Experian의 직원과 고객 및 파트너사: 다양한 경험 하나의 아이덴티티 표준
employees connected to Okta, along with all their applications
year to company-wide implementation for employees, customers, and partners
disparate identity management technologies replaced by Okta
- From credit bureau to technology company
- A standout consumer app
- Standardized identity management
- More accessible employee apps
- Unified authentication, company-wide
- Enabling the API economy
Inside Experian’s journey to deliver data services through new applications and APIs, and why they chose Okta as the identity layer to power it all.
Experian Consumer Services’ Credit Tracker app becomes a huge hit with customers for its unprecedented access to credit management tools. Okta provides the identity component.
Company-wide, Experian relies on six disparate identity management providers. IT leaders recognize the need to consolidate, and choose Okta as the standard.
Experian deploys Okta internally to Experian’s 17,000 employees, connecting all applications company-wide and retiring six on-prem services within a few months.
Next, Experian brings its external business services applications onto the Okta platform. In less than a year, the company brings all employees, customers, and partners onto Okta.
Experian begins building an API services environment that allows customers to interface with Experian data sources programmatically. Okta’s integration with Apigee makes it possible.
Executing on the digital vision
Experian is transforming from a credit reporting agency to a customer-driven data services company. At the heart of all its services lies a need for secure, user-friendly authentication at every stage of employee and customer interactions. By first standardizing on Okta internally and externally, Experian positions itself to lead in the API micro-services economy.
Okta is the go-forward strategy for all authentication, and will be the single standard that we use. It will have a huge impact on everything we build going forward.
Barry Libenson, CIO, Experian
From credit reporting to data services
On the list of great business challenges, one of the most daunting today may be this: Transforming an established enterprise built on legacy software into a fast-moving, agile organization ready to take on the digital world.
That’s why Barry Libenson was hired in 2015 as CIO of Experian. Prior to Libenson, the company had already made great strides. While it’s still the largest consumer credit reporting agency in the world, today Experian also helps business customers prevent fraud, offer on-the-spot credit to consumers, or make data-driven marketing decisions.
“I would say that Experian to a large extent really is a technology company,” says Libenson. “Gone are the days where our responsibility was to keep the lights on and keep financial systems operating. We’ve morphed into being more of a strategic partner with the business, helping to decide what type of product should be built, to better understand how customers want to access information.”
That shift—from providing standardized credit reporting, to integrating real-time data into a line of customer-driven services—encapsulates the transformation that Experian is undergoing today.
Identity management sits at the heart of it, says Libenson. “Ensuring that the person who’s requesting information is the person they say they are. Ensuring that we don’t share proprietary information with somebody who’s not entitled to see it. That’s at the forefront of all the products we build.”
The vision: A single identity platform
In shepherding Experian through that transformation, one of Libenson’s first priorities was standardization. He wanted to give developers across the company one set of tools, so they could build products in a consistent way. That’s how you build consistent customer experiences, product to product, he says.
When Libenson came on board, Experian had many different identity management systems—including products from Okta, Ping, RSA, Oracle, and MobileIron—implemented across various parts of the company. He recognized that standardizing on one identity and authentication platform would be critical for unifying the company’s architecture internally and externally.
For that single identity platform, Libenson wanted a cloud-based identity solution. It needed to be flexible enough to handle Experian’s broad mix of internal productivity applications, as well as the growing number of customer and partner-facing applications.
To meet the challenge of the digital age, Experian also needed an identity partner that could help secure a growing API ecosystem. Libenson wanted to be able to respond to customer and partner demands for even more sophisticated and customized data services.
A solution already in place
In April 2015, two months before Libenson came on board, Experian’s Consumer Services division had launched its Credit Tracker app, allowing individual consumers to keep track of and manage their credit in an unprecedented way. “People love the interface, how clean it is,” says Libenson. “You can log on and see your FICO credit score, how many open accounts you have, and any issues that are affecting your credit. You can also do what-if scenarios to see how you might improve (or negatively affect) your credit score.”
It was a huge hit. It was also the first app that Experian built on the Okta platform. Jeff Scanlon, VP of global infrastructure and technology operations, chose Okta because of the way it allowed Experian to bring usability and security together, to build a world-class mobile app.
Mervyn Lally, Experian’s EVP of global product development, was Libenson’s first hire. He was charged with evaluating the various identity solutions that Experian had in use across the company. When he came to review what Consumer Services had done with Okta, he was impressed both with the technology and with how easily and quickly it had been implemented.
