
The Analyst Brief
By The Cyber Hut
For more information on The Cyber Hut visit www.thecyberhut.com/


E75 - Identiverse 2026: Agentic AI, NHI Security & the Future of Identity Platforms
In Episode 75 of The Analyst Brief Podcast, Simon Moffatt and David Mahdi unpack the biggest themes from Identiverse, including the rise of agentic identity, non-human identity security, machine identity management, and the growing overlap between identity, data security, SOC operations, and AI-driven cybersecurity.The discussion covers why traditional human identity management still has unresolved challenges, how AI could automate identity governance work, and why enterprises need to think beyond tactical standards and tools toward broader information flows, attribution, intent, runtime security, and trusted interactions.Simon and David also analyze recent market moves, including SailPoint’s agreement to acquire Entro Security and Cisco’s acquisition of WideField, exploring what these deals say about the future of identity security platforms, go-to-market challenges, and the next wave of consolidation across IGA, NHI, PAM, ITDR, and agentic security.Topics covered:Identiverse key takeawaysAgentic AI and consumer agentsNon-human identity and machine identity securitySailPoint’s acquisition of Entro SecurityCisco’s acquisition of WideFieldIdentity’s role in the SOCAI, runtime security, attribution, and intentWhy identity security is converging with broader cybersecurity platforms#IdentitySecurity #AgenticAI #MachineIdentity#Identiverse #agenticai #ai #iam #nhi @Cisco @SailPointTechnologies @Entrosecurity #iga #itdr #cybersecurity

E74 - The Rise of Agentic AI: Risks and Opportunities
In this episode, Simon Moffatt and David Mahdi explore the evolving landscape of AI, trust, and cybersecurity. They discuss how AI amplifies vulnerabilities, the importance of trust and integrity, and the future of agentic AI in security and identity management.
Keywords
AI, cybersecurity, trust, deepfakes, agentic AI, identity verification, zero trust, content verification, threat modeling, security architecture
Topics
AI amplification of vulnerabilities
Trust and trustworthiness in security
Deepfakes and content verification
Agentic AI and intent management
Dynamic risk and trust models
Chapters
00:00 Introduction and AI's Pervasiveness
00:56 AI in Daily Life and Tools Used
02:07 AI in Product Management and Content Creation
03:25 Deepfakes and Content Manipulation
05:14 Technical Solutions for Deepfake Verification
06:54 Voice Fakes and Generative Content
08:24 Human vs Machine Identity Trust
09:55 Future of Trust and Assurance in AI
12:05 Hardware Trustworthiness and Dynamic Trust Models
15:23 Evolving Identity and Trust Frameworks
20:09 AI-Driven Policy and Access Control
22:01 Agentic Ownership and Behavior
25:19 Explicit Goals and Intent in AI Agents
28:53 Risk, Scope, and Drift in AI Actions
33:20 Objective Clarity and Hierarchies of Intent
40:27 Information Flow and End-to-End Security
44:12 Coordination and Collective Defense
50:08 Dynamic Trust and Risk Management
53:46 Future-Proofing Security with AI
56:01 Conclusion and Future Outlook

E73 - Market News: Cisco + Astrix Security, Silverfort + Fabrix
This episode explores the latest trends in identity security, machine identity, and the strategic moves by major players like Cisco and Silverfort. We discuss acquisitions, the evolution of identity platforms, and the impact of AI on security decision-making.
Keywords
Identity Security, Machine Identity, Cisco, Silverfort, Asterix Security, AI, Cybersecurity, Mergers and Acquisitions, NHI, Identity Control Plane
Chapters
00:00 Introduction and Current Events in Identity Space
02:41 Cisco's Acquisition of Astrix Security
05:44 The Strategic Importance of Machine Identity
08:37 Market Dynamics and Competitive Landscape
11:48 The Future of Identity Management
14:36 The Role of AI in Identity Solutions
17:44 Challenges in the Current Market
20:54 The Impact of Vibe Coding on Development
23:36 Conclusion and Future Outlook
26:00 Navigating the Landscape of AI and Team Dynamics
27:38 The Evolution of Identity Security and Governance
29:21 Acquisitions in the Identity Security Space
31:48 The Role of AI in Identity Governance
36:54 The Future of Authorization and Decision-Making
44:33 Intent and Attribution in Cybersecurity
51:59 The Impact of AI Agents on Privacy and User Experience

E72 - Mythos and a Vulnerability Revolution / Review of IAM Tech Day
Keywords#cybersecurity, #identity #security, #ai #vulnerabilities, #Mythos, #resilience, #vulnerability management, #zerotrust , agent security, cyber innovationChapters00:00 Introduction and Event Overview03:08 Insights from IAM Tech Day in Sao Paulo05:50 The Role of Vendors and Practitioners in Identity Security08:57 Exploring Vulnerabilities and Mythos Project11:40 The Impact of AI on Vulnerability Management14:46 The Future of Cybersecurity and the CISO Role27:22 Building Resilience in Cybersecurity29:46 The Evolution of Cybersecurity Practices32:19 Understanding Business Resilience34:45 The Human Element in Cybersecurity39:26 AI and the Future of Cybersecurity42:17 Agentic Technology and Its Implications

