Identity & Access
Management for Regulated
IT Environments

We advise, implement, and operate IAM, PAM, and Non-Human Identity solutions for audit-critical organizations — vendor-independent and backed by more than 25 years of experience.

25+ years of IAM experience
End-to-end responsibility
Consulting, implementation, and operations

Do you really know who — and what —
has access to your systems?

Evolving access structures, increasing requirements driven by NIS2 and DORA, and a growing number of technical identities are leading to a lack of transparency and increased audit risks in many organizations. We create structure, transparent access processes, and robust identity governance — before the auditor asks.

Struktur - Zugriff auf Ihre Systeme

Our Services

Identity & Access Management (IAM) &
Identity Governance Administration (IGA)

Problem

Fragmented access structures and a lack of governance lead to uncontrolled permissions and audit risks.

Outcome

Consistent identity governance with transparent access processes throughout the entire identity lifecycle.

Privileged Access Management (PAM)

Problem

Uncontrolled administrative access and service accounts are among the biggest entry points for attackers.

Outcome

A Zero Standing Privilege architecture with just-in-time access and complete traceability.

Non-Human Identity

Problem

Service accounts, API keys, and automation processes grow uncontrollably and often remain invisible.

Outcome

Complete transparency and automated lifecycle management for technical identities.

Access Management

Problem

Unclear access rights, outdated role assignments, and a lack of recertification processes lead to excessive permissions and compliance violations.

Outcome

Role-based access control with automated provisioning, regular access reviews, and complete traceability of all permissions.

Consumer Identity (CIAM)

Problem

Fragmented login processes, inadequate consent management, and increasing GDPR requirements put both customer experience and privacy compliance at risk.

Outcome

Seamless customer registration and authentication with integrated consent management, self-service functionality, and privacy-compliant identity management.

Exclusive Content

Access Exclusive Content

Get access to additional information, practical examples, and selected materials.

Simply provide your name, email address, and area of interest.

     Privacy Policy.

    IGA Fitness Check

    Receive a structured assessment of your Identity Governance against regulatory requirements such as NIS2 and DORA in a short amount of time. Our IGA Fitness Check provides a quick and effective assessment of the performance of your current IGA strategy.

    • Gap analysis against regulatory best practices
    • Assessment of your current IGA maturity
    • Prioritized recommendations for action
    Industries

    Your Specialist for Regulated and Complex Industries

    Identity architectures tailored to industry-specific compliance requirements such as NIS2, DORA, BAIT, and BSI IT-Grundschutz.

    Healthcare

    Clinical and patient data, KRITIS requirements, and secure management of privileged access.

    Financial Services

    DORA-, BAIT-, and MaRisk-compliant identity governance with audit-proof audit trails.

    Industry

    OT/IT convergence, industrial identities, and Zero Trust-enabled access concepts.

    Public Sector

    BSI IT-Grundschutz, federal structures, and transparent citizen and administrative identities.

    Energy & Utilities

    NIS2, BSI KRITISV, and high-availability requirements in critical infrastructure environments.

    Insurance

    Data protection, risk models, and granular permission structures.

    Retail & E-Commerce

    Customer data protection, secure transactions, and omnichannel security for retail environments.

    Telecommunications

    NIS2-compliant network security and access protection for communications infrastructure.

    Transport & Logistics

    Supply chain security, IoT identities, and NIS2-compliant access management.

     

    See for Yourself

    Experience, technical expertise, and solutions tailored to your organization’s IT environment:

    Discover how OEDIV SecuSys helps organizations reliably manage digital identities, access, and security processes.

    Schedule a initial consultation.

    Why OEDIV SecuSys?

    Your Specialist for Regulated and Complex Industries

    Herstellerunabhängig

    Vendor-Neutral and Independent

    We are not tied to any software vendor. Instead, our architectural decisions are based exclusively on your existing infrastructure, your compliance requirements, and your long-term operating strategy.

    Beratung, Implementierung & Betrieb

    Consulting, Implementation, and Operations

    We do not only provide strategic consulting — we also take care of the technical implementation. From defining the architecture through implementation and operations, we support you across the entire lifecycle.

    Regulierungssichere Identity Governance

    Compliance-Ready Identity Governance

    Our IAM concepts take regulatory requirements such as NIS2, DORA, BAIT, MaRisk, and BSI IT-Grundschutz into account from the outset. We create transparent governance structures that are documented in an audit-ready manner and designed for long-term resilience.

    Non-Human Identity im Fokus

    Non-Human Identity at the Center

    In addition to workforce identities, we systematically address service accounts, API keys, automation processes, and machine identities. Particularly in hybrid and cloud-based infrastructures, controlled lifecycle management of these identities is critical to security.

    Langjährige Partnerschaft

    Long-Term Partnerships

    IAM is not a one-time project, but a continuous maturity process.

    We support many of our customers over several years — strategically, operationally, and through managed services — with the goal of creating a sustainably stable identity architecture.

    We also draw on our long-standing global partner network.

    Stabilität in der Integration

    Stability Through OEDIV Integration

    As part of the renowned OEDIV Group, we combine specialized IAM expertise with organizational stability and long-term reliability. For regulated organizations, this combination is a key factor when selecting a partner.

