The Analyst Brief

The Analyst Brief

By The Cyber Hut

"The Analyst Brief" provides expert and impartial commentary and analysis on the global identity and cyber security markets - with an eye on emerging technology and trends. Hosts Simon Moffatt (Founder at The Cyber Hut) and David Mahdi (ex-Gartner Analyst and C-level Advisor) provide deep dive comment and opinion on some of the most exciting technology trends.

For more information on The Cyber Hut visit www.thecyberhut.com/
Available on
Amazon Music Logo
Spotify Logo
Currently playing episode

E18 - 2022 Year in Review Quiz

The Analyst BriefDec 23, 2022
00:00
44:05
E75 - Identiverse 2026: Agentic AI, NHI Security & the Future of Identity Platforms

E75 - Identiverse 2026: Agentic AI, NHI Security & the Future of Identity Platforms

Jun 30, 202653:28
E74 - The Rise of Agentic AI: Risks and Opportunities

E74 - The Rise of Agentic AI: Risks and Opportunities

In this episode, Simon Moffatt and David Mahdi explore the evolving landscape of AI, trust, and cybersecurity. They discuss how AI amplifies vulnerabilities, the importance of trust and integrity, and the future of agentic AI in security and identity management.


Keywords

AI, cybersecurity, trust, deepfakes, agentic AI, identity verification, zero trust, content verification, threat modeling, security architecture


Topics

AI amplification of vulnerabilities

Trust and trustworthiness in security

Deepfakes and content verification

Agentic AI and intent management

Dynamic risk and trust models


Chapters

00:00 Introduction and AI's Pervasiveness

00:56 AI in Daily Life and Tools Used

02:07 AI in Product Management and Content Creation

03:25 Deepfakes and Content Manipulation

05:14 Technical Solutions for Deepfake Verification

06:54 Voice Fakes and Generative Content

08:24 Human vs Machine Identity Trust

09:55 Future of Trust and Assurance in AI

12:05 Hardware Trustworthiness and Dynamic Trust Models

15:23 Evolving Identity and Trust Frameworks

20:09 AI-Driven Policy and Access Control

22:01 Agentic Ownership and Behavior

25:19 Explicit Goals and Intent in AI Agents

28:53 Risk, Scope, and Drift in AI Actions

33:20 Objective Clarity and Hierarchies of Intent

40:27 Information Flow and End-to-End Security

44:12 Coordination and Collective Defense

50:08 Dynamic Trust and Risk Management

53:46 Future-Proofing Security with AI

56:01 Conclusion and Future Outlook





Jun 04, 202659:56
E73 - Market News: Cisco + Astrix Security, Silverfort + Fabrix

E73 - Market News: Cisco + Astrix Security, Silverfort + Fabrix

This episode explores the latest trends in identity security, machine identity, and the strategic moves by major players like Cisco and Silverfort. We discuss acquisitions, the evolution of identity platforms, and the impact of AI on security decision-making.


Keywords

Identity Security, Machine Identity, Cisco, Silverfort, Asterix Security, AI, Cybersecurity, Mergers and Acquisitions, NHI, Identity Control Plane


Chapters


00:00 Introduction and Current Events in Identity Space

02:41 Cisco's Acquisition of Astrix Security

05:44 The Strategic Importance of Machine Identity

08:37 Market Dynamics and Competitive Landscape

11:48 The Future of Identity Management

14:36 The Role of AI in Identity Solutions

17:44 Challenges in the Current Market

20:54 The Impact of Vibe Coding on Development

23:36 Conclusion and Future Outlook

26:00 Navigating the Landscape of AI and Team Dynamics

27:38 The Evolution of Identity Security and Governance

29:21 Acquisitions in the Identity Security Space

31:48 The Role of AI in Identity Governance

36:54 The Future of Authorization and Decision-Making

44:33 Intent and Attribution in Cybersecurity

51:59 The Impact of AI Agents on Privacy and User Experience








May 18, 202653:49
E72 - Mythos and a Vulnerability Revolution / Review of IAM Tech Day

E72 - Mythos and a Vulnerability Revolution / Review of IAM Tech Day

Keywords#cybersecurity, #identity #security, #ai #vulnerabilities, #Mythos, #resilience, #vulnerability management, #zerotrust , agent security, cyber innovationChapters00:00 Introduction and Event Overview03:08 Insights from IAM Tech Day in Sao Paulo05:50 The Role of Vendors and Practitioners in Identity Security08:57 Exploring Vulnerabilities and Mythos Project11:40 The Impact of AI on Vulnerability Management14:46 The Future of Cybersecurity and the CISO Role27:22 Building Resilience in Cybersecurity29:46 The Evolution of Cybersecurity Practices32:19 Understanding Business Resilience34:45 The Human Element in Cybersecurity39:26 AI and the Future of Cybersecurity42:17 Agentic Technology and Its Implications

May 11, 202657:21
E71 - A Review of RSAC 2026

E71 - A Review of RSAC 2026

RSAC 2026, Conference, AI trends, cybersecurity, identity security, investment, technology, innovation, compliance, vendor landscape, digital transformation

Summary

In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss their experiences and insights from the RSAC 2026 Conference. They explore the overwhelming presence of AI in cybersecurity discussions, the evolving role of identity security, and the challenges of AI reliability. The conversation also touches on investment perspectives in the AI landscape and the future dynamics of cybersecurity companies, emphasizing the need for clarity and innovation in a rapidly changing environment.

Sound Bites


"AI is everywhere at RSA this year."

"Identity security is the control plane."

"We need to cut through the AI noise."

"AI is not all the same."

"The models hold the cards right now."

"AI will disrupt and add value."