E71 - A Review of RSAC 2026
RSAC 2026, Conference, AI trends, cybersecurity, identity security, investment, technology, innovation, compliance, vendor landscape, digital transformation
Summary
In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss their experiences and insights from the RSAC 2026 Conference. They explore the overwhelming presence of AI in cybersecurity discussions, the evolving role of identity security, and the challenges of AI reliability. The conversation also touches on investment perspectives in the AI landscape and the future dynamics of cybersecurity companies, emphasizing the need for clarity and innovation in a rapidly changing environment.
Sound Bites
"AI is everywhere at RSA this year."
"Identity security is the control plane."
"We need to cut through the AI noise."
"AI is not all the same."
"The models hold the cards right now."
"AI will disrupt and add value."
Chapters
00:00 RSAC Conference Overview
02:57 AI Trends and Observations
06:02 The Role of Identity in Cybersecurity
09:11 Challenges with AI Reliability
12:01 Investment Perspectives on AI
15:10 Future of Cybersecurity Companies
18:06 The Impact of AI on Cybersecurity Dynamics
21:05 Concluding Thoughts on AI and Cybersecurity

E70 - What impact will AI Browsers have on IAM?
The Future of Browsers, AI Agents, and Cybersecurity
Key Topics
- Insights from the recent FSI SAC, Gartner Identity Summit, and upcoming RSA Conference
- How consumer browsers equipped with AI agents are transforming user experiences
- The evolution of search engines into AI-powered agents and their implications
- Security challenges associated with agentic AI and fraud detection
- The shift from enterprise product-centric identity systems to platform-based identity fabrics
- The role of identity in B2C, B2E, and the impact of outside-in and inside-out models
- Future trends in digital identity, including multi-personas, personas, and the role of digital employees and agents
- The influence of consumer tech innovation on enterprise security and identity strategies
- Practical considerations for securing agentic AI and managing associated cyber risks

E69 - The Rise of IAM Resilience - Why Semperis is acquiring MightyID
Keywords
identity, cybersecurity, acquisitions, resilience, AI, identity providers, OpenClaw, regulatory implications, consumer experience, employee experience
Summary
In this episode of the Analyst Brief podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity management and cybersecurity, focusing on recent acquisitions, the importance of cyber resilience, and the convergence of identity and cybersecurity. They explore the implications of identity providers, regulatory challenges, and the impact of AI innovations, particularly the new tool OpenClaw. The conversation emphasizes the need for organizations to prioritize identity resilience and security as they navigate the evolving digital landscape.
Takeaways
- The identity space is experiencing significant acquisition activity.
- Cyber resilience is becoming increasingly important in identity management.
- Identity is more than just the IDP; it plays a critical role in security.
- If an IDP is unavailable, it can severely impact business operations.
- The convergence of identity and cybersecurity is a growing trend.
- Organizations need to focus on identity resilience to ensure service availability.
- Regulatory implications are becoming more significant in the identity space.
- AI innovations are rapidly changing the landscape of identity management.
- OpenClaw represents a new approach to productivity but raises security concerns.
- The future of identity management will require a balance between innovation and security.
Chapters
00:00 Introduction and Current Events
01:22 Acquisitions in the Cybersecurity Space
05:35 The Importance of Identity Resilience
11:24 Convergence of Identity and Cybersecurity
18:10 Regulatory Implications and Future Outlook
22:52 Navigating Identity Lifecycle and Governance
26:37 The Role of AI in Identity Management
29:56 Exploring OpenClaw and Its Implications
42:19 The Future of AI and Security Challenges

E68 - Delinea and StrongDM, the rising role of AI in identity, further market consolidation
Keywords
identity management, cybersecurity, acquisitions, AI, conferences, CrowdStrike, PAM, market trends, technology, security, Delinea, StrongDM
Summary
In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity management and cybersecurity, including upcoming conferences, recent acquisitions, and the evolving role of AI in the industry. They explore the challenges organizations face with technical debt and the need for better resolution in identity management. The conversation also touches on CrowdStrike's recent developments and the importance of ecosystem partnerships in navigating the complex landscape of identity management.
Takeaways
- RSA Conference is a key event for industry professionals.
- Delinia's acquisition of Strong DM highlights market consolidation.
- Identity management is increasingly recognized as a control plane.
- AI is becoming integral to identity management solutions.
- Technical debt poses significant challenges for organizations.
- The identity management landscape is evolving rapidly.
- Ecosystem partnerships are crucial for smaller vendors.
- Vendors need to clearly differentiate their offerings.
- The future of identity management will involve more dynamic solutions.
Chapters
00:00 Introduction
02:54 Upcoming Conferences and Industry Events
05:49 Market Changes: Acquisitions and Mergers
11:43 The Evolution of Identity Management
17:40 The Future of Identity Control Plane
25:07 Leveraging Identity Solutions
26:22 The Role of Identity in Business Agility
28:09 Understanding Information Asymmetry in Business
29:30 The Need for Speed in Identity Management
31:51 Conceptualizing Identity Management
33:16 Addressing Technical Debt in IAM
35:21 AI's Role in Modernizing Identity Infrastructure
38:09 Vendor Narratives and Market Confusion
41:11 Ecosystem Partnerships in Identity Management
43:39 CrowdStrike's New Partnership with Natoma

