IGEL is repositioning itself as a security company and encouraging enterprises to ‘just IGEL it’. James Goulding finds out more from CEO Klaus Oestermann
A little over one year ago, in July 2023, Klaus Oestermann took over as CEO at IGEL, where he quickly made his mark with the launch of a new corporate logo and identity as ‘the Secure Endpoint OS for Now & Next’.
Security has long been a selling point of IGEL’s, particularly after it got out of thin client hardware and reinvented itself as a software company providing a secure endpoint OS for VDI, desktop as a service (DaaS) and secure browsing (see box).
In January, Oestermann took this to the next level with the unveiling of the IGEL Preventative Security Model. This positions IGEL, first and foremost, as a security company and highlights the value of its OS as enterprises reassess their endpoint strategies and implement Zero Trust and SASE initiatives to eliminate endpoint vulnerabilities.
“If you look at the world today, everybody knows the bad guys are coming – they want to penetrate your infrastructure. Today’s security model is really built around the idea that bad actors are going to get in so let’s monitor, detect, mitigate and remediate. That’s today’s model – when something happens, this is how we react to it,” explains Oestermann.
“We think there’s a different way of doing this, which is why we call it the Preventative Security Model. We basically prevent a breach from happening in the first place. And key to that is putting a super secure operating system on your endpoint, whether that’s a PC, a laptop, a thin client or a tablet. IGEL OS is a system that you cannot write to, a system that is built not to be penetrated. It’s why we call it ‘the Secure Endpoint OS for Now & Next’. It’s the endpoint you use today for infrastructure and it’s also for what you do tomorrow.”
And what’s coming tomorrow, he says, is a continuation of the cloud-first approach which has seen workloads move from Windows endpoints to a VDI, DaaS or SaaS infrastructure often accessed through secure browsers.
“We have a lot of customers that are one third fat Windows, one third VDI or DaaS and one third browser-based on the application side. We’re seeing a big shift now to companies saying new applications have got to be browser-based. We still see a lot of customers leveraging VDI and DaaS, but we see a clear movement towards the browser. IGEL is designed for today’s world and for tomorrow’s world which might be distributing applications differently. That’s the cornerstone in how we position the company.”
Three-ring circus
In explaining the IGEL Preventative Security Model, Oestermann uses the analogy of a three-ring circus, with three acts performing simultaneously and a separate ringmaster controlling each one. These three rings represent the three distinct areas of IT that need to work together to secure the enterprise:
1. Application deployment methodologies (e.g. VDI, DaaS, browser);
2. Identity access management (inc. unified endpoint management, secure service edge and SASE network security); and
3. All x86 hardware platforms.
“In most organisations, these are three distinct organisations, each with its own ringmaster. IGEL sits comfortably in the middle, like Switzerland, and we say ‘OK, what are you using in these different technology pockets and how do you make all this work together?’.”
What enables IGEL to do this is its IGEL-Ready ecosystem of approximately 120 vendor partners (so far) that operate in those three areas and which are integrated with the IGEL OS and, through that, with each other. This, says Oestermann, effectively reduces the attack surface by 95% and saves money because you no longer need multiple endpoint security and management agents.
“You are able to implement what’s called a Zero Trust architecture, which is very big in both the US and UK Governments and is something we believe will be implemented in enterprises as well in the next four to five years. This basically enables you to simplify your endpoint security because, with IGEL, you don’t need all those endpoint agents that you used to have to have to check whether there’s something wrong. We have that under control.”
He points out that because of the integrations between IGEL and, say, Active Directory or Conditional Access in Entra ID and Imprivata, which uses smartcards for faster log-in, customers in sectors such as healthcare, government and financial services can easily establish trust between their hardware platform and identity access management platform, enabling smart single sign-on.
“You can login, in one go, to VDI, to DaaS and to browser, and because IGEL fully containerises and isolates these different workloads you cannot get from one to the other. We basically establish trust, enable smart login and isolate those workloads. IGEL has spent over 20 years on all of these partnerships and integrations and this gives the customer what we call a ‘wheel of fortune’ of benefits from leveraging IGEL.”
