Service — Identity Advisory

Buying the platform was never the hard part

Identity Advisory is independent, vendor-neutral guidance for your identity security programme: work out where you actually stand, decide where you need to be, and get a phased roadmap that survives contact with reality. Kommando assesses, benchmarks and plans it across the Nordics, before you commit to a platform, not after.

Start with an assessment: see where your identity programme actually stands before you spend another krone on tooling.

Why identity programmes stall
  1. More than half of IGA deployments miss their goals
  2. The failure is the operating model, not the tool
  3. Nobody owns the access decisions

What is Identity Advisory?

Independent strategy before you commit to a platform

Identity Advisory is independent, vendor-neutral consulting that assesses your current identity security posture, defines a target state, and produces a phased roadmap to get there. It answers three questions before anyone signs a licence: where are you now, where do you need to be, and what is the right order to get there.

Most identity programmes don’t fail because the technology was bad. They fail because the operating model underneath it was never agreed. Practitioners consistently find that more than half of identity governance deployments run into distress, and the root cause is almost always the same: goals, ownership and process were never defined before the platform arrived.

An advisor’s job is to fix that first. That means mapping the identities you actually have, human and machine, the applications they touch, and the service accounts nobody remembers creating. It means benchmarking your maturity honestly, deciding who owns access decisions, and only then choosing tooling to fit, rather than reshaping the organisation around whatever a platform does by default.

Done well, advisory is the cheapest part of an identity programme and the part that decides whether the expensive parts work. Get the strategy and the operating model right, and implementation is execution. Get them wrong, and a capable platform will automate the mess faster.

What Identity Advisory covers
  • Current-state assessment
  • Identity maturity benchmarking
  • Target operating model
  • Phased roadmap
  • Vendor-neutral platform selection
  • Business case & ROI

Advisory-led vs tool-led

Buying a platform vs fixing the programme

The instinct when access feels out of control is to buy a platform and hope it imposes order. It rarely does. An advisory-led approach fixes the operating model first, then selects tooling to fit what you actually need, in the order that reduces the most risk.

Tool-ledAdvisory-led
Starts withA platform purchaseAn honest assessment of where you are
Scope decided byWhat the tool does out of the boxYour risks, obligations and priorities
OwnershipAssumed, rarely definedNamed owners for every access decision
RoadmapThe vendor's implementation planPhased to your risk and your capacity
Typical resultAn expensive tool, the same problemsA programme that holds up in an audit

The engagement

The six areas an identity assessment covers

Current-state assessment

We map the identities you actually have, human and machine, the applications they reach, and the access each one holds. The inventory alone is usually the first time anyone has seen the whole picture, and it surfaces the service accounts and standing access nobody remembered.

Identity maturity benchmarking

We benchmark your programme against an established maturity model, from ad hoc to optimised. Most organisations discover they sit at “tooled but inconsistent”: platforms are in place, but the processes around them aren’t. Knowing where you really are is what makes the roadmap realistic.

Risk & compliance alignment

We map your identity gaps to the obligations that matter: NIS2, DORA and GDPR. These regulations now expect demonstrable access control and put accountability on the board, so the assessment ties every finding to a risk and, where relevant, a regulatory requirement.

Target operating model

The half that decides success: who owns access decisions, who runs certifications, who approves privileged access, and how those responsibilities sit across IT, security and the business. Most programmes fail here, not in the technology.

Roadmap & sequencing

A phased plan ordered by risk and by what your team can realistically absorb. Quick wins that reduce exposure early, foundations that make the later phases possible, and a clear sequence rather than the big-bang everyone dreads.

Platform selection & business case

If you do need tooling, we help you choose it on your requirements, not a vendor’s demo, and build the business case that gets it funded. Because we implement SailPoint, CyberArk and Silverfort, the recommendation is grounded in what actually deploys in Nordic environments.

Why now

Why identity advisory matters now

Identity has quietly become the main way attackers get in, and the main thing regulators now ask about. Three shifts made strategy, not just tooling, the priority.

Identity is the primary attack surface. In Sophos’ State of Identity Security 2026, 71% of organisations reported at least one identity-related breach in the past year, and 67% of ransomware incidents began with an identity attack rather than malware. When identity is how attacks start, an unowned, unmeasured identity programme is a strategic risk, not an IT backlog item.

Machine identities took over. Service accounts, tokens and AI agents now vastly outnumber human users, and weak management of them is behind a large share of breaches. Yet most organisations still review only human access, and only about a third regularly audit or rotate service accounts. An assessment that ignores machine identities misses most of the risk.

Accountability moved to the board. Under NIS2, implemented in Norway as the Digitalsikkerhetsloven, and DORA for financial entities, management bodies must approve and are personally accountable for cyber-risk measures, with NIS2 converging on a demonstrable-compliance deadline in late 2026. “We bought a tool” is no longer an answer a board can give. Most of that risk still traces back to credential misuse, the problem identity governance exists to solve.