E67 - CrowdStrike & SGNL Acquisition - and 2026 market consolidation outlook
KeywordsCybersecurity, Identity Security, CrowdStrike, SGNL Acquisition, Zero Trust, Trust in Technology, ITDR, NHI, PAM, Digital TrustSummaryIn this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the rapid changes in the cybersecurity landscape as they enter the new year. They delve into CrowdStrike's recent acquisition of SGNL, exploring its implications for identity security and competition in the market. The conversation highlights the importance of trust in cybersecurity, the evolution of zero trust frameworks, and the anticipated trends in identity security and consolidation within the industry. The hosts emphasize the need for organizations to establish and maintain trust while navigating the complexities of modern cybersecurity challenges.TakeawaysThe cybersecurity landscape is evolving rapidly with new acquisitions.CrowdStrike's acquisition of SGNL marks a significant shift in identity security.Trust is becoming a central theme in cybersecurity discussions.Zero trust is evolving into a more integrated approach to security.Organizations need to focus on end-to-end trust in their cybersecurity strategies.The market is seeing increased consolidation in identity security solutions.Identity security is now a critical component of overall cybersecurity strategy.The role of procurement in technology decisions is often underestimated.Emerging technologies are reshaping the identity security landscape.The year ahead promises significant developments in trust and security. Chapters00:00 Welcome and New Year Reflections01:41 The Rapid Evolution of Identity Security02:10 CrowdStrike's Acquisition of SGNL04:54 The Impact of SGNL on CrowdStrike's Strategy08:09 Competition in the Identity Security Space11:58 The Role of Identity in Cybersecurity21:46 The Future of Identity Security and Zero Trust26:31 The Evolution of Zero Trust in Cybersecurity29:07 The End of the Beginning: Zero Trust Maturity30:32 Trust in a Non-Trusted World34:12 The Shift from Zero Trust to Digital Trust38:32 End-to-End Trust: A New Paradigm42:44 Consolidation Trends in Identity Security50:06 The Future of Acquisitions in Cybersecurity

E66 - Review of Gartner IAM Texas, Blackhat Europe, Saviynt $700M funding and 2026 predictions
Keywords
identity, cybersecurity, AI, Gartner, conferences, funding, innovation, resilience, OWASP, predictions
Summary
In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity and cybersecurity, reflecting on recent conferences, particularly the Gartner Identity Conference. They explore the evolving role of identity in organizations, the impact of AI, and the importance of resilience in supply chains. The conversation also touches on funding dynamics in the identity space, the challenges of innovation versus reliability, and the newly released OWASP Top 10 for Agentic AI. As they look ahead to 2026, they share predictions about the future of identity and the cybersecurity landscape.
Takeaways
Identity is becoming increasingly central to cybersecurity strategies.
The Gartner Identity Conference highlighted key trends in identity management.
AI is reshaping the identity landscape but hasn't introduced new business models yet.
Organizations need to focus on resilience in their identity systems.
Funding in the identity space is shifting, with significant investments being made.
Innovation in identity solutions must balance reliability and customer needs.
The complexity of supply chains poses challenges for identity management.
OWASP's Top 10 for Agentic AI emphasizes the importance of identity in AI security.
2025 has been a pivotal year for identity, with increased attention and funding.
Organizations should start small and automate basic identity management tasks.
Sound bites
"Identity is at the core."
"Identity is foundational."
"Phishing isn't fixed."
Chapters
00:00 Introduction and Festive Greetings
02:04 Conferences and Events: Insights from Black Hat Europe
04:38 Gartner Identity and Access Management Conference Overview
09:32 Emerging Trends in Identity Management
12:47 Identity as Core Infrastructure
17:48 The Future of Identity in Cybersecurity
23:39 Funding and Market Trends in Identity Solutions
28:08 Navigating Customer Satisfaction and Market Dynamics
29:32 The Shift from Hypergrowth to Profitability
31:53 Investment Strategies and Market Positioning
33:37 Innovation vs. Reliability in Established Companies
36:57 The Role of Innovation Across Business Functions
38:44 The Importance of Identity in Cybersecurity
40:03 Supply Chain Vulnerabilities and Interdependencies
44:26 Resilience and Recovery in Cybersecurity
48:07 The Need for Investment in Incident Response
49:31 Privacy Challenges in the Digital Age
51:30 OWASP Top 10 for Agentic AI
55:37 Predictions for 2026: AI and Cybersecurity Trends

E65 - ConductorOne funding, Ping + Keyless, JumpCloud + Breez Security, Imprivata + Verosint, Twilio + Stytch
Summary
In this episode of the Analyst Brief podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity security, including recent funding rounds and acquisitions. They explore the growing importance of identity governance, the intersection of security and identity management, and the role of trust in the age of AI. The conversation also touches on the significance of ITDR and the implications of recent acquisitions for the market. The hosts reflect on the future of identity security and the need for continuous innovation in this evolving landscape.
Chapters
00:00 Introduction to the Analyst Brief Podcast
03:03 Autumn Conference Season Insights
06:05 Funding and Acquisitions in Identity Governance
08:59 The Growing Complexity of Identity Governance
12:01 The Intersection of Security and Identity
14:49 The Future of Cybersecurity and Identity Integration
17:42 Understanding the Broader Ecosystem of Cybersecurity
21:04 The Importance of Protecting All Identities
23:53 First Principles in Cybersecurity Strategy
29:10 Navigating Resilience and Availability in Security
29:56 Funding Trends in Identity Security
31:45 The Impact of Acquisitions on Identity Security
32:13 Twilio's Acquisition of Stitch: A New Era in Identity
36:33 Building Trust in the Age of AI
39:21 Zero Trust: Establishing and Maintaining Trust
44:14 Ping Identity's Acquisition of Keyless: Innovations in Biometric Authentication
55:11 JumpCloud Acquires Breeze Security: Enhancing ITDR Solutions
59:54 Improvata's Strategic Moves in Identity Security
Keywords
identity security, funding, acquisitions, AI, trust, governance, ITDR, cybersecurity, authentication, market trends