Chapters

00:00 RSAC Conference Overview

02:57 AI Trends and Observations

06:02 The Role of Identity in Cybersecurity

09:11 Challenges with AI Reliability

12:01 Investment Perspectives on AI

15:10 Future of Cybersecurity Companies

18:06 The Impact of AI on Cybersecurity Dynamics

21:05 Concluding Thoughts on AI and Cybersecurity


Apr 02, 202632:48
E70 - What impact will AI Browsers have on IAM?

E70 - What impact will AI Browsers have on IAM?

The Future of Browsers, AI Agents, and Cybersecurity

Key Topics

  • Insights from the recent FSI SAC, Gartner Identity Summit, and upcoming RSA Conference
  • How consumer browsers equipped with AI agents are transforming user experiences
  • The evolution of search engines into AI-powered agents and their implications
  • Security challenges associated with agentic AI and fraud detection
  • The shift from enterprise product-centric identity systems to platform-based identity fabrics
  • The role of identity in B2C, B2E, and the impact of outside-in and inside-out models
  • Future trends in digital identity, including multi-personas, personas, and the role of digital employees and agents
  • The influence of consumer tech innovation on enterprise security and identity strategies
  • Practical considerations for securing agentic AI and managing associated cyber risks



Mar 19, 202645:42
E69 - The Rise of IAM Resilience - Why Semperis is acquiring MightyID

E69 - The Rise of IAM Resilience - Why Semperis is acquiring MightyID

Keywords

identity, cybersecurity, acquisitions, resilience, AI, identity providers, OpenClaw, regulatory implications, consumer experience, employee experience


Summary

In this episode of the Analyst Brief podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity management and cybersecurity, focusing on recent acquisitions, the importance of cyber resilience, and the convergence of identity and cybersecurity. They explore the implications of identity providers, regulatory challenges, and the impact of AI innovations, particularly the new tool OpenClaw. The conversation emphasizes the need for organizations to prioritize identity resilience and security as they navigate the evolving digital landscape.


Takeaways


  • The identity space is experiencing significant acquisition activity.
  • Cyber resilience is becoming increasingly important in identity management.
  • Identity is more than just the IDP; it plays a critical role in security.
  • If an IDP is unavailable, it can severely impact business operations.
  • The convergence of identity and cybersecurity is a growing trend.
  • Organizations need to focus on identity resilience to ensure service availability.
  • Regulatory implications are becoming more significant in the identity space.
  • AI innovations are rapidly changing the landscape of identity management.
  • OpenClaw represents a new approach to productivity but raises security concerns.
  • The future of identity management will require a balance between innovation and security.


Chapters


00:00 Introduction and Current Events

01:22 Acquisitions in the Cybersecurity Space

05:35 The Importance of Identity Resilience

11:24 Convergence of Identity and Cybersecurity

18:10 Regulatory Implications and Future Outlook

22:52 Navigating Identity Lifecycle and Governance

26:37 The Role of AI in Identity Management

29:56 Exploring OpenClaw and Its Implications

42:19 The Future of AI and Security Challenges


Feb 11, 202646:46
E68 - Delinea and StrongDM, the rising role of AI in identity, further market consolidation

E68 - Delinea and StrongDM, the rising role of AI in identity, further market consolidation

Keywords


identity management, cybersecurity, acquisitions, AI, conferences, CrowdStrike, PAM, market trends, technology, security, Delinea, StrongDM


Summary


In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity management and cybersecurity, including upcoming conferences, recent acquisitions, and the evolving role of AI in the industry. They explore the challenges organizations face with technical debt and the need for better resolution in identity management. The conversation also touches on CrowdStrike's recent developments and the importance of ecosystem partnerships in navigating the complex landscape of identity management.


Takeaways


  • RSA Conference is a key event for industry professionals.
  • Delinia's acquisition of Strong DM highlights market consolidation.
  • Identity management is increasingly recognized as a control plane.
  • AI is becoming integral to identity management solutions.
  • Technical debt poses significant challenges for organizations.
  • The identity management landscape is evolving rapidly.
  • Ecosystem partnerships are crucial for smaller vendors.
  • Vendors need to clearly differentiate their offerings.
  • The future of identity management will involve more dynamic solutions.


Chapters

00:00 Introduction

02:54 Upcoming Conferences and Industry Events

05:49 Market Changes: Acquisitions and Mergers

11:43 The Evolution of Identity Management

17:40 The Future of Identity Control Plane

25:07 Leveraging Identity Solutions

26:22 The Role of Identity in Business Agility

28:09 Understanding Information Asymmetry in Business

29:30 The Need for Speed in Identity Management

31:51 Conceptualizing Identity Management

33:16 Addressing Technical Debt in IAM

35:21 AI's Role in Modernizing Identity Infrastructure

38:09 Vendor Narratives and Market Confusion

41:11 Ecosystem Partnerships in Identity Management

43:39 CrowdStrike's New Partnership with Natoma


Jan 30, 202653:15
E67 - CrowdStrike & SGNL Acquisition - and 2026 market consolidation outlook