71%

had an identity-related breach in the past year (Sophos, 2026)

67%

of ransomware attacks started with an identity attack, not malware

Oct 2026

NIS2 becomes the operational deadline for demonstrable access control

By sector

Identity advisory by sector

The gap is universal, but the starting point differs by sector.

Financial services

Usually the most mature tooling and the strictest obligations under DORA, yet the operating model often lags the platform. Advisory here is about closing the gap between capable technology and the ownership and evidence an audit expects.

Public sector

NIS2, legacy systems and slow procurement combine into years of accumulated access. A roadmap lets you bring it under control in sequence, without a rip-and-replace the organisation can’t absorb.

Healthcare

Patient data under GDPR, complex access across clinical and administrative staff, and a rotating temporary workforce make the current-state assessment the priority. You can’t govern access you haven’t mapped.

Energy & utilities

OT/IT convergence and long-tenured staff mean accumulated entitlements are the norm, and the sector is among the most breached. Advisory focuses on untangling decades of access before layering new controls on top.

Our approach

How Kommando delivers Identity Advisory

Assessment

We map your identities, applications and access, human and machine, and benchmark where your programme actually sits. It’s usually the first complete picture the organisation has had.

Strategy & operating model

The target state and, more importantly, who owns it: the access decisions, certifications and privileged approvals that determine whether any of it holds. This is the step that decides success.

Roadmap & business case

A phased plan ordered by risk, with the business case to fund it. Quick wins first, foundations next, and a clear sequence instead of a big-bang programme.

Implementation support

We can hand the roadmap to your team, or deliver it ourselves on SailPoint, CyberArk or Silverfort. Either way, we don’t disappear once the strategy is signed off.

The organisations that succeed aren't the ones with the best platform. They're the ones who decided who owns access before they bought anything.
— Kommando identity security team
Local delivery
Kommando is a Nordic identity security consultancy with certified consultants in Oslo, Gothenburg, Stockholm and Copenhagen. Our advice is vendor-independent, but grounded in what we deliver: SailPoint IGA, CyberArk PAM and, where legacy systems can’t take modern MFA, Silverfort. So the roadmap you get is one we know how to build, not just draw.

A note on what advisory doesn't do

Advisory doesn't fix anything on its own. A strategy nobody owns or funds is a slide deck that ages in a shared drive, and we've been called in to rescue enough of those to say so plainly. The value isn't the document; it's the decisions it forces, chiefly who owns access, and the discipline to work the roadmap in order. We stay to help you act on it, not to hand over a report and leave.

Frequently asked questions

Questions we actually get

What is Identity Advisory?

Identity Advisory is independent, vendor-neutral consulting that assesses your current identity security posture, benchmarks your maturity, defines a target operating model, and produces a phased roadmap. It answers where you are, where you need to be, and in what order to get there, before you commit to a platform rather than after.

Why do identity programmes fail even with good tools?

Because the failure is usually in the operating model, not the technology. More than half of identity governance deployments run into distress, and the common cause is that goals, ownership and process were never agreed before the platform arrived. A capable tool with no owner for access decisions automates the existing mess rather than fixing it.

What is an identity security maturity assessment?

It benchmarks your identity programme against an established maturity model, from ad hoc and manual through to automated and optimised. It shows where you actually sit, which for most organisations is “tooled but inconsistent”, and turns that into a realistic roadmap instead of an aspirational one.

Is Kommando's identity advisory vendor-independent?

Yes. The assessment, strategy and roadmap are built around your requirements, not a product. We do implement SailPoint, CyberArk and Silverfort, which means the recommendations are grounded in what actually deploys in Nordic environments, but the advice comes first and the tooling follows it.

How does identity advisory help with NIS2 and DORA compliance?

Both regulations expect demonstrable access control and place accountability on the board rather than the IT team. An advisory engagement maps your identity gaps to those obligations, ties each to a risk, and sequences the roadmap so you can show auditors and regulators controlled, evidenced access rather than a tool and good intentions.

What is a target operating model for identity?

It’s the definition of who does what in your identity programme: who owns access decisions, who runs access certifications, who approves privileged access, and how those responsibilities sit across IT, security and the business. It’s the half of an identity programme that technology can’t supply, and the half where most programmes fail.

How long does an identity assessment take?

It depends on the size of your estate and the state of your documentation, but a focused assessment and roadmap is typically a matter of weeks, not months. The point is to reach clear decisions and a sequenced plan quickly, so the organisation can start reducing risk rather than waiting for a perfect model.

Do you only advise, or do you implement as well?

Both. Many advisors hand over a strategy and disappear; we can deliver the roadmap ourselves on SailPoint IGA, CyberArk PAM or Silverfort, or support your own team doing it. The advice is independent, but it’s written by people who also build the thing.

Next step

See where your identity programme actually stands

An assessment maps your identities, access and obligations, benchmarks your maturity, and gives you a phased roadmap and a business case to fund it. If you want to talk through where you’re at, we’re happy to help.

  • An independent, vendor-neutral view of where you stand
  • A roadmap sequenced by risk, not vendor timelines
  • Delivered locally across the Nordics

Oslo · Gothenburg · Stockholm · Copenhagen

Kommando identity security consultant at the office