E64 - The Growing Impact of Digital Dependency
Keywords
AWS outage, digital dependency, business continuity, FIDO, authentication, passkeys, digital certificates, threat informed defense, false positives, cyber resilience
Summary
In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the recent AWS outage and its implications on digital dependency and business continuity. They explore the importance of disaster recovery plans and the evolving landscape of authentication technologies, particularly focusing on the FIDO Authenticate Conference. The conversation delves into the lifecycle of passkeys and digital certificates, emphasizing the need for threat-informed defense strategies and the challenges of managing false positives in security. The episode concludes with a call for better integration of systems and shared intelligence across the industry.
Chapters
00:00 Introduction and Global Outage Discussion
03:01 The Impact of Digital Dependency
06:00 Business Continuity and Disaster Recovery
09:10 FIDO Authenticate Conference Overview
16:09 Evolution of Authentication Technologies
21:45 The Lifecycle of Passkeys and Digital Certificates
29:59 Threat Informed Defense and False Positives
39:55 Conclusion and Future Considerations

E63 - Are Identity Platforms Legacy? The Rise of Identity Information Flows
Keywords
PAM, IGA, CyberArk, Palo Alto, identity security, AI, machine identity, cybersecurity, information flows, behavioral analysis
Summary
In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the significant changes in the cybersecurity landscape, particularly focusing on Privileged Access Management (PAM) and Identity Governance and Administration (IGA). They explore the recent acquisition of CyberArk by Palo Alto, the evolution of identity security, and the convergence of various identity management solutions.
The conversation highlights the importance of information flows, and the need for a mindset shift in the industry to effectively address identity security challenges.
Takeaways
- The cybersecurity landscape is rapidly changing due to AI.
- PAM and IGA are evolving but remain siloed.
- The acquisition of CyberArk by Palo Alto signifies a shift in identity security.
- Organizations struggle with integrating disparate identity technologies.
- Behavioral analysis is crucial for identifying security threats.
- AI will play a significant role in optimizing identity security.
- Defensive acquisitions are common in the cybersecurity industry.
- The future of identity security relies on understanding information flows.
Chapters
00:00 Welcome Back and Industry Changes
02:01 The Evolution of Privileged Access Management (PAM)
10:41 The Convergence of Cybersecurity and Identity
16:13 The Future of Identity Management Platforms
24:23 Understanding Information Flows in Cybersecurity
28:12 The Role of AI in Identity Management
33:42 Navigating Mergers and Acquisitions in Tech
39:50 The Future of Identity Security and AI Integration

E62 - Analyst Mashup Episode with Francis Odum, Dave Mahdi and Simon Moffatt
A special mashup episode with fellow analyst Francis Odum. Francis is founder and analyst at Software Analyst Cyber Research and global thought leader on a broad array of cyber topics.
Episode Takeaways
- RSA Conference 2025 review
- AI is a major theme, but many vendors are using it as marketing fluff.
- Identity security is essential for mitigating risks in cybersecurity.
- Data security is increasingly reliant on effective identity management.
- Agentic AI presents both opportunities and challenges for security.
- The need for new identity types for AI agents is emerging.
- AI can automate many security processes, potentially reducing human error.
- The cybersecurity landscape is evolving rapidly, with new threats and solutions.
- Secure by design principles are crucial for future-proofing security measures.
- The industry must adapt to the growing complexity of identity and access management.
Chapters
00:00 Introduction and Conference Reflections
03:04 The Analyst Mashup: Introducing Francis Odum
05:51 Francis Odum's Journey into Cyber Research
08:52 Insights from RSA Conference 2023
11:59 Key Takeaways: AI, Identity, and Data Security
14:56 The Role of Identity in Cybersecurity
18:03 Emerging Themes in Cloud Security and AI
21:00 Challenges in AI Strategy and Budgeting
24:06 Ethics and Accountability in AI Security
26:47 The Future of Agentic AI and Cybersecurity
28:13 The Role of AI in Business and Security
31:35 Emerging Identity Types and Their Implications
35:07 The Need for Pain to Drive Change
39:31 Future Trends in AI and Security
44:15 Platforms vs. Portfolios in Cybersecurity
51:51 Secure by Design: A New Paradigm
53:27 Final Thoughts and Future Conversations

E61 - RSA Conference 2025 Predictions / Security for AI / Funding Rounds for AuthMind, Push Security & UnoSecur
Keywords
RSA Conference, Identity Security, AI in Cybersecurity, Cybersecurity Trends, Identity Management, Funding in Cybersecurity, Observability, AI Security, Cyber Threats, Identity Protection, cybersecurity, identity protection, AI trends, discovery, observability, response strategies, browser security, identity security, ITDR, innovation
Chapters
00:00 Introduction to RSA Conf 2025 and Anticipation
03:01 The Importance of Identity at RSA
05:55 AI's Role in Cybersecurity
08:55 Challenges in AI Security
11:58 Funding Trends in Identity Protection
15:04 Observability in Identity Management
25:31 The Importance of Discovery in Cybersecurity
28:02 Innovative Approaches to Identity Protection
35:12 Emerging Trends in AI and Identity Security
41:03 The Future of AI in Cybersecurity
Links

E60 - SGNL $30m Raise / What is Identity Security / IAM Standards / Behaviour Monitoring
Summary
This episode explores the importance of standards, the role of identity in cybersecurity, and the challenges faced by organizations in managing identity security effectively. The conversation highlights the need for innovation and collaboration in the identity space, as well as the critical nature of identity being an attack surface - especially vendors in the JML firing line. How can behaviour monitoring help?
Keywords
identity security, funding news, leadership changes, market trends, cybersecurity, access management, identity governance, AI in security, standards in identity, identity as a service, identity management, security controls, behavioral analysis, customer experience, identity standards, identity security, digital identity, identity governance, cybersecurity, identity threats
Chapters
00:00 Introduction
03:12 Market News: Funding and Innovations
12:37 Leadership Changes in Identity Security
14:04 The Evolution of Identity Security
24:11 Identity as a Strategic Business Element
25:57 The Security Landscape and Vendor Commitments
28:00 Evolving Security Controls in Identity Management
30:11 Behavioral Analysis: The Missing Piece
32:00 The Strategic Importance of Identity Management
34:03 Identity as a Brand and Customer Experience
35:58 The Maturity of Identity Solutions
37:56 Decoupling User Experience from Identity Security
39:49 Complexity in Identity Standards and Security
44:07 Emerging Threats and the Need for Standards