E67 - CrowdStrike & SGNL Acquisition - and 2026 market consolidation outlook

KeywordsCybersecurity, Identity Security, CrowdStrike, SGNL Acquisition, Zero Trust, Trust in Technology, ITDR, NHI, PAM, Digital TrustSummaryIn this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the rapid changes in the cybersecurity landscape as they enter the new year. They delve into CrowdStrike's recent acquisition of SGNL, exploring its implications for identity security and competition in the market. The conversation highlights the importance of trust in cybersecurity, the evolution of zero trust frameworks, and the anticipated trends in identity security and consolidation within the industry. The hosts emphasize the need for organizations to establish and maintain trust while navigating the complexities of modern cybersecurity challenges.TakeawaysThe cybersecurity landscape is evolving rapidly with new acquisitions.CrowdStrike's acquisition of SGNL marks a significant shift in identity security.Trust is becoming a central theme in cybersecurity discussions.Zero trust is evolving into a more integrated approach to security.Organizations need to focus on end-to-end trust in their cybersecurity strategies.The market is seeing increased consolidation in identity security solutions.Identity security is now a critical component of overall cybersecurity strategy.The role of procurement in technology decisions is often underestimated.Emerging technologies are reshaping the identity security landscape.The year ahead promises significant developments in trust and security. Chapters00:00 Welcome and New Year Reflections01:41 The Rapid Evolution of Identity Security02:10 CrowdStrike's Acquisition of SGNL04:54 The Impact of SGNL on CrowdStrike's Strategy08:09 Competition in the Identity Security Space11:58 The Role of Identity in Cybersecurity21:46 The Future of Identity Security and Zero Trust26:31 The Evolution of Zero Trust in Cybersecurity29:07 The End of the Beginning: Zero Trust Maturity30:32 Trust in a Non-Trusted World34:12 The Shift from Zero Trust to Digital Trust38:32 End-to-End Trust: A New Paradigm42:44 Consolidation Trends in Identity Security50:06 The Future of Acquisitions in Cybersecurity

Jan 14, 202652:31
E66 - Review of Gartner IAM Texas, Blackhat Europe, Saviynt $700M funding and 2026 predictions

E66 - Review of Gartner IAM Texas, Blackhat Europe, Saviynt $700M funding and 2026 predictions

Keywords

identity, cybersecurity, AI, Gartner, conferences, funding, innovation, resilience, OWASP, predictions


Summary

In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity and cybersecurity, reflecting on recent conferences, particularly the Gartner Identity Conference. They explore the evolving role of identity in organizations, the impact of AI, and the importance of resilience in supply chains. The conversation also touches on funding dynamics in the identity space, the challenges of innovation versus reliability, and the newly released OWASP Top 10 for Agentic AI. As they look ahead to 2026, they share predictions about the future of identity and the cybersecurity landscape.


Takeaways

Identity is becoming increasingly central to cybersecurity strategies.

The Gartner Identity Conference highlighted key trends in identity management.

AI is reshaping the identity landscape but hasn't introduced new business models yet.

Organizations need to focus on resilience in their identity systems.

Funding in the identity space is shifting, with significant investments being made.

Innovation in identity solutions must balance reliability and customer needs.

The complexity of supply chains poses challenges for identity management.

OWASP's Top 10 for Agentic AI emphasizes the importance of identity in AI security.

2025 has been a pivotal year for identity, with increased attention and funding.

Organizations should start small and automate basic identity management tasks.


Sound bites


"Identity is at the core."

"Identity is foundational."

"Phishing isn't fixed."


Chapters

00:00 Introduction and Festive Greetings

02:04 Conferences and Events: Insights from Black Hat Europe

04:38 Gartner Identity and Access Management Conference Overview

09:32 Emerging Trends in Identity Management

12:47 Identity as Core Infrastructure

17:48 The Future of Identity in Cybersecurity

23:39 Funding and Market Trends in Identity Solutions

28:08 Navigating Customer Satisfaction and Market Dynamics

29:32 The Shift from Hypergrowth to Profitability

31:53 Investment Strategies and Market Positioning

33:37 Innovation vs. Reliability in Established Companies

36:57 The Role of Innovation Across Business Functions

38:44 The Importance of Identity in Cybersecurity

40:03 Supply Chain Vulnerabilities and Interdependencies

44:26 Resilience and Recovery in Cybersecurity

48:07 The Need for Investment in Incident Response

49:31 Privacy Challenges in the Digital Age

51:30 OWASP Top 10 for Agentic AI

55:37 Predictions for 2026: AI and Cybersecurity Trends


Dec 17, 202501:03:19
E65 - ConductorOne funding, Ping + Keyless, JumpCloud + Breez Security, Imprivata + Verosint, Twilio + Stytch

E65 - ConductorOne funding, Ping + Keyless, JumpCloud + Breez Security, Imprivata + Verosint, Twilio + Stytch

Summary

In this episode of the Analyst Brief podcast, Simon Moffatt and David Mahdi discuss the latest trends in identity security, including recent funding rounds and acquisitions. They explore the growing importance of identity governance, the intersection of security and identity management, and the role of trust in the age of AI. The conversation also touches on the significance of ITDR and the implications of recent acquisitions for the market. The hosts reflect on the future of identity security and the need for continuous innovation in this evolving landscape.

Chapters

00:00 Introduction to the Analyst Brief Podcast

03:03 Autumn Conference Season Insights

06:05 Funding and Acquisitions in Identity Governance

08:59 The Growing Complexity of Identity Governance

12:01 The Intersection of Security and Identity

14:49 The Future of Cybersecurity and Identity Integration

17:42 Understanding the Broader Ecosystem of Cybersecurity

21:04 The Importance of Protecting All Identities

23:53 First Principles in Cybersecurity Strategy

29:10 Navigating Resilience and Availability in Security

29:56 Funding Trends in Identity Security

31:45 The Impact of Acquisitions on Identity Security

32:13 Twilio's Acquisition of Stitch: A New Era in Identity

36:33 Building Trust in the Age of AI

39:21 Zero Trust: Establishing and Maintaining Trust

44:14 Ping Identity's Acquisition of Keyless: Innovations in Biometric Authentication

55:11 JumpCloud Acquires Breeze Security: Enhancing ITDR Solutions

59:54 Improvata's Strategic Moves in Identity Security


Keywords

identity security, funding, acquisitions, AI, trust, governance, ITDR, cybersecurity, authentication, market trends



Nov 13, 202501:05:44
E64 - The Growing Impact of Digital Dependency

E64 - The Growing Impact of Digital Dependency

Keywords

AWS outage, digital dependency, business continuity, FIDO, authentication, passkeys, digital certificates, threat informed defense, false positives, cyber resilience


Summary

In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the recent AWS outage and its implications on digital dependency and business continuity. They explore the importance of disaster recovery plans and the evolving landscape of authentication technologies, particularly focusing on the FIDO Authenticate Conference. The conversation delves into the lifecycle of passkeys and digital certificates, emphasizing the need for threat-informed defense strategies and the challenges of managing false positives in security. The episode concludes with a call for better integration of systems and shared intelligence across the industry.


