Home • Services • IAM Consulting

IAM Consulting
for Organizations


Practical consulting for Identity & Access Management (IAM) and

Identity Governance & Administration (IGA).

Strategically Developing
Identity & Access Management


Identity & Access Management is more than implementing software. Identities, permissions, and access processes are closely linked to an organization’s structures. That is why a successful IAM strategy does not start with selecting technology, but with the question: What requirements exist within the organization, and how should identities and access be managed in the future?

IAM Consulting from Strategy
to Implementation


OEDIV SecuSys supports organizations in developing and implementing their IAM strategy. We consider both functional and organizational requirements as well as existing technical structures. Our consulting services can cover topics such as:

  • IAM strategy and target vision
  • Analysis of existing IAM structures
  • Identity Governance & Administration
  • Access Management and SSO
  • Privileged Access Management
  • Non-Human Identity Management
  • Certificate Lifecycle Management
  • Technology selection and architecture
  • Roadmap and implementation planning
IAM Beratung

Our Consulting Services

Why OEDIV SecuSys GmbH?


IAM projects bring together organizations, processes, and technology. That is why we take a consulting approach that considers all three areas.

Our goal is not a standard solution, but an Identity & Access Management environment that fits your processes, organization, and requirements.

More than 25 years of experience in Identity & Access Management

Vendor-independent consulting

Many years of project experience across different industries

Support from initial analysis through to implementation

Consulting for organizations throughout the DACH region

Vendor-Independent Consulting

OEDIV SecuSys is not tied to a single vendor. This allows us to evaluate technologies and solution approaches independently of existing product interests. What matters to us is which solution best fits the organization, system landscape, and objectives of the respective company.

IAM Must Work Within the Organization

A technically powerful solution provides little value if processes do not work or responsibilities remain unclear. That is why, in addition to IT, we involve the relevant business units and organizational processes.

OEDIV SecuSys supports organizations in establishing IAM structures, further developing existing solutions, and sustainably securing ongoing operations.

From Initial Analysis to Operations

Depending on the starting point, collaboration can begin with an assessment of the existing environment or a Fitness Check. Based on this, a target vision, roadmap, and specific implementation projects can be developed.

Even after implementation, OEDIV SecuSys can support organizations with the operation, further development, and optimization of their IAM environment.

FAQ

Frequently Asked
Questions

Here you will find answers to the most important questions about

our consulting services.

What Does IAM Consulting Cover?
IAM consulting covers the journey from analysis through to operations: assessing the current environment and maturity, defining requirements together with the business units, developing a strategy and target architecture for Identity & Access Management, designing processes for onboarding and offboarding and the regular recertification of access rights, developing the role model, vendor-independent tool selection including a Proof of Concept, supporting implementation, and transitioning into operations. Two topics are part of every strategy we develop: regulatory requirements arising from NIS2, DORA, and ISO 27001, and the management of AI agent identities, because both will shape IAM architectures in the coming years. At OEDIV SecuSys, these services can be provided individually or as an end-to-end program, depending on your needs.
We use a classic framework with agile implementation. The phases — Analysis, Design, Basic Setup, Execution, Testing, and Go-Live — provide planning certainty. During Execution and Testing, we work in sprints with regular reviews to deliver individual functions at an early stage and respond to new requirements. Five Quality Gates mark the transition between the phases, each with agreed deliverables such as an approved role model or accepted test results. After Go-Live, a stabilization phase with intensive support follows, along with an operations manual and the handover to regular operations.
Yes. Awareness is the first stage of our consulting portfolio. Training for business units, managers, and access rights owners explains why regular access reviews, least privilege, and properly managed offboarding processes are their responsibility — not just IT’s. IAM projects are less likely to fail because of the technology than because business units are not aware of their role as owners of roles and access rights. Our training addresses this directly.
Yes. Access rights management is a business process, not a software feature: Who submits a request? Who approves it? What deadlines apply? What needs to be completed by when when an employee leaves? We model these processes together with the business units, define responsibilities, and implement them in the IGA platform where appropriate. For processes that precede or follow the system and cannot be natively mapped within it, we use process orchestration to logically connect multiple systems and involve a human decision at defined points. We use the same tool to control processes involving AI agents in a controlled manner.
This depends on the scope, complexity, and objectives and is agreed on a project-by-project basis. The IGA Fitness Check has a fixed price of €9,500 plus VAT. Assessments and tool selection processes are calculated based on consulting days, while implementation support and role model projects are billed either based on effort or as defined work packages with specified deliverables. Following the free initial consultation, you will receive a proposal with a clearly defined scope of services.
An IAM platform remains in use for ten years or longer. Making the wrong selection decision can cost years. Vendor-affiliated consultants recommend their own product. We look for the solution that fits your organization and evaluate requirements, system landscape, operating model, and total costs over the entire contract term. Because we implement and operate multiple platforms for Identity Governance, Privileged Access, and Access Management, we know their strengths and limitations from practical experience, not just from datasheets. We advise you on an equal footing and do not favor any particular vendor.
This depends primarily on the number of identities and the complexity of hierarchies and processes. For organizations with more than 5,000 identities or complex structures, an initial project phase typically comprises around 160 consulting days over approximately nine months, from analysis through to Go-Live, including integration with the HR system, directory service, and initial business applications. Smaller projects start at 15 to 30 consulting days. The rollout to additional target systems then takes place in waves. A complete IAM program in a large enterprise can extend over several years.
There are five recurring causes: starting with the software instead of the processes; poor-quality HR data that prevents automation; an overly detailed role model that nobody maintains; insufficient involvement of business units as access rights owners; and no defined operating model after the project ends. We spent many years developing Identity Governance software ourselves and learned that the process determines the outcome, not the tool. That is why we clarify all five points before the first licensing decision.
Yes. We translate the requirements of NIS2, DORA, ISO 27001, and the BSI IT-Grundschutz framework relating to access control, privileged accounts, regular access reviews, and evidence requirements into concrete IAM measures and support their implementation. We take responsibility for the Identity & Access Management component within your Information Security Management System (ISMS). Overall responsibility remains with your Information Security Officer.