One of these, he says, is endpoint ransomware protection.
“We proudly say that you don’t get ransomware attacks on endpoints if you run IGEL and there are side benefits to this as well. With the CrowdStrike situation in July, large parts of the US and UK healthcare sectors were unaffected because most of their endpoints run IGEL, which is a Linux-based system. Nor does IGEL allow the whole reboot sequence that was happening. You have ransomware protection and also what we call manageability. Business continuity, disaster recovery are huge benefits of running an IGEL infrastructure.
“Another is TCO. Typically, it costs around £750,000 to run 1,000 endpoints. IGEL saves 50-75% of that through not having to pay for all those endpoint software products. Your manageability is a lot easier, so you can basically divert your staff to do more interesting things, and you have significant savings in productivity. We have customers who report that their nurses are saving 40 minutes a week when logging in because they have smart login between Imprivata, IGEL and their identity access management platform.”
IGEL it
Oestermann uses the verb ‘IGEL it’ to describe the process of replacing Windows OS on endpoint devices with the IGEL OS offering secure access to browser-based applications, a VDI infrastructure that you already have up and running (e.g. Citrix or Omnissa) or Microsoft Azure Virtual Desktop (AVD).
This helps solve a variety of problems, including costly hardware upgrades necessitated by end of life for Windows 10 support.
“In most environments, healthcare, government and financial services, about one third of PCs, sometimes half, cannot run Windows 11 because it’s missing the security chipset that’s needed. And to them we simply say ‘IGEL it’. Run IGEL on your endpoint and connect to Windows 365 or to Windows in your datacentre delivered via VDI or DaaS.”
The same applies to Dell thin client customers.
“Dell has just released a new version of its thin OS software that requires 8 Gig of RAM, and a very big part of Dell’s thin client infrastructure only has 2 or 4 Gig of RAM. Those clients have to buy new thin clients. That creates e-waste and is not very sustainable. We say ‘IGEL it’. Run IGEL on your 2 and 4 Gig devices instead.”
During the pandemic, IGEL enabled organisations to keep working by providing employees with secure access to corporate applications from devices in their homes (and from anywhere else). For expanding businesses, it can also speed up the integration of an acquired business’s workforce to their existing infrastructure and provide disaster recovery for parts of a customer’s infrastructure that don’t already run IGEL.
“IGEL has something called a UD Pocket, which is a small USB key. If your Windows computer is still running fat Windows and there is a ransomware attack, what do you do? Well, if you have an agreement with IGEL around disaster recovery or business continuity, you just stick that UD Pocket in your PC, and within a couple of minutes, you’re back to a good place and we’ve IGEL’d that PC for you.”
UD Pocket boots the affected endpoint to provide secure access to cloud- based workspaces including Office 365, Windows Virtual Desktop, Citrix, Omnissa, Amazon, Google etc.. Importantly, this is self-contained and remains distinct from the affected device’s installed operating system and files.
Rising sales
Oestermann reports rising sales in the five industry sectors IGEL targets. These are healthcare, financial services, government and manufacturing, which all have strict data/IP protection and compliance requirements, and a fifth, hybrid group made up of big thin client users, including retail and transportation. He expects some of the applications/drivers outlined above to give IGEL a boost next year as well.
“A lot of new customers are coming in where a third of their clients are thin clients, many of them Dell thin clients, one third are PCs that cannot run Windows 11 and then for the last third customers are saying ‘Should we leave those on fat Windows or should we ransomware protect them with IGEL and get the TCO benefit that we see with IGEL?’. We’ve seen a lot of organisations go all in now on IGEL, particularly in the healthcare space.”
An emerging area for IGEL, highlighted by images of stranded holiday-makers staring at blank screens in airport departure halls during the Crowdstrike- Microsoft outage, is OT and IoT.