    Über uns

    About Us — Built on Experience, Founded on Trust

    OEDIV SecuSys was founded on the understanding that genuine security cannot be achieved through standard solutions alone. For more than 25 years, we have been working with organizations that need to truly understand their identities and access.

    As part of the OEDIV Group, we combine specialized IAM expertise with organizational stability — for organizations that cannot compromise on reliability.

    Erfahrung & Vertrauen - IAM Austausch
    Contactform

    Strategic Clarity for Your
    Identity Architecture

    Let us work together to assess how resilient, audit-ready, and future-proof your Identity & Access Management really is today.


    • Response within 24 hours
    • Free, non-binding initial consultation
    • More than 25 years of IAM project experience

    Get in Touch

    We usually respond within 24 hours.


       privacy policy.

      FAQ

      Frequently Asked Questions

      Here you will find answers to the most important questions about our services and solutions.

      What does OEDIV SecuSys do?
      OEDIV SecuSys is a specialist in Identity & Access Management (IAM), i.e. the management of digital identities and access rights, based in Rostock, Germany. Founded in 1998 as a provider of its own Identity Governance software, we now focus entirely on consulting, implementation, and operations, without offering a proprietary product. We manage employee, customer, machine, and administrator identities for companies across all industries – from regulated environments such as energy, financial services, and healthcare to the automotive industry, retail, and the public sector. We serve organizations in the German-speaking region as well as internationally operating companies. Since 2020, we have been part of the Oetker Group through OEDIV Oetker Daten- und Informationsverarbeitung KG.
      Identity & Access Management (IAM) encompasses all processes an organization uses to manage digital identities and control who is allowed to access which systems and data. This includes creating and deactivating accounts, assigning and reviewing permissions, secure authentication through Single Sign-On and Multi-Factor Authentication, and the dedicated protection of administrator accounts. IAM provides the foundation for demonstrably meeting access control requirements arising from the EU NIS2 Directive, the DORA regulation, and ISO 27001.
      Because we look for the right approach and the right technology for your organization – not the other way around. We started out in 1998 with our own Identity Governance software, which taught us that the process is the determining factor, not the tool. Today, we provide vendor-independent consulting without a proprietary product, working with partners selected according to clearly defined criteria. We evaluate every recommendation based on the outcome for the customer and the total cost over the contract term. We cover all types of identities – employees, administrators, customers, machines, and AI agents – and support initiatives from awareness and assessment through to ongoing operations.

      AI agents that independently perform tasks and access systems as part of those tasks represent a new class of identities. They act faster than humans, often require extensive permissions, and are frequently created outside of IT. Organizations that fail to treat them as identities risk losing control over access and auditability. We have been working on this topic since the early stages of this development. We give AI agents their own identity, minimal and time-limited permissions, a responsible human owner, complete logging, and process orchestration that defines where human decisions are required. We also take regulations such as NIS2 and DORA into account from the outset, as these requirements do not distinguish between human and machine access.

      We work with organizations that take identity and access seriously, regardless of industry: energy providers and operators of critical infrastructure, banks and insurers, hospitals, automotive manufacturers and suppliers, retailers, industrial companies, educational institutions, and public-sector organizations. Our focus is on medium-sized and large organizations where access rights must be demonstrably managed, including globally operating corporations. We support many customers over several years and through multiple stages of expanding their IAM environments. We are happy to provide references in a personal conversation.

      We are vendor-independent and select the platform based on your system landscape, compliance requirements, and operating model. Our partner portfolio covers Identity Governance, Privileged Access and Endpoint Privilege Management, Access Management with smart cards and passwordless authentication, Customer IAM, certificate management, Third-Party Risk Management, and process orchestration. We selected our partners according to clearly defined criteria. If a solution outside our portfolio is a better fit for your organization, we will recommend it and, if required, suggest a suitable implementation partner. Even in such cases, we do not leave you on your own: we support the project from an organizational perspective and provide process consulting based on our experience. Our recommendation comes after the requirements analysis – not before.

      Less time than many expect when it is implemented in stages. We do not start with a major all-at-once implementation. Instead, we begin with an initial stage that goes live quickly and delivers immediate value – for example, automatically blocking all access when an employee leaves the organization. Additional systems and processes are then integrated step by step, each with its own tangible outcome. The duration of the initial stage depends on the number of systems involved, the quality of your HR data, and your role model. We assess exactly these factors in our IGA Fitness Check within five days, so you know what to expect before the project begins.
      Costs depend on three factors: the number of target systems to be connected, the maturity of your role and process landscape, and the licensing model of the selected platform. Our IGA Fitness Check provides a reliable initial budget indication: five consulting days at a fixed price of EUR 9,500 plus VAT, including a management summary, action plan, and roadmap with effort estimates.
      The first step is a free strategy consultation, and we respond within 24 hours. Depending on your starting point, this is followed by an IGA Fitness Check or an individual assessment. In both cases, the result is a prioritized roadmap with effort estimates. Based on this, you decide whether and how to proceed.
      Yes. Through our Application Management Service, we take care of operating, monitoring, updating, troubleshooting, and continuously developing your IAM platform – even if it was originally implemented by another service provider. Responsibility for your infrastructure and approval of changes remain with you.