Chapters


00:00 Introduction and Global Outage Discussion

03:01 The Impact of Digital Dependency

06:00 Business Continuity and Disaster Recovery

09:10 FIDO Authenticate Conference Overview

16:09 Evolution of Authentication Technologies

21:45 The Lifecycle of Passkeys and Digital Certificates

29:59 Threat Informed Defense and False Positives

39:55 Conclusion and Future Considerations


Oct 21, 202551:44
E63 - Are Identity Platforms Legacy? The Rise of Identity Information Flows

E63 - Are Identity Platforms Legacy? The Rise of Identity Information Flows

Keywords

PAM, IGA, CyberArk, Palo Alto, identity security, AI, machine identity, cybersecurity, information flows, behavioral analysis


Summary


In this episode of the Analyst Brief Podcast, Simon Moffatt and David Mahdi discuss the significant changes in the cybersecurity landscape, particularly focusing on Privileged Access Management (PAM) and Identity Governance and Administration (IGA). They explore the recent acquisition of CyberArk by Palo Alto, the evolution of identity security, and the convergence of various identity management solutions.

The conversation highlights the importance of information flows, and the need for a mindset shift in the industry to effectively address identity security challenges.


Takeaways


  • The cybersecurity landscape is rapidly changing due to AI.
  • PAM and IGA are evolving but remain siloed.
  • The acquisition of CyberArk by Palo Alto signifies a shift in identity security.
  • Organizations struggle with integrating disparate identity technologies.
  • Behavioral analysis is crucial for identifying security threats.
  • AI will play a significant role in optimizing identity security.
  • Defensive acquisitions are common in the cybersecurity industry.
  • The future of identity security relies on understanding information flows.


Chapters


00:00 Welcome Back and Industry Changes

02:01 The Evolution of Privileged Access Management (PAM)

10:41 The Convergence of Cybersecurity and Identity

16:13 The Future of Identity Management Platforms

24:23 Understanding Information Flows in Cybersecurity

28:12 The Role of AI in Identity Management

33:42 Navigating Mergers and Acquisitions in Tech

39:50 The Future of Identity Security and AI Integration


Oct 10, 202549:30
E62 - Analyst Mashup Episode with Francis Odum, Dave Mahdi and Simon Moffatt

E62 - Analyst Mashup Episode with Francis Odum, Dave Mahdi and Simon Moffatt

A special mashup episode with fellow analyst Francis Odum. Francis is founder and analyst at Software Analyst Cyber Research and global thought leader on a broad array of cyber topics.


Episode Takeaways

  • RSA Conference 2025 review
  • AI is a major theme, but many vendors are using it as marketing fluff.
  • Identity security is essential for mitigating risks in cybersecurity.
  • Data security is increasingly reliant on effective identity management.
  • Agentic AI presents both opportunities and challenges for security.
  • The need for new identity types for AI agents is emerging.
  • AI can automate many security processes, potentially reducing human error.
  • The cybersecurity landscape is evolving rapidly, with new threats and solutions.
  • Secure by design principles are crucial for future-proofing security measures.
  • The industry must adapt to the growing complexity of identity and access management.


Chapters

00:00 Introduction and Conference Reflections

03:04 The Analyst Mashup: Introducing Francis Odum

05:51 Francis Odum's Journey into Cyber Research

08:52 Insights from RSA Conference 2023

11:59 Key Takeaways: AI, Identity, and Data Security

14:56 The Role of Identity in Cybersecurity

18:03 Emerging Themes in Cloud Security and AI

21:00 Challenges in AI Strategy and Budgeting

24:06 Ethics and Accountability in AI Security

26:47 The Future of Agentic AI and Cybersecurity

28:13 The Role of AI in Business and Security

31:35 Emerging Identity Types and Their Implications

35:07 The Need for Pain to Drive Change

39:31 Future Trends in AI and Security

44:15 Platforms vs. Portfolios in Cybersecurity

51:51 Secure by Design: A New Paradigm

53:27 Final Thoughts and Future Conversations


May 14, 202556:38
E61 - RSA Conference 2025 Predictions / Security for AI / Funding Rounds for AuthMind, Push Security & UnoSecur
Apr 25, 202548:14
E60 - SGNL $30m Raise / What is Identity Security / IAM Standards / Behaviour Monitoring

E60 - SGNL $30m Raise / What is Identity Security / IAM Standards / Behaviour Monitoring

Summary

This episode explores the importance of standards, the role of identity in cybersecurity, and the challenges faced by organizations in managing identity security effectively. The conversation highlights the need for innovation and collaboration in the identity space, as well as the critical nature of identity being an attack surface - especially vendors in the JML firing line. How can behaviour monitoring help?


Keywords

identity security, funding news, leadership changes, market trends, cybersecurity, access management, identity governance, AI in security, standards in identity, identity as a service, identity management, security controls, behavioral analysis, customer experience, identity standards, identity security, digital identity, identity governance, cybersecurity, identity threats

Chapters

00:00 Introduction

03:12 Market News: Funding and Innovations

12:37 Leadership Changes in Identity Security

14:04 The Evolution of Identity Security

24:11 Identity as a Strategic Business Element

25:57 The Security Landscape and Vendor Commitments

28:00 Evolving Security Controls in Identity Management

30:11 Behavioral Analysis: The Missing Piece

32:00 The Strategic Importance of Identity Management

34:03 Identity as a Brand and Customer Experience

35:58 The Maturity of Identity Solutions

37:56 Decoupling User Experience from Identity Security

39:49 Complexity in Identity Standards and Security

44:07 Emerging Threats and the Need for Standards



Feb 18, 202550:16
E59 - Token Security Funding / Jumpcloud + Stack Identity / Identity Data Management

E59 - Token Security Funding / Jumpcloud + Stack Identity / Identity Data Management

Summary

In this episode of the Analyst Brief Podcast, Simon and Dave return to discuss the latest funding trends in identity security, the rise of non-human identity (NHI), and the importance of governance and data management in identity solutions.