E59 - Token Security Funding / Jumpcloud + Stack Identity / Identity Data Management
Summary
In this episode of the Analyst Brief Podcast, Simon and Dave return to discuss the latest funding trends in identity security, the rise of non-human identity (NHI), and the importance of governance and data management in identity solutions.
Useful Links:
Keywords
identity security, funding, non-human identity, governance, AI, identity management, chief data officer, AI, identity security, prompt engineering, content authenticity, digital transformation, business opportunities
Chapters
00:00 Introduction and Podcast Evolution
03:04 Funding Trends in Identity Security
08:43 The Rise of Non-Human Identity (NHI)
15:03 Governance and Identity Data Management
23:38 Emerging Trends in Data Technology
26:20 The Role of Chief Data Officers
30:12 AI's Impact on Identity and Security
32:38 Navigating the Challenges of AI and Data Authenticity

E58 - Microsoft SFI / Okta SIC / Funding for Apono, Hydden and P0 Security
Summary
In this episode, Simon and David Mardy discuss the rapidly evolving landscape of identity security, highlighting significant trends, initiatives from major tech companies, and the importance of cyber resilience. They explore the recent funding rounds for startups in the identity space, emphasizing the need for innovative solutions to address ongoing challenges in identity governance and access management. The conversation underscores the critical role of identity security in today's digital business environment and the necessity for organizations to adapt to emerging threats.
Keywords
identity security, access management, cyber resilience, Microsoft, Okta, funding rounds, identity governance, PAM, IGA, cybersecurity
Links
- Microsoft Secure Future Initiative
- Okta Secure Identity Commitment
- Apono $15m funding
- Hydden $4m funding
- P0 Security $15m funding

E57 - Back to School 2024 Episode
Summary
In this episode of the Week in Identity podcast, Simon and David discuss the latest trends and developments in identity security, including market activity, funding rounds, and significant acquisitions. They delve into the importance of NIST guidelines, the rise of non-human identity (NHI), and the implications of recent acquisitions by MasterCard and Salesforce. The conversation highlights the evolving landscape of identity management and the critical need for organizations to adapt to new challenges in cybersecurity.
Chapters
00:00 Introduction to the Week in Identity Podcast
03:52 NIST Guidelines and Identity Assurance
06:30 Aembit Funding Rounds and Non-Human Identity
13:42 Acquisitions in Identity: IndyKite and 3Edges
20:17 MasterCard and Recorded Future
26:39 Salesforce and Own Data

E56 - Emergency Episode Discussing the Global Crowdstrike Issue
Simon and David convene for a special episode to discuss the ongoing global IT outages caused by a Crowdstrike update. Note this was released Friday 19th July 9am PST / 5pm BST

E55 - Identiverse, Identity Week Europe and Gartner SRM
Summary
In this episode, Simon and David discuss the recent identity conferences they attended, including Identiverse and Identity Week. They highlight the growing interest in identity across various industries and the need for resilience and security in identity management. They also delve into the topics of decentralized identity and generative AI, emphasizing the importance of tying security investment to business outcomes and altering the way we think about data and technology. They conclude by mentioning future episodes dedicated to decentralized identity and generative AI.
Keywords
identity conferences, Identiverse, Identity Week, resilience, security, decentralized identity, generative AI, security investment, business outcomes
Takeaways
- Identity conferences have seen a surge in interest from various industries, indicating the growing importance of identity management.
- Resilience and security are crucial in identity management, especially in the face of evolving threats and attacks.
- Decentralized identity and generative AI are emerging topics that require careful consideration and alignment with business goals.
- Security investment should be tied to business outcomes and the specific needs of the organization.
- The identity and security industry is still relatively young and evolving, requiring a shift in thinking and approach.
Links

E54 - CyberArk and Venafi / QRadar and Palo Alto / Akamai and NoName Security
Summary
In this episode, Simon and David discuss recent acquisitions in the identity and access management space, including Palo Alto's acquisition of QRadar, Akamai's acquisition of NoName, and CyberArk's acquisition of Venafi. They explore the importance of resilience in IAM infrastructure and the growing need for managing machine identities and workloads. The conversation highlights the challenges and opportunities in securing non-human identities and the role of PAM in addressing these issues. They also touch on the dark web and identity-based threats.
Keywords
identity and access management, acquisitions, resilience, IAM infrastructure, machine identities, workloads, PAM, non-human identities, dark web, identity-based threats
Takeaways
- Recent acquisitions in the IAM space include Palo Alto's acquisition of Q Radar, Akamai's acquisition of No Name Security, and CyberArk's acquisition of Venafi.
- Managing machine identities and workloads is a growing challenge in the IAM space.
- PAM plays a crucial role in securing non-human identities.
Chapters
00:00 Introduction and Overview
02:40 Recent Acquisitions in the IAM Space
06:02 The Importance of Resilience in IAM Infrastructure
09:12 Managing Machine Identities and Workloads
15:23 The Role of PAM in Securing Non-Human Identities
26:14 Upcoming Presentation at Identiverse

