Engineering budget competes with security.
Manages Workday HCM. Has been requesting automated provisioning for 2 years. Key ally for identity lifecycle automation project.
Kickoff Meeting
| Time | Topic | Lead |
|---|---|---|
| 0:00 - 0:10 | Introductions & Engagement Overview | You (Consultant) |
| 0:10 - 0:25 | Client's Vision & Pain Points | Jennifer Walsh (CISO) |
| 0:25 - 0:40 | Scope Confirmation & Success Criteria | Joint Discussion |
| 0:40 - 0:55 | Interview Schedule & Documentation Access | You (Consultant) |
| 0:55 - 1:00 | Next Steps & Action Items | You (Consultant) |
Send this to Marcus (IAM Director) within 24 hours of kickoff:
-
Network/System Diagrams: Current identity architecture diagrams (if any exist)
-
User Counts: Current active user counts per identity system (Okta, Azure AD, Google)
-
Application Inventory: List of applications with SSO integration status
-
AD Documentation: Active Directory forest/domain structure documentation
-
Cloud IAM: AWS Organizations structure, Azure subscription hierarchy
-
Audit Reports: Last SOC 2 report and remediation tracker
-
PAM Configuration: CyberArk deployment documentation and vault structure
-
Policies: Identity and access management policies
Week 1: Discovery & Documentation
| Day | Activities |
|---|---|
| Day 1 | Kickoff meeting • Documentation request • Environment access setup |
| Day 2 | CISO interview • IAM Director interview • Initial doc review |
| Day 3 | Cloud Lead interview • Compliance Manager interview |
| Day 4 | VP Engineering interview • HR Systems interview • AD walkthrough |
| Day 5 | Documentation analysis • Current state mapping • Gap identification prep |
-
Complete all 6 stakeholder interviews
-
Document current state architecture diagram
-
Compile user population by identity system
-
List all applications and SSO status
-
Identify initial red flags for Week 2 deep-dive
-
Send mid-engagement status update to CISO
Stakeholder Interview Simulator
DO
- Ask open-ended questions first
- Listen for what's NOT being said
- Follow up on emotional responses
- Take verbatim notes on key quotes
- Ask "what would you fix first?"
- Probe for specific examples
DON'T
- Lead with yes/no questions
- Show judgment about current state
- Promise specific outcomes
- Share other stakeholders' opinions
- Rush through to check boxes
- Interrupt when they're venting
Week 2: Deep Analysis
| Day | Focus Area |
|---|---|
| Day 6 | Authentication flow mapping • MFA coverage analysis |
| Day 7 | AWS IAM deep-dive • Access key audit |
| Day 8 | Azure AD analysis • Conditional Access review |
| Day 9 | Active Directory security assessment |
| Day 10 | CyberArk utilization review • PAM gap analysis |
-
MFA enrollment rates per identity system
-
AWS access key age and rotation compliance
-
Privileged account inventory (DA, AWS Admin)
-
Service account password age
-
CyberArk vault utilization metrics
-
SSO coverage across application portfolio
AWS IAM Analysis (340 Accounts)
| Metric | Current | Target | Status |
|---|---|---|---|
| Root accounts with MFA | 287/340 | 340/340 | 84% |
| Root accounts with access keys | 4 | 0 | CRITICAL |
| Total IAM access keys | 847 | — | AUDIT |
| Access keys > 90 days | 312 (37%) | 0 | HIGH |
| Unused keys > 90 days | 156 (18%) | 0 | HIGH |
| Users with AdministratorAccess | 34 | <10 | CRITICAL |
MFA Coverage Analysis
| System | Total Users | MFA Enabled | Coverage |
|---|---|---|---|
| Okta (Original Nexus) | 1,400 | 1,372 | 98% |
| Azure AD (PayFlow) | 600 | 534 | 89% |
| Google Workspace (SecureTransact) | 400 | 256 | 64% |
| TOTAL | 2,400 | 2,162 | 71% (29% gap) |
Week 3: Synthesis & Presentation
| Day | Activities |
|---|---|
| Day 11 | Findings consolidation • Risk scoring |
| Day 12 | Roadmap development • Budget estimation |
| Day 13 | Vendor comparison • Recommendation drafting |
| Day 14 | Executive presentation • Q&A prep |
| Day 15 | Technical workshop • Final deliverables handoff |
-
Executive Summary (2-page PDF)
-
Detailed Technical Report (30+ pages)
-
Current State Architecture Diagrams
-
Future State Architecture Recommendation
-
12-Month Prioritized Roadmap
-
Vendor Comparison Matrix
-
Executive Presentation Deck
- Already deployed (1,400 users)
- Best AWS SSO integration
- Native Workday connector
- Strong MFA options
- Bundled with M365
- Best Azure integration
- Conditional Access maturity
- Migration complexity
- Strong on-prem support
- Complex deployment
- Higher TCO
- Not a fit for cloud-first
Consolidated Findings & Risk Matrix
| ID | Finding | Risk | Business Impact |
|---|---|---|---|
| R1 | 4 AWS root accounts have active access keys | CRITICAL | Full environment compromise if keys leaked |
| R2 | 53 AWS root accounts missing MFA | CRITICAL | Account takeover via password spray/phishing |
| R3 | 29% of users (700+) have no MFA | HIGH | Credential-based attacks, SOC 2 finding |
| R4 | 22 Domain Admin accounts (target: 4) | HIGH | Excessive blast radius for compromise |
| R5 | 34 users with AWS AdministratorAccess | HIGH | Privilege creep, audit finding risk |
| R6 | No automated provisioning from Workday | HIGH | 3-day onboarding delay, orphaned accounts |
| R7 | CyberArk at 20% utilization | MEDIUM | $200K+ annual license waste |
| R8 | No Conditional Access / device trust | MEDIUM | No context-aware security controls |
| R9 | PayFlow using SMS-only MFA | MEDIUM | SIM swap vulnerability for 600 users |
12-Month IAM Transformation Roadmap
| Phase | Timeline | Budget | Primary Focus |
|---|---|---|---|
| Phase 1 | Months 1-3 | $150,000 | Critical remediation, SOC 2 prep |
| Phase 2 | Months 4-6 | $400,000 | Identity consolidation, HR integration |
| Phase 3 | Months 7-9 | $300,000 | PAM optimization, secrets management |
| Phase 4 | Months 10-12 | $350,000 | Zero Trust, device trust |
| TOTAL | 12 Months | $1,200,000 | Under $2M budget approval |
Final Deliverables Package
Discovery Skills
- Stakeholder interview techniques
- Organizational dynamics reading
- Documentation request processes
- Current state mapping
Analysis Skills
- AWS IAM security assessment
- MFA coverage analysis
- Privileged access review
- Compliance gap identification
Synthesis Skills
- Risk quantification
- Roadmap development
- Vendor evaluation
- Executive communication