Useful Links:


Keywords

identity security, funding, non-human identity, governance, AI, identity management, chief data officer, AI, identity security, prompt engineering, content authenticity, digital transformation, business opportunities


Chapters

00:00 Introduction and Podcast Evolution

03:04 Funding Trends in Identity Security

08:43 The Rise of Non-Human Identity (NHI)

15:03 Governance and Identity Data Management

23:38 Emerging Trends in Data Technology

26:20 The Role of Chief Data Officers

30:12 AI's Impact on Identity and Security

32:38 Navigating the Challenges of AI and Data Authenticity



Feb 04, 202540:54
E58 - Microsoft SFI / Okta SIC / Funding for Apono, Hydden and P0 Security
Oct 08, 202441:27
E57 - Back to School 2024 Episode

E57 - Back to School 2024 Episode

Summary

In this episode of the Week in Identity podcast, Simon and David discuss the latest trends and developments in identity security, including market activity, funding rounds, and significant acquisitions. They delve into the importance of NIST guidelines, the rise of non-human identity (NHI), and the implications of recent acquisitions by MasterCard and Salesforce. The conversation highlights the evolving landscape of identity management and the critical need for organizations to adapt to new challenges in cybersecurity.


Chapters

00:00 Introduction to the Week in Identity Podcast

03:52 NIST Guidelines and Identity Assurance

06:30 Aembit Funding Rounds and Non-Human Identity

13:42 Acquisitions in Identity: IndyKite and 3Edges

20:17 MasterCard and Recorded Future

26:39 Salesforce and Own Data






Sep 17, 202430:45
E56 - Emergency Episode Discussing the Global Crowdstrike Issue

E56 - Emergency Episode Discussing the Global Crowdstrike Issue

Simon and David convene for a special episode to discuss the ongoing global IT outages caused by a Crowdstrike update. Note this was released Friday 19th July 9am PST / 5pm BST

Jul 19, 202442:42
E55 - Identiverse, Identity Week Europe and Gartner SRM
Jun 19, 202436:26
E54 - CyberArk and Venafi / QRadar and Palo Alto / Akamai and NoName Security

E54 - CyberArk and Venafi / QRadar and Palo Alto / Akamai and NoName Security

Summary

In this episode, Simon and David discuss recent acquisitions in the identity and access management space, including Palo Alto's acquisition of QRadar, Akamai's acquisition of NoName, and CyberArk's acquisition of Venafi. They explore the importance of resilience in IAM infrastructure and the growing need for managing machine identities and workloads. The conversation highlights the challenges and opportunities in securing non-human identities and the role of PAM in addressing these issues. They also touch on the dark web and identity-based threats.

Keywords

identity and access management, acquisitions, resilience, IAM infrastructure, machine identities, workloads, PAM, non-human identities, dark web, identity-based threats

Takeaways

  • Recent acquisitions in the IAM space include Palo Alto's acquisition of Q Radar, Akamai's acquisition of No Name Security, and CyberArk's acquisition of Venafi.
  • Managing machine identities and workloads is a growing challenge in the IAM space.
  • PAM plays a crucial role in securing non-human identities.

Chapters

00:00 Introduction and Overview

02:40 Recent Acquisitions in the IAM Space

06:02 The Importance of Resilience in IAM Infrastructure

09:12 Managing Machine Identities and Workloads

15:23 The Role of PAM in Securing Non-Human Identities

26:14 Upcoming Presentation at Identiverse

May 24, 202439:08
E53 - A Review of RSA Conference 2024 - Part 2

E53 - A Review of RSA Conference 2024 - Part 2

Summary

In this episode, Simon and David discuss the convergence of identity and cybersecurity, particularly in the context of cloud adoption. They explore the challenges and opportunities that arise from this convergence and the impact on organizations of different sizes. They also touch on the confusion caused by the abundance of acronyms in the industry and the need for clarity and standardization. Overall, they emphasize the importance of protecting identity components and the critical role of identity in security. The conversation explores the challenges and opportunities in the identity and access management (IAM) space, with a focus on the importance of data management and the need for effective discovery and remediation processes. The fragmentation of identity systems and the lack of visibility into identities and their interactions are identified as key issues. The acquisition of Q Radar by Palo Alto is discussed as a potential game-changer in the IAM space. The conversation concludes with the recognition that while automation and AI have their place, human involvement is still crucial for effective remediation.

Keywords

identity, cybersecurity, convergence, cloud, challenges, opportunities, acronyms, standardization, protection, security, identity and access management, IAM, data management, discovery, remediation, fragmentation, visibility, Q Radar, Palo Alto, automation, AI, human involvement

Takeaways

Identity and cybersecurity are converging, particularly in the context of cloud adoption.

Organizations of different sizes face different challenges and opportunities in managing identity and security.

The abundance of acronyms in the industry can be confusing, and there is a need for clarity and standardization.

Protecting identity components is crucial, as identity often plays a central role in security breaches. Effective data management is crucial in the identity and access management space.

Fragmentation of identity systems and lack of visibility into identities and their interactions are key challenges.

The acquisition of Q Radar by Palo Alto has the potential to impact the IAM space.

While automation and AI have their place, human involvement is still necessary for effective remediation.