“It was clear to us that Okta was the leader,” says Lally. “Not only in the marketplace, but in how it was deployed in our environment. We decided that we would standardize as an organization on what our Consumer Services division had started.”
Experian goes all-in on Okta
The next step was deploying Okta to Experian’s 16,000 employees and connecting all their applications to it: financial systems, email, human resources systems, marketing platforms, and so forth. As that phase was completed, IT was able to shut down an array of fragmented legacy on-prem solutions.
“I’m getting rid of six different technologies,” says Lally. “That’s six different support contracts, that’s six different types of servers that I have to maintain, patch, and maintain zero vulnerabilities on.” Today, those components are taken care of by Okta in the cloud, and Experian’s internal IT environment is much simpler to manage. Costs have also decreased as the ongoing expense of managing those services is estimated at over $1M annually.
Another advantage, says Lally, is how efficiently the company can now onboard users. Employees can be more productive because they can get to their applications more quickly.
Next, Experian IT targeted its business customers, to make their access and onboarding just as efficient. Today, it’s standard for retailers such as Home Depot or Target to ask you at checkout if you’d like to apply for a store credit card—even when there are long lines at the registers. Those stores contract with Experian to facilitate that on-the-spot credit analysis.
Experian also offers marketing services, fraud detection, and credit services to financial institutions, such as American Express, Barclay’s, Citibank, and Chase. All of those services include an authentication component.
“There’s a critical need to authenticate that everybody who’s pulling information is who they say they are,” says Libenson. “Equally important is that they’re authorized to pull the piece of information that they’re actually looking at.” Thanks to Okta, that authentication process is even more simple, secure, and reliable today for Experian business clients and their customers.
For a large enterprise, the Okta implementation has gone remarkably fast, effectively consolidating all internal and external Experian applications onto Okta within one year. “We’ve had a very positive experience in terms of working with Okta,” says Lally. “The most interesting for us was the transition from looking at identity in a waterfall type method to looking at it in terms of agile—to learn fast as we deploy the environment, bring it up, configure it, and test.”
The teams struggled a bit at first, says Lally. Spinning new applications up and down quickly was a foreign concept, but it didn’t take long for them to get comfortable with it. “It’s nice watching the speed and the acceleration happen as we do the deployment,” he says.
Enabling the API economy
Experian’s next phase of Okta implementation is about embracing the data-as-a-service opportunity, putting customers in control of the way they pull and view the data they need. “The days of companies dictating how people consume information are really changing,” says Libenson. “Where we used to provide a prescriptive way that we wanted to interface with customers, they’re now coming back and saying, ‘We love the information and services you provide, but we want to consume them differently.’”
To meet those demands, Experian is building out an API services environment that will allow customers to programmatically interface with Experian data sources and pull the exact information they need. “It’s important to understand that almost any app built by our customers wants to incorporate a bunch of different pieces,” says Libenson. “We may be just one component.”
Uber is one example. They use Experian to check the credit background of potential drivers, but there are a number of components built into Uber’s driver hiring platform—it’s not a pure Experian play. Being able to tie various products together is critical to building those kinds of apps.
The API project is a big one. Experian selected Apigee as an API management tool, in part because it integrates seamlessly with Okta API Access Management. “It was really nice watching the partnership between Okta and Apigee,” says Lally. “Now I have the ability to manage APIs in the same way that I manage devices, users, and applications, and how we give access to those applications.”
Giving consumers more control
Libenson doesn’t view Experian as particularly unique in its quest for digital transformation, but getting the API micro-services economy right is extremely important. Failure is not an option, when it comes to responding quickly to customer and consumer demands. The new API environment will help Experian enter new markets, integrate business units, and expand its business.
But even for a financial services-focused organization, it’s not all entirely about money. “The user experience is so much enriched by an API economy,” says Lally. He envisions a world where consumers take unprecedented control of their financial accounts and data.
Imagine being able to lock or unlock your credit report or your credit card account in a single phone swipe. “That would be an API call that uses Apigee and Okta: Okta to make sure we’ve got the security right, and Apigee to make sure the right API call is being executed,” says Lally.
Now that’s a vision we can all buy into.
Experian® is the world's leading global information services company. During life's big moments — from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers — it empowers consumers and clients to manage their data with confidence. Experian helps individuals to take financial control and access financial services, businesses to make smarter decisions and thrive, lenders to lend more responsibly, and organizations to prevent identity fraud and crime.
Experian has more than 16,000 people operating across 37 countries and every day it is investing in new technologies, talented people and innovation to help all clients maximize every opportunity. Experian is listed on the London Stock Exchange (EXPN) and are a constituent of the FTSE 100 Index.