E53 - A Review of RSA Conference 2024 - Part 2
Summary
In this episode, Simon and David discuss the convergence of identity and cybersecurity, particularly in the context of cloud adoption. They explore the challenges and opportunities that arise from this convergence and the impact on organizations of different sizes. They also touch on the confusion caused by the abundance of acronyms in the industry and the need for clarity and standardization. Overall, they emphasize the importance of protecting identity components and the critical role of identity in security. The conversation explores the challenges and opportunities in the identity and access management (IAM) space, with a focus on the importance of data management and the need for effective discovery and remediation processes. The fragmentation of identity systems and the lack of visibility into identities and their interactions are identified as key issues. The acquisition of Q Radar by Palo Alto is discussed as a potential game-changer in the IAM space. The conversation concludes with the recognition that while automation and AI have their place, human involvement is still crucial for effective remediation.
Keywords
identity, cybersecurity, convergence, cloud, challenges, opportunities, acronyms, standardization, protection, security, identity and access management, IAM, data management, discovery, remediation, fragmentation, visibility, Q Radar, Palo Alto, automation, AI, human involvement
Takeaways
Identity and cybersecurity are converging, particularly in the context of cloud adoption.
Organizations of different sizes face different challenges and opportunities in managing identity and security.
The abundance of acronyms in the industry can be confusing, and there is a need for clarity and standardization.
Protecting identity components is crucial, as identity often plays a central role in security breaches. Effective data management is crucial in the identity and access management space.
Fragmentation of identity systems and lack of visibility into identities and their interactions are key challenges.
The acquisition of Q Radar by Palo Alto has the potential to impact the IAM space.
While automation and AI have their place, human involvement is still necessary for effective remediation.
Chapters
00:00 Introduction and Post-RSA Recovery
01:23 Unpacking the Convergence of Identity and Cybersecurity
07:13 Lessons from the Transition from Horses to Cars
09:08 The Confusion of Acronyms and the Need for Clarity
13:25 The Hype Cycle and the Trajectory of New Technologies
15:16 The Impact of Cloud Adoption on Identity and Security
23:21 The Transient Tilt in the Cloud and the Importance of Protecting Identity Components
24:13 The Importance of Data Management in IAM
27:38 Challenges of Fragmentation and Lack of Visibility
30:53 The Potential Impact of the Q Radar Acquisition
34:44 The Role of Automation and Human Involvement in Remediation

E52 - A Review of RSA Conference 2024 - Part 1
Summary
In this episode, Simon and David discuss their experiences at the RSA Conference 2024 and highlight the key themes and trends in the identity and access management (IAM) space. They emphasize the growing importance of identity in the security landscape and the increasing integration of identity into RSA. They also discuss the impact of AI and Gen AI on IAM, the need for better discovery and visibility in identity systems, and the challenges of transitioning from legacy technology to new, intelligent systems. They conclude by highlighting the importance of preparing data for the Gen AI world and the need for organizations to adapt and embrace new technologies in order to stay competitive.
Keywords
RSA Conference, RSAC2024, identity and access management, IAM, security, AI, Gen AI, discovery, visibility, legacy technology, data preparation, competitive advantage
Takeaways
Identity is becoming increasingly important in the security landscape, and RSA is a key event for identity professionals.
The integration of identity into themes and topics at RSAC2024 is a reflection of the growing significance of identity in the industry.
AI and Gen AI are driving the need for more intelligent identity systems and the transition from legacy technology.
Discovery and visibility are crucial in identity systems, and organizations need to break down silos and integrate their identity infrastructure.
Preparing data for the Gen AI world is essential for organizations to stay competitive and take advantage of new technologies.
Chapters
00:00 Introduction and Overview of RSA Conference
13:02 The Growing Importance of Identity in the Security Landscape
21:03 Challenges of Transitioning from Legacy Technology to New, Intelligent Systems
25:01 The Impact of AI and Gen AI on IAM
31:05 Preparing Data for the Gen AI World
33:30 Preview of Next Episode on Fraud and Cloud

E51 - Microsoft Entra External IDs / Cisco and StrongDM / CEO view on Cyber
This week Simon and David return with a weekly dose of industry analysis on the global identity and access management space. First up a discussion on Microsoft announcing the GA of their Entra for External IDs - who is it aimed at? Is it ground breaking? Next up is Cisco who announced an investment round into next-gen PAM provider StrongDM. Finally they discuss a great interview by Standard Chartered CEO Bill Winters and his view of cyber in the board and its strategic value.

E50 - BeyondTrust and Entitle / Cisco Duo breach and Hypershield launch / CSPM+NHI / SecureAuth new CEO
This week hosts Simon and David review a range of topical news events in the global identity and access management space. First up BeyondTrust have a definitive agreement with Entitle to combine up PAM and IGA. Cisco appear twice..once regarding a breach on Duo MFA service and another regarding their new solution launch - the Hypershield. A discussion on definitions before a quick comment on the new CEO at SecureAuth.

E49 - The IAM and Fraud Episode
After a small spring break, Simon and David return with a special episode focused on the convergence of identity and access management and fraud. Why the convergence? How to measure success? What are the three 'V's' as they relate to fraud? How should people and process adapt to keep up with technology changes? And how to thwart the asymmetric advantage of the fraudster?

E48 - NIST CSF 2.0 / Nightdragon CISO Spend Report / PAM + IGA Convergence
This week Simon and David tackle several topics in the governance space - how NIST Cyber Security Framework got a rev to v2.0, with the addition of a governance stage, are Privileged Access Management and Identity Governance & Administration convergence and a review of some CISO spending habits by investment firm Nightdragon.

E47 - The Data Security Episode
This week Simon and David have a mini-deep dive on data security. Data storage locations are changing. Organisations are harvesting PII, transaction and payment data continually being collected. And what about disinformation and misinformation? What role does identity have here? What about data and deepfakes for onboarding and biometrics? What does data access governance meanin 2024? Is data integrity protection the biggest issue within cyber today? How should we handle fine grained and contextual access and how do the CISO and Chief Data Officer relate?