Chapters

00:00 Introduction and Post-RSA Recovery

01:23 Unpacking the Convergence of Identity and Cybersecurity

07:13 Lessons from the Transition from Horses to Cars

09:08 The Confusion of Acronyms and the Need for Clarity

13:25 The Hype Cycle and the Trajectory of New Technologies

15:16 The Impact of Cloud Adoption on Identity and Security

23:21 The Transient Tilt in the Cloud and the Importance of Protecting Identity Components

24:13 The Importance of Data Management in IAM

27:38 Challenges of Fragmentation and Lack of Visibility

30:53 The Potential Impact of the Q Radar Acquisition

34:44 The Role of Automation and Human Involvement in Remediation

May 17, 202443:13
E52 - A Review of RSA Conference 2024 - Part 1

E52 - A Review of RSA Conference 2024 - Part 1

Summary

In this episode, Simon and David discuss their experiences at the RSA Conference 2024 and highlight the key themes and trends in the identity and access management (IAM) space. They emphasize the growing importance of identity in the security landscape and the increasing integration of identity into RSA. They also discuss the impact of AI and Gen AI on IAM, the need for better discovery and visibility in identity systems, and the challenges of transitioning from legacy technology to new, intelligent systems. They conclude by highlighting the importance of preparing data for the Gen AI world and the need for organizations to adapt and embrace new technologies in order to stay competitive.

Keywords

RSA Conference, RSAC2024, identity and access management, IAM, security, AI, Gen AI, discovery, visibility, legacy technology, data preparation, competitive advantage

Takeaways

Identity is becoming increasingly important in the security landscape, and RSA is a key event for identity professionals.

The integration of identity into themes and topics at RSAC2024 is a reflection of the growing significance of identity in the industry.

AI and Gen AI are driving the need for more intelligent identity systems and the transition from legacy technology.

Discovery and visibility are crucial in identity systems, and organizations need to break down silos and integrate their identity infrastructure.

Preparing data for the Gen AI world is essential for organizations to stay competitive and take advantage of new technologies.

Chapters

00:00 Introduction and Overview of RSA Conference

13:02 The Growing Importance of Identity in the Security Landscape

21:03 Challenges of Transitioning from Legacy Technology to New, Intelligent Systems

25:01 The Impact of AI and Gen AI on IAM

31:05 Preparing Data for the Gen AI World

33:30 Preview of Next Episode on Fraud and Cloud

May 14, 202435:10
E51 - Microsoft Entra External IDs / Cisco and StrongDM / CEO view on Cyber

E51 - Microsoft Entra External IDs / Cisco and StrongDM / CEO view on Cyber

This week Simon and David return with a weekly dose of industry analysis on the global identity and access management space. First up a discussion on Microsoft announcing the GA of their Entra for External IDs - who is it aimed at? Is it ground breaking? Next up is Cisco who announced an investment round into next-gen PAM provider StrongDM. Finally they discuss a great interview by Standard Chartered CEO Bill Winters and his view of cyber in the board and its strategic value.

May 03, 202456:10
E50 - BeyondTrust and Entitle / Cisco Duo breach and Hypershield launch / CSPM+NHI / SecureAuth new CEO
Apr 23, 202455:25
E49 - The IAM and Fraud Episode

E49 - The IAM and Fraud Episode

After a small spring break, Simon and David return with a special episode focused on the convergence of identity and access management and fraud. Why the convergence? How to measure success? What are the three 'V's' as they relate to fraud? How should people and process adapt to keep up with technology changes? And how to thwart the asymmetric advantage of the fraudster?

Apr 16, 202451:17
E48 - NIST CSF 2.0 / Nightdragon CISO Spend Report / PAM + IGA Convergence
Mar 05, 202457:57
E47 - The Data Security Episode

E47 - The Data Security Episode

This week Simon and David have a mini-deep dive on data security. Data storage locations are changing. Organisations are harvesting PII, transaction and payment data continually being collected. And what about disinformation and misinformation? What role does identity have here? What about data and deepfakes for onboarding and biometrics? What does data access governance meanin 2024? Is data integrity protection the biggest issue within cyber today? How should we handle fine grained and contextual access and how do the CISO and Chief Data Officer relate?

Feb 23, 202448:50
E46 - SecureAuth acquire Cloudentity / Entrust to acquire OnFido / Cisco announces Identity Intelligence / Mastercard Emerging Trends

E46 - SecureAuth acquire Cloudentity / Entrust to acquire OnFido / Cisco announces Identity Intelligence / Mastercard Emerging Trends

This week Simon and David focus on a new raft of pending acquisitions. They discuss the impact of SecureAuth and Cloudentity joining forces as well as news that Entrust are in talks to buy OnFido. They also cover the announcement that Cisco has launched a new Identity Intelligence offering hot on the back of acquiring ITDR vendor Oort in 2023. They finish up by taking a look at an emerging technology trends report released by Mastercard. Is Data security the next big IAM integration story?

Feb 13, 202436:26
E45 - Okta Layoffs / Tech Downturn / Market Consolidation

E45 - Okta Layoffs / Tech Downturn / Market Consolidation

This week Simon and David take a look at the recent announcement that Okta are laying off 400 staff globally. Is this part of a broader tech slow down? They discuss some of the trends from 2023 with respect to staff attrition and the impact that has had. With funding still high for IAM and cyber what does 2024 have in store?

Feb 06, 202443:11
E44 - World Economic Forum Cybersecurity 2024 Outlook Report Review

E44 - World Economic Forum Cybersecurity 2024 Outlook Report Review

This week Simon and David review the 40 page Global Cybersecurity Outlook 2024 report released by the World Economic Forum.

This report covered 49 countries with over 200 respondents from a range of organisations. The report covered cyber resilience, inequity, emerging technologies such as generative AI, the role of cyber regulations, how to engage strategic leaders with respect to cyber risk and strategy and the role of changing geopolitical tensions and the impact on private sector cyber risk.