“All those blue screens happened because a big part of that digital signage is running on Windows. We are now seeing a lot of PoCs for replacing Windows and running digital signage over an IGEL infrastructure because of its manageability and survivability in those types of situation. OT and IoT is a new frontier for us. How do you secure digital signage, medical devices and national infrastructure against really bad actors? There’s a lot of vulnerability on the OT side and in the future IGEL will help on that front as well.”
Priorities for 2025
In the meantime, Oestermann’s priorities for the next 12 months are to increase adoption in its five key verticals and to convince partners to lead with IGEL’s Preventative Security Model, rather than just positioning IGEL as part of, say, the Citrix ecosystem.
“We are a 100% channel company and we have a lot of very, very good channel partners that are pushing IGEL very hard to their customers. We want to expand the channel and we want to become
more important for our existing channel partners, which means more wallet share. We want to be in all their projects. We have a lot of partners who have a Citrix or an Omnissa or a Microsoft practice and have IGEL as an add-on to those projects. What we’re working on is for those partners to understand the significance of what the Preventative Security Model can do for their clients and to lead with IGEL as a practice.”
He expects the IGEL Preventative Security Model to attract new partners too.
“Going back to the three-ring circus, partners that have expertise in security, identity, access management, SASE and so forth are now starting to leverage IGEL even though they might be new to the deployment methodologies – VDI, DaaS, the browser. In many cases, partners will have a security practice and a deployment practice and we are now seeing more interest from the security practices in new and existing partners, where the security team is coming to the table saying ‘Wow, this IGEL stuff is phenomenal’ and are starting to get trained on it. This is where a partner can become that ring master linking those three rings. Partners are starting to adopt this model and say ‘Ah, we can actually consult with our clients in a different manner if we think like this’.”
In February, IGEL strengthened its proposition for channel partners with the launch of a new MSP partner programme that makes it easier for MSPs to deliver secure managed endpoints with MSP- optimised ‘pay as you grow’ licensing and a choice of multi-tenant and single-tenant deployment options.
In parallel with this change, Oestermann believes end users are starting to look at IGEL in a new way, with the C-suite in particular beginning to recognise IGEL’s ability to deliver security benefits, financial benefits and sustainability benefits in one go.
“A lot of projects get initiated with the CFO or the CIO or the CISO going to the end user compute and security group and saying ‘How come we’re not IGEL’d?’.
A lot of initiatives are now driven from the C suite. That can be a CFO looking at it from a TCO, financial standpoint or a sustainability standpoint, because they’ve got to report on sustainability and IGEL is your best friend to reduce e-waste and sweat your assets for longer and reduce the power consumption of your assets as well. Then, CIOs and CISOs often come at this from a security angle – ransomware protection, integration with data protection, compliance. CIOs are very focused on TCO as well. But it could also be a company that is in acquisition mode asking ‘How can we acquire companies and quickly have them adopt our technology platform?’. IGEL is the best way to do that.”
The big five
The five key qualities/capabilities that enable the IGEL platform to support growing demand for a Zero Trust approach to data security:
1 It is a read-only Linux-based OS – so users can’t unwittingly or maliciously install malware on endpoints;
2 There is no local storage of data – because users can’t download customer, patient or financial data or exfiltrate it through USB devices, the risk from lost/stolen devices or data theft by internal users is massively reduced;
3 It is a trusted application platform – a secure boot process ensures code hasn’t been tampered with, and if there is a cyber-attack rebooting returns a device to a known good state enabling organisations to restore services in minutes, not weeks or months;
4 It supports authentication, SSO integration and SASE – IGEL partners with leading authentication vendors including Microsoft, Imprivata, Okta, Ping Identity, VMware and Citrix, and with SASE and Secure Service Edge partners to optimize Zero Trust implementations; and
5 It has a modular design and small footprint. At 2GB, IGEL OS 12 has a much smaller attack surface than a traditional endpoint OS. It only contains what the user needs to accomplish their tasks, with additional functionality, such as partner integrations, downloadable from the IGEL App Portal.


Be First to Comment