E46 - SecureAuth acquire Cloudentity / Entrust to acquire OnFido / Cisco announces Identity Intelligence / Mastercard Emerging Trends
This week Simon and David focus on a new raft of pending acquisitions. They discuss the impact of SecureAuth and Cloudentity joining forces as well as news that Entrust are in talks to buy OnFido. They also cover the announcement that Cisco has launched a new Identity Intelligence offering hot on the back of acquiring ITDR vendor Oort in 2023. They finish up by taking a look at an emerging technology trends report released by Mastercard. Is Data security the next big IAM integration story?

E45 - Okta Layoffs / Tech Downturn / Market Consolidation
This week Simon and David take a look at the recent announcement that Okta are laying off 400 staff globally. Is this part of a broader tech slow down? They discuss some of the trends from 2023 with respect to staff attrition and the impact that has had. With funding still high for IAM and cyber what does 2024 have in store?

E44 - World Economic Forum Cybersecurity 2024 Outlook Report Review
This week Simon and David review the 40 page Global Cybersecurity Outlook 2024 report released by the World Economic Forum.
This report covered 49 countries with over 200 respondents from a range of organisations. The report covered cyber resilience, inequity, emerging technologies such as generative AI, the role of cyber regulations, how to engage strategic leaders with respect to cyber risk and strategy and the role of changing geopolitical tensions and the impact on private sector cyber risk.

E43 - 2024 Predictions / ITDR Acquisition Discussion / IAM and Cyber Mashup
The first episode of 2024 sees Simon and David analyse the recent spate of IDTR and ISPM acquisitions including:
Cisco's 2023 purchase of Oort;
Okta's acquisition of Spera Security;
Delinea's acquisition of Authomize.
What do those acquisitions have in common? Will there be more? Is cyber and IAM now becoming one thing? Other predictions include consolidation within passwordless authentication, the rise of workload identity.

E42 - Blackhat 2023 London Review / Is the CISO role too tough? / Imprivata new CEO
This week Simon and David review the recent Blackhat EMEA 2023 event that was held in London. They discuss the recent CEO change at Imprivata - and what means for their plans going forward. With respect to Blackhat they discuss the role of the CISO - is it becoming difficult to hire and be successful? Other Blackhat topics included a keynote by the UK's NCSC CTO discussing the asymmetric adversarial threat, password managers on mobile and how they "Autospill" credentials, the tampering of patient records and is data integrity now more important than confidentiality?
The Cyber Hut Blackhat review is here.

E41 - Okta Breach Part II / Okta Q3 Results / Bookings.com Attack
This week Simon and David return to Okta - to uncover more about details on their recent breach. They also discuss their recent Q3 results and are Microsoft their only competitor? They also discuss a recent complex attack involving customers of Booking.com - and cover push payment fraud, ATO, complex supply chains and protecting trust boundaries.

E40 - Forrester SRM Washington / Ping Youniverse London / Okta Breach
After a couple of weeks off, Simon and David return for an hour long special. They review the recent Security and Risk Management event in Washington DC hosted by Forrester where the topic of identity and cyber convergence appeared. They comment on the recent Okta breach and what that means for the world of complex software supply chain attacks and the rise of identity security, ITDR and identit security posture management. They also review the London version of the Ping Identity Youniverse series of events.

E39 - The FIDO Authenticate 2023 Lookback Episode
This week Simon and David were in sunny Carlsbad, San Diego for the latest Authenticate conference hosted by the FIDO Alliance. In this episode they review the main topics of the event, taking a look at passkey deployment maturity, KPIs, biometrics, threat models, adoption patterns as well as orthogonal topics such as machine identity, crypto agility, IDV + converged identity assurance.

E38 - The NSA + CISA Top 10 Cyber Security Misconfigurations Episode
This week Simon and David take a deep dive look at a recent cyber security advisory that was released by the NSA and CISA recently. This top 10 list covers a range of issues from default credentials, excessive permissions, a lack of networking monitoring and segmentation as well a lack of MFA and poor credential management. Simon and David apply their identity lens to the top 10 and what it may mean for your organisation.

E37 - MGM Cyber Attack / Part II on ForgeRock and Ping
This week Simon and David return to discuss a recent cyber attack against the hospitality chain MGM resorts - that leveraged social engineering, credential theft and more. Are attacks against complex digital entities now standard practice? They also return for part II of the ForgeRock and Ping Identity integration and discuss a recent article by David and a market choice poll by The Cyber Hut.

E36 - Tenable acquires Ermetic / Cisco acquires Oort / ForgeRock and Ping to combine / Okta attack
After the summer recess, Simon and David return for another Week in Identity catch-up. This week...heavily influenced by some recent acquisition activity...they discuss Tenable buying CNAPP/CIEM provider Ermetic, a rewind to Cisco buying ITDR vendor Oort and a detailed discussion on the uncertainties surrounding Thoma Bravo adding ForgeRock to their stable. They also discuss the further rise of Identity Security and a recent release by Okta's Defensive Cyber Operations team on a recent attack.

E35 - The SEC Cyber Risk Management Rules Episode
This week the US Security and Exchanges Commission announced rules requiring organisations to handle cyber breach notifications, risk management and expert cyber personnel in a different way. Simon and David delve into the implications of this. Why have organisations been reluctant to notify on breaches historically? A lack of detection? A lack of incident response playbooks? A lack of expert personnel? What is the end goal of such regulation? What will success look like in the short and long terms? Clearly a move towards a more risk based approach is the ideal outcome but why has the market failed for cyber security? What are the three V's of threats?