Jan 19, 202451:15
E43 - 2024 Predictions / ITDR Acquisition Discussion / IAM and Cyber Mashup

E43 - 2024 Predictions / ITDR Acquisition Discussion / IAM and Cyber Mashup

The first episode of 2024 sees Simon and David analyse the recent spate of IDTR and ISPM acquisitions including:

Cisco's 2023 purchase of Oort;

Okta's acquisition of Spera Security;

Delinea's acquisition of Authomize.

What do those acquisitions have in common? Will there be more? Is cyber and IAM now becoming one thing? Other predictions include consolidation within passwordless authentication, the rise of workload identity.

Jan 16, 202446:07
E42 - Blackhat 2023 London Review / Is the CISO role too tough? / Imprivata new CEO

E42 - Blackhat 2023 London Review / Is the CISO role too tough? / Imprivata new CEO

This week Simon and David review the recent Blackhat EMEA 2023 event that was held in London. They discuss the recent CEO change at Imprivata - and what means for their plans going forward. With respect to Blackhat they discuss the role of the CISO - is it becoming difficult to hire and be successful? Other Blackhat topics included a keynote by the UK's NCSC CTO discussing the asymmetric adversarial threat, password managers on mobile and how they "Autospill" credentials, the tampering of patient records and is data integrity now more important than confidentiality?

The Cyber Hut Blackhat review is here.

Dec 19, 202301:00:04
E41 - Okta Breach Part II / Okta Q3 Results / Bookings.com Attack

E41 - Okta Breach Part II / Okta Q3 Results / Bookings.com Attack

This week Simon and David return to Okta - to uncover more about details on their recent breach. They also discuss their recent Q3 results and are Microsoft their only competitor? They also discuss a recent complex attack involving customers of Booking.com - and cover push payment fraud, ATO, complex supply chains and protecting trust boundaries.

Dec 05, 202338:49
E40 - Forrester SRM Washington / Ping Youniverse London / Okta Breach

E40 - Forrester SRM Washington / Ping Youniverse London / Okta Breach

After a couple of weeks off, Simon and David return for an hour long special. They review the recent Security and Risk Management event in Washington DC hosted by Forrester where the topic of identity and cyber convergence appeared. They comment on the recent Okta breach and what that means for the world of complex software supply chain attacks and the rise of identity security, ITDR and identit security posture management. They also review the London version of the Ping Identity Youniverse series of events.

Nov 20, 202301:00:03
E39 - The FIDO Authenticate 2023 Lookback Episode

E39 - The FIDO Authenticate 2023 Lookback Episode

This week Simon and David were in sunny Carlsbad, San Diego for the latest Authenticate conference hosted by the FIDO Alliance. In this episode they review the main topics of the event, taking a look at passkey deployment maturity, KPIs, biometrics, threat models, adoption patterns as well as orthogonal topics such as machine identity, crypto agility, IDV + converged identity assurance.

Oct 20, 202347:13
E38 - The NSA + CISA Top 10 Cyber Security Misconfigurations Episode

E38 - The NSA + CISA Top 10 Cyber Security Misconfigurations Episode

This week Simon and David take a deep dive look at a recent cyber security advisory that was released by the NSA and CISA recently. This top 10 list covers a range of issues from default credentials, excessive permissions, a lack of networking monitoring and segmentation as well a lack of MFA and poor credential management. Simon and David apply their identity lens to the top 10 and what it may mean for your organisation.

Oct 11, 202349:02
E37 - MGM Cyber Attack / Part II on ForgeRock and Ping
Sep 18, 202349:23
E36 - Tenable acquires Ermetic / Cisco acquires Oort / ForgeRock and Ping to combine / Okta attack

E36 - Tenable acquires Ermetic / Cisco acquires Oort / ForgeRock and Ping to combine / Okta attack

After the summer recess, Simon and David return for another Week in Identity catch-up. This week...heavily influenced by some recent acquisition activity...they discuss Tenable buying CNAPP/CIEM provider Ermetic, a rewind to Cisco buying ITDR vendor Oort and a detailed discussion on the uncertainties surrounding Thoma Bravo adding ForgeRock to their stable. They also discuss the further rise of Identity Security and a recent release by Okta's Defensive Cyber Operations team on a recent attack.

Sep 08, 202343:16
E35 - The SEC Cyber Risk Management Rules Episode

E35 - The SEC Cyber Risk Management Rules Episode

This week the US Security and Exchanges Commission announced rules requiring organisations to handle cyber breach notifications, risk management and expert cyber personnel in a different way. Simon and David delve into the implications of this. Why have organisations been reluctant to notify on breaches historically? A lack of detection? A lack of incident response playbooks? A lack of expert personnel? What is the end goal of such regulation? What will success look like in the short and long terms? Clearly a move towards a more risk based approach is the ideal outcome but why has the market failed for cyber security? What are the three V's of threats?

Jul 28, 202346:37
E34 - Thoughts on Kevin Mitnick / Cisco buying Oort / ITDR problem space / Are Microsoft en-route to monopolising IAM?

E34 - Thoughts on Kevin Mitnick / Cisco buying Oort / ITDR problem space / Are Microsoft en-route to monopolising IAM?

This week Simon and David discuss the recent acquisition of Oort by Cisco, which finds them discussing the entire ITDR space - who is the buying persona and what problems will it solve? As always technology isn't always the answer and we mustn't forget the human element. They answer an audience question focused on Microsoft - and will they start to dominate the IAM space? They also remember the passing of hacking pioneer Kevin Mitnick.