E34 - Thoughts on Kevin Mitnick / Cisco buying Oort / ITDR problem space / Are Microsoft en-route to monopolising IAM?
This week Simon and David discuss the recent acquisition of Oort by Cisco, which finds them discussing the entire ITDR space - who is the buying persona and what problems will it solve? As always technology isn't always the answer and we mustn't forget the human element. They answer an audience question focused on Microsoft - and will they start to dominate the IAM space? They also remember the passing of hacking pioneer Kevin Mitnick.

E33 - An interview with Eric Olden from Strata.io
This week there is a special guest on the podcast. Eric Olden CEO at Strata joins Simon for a discussion. They cover a broad and meandering set of topics focused on Eric's journey to being a multi-company founder (his first startup was at age 23..), contributing to the SAML specification and how he is now focused on identity orchestration at Strata. What is orchestration? Why is it needed and how the rise of the hybrid cloud landscape is here to stay. They deep dive into IDQL, identity integration recipes and how the rise of the AI co-pilot may save us all.

E32 - N0Auth Vulnerability / Infosec 2023 London - Data Integrity / Cyber + IAM Mashups / The Rise of Fraud / Generative AI (good and bad)
This week Simon and David took a meandering look at the last weeks most eye catching events in the world of identity. They had a quick recap of Infosec 2023 held at the eXcel in London, where the topic of data level encryption, data origin authentication and integrity caught Simon's eye. They discussed a recent vulnerability found in deployments on OIDC in the Microsoft world as uncovered by Descope called NOAuth - which essentially was caused by poor verificaiton of OIDC id token claims. They finished off by discussing the world of generative AI and how that is impacting the world of fraud, content, biometrics, misinformation and more...

E31 - An interview with HYPR CEO Bojan Simic
This episode, sees The Week in Identity have another specialist guest: Bojan Simic, Co founder and CEO of passwordless specialists HYPR. Simon and Bojan delve into Bojan's story from being a computer science graduate to entering the security world pen-testing in New York and working with some of the world's largest financial services institutions. From there the inspiration to rid the world of passwords started to take hold...and ten years later, seeing HYPR as a leading passwordless authentication provider. The topic covers a range of fascinating subjects, from the perfect storm of FIDO, mobile biometrics and secure hardware storage, through to how to create strategies for mass passwordless adoption based on nudge-theory, gamification and stakeholder buy-in. They also cover success criteria, AI and what the future may hold for IAM...

E30 - Identiverse 2023 / Gartner Security & Risk Management USA / Passkeys / Minimum Effective Models...
This week Simon and David discuss the recent Identiverse conference as well the Gartner Security Risk Management summit that happened shortly afterwards. They delve into the world of passkeys (again), verifiable credentials and modern architectures and how we're moving to an industry education maturity model, where organisations are going beyond knowing what a technology is, to how to get started and derive value. They also discuss the concept of "minimum effectiveness" as it pertains to technology, expertise, friction and insights and that essentially having too much identity and access management "stuff" is often a precursor to complexity and failure.

E29 - Identity Mesh and Identity Fabric / Heliview IAM Conference Review / Cyber + Identity Mashup / People, Process and Technology / IAM Threat Reports
This week Simon and David review the recent Heliview IAM Conference that took place in the Netherlands. The main topic for the day was the rise of the identity fabric (or mesh) and how this can enable the modern organisation with a range of agile IAM components that supports both business and security use cases. Simon presented a keynote on the future of IAM - using some research from The Cyber Hut focusing on where IAM may look like in 2028 and beyond...
They also discussed the need for people, process and technology integration, in order to map the existing IAM landscape to future investment and metrics.
They finish off by discussing the rise in cyber threat reports that have emerged in the past month that all have a very strong reliance on IAM - and why ITDR is a process not a product.
Cyber Threat Reports:
- Joint Cyber Advisory: People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
- CISA Advisory: Hunting Russian Intelligence “Snake” Malware
- Permiso Security: Unmasking GUI-Vil - Financially Motivated Cloud Threat Actor

E28 - The RSA 2023 Episode - Passkeys / MFA / Adversary in the Middle / Collaboration / Standards
This week Simon and David review the recent RSA Conference that occurred at the end of April over in San Francisco. From the generic meta-patterns at the conference covering themes such as collaboration, standards, multi-cloud and technology integration, through to more IAM focused conversations covering MFA, passkeys and authentication attacks. Are passkeys now here to stay? What will help adoption? Will attacks on passkeys start to increase along with usage rates? Will attacks against existing MFA forms including SIM swap, MFA fatigue and social engineering be a compelling event to improve adoption?

E27 - RadiantLogic & Brainwave / New Styra CEO / Auth0 OpenFGA project / Chief Identity Officers / AuthZ as part of ZT
This week Simon and David tackle a range of news items including: Radiant Logic completing the acquisition of IGA vendor Brainwave; Authorization vendor Styra getting a new CEO and Auth0 (by Okta) releasing v1.0 of a new open source authorization project called OpenFGA. They also tackle the question of whether we need to see Chief Identity Officers in the board room and how zero trust is essentially driving the demand for authorization platforms.

E26 - Interview with Alex Bovee from ConductorOne
In this week's episode, Simon and David are joined by Alex Bovee the CEO of https://www.conductorone.com/ - a next generation identity security and IGA provider. They cover a range of topics including the adoption of cloud services and the impact on security, the cloud shared security model, the left shifting of identity risk from being detection focused to preventative, reducing access reviews to focus on exceptions only, how the security world is taking on more IAM capabilities and knowledge and the introduction of a new open source project called Baton - to extract and manage identity data.