Jul 21, 202337:42
E33 - An interview with Eric Olden from Strata.io

E33 - An interview with Eric Olden from Strata.io

This week there is a special guest on the podcast. Eric Olden CEO at Strata joins Simon for a discussion. They cover a broad and meandering set of topics focused on Eric's journey to being a multi-company founder (his first startup was at age 23..), contributing to the SAML specification and how he is now focused on identity orchestration at Strata. What is orchestration? Why is it needed and how the rise of the hybrid cloud landscape is here to stay. They deep dive into IDQL, identity integration recipes and how the rise of the AI co-pilot may save us all.

Jul 07, 202347:38
E32 - N0Auth Vulnerability / Infosec 2023 London - Data Integrity / Cyber + IAM Mashups / The Rise of Fraud / Generative AI (good and bad)

E32 - N0Auth Vulnerability / Infosec 2023 London - Data Integrity / Cyber + IAM Mashups / The Rise of Fraud / Generative AI (good and bad)

This week Simon and David took a meandering look at the last weeks most eye catching events in the world of identity. They had a quick recap of Infosec 2023 held at the eXcel in London, where the topic of data level encryption, data origin authentication and integrity caught Simon's eye. They discussed a recent vulnerability found in deployments on OIDC in the Microsoft world as uncovered by Descope called NOAuth - which essentially was caused by poor verificaiton of OIDC id token claims. They finished off by discussing the world of generative AI and how that is impacting the world of fraud, content, biometrics, misinformation and more...

Jun 26, 202338:21
E31 - An interview with HYPR CEO Bojan Simic

E31 - An interview with HYPR CEO Bojan Simic

This episode, sees The Week in Identity have another specialist guest: Bojan Simic, Co founder and CEO of passwordless specialists HYPR. Simon and Bojan delve into Bojan's story from being a computer science graduate to entering the security world pen-testing in New York and working with some of the world's largest financial services institutions. From there the inspiration to rid the world of passwords started to take hold...and ten years later, seeing HYPR as a leading passwordless authentication provider. The topic covers a range of fascinating subjects, from the perfect storm of FIDO, mobile biometrics and secure hardware storage, through to how to create strategies for mass passwordless adoption based on nudge-theory, gamification and stakeholder buy-in. They also cover success criteria, AI and what the future may hold for IAM...

Jun 16, 202344:26
E30 - Identiverse 2023 / Gartner Security & Risk Management USA / Passkeys / Minimum Effective Models...

E30 - Identiverse 2023 / Gartner Security & Risk Management USA / Passkeys / Minimum Effective Models...

This week Simon and David discuss the recent Identiverse conference as well the Gartner Security Risk Management summit that happened shortly afterwards. They delve into the world of passkeys (again), verifiable credentials and modern architectures and how we're moving to an industry education maturity model, where organisations are going beyond knowing what a technology is, to how to get started and derive value. They also discuss the concept of "minimum effectiveness" as it pertains to technology, expertise, friction and insights and that essentially having too much identity and access management "stuff" is often a precursor to complexity and failure.

Jun 09, 202334:40
E29 - Identity Mesh and Identity Fabric / Heliview IAM Conference Review / Cyber + Identity Mashup / People, Process and Technology / IAM Threat Reports

E29 - Identity Mesh and Identity Fabric / Heliview IAM Conference Review / Cyber + Identity Mashup / People, Process and Technology / IAM Threat Reports

This week Simon and David review the recent Heliview IAM Conference that took place in the Netherlands. The main topic for the day was the rise of the identity fabric (or mesh) and how this can enable the modern organisation with a range of agile IAM components that supports both business and security use cases. Simon presented a keynote on the future of IAM - using some research from The Cyber Hut focusing on where IAM may look like in 2028 and beyond...

They also discussed the need for people, process and technology integration, in order to map the existing IAM landscape to future investment and metrics.

They finish off by discussing the rise in cyber threat reports that have emerged in the past month that all have a very strong reliance on IAM - and why ITDR is a process not a product.

Cyber Threat Reports:

May 26, 202344:42
E28 - The RSA 2023 Episode - Passkeys / MFA / Adversary in the Middle / Collaboration / Standards

E28 - The RSA 2023 Episode - Passkeys / MFA / Adversary in the Middle / Collaboration / Standards

This week Simon and David review the recent RSA Conference that occurred at the end of April over in San Francisco. From the generic meta-patterns at the conference covering themes such as collaboration, standards, multi-cloud and technology integration, through to more IAM focused conversations covering MFA, passkeys and authentication attacks. Are passkeys now here to stay? What will help adoption? Will attacks on passkeys start to increase along with usage rates? Will attacks against existing MFA forms including SIM swap, MFA fatigue and social engineering be a compelling event to improve adoption?

May 11, 202354:26
E27 - RadiantLogic & Brainwave / New Styra CEO / Auth0 OpenFGA project / Chief Identity Officers / AuthZ as part of ZT

E27 - RadiantLogic & Brainwave / New Styra CEO / Auth0 OpenFGA project / Chief Identity Officers / AuthZ as part of ZT

This week Simon and David tackle a range of news items including: Radiant Logic completing the acquisition of IGA vendor Brainwave; Authorization vendor Styra getting a new CEO and Auth0 (by Okta) releasing v1.0 of a new open source authorization project called OpenFGA. They also tackle the question of whether we need to see Chief Identity Officers in the board room and how zero trust is essentially driving the demand for authorization platforms.

Apr 21, 202345:22
E26 - Interview with Alex Bovee from ConductorOne

E26 - Interview with Alex Bovee from ConductorOne

In this week's episode, Simon and David are joined by Alex Bovee the CEO of https://www.conductorone.com/ - a next generation identity security and IGA provider. They cover a range of topics including the adoption of cloud services and the impact on security, the cloud shared security model, the left shifting of identity risk from being detection focused to preventative, reducing access reviews to focus on exceptions only, how the security world is taking on more IAM capabilities and knowledge and the introduction of a new open source project called Baton - to extract and manage identity data.

Mar 